ComboFix 11-05-11.04 - mmartin 05/12/2011 16:28:47.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1478 [GMT -5:00]
Running from: c:\documents and settings\mmartin\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\iM28601JgCdN28601
c:\documents and settings\All Users\Application Data\iM28601JgCdN28601\iM28601JgCdN28601
c:\documents and settings\All Users\Application Data\iM28601JgCdN28601\iM28601JgCdN28601.exe
c:\documents and settings\mmartin\Local Settings\Application Data\{965D8DA0-38B9-4456-B9D5-FB0C9EF3FD36}
c:\documents and settings\mmartin\Local Settings\Application Data\{965D8DA0-38B9-4456-B9D5-FB0C9EF3FD36}\chrome.manifest
c:\documents and settings\mmartin\Local Settings\Application Data\{965D8DA0-38B9-4456-B9D5-FB0C9EF3FD36}\chrome\content\_cfg.js
c:\documents and settings\mmartin\Local Settings\Application Data\{965D8DA0-38B9-4456-B9D5-FB0C9EF3FD36}\chrome\content\overlay.xul
c:\documents and settings\mmartin\Local Settings\Application Data\{965D8DA0-38B9-4456-B9D5-FB0C9EF3FD36}\install.rdf
c:\windows\system32\bszip.dll
c:\windows\system32\ReadMe.txt
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_INPUT_MANAGER
-------\Legacy_MOUSEDRIVER
-------\Legacy_PLUG_MANAGER
.
.
((((((((((((((((((((((((( Files Created from 2011-04-12 to 2011-05-12 )))))))))))))))))))))))))))))))
.
.
2011-05-12 19:00 . 2011-05-12 19:00 -------- d-----w- c:\documents and settings\mmartin\Application Data\Sammsoft
2011-05-12 18:59 . 2011-05-12 18:59 -------- d-----w- c:\program files\ARO 2011
2011-05-12 03:43 . 2011-05-12 03:43 -------- d-----w- c:\documents and settings\mmartin\Application Data\Malwarebytes
2011-05-12 03:35 . 2011-05-12 03:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-05-12 03:35 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-12 03:35 . 2011-05-12 03:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-12 03:35 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-11 20:02 . 2011-05-11 20:02 0 ----a-w- c:\windows\Pcinidedu.bin
2011-05-11 20:00 . 2011-05-11 20:00 131072 --sha-r- c:\windows\system32\tapiz.dll
2011-04-27 03:49 . 2011-04-27 03:49 -------- d-----w- c:\documents and settings\mmartin\Application Data\SmartFTP
2011-04-27 03:49 . 2011-04-27 03:49 -------- d-----w- c:\program files\SmartFTP Client
2011-04-27 03:47 . 2011-04-27 03:47 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files
2011-04-27 02:12 . 2011-04-27 02:12 -------- d-----w- c:\program files\HashTab Shell Extension
2011-04-22 19:04 . 2011-04-23 03:24 -------- d-----w- c:\documents and settings\mmartin\Application Data\Download Manager
2011-04-21 14:41 . 2011-04-21 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2011-04-15 16:30 . 2011-04-20 15:48 -------- d-----w- c:\program files\ATI
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-20 05:03 . 2011-02-20 05:03 4422992 ----a-w- c:\windows\mfc100u.dll
2011-02-20 04:03 . 2011-02-20 04:03 64336 ----a-w- c:\windows\system32\mfc100fra.dll
2011-02-20 04:03 . 2011-02-20 04:03 64336 ----a-w- c:\windows\system32\mfc100deu.dll
2011-02-20 04:03 . 2011-02-20 04:03 63824 ----a-w- c:\windows\system32\mfc100esn.dll
2011-02-20 04:03 . 2011-02-20 04:03 62288 ----a-w- c:\windows\system32\mfc100ita.dll
2011-02-20 04:03 . 2011-02-20 04:03 60752 ----a-w- c:\windows\system32\mfc100rus.dll
2011-02-20 04:03 . 2011-02-20 04:03 55120 ----a-w- c:\windows\system32\mfc100enu.dll
2011-02-20 04:03 . 2011-02-20 04:03 43856 ----a-w- c:\windows\system32\mfc100jpn.dll
2011-02-20 04:03 . 2011-02-20 04:03 43344 ----a-w- c:\windows\system32\mfc100kor.dll
2011-02-20 04:03 . 2011-02-20 04:03 421200 ----a-w- c:\windows\system32\msvcp100.dll
2011-02-20 04:03 . 2011-02-20 04:03 36176 ----a-w- c:\windows\system32\mfc100cht.dll
2011-02-20 04:03 . 2011-02-20 04:03 36176 ----a-w- c:\windows\system32\mfc100chs.dll
2011-02-19 05:40 . 2011-02-19 05:40 773968 ----a-w- c:\windows\system32\msvcr100.dll
2011-02-18 21:36 . 2009-08-04 17:06 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2009-08-04 17:06 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-05-01 16:47 . 2011-03-24 16:37 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2007-10-26 15:00 . 2009-01-12 18:19 16896 ----a-w- c:\program files\mozilla firefox\components\tmfftb.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AROReminder"="c:\program files\ARO 2011\aro.exe" [2011-01-25 2312048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2006-08-03 577536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2003-10-03 61440]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-04-09 184320]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe" [2009-01-12 98304]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2003-12-05 49152]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-31 2595616]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-31 909208]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-10-31 140568]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
"Share-to-Web Namespace Daemon"="c:\program files\hp\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-04 198160]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-11 368706]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 813912]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-28 61440]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
palmOne Registration.lnk - c:\program files\palmOne\register.exe [2005-6-9 2355200]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
CardMinder Viewer.lnk - c:\program files\PFU\ScanSnap\CardMinder\CardLauncher.exe [2009-6-10 77824]
Conversion to PDF with ScanSnap Organizer.lnk - c:\program files\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe [2009-6-10 15360]
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2008-1-3 1392640]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-11-6 815104]
SATARaid.lnk - c:\program files\Silicon Image\SiISATARaid\SATARaid.exe [2009-1-8 1019961]
ScanSnap Manager.lnk - c:\program files\PFU\ScanSnap\Driver\PfuSsMon.exe [2009-6-10 1048576]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"c:\\Program Files\\Laplink\\PCsync\\SFTHost.exe"=
"c:\\Program Files\\Sling Media\\SlingPlayer\\SlingPlayer.exe"=
"c:\\Documents and Settings\\mmartin\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Documents and Settings\\mmartin\\Application Data\\Macromedia\\Flash Player\\
www.macromedia.com\\bin\\octoshape\\octoshape.exe"="c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
.
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [1/9/2009 3:16 PM 38144]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/18/2009 11:33 PM 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/18/2009 11:33 PM 135664]
S3 gwiopm;gwiopm;\??\c:\program files\Unknown Device Identifier\gwiopm.sys --> c:\program files\Unknown Device Identifier\gwiopm.sys [?]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [8/4/2009 12:06 PM 17408]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys --> c:\windows\system32\DRIVERS\RTL8187B.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-19 04:33]
.
2011-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-19 04:33]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.markemartin.com/uInternet Settings,ProxyOverride = *.local
IE: Add to Evernote - c:\program files\Evernote\Evernote3\enbar.dll/2000
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
FF - ProfilePath - c:\documents and settings\mmartin\Application Data\Mozilla\Firefox\Profiles\p5a9s7yp.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: keyword.URL -
hxxp://search.avg.com/?d=4d63328c&i=23&tp=ab&nt=1&q=FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-HotSync - c:\program files\PalmSource\Desktop\HotSync.exe
Notify-avgrsstarter - avgrsstx.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-05-12 16:36
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3396)
c:\windows\system32\MSVCP100.dll
c:\program files\SmartFTP Client\en-US\sfShellTools.dll.mui
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\SOUNDMAN.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\hp\HP Share-to-Web\hpgs2wnf.exe
c:\program files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-05-12 16:42:17 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-12 21:42
.
Pre-Run: 213,967,106,048 bytes free
Post-Run: 215,889,342,464 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - DAD9AE568BA6E1609A04ED14AE2BA707