ComboFix 08-12-09.03 - sanchezG 2008-12-11 13:15:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1512 [GMT -5:00]
Running from: c:\documents and settings\sanchezG\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\restore\S-1-5-21-1482476501-1644491937-682003330-1013
c:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
c:\windows\system32\x64
E:\autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-11-11 to 2008-12-11 )))))))))))))))))))))))))))))))
.
2008-12-11 13:17 . 2008-12-11 13:17 53,248 --a------ c:\temp\catchme.dll
2008-12-11 12:16 . 2008-12-11 12:25
d-------- c:\temp\~nsu.tmp
2008-12-10 13:19 . 2008-12-11 13:17 d-------- c:\temp\WER90d0.dir00
2008-12-10 13:05 . 2008-12-10 13:06 d-------- c:\temp\plugtmp
2008-12-07 15:31 . 2008-12-11 13:17 d-------- c:\temp\Domino Web Access
2008-12-05 13:19 . 2008-12-05 13:19 d-------- c:\temp\Adobe
2008-12-04 14:47 . 2008-12-04 14:47 d-------- c:\temp\OIS
2008-11-21 16:01 . 2008-12-11 13:15 dr-hs---- C:\RESTORE
2008-11-13 09:41 . 2008-12-11 13:17 d-------- c:\temp\WMC0000.tmp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 19:44 --------- d-----w c:\documents and settings\All Users\Application Data\Citrix
2008-10-28 19:43 61,224 ----a-w c:\documents and settings\sanchezG\GoToAssistDownloadHelper.exe
2008-10-28 19:43 --------- d-----w c:\program files\Citrix
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 10:37 659,456 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:15 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 21:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2005-11-15 20:32 3,638 ----a-r c:\program files\Common Files\Altiris_Icon.ico
2007-08-06 16:07 8,784 ----a-w c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-07-18 18:54 245,408 ----a-w c:\program files\mozilla firefox\plugins\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"WinDNN"="c:\documents and settings\sanchezG\Application Data\Google\klnxv19819115.exe" [2008-12-10 123392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2008-09-11 356429]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 138008]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-04-17 159744]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"AccessManager"="c:\program files\AccessManager\Client\AccessMgr.exe" [2004-11-03 794624]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"MFP1815_S2P"="c:\program files\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe" [2006-12-22 258952]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe" [2006-02-20 36864]
"IndexSearch"="c:\program files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe" [2006-02-20 40960]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"AT&T Communication Manager"="c:\program files\AT&T\Communication Manager\ATTCM.exe" [2008-05-01 33280]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2005-03-07 176128]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
VPN Client.lnk - c:\windows\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico [2008-03-06 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-28 14:43 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= AMINIT.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AeXAgentLogon]
--a------ 2008-01-30 22:06 143360 c:\program files\Altiris\Altiris Agent\AeXAgentActivate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AeXRSAView]
--a------ 2007-05-31 20:23 1204224 c:\program files\Altiris\Recovery Solution Agent\AeXRSAView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]
--a------ 2005-06-10 08:43 1095680 c:\program files\Webroot\Washer\wwDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Altiris Local Recovery Server"=3 (0x3)
"AeXNSClient"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Cassie1000\\AvonFtp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\AT&T\\Communication Manager\\SwiApiMux.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Altiris\\Altiris Agent\\AeXAgentActivate.exe"=
R0 aarich;aarich;c:\windows\system32\DRIVERS\aarich.sys [2007-10-19 204800]
R0 megasas;DELL PERC RAID Driver;c:\windows\system32\drivers\megasas.sys [2007-10-19 17664]
R0 OfmLvDrv;OfmLvDrv;c:\windows\system32\drivers\OfmLvDrv.sys [2007-05-16 118683]
R1 NEOFLTR_520_9469;Juniper Networks TDI Filter Driver (NEOFLTR_520_9469);\??\c:\windows\system32\Drivers\NEOFLTR_520_9469.SYS [2005-11-09 57062]
R2 AMBroker;Access Manager Configuration Service;"c:\program files\AccessManager\Client\AMBroker.exe" [2004-11-03 77824]
R2 GtDetectSc;GT Detect;c:\windows\system32\GtDetectSc.exe [2006-09-21 167936]
R2 Sygman;SSA Integration Manager;"c:\program files\AccessManager\Client\sygman.exe" [2004-11-03 126976]
R2 TmFilter;Trend Micro Filter;\??\c:\program files\Trend Micro\OfficeScan Client\TmXPFlt.sys [2006-09-06 205328]
R2 TmPreFilter;Trend Micro PreFilter;\??\c:\program files\Trend Micro\OfficeScan Client\TmPreFlt.sys [2006-09-06 36368]
R3 BWNDIS5;BWNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\BWNDIS5.SYS [2004-03-10 15744]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys []
S3 ATTRcAppSvc;AT&T RcAppSvc;"c:\program files\AT&T\Communication Manager\RcAppSvc.exe" /n "ATTRcAppSvc" [2008-03-06 106496]
S3 DAPlugin;Visual Insight DA Plugin;c:\program files\AccessManager\Client\DAPlugin.exe [2004-11-03 81920]
S3 GTFFBUS;GT FF BUS;c:\windows\system32\DRIVERS\gtffbus.sys [2006-09-20 16128]
S3 GTMNDISIRPXP;GT M 3G+ IRP NDIS;c:\windows\system32\DRIVERS\Gtm51Irp.sys [2006-09-20 113408]
S3 GTPTSER;GT PT SER;c:\windows\system32\DRIVERS\gtptser.sys [2006-09-20 8064]
S3 GTUQBUS;GT UQ BUS;c:\windows\system32\DRIVERS\gtuqbus.sys [2006-09-20 34560]
S3 sp_spi_da;Visual Insight Dial Analysis;c:\program files\SmartPipes\SMOC\spi_da.exe [2004-10-15 81920]
S4 a320raid;a320raid;c:\windows\system32\DRIVERS\a320raid.sys [2007-10-19 218112]
S4 aac;PERC 320/DC SCSI RAID Miniport Driver;c:\windows\system32\DRIVERS\aac.sys [2007-10-19 48140]
S4 Altiris Local Recovery Server;Altiris Local Recovery Server;c:\program files\Altiris\Recovery Solution Agent\LocalRSvc.exe [2007-05-31 856064]
S4 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [2007-10-19 11029]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a17ffd96-7ea2-11dc-923e-0011430e221e}]
\Shell\AutoRun\command - e:\programs\nu2menu\nu2menu.exe
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-05-01 c:\windows\Tasks\AeX Local Job 12.job
- c:\program files\Altiris\Recovery Solution Agent\AeXCmd.exe [2007-05-31 20:13]
2008-04-27 c:\windows\Tasks\AeX Local Job 2.job
- c:\program files\Altiris\Recovery Solution Agent\AeXCmd.exe [2007-05-31 20:13]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-UpdateManager - c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://youravon.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-11 13:17:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1288)
c:\windows\system32\AMINIT.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
c:\windows\system32\igfxdev.dll
- - - - - - - > 'lsass.exe'(1344)
c:\windows\system32\AMINIT.dll
c:\windows\system32\bmnet.dll
.
Completion time: 2008-12-11 13:17:58
ComboFix-quarantined-files.txt 2008-12-11 18:17:50
Pre-Run: 24,291,676,160 bytes free
Post-Run: 24,591,601,664 bytes free
186 --- E O F --- 2008-12-10 13:40:37