ComboFix 10-06-13.01 - Tony 15/06/2010 18:51:54.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.2039.1395 [GMT 10:00]
Running from: c:\documents and settings\Tony\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Tony\Desktop\CFScript.txt.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-05-15 to 2010-06-15 )))))))))))))))))))))))))))))))
.
2010-06-14 01:25 . 2010-06-14 01:32 -------- d-----w- C:\Combo-Fix4530C
2010-06-14 01:07 . 2010-06-14 01:25 -------- d-----w- C:\Combo-Fix
2010-06-12 06:46 . 2010-06-12 09:17 -------- d-----w- c:\documents and settings\Tony\Application Data\HPAppData
2010-06-12 06:41 . 2010-06-12 06:41 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-12 06:40 . 2010-06-12 06:40 -------- d-----w- c:\windows\hpoj6500e709
2010-06-12 06:40 . 2010-06-12 06:40 -------- d-----w- c:\program files\Common Files\HP
2010-06-12 06:40 . 2010-06-12 06:40 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-06-12 06:40 . 2010-06-12 06:40 -------- d-----w- c:\documents and settings\Tony\Local Settings\Application Data\Help
2010-06-12 06:39 . 2010-06-12 06:39 -------- d-----w- c:\documents and settings\All Users\Application Data\FileOpen
2010-06-12 06:38 . 2010-06-12 06:38 -------- d-----w- c:\documents and settings\Tony\Local Settings\Application Data\Apple
2010-06-05 02:13 . 2010-06-05 02:13 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2010-06-05 02:03 . 2010-06-12 05:47 -------- d-----w- c:\program files\HP
2010-06-05 02:03 . 2008-04-13 14:17 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-06-05 02:03 . 2008-04-13 14:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-06-05 02:02 . 2010-06-05 08:54 186571 ----a-w- c:\windows\hpwins23.dat
2010-06-05 02:02 . 2008-10-25 09:30 1847 ------w- c:\windows\hpwmdl23.dat
2010-05-30 03:06 . 2010-05-30 03:06 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-05-26 11:21 . 2010-05-26 11:21 -------- d-----w- c:\documents and settings\Tony\Application Data\FileOpen
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-12 06:39 . 2010-05-06 10:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-29 02:32 . 2010-03-07 10:37 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-25 08:38 . 2010-03-08 02:44 -------- d-----w- c:\program files\Bonjour
2010-05-10 06:28 . 2010-05-10 06:27 79456 ----a-w- c:\documents and settings\Tony\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-06 20:59 . 2010-03-07 12:04 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-03-07 12:05 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-03-07 12:05 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-03-07 12:05 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2010-03-07 12:05 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2010-03-07 12:05 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2010-03-07 12:05 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2010-03-07 12:05 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 10:51 . 2010-05-06 10:51 -------- d-----w- c:\documents and settings\Tony\Application Data\Malwarebytes
2010-05-06 10:51 . 2010-05-06 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-04 12:00 . 2010-05-04 12:00 503808 ----a-w- c:\documents and settings\Tony\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7ff4c5fd-n\msvcp71.dll
2010-05-04 12:00 . 2010-05-04 12:00 499712 ----a-w- c:\documents and settings\Tony\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7ff4c5fd-n\jmc.dll
2010-05-04 12:00 . 2010-05-04 12:00 348160 ----a-w- c:\documents and settings\Tony\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7ff4c5fd-n\msvcr71.dll
2010-05-04 12:00 . 2010-05-04 12:00 61440 ----a-w- c:\documents and settings\Tony\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-37e3728f-n\decora-sse.dll
2010-05-04 12:00 . 2010-05-04 12:00 12800 ----a-w- c:\documents and settings\Tony\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-37e3728f-n\decora-d3d.dll
2010-04-29 05:39 . 2010-05-06 10:51 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 05:39 . 2010-05-06 10:51 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-14 16:47 . 2010-03-07 12:04 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-03-23 00:27 . 2010-03-15 14:08 2880 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2010-03-23 00:27 . 2010-03-15 14:08 2880 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-11 37232]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 110592]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-23 33648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-24 210472]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Brother\\Brmfl07a\\FAXRX.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"54925:UDP"= 54925:UDP:Brother Network Scanner
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [7/03/2010 9:20 PM 5504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/03/2010 10:05 PM 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/03/2010 10:05 PM 19024]
S0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [7/03/2010 9:20 PM 140800]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [15/08/2008 4:46 AM 284016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-05-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
.
.
------- Supplementary Scan -------
.
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Tony\Application Data\Mozilla\Firefox\Profiles\24kgee3s.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-15 18:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2752)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-15 18:56:21
ComboFix-quarantined-files.txt 2010-06-15 08:56
ComboFix2.txt 2010-06-14 01:32
Pre-Run: 57,117,982,720 bytes free
Post-Run: 57,103,761,408 bytes free
- - End Of File - - 8FD62A4E9BA1629CC1E2A1260DAE7154