ComboFix 09-07-29.04 - Administrator 07/31/2009 5:15.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.383.161 [GMT -4:00]
Running from: c:\documents and settings\Administrator\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
FILE ::
"C:\bicfei.exe"
"c:\windows\ppp3.dat"
"c:\windows\ppp4.dat"
"c:\windows\svchast.exe"
"c:\windows\system32\desot.exe"
"C:\ytnkf.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\bicfei.exe
c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Settings\AskLogo.ico
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevCfg2.htm
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\program files\BitTorrent
c:\program files\BitTorrent\bittorrent.exe
c:\program files\BitTorrent\uninst.exe
c:\program files\Windows Antivirus Pro
c:\program files\Windows Antivirus Pro\msvcm80.dll
c:\program files\Windows Antivirus Pro\msvcp80.dll
c:\program files\Windows Antivirus Pro\msvcr80.dll
c:\program files\Windows Antivirus Pro\Windows Antivirus Pro.exe
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\svchast.exe
c:\windows\system32\desot.exe
c:\windows\system32\drivers\ntndis.sys
C:\ytnkf.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_XDVA275
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_XDva275
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.
2009-07-30 03:28 . 2009-07-30 03:32 -------- d-----w- c:\program files\Bejeweled Twist
2009-07-29 03:53 . 2009-07-29 03:53 38912 ----a-w- C:\jars.exe
2009-07-27 20:27 . 2008-10-16 18:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-07-27 20:04 . 2009-07-27 20:04 -------- d-s---w- c:\windows\system32\config\systemprofile\UserData
2009-07-27 20:04 . 2009-07-30 21:03 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
2009-07-27 14:31 . 2009-07-27 14:32 4 ----a-w- c:\windows\system32\bincd32.dat
2009-07-27 14:31 . 2009-07-27 14:31 40960 --sh--r- c:\windows\system32\flashad32.dll
2009-07-27 14:31 . 2009-07-27 14:31 212480 ----a-w- c:\windows\system32\dllcache\ndis.sys
2009-07-27 14:30 . 2009-07-27 14:30 36 ----a-w- c:\windows\system32\sysnet.dat
2009-07-27 14:29 . 2009-07-27 14:29 827392 ----a-w- c:\windows\system32\dddesot.dll
2009-07-27 14:28 . 2009-07-27 14:28 59904 ----a-w- c:\windows\system32\classapi64.dll
2009-07-27 14:28 . 2009-07-27 14:28 134144 ----a-w- c:\windows\system32\mapitools.dll
2009-07-27 14:28 . 2009-07-27 14:28 134144 ----a-w- C:\nklttk.exe
2009-07-27 14:27 . 2009-07-29 17:26 200704 ----a-w- c:\windows\system32\samsvc.exe
2009-07-27 01:46 . 2009-07-27 02:12 -------- d-----w- c:\documents and settings\Administrator\Tracing
2009-07-27 01:42 . 2009-07-27 01:42 -------- d-----w- c:\program files\Microsoft
2009-07-27 01:40 . 2009-07-27 01:40 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-07-27 01:38 . 2009-07-27 01:41 -------- d-----w- c:\program files\Windows Live
2009-07-27 01:28 . 2009-07-27 01:28 -------- d-----w- c:\program files\Common Files\Windows Live
2009-07-26 23:33 . 2009-07-26 23:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\JewelMatch2
2009-07-26 04:04 . 2009-07-26 04:05 2383904 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\Unpack\bfgsetup_s1_l1.exe
2009-07-26 04:04 . 2009-07-26 04:04 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-07-26 03:05 . 2009-07-26 03:05 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-25 17:58 . 2009-07-25 17:58 -------- d-----w- c:\program files\Bejeweled 2 Deluxe
2009-07-25 17:52 . 2009-07-27 05:23 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitTorrent
2009-07-24 18:44 . 2008-03-05 20:03 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2009-07-24 18:43 . 2005-05-26 19:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-07-24 18:42 . 2009-07-24 18:42 -------- d-----w- c:\windows\Logs
2009-07-24 17:39 . 2009-07-24 17:39 -------- d-----w- c:\program files\Redbana
2009-07-24 17:39 . 2009-07-24 17:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 17:38 . 2009-07-24 17:38 -------- d-----w- c:\program files\Common Files\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-30 21:18 . 2008-07-29 02:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-30 21:18 . 2008-06-11 19:47 768 ----a-w- c:\windows\system32\d3d8caps.dat
2009-07-30 07:46 . 2008-06-01 03:47 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-30 03:21 . 2000-12-06 08:52 16 -c--a-w- c:\windows\popcinfo.dat
2009-07-29 19:52 . 2009-06-01 06:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-29 19:09 . 2000-11-17 21:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-07-27 14:31 . 2004-08-04 12:00 212480 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-07-27 01:45 . 2008-05-24 02:51 12912 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-26 20:51 . 2009-07-26 20:51 0 ----a-w- c:\windows\system32\drivers\SETD.tmp
2009-07-13 17:36 . 2009-06-01 06:01 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 17:36 . 2009-06-01 06:01 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-16 14:55 . 2004-08-04 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-07 14:10 . 2008-07-13 03:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
2009-06-07 14:02 . 2008-07-13 03:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-03 19:27 . 2004-08-04 12:00 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-19 22:10 . 2009-05-19 22:10 143864 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\stub\flower-paradise_s1_l1_gF5012T1L1_d589772138.exe
2009-05-19 22:10 . 2009-05-19 22:10 2319528 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\clientinstaller\bfgsetup_s1_l1.exe
2009-05-07 15:44 . 2004-08-04 12:00 344064 ----a-w- c:\windows\system32\localspl.dll
2009-07-27 01:04 . 2008-08-26 18:44 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-07-29_18.58.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-27 20:04 . 2009-07-29 18:56 32768 c:\windows\system32\config\systemprofile\UserData\index.dat
+ 2009-07-27 20:04 . 2009-07-31 09:47 32768 c:\windows\system32\config\systemprofile\UserData\index.dat
+ 2009-07-31 09:47 . 2009-07-31 09:48 65536 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-31 04:03 . 2009-07-31 10:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009073120090801\index.dat
+ 2009-07-30 04:53 . 2009-07-31 03:18 49152 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009073020090731\index.dat
+ 2009-07-29 17:40 . 2009-07-30 03:36 49152 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009072920090730\index.dat
+ 2009-07-27 14:27 . 2009-07-31 09:50 98304 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-07-27 14:27 . 2009-07-29 18:56 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-07-27 14:27 . 2009-07-31 09:47 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{58101905-D80F-4788-96F6-98618186178A}"= "c:\windows\system32\flashad32.dll" [2009-07-27 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt64chain]
2009-07-27 14:28 59904 ----a-w- c:\windows\system32\classapi64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R3 neo20xx;neo20xx;c:\windows\system32\drivers\neo20xx.sys [11/16/2000 7:02 PM 39264]
R3 wdm_nm6;NeoMagic MagicMedia 256 + AC97 Driver (WDM);c:\windows\system32\drivers\nm6wdm.sys [11/16/2000 7:02 PM 87040]
R3 WPC54Gv3;Linksys Wireless Notebook Adapter WPC54Gv3 Driver;c:\windows\system32\drivers\WPC54Gv3.SYS [12/1/2006 12:54 AM 610816]
S2 MSMQSVC;Message Queuing Service;c:\windows\system32\mqsv32.exe --> c:\windows\system32\mqsv32.exe [?]
S3 atimtai;atimtai;c:\windows\system32\drivers\atimtai.sys [11/24/2007 11:27 AM 281600]
S3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family Driver;c:\windows\system32\drivers\cben5.sys [11/24/2007 11:27 AM 46108]
S3 maestro;ESS Maestro 3 Audio Driver (WDM);c:\windows\system32\drivers\es198x.sys [11/24/2007 11:26 AM 174464]
S3 XDva280;XDva280;\??\c:\windows\system32\XDva280.sys --> c:\windows\system32\XDva280.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - {79007602-0CDB-4405-9DBF-1257BB3226ED}
*NewlyCreated* - {79007602-0CDB-4405-9DBF-1257BB3226EE}
*Deregistered* - {79007602-0CDB-4405-9DBF-1257BB3226ED}
.
Contents of the 'Scheduled Tasks' folder
2009-07-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-HookURL - (no file)
URLSearchHooks-Rank - (no file)
HKCU-Run-Aim6 - (no file)
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Administrator\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ny0z0or0.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage -
hxxp://www.yahoo.com/FF - prefs.js: keyword.URL -
hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=108&ei=utf-8&yahoo_domain=search.yahoo.com&p=FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 51436
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ny0z0or0.default\extensions\activegs@freetoolsassociation.com\plugins\npActiveGS.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-31 06:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\FontCache3.0.0.0]
"ImagePath"="c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\Fs_Rec]
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\Ftdisk]
"ImagePath"="system32\DRIVERS\ftdisk.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\Gpc]
"ImagePath"="system32\DRIVERS\msgpc.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\helpsvc]
"ServiceDll"="%WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\HidServ]
"ServiceDll"="%SystemRoot%\System32\hidserv.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\HidUsb]
"ImagePath"="system32\DRIVERS\hidusb.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\hpn]
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\HTTP]
"ImagePath"="System32\Drivers\HTTP.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\HTTPFilter]
"ServiceDll"="%SystemRoot%\System32\w3ssl.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\i2omgmt]
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\i2omp]
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\i8042prt]
"ImagePath"="system32\DRIVERS\i8042prt.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\idsvc]
"ImagePath"="\"c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe\""
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\Imapi]
"ImagePath"="system32\DRIVERS\imapi.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ImapiService]
"ImagePath"="%systemroot%\system32\imapi.exe"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\inetaccs]
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\ini910u]
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\Inport]
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\IntelIde]
"ImagePath"="system32\DRIVERS\intelide.sys"