ComboFix 08-08-04.09 - bruno decaria 2008-12-11 7:51:41.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.219 [GMT -5:00]
Running from: E:\cf2332.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
2008-12-09 13:10 . 2008-12-09 13:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-12-09 12:38 . 2008-12-09 12:38 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-09 12:38 . 2008-12-09 12:38 <DIR> d-------- C:\Documents and Settings\bruno decaria\Application Data\Malwarebytes
2008-12-09 12:38 . 2008-12-09 12:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-09 12:38 . 2008-12-03 19:59 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-12-09 12:38 . 2008-12-03 19:59 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-12-09 11:30 . 2008-12-09 11:30 <DIR> d-------- C:\Program Files\CCleaner
2008-12-08 20:19 . 2008-12-08 20:19 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-12-08 20:19 . 2008-12-08 20:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-12-08 20:19 . 2008-12-08 20:19 <DIR> d-------- C:\Documents and Settings\bruno decaria\Application Data\SUPERAntiSpyware.com
2008-12-08 20:19 . 2008-12-08 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-08 20:09 . 2008-12-10 08:12 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-08 20:07 . 2008-12-08 20:07 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-12-08 20:07 . 2008-12-08 20:07 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-12-08 20:07 . 2008-12-08 20:07 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-12-08 20:06 . 2008-12-08 20:06 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-12-08 20:06 . 2008-12-08 20:06 <DIR> d-------- C:\Program Files\AVG
2008-12-08 20:06 . 2008-12-08 20:09 <DIR> d-------- C:\Documents and Settings\bruno decaria\Application Data\AVGTOOLBAR
2008-12-08 20:06 . 2008-12-08 20:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-12-08 20:00 . 2006-01-30 18:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-12-08 20:00 . 2008-12-08 20:07 <DIR> d-------- C:\Documents and Settings\Administrator
2008-12-06 23:01 . 2006-01-30 18:47 <DIR> d-------- C:\Documents and Settings\noel\Application Data\Sonic
2008-12-06 23:01 . 2008-12-06 23:01 <DIR> d-------- C:\Documents and Settings\noel\Application Data\alot
2008-12-06 23:01 . 2008-12-08 20:07 <DIR> d-------- C:\Documents and Settings\noel
2008-12-05 19:24 . 2008-12-09 12:31 <DIR> d-------- C:\Program Files\avrlabs
2008-12-05 19:24 . 2008-12-05 19:24 <DIR> d--hs---- C:\Documents and Settings\bruno decaria\DC48230827A3E4F8
2008-12-03 21:40 . 2008-12-08 20:09 <DIR> d-------- C:\WINDOWS\system32\351631
2008-12-03 21:40 . 2008-12-04 20:18 478 ---h----- C:\WINDOWS\f49f4d98.dat
2008-12-03 21:40 . 2008-12-05 19:23 1 ---h----- C:\WINDOWS\f49f4daa.dat
2008-12-03 13:28 . 2008-12-03 13:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-12-03 13:28 . 2008-12-03 13:28 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-10 13:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-12-09 18:25 --------- d-----w C:\Program Files\Google
2008-12-09 16:07 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-07 04:05 --------- d-----w C:\Program Files\Bodog Poker
2008-12-05 16:58 --------- d-----w C:\Documents and Settings\bruno decaria\Application Data\alot
2008-12-03 18:11 --------- d-----w C:\Program Files\Yahoo! Games
2008-12-03 18:11 --------- d-----w C:\Program Files\GameHouse
2008-12-03 18:10 --------- d-----w C:\Documents and Settings\bruno decaria\Application Data\PlayFirst
2008-12-03 18:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-12-03 18:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\HipSoft
2008-12-01 21:21 --------- d--h--w C:\Documents and Settings\bruno decaria\Application Data\Move Networks
2008-11-23 19:19 --------- d-----w C:\Program Files\betED.com
2008-10-24 11:10 453,632 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-10-24 11:10 453,632 ------w C:\WINDOWS\system32\dllcache\mrxsmb.sys
2008-10-20 12:21 --------- d-----w C:\Documents and Settings\bruno decaria\Application Data\MSNInstaller
2008-10-16 19:13 202,776 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w C:\WINDOWS\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w C:\WINDOWS\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w C:\WINDOWS\system32\wups.dll
2008-10-16 19:08 34,328 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w C:\WINDOWS\system32\muweb.dll
2008-10-15 16:57 332,800 ------w C:\WINDOWS\system32\dllcache\netapi32.dll
2008-09-15 11:57 1,846,016 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-15 11:57 1,846,016 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2006-05-13 14:28 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 21:55 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 04:33 155648]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 16:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 16:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 16:36 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 03:10 49263]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-09-01 18:24 684032]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 09:04 53248]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01 110592]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-01-30 18:46 168448]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-01-17 07:28 282624]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 01:38 34672]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-12-08 20:06 1261336]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 02:19:50 217193]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-01-30 18:41:31 24576]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 09:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\PowerTerm WebConnect 5.1\\www.decariarx.com\\PtLpd.exe"=
"C:\\PowerTerm WebConnect 5.1\\www.decariarx.com\\ptermX.exe"=
"C:\\Program Files\\betED.com\\client.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-12-08 20:07]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-12-08 20:06]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-12-08 20:06]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-12-08 20:07]
R2 DC48230827A3E4F8;DC48230827A3E4F8;C:\Documents and Settings\bruno decaria\DC48230827A3E4F8\DC48230827A3E4F8 [2008-12-05 19:24]
S2 Logical Disk Manager (dmserver) ;Logical Disk Manager (dmserver) ;C:\Program Files\tinyproxy\tinyproxy.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{6A26574A-DD6D-4382-8C76-0DF06C478D3A} - C:\WINDOWS\system32\351631\351631.dll
BHO-{D695B871-8020-4041-A6D2-59F922E1B2E2} - C:\Program Files\avrlabs\avrlabsWarning.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://yahoo.com/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-Internet Settings,ProxyServer = http=127.0.0.1:9090
R1 -: HKCU-Internet Settings,ProxyOverride = *.local;<local>
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 -: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-11 07:52:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DC48230827A3E4F8]
"ImagePath"="\??\C:\Documents and Settings\bruno decaria\DC48230827A3E4F8\DC48230827A3E4F8"
.
Completion time: 2008-12-11 7:54:31
ComboFix-quarantined-files.txt 2008-12-11 12:54:19
Pre-Run: 69,572,632,576 bytes free
Post-Run: 69,640,871,936 bytes free
158 --- E O F --- 2008-12-10 13:19:09