ComboFix 08-03-21.2 - Compaq_Owner 2008-03-22 0:05:00.1 - NTFSx86
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
.((((((((((((((((((((((((( Files Created from 2008-02-22 to 2008-03-22 )))))))))))))))))))))))))))))))
.
2008-03-21 22:49 . 2008-03-21 22:49 0 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2008-03-20 13:36 . 2008-03-20 13:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-03-20 11:43 . 2008-03-20 13:09 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\.housecall6.6
2008-03-07 23:02 . 2008-03-07 23:02 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-07 04:38 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-07 04:38 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-07 04:38 . 2007-07-30 20:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-06 16:47 . 2008-03-06 16:47 16 --a------ C:\WINDOWS\system32\coh.cache
2008-03-06 13:56 . 2008-03-06 13:56 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-06 13:55 . 2008-03-06 13:59 <DIR> d-------- C:\Program Files\Windows Live
2008-03-06 13:54 . 2008-03-06 13:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-06 12:02 . 2008-03-06 12:02 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-06 12:02 . 2008-03-06 12:05 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\AVG7
2008-03-06 12:01 . 2008-03-06 14:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-05 14:56 . 2008-03-05 15:00 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-20 15:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-20 15:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-20 15:29 --------- d-----w C:\Program Files\Norton AntiVirus
2008-03-15 02:29 --------- d-----w C:\Program Files\Java
2008-03-06 18:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 21:52 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-21 01:55 155648]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 11:01 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-21 07:15 180269]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 23:43 233472]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-29 04:34 2551808 C:\WINDOWS\ALCWZRD.EXE]
"VTTimer"="VTTimer.exe" [2005-03-08 04:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 20:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 23:13 98304]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 00:54 253952]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-10-21 07:36 98304]
"StandardKeyboard"="C:\WINDOWS\Wireless\Wireless.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2008-01-02 03:12]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-22 00:10:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-22 0:15:34
ComboFix-quarantined-files.txt 2008-03-22 04:15:29
.
2008-03-13 02:09:32 --- E O F ---
angeljam