ComboFix 09-12-07.05 - luis castro 12/07/2009 19:13.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.382.166 [GMT -8:00]
Running from: c:\documents and settings\luis castro\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1351 [VPS 091104-1] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\luis castro\Local Settings\Application Data\rrgofl
c:\documents and settings\luis castro\Local Settings\Application Data\rrgofl\vvgwsysguard.exe
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000022_.tmp.dll
c:\windows\system32\_000023_.tmp.dll
c:\windows\system32\_000024_.tmp.dll
c:\windows\system32\_000025_.tmp.dll
D:\Autorun.inf
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-11-08 to 2009-12-08 )))))))))))))))))))))))))))))))
.
2009-12-04 02:03 . 2009-12-04 02:03 -------- d-----w- c:\documents and settings\luis castro\Application Data\Malwarebytes
2009-12-04 02:03 . 2009-12-04 00:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-04 02:03 . 2009-12-04 02:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-04 02:03 . 2009-12-04 02:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-04 02:03 . 2009-12-04 00:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-03 06:53 . 2009-12-03 06:53 -------- d-----w- c:\documents and settings\luis castro\Local Settings\Application Data\Identities
2009-12-03 02:30 . 2009-12-03 02:30 -------- d-----w- c:\program files\Trend Micro
2009-12-02 06:32 . 2009-12-02 06:32 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2009-12-02 06:30 . 2009-12-03 00:05 -------- d-----w- c:\documents and settings\Guest\Tracing
2009-11-22 18:47 . 2009-08-13 15:16 512000 ------w- c:\windows\system32\dllcache\jscript.dll
2009-11-21 18:45 . 2009-11-21 18:45 -------- d-----w- c:\windows\system32\scripting
2009-11-21 18:45 . 2009-11-21 18:45 -------- d-----w- c:\windows\l2schemas
2009-11-21 18:45 . 2009-11-21 18:45 -------- d-----w- c:\windows\system32\en
2009-11-21 18:45 . 2009-11-21 18:45 -------- d-----w- c:\windows\system32\bits
2009-11-21 18:34 . 2009-11-21 18:34 -------- d-----w- c:\windows\EHome
2009-11-15 07:15 . 2008-04-14 00:12 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-11-15 07:07 . 2009-11-15 07:07 -------- d-----w- c:\program files\Windows Media Connect 2
2009-11-15 07:02 . 2009-11-15 07:05 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-11-15 07:02 . 2009-11-15 07:02 -------- d-----w- c:\windows\system32\LogFiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-08 02:46 . 2006-02-28 04:51 -------- d-----w- c:\program files\Java
2009-12-08 02:42 . 2009-09-20 19:54 -------- d-----w- c:\program files\Ask.com
2009-12-08 02:41 . 2009-09-20 19:50 -------- d-----w- c:\documents and settings\luis castro\Application Data\uTorrent
2009-12-05 10:42 . 2009-09-18 13:26 -------- d-----w- c:\documents and settings\luis castro\Application Data\HP
2009-12-05 00:21 . 2004-08-04 00:59 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-11-30 03:21 . 2009-09-20 04:58 -------- d-----w- c:\documents and settings\luis castro\Application Data\Skype
2009-11-30 02:55 . 2006-02-28 05:42 -------- d-----w- c:\program files\Google
2009-11-30 00:06 . 2009-09-20 04:59 -------- d-----w- c:\documents and settings\luis castro\Application Data\skypePM
2009-11-28 22:15 . 2009-11-06 05:42 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-23 22:31 . 2009-09-30 23:42 -------- d-----w- c:\program files\Warcraft III
2009-11-21 18:48 . 2004-08-07 13:10 79395 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-15 23:04 . 2009-10-08 22:35 -------- d-----w- c:\program files\Empire Earth
2009-11-13 00:00 . 2006-02-28 05:36 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-07 21:18 . 2009-11-07 21:18 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-11-06 15:12 . 2009-11-04 06:09 -------- d-----w- c:\program files\BitZipper
2009-11-04 06:10 . 2009-11-04 06:10 -------- d-----w- c:\documents and settings\luis castro\Application Data\BitZipper
2009-11-01 18:23 . 2009-10-10 04:50 62728 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 02:54 . 2009-10-29 02:49 63 ----a-w- c:\documents and settings\luis castro\jagex_runescape_preferences2.dat
2009-10-29 02:50 . 2009-10-29 02:41 38 ----a-w- c:\documents and settings\luis castro\jagex_runescape_preferences.dat
2009-10-27 13:52 . 2009-10-27 13:52 -------- d-----w- c:\documents and settings\luis castro\Application Data\Sonic
2009-10-25 18:59 . 2009-09-21 05:57 -------- d-----w- c:\documents and settings\luis castro\Application Data\Apple Computer
2009-10-14 14:05 . 2009-10-14 14:05 49168 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-13 00:38 . 2009-10-08 22:31 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-10-11 16:45 . 2009-09-18 06:46 62728 ----a-w- c:\documents and settings\luis castro\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-11 00:49 . 2009-10-11 00:49 3310 ----a-r- c:\documents and settings\luis castro\Application Data\Microsoft\Installer\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}\_16496df1.exe
2009-10-11 00:49 . 2009-10-11 00:49 1078 ----a-r- c:\documents and settings\luis castro\Application Data\Microsoft\Installer\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}\_69525f90.exe
2009-10-11 00:49 . 2009-10-11 00:49 1078 ----a-r- c:\documents and settings\luis castro\Application Data\Microsoft\Installer\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}\_4ae13d6c.exe
2009-10-11 00:49 . 2009-10-11 00:49 1078 ----a-r- c:\documents and settings\luis castro\Application Data\Microsoft\Installer\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}\_2cd672ae.exe
2009-10-11 00:49 . 2009-10-11 00:49 1078 ----a-r- c:\documents and settings\luis castro\Application Data\Microsoft\Installer\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}\_294823.exe
2009-10-11 00:49 . 2009-10-11 00:49 1078 ----a-r- c:\documents and settings\luis castro\Application Data\Microsoft\Installer\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}\_18be6784.exe
2009-10-11 00:49 . 2009-10-11 00:49 -------- d-----w- c:\program files\Power Tab Software
2009-10-11 00:37 . 2009-10-11 00:37 -------- d-----w- c:\documents and settings\luis castro\Application Data\AdobeUM
2009-10-11 00:37 . 2009-10-11 00:37 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-10 04:55 . 2009-10-10 04:50 128 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\fusioncache.dat
2009-10-04 16:25 . 2009-10-04 16:25 1961720 ----a-w- c:\documents and settings\luis castro\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe2009-09-25 05:37 . 2004-08-04 08:00 667136 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-04 08:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-20 04:59 . 2009-09-20 04:59 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-09-19 18:21 . 2009-09-19 18:20 15446136 ----a-w- c:\documents and settings\All Users\Application Data\WildTangent\My HP Game Console\Downloads\Installers\SetupGamesClient.exe
2009-09-18 13:21 . 2009-09-18 13:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-18 06:48 . 2009-09-18 06:46 134 ----a-w- c:\documents and settings\luis castro\Local Settings\Application Data\fusioncache.dat
2009-09-11 14:18 . 2004-08-04 08:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 04:43 . 2009-09-09 04:43 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.0.70\SetupAdmin.exe
2006-08-01 06:59 . 2009-09-18 05:38 22 --sha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-05 198160]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^luis castro^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\luis castro\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-11-11 05:05 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2009-08-17 16:07 81000 ----a-w- c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CarboniteSetupLite]
2009-08-01 01:38 283792 ----a-w- c:\program files\Carbonite\CarbonitePreinstaller.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
2005-08-01 22:26 233534 ----a-w- c:\program files\HPQ\Default Settings\Cpqset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]
2005-12-07 18:56 409600 ----a-w- c:\program files\HPQ\Quick Launch Buttons\eabservr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-09-18 05:58 133104 ----atw- c:\documents and settings\luis castro\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-17 07:11 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-09 04:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 23:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2005-12-12 19:39 94208 ----a-w- c:\program files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 08:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecGuard]
2005-10-11 18:23 1187840 ----a-w- c:\windows\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2005-06-19 20:50 729178 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-10-05 06:20 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Empire Earth\\Empire Earth.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [9/18/2009 6:16 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/18/2009 6:16 AM 20560]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/22/2005 1:06 AM 231424]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/6/2009 7:47 PM 133104]
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptopuInternet Settings,ProxyOverride =
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\luis castro\Application Data\Mozilla\Firefox\Profiles\i271sulc.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\luis castro\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
AddRemove-HP Rhapsody - c:\progra~1\HPRHAP~1\Unwise32.exe
AddRemove-Microsoft Interactive Training - c:\windows\IsUninst.exe -fc:\windows\orun32.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-07 19:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-07 19:25
ComboFix-quarantined-files.txt 2009-12-08 03:24
Pre-Run: 19,846,860,800 bytes free
Post-Run: 21,488,783,360 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 7A2CDC1CAACD0512AD2C3AC4A1CE4E57