ComboFix 07-12-21.4 - Dad 2007-12-22 7:03:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1050 [GMT -5:00]
Running from: C:\Documents and Settings\Dad\Local Settings\Temporary Internet Files\Content.IE5\QPV9AMJN\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\rhhaiofb.dat
C:\WINDOWS\system32\dsauthg.dll
C:\WINDOWS\Tasks.\At1.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_KDARJMBC
-------\LEGACY_RXIZZUXA
-------\LEGACY_ZBKRFHCQ
-------\kdarjmbc
-------\rxizzuxa
-------\zbkrfhcq
((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 )))))))))))))))))))))))))))))))
.
2007-12-20 22:22 . 2007-12-20 22:22 <DIR> d-------- C:\Documents and Settings\Dad\Lightroom
2007-12-20 09:44 . 2007-12-21 15:56 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-20 09:44 . 2007-12-20 09:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-20 09:44 . 2007-12-20 09:44 <DIR> d-------- C:\Documents and Settings\Dad\Application Data\SUPERAntiSpyware.com
2007-12-20 09:44 . 2007-12-20 09:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-20 09:30 . 2007-12-22 06:37 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2007-12-20 09:21 . 2007-12-20 09:22 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-12-20 09:18 . 2007-12-20 09:18 <DIR> d-------- C:\Program Files\Microsoft Easy Assist
2007-12-20 07:53 . 2007-12-20 07:53 <DIR> d-------- C:\Documents and Settings\Dad\Application Data\Lavasoft
2007-12-20 07:38 . 2007-12-20 07:39 <DIR> d-------- C:\Documents and Settings\Dad\Application Data\AdwareAlert
2007-12-19 19:31 . 2007-12-19 19:31 <DIR> d-------- C:\Documents and Settings\Dad\Application Data\iolo
2007-12-19 19:31 . 2007-12-19 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\iolo
2007-12-19 19:31 . 2007-12-19 19:31 406 --a------ C:\WINDOWS\system32\ioloBootDefrag.cfg
2007-12-19 19:12 . 2007-12-19 19:12 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2007-12-19 18:54 . 2007-12-19 18:57 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-12-19 18:37 . 2004-08-03 23:14 359,040 --a------ C:\WINDOWS\tcpip.sy_
2007-12-19 18:10 . 2003-04-11 05:14 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\MSN6
2007-12-19 18:10 . 2003-04-11 04:52 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterTrust
2007-12-19 16:25 . 2007-12-19 16:25 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AVG7
2007-12-19 13:29 . 2007-12-19 13:29 8,192 --ahs---- C:\WINDOWS\Thumbs.db
2007-12-19 06:41 . 2007-12-19 06:41 1,188,375 --a------ C:\WINDOWS\system32\libeay32.dll
2007-12-19 06:41 . 2007-12-19 06:41 741,632 --a------ C:\WINDOWS\system32\qtijcbnr.dat
2007-12-19 06:41 . 2007-12-19 06:41 246,545 --a------ C:\WINDOWS\system32\libssl32.dll
2007-12-19 06:41 . 2007-12-19 06:41 119,552 --a------ C:\WINDOWS\system32\plqiiten.dat
2007-12-19 06:41 . 2007-12-19 06:41 42,240 --a------ C:\WINDOWS\system32\ocuygllh.dat
2007-12-19 06:41 . 2007-12-19 06:41 36,096 --a------ C:\WINDOWS\system32\wowwmiqt.dat
2007-12-19 06:41 . 2007-12-19 06:41 35,072 --a------ C:\WINDOWS\system32\yxanswll.dat
2007-12-19 06:30 . 2007-12-19 06:30 28 --a------ C:\WINDOWS\DustKleen.INI
2007-12-19 06:20 . 2007-12-19 06:20 1,396 --a------ C:\WINDOWS\system32\wpa.bak
2007-12-18 23:34 . 2004-08-04 07:00 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winzm.ime
2007-12-18 23:34 . 2004-08-04 07:00 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winsp.ime
2007-12-18 23:34 . 2004-08-04 07:00 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winpy.ime
2007-12-18 23:34 . 2004-08-04 07:00 79,360 --a--c--- C:\WINDOWS\system32\dllcache\winar30.ime
2007-12-18 23:34 . 2004-08-04 07:00 69,120 --a--c--- C:\WINDOWS\system32\dllcache\wingb.ime
2007-12-18 23:34 . 2004-08-04 07:00 65,536 --a--c--- C:\WINDOWS\system32\dllcache\winime.ime
2007-12-18 23:34 . 2004-08-04 07:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2007-12-18 23:32 . 2004-08-04 07:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2007-12-18 23:31 . 2004-08-04 07:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2007-12-18 23:30 . 2004-05-13 00:39 876,653 --a--c--- C:\WINDOWS\system32\dllcache\fp4awel.dll
2007-12-18 23:29 . 2007-12-18 23:29 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2007-12-18 23:28 . 2007-12-18 23:28 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2007-12-18 23:28 . 2007-12-18 23:28 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2007-12-18 23:28 . 2007-12-18 23:28 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2007-12-18 23:28 . 2007-12-18 23:28 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2007-12-18 22:05 . 2004-08-03 23:04 134,912 --a------ C:\WINDOWS\ipnat.sy_
2007-12-16 11:31 . 2007-12-16 11:31 12,288 --ahs---- C:\WINDOWS\system32\Thumbs.db
2007-12-15 12:05 . 2007-12-15 12:05 119,552 --a------ C:\WINDOWS\system32\qhxosowh.dat
2007-12-15 11:59 . 2002-08-29 07:00 83,456 --a------ C:\WINDOWS\system32\dsauthg.dll.bak
2007-11-23 08:05 . 2007-11-24 10:11 156 --a------ C:\WINDOWS\Twunk001.MTX
2007-11-23 08:05 . 2007-11-24 10:11 4 --a------ C:\WINDOWS\Twain001.Mtx
2007-11-23 08:05 . 2007-11-23 08:05 0 --a------ C:\WINDOWS\Twunk002.MTX
2007-11-22 21:54 . 2004-08-04 02:10 48,128 --a------ C:\WINDOWS\system32\drivers\61883.sys
2007-11-22 21:54 . 2004-08-04 02:10 38,912 --a------ C:\WINDOWS\system32\drivers\avc.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-22 12:10 6,533,152 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-22 12:09 78,656 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-21 20:17 --------- d-----w C:\Documents and Settings\Dad\Application Data\LumaPix
2007-12-21 20:04 279,334 ----a-w C:\WINDOWS\FotoFusionV4 Uninstaller.exe
2007-12-21 20:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-21 13:00 --------- d-----w C:\Documents and Settings\Dad\Application Data\AVG7
2007-12-19 21:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-16 12:42 --------- d-----w C:\Documents and Settings\Other\Application Data\AVG7
2007-11-24 13:00 --------- d-----w C:\Documents and Settings\Dad\Application Data\Canon
2007-11-14 21:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 01:20 --------- d-----w C:\Documents and Settings\Dad\Application Data\Move Networks
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2007-12-19 19:12 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2007-12-19 19:12 262144]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 11:24]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 07:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2003-03-03 21:44 C:\WINDOWS\system32\nwiz.exe]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-02-28 23:00]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 13:24]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 13:11]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 12:29]
"CreateCD_Reminder"="C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe" [2003-04-17 19:51]
"AGRSMMSG"="AGRSMMSG.exe" [2004-07-22 12:38 C:\WINDOWS\AGRSMMSG.exe]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-17 23:01]
"VAIO Recovery"="C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 00:08]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-29 11:09]
"Omnipage"="C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 10:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 10:24]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-28 09:43]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-04-11 14:25]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 17:37]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe" [2007-08-30 05:32]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-29 11:09]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Remocon Driver.lnk - C:\Program Files\Sony\USBSircs\usbsircs.exe [2007-07-16 17:49:52]
TabUserW.exe.lnk - C:\WINDOWS\system32\WTablet\TabUserW.exe [2007-07-19 21:09:11]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R3 SONYWBMS;Sony Memory Stick controller(WB);C:\WINDOWS\system32\DRIVERS\SonyWBMS.SYS [2002-12-18 10:03]
.
Contents of the 'Scheduled Tasks' folder
"2007-12-22 08:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-19 18:38:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-11 21:19:07 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#deskjet5100#MY3923M2ZD7A.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe+/#Hewlett-Packard#deskjet5100#MY3923M2ZD7A
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-22 07:12:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-22 7:13:47 - machine was rebooted
.
2007-12-22 08:00:49 --- E O F ---