Thank you, sneakyone!
ComboFix 10-08-06.01 - jeff 08/06/2010 14:15:09.1.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1781 [GMT -8:00]
Running from: c:\documents and settings\jeff\desktop\commy.exe
Command switches used :: /stepdel
AV: AVG Anti-Virus SBS Edition *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\jeff\Local Settings\Application Data\dxfniucap
c:\documents and settings\jeff\Local Settings\Application Data\dxfniucap\qqqifavtssd.exe
C:\Images
c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe
c:\documents and settings\jeff\Local Settings\Application Data\dxfniucap\qqqifavtssd.exe
c:\images\DirCfg.ini
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-07-06 to 2010-08-06 )))))))))))))))))))))))))))))))
.
2010-07-24 00:12 . 2010-07-24 00:12 388096 ----a-r- c:\documents and settings\jeff\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-23 23:44 . 2010-07-23 23:44 -------- d-----w- c:\program files\Trend Micro
2010-07-23 14:11 . 2010-07-23 14:11 -------- d-----w- c:\program files\iPod
2010-07-23 14:06 . 2010-07-23 14:06 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-22 19:02 . 2008-04-14 00:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-07-22 19:02 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-07-22 19:02 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\dllcache\usbscan.sys
2010-07-22 19:02 . 2001-08-18 06:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-07-21 14:55 . 2010-08-06 22:02 118784 ----a-w- c:\windows\system32\chg.exe
2010-07-16 19:47 . 2010-07-16 19:47 711168 ----a-w- c:\documents and settings\dprins\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv307hw-1007080-0-main.dll
2010-07-16 16:58 . 2010-07-19 16:11 -------- d-----w- c:\program files\Windows Live Safety Center
2010-07-15 23:00 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-15 20:52 . 2010-07-15 20:52 77568 ----a-w- c:\windows\system32\drivers\WUDFPF.SYS
2010-07-15 19:40 . 2010-07-15 20:58 -------- d-----w- c:\windows\system32\MpEngineStore
2010-07-10 16:11 . 2010-07-10 16:11 -------- d-----w- c:\documents and settings\drvictor\Local Settings\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-06 16:28 . 2008-12-12 15:34 -------- d-----w- c:\program files\Wisdom
2010-07-23 14:12 . 2010-06-18 14:37 -------- d-----w- c:\program files\iTunes
2010-07-23 14:11 . 2010-01-04 05:17 -------- d-----w- c:\program files\Common Files\Apple
2010-07-15 23:10 . 2008-11-17 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-06 18:50 . 2010-07-08 23:57 171904 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2010-07-05 07:46 . 2010-07-05 07:46 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-05 07:46 . 2010-07-05 07:46 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-06-30 19:31 . 2010-06-30 19:31 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2010-06-29 18:10 . 2010-06-29 18:10 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
2010-06-29 17:54 . 2010-06-29 17:54 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-06-23 06:50 . 2010-02-25 22:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-18 14:39 . 2010-01-04 15:39 -------- d-----w- c:\documents and settings\dprins\Application Data\Apple Computer
2010-06-18 14:35 . 2010-06-18 14:35 -------- d-----w- c:\program files\Bonjour
2010-06-18 14:31 . 2010-05-03 18:18 -------- d-----w- c:\program files\Safari
2010-06-18 14:30 . 2010-06-18 14:30 71992 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-14 14:31 . 2006-02-28 02:00 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-19 00:35 . 2010-05-19 00:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-19 00:35 . 2010-05-19 00:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-11 15:29 . 2010-05-11 15:29 666112 ----a-w- c:\documents and settings\dprins\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv306hw-1004220-0-main.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-11-26 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-11-26 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-11-26 137752]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2008-04-07 318488]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"Recguard"="c:\windows\Sminst\Recguard.exe" [2006-05-12 1138688]
"Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-07-10 872448]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-07-09 2048352]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
VPN Client.lnk - c:\windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2009-1-20 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 17:13 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-12-12 15:26 10536 ----a-w- c:\program files\Citrix\GoToAssist\508\g2awinlogon.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/19/2008 7:57 AM 12552]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/19/2008 7:57 AM 108552]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/19/2008 7:57 AM 335240]
S1 oxpar;%OXPAR.SVCDESC%;c:\windows\system32\drivers\oxpar.sys [1/24/2007 2:28 AM 80128]
S2 0098011228158574mcinstcleanup;McAfee Application Installer Cleanup (0098011228158574);c:\docume~1\ADMINI~1\LOCALS~1\Temp\009801~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\009801~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/9/2009 9:55 AM 297752]
S2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [11/17/2008 11:51 AM 576024]
S3 oxmf;OXPCI Bus enumerator;c:\windows\system32\drivers\oxmf.sys [1/24/2007 2:28 AM 21888]
S3 Oxmfuf;Filter driver for OX16PCI95x ports;c:\windows\system32\drivers\oxmfuf.sys [1/24/2007 2:28 AM 5888]
S3 oxser;OX16C95x Serial port driver;c:\windows\system32\drivers\oxser.sys [1/24/2007 2:28 AM 70784]
.
Contents of the 'Scheduled Tasks' folder
2010-07-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 19:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.drudgereport.com/
uInternet Settings,ProxyServer = http=127.0.0.1:6522
uInternet Settings,ProxyOverride =
FF - ProfilePath - c:\documents and settings\jeff\Application Data\Mozilla\Firefox\Profiles\wgvfa3ci.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.drudgereport.com/
FF - prefs.js: network.proxy.type - 0
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
HKCU-Run-dcvrrvmm - c:\documents and settings\jeff\Local Settings\Application Data\dxfniucap\qqqifavtssd.exe
HKLM-Run-dcvrrvmm - c:\documents and settings\jeff\Local Settings\Application Data\dxfniucap\qqqifavtssd.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\program files\Citrix\GoToAssist\508\G2AWinLogon.dll
.
Completion time: 2010-08-06 14:24:12
ComboFix-quarantined-files.txt 2010-08-06 22:24
Pre-Run: 44,928,225,280 bytes free
Post-Run: 46,055,038,976 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - A56D2C2F33D599CC6A1D1F8DCEA2FF1F