ComboFix 10-01-14.02 - Frank 01/14/2010 13:59:36.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1791.1374 [GMT -8:00]
Running from: J:\Combo-Fix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\alexa toolbar
c:\windows\Downloaded Program Files\popcaploader.inf
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-12-14 to 2010-01-14 )))))))))))))))))))))))))))))))
.
2010-01-09 13:21 . 2010-01-09 13:21 -------- d-----w- c:\program files\ewido anti-malware
2010-01-07 21:58 . 2010-01-07 21:58 -------- d-----w- c:\program files\TrendMicro
2010-01-03 11:19 . 2010-01-03 11:19 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\IsolatedStorage
2010-01-03 11:19 . 2010-01-03 11:19 -------- d-----w- c:\documents and settings\Frank\Local Settings\Application Data\Intuit
2010-01-03 11:17 . 2010-01-03 11:17 -------- d-----w- c:\program files\Common Files\AnswerWorks 5.0
2010-01-03 10:43 . 2010-01-03 10:43 -------- d-----w- c:\documents and settings\Frank\Local Settings\Application Data\IsolatedStorage
2009-12-29 21:15 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-29 11:32 . 2009-12-29 11:33 -------- d-----w- c:\program files\Safari
2009-12-28 19:48 . 2009-12-28 19:53 -------- d-----w- c:\windows\system32\NtmsData
2009-12-26 23:10 . 2009-12-26 23:10 -------- d-----w- c:\documents and settings\Frank\Application Data\Malwarebytes
2009-12-26 23:05 . 2009-12-26 23:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-26 23:05 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-26 23:05 . 2010-01-08 11:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-26 10:39 . 2009-12-28 11:54 -------- d-----w- c:\documents and settings\Frank\Local Settings\Application Data\ygmokc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-09 13:18 . 2007-10-17 10:22 -------- d-----w- c:\program files\dl_Cats
2010-01-04 07:25 . 2007-08-17 19:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-04 07:24 . 2008-12-06 19:51 -------- d-----w- c:\documents and settings\Frank\Application Data\uTorrent
2010-01-03 11:13 . 2008-02-04 00:58 -------- d-----w- c:\program files\Common Files\Intuit
2010-01-03 11:02 . 2008-02-04 00:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit
2010-01-03 10:59 . 2008-02-04 00:57 -------- d-----w- c:\program files\TurboTax
2010-01-03 08:17 . 2009-03-17 05:41 -------- d-----w- c:\documents and settings\Frank\Application Data\Move Networks
2010-01-02 22:14 . 2009-10-03 22:14 -------- d-----w- c:\documents and settings\Frank\Application Data\FrostWire
2010-01-02 08:50 . 2009-08-31 06:13 -------- d-----w- c:\program files\iCall
2009-12-27 15:26 . 2008-02-14 17:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-04 01:40 . 2009-07-13 04:55 -------- d-----w- c:\program files\Full Tilt Poker
2009-12-03 04:20 . 2009-12-03 04:20 -------- d-----w- c:\program files\Compedia
2009-12-03 04:20 . 2007-08-16 10:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-03 04:20 . 2009-12-03 04:20 -------- d-----w- c:\documents and settings\Frank\Application Data\InterTrust
2009-12-03 04:20 . 2007-08-31 01:41 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-03 03:58 . 2009-10-03 22:13 -------- d-----w- c:\program files\FrostWire
2009-12-03 03:55 . 2008-04-01 06:15 -------- d-----w- c:\program files\The Learning Company
2009-12-03 03:06 . 2009-12-03 03:06 -------- d-----w- c:\program files\Animal Kids
2009-12-03 02:07 . 2009-12-03 02:07 -------- d-----w- c:\program files\brighter child
2009-12-01 03:33 . 2008-06-19 09:27 96200 ----a-w- c:\documents and settings\Aimee\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-03 19:33 . 2009-11-03 19:33 1716297 ----a-w- c:\windows\system32\InetClnt.dll
2009-10-31 11:32 . 2009-10-31 11:26 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-10-29 07:45 . 2004-08-04 15:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 15:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 15:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 20:24 . 2009-03-18 18:20 64604 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-20 19:55 . 2007-08-20 21:25 96200 ----a-w- c:\documents and settings\Frank\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-20 16:20 . 2004-08-04 15:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Frank\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-20 133104]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-26 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 1443072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"eBook Library Launcher"="c:\program files\Sony\Reader\Data\bin\launcher\eBook Library Launcher.exe" [2009-07-03 902440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-22 198160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ClientManager3.lnk - c:\program files\BUFFALO\Client Manager3\cm3_tray.exe [2007-8-16 471040]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC SpeedScan Pro
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" /background
"Aim6"=
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"20090604"=c:\program files\Common Files\Datalode\Encore\Hoyle Casino 2010\encore_reg.exe /r "c:\program files\Common Files\Datalode\Encore\Hoyle Casino 2010\encore_reg.rpd"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"iCall Internet Phone"="c:\program files\iCall\iCall.exe" /startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Program Files\\BUFFALO\\Client Manager3\\BWSVC\\bwsvc.exe"=
"c:\\Program Files\\BUFFALO\\Client Manager3\\AOSS\\aoss.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\PFPortChecker\\PFPortChecker.exe"=
"c:\\Program Files\\Safari\\Safari.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\AdCalls\\Dialer.exe"=
"c:\\Program Files\\iCall\\iCall.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"17403:TCP"= 17403:TCP:eus
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [12/21/2007 8:21 AM 33800]
R2 Bwcdrv;BUFFALO Wireless Configuration;c:\windows\system32\drivers\BWCDRV.SYS [12/21/2003 12:21 AM 19840]
R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [7/16/2009 2:11 PM 266240]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [12/21/2007 8:21 AM 468224]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/16/2008 3:21 PM 24652]
R3 CBBCM43;BUFFALO WLI-CB-XXX Series Wireless LAN Adapter;c:\windows\system32\drivers\CBG54.SYS [11/1/2005 12:13 AM 372480]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/5/2007 3:59 PM 716272]
S4 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-04 c:\windows\Tasks\Ace Optimizer Maintenance.job
- c:\program files\Ace Utilities\au.exe [2008-08-14 07:02]
2010-01-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2010-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-1960408961-682003330-1004Core.job
- c:\documents and settings\Frank\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 11:48]
2010-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-1960408961-682003330-1004UA.job
- c:\documents and settings\Frank\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-20 11:48]
2010-01-09 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 19:25]
2010-01-09 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 19:25]
2010-01-14 c:\windows\Tasks\User_Feed_Synchronization-{865632C5-7C41-447A-A510-E5563E1C29C4}.job
- c:\windows\system32\msfeedssync.exe [2007-08-16 11:31]
2010-01-14 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-29 05:18]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/ig?hl=enuInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
TCP: {79158D15-B808-4B0B-8741-69488A14C123} = 192.168.11.1
FF - ProfilePath - c:\documents and settings\Frank\Application Data\Mozilla\Firefox\Profiles\j25rniry.default\
FF - plugin: c:\documents and settings\Frank\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\documents and settings\Frank\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npArtistScope42.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npArtistScopeDRM11.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Sony\Reader\Data\bin\npebldetectmoz.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{A0729639-D831-46C9-811B-9B0AA79FB45A} - (no file)
AddRemove-Samantha Swift and the Golden Touch1.0 - c:\windows\Samantha Swift and the Golden Touch\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-14 14:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1202660629-1960408961-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B7F8B6BB-0EF8-6D52-7613-DD3ACE95E03D}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abepjkfgpdgnoleemmedddmpodgdpbaoaj"=hex:61,62,67,6f,66,67,61,70,67,6b,67,62,
62,6d,62,70,65,69,64,6c,6f,6e,63,64,6e,6c,64,6a,66,6f,6e,6d,65,66,00,77
"bbepjkfgpdgnoleemmfdagjjcgflknbmeelk"=hex:61,62,6c,6f,64,6b,69,64,6f,69,69,61,
6f,6f,69,64,61,69,6f,64,6f,6c,63,61,68,6d,6d,67,63,6d,70,6d,61,70,00,77
[HKEY_USERS\S-1-5-21-1202660629-1960408961-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:38,97,f4,fd,80,9c,91,07,db,25,e0,8d,f6,3c,9b,f6,e4,a5,11,e0,bf,00,a3,
49,21,d3,e6,76,f5,f5,2f,16,76,54,79,8a,fb,1c,ed,8b,17,74,e5,3a,9e,cb,28,3a,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2288)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\System32\Drivers\bwcsrv.exe
c:\program files\BUFFALO\Client Manager3\bwsvc\bwsvc.exe
c:\program files\ewido anti-malware\ewidoctrl.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.EXE
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
c:\program files\ATI Technologies\ATI.ACE\cli.exe
.
**************************************************************************
.
Completion time: 2010-01-14 14:32:28 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-14 22:32
Pre-Run: 14,242,406,400 bytes free
Post-Run: 15,286,259,712 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
Timeout=2
Default=c:\$win_nt$.~bt\BOOTSECT.DAT
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
c:\$win_nt$.~bt\BOOTSECT.DAT="Microsoft Windows XP Professional Setup"
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - A8B40044AF23E248D3FA5F563A97CF43