ComboFix 08-04-18.3 - SuperGuard 2008-04-19 15:06:06.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.368 [GMT 1:00]
Running from: C:\Documents and Settings\SuperGuard\My Documents\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-19 to 2008-04-19 )))))))))))))))))))))))))))))))
.
2021-04-04 15:44 . 2004-08-04 01:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2021-04-04 15:44 . 2004-08-04 01:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2021-04-04 15:44 . 2004-08-03 23:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2021-04-04 15:44 . 2004-08-03 23:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2021-04-04 15:44 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2021-04-04 15:44 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-04-19 14:27 . 2008-04-19 14:27 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-04-19 14:17 . 2008-04-19 14:17 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-19 14:11 . 2001-08-17 13:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2008-04-19 14:10 . 2001-08-17 12:18 285,760 --a--c--- C:\WINDOWS\system32\dllcache\stlnata.sys
2008-04-19 14:09 . 2001-08-17 13:28 899,146 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-04-19 14:08 . 2001-08-17 14:05 351,616 --a--c--- C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-04-19 14:07 . 2003-03-31 13:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-04-19 14:06 . 2003-03-31 13:00 1,158,818 --a--c--- C:\WINDOWS\system32\dllcache\korwbrkr.lex
2008-04-19 14:05 . 2003-03-31 13:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-04-19 14:04 . 2001-08-17 13:28 634,134 --a--c--- C:\WINDOWS\system32\dllcache\el656ct5.sys
2008-04-19 14:03 . 2001-08-17 12:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
2008-04-19 14:02 . 2003-03-31 13:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-04-19 14:01 . 2001-08-17 13:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-04-19 14:00 . 2001-08-17 13:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-04-19 13:38 . 2008-04-19 13:38 2,726 --a------ C:\Documents and Settings\SuperGuard\RUN-191338399.reg
2008-04-19 13:33 . 2008-04-19 13:33 582 --a------ C:\Documents and Settings\SuperGuard\BE-19133334.reg
2008-04-19 13:31 . 2008-04-19 13:31 2,806 --a------ C:\Documents and Settings\SuperGuard\RUN-191331235.reg
2008-04-19 13:31 . 2008-04-19 13:31 840 --a------ C:\Documents and Settings\SuperGuard\BE-191331565.reg
2008-04-19 13:27 . 2008-04-19 13:27 802 --a------ C:\Documents and Settings\SuperGuard\RUN-191327494.reg
2008-04-19 13:27 . 2008-04-19 13:27 149 --a------ C:\Documents and Settings\SuperGuard\BHO-19132738.reg
2008-04-19 13:26 . 2008-04-19 13:26 5,938 --a------ C:\Documents and Settings\SuperGuard\TB-191326522.reg
2008-04-19 13:26 . 2008-04-19 13:26 149 --a------ C:\Documents and Settings\SuperGuard\BHO-191326565.reg
2008-04-19 12:37 . 2004-08-03 22:41 1,309,184 --a------ C:\WINDOWS\system32\drivers\mtlstrm.sys
2008-04-19 12:32 . 2008-04-19 12:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-04-17 07:01 . 2008-04-13 12:56 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-04-13 12:55 . 2008-04-18 07:12 <DIR> d-------- C:\Documents and Settings\SuperGuard\.housecall6.6
2008-04-13 02:21 . 2008-04-13 02:37 7,749,227 --a------ C:\WINDOWS\system32\STDLVNFH
2008-04-13 01:33 . 2008-04-19 12:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-13 01:11 . 2008-04-19 12:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-13 00:54 . 2008-03-01 14:06 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-13 00:54 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-13 00:54 . 2007-07-01 04:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-13 00:54 . 2008-03-01 14:06 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-13 00:54 . 2008-03-01 14:06 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-13 00:54 . 2008-03-01 14:06 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-13 00:54 . 2008-03-01 14:06 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-13 00:54 . 2008-03-01 14:06 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-13 00:54 . 2008-02-22 11:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-13 00:46 . 2008-04-14 18:12 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-12 23:11 . 2008-04-19 14:58 <DIR> d-------- C:\SDFix
2008-04-12 22:51 . 2008-04-12 22:53 <DIR> d-------- C:\Program Files\CCleaner
2008-04-12 22:44 . 2008-04-19 13:08 <DIR> d-------- C:\Documents and Settings\SuperGuard\Application Data\wsInspector
2008-04-12 22:42 . 2008-04-12 22:43 <DIR> d-------- C:\Program Files\Startup Inspector for Windows
2008-04-12 22:15 . 2008-04-12 22:15 <DIR> d-------- C:\WINDOWS\Sun
2008-04-09 22:48 . 2008-04-09 22:48 127 --a------ C:\WINDOWS\system32\MRT.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 12:50 --------- d-----w C:\Program Files\Creative
2008-04-19 12:23 --------- d-----w C:\Program Files\Common Files\Motive
2008-04-19 11:55 --------- d-----w C:\Program Files\Maxis
2008-04-19 11:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-13 18:54 --------- d-----w C:\Program Files\BigFix
2008-04-13 15:39 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-04-13 01:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW
2008-04-12 23:00 --------- d-----w C:\Program Files\iWin.com
2008-04-12 22:42 --------- d-----w C:\Program Files\Yahoo!
2008-04-12 21:50 --------- d-----w C:\Documents and Settings\SuperGuard\Application Data\SpinTop
2008-04-12 21:09 --------- d-----w C:\Program Files\Java
2008-04-12 20:53 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-12 20:50 --------- d-----w C:\Program Files\Google
2008-04-01 11:48 --------- d-----w C:\Documents and Settings\SuperGuard\Application Data\LimeWire
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-04 19:43 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-04 19:28 --------- d-----w C:\Documents and Settings\SuperGuard\Application Data\iWin
2008-03-04 19:26 --------- d-----w C:\Documents and Settings\SuperGuard\Application Data\iWinArcade
2008-03-04 19:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\iWin Games
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-29 17:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="zHotkey.exe" [2003-06-03 11:01 496640 C:\WINDOWS\zHotkey.exe]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 18:44 65536]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2004-01-09 16:01 868352]
"RoxioAudioCentral"="C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-07-15 12:38 319488]
"SunKistEM"="C:\Program Files\eMachines Bay Reader\shwiconem.exe" [2004-03-11 15:18 135168]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 18:37 79224]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36 256576]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"AVFX Engine"="C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-06-09 02:11 24576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MS Sound Config 16bit"="sndcfg16.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 01:56 15360]
"MS Sound Config 16bit"="sndcfg16.exe" []
"Microsoft Services"="lsrv.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WG111v2 Smart Wizard Wireless Setting.lnk - C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2006-02-18 13:33:14 745472]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Documents and Settings\\J. O'Brien\\Application Data\\NAMCO BANDAI Games\\Warhammer Mark of Chaos\\Warhammer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
S1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 18:31]
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 18:35]
S2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [2005-04-01 11:42]
S3 bfastfao;bfastfao;C:\DOCUME~1\JORDAN~1\LOCALS~1\Temp\bfastfao.sys []
S3 EL910;3Com 3CSOHO100B-TX PCI;C:\WINDOWS\system32\DRIVERS\EL910N51.sys [2003-07-11 17:54]
S3 gbalink;GBA Link Driver (gbalink.sys);C:\WINDOWS\system32\Drivers\gbalink.sys [2001-03-08 11:15]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2005-04-21 14:33]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2002-10-02 09:57]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24e1c4c2-82ef-11d8-a365-806d6172696f}]
\shell\PlayWithPowerDVD\Command - "C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" "%L"
.
Contents of the 'Scheduled Tasks' folder
"2008-04-15 17:07:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-04-19 15:15:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-04-19 15:18:11
ComboFix-quarantined-files.txt 2008-04-19 14:17:16
Pre-Run: 58,496,053,248 bytes free
Post-Run: 58,997,669,888 bytes free
150 --- E O F --- 2008-04-14 17:12:53