Combo Fix Log:
ComboFix 08-11-18.02 - Owner 2008-11-22 10:07:01.3 - NTFSx86
Running from: c:\documents and settings\Owner\Desktop\combofix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2008-10-22 to 2008-11-22 )))))))))))))))))))))))))))))))
.
2008-11-22 07:43 . 2008-11-22 07:43 439,012 --a------ C:\after-sr.bmp
2008-11-22 07:42 . 2008-11-22 07:42 674,864 --a------ C:\before-sr.bmp
2008-11-21 09:10 . 2008-11-21 09:10 <DIR> d-------- c:\program files\Sunbelt Software
2008-11-21 09:10 . 2008-10-31 07:09 270,888 -ra------ c:\windows\system32\drivers\SbFw.sys
2008-11-21 09:10 . 2008-06-21 04:54 65,576 --a------ c:\windows\system32\drivers\SbFwIm.sys
2008-11-21 09:06 . 2008-11-21 09:06 <DIR> d-------- c:\program files\Avira
2008-11-21 09:06 . 2008-11-21 09:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-21 06:48 . 2008-11-21 06:48 6,000,608 --a------ c:\temp\sunbelt-personal-firewall.exe
2008-11-21 06:45 . 2008-11-21 06:46 25,129,080 --a------ c:\temp\antivir_workstation_winu_en_h.exe
2008-11-20 08:58 . 2008-11-20 17:56 <DIR> d-------- c:\program files\EsetOnlineScanner
2008-11-19 17:56 . 2008-11-19 17:56 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-18 13:24 . 2008-11-18 13:24 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-18 13:24 . 2008-11-18 13:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-18 13:24 . 2008-10-22 16:27 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-18 13:24 . 2008-10-22 16:27 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-18 12:15 . 2004-01-26 08:10 <DIR> d-------- c:\documents and settings\Administrator\WINDOWS
2008-11-18 12:15 . 2004-01-27 05:21 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Symantec
2008-11-18 12:15 . 2004-01-26 07:28 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Sonic
2008-11-18 12:15 . 2004-01-26 08:49 <DIR> d-------- c:\documents and settings\Administrator\Application Data\SampleView
2008-11-18 12:15 . 2004-01-27 05:26 <DIR> d-------- c:\documents and settings\Administrator\Application Data\interMute
2008-11-18 12:15 . 2008-11-21 09:01 <DIR> d-------- c:\documents and settings\Administrator
2008-11-18 07:38 . 2008-11-20 08:55 <DIR> d-------- C:\HiJack
2008-11-18 07:08 . 2008-11-18 07:07 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-18 07:08 . 2008-11-18 07:07 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-17 15:53 . 2008-11-17 15:53 <DIR> d-------- C:\rsit
2008-11-17 15:53 . 2008-11-17 15:53 <DIR> d-------- c:\program files\trend micro
2008-11-17 14:45 . 2008-11-17 14:43 9,830 --a------ c:\temp\exefix.reg
2008-11-17 14:11 . 2008-11-17 14:08 2,373,088 --a------ c:\temp\mb.exe
2008-11-17 14:02 . 2008-08-20 12:46 6,467,096 --a------ c:\temp\SUPERAntiSpyware.exe
2008-11-11 14:52 . 2008-11-11 14:58 <DIR> d-------- c:\temp\Microsoft - Other hardware - HID Non-User Input Data Filter
2008-11-11 12:45 . 2008-11-11 12:56 278,927,592 --a------ c:\temp\WindowsXP-KB835935-SP2-ENU.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-21 14:01 --------- d-----w c:\documents and settings\Owner\Application Data\AVG7
2008-11-21 14:01 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2008-11-21 14:01 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
2008-11-19 16:10 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-18 18:26 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-18 18:26 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-18 12:07 --------- d-----w c:\program files\Java
2008-10-12 11:38 --------- d-----w c:\program files\Big Kahuna Reef
2008-10-04 17:55 --------- d-----w c:\documents and settings\Owner\Application Data\iWin
2008-10-04 17:52 --------- d-----w c:\program files\Best Buy Games
2008-10-04 17:29 --------- d-----w c:\documents and settings\Owner\Application Data\MysteryStudio
2008-10-01 13:41 --------- d-----w c:\documents and settings\Owner\Application Data\Ancient Quest of Saqqarah_msn
2002-08-15 16:54 3,198,976 ----a-w c:\program files\ViewSonicregistration.exe
2005-01-06 13:20 0 --sha-w c:\windows\SMINST\HPCD.sys
.
(((((((((((((((((((((((((((((
snapshot@2008-11-19_17.29.16.87 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-21 14:10:31 18,718 ----a-r c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\ARPPRODUCTICON.exe
+ 2008-11-21 14:10:31 18,718 ----a-r c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut1_E659E0EE10E649B7869660F38D0EB174.exe
+ 2008-11-21 14:10:31 57,344 ----a-r c:\windows\Installer\{82B1150E-9B37-49FC-83EB-D52197D900D0}\NewShortcut4_C665E66BE8EF49DBB30B81BB5E60462C.exe
+ 2008-04-14 09:42:34 380,416 -c--a-w c:\windows\system32\dllcache\rstrui.exe
+ 2008-04-14 04:06:54 73,472 -c--a-w c:\windows\system32\dllcache\sr.sys
+ 2008-04-14 09:42:08 67,584 -c--a-w c:\windows\system32\dllcache\srclient.dll
+ 2008-04-14 09:42:08 239,104 -c--a-w c:\windows\system32\dllcache\srrstr.dll
+ 2008-04-14 09:42:08 171,008 -c--a-w c:\windows\system32\dllcache\srsvc.dll
+ 2008-05-09 18:15:51 45,376 ----a-w c:\windows\system32\drivers\avgntdd.sys
+ 2008-01-21 23:11:28 22,336 ----a-w c:\windows\system32\drivers\avgntmgr.sys
+ 2008-11-21 14:09:02 75,072 ----a-w c:\windows\system32\drivers\avipbb.sys
+ 2008-06-21 09:54:54 66,600 ----a-r c:\windows\system32\drivers\sbhips.sys
+ 2007-03-01 15:34:22 28,352 ----a-w c:\windows\system32\drivers\ssmdrv.sys
+ 2007-07-27 19:49:02 196,683 ----a-w c:\windows\system32\lnod32apiA.dll
+ 2007-07-27 19:49:02 225,355 ----a-w c:\windows\system32\lnod32apiW.dll
+ 2005-12-06 00:25:22 139,264 ----a-w c:\windows\system32\lnod32umc.dll
+ 2005-12-05 17:37:10 106,496 ----a-w c:\windows\system32\lnod32upd.dll
+ 2008-02-11 14:39:26 253,952 ----a-w c:\windows\system32\OnlineScannerDLLA.dll
+ 2008-02-11 14:39:18 237,568 ----a-w c:\windows\system32\OnlineScannerDLLW.dll
+ 2008-02-08 18:53:46 110,592 ----a-w c:\windows\system32\OnlineScannerLang.dll
+ 2008-02-05 13:48:04 77,824 ----a-w c:\windows\system32\OnlineScannerUninstaller.exe
+ 2008-11-22 12:14:16 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_5b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-08-21 483328]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2003-11-03 221184]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-12 98304]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-12-15 188416]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-10-29 4620288]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-10-29 86016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-18 136600]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 c:\windows\LOGI_MWX.EXE]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 53248]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2004-10-16 151552]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\fuzz\EuShlExt.dll" [2002-09-30 86016]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk
backup=c:\windows\pss\Event Reminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=c:\windows\pss\ymetray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^spamsubtract.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\spamsubtract.lnk
backup=c:\windows\pss\spamsubtract.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^TA_Start.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\TA_Start.lnk
backup=c:\windows\pss\TA_Start.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Think-Adz.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Think-Adz.lnk
backup=c:\windows\pss\Think-Adz.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acme.PCHButton]
--a------ 2005-04-10 10:20 159744 c:\progra~1\COMPAQ~2\Presario\XPHNARP4EN\plugin\bin\PCHButton.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
--a------ 2008-02-22 09:33 72192 c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2005-02-25 04:33 127037 c:\windows\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 14:49 49152 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
--a------ 2003-08-21 06:23 49152 c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a------ 2003-09-05 23:35 40960 c:\program files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
--a------ 2003-02-11 22:02 61440 c:\hp\KBD\kbd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2006-01-09 17:04 36864 c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2005-05-09 15:32 53248 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-14 04:42 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ovt Wia]
--a------ 2008-01-28 08:53 36864 c:\windows\OV550EM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2003-09-05 23:16 57393 c:\program files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-06-16 16:35 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
--a------ 2003-12-18 02:31 118784 c:\windows\CREATOR\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sunkist2k]
--a------ 2003-10-29 10:17 135168 c:\program files\Multimedia Card Reader\shwicon2k.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-21 06:09 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2005-06-04 06:48 146432 c:\program files\Common Files\Real\Update_OB\evntsvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 11:01 110592 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2003-04-03 23:35 50176 c:\windows\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTMSG]
--a------ 2003-07-14 20:52 40960 c:\windows\ltmsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2004-10-29 15:50 921600 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 2004-10-22 11:53 53248 c:\windows\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"Fax"=3 (0x3)
"PhotoshopElementsDeviceConnect"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a53be00-6082-11dd-b5a5-000ea698e879}]
\Shell\AutoRun\command - h:\wd_windows_tools\Setup.exe
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\2b2rd7m2.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com
.
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\WmiApSrv]
"ImagePath"=""
.
Completion time: 2008-11-22 10:14:00
ComboFix-quarantined-files.txt 2008-11-22 15:13:51
ComboFix2.txt 2008-11-22 14:53:49
ComboFix3.txt 2008-11-19 22:29:41
Pre-Run: 87,287,607,296 bytes free
Post-Run: 87,271,198,720 bytes free
234
thanks,