ComboFix 10-09-29.01 - lcdig 09/29/2010 15:01:23.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.534 [GMT -7:00]
Running from: c:\documents and settings\lcdig\My Documents\Downloads\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
ADS - WINDOWS: deleted 72 bytes in 1 streams. ((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-29 )))))))))))))))))))))))))))))))
.
2010-12-29 01:06 . 2010-12-29 01:06 -------- d-----w- c:\windows\LastGood
2010-09-23 00:11 . 2010-09-23 00:11 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2010-09-21 17:56 . 2010-09-21 17:57 8 ----a-w- c:\windows\system32\nvModes.dat
2010-09-21 17:55 . 2010-09-21 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA
2010-09-21 17:45 . 2006-10-22 19:22 208896 ----a-w- c:\windows\system32\nvudisp.exe
2010-09-21 17:44 . 2006-10-22 22:06 208896 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-09-21 17:43 . 2010-09-21 17:43 -------- d-----w- C:\NVIDIA
2010-09-21 17:32 . 2010-09-21 17:32 -------- d-----w- c:\program files\SystemRequirementsLab
2010-09-21 17:32 . 2010-09-21 17:32 -------- d-----w- c:\documents and settings\lcdig\Application Data\SystemRequirementsLab
2010-09-21 17:32 . 2010-09-21 17:32 290816 ----a-w- c:\documents and settings\lcdig\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll
2010-09-21 17:32 . 2010-09-21 17:32 290816 ----a-w- c:\documents and settings\lcdig\Application Data\SystemRequirementsLab\SRLProxy_nvd_3.dll
2010-09-21 17:32 . 2010-09-21 17:32 290816 ----a-w- c:\documents and settings\lcdig\Application Data\SystemRequirementsLab\SRLProxy_nvd_2.dll
2010-09-21 17:32 . 2010-09-21 17:32 290816 ----a-w- c:\documents and settings\lcdig\Application Data\SystemRequirementsLab\SRLProxy_nvd_1.dll
2010-09-21 17:32 . 2010-09-21 17:33 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-09-21 17:18 . 2010-09-21 17:18 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-09-15 21:32 . 2010-09-15 21:34 -------- d-----w- c:\program files\QuickTime
2010-09-08 18:00 . 2010-09-08 18:00 -------- d-----w- c:\program files\iPod
2010-09-08 18:00 . 2010-09-08 18:02 -------- d-----w- c:\program files\iTunes
2010-09-08 17:47 . 2010-09-08 17:47 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-29 01:07 . 2010-02-24 17:56 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-28 19:35 . 2008-10-07 16:23 -------- d-----w- c:\program files\DYMO Label
2010-09-27 22:16 . 2009-12-31 19:43 -------- d-----w- c:\documents and settings\lcdig\Application Data\Azureus
2010-09-08 18:00 . 2008-07-03 16:52 -------- d-----w- c:\program files\Common Files\Apple
2010-08-25 17:08 . 2010-08-25 17:08 -------- d-----w- c:\documents and settings\lcdig\Application Data\NSBackup
2010-08-20 23:43 . 2008-08-25 21:38 -------- d-----w- c:\program files\Common Files\Java
2010-08-20 23:42 . 2008-08-25 21:39 -------- d-----w- c:\program files\Java
2010-08-20 00:48 . 2010-08-20 00:48 40624 ---ha-w- c:\windows\system32\mlfcache.dat
2010-08-17 13:17 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-07 23:18 . 2010-08-07 23:18 503808 ----a-w- c:\documents and settings\lcdig\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1d8d48ad-n\msvcp71.dll
2010-08-07 23:18 . 2010-08-07 23:18 499712 ----a-w- c:\documents and settings\lcdig\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1d8d48ad-n\jmc.dll
2010-08-07 23:18 . 2010-08-07 23:18 348160 ----a-w- c:\documents and settings\lcdig\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1d8d48ad-n\msvcr71.dll
2010-08-07 23:18 . 2010-08-07 23:18 61440 ----a-w- c:\documents and settings\lcdig\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-66eceaa1-n\decora-sse.dll
2010-08-07 23:18 . 2010-08-07 23:18 12800 ----a-w- c:\documents and settings\lcdig\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-66eceaa1-n\decora-d3d.dll
2010-07-22 15:49 . 2004-08-04 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-16 06:16 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-07-17 12:00 . 2010-05-26 19:14 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-09 22:24 . 2010-07-09 22:25 53632 ----a-w- c:\documents and settings\lcdig\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe2010-07-09 22:24 . 2010-04-06 23:53 53632 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe2010-07-09 22:23 . 2010-07-09 22:22 71680 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2009-09-11 3042240]
"Aim"="c:\program files\AIM7\aim.exe" [2010-04-19 3972440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2006-10-22 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\lcdig\\Application Data\\Macromedia\\Flash Player\\
www.macromedia.com\\bin\\octoshape\\octoshape.exe"="c:\\Program Files\\AIM7\\aim.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1108000.005\symds.sys [9/23/2010 4:08 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1108000.005\symefa.sys [9/23/2010 4:08 PM 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100901.003\BHDrvx86.sys [8/31/2010 3:57 PM 692272]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1108000.005\cchpx86.sys [9/23/2010 4:08 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1108000.005\ironx86.sys [9/23/2010 4:08 PM 116784]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.8.0.5\ccsvchst.exe [9/23/2010 4:07 PM 126392]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/12/2008 10:03 AM 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [7/23/2010 1:39 PM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100928.001\IDSXpx86.sys [12/28/2010 6:04 PM 331640]
.
Contents of the 'Scheduled Tasks' folder
2010-12-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\lcdig\Application Data\Mozilla\Firefox\Profiles\h8je9slv.default\
FF - prefs.js: browser.startup.homepage -
hxxps://secure.accountsupport.com/secure/maillogin.bmlFF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\lcdig\Application Data\Mozilla\Firefox\Profiles\h8je9slv.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc_fireftp.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-29 15:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]
"ImagePath"=""c:\program files\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe" /s "NIS" /m "c:\program files\Norton Internet Security\Engine\17.8.0.5\diMaster.dll" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2416)
c:\windows\system32\WININET.dll
c:\program files\SlySoft\AnyDVD\ADvdDiscHlp.dll
c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2010-09-29 15:13:14
ComboFix-quarantined-files.txt 2010-09-29 22:13
Pre-Run: 176,647,200,768 bytes free
Post-Run: 177,977,372,672 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 8A6EC3CEB446693E1A20943E7DE286EA