ComboFix 09-02-25.02 - Robert 2009-02-26 8:28:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.603 [GMT -6:00]
Running from: c:\documents and settings\Robert\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Robert\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\Robert\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\setup.exe
c:\windows\system\oeminfo.ini
c:\windows\system32\bknuvhxj.ini
c:\windows\system32\fxqleaxb.ini
c:\windows\system32\koefsjrv.ini
c:\windows\system32\octvshbq.ini
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Legacy_new_drv
-------\Legacy_SYSREST.SYS
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2009-01-26 to 2009-02-26 )))))))))))))))))))))))))))))))
.
2009-02-25 17:13 . 2009-02-25 17:13 <DIR> d-------- c:\program files\Alwil Software
2009-02-23 22:13 . 2009-02-23 22:13 552 --a------ c:\windows\system32\d3d8caps.dat
2009-02-23 21:44 . 2009-02-23 21:44 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-23 21:44 . 2009-02-23 21:44 <DIR> d-------- c:\documents and settings\Robert\Application Data\Malwarebytes
2009-02-23 21:44 . 2009-02-23 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-23 21:44 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-23 21:44 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-19 18:33 . 2009-02-20 08:53 <DIR> d-------- c:\documents and settings\Robert\Shared
2009-02-19 18:33 . 2009-02-24 07:46 <DIR> d-------- c:\documents and settings\Robert\Incomplete
2009-02-19 18:32 . 2009-02-19 19:41 <DIR> d-------- c:\documents and settings\Robert\Application Data\LimeWire Music
2009-02-15 09:46 . 2009-02-15 09:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\GameHouse
2009-02-15 09:45 . 2009-02-15 09:45 <DIR> d-------- c:\program files\TextTwist 2
2009-02-15 09:45 . 2009-02-15 09:45 <DIR> d-------- c:\documents and settings\Robert\Application Data\SpinTop
2009-02-15 09:45 . 2009-02-15 18:29 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-01-28 17:09 . 2009-02-17 18:02 0 --a------ c:\windows\system32\drivers\e164f576.sys
2009-01-28 17:08 . 2009-01-28 17:08 2 --a------ C:\1155048582
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 03:26 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-21 04:00 --------- d-----w c:\program files\Spybot
2009-02-21 03:54 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-21 03:21 --------- d-----w c:\program files\Trend Micro
2009-02-21 03:17 --------- d-----w c:\program files\LimeWire
2009-02-20 00:30 --------- d-----w c:\documents and settings\Robert\Application Data\LimeWire
2008-12-13 02:08 16,384 ----a-w c:\windows\DCEBoot.exe
2008-07-02 02:51 0 ----a-w c:\documents and settings\Robert\jagex_runescape_preferences.dat
2001-05-21 15:54 3,932 ------w c:\documents and settings\Robert\Application Data\CMLayout.dat
2008-09-08 13:41 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090120080908\index.dat
2008-09-15 23:02 49,152 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090820080915\index.dat
2008-09-22 13:54 49,152 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091520080922\index.dat
2008-09-23 01:20 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092220080923\index.dat
2008-09-24 23:25 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092420080925\index.dat
2008-09-26 04:30 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092520080926\index.dat
2008-09-27 01:49 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092620080927\index.dat
2008-09-27 21:34 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092720080928\index.dat
.
------- Sigcheck -------
2008-04-13 18:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe
2004-08-10 09:00 17408 83bf18aab3e169d2a78dd2672d1525bb c:\windows\system32\svchost.exe
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2004-10-16 00:18 506368 3fafcdd4cc0af9ab3ee695cd8e901b89 c:\windows\system32\winlogon.exe
2004-08-10 09:00 1034752 619bdce4bcd0331da1d982e07e5a9414 c:\windows\explorer.exe
2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2008-04-13 18:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2004-08-10 09:00 110592 f34dcda03b10b32c1402110e196d7097 c:\windows\system32\services.exe
2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2004-08-10 09:00 14848 b54c37eadae349b737240915774b9666 c:\windows\system32\lsass.exe
2005-06-10 18:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2008-04-13 18:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
2004-08-10 09:00 58880 58d43b5a04410e765fdf1753b0b6038e c:\windows\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-06-02 267048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-06-20 17:11 73728 c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-09-01 226304]
S1 5738137;5738137;c:\windows\system32\drivers\5738137.sys [2008-09-09 0]
S1 e164f576;e164f576;c:\windows\system32\drivers\e164f576.sys [2009-01-28 0]
S3 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\Robert\Application Data\Mozilla\Firefox\Profiles\n457tnyv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - P2P_Energy Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-26 08:32:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EvtEng]
"ImagePath"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1004)
c:\windows\system32\VESWinlogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-02-26 8:38:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-26 14:38:16
Pre-Run: 51,395,051,520 bytes free
Post-Run: 51,402,395,648 bytes free
158 --- E O F --- 2009-02-25 20:02:55
ComboFix 09-02-26.02 - Robert 2009-02-27 10:49:38.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.599 [GMT -6:00]
Running from: c:\documents and settings\Robert\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system\oeminfo.ini
.
---- Previous Run -------
.
C:\1155048582
c:\windows\system32\drivers\5738137.sys
c:\windows\system32\drivers\e164f576.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_5738137
-------\Service_e164f576
((((((((((((((((((((((((( Files Created from 2009-01-27 to 2009-02-27 )))))))))))))))))))))))))))))))
.
2009-02-27 10:45 . 2009-02-27 10:45 <DIR> d-------- c:\windows\LastGood
2009-02-27 03:37 . 2004-08-10 09:00 58,880 --a------ c:\windows\system32\spoolsv.exe
2009-02-27 03:36 . 2004-08-10 09:00 14,848 --a------ c:\windows\system32\lsass.exe
2009-02-27 03:35 . 2004-08-10 09:00 110,592 --a------ c:\windows\system32\services.exe
2009-02-27 03:34 . 2004-08-10 09:00 1,034,752 --a------ c:\windows\explorer.exe
2009-02-27 03:32 . 2004-08-10 09:00 17,408 --a------ c:\windows\system32\svchost.exe
2009-02-27 03:25 . 2004-10-16 00:18 506,368 --a------ c:\windows\system32\winlogon.exe
2009-02-26 12:00 . 2009-02-26 13:18 <DIR> d--h----- C:\$AVG8.VAULT$
2009-02-26 08:48 . 2009-02-26 08:48 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-02-26 08:47 . 2009-02-27 10:42 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-02-26 08:47 . 2009-02-26 08:47 <DIR> d-------- c:\program files\AVG
2009-02-26 08:47 . 2009-02-27 09:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-02-26 08:47 . 2009-02-26 08:47 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-02-25 17:13 . 2009-02-25 17:13 <DIR> d-------- c:\program files\Alwil Software
2009-02-23 22:13 . 2009-02-23 22:13 552 --a------ c:\windows\system32\d3d8caps.dat
2009-02-23 21:44 . 2009-02-23 21:44 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-23 21:44 . 2009-02-23 21:44 <DIR> d-------- c:\documents and settings\Robert\Application Data\Malwarebytes
2009-02-23 21:44 . 2009-02-23 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-23 21:44 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-23 21:44 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-19 18:33 . 2009-02-26 12:13 <DIR> d-------- c:\documents and settings\Robert\Shared
2009-02-19 18:33 . 2009-02-24 07:46 <DIR> d-------- c:\documents and settings\Robert\Incomplete
2009-02-19 18:32 . 2009-02-19 19:41 <DIR> d-------- c:\documents and settings\Robert\Application Data\LimeWire Music
2009-02-15 09:46 . 2009-02-15 09:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\GameHouse
2009-02-15 09:45 . 2009-02-15 09:45 <DIR> d-------- c:\program files\TextTwist 2
2009-02-15 09:45 . 2009-02-15 09:45 <DIR> d-------- c:\documents and settings\Robert\Application Data\SpinTop
2009-02-15 09:45 . 2009-02-15 18:29 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 03:26 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-21 04:00 --------- d-----w c:\program files\Spybot
2009-02-21 03:54 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-21 03:21 --------- d-----w c:\program files\Trend Micro
2009-02-21 03:17 --------- d-----w c:\program files\LimeWire
2009-02-20 00:30 --------- d-----w c:\documents and settings\Robert\Application Data\LimeWire
2008-12-13 02:08 16,384 ----a-w c:\windows\DCEBoot.exe
2008-07-02 02:51 0 ----a-w c:\documents and settings\Robert\jagex_runescape_preferences.dat
2001-05-21 15:54 3,932 ------w c:\documents and settings\Robert\Application Data\CMLayout.dat
2008-09-08 13:41 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090120080908\index.dat
2008-09-15 23:02 49,152 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090820080915\index.dat
2008-09-22 13:54 49,152 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091520080922\index.dat
2008-09-23 01:20 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092220080923\index.dat
2008-09-24 23:25 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092420080925\index.dat
2008-09-26 04:30 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092520080926\index.dat
2008-09-27 01:49 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092620080927\index.dat
2008-09-27 21:34 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092720080928\index.dat
.
------- Sigcheck -------
2008-04-13 18:12 14336 27c6d03bcdb8cfeb96b716f3d8be3e18 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe
2004-08-10 09:00 17408 83bf18aab3e169d2a78dd2672d1525bb c:\windows\system32\svchost.exe
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2004-10-16 00:18 506368 3fafcdd4cc0af9ab3ee695cd8e901b89 c:\windows\system32\winlogon.exe
2004-08-10 09:00 1034752 619bdce4bcd0331da1d982e07e5a9414 c:\windows\explorer.exe
2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2008-04-13 18:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2004-08-10 09:00 110592 f34dcda03b10b32c1402110e196d7097 c:\windows\system32\services.exe
2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2004-08-10 09:00 14848 b54c37eadae349b737240915774b9666 c:\windows\system32\lsass.exe
2005-06-10 18:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2008-04-13 18:12 57856 d8e14a61acc1d4a6cd0d38aebac7fa3b c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\spoolsv.exe
2004-08-10 09:00 58880 58d43b5a04410e765fdf1753b0b6038e c:\windows\system32\spoolsv.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-02-26_ 8.36.54.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-26 14:47:58 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-06-02 267048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-26 1601304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-26 08:48 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-06-20 17:11 73728 c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-26 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-26 298264]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-09-01 226304]
S3 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB --> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\Robert\Application Data\Mozilla\Firefox\Profiles\n457tnyv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - P2P_Energy Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-27 10:52:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EvtEng]
"ImagePath"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1020)
c:\windows\system32\VESWinlogon.dll
.
Completion time: 2009-02-27 10:54:25
ComboFix-quarantined-files.txt 2009-02-27 16:53:47
ComboFix2.txt 2009-02-26 14:38:38
Pre-Run: 51,013,218,304 bytes free
Post-Run: 50,998,452,224 bytes free
165 --- E O F --- 2009-02-27 16:46:13
O4 - HKUS\S-1-5-20\..\Run: [InetChk] C:\DOCUME~1\NETWOR~1\LOCAL
O4 - HKUS\S-1-5-18\..\Run: [InetChk] C:\WINDOWS\TEMP\ms12353451
O4 - HKUS\.DEFAULT\..\Run: [InetChk] C:\WINDOWS\TEMP\ms12353451
O20 - AppInit_DLLs: qbbmzu.dll nxtmft.dll vrixxu.dll qlythg.dll hinzvc.dll awcclt.dll mrzyoz.dll mzxmtv.dll fsjtnt.dll mcrxqg.dll cnnhda.dll kwhuji.dll slpwmq.dll pqfidp.dll nlnpaj.dll fjbiop.dll vqrzaa.dll yprmcx.dll dqhgqe.dll vmkkdw.dll
Hi,
Fix the above entries in Hijackthis and run either one of the tools below and show us the log please.
Download Malwarebytes' Anti-Malware to your desktop, check for the tool's Updates before running a scan.
http://www.malwarebytes.or
If you can't access the above link then use this link and rename the file before saving to your desktop.
http://www.download.com/Ma
Please download ComboFix by sUBs:
http://download.bleepingco
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.