ComboFix 08-04-22.5 - monica griffin 2008-04-23 18:35:53.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.151 [GMT -7:00]
Running from: C:\Documents and Settings\monica griffin\Desktop\ComboFix.exe
* Created a new restore point[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\stlbdist.XML
.
((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.
2008-04-20 02:14 . 2008-04-20 02:14 <DIR> d-------- C:\Documents and Settings\monica griffin\Application Data\Malwarebytes
2008-04-20 02:13 . 2008-04-20 02:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-18 07:15 . 2008-04-18 07:15 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-17 17:28 . 2008-04-17 17:28 <DIR> d-------- C:\Documents and Settings\monica griffin\Application Data\TrojanHunter
2008-04-17 13:38 . 2008-04-17 17:29 <DIR> d-------- C:\Program Files\TrojanHunter 5.0
2008-04-17 07:42 . 2008-04-23 18:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-04-17 07:37 . 2008-04-17 07:37 <DIR> d-------- C:\Program Files\PayPal
2008-04-05 15:52 . 2008-04-05 15:52 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-05 15:52 . 2008-04-05 15:52 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-23 21:05 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-04-23 18:43 --------- d-----w C:\Documents and Settings\monica griffin\Application Data\AVG7
2008-04-17 20:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-17 14:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-30 08:00 --------- d-----w C:\Program Files\Real
2008-03-23 22:32 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-02-24 20:58 --------- d-----w C:\Program Files\HP Photosmart 11
2008-02-24 17:28 --------- d-----w C:\Program Files\Kodak
2008-02-24 17:28 --------- d-----w C:\Program Files\Common Files\KODAK
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2007-07-29 19:36 2,492 ----a-w C:\Documents and Settings\monica griffin\Application Data\ViewerApp.dat
2006-12-11 19:05 1,410,680 ----a-w C:\Program Files\install_flash_player.exe
2006-10-28 20:59 5,900,416 ----a-w C:\Program Files\Firefox Setup 2.0.exe
2006-10-28 20:58 6,335,024 ----a-w C:\Program Files\Thunderbird Setup 1.5.0.7.exe
2006-10-27 06:12 23,608,632 ----a-w C:\Program Files\wmp11-windowsxp-x86-enu.exe
2006-10-24 04:13 45,828 ----a-w C:\Program Files\cache_500_1__mb4_d5b42beb350e7765c359d9ee4aba285f_addpic3.img
2006-10-21 05:35 443,432 ----a-w C:\Program Files\msgr8us(2).exe
2006-10-06 06:35 443,432 ----a-w C:\Program Files\msgr8us.exe
2006-10-03 23:12 0 ----a-w C:\Program Files\file.bin
2005-12-04 18:01 15,561,744 ----a-w C:\Program Files\avg71free_361a651.exe
2005-12-04 01:40 20,480 -c--a-w C:\Program Files\cdrun.exe
2003-02-02 20:49 4,650,695 ----a-w C:\Documents and Settings\My Shared Folder\kmd202_en.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 13:00 28739]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22 4670968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-04 00:56 380416 C:\WINDOWS\system32\irprops.cpl]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-09-09 01:05 114688]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 01:01 155648]
"CamMonitor"="C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 00:23 90112]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 10:42 69632]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-11-08 10:37 98304]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-14 08:18 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe" [2000-06-07 12:32 36864]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-22 18:31 185896]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 12:07 188416]
"NielsenOnline"="C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2007-11-16 19:55 45056]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 12:07 348160]
"HPHUPD04"="C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec Network Driver Update Warning"="C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE" [ ]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [ ]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-28 15:04 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-02-23 14:11 9216 C:\WINDOWS\system32\avgwlntf.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=C:\WINDOWS\pss\Picture Package Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=C:\WINDOWS\pss\Picture Package VCD Maker.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Viewbar]
--a------ 2007-11-01 13:05 132608 C:\Program Files\AGLOCO Viewbar\Viewbar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-03-27 15:22 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LexBceS"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
R1 nnrnstdi;nnrnstdi;C:\WINDOWS\system32\drivers\nnrnstdi.sys [2007-06-08 10:47]
R3 epstw2k;SCM Parallel Port SCSI Driver;C:\WINDOWS\system32\DRIVERS\epstw2k.sys [2001-08-17 13:50]
R3 km_filter;km_filter;C:\WINDOWS\system32\drivers\km_filter.sys [2007-06-08 10:47]
R3 scsiscan;SCSI Scanner Driver;C:\WINDOWS\system32\DRIVERS\scsiscan.sys [2001-08-17 13:53]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-14 07:00:00 C:\WINDOWS\Tasks\Automatic Full Backup.job"
- C:\Program Files\Stomp\Backup MyPC\System\bestart.exe
"2008-04-24 01:18:20 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
"2008-04-24 01:18:22 C:\WINDOWS\Tasks\HP Usg Login.job"
- C:\Program Files\hp photosmart 11\printer\Hphusg04.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-23 18:41:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-23 18:51:06
ComboFix-quarantined-files.txt 2008-04-24 01:50:26
Pre-Run: 11,770,540,032 bytes free
Post-Run: 11,788,853,248 bytes free
131 --- E O F --- 2008-04-11 00:19:11