ComboFix 09-03-18.01 - user 2009-03-20 3:30:45.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.504.240 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2009-02-20 to 2009-03-20 ))))))))))))))))))))))))))))))) . 2009-03-19 16:09 . 2009-03-19 16:09 2,348 --a------ c:\windows\system32\PerfStringBackup.TMP 2009-03-19 15:00 . 2009-03-19 15:00 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll 2009-03-19 14:59 . 2009-03-19 14:59 d-------- c:\windows\ERUNT 2009-03-19 14:43 . 2009-03-19 15:09 d----c--- C:\SDFix 2009-03-19 13:48 . 2009-03-19 13:48 d----c--- C:\32788R22FWJFW.0.tmp 2009-03-18 23:54 . 2009-03-18 23:54 d-------- c:\program files\Trend Micro 2009-03-18 23:24 . 2009-03-18 23:24 d-------- c:\windows\Sun 2009-03-18 23:24 . 2009-03-18 23:23 410,984 --a------ c:\windows\system32\deploytk.dll 2009-03-18 23:24 . 2009-03-18 23:23 73,728 --a------ c:\windows\system32\javacpl.cpl 2009-03-18 23:23 . 2009-03-18 23:23 d-------- c:\program files\Java 2009-03-18 23:15 . 2009-03-19 16:10 d-------- c:\program files\SUPERAntiSpyware 2009-03-18 23:15 . 2009-03-19 16:10 d-------- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com 2009-03-18 23:15 . 2009-03-18 23:15 d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-03-18 23:08 . 2009-03-18 23:08 d-------- c:\documents and settings\user\Application Data\Malwarebytes 2009-03-18 23:08 . 2009-02-11 13:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-03-18 23:07 . 2009-03-18 23:08 d-------- c:\program files\Malwarebytes' Anti-Malware 2009-03-18 23:07 . 2009-03-18 23:07 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-03-18 23:07 . 2009-02-11 13:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-03-18 17:28 . 2009-03-18 18:11 d-------- c:\program files\Norton Security Scan 2009-03-18 11:54 . 2009-03-18 11:54 d-------- c:\windows\system32\GroupPolicy 2009-03-18 11:54 . 2009-03-18 16:39 d-------- c:\program files\Windows Desktop Search 2009-03-18 11:52 . 2009-03-19 07:20 d-------- c:\program files\Windows Media Connect 2 2009-03-15 15:11 . 2009-03-15 16:12 d----c--- C:\MyAudio 2009-03-14 16:51 . 2009-03-14 16:51 d-------- C:\c4fa75a403273a5728dd2d773c 2009-03-14 16:49 . 2009-03-15 18:56 d-------- c:\windows\SxsCaPendDel 2009-03-14 15:55 . 2008-07-06 08:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll 2009-03-14 15:55 . 2008-07-06 08:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll 2009-03-14 15:55 . 2008-07-06 06:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-03-14 15:55 . 2008-07-06 08:06 575,488 --------- c:\windows\system32\xpsshhdr.dll 2009-03-14 15:55 . 2008-07-06 08:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll 2009-03-14 15:55 . 2008-07-06 08:06 117,760 --------- c:\windows\system32\prntvpt.dll 2009-03-14 15:55 . 2008-07-06 08:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-03-14 15:06 . 2009-03-14 16:46 d-------- C:\eb4a5e7b53740aae3305081d 2009-03-14 15:06 . 2009-03-14 15:12 d-------- C:\e210719537a1c91523236d 2009-03-14 13:57 . 2008-04-13 20:12 91,136 --a------ c:\windows\system32\kswdmcap.ax 2009-03-14 13:57 . 2008-04-13 20:12 91,136 --a--c--- c:\windows\system32\dllcache\kswdmcap.ax 2009-03-14 13:57 . 2008-04-13 20:12 61,952 --a------ c:\windows\system32\kstvtune.ax 2009-03-14 13:57 . 2008-04-13 20:12 61,952 --a--c--- c:\windows\system32\dllcache\kstvtune.ax 2009-03-14 13:57 . 2008-04-13 20:12 53,760 --a------ c:\windows\system32\vfwwdm32.dll 2009-03-14 13:57 . 2008-04-13 20:12 53,760 --a--c--- c:\windows\system32\dllcache\vfwwdm32.dll 2009-03-14 13:57 . 2008-04-13 20:12 43,008 --a------ c:\windows\system32\ksxbar.ax 2009-03-14 13:57 . 2008-04-13 20:12 43,008 --a--c--- c:\windows\system32\dllcache\ksxbar.ax 2009-03-14 13:46 . 2000-10-31 15:00 307,200 --a------ c:\windows\vidcap32.Exe 2009-03-14 13:46 . 2002-08-22 19:34 147,456 --a------ c:\windows\VMCap.exe 2009-03-14 13:46 . 2002-08-22 20:02 53,248 --a------ c:\windows\StillCap.exe 2009-03-14 13:46 . 2002-10-16 12:29 49,152 --a------ c:\windows\amcap.exe 2009-03-13 17:10 . 2009-03-18 16:39 d-------- c:\documents and settings\Administrator 2009-03-11 15:17 . 2009-03-14 16:47 d-------- c:\program files\7-Zip 2009-03-11 12:49 . 2009-03-14 22:21 d-------- c:\program files\Paint.NET 2009-03-11 10:14 . 2009-03-11 13:07 d----c--- c:\windows\system32\DRVSTORE 2009-03-11 10:14 . 2009-03-11 10:14 d-------- c:\documents and settings\user\Application Data\InstallShield 2009-03-11 09:44 . 2009-03-11 13:07 d-------- c:\program files\SanDisk 2009-03-11 09:44 . 2005-05-26 18:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll 2009-03-11 09:44 . 2008-10-14 15:01 14,608 --a------ c:\windows\system32\iviaspi.sys 2009-03-10 21:20 . 2009-03-10 21:20 d-------- c:\documents and settings\user\Application Data\gtk-2.0 2009-03-10 21:20 . 2009-03-10 21:20 d-------- c:\documents and settings\user\.thumbnails 2009-03-10 21:16 . 2009-03-10 21:24 d-------- c:\documents and settings\user\.gimp-2.6 2009-03-10 21:16 . 2009-03-10 21:16 d-------- c:\documents and settings\user\.gegl-0.0 2009-03-10 21:13 . 2009-03-18 18:41 d-a------ c:\documents and settings\All Users\Application Data\TEMP 2009-03-10 13:10 . 2009-03-10 13:10 d-------- c:\documents and settings\user\Application Data\Yahoo! 2009-03-10 13:08 . 2009-03-11 13:06 d-------- c:\program files\Yahoo! 2009-03-10 13:08 . 2009-03-10 13:11 d-------- c:\documents and settings\All Users\Application Data\Yahoo! 2009-03-10 13:01 . 2009-03-10 13:01 d-------- c:\documents and settings\user\Application Data\acccore 2009-03-10 13:00 . 2009-03-18 23:27 d-------- c:\documents and settings\All Users\Application Data\Viewpoint 2009-03-10 13:00 . 2009-03-10 13:00 d-------- c:\documents and settings\All Users\Application Data\AOL OCP 2009-03-10 13:00 . 2009-03-10 13:00 d-------- c:\documents and settings\All Users\Application Data\AOL 2009-03-10 13:00 . 2009-03-10 13:00 d-------- c:\documents and settings\All Users\Application Data\acccore 2009-03-10 12:59 . 2009-03-10 12:59 d-------- c:\program files\Common Files\AOL 2009-03-10 12:59 . 2009-03-10 13:00 d-------- c:\program files\AIM6 2009-03-10 12:58 . 2009-03-10 13:00 459 --ah----- C:\IPH.PH 2009-03-10 12:29 . 2009-03-10 12:29 d-------- c:\program files\Microsoft 2009-03-10 12:29 . 2009-03-19 05:19 d-------- c:\documents and settings\user\Tracing 2009-03-10 12:28 . 2009-03-10 12:28 d-------- c:\program files\Windows Live SkyDrive 2009-03-10 12:28 . 2009-03-10 12:28 d-------- c:\program files\Windows Live 2009-03-10 12:24 . 2009-03-10 12:24 d-------- c:\program files\Common Files\Windows Live 2009-03-10 11:22 . 2008-04-13 14:45 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys 2009-03-10 11:13 . 1999-12-12 13:01 44,032 --------- c:\windows\system32\CTSVCCDA.EXE 2009-03-10 11:13 . 1999-11-17 13:00 25,088 --------- c:\windows\system32\CTSVCCTL.EXE 2009-03-10 11:12 . 2009-03-10 11:14 d--h----- c:\program files\Creative Installation Information 2009-03-10 11:12 . 2009-03-10 11:12 d-------- c:\program files\Common Files\Creative 2009-03-10 11:10 . 2009-03-10 11:21 d-------- c:\documents and settings\user\Application Data\Creative 2009-03-10 11:07 . 2009-03-10 11:19 d-------- c:\documents and settings\All Users\Application Data\Creative 2009-03-10 11:03 . 2000-05-21 20:58 647,872 --------- c:\windows\system32\Mscomct2.ocx 2009-03-10 11:03 . 2006-10-05 18:17 53,248 --------- c:\windows\Ctregrun.exe 2009-03-10 11:02 . 2009-03-10 11:21 d-------- c:\program files\Creative 2009-03-10 10:59 . 2009-03-10 10:59 d-------- c:\windows\system32\LogFiles 2009-03-10 10:59 . 2009-03-10 11:04 d-------- c:\windows\system32\drivers\UMDF 2009-03-10 10:57 . 2009-03-14 16:47 d--h----- c:\program files\InstallShield Installation Information 2009-03-10 10:57 . 2009-03-11 09:43 d-------- c:\program files\Common Files\InstallShield 2009-03-10 10:27 . 2009-03-10 10:27 d--hs---- c:\documents and settings\user\IECompatCache 2009-03-10 10:26 . 2009-03-10 10:26 d--hs---- c:\documents and settings\user\PrivacIE 2009-03-10 10:26 . 2009-03-10 10:26 d--hs---- c:\documents and settings\user\IETldCache 2009-03-10 10:20 . 2009-03-10 10:20 d-------- c:\windows\ie8updates 2009-03-10 10:17 . 2009-03-10 10:18 d--h-c--- c:\windows\ie8 2009-03-10 10:13 . 2009-01-11 01:00 79,360 -----c--- c:\windows\system32\dllcache\iecompat.dll 2009-03-10 02:28 . 2009-03-10 02:28 d-------- c:\documents and settings\user\Application Data\Apple Computer 2009-03-09 23:20 . 2009-02-09 07:13 1,846,784 -----c--- c:\windows\system32\dllcache\win32k.sys 2009-03-09 22:21 . 2009-03-09 22:21 d-------- c:\documents and settings\user\Application Data\MPEG Streamclip 2009-03-09 22:17 . 2009-03-09 22:18 d-------- c:\program files\QuickTime 2009-03-09 22:17 . 2009-03-09 22:17 d-------- c:\documents and settings\All Users\Application Data\Apple Computer 2009-03-09 22:16 . 2009-03-09 22:16 d-------- c:\program files\Apple Software Update 2009-03-09 22:16 . 2009-03-09 22:16 d-------- c:\documents and settings\All Users\Application Data\Apple 2009-03-09 21:43 . 2009-03-09 21:43 d-------- c:\program files\Auslogics 2009-03-09 21:43 . 2009-03-09 21:43 d-------- c:\documents and settings\user\Application Data\Auslogics 2009-03-09 21:40 . 2005-08-25 21:19 115,920 --a------ c:\windows\system32\MSINET.OCX 2009-03-09 21:34 . 2009-03-09 21:34 25,304 --a------ c:\windows\system32\EclipseHook.chm 2009-03-09 21:32 . 2009-03-15 15:11 d-------- c:\program files\AoA Audio Extractor 2009-03-09 21:28 . 2009-03-18 16:53 d--h----- C:\$AVG8.VAULT$ 2009-03-09 21:17 . 2009-01-15 05:12 10,963,968 --a--c--- c:\windows\system32\dllcache\ieframe.dll 2009-03-09 21:17 . 2008-12-14 20:12 3,698,040 --a--c--- c:\windows\system32\dllcache\ieapfltr.dat 2009-03-09 21:17 . 2009-01-15 05:02 1,975,296 --a--c--- c:\windows\system32\dllcache\iertutil.dll 2009-03-09 21:17 . 2009-01-15 05:22 1,228,800 --a--c--- c:\windows\system32\dllcache\ieframe.dll.mui 2009-03-09 21:17 . 2009-01-15 05:02 593,920 --a--c--- c:\windows\system32\dllcache\msfeeds.dll 2009-03-09 21:17 . 2009-01-15 04:35 445,440 --a--c--- c:\windows\system32\dllcache\ieapfltr.dll 2009-03-09 21:17 . 2009-01-15 05:01 59,904 --a--c--- c:\windows\system32\dllcache\icardie.dll 2009-03-09 21:17 . 2009-01-15 05:01 54,272 --a--c--- c:\windows\system32\dllcache\msfeedsbs.dll 2009-03-09 21:17 . 2008-12-19 05:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe 2009-03-09 21:15 . 2009-03-09 21:15 325,640 --a------ c:\windows\system32\drivers\avgldx86.sys 2009-03-09 21:15 . 2009-03-09 21:15 107,912 --a------ c:\windows\system32\drivers\avgtdix.sys 2009-03-09 21:15 . 2009-03-09 21:15 10,520 --a------ c:\windows\system32\avgrsstx.dll 2009-03-09 21:14 . 2009-03-19 13:05 d-------- c:\windows\system32\drivers\Avg 2009-03-09 21:14 . 2009-03-09 21:14 d-------- c:\program files\AVG 2009-03-09 21:14 . 2009-03-09 21:14 d-------- c:\documents and settings\All Users\Application Data\avg8 2009-03-09 20:50 . 2009-03-09 20:50 d-------- c:\windows\system32\scripting 2009-03-09 20:50 . 2009-03-09 20:50 d-------- c:\windows\system32\en . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys 2009-02-07 01:52 49,504 ----a-w c:\windows\system32\sirenacm.dll 2009-02-03 22:30 237,568 ----a-w c:\windows\system32\config\systemprofile\NTUSER(2).DAT 2009-02-02 23:51 --------- d-----w c:\program files\Microsoft ActiveSync 2009-02-02 23:01 --------- d-----w c:\program files\VideoLAN 2009-02-02 22:38 499,712 ----a-w c:\windows\system32\msvcp71.dll 2009-02-02 22:38 348,160 ----a-w c:\windows\system32\msvcr71.dll 2009-02-02 22:34 --------- d-----w c:\program files\DivX 2009-02-02 22:26 --------- d-----w c:\program files\Common Files\Adobe 2009-01-30 23:26 --------- d-----w c:\program files\microsoft frontpage 2009-01-15 09:05 911,872 ----a-w c:\windows\system32\wininet.dll 2009-01-15 09:05 43,008 ----a-w c:\windows\system32\licmgr10.dll 2009-01-15 09:04 18,944 ----a-w c:\windows\system32\corpol.dll 2009-01-15 09:03 72,704 ----a-w c:\windows\system32\admparse.dll 2009-01-15 09:03 71,680 ----a-w c:\windows\system32\iesetup.dll 2009-01-15 09:03 420,352 ----a-w c:\windows\system32\vbscript.dll 2009-01-15 09:01 34,304 ----a-w c:\windows\system32\imgutil.dll 2009-01-15 09:00 48,128 ----a-w c:\windows\system32\mshtmler.dll 2009-01-15 09:00 45,568 ----a-w c:\windows\system32\mshta.exe 2009-01-15 08:50 156,160 ----a-w c:\windows\system32\msls31.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-04-01 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-04-01 126976] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-09 1932568] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "CTCheck"="c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048] Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-03-09 21:15 10520 c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "ose"=3 (0x3) "JavaQuickStarterService"=2 (0x2) "aspnet_state"=3 (0x3) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-09 325640] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-03-09 107912] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-09 298264] S3 zsi_fmw;Sansa Connect Firmware Recovery;c:\windows\system32\Drivers\zsi_fmw.sys --> c:\windows\system32\Drivers\zsi_fmw.sys [?] S3 zsi_zap;Sansa Connect ZAP Recovery Driver;c:\windows\system32\Drivers\zsi_zap.sys --> c:\windows\system32\Drivers\zsi_zap.sys [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-03-10 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 15:34] 2009-03-20 c:\windows\Tasks\User_Feed_Synchronization-{B409C876-6E01-4CD1-847F-D9947924312D}.job - c:\windows\system32\msfeedssync.exe [2009-01-15 05:01] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . . ------- File Associations ------- . inffile=c:\windows\System32\NOTEPAD.EXE "%1" . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-20 03:32:47 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-03-20 3:35:13 ComboFix-quarantined-files.txt 2009-03-20 07:35:10 ComboFix2.txt 2009-03-19 18:55:53 ComboFix3.txt 2009-03-19 18:29:22 Pre-Run: 33,322,983,424 bytes free Post-Run: 33,318,719,488 bytes free 232 --- E O F --- 2009-03-14 19:59:09