ComboFix 10-01-18.03 - My Computer 01/19/2010 13:28:36.1.2 - x86
Running from: c:\documents and settings\My Computer\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\My Computer\Desktop\Internet Security 2010.lnk
c:\documents and settings\My Computer\My Documents\ZbThumbnail.info
c:\program files\Internet Explorer\msimg32.dll
c:\windows\install.exe
c:\windows\system\oeminfo.ini
c:\windows\system32\11478.exe
c:\windows\system32\11942.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\dbxDgrevCheck.dll
c:\windows\system32\twain_32.dll
Infected copy of c:\windows\system32\qmgr.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\qmgr.dll
.
((((((((((((((((((((((((( Files Created from 2009-12-19 to 2010-01-19 )))))))))))))))))))))))))))))))
.
2010-01-19 15:36 . 2002-08-29 10:40 5120 ----a-w- c:\windows\system32\hccoin.dll
2010-01-19 15:36 . 2002-08-29 08:32 19328 ----a-w- c:\windows\system32\drivers\usbehci.sys
2010-01-18 22:46 . 2010-01-18 22:46 -------- d-----w- c:\windows\ServicePackFiles
2010-01-18 22:40 . 2002-08-29 10:41 74240 ----a-w- c:\windows\system32\rtcshare.exe
2010-01-18 22:39 . 2002-08-29 10:41 272896 ----a-w- c:\windows\system32\kerberos.dll
2010-01-18 21:03 . 2010-01-18 21:03 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-01-18 20:24 . 2010-01-18 20:24 -------- d-----w- c:\program files\TrendMicro
2010-01-18 16:39 . 2010-01-18 16:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-18 16:22 . 2001-08-18 12:00 229439 -c--a-w- c:\windows\system32\dllcache\multibox.dll
2010-01-18 16:21 . 2001-08-18 12:00 9728 -c--a-w- c:\windows\system32\dllcache\change.exe
2010-01-18 16:16 . 2001-08-18 12:00 106562 -c--a-w- c:\windows\system32\dllcache\srchctls.dll
2010-01-18 16:15 . 2001-08-18 12:00 76800 -c--a-w- c:\windows\system32\dllcache\wabimp.dll
2010-01-18 16:14 . 2001-08-18 12:00 272896 -c--a-w- c:\windows\system32\dllcache\pinball.exe
2010-01-18 16:12 . 2002-08-29 08:06 182400 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2010-01-18 16:09 . 2001-08-17 19:59 50048 ----a-w- c:\windows\system32\drivers\DMusic.sys
2010-01-18 16:09 . 2002-08-29 08:32 5888 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-01-18 16:05 . 2008-04-13 16:36 144384 ----a-w- c:\windows\system32\drivers\hdaudbus.sys
2010-01-18 15:13 . 2001-08-18 04:36 4096 ----a-w- c:\windows\system32\ksuser.dll
2010-01-18 15:13 . 2002-08-29 08:27 56576 ----a-w- c:\windows\system32\drivers\redbook.sys
2010-01-16 20:58 . 2002-08-29 10:46 38024 ----a-w- c:\windows\system32\drivers\termdd.sys
2010-01-12 22:34 . 2001-08-18 04:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-01-12 22:34 . 2002-08-29 08:48 14208 ----a-w- c:\windows\system32\drivers\usbscan.sys
2010-01-12 22:34 . 2008-04-14 01:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-01-10 20:28 . 2010-01-10 20:29 38820344 ----a-w- C:\GoogleSketchUpWEN.exe
2010-01-07 22:48 . 2010-01-07 22:49 8087352 ----a-w- C:\Firefox Setup 3.5.7.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-18 21:54 . 2009-01-12 03:28 62009 ----a-w- c:\windows\system32\wpfb_ati2dvag.dll
2010-01-18 20:24 . 2010-01-18 20:24 388096 ----a-r- c:\documents and settings\My Computer\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-18 17:24 . 2009-05-07 22:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-18 16:19 . 2010-01-18 16:17 76825 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-18 16:15 . 2005-09-21 17:18 23348 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-12 22:35 . 2005-09-21 21:13 -------- d-----w- c:\documents and settings\My Computer\Application Data\Snapfish
2010-01-07 22:07 . 2009-05-07 22:04 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2009-05-07 22:04 18520 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 14:30 . 2009-10-11 00:02 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-20 05:50 . 2009-12-01 04:57 93280 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-19 17:01 . 2009-12-19 17:01 -------- d-----w- c:\program files\MixMeister EZ Vinyl Tape Converter
2009-12-09 23:44 . 2005-09-23 02:16 116464 ----a-w- c:\documents and settings\My Computer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-04 02:27 . 2005-09-26 02:46 -------- d-----w- c:\documents and settings\My Computer\Application Data\Apple Computer
2009-12-04 02:12 . 2008-05-23 14:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-01 05:14 . 2009-12-01 05:14 -------- d-----w- c:\program files\MediaMonkey
2009-12-01 03:08 . 2009-12-01 03:06 -------- d-----w- c:\program files\iTunes
2009-12-01 03:08 . 2009-12-01 03:06 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-01 03:06 . 2009-12-01 03:06 -------- d-----w- c:\program files\iPod
2009-12-01 03:06 . 2008-05-23 14:20 -------- d-----w- c:\program files\Common Files\Apple
2009-12-01 03:03 . 2006-05-16 13:27 -------- d-----w- c:\program files\QuickTime
2009-12-01 02:48 . 2009-12-01 02:48 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-03 23:09 . 2009-11-03 23:09 152576 ----a-w- c:\documents and settings\My Computer\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2006-10-07 21:06 . 2005-11-05 20:27 135680 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
------- Sigcheck -------
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Nero\data\Xtras\mssysmgr.exe" [2004-11-12 212992]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-11-05 180269]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-11 1836544]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-15 623992]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Software\wpctrl.exe" [2007-02-09 694008]
"DT ACR"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2008-06-06 81920]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2001-08-18 51200]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2002-08-29 40960]
c:\documents and settings\My Computer\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-9-25 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-9-25 110592]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-9-21 184320]
RAID Manager.lnk - c:\program files\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe [2005-9-21 724992]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R4 Pdaudumvsm;Pdaudumvsm; [x]
S0 iteraid;ITERAID_Service_Install;c:\windows\system32\DRIVERS\iteraid.sys [2005-08-04 26112]
S2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2008-06-04 90112]
S3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2005-06-20 1425152]
S3 W8100XP;Marvell Libertas 802.11b/g SoftAP Driver for Windows XP ;c:\windows\system32\DRIVERS\mrv8ka51.sys [2005-01-06 310656]
.
Contents of the 'Scheduled Tasks' folder
2009-12-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-01-19 c:\windows\Tasks\User_Feed_Synchronization-{11C06F74-C9D7-45B6-AD8D-CB96D7AC8317}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.ca/newsuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: &Search
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} -
hxxp://www.digitalwebbooks.com/reader/dbplugin.cabFF - ProfilePath - c:\documents and settings\My Computer\Application Data\Mozilla\Firefox\Profiles\sr5ybc7z.default\
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-Run-NWEReboot - (no file)
AddRemove-BookSmart
1.9.7 1.9.7 - c:\007_sh\sh_2008\booksmart\BookSmart\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-19 13:43
Windows 5.1.2600 Service Pack 1 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\HID\Vid_045e&Pid_00d1&Col02\6&1727dbbc&0&0001\LogConf]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\HID\Vid_045e&Pid_00d1&Col02\6&7cf696b&0&0001\LogConf]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(848)
c:\windows\System32\ODBC32.dll
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(904)
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\windows\System32\dssenh.dll
- - - - - - - > 'explorer.exe'(3088)
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
c:\program files\Logitech\iTouch\iTchHk.dll
c:\program files\Common Files\Logitech\Scrolling\LgMsgHk.dll
c:\program files\Portrait Displays\Pivot Software\winphook.dll
c:\windows\System32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\RunDll32.exe
c:\program files\Portrait Displays\Pivot Software\floater.exe
c:\program files\Acer Display\eDisplay Management\DTHtml.exe
c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\windows\System32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2010-01-19 13:49:15 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-19 19:49
Pre-Run: 13,377,691,648 bytes free
Post-Run: 16,621,490,176 bytes free
winxpsp1_en_hom_bf.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 35EE9B6BFDC35D3FBA95A7051ADDDD52