ComboFix 10-07-07.02 - Deb 07/08/2010 13:50:57.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1112 [GMT -5:00]
Running from: c:\documents and settings\Deb\desktop\commy.exe
Command switches used :: /stepdel
AV: ACenter *On-access scanning disabled* (Outdated) {718043C0-05E9-453A-BB0D-E1C22F4673C5}
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ACenter *disabled* {718043C0-05E9-453A-BB0D-E1C22F4673C5}
.
The following files were disabled during the run:
c:\windows\system32\autosmgr.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Deb\Local Settings\Application Data\tbayiiygg
c:\documents and settings\Deb\Local Settings\Application Data\tbayiiygg\kdxlgnmtssd.exe
c:\documents and settings\Deb\Local Settings\Application Data\Windows Server
c:\docume~1\Deb\LOCALS~1\Temp\svchost.exe
c:\documents and settings\Deb\Local Settings\Application Data\tbayiiygg\kdxlgnmtssd.exe
c:\documents and settings\Deb\Local Settings\Application Data\Windows Server\flags.ini
c:\documents and settings\Deb\Local Settings\Application Data\Windows Server\uses32.dat
C:\Install.exe
.
((((((((((((((((((((((((( Files Created from 2010-06-08 to 2010-07-08 )))))))))))))))))))))))))))))))
.
2010-07-08 18:19 . 2010-07-08 18:19 -------- d-----w- C:\_OTL
2010-07-08 04:27 . 2010-07-08 04:27 -------- d-----w- C:\c69b421b5980e0432af95591102264
2010-07-08 04:27 . 2010-07-08 04:27 -------- d-----w- C:\c4769474cd3adb9ca3ad5a7cb4
2010-07-08 04:26 . 2010-07-08 04:26 -------- d-----w- C:\5a24e1a3accec1656d257c
2010-07-08 04:26 . 2010-07-08 04:26 -------- d-----w- C:\fe08ddc1ffb53bf1391b505c1426b1
2010-07-08 04:26 . 2010-07-08 04:26 -------- d-----w- C:\c667b6ae237014c9e1ba79b01a1f2e
2010-07-08 04:26 . 2010-07-08 04:26 -------- d-----w- C:\a13628c8b20bb9e458d9
2010-07-07 15:03 . 2010-07-07 15:04 48128 ----a-w- c:\windows\system32\autosmgr.dll.vir
2010-06-28 00:07 . 2010-06-28 00:07 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2010-06-28 00:06 . 2010-06-28 00:06 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Mozilla
2010-06-11 03:32 . 2010-06-11 03:32 -------- d-----w- c:\program files\Common Files\DirectX
2010-06-11 02:47 . 2010-06-11 02:47 -------- d-----w- C:\AeriaGames
2010-06-10 20:53 . 2010-07-08 18:25 -------- d-----w- c:\program files\Common Files\Akamai
2010-06-08 19:47 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-29 07:22 . 2007-03-24 05:17 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2010-06-05 00:07 . 2010-02-05 13:25 -------- d-----w- c:\documents and settings\Deb\Application Data\U3
2010-05-31 14:36 . 2010-05-31 14:36 503808 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-514d7267-n\msvcp71.dll
2010-05-31 14:36 . 2010-05-31 14:36 499712 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-514d7267-n\jmc.dll
2010-05-31 14:36 . 2010-05-31 14:36 348160 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-514d7267-n\msvcr71.dll
2010-05-31 14:36 . 2010-05-31 14:36 61440 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-141e7c6d-n\decora-sse.dll
2010-05-31 14:36 . 2010-05-31 14:36 12800 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-141e7c6d-n\decora-d3d.dll
2010-05-31 13:27 . 2010-05-31 13:27 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-29 17:27 . 2010-05-04 02:16 -------- d-----w- c:\documents and settings\Deb\Application Data\Apple Computer
2010-05-28 01:40 . 2005-08-11 22:27 37072 -c--a-w- c:\documents and settings\Deb\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-28 01:36 . 2010-04-15 02:17 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple
2010-05-28 00:32 . 2010-05-28 00:32 12 ----a-w- c:\documents and settings\Deb\Application Data\bpzmnq.dat
2010-05-25 23:24 . 2010-05-25 23:24 -------- d-----w- c:\program files\MSECache
2010-05-23 22:43 . 2010-05-23 22:43 503808 ----a-w- c:\documents and settings\Deb\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5bfdf7fb-n\msvcp71.dll
2010-05-23 22:43 . 2010-05-23 22:43 499712 ----a-w- c:\documents and settings\Deb\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5bfdf7fb-n\jmc.dll
2010-05-23 22:43 . 2010-05-23 22:43 348160 ----a-w- c:\documents and settings\Deb\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5bfdf7fb-n\msvcr71.dll
2010-05-23 22:43 . 2010-05-23 22:43 61440 ----a-w- c:\documents and settings\Deb\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5f515d5c-n\decora-sse.dll
2010-05-23 22:43 . 2010-05-23 22:43 12800 ----a-w- c:\documents and settings\Deb\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5f515d5c-n\decora-d3d.dll
2010-05-09 17:36 . 2010-05-09 17:36 503808 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bc03b93-n\msvcp71.dll
2010-05-09 17:36 . 2010-05-09 17:36 499712 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bc03b93-n\jmc.dll
2010-05-09 17:36 . 2010-05-09 17:36 348160 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4bc03b93-n\msvcr71.dll
2010-05-09 17:36 . 2010-05-09 17:36 61440 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-70c442b4-n\decora-sse.dll
2010-05-09 17:36 . 2010-05-09 17:36 12800 ----a-w- c:\documents and settings\Kids.DEBBI\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-70c442b4-n\decora-d3d.dll
2010-05-06 10:41 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 02:51 . 2010-05-04 02:51 30312 ---ha-w- c:\windows\system32\mlfcache.dat
2010-05-02 05:22 . 2004-08-04 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-28 20:45 . 2010-04-28 20:45 73000 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-04-20 05:30 . 2004-08-04 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 13:33 . 2010-05-04 02:02 41472 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-16 13:33 . 2010-05-04 02:02 3003680 ----a-w- c:\windows\system32\usbaaplrc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Deb\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-04-02 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"chk_mdc1303b1"="c:\program files\MDC1303B1\chk_mdc1303b1" [X]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-13 642856]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Sony\\EverQuest II\\LaunchPad.exe"=
"c:\\Program Files\\KODAK\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Sony\\EverQuest II\\EverQuest2CC.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Sony\\Station\\Launchpad\\LaunchPad.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Sony\\EverQuest II\\EverQuest2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/4/2004 7:00 AM 14336]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/15/2009 10:31 AM 108289]
S2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [11/13/2008 2:43 PM 204800]
S3 AntiyFirewall;AntiyFirewall;\??\c:\windows\system32\drivers\AntiyFW.sys --> c:\windows\system32\drivers\AntiyFW.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
S3 XDva337;XDva337;\??\c:\windows\system32\XDva337.sys --> c:\windows\system32\XDva337.sys [?]
S3 XDva349;XDva349;\??\c:\windows\system32\XDva349.sys --> c:\windows\system32\XDva349.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
2010-07-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
2010-07-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1085031214-725345543-1004Core.job
- c:\documents and settings\Deb\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-02 14:31]
2010-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1482476501-1085031214-725345543-1004UA.job
- c:\documents and settings\Deb\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-02 14:31]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.freeworldgroup.com/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5577
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} - hxxp://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB
FF - ProfilePath - c:\documents and settings\Deb\Application Data\Mozilla\Firefox\Profiles\hxa7tyr3.default\
FF - plugin: c:\documents and settings\Deb\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\Kids.DEBBI\Application Data\Sony Online Entertainment\npsoe.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU-Run-yifftlti - c:\documents and settings\Deb\Local Settings\Application Data\tbayiiygg\kdxlgnmtssd.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-Run-yifftlti - c:\documents and settings\Deb\Local Settings\Application Data\tbayiiygg\kdxlgnmtssd.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-08 13:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-07-08 13:58:17
ComboFix-quarantined-files.txt 2010-07-08 18:58
Pre-Run: 6,505,070,592 bytes free
Post-Run: 8,118,673,408 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /noexecute=optin
- - End Of File - - 4C2B94BD44ED78C397E3B1308F6AF9FF