ComboFix 10-02-07.08 - Danille 02/08/2010 9:49.1.1 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.808 [GMT -6:00]
Running from: G:\ComboFix.exe
FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\dobe~1
c:\program files\Common Files\sstem~1
c:\program files\fnts~1
c:\program files\wnsxs~1
c:\program files\ystem~1
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-1708537768-602609370-725345543-500
c:\recycler\S-1-5-21-580904943-1621082120-2705454646-500
c:\windows\system32\curity~1
c:\windows\system32\scurit~1
c:\windows\ymbols~1
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
.
2010-02-07 06:02 . 2010-02-07 06:02 -------- d-----w- c:\program files\Lavalys
2010-02-06 02:20 . 2010-02-06 02:20 -------- d-----w- c:\program files\WhoCrashed
2010-01-30 02:10 . 2010-01-30 02:10 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-01-24 15:26 . 2010-02-02 15:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-01-12 18:25 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 20:20 . 2009-02-02 17:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-06 02:18 . 2008-11-21 02:00 -------- d-----w- c:\program files\AWS
2010-02-02 15:53 . 2009-12-14 17:37 -------- d-----w- c:\program files\Alwil Software
2010-02-01 23:29 . 2005-02-05 01:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-01 23:29 . 2009-01-11 07:19 -------- d-----w- c:\documents and settings\All Users\Application Data\MinigolfAdventures
2010-02-01 23:24 . 2007-09-23 03:07 -------- d-----w- c:\program files\MySpace
2010-02-01 23:24 . 2005-10-16 18:52 -------- d-----w- c:\program files\Zone.com Deluxe Games
2010-01-31 22:33 . 2009-02-03 19:27 -------- d-----w- c:\program files\BookSmart
2010-01-30 02:05 . 2006-11-25 03:06 -------- d-----w- c:\program files\Google
2010-01-29 01:42 . 2007-08-14 15:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-20 03:41 . 2009-07-01 19:39 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-07 22:07 . 2009-02-02 17:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2009-02-02 17:18 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-04 21:42 . 2007-01-30 21:05 -------- d-----w- c:\documents and settings\Danille\Application Data\U3
2009-12-21 19:14 . 2004-08-04 08:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-15 16:14 . 2008-12-17 19:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-12-15 16:13 . 2008-12-17 18:42 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-12-15 16:13 . 2008-12-17 18:42 -------- d-----w- c:\program files\Symantec
2009-12-13 17:48 . 2005-05-24 22:49 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-13 05:02 . 2009-12-13 05:02 -------- d-----w- c:\program files\Apple Software Update
2009-12-13 05:01 . 2008-04-14 19:05 -------- d-----w- c:\program files\Common Files\Apple
2009-12-13 05:01 . 2009-12-13 05:00 -------- d-----w- c:\program files\QuickTime
2009-12-13 05:00 . 2005-02-05 02:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-29 15:19 . 2003-03-19 09:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-11-29 15:19 . 2003-02-21 17:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-11-21 15:51 . 2004-08-04 08:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2005-10-16 20:08 . 2005-10-16 20:09 774144 -c--a-w- c:\program files\RngInterstitial.dll
2008-06-03 14:34 . 2007-08-01 00:28 952 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-29 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-05-02 77913]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-05-02 720985]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-02-17 233534]
"hpWirelessAssistant"="c:\program files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2004-12-09 790528]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"\\DESKTOP\EPSON Stylus Photo RX500"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE" [2003-06-01 99840]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 217194]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-5-24 113664]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-11-29 569405]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
WG111v2 Smart Wizard Wireless Setting.lnk - c:\program files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe [2009-2-2 745472]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [4/10/2006 8:28 PM 78848]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [9/3/2006 4:22 PM 66048]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [5/23/2005 11:48 PM 192896]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [9/3/2006 4:22 PM 167808]
R3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [2/2/2009 9:14 AM 13532]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/29/2010 8:05 PM 135664]
S2 pciinfo;HP Pci Information;\??\c:\docume~1\Danille\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys --> c:\docume~1\Danille\LOCALS~1\Temp\HPISPz\hpdom\pciinfo.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-02-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-02-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 02:05]
2010-02-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 02:05]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/ig?hl=enuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uInternet Connection Wizard,ShellNext =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=laptopuInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: &Search
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {D9CDEFE3-51BB-4737-A12C-53D9814A148C} -
hxxps://myemail.amd.com/exchweb/controls/DAX.cab.
- - - - ORPHANS REMOVED - - - -
BHO-{BFA2F340-6EFF-392C-8F2E-39E600845EB7} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-08 10:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????0?6?2?4??@???? ???B?????????????hLC? ??????
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-725065103-563730624-2752237133-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e1,51,8d,e8,82,38,f6,ef,e6,0e,1f,b6,f3,c6,63,44,32,fe,c5,92,0b,f6,76,
57,4d,4d,71,33,48,af,f3,46,ad,a7,eb,c0,06,ae,ae,de,24,7a,95,a6,9f,65,90,aa,\
"??"=hex:60,e7,21,b4,22,94,78,d3,9e,d3,e4,57,ff,30,8d,57
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1040)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(4756)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\PC Tools Firewall Plus\FWService.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Windows Media Player\WMPNetwk.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\NETGEAR\WG111v2 Configuration Utility\RtWLan.exe
c:\program files\HPQ\SHARED\HPQWMI.exe
.
**************************************************************************
.
Completion time: 2010-02-08 10:19:24 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-08 16:19
Pre-Run: 45,340,475,392 bytes free
Post-Run: 44,318,101,504 bytes free
- - End Of File - - 7048DAB16B5A30666EEBCD38140FA769