ComboFix 07-11-19.4C - SpenceJan 2007-11-30 20:37:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.186 [GMT -7:00]
Running from: C:\Documents and Settings\SpenceJan\Desktop\virus stuff\ComboFix.exe
* Created a new restore point
.
((Other Deletions )))))))))))))
.
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
.
Files Created from 2007-11-01 to 2007-12-01 )))))))))))
.
2007-11-30 12:54 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2007-11-30 12:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2007-11-30 12:43 <DIR> d-------- C:\Deckard
2007-11-28 21:14 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2007-11-28 20:24 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-11-28 20:24 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-11-28 20:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-11-28 20:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-11-28 20:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-11-27 21:25 <DIR> d-------- C:\Documents and Settings\SpenceJan\Application Data\Grisoft
2007-11-27 21:22 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-27 21:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-27 21:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-27 21:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-27 21:20 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-20 21:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2007-11-20 20:39 <DIR> d-------- C:\Program Files\Cool
2007-11-16 10:20 208,896 --a------ C:\WINDOWS\io43mvuiw4kj.exe
2007-11-11 10:37 236 --a------ C:\Documents and Settings\SpenceJan\jobq.dat
2007-11-11 10:36 <DIR> d-------- C:\Documents and Settings\SpenceJan\iArchives
2007-11-01 19:55 <DIR> d-------- C:\Program Files\Netflix
.
Find3M Report )))))))))))))
.
2007-12-01 02:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-01 02:06 --------- d-----w C:\Program Files\Radio Free Virgin
2007-11-30 02:17 3,500 ----a-w C:\WINDOWS\system32\tmp.reg
2007-11-30 02:12 --------- d-----w C:\Documents and Settings\SpenceJan\Application Data\Smilebox
2007-11-11 17:35 --------- d-----w C:\Program Files\Java
2007-11-02 22:32 --------- d-----w C:\Program Files\Microsoft Digital Image 10
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-21 23:38 --------- d-----w C:\Program Files\GospeLink
2007-10-07 16:21 --------- d--h--w C:\Documents and Settings\SpenceJan\Application Data\Move Networks
2007-09-12 18:52 53,248 ----a-w C:\WINDOWS\hg173.exe
2007-09-12 18:50 53,248 ----a-w C:\WINDOWS\df87173.exe
2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-09-06 06:22 289,144 ----a-w C:\WINDOWS\system32\VCCLSID.exe
.
(((((((( Reg Loading Points ))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5C2A9795-B130-4622-B036-BDCAD28602DC}]
2007-11-12 11:50 397312 --a------ C:\Program Files\Cool\Cool.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 19:44]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 04:40]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 17:42]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 18:12]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-06 23:01]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-05 23:05]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 03:06]
"Dell Photo AIO Printer 942"="C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe" [2004-08-31 07:18]
"DellMCM"="C:\Program Files\Dell Photo AIO Printer 942\memcard.exe" [2004-07-27 07:08]
"io43mvuiw4kj"="C:\WINDOWS\io43mvuiw4kj.exe" [2007-11-16 10:20]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= c:\windows\system32\ldcore.dll
R2 WUSB54Gv4SVC;WUSB54Gv4SVC;"C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe"
R3 WUSB54GPV4SRV;Linksys Home Wireless-G USB Adaptor Driver;C:\WINDOWS\system32\DRIVERS\rt2500usb.sys
S1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys
*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
"2007-11-30 20:40:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
***********
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-30 20:54:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**
.
Completion time: 2007-11-30 20:56:51 - machine was rebooted
.
--- E O F ---