ComboFix 08-11-10.01 - Royus 2008-11-11 14:07:47.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.592 [GMT 1:00]
Running from: c:\documents and settings\Royus\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Royus\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\gggogoao.ini
c:\windows\system32\xfuqquwa.ini
.
((((((((((((((((((((((((( Files Created from 2008-10-11 to 2008-11-11 )))))))))))))))))))))))))))))))
.
2008-11-11 02:58 . 2008-11-11 02:59 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-11-11 02:58 . 2008-11-11 02:58 <DIR> d-------- c:\program files\AVG
2008-11-11 02:58 . 2008-11-11 02:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-11-11 02:58 . 2008-11-11 02:58 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-11-11 02:58 . 2008-11-11 02:58 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-11-11 02:20 . 2008-11-11 02:20 <DIR> d-------- c:\program files\Trend Micro
2008-11-11 01:52 . 2008-11-11 02:00 2,312 --a------ c:\windows\system32\tmp.reg
2008-11-11 00:49 . 2008-11-11 00:49 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-11 00:49 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-11 00:49 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-11 00:37 . 2008-11-11 01:00 <DIR> d-------- c:\program files\Exterminate It!
2008-11-11 00:14 . 2008-11-11 00:14 <DIR> d-------- c:\documents and settings\Royus\Application Data\Malwarebytes
2008-11-11 00:14 . 2008-11-11 00:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-11 00:01 . 2008-11-11 02:10 <DIR> d-------- c:\program files\PackageFactory
2008-11-02 14:14 . 2008-11-11 14:07 <DIR> d-------- C:\QUARANTINE
2008-10-29 23:25 . 2008-11-11 03:12 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-10-29 22:23 . 2008-04-14 05:42 116,224 --a--c--- c:\windows\system32\dllcache\xrxwiadr.dll
2008-10-29 22:23 . 2008-04-14 05:42 18,944 --a--c--- c:\windows\system32\dllcache\xrxscnui.dll
2008-10-29 22:23 . 2008-04-14 00:06 8,832 --a--c--- c:\windows\system32\dllcache\wmiacpi.sys
2008-10-29 22:23 . 2008-04-14 05:42 8,192 --a--c--- c:\windows\system32\dllcache\wshirda.dll
2008-10-29 22:22 . 2008-04-14 00:15 60,032 --a--c--- c:\windows\system32\dllcache\usbaudio.sys
2008-10-29 22:22 . 2008-04-14 05:42 53,760 --a--c--- c:\windows\system32\dllcache\vfwwdm32.dll
2008-10-29 22:22 . 2008-04-14 00:15 31,744 --a--c--- c:\windows\system32\dllcache\wceusbsh.sys
2008-10-29 22:22 . 2008-04-14 00:15 26,112 --a--c--- c:\windows\system32\dllcache\usbser.sys
2008-10-29 22:22 . 2008-04-14 00:17 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2008-10-29 22:22 . 2008-04-14 00:15 20,608 --a--c--- c:\windows\system32\dllcache\usbuhci.sys
2008-10-29 22:22 . 2008-04-14 00:10 5,376 --a--c--- c:\windows\system32\dllcache\viaide.sys
2008-10-29 22:21 . 2008-04-14 00:10 149,376 --a--c--- c:\windows\system32\dllcache\tffsport.sys
2008-10-29 22:21 . 2008-04-14 05:42 82,944 --a--c--- c:\windows\system32\dllcache\tp4mon.exe
2008-10-29 22:21 . 2008-04-14 00:10 7,552 --a--c--- c:\windows\system32\dllcache\sonyait.sys
2008-10-29 22:20 . 2008-04-14 00:10 43,904 --a--c--- c:\windows\system32\dllcache\sbp2port.sys
2008-10-29 22:20 . 2008-04-14 05:42 29,696 --a--c--- c:\windows\system32\dllcache\rw450ext.dll
2008-10-29 22:20 . 2008-04-14 05:42 27,648 --a--c--- c:\windows\system32\dllcache\rw430ext.dll
2008-10-29 22:20 . 2008-04-14 00:06 16,000 --a--c--- c:\windows\system32\dllcache\smbbatt.sys
2008-10-29 22:20 . 2008-04-14 00:15 11,520 --a--c--- c:\windows\system32\dllcache\scsiscan.sys
2008-10-29 22:20 . 2008-04-14 00:06 6,912 --a--c--- c:\windows\system32\dllcache\smbclass.sys
2008-10-29 22:19 . 2008-04-14 05:40 259,328 --a--c--- c:\windows\system32\dllcache\perm3dd.dll
2008-10-29 22:19 . 2008-04-14 05:40 211,584 --a--c--- c:\windows\system32\dllcache\perm2dll.dll
2008-10-29 22:19 . 2008-04-14 05:42 159,232 --a--c--- c:\windows\system32\dllcache\ptpusd.dll
2008-10-29 22:19 . 2008-04-14 00:10 79,104 --a--c--- c:\windows\system32\dllcache\rocket.sys
2008-10-29 22:19 . 2008-04-14 00:14 28,032 --a--c--- c:\windows\system32\dllcache\perm3.sys
2008-10-29 22:19 . 2008-04-14 00:14 27,904 --a--c--- c:\windows\system32\dllcache\perm2.sys
2008-10-29 22:19 . 2008-04-14 00:11 17,664 --a--c--- c:\windows\system32\dllcache\ppa3.sys
2008-10-29 22:19 . 2008-04-14 00:10 8,832 --a--c--- c:\windows\system32\dllcache\powerfil.sys
2008-10-29 22:19 . 2008-04-14 00:10 6,016 --a--c--- c:\windows\system32\dllcache\qic157.sys
2008-10-29 22:18 . 2008-04-14 00:16 61,696 --a--c--- c:\windows\system32\dllcache\ohci1394.sys
2008-10-29 22:18 . 2008-04-14 00:16 49,024 --a--c--- c:\windows\system32\dllcache\mstape.sys
2008-10-29 22:18 . 2008-04-14 00:24 28,672 --a--c--- c:\windows\system32\dllcache\nscirda.sys
2008-10-29 22:17 . 2008-04-14 00:11 26,112 --a--c--- c:\windows\system32\dllcache\memstpci.sys
2008-10-29 22:17 . 2008-04-14 00:24 22,016 --a--c--- c:\windows\system32\dllcache\msircomm.sys
2008-10-29 22:17 . 2008-04-14 00:10 7,040 --a--c--- c:\windows\system32\dllcache\ltotape.sys
2008-10-29 22:16 . 2008-04-14 05:41 253,952 --a--c--- c:\windows\system32\dllcache\kdsusd.dll
2008-10-29 22:16 . 2008-04-14 05:42 151,552 --a--c--- c:\windows\system32\dllcache\irftp.exe
2008-10-29 22:16 . 2008-04-14 00:24 88,192 --a--c--- c:\windows\system32\dllcache\irda.sys
2008-10-29 22:16 . 2008-04-14 05:41 48,640 --a--c--- c:\windows\system32\dllcache\kdsui.dll
2008-10-29 22:16 . 2008-04-14 00:10 34,688 --a--c--- c:\windows\system32\dllcache\lbrtfdc.sys
2008-10-29 22:16 . 2008-04-14 05:41 28,160 --a--c--- c:\windows\system32\dllcache\irmon.dll
2008-10-29 22:16 . 2008-04-14 05:39 6,144 --a--c--- c:\windows\system32\dllcache\kbd106.dll
2008-10-29 22:16 . 2008-04-14 00:10 5,504 --a--c--- c:\windows\system32\dllcache\intelide.sys
2008-10-29 22:15 . 2008-04-14 05:41 702,845 --a--c--- c:\windows\system32\dllcache\i81xdnt5.dll
2008-10-29 22:15 . 2008-04-14 00:11 18,560 --a--c--- c:\windows\system32\dllcache\i2omp.sys
2008-10-29 22:15 . 2008-04-14 00:11 8,576 --a--c--- c:\windows\system32\dllcache\i2omgmt.sys
2008-10-29 22:14 . 2008-04-14 00:15 59,136 --a--c--- c:\windows\system32\dllcache\gckernel.sys
2008-10-29 22:14 . 2008-04-14 00:10 28,288 --a--c--- c:\windows\system32\dllcache\grserial.sys
2008-10-29 22:14 . 2008-04-14 00:06 20,352 --a--c--- c:\windows\system32\dllcache\hidbatt.sys
2008-10-29 22:14 . 2008-04-14 00:15 10,624 --a--c--- c:\windows\system32\dllcache\gameenum.sys
2008-10-29 22:13 . 2008-04-14 00:09 206,976 --a--c--- c:\windows\system32\dllcache\dot4.sys
2008-10-29 22:13 . 2008-04-14 05:42 20,992 --a--c--- c:\windows\system32\dllcache\dshowext.ax
2008-10-29 22:13 . 2008-04-14 00:10 8,320 --a--c--- c:\windows\system32\dllcache\dlttape.sys
2008-10-29 22:12 . 2008-04-14 05:41 249,856 --a--c--- c:\windows\system32\dllcache\ctmasetp.dll
2008-10-29 22:12 . 2008-04-14 05:41 121,856 --a--c--- c:\windows\system32\dllcache\camext30.dll
2008-10-29 22:12 . 2008-04-14 00:06 13,952 --a--c--- c:\windows\system32\dllcache\cmbatt.sys
2008-10-29 22:12 . 2008-04-14 00:06 10,240 --a--c--- c:\windows\system32\dllcache\compbatt.sys
2008-10-29 22:12 . 2008-04-14 00:11 8,192 --a--c--- c:\windows\system32\dllcache\changer.sys
2008-10-29 22:11 . 2008-04-14 00:16 38,912 --a--c--- c:\windows\system32\dllcache\avc.sys
2008-10-29 22:11 . 2008-04-14 00:06 14,208 --a--c--- c:\windows\system32\dllcache\battc.sys
2008-10-29 22:11 . 2008-04-14 00:16 13,696 --a--c--- c:\windows\system32\dllcache\avcstrm.sys
2008-10-29 22:10 . 2008-04-14 00:16 53,376 --a--c--- c:\windows\system32\dllcache\1394bus.sys
2008-10-29 22:10 . 2008-04-14 00:16 48,128 --a--c--- c:\windows\system32\dllcache\61883.sys
2008-10-29 22:10 . 2008-04-14 00:10 12,288 --a--c--- c:\windows\system32\dllcache\4mmdat.sys
2008-10-15 17:15 . 2008-08-14 11:09 2,145,280 --a--c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 17:15 . 2008-08-14 10:33 2,023,936 --a--c--- c:\windows\system32\dllcache\ntkrpamp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 00:14 --------- d-----w c:\documents and settings\Royus\Application Data\U3
2008-11-09 17:07 --------- d-----w c:\documents and settings\Royus\Application Data\uTorrent
2008-11-02 19:01 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-02 18:44 --------- d-----w c:\program files\Shareaza
2008-11-02 18:43 --------- d-----w c:\program files\DVDlabPro2
2008-11-02 18:43 --------- d-----w c:\program files\AviSynth 2.5
2008-11-02 18:43 --------- d-----w c:\program files\Avi2Dvd
2008-11-02 18:41 --------- d-----w c:\documents and settings\Kasiunia\Application Data\Skype
2008-11-01 14:17 99,856 ----a-w c:\windows\system32\drivers\cmdGuard.sys
2008-11-01 14:17 31,504 ----a-w c:\windows\system32\drivers\cmdhlp.sys
2008-10-31 17:03 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-10-12 09:54 --------- d-----w c:\program files\McAfee
2007-05-06 09:51 10,022 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 139320]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
"NetLimiter"="c:\program files\NetLimiter\NetLimiter.exe" [2004-03-31 823296]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2008-11-01 1797880]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-01-24 111952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
--a------ 2008-11-11 02:58 1234712 c:\progra~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Internet Security]
--a------ 2008-11-01 15:16 1797880 c:\program files\COMODO\Firewall\cfp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 c:\program files\QuickTime\QTTask.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-11 97928]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-11-01 99856]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-11-01 31504]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-11 231704]
.
- - - - ORPHANS REMOVED - - - -
SSODL-E404Helper-{cb3d5114-1cdf-4a66-aa76-c01d425a5b51} - e404d.dll
Notify-ddcywxu - ddcywxu.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.nl/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Start Page = hxxp://www.google.nl/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O17 -: HKLM\CCS\Interface\{93411B4B-2EEC-4612-96C1-25ABC107B13C}: NameServer = 208.67.220.220,208.67.222.222
O16 -: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} - hxxp://as.photoprintit.de/ips-opdata/74914090/activex/IPSUploader4.cab
c:\windows\Downloaded Program Files\IPSUploader4.inf
c:\windows\system32\unicows.dll
c:\windows\Downloaded Program Files\IPSUploader4.ocx
O16 -: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} - hxxp://as.photoprintit.de/ips-opdata/74914090/activex/IPSUploader.cab
c:\windows\Downloaded Program Files\IPSUploader.inf
c:\windows\system32\unicows.dll
c:\windows\Downloaded Program Files\IPSUploader.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-11 14:14:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: c:\windows\system32\lsass.exe
-> c:\program files\NetLimiter\nl_lsp.dll
-> c:\windows\system32\nl_msgc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\COMODO\Firewall\cmdagent.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-11-11 14:17:35 - machine was rebooted [Royus]
ComboFix-quarantined-files.txt 2008-11-11 13:17:24
Pre-Run: 21,679,517,696 bytes free
Post-Run: 21,730,938,880 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
221 --- E O F --- 2008-10-24 15:58:05