ComboFix 09-03-18.01 - user 2009-03-20 3:30:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.504.240 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-02-20 to 2009-03-20 )))))))))))))))))))))))))))))))
.
2009-03-19 16:09 . 2009-03-19 16:09 2,348 --a------ c:\windows\system32\PerfStringBackup.TMP
2009-03-19 15:00 . 2009-03-19 15:00 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2009-03-19 14:59 . 2009-03-19 14:59
d-------- c:\windows\ERUNT
2009-03-19 14:43 . 2009-03-19 15:09 d----c--- C:\SDFix
2009-03-19 13:48 . 2009-03-19 13:48 d----c--- C:\32788R22FWJFW.0.tmp
2009-03-18 23:54 . 2009-03-18 23:54 d-------- c:\program files\Trend Micro
2009-03-18 23:24 . 2009-03-18 23:24 d-------- c:\windows\Sun
2009-03-18 23:24 . 2009-03-18 23:23 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-18 23:24 . 2009-03-18 23:23 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-18 23:23 . 2009-03-18 23:23 d-------- c:\program files\Java
2009-03-18 23:15 . 2009-03-19 16:10 d-------- c:\program files\SUPERAntiSpyware
2009-03-18 23:15 . 2009-03-19 16:10 d-------- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com
2009-03-18 23:15 . 2009-03-18 23:15 d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-18 23:08 . 2009-03-18 23:08 d-------- c:\documents and settings\user\Application Data\Malwarebytes
2009-03-18 23:08 . 2009-02-11 13:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-18 23:07 . 2009-03-18 23:08 d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-18 23:07 . 2009-03-18 23:07 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-18 23:07 . 2009-02-11 13:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-18 17:28 . 2009-03-18 18:11 d-------- c:\program files\Norton Security Scan
2009-03-18 11:54 . 2009-03-18 11:54 d-------- c:\windows\system32\GroupPolicy
2009-03-18 11:54 . 2009-03-18 16:39 d-------- c:\program files\Windows Desktop Search
2009-03-18 11:52 . 2009-03-19 07:20 d-------- c:\program files\Windows Media Connect 2
2009-03-15 15:11 . 2009-03-15 16:12 d----c--- C:\MyAudio
2009-03-14 16:51 . 2009-03-14 16:51 d-------- C:\c4fa75a403273a5728dd2d773c
2009-03-14 16:49 . 2009-03-15 18:56 d-------- c:\windows\SxsCaPendDel
2009-03-14 15:55 . 2008-07-06 08:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-03-14 15:55 . 2008-07-06 08:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-03-14 15:55 . 2008-07-06 06:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-03-14 15:55 . 2008-07-06 08:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-03-14 15:55 . 2008-07-06 08:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-03-14 15:55 . 2008-07-06 08:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-03-14 15:55 . 2008-07-06 08:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-03-14 15:06 . 2009-03-14 16:46 d-------- C:\eb4a5e7b53740aae3305081d
2009-03-14 15:06 . 2009-03-14 15:12 d-------- C:\e210719537a1c91523236d
2009-03-14 13:57 . 2008-04-13 20:12 91,136 --a------ c:\windows\system32\kswdmcap.ax
2009-03-14 13:57 . 2008-04-13 20:12 91,136 --a--c--- c:\windows\system32\dllcache\kswdmcap.ax
2009-03-14 13:57 . 2008-04-13 20:12 61,952 --a------ c:\windows\system32\kstvtune.ax
2009-03-14 13:57 . 2008-04-13 20:12 61,952 --a--c--- c:\windows\system32\dllcache\kstvtune.ax
2009-03-14 13:57 . 2008-04-13 20:12 53,760 --a------ c:\windows\system32\vfwwdm32.dll
2009-03-14 13:57 . 2008-04-13 20:12 53,760 --a--c--- c:\windows\system32\dllcache\vfwwdm32.dll
2009-03-14 13:57 . 2008-04-13 20:12 43,008 --a------ c:\windows\system32\ksxbar.ax
2009-03-14 13:57 . 2008-04-13 20:12 43,008 --a--c--- c:\windows\system32\dllcache\ksxbar.ax
2009-03-14 13:46 . 2000-10-31 15:00 307,200 --a------ c:\windows\vidcap32.Exe
2009-03-14 13:46 . 2002-08-22 19:34 147,456 --a------ c:\windows\VMCap.exe
2009-03-14 13:46 . 2002-08-22 20:02 53,248 --a------ c:\windows\StillCap.exe
2009-03-14 13:46 . 2002-10-16 12:29 49,152 --a------ c:\windows\amcap.exe
2009-03-13 17:10 . 2009-03-18 16:39 d-------- c:\documents and settings\Administrator
2009-03-11 15:17 . 2009-03-14 16:47 d-------- c:\program files\7-Zip
2009-03-11 12:49 . 2009-03-14 22:21 d-------- c:\program files\Paint.NET
2009-03-11 10:14 . 2009-03-11 13:07 d----c--- c:\windows\system32\DRVSTORE
2009-03-11 10:14 . 2009-03-11 10:14 d-------- c:\documents and settings\user\Application Data\InstallShield
2009-03-11 09:44 . 2009-03-11 13:07 d-------- c:\program files\SanDisk
2009-03-11 09:44 . 2005-05-26 18:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2009-03-11 09:44 . 2008-10-14 15:01 14,608 --a------ c:\windows\system32\iviaspi.sys
2009-03-10 21:20 . 2009-03-10 21:20 d-------- c:\documents and settings\user\Application Data\gtk-2.0
2009-03-10 21:20 . 2009-03-10 21:20 d-------- c:\documents and settings\user\.thumbnails
2009-03-10 21:16 . 2009-03-10 21:24 d-------- c:\documents and settings\user\.gimp-2.6
2009-03-10 21:16 . 2009-03-10 21:16 d-------- c:\documents and settings\user\.gegl-0.0
2009-03-10 21:13 . 2009-03-18 18:41 d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-03-10 13:10 . 2009-03-10 13:10 d-------- c:\documents and settings\user\Application Data\Yahoo!
2009-03-10 13:08 . 2009-03-11 13:06 d-------- c:\program files\Yahoo!
2009-03-10 13:08 . 2009-03-10 13:11 d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-10 13:01 . 2009-03-10 13:01 d-------- c:\documents and settings\user\Application Data\acccore
2009-03-10 13:00 . 2009-03-18 23:27 d-------- c:\documents and settings\All Users\Application Data\Viewpoint
2009-03-10 13:00 . 2009-03-10 13:00 d-------- c:\documents and settings\All Users\Application Data\AOL OCP
2009-03-10 13:00 . 2009-03-10 13:00 d-------- c:\documents and settings\All Users\Application Data\AOL
2009-03-10 13:00 . 2009-03-10 13:00 d-------- c:\documents and settings\All Users\Application Data\acccore
2009-03-10 12:59 . 2009-03-10 12:59 d-------- c:\program files\Common Files\AOL
2009-03-10 12:59 . 2009-03-10 13:00 d-------- c:\program files\AIM6
2009-03-10 12:58 . 2009-03-10 13:00 459 --ah----- C:\IPH.PH
2009-03-10 12:29 . 2009-03-10 12:29 d-------- c:\program files\Microsoft
2009-03-10 12:29 . 2009-03-19 05:19 d-------- c:\documents and settings\user\Tracing
2009-03-10 12:28 . 2009-03-10 12:28 d-------- c:\program files\Windows Live SkyDrive
2009-03-10 12:28 . 2009-03-10 12:28 d-------- c:\program files\Windows Live
2009-03-10 12:24 . 2009-03-10 12:24 d-------- c:\program files\Common Files\Windows Live
2009-03-10 11:22 . 2008-04-13 14:45 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2009-03-10 11:13 . 1999-12-12 13:01 44,032 --------- c:\windows\system32\CTSVCCDA.EXE
2009-03-10 11:13 . 1999-11-17 13:00 25,088 --------- c:\windows\system32\CTSVCCTL.EXE
2009-03-10 11:12 . 2009-03-10 11:14 d--h----- c:\program files\Creative Installation Information
2009-03-10 11:12 . 2009-03-10 11:12 d-------- c:\program files\Common Files\Creative
2009-03-10 11:10 . 2009-03-10 11:21 d-------- c:\documents and settings\user\Application Data\Creative
2009-03-10 11:07 . 2009-03-10 11:19 d-------- c:\documents and settings\All Users\Application Data\Creative
2009-03-10 11:03 . 2000-05-21 20:58 647,872 --------- c:\windows\system32\Mscomct2.ocx
2009-03-10 11:03 . 2006-10-05 18:17 53,248 --------- c:\windows\Ctregrun.exe
2009-03-10 11:02 . 2009-03-10 11:21 d-------- c:\program files\Creative
2009-03-10 10:59 . 2009-03-10 10:59 d-------- c:\windows\system32\LogFiles
2009-03-10 10:59 . 2009-03-10 11:04 d-------- c:\windows\system32\drivers\UMDF
2009-03-10 10:57 . 2009-03-14 16:47 d--h----- c:\program files\InstallShield Installation Information
2009-03-10 10:57 . 2009-03-11 09:43 d-------- c:\program files\Common Files\InstallShield
2009-03-10 10:27 . 2009-03-10 10:27 d--hs---- c:\documents and settings\user\IECompatCache
2009-03-10 10:26 . 2009-03-10 10:26 d--hs---- c:\documents and settings\user\PrivacIE
2009-03-10 10:26 . 2009-03-10 10:26 d--hs---- c:\documents and settings\user\IETldCache
2009-03-10 10:20 . 2009-03-10 10:20 d-------- c:\windows\ie8updates
2009-03-10 10:17 . 2009-03-10 10:18 d--h-c--- c:\windows\ie8
2009-03-10 10:13 . 2009-01-11 01:00 79,360 -----c--- c:\windows\system32\dllcache\iecompat.dll
2009-03-10 02:28 . 2009-03-10 02:28 d-------- c:\documents and settings\user\Application Data\Apple Computer
2009-03-09 23:20 . 2009-02-09 07:13 1,846,784 -----c--- c:\windows\system32\dllcache\win32k.sys
2009-03-09 22:21 . 2009-03-09 22:21 d-------- c:\documents and settings\user\Application Data\MPEG Streamclip
2009-03-09 22:17 . 2009-03-09 22:18 d-------- c:\program files\QuickTime
2009-03-09 22:17 . 2009-03-09 22:17 d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-09 22:16 . 2009-03-09 22:16 d-------- c:\program files\Apple Software Update
2009-03-09 22:16 . 2009-03-09 22:16 d-------- c:\documents and settings\All Users\Application Data\Apple
2009-03-09 21:43 . 2009-03-09 21:43 d-------- c:\program files\Auslogics
2009-03-09 21:43 . 2009-03-09 21:43 d-------- c:\documents and settings\user\Application Data\Auslogics
2009-03-09 21:40 . 2005-08-25 21:19 115,920 --a------ c:\windows\system32\MSINET.OCX
2009-03-09 21:34 . 2009-03-09 21:34 25,304 --a------ c:\windows\system32\EclipseHook.chm
2009-03-09 21:32 . 2009-03-15 15:11 d-------- c:\program files\AoA Audio Extractor
2009-03-09 21:28 . 2009-03-18 16:53 d--h----- C:\$AVG8.VAULT$
2009-03-09 21:17 . 2009-01-15 05:12 10,963,968 --a--c--- c:\windows\system32\dllcache\ieframe.dll
2009-03-09 21:17 . 2008-12-14 20:12 3,698,040 --a--c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-03-09 21:17 . 2009-01-15 05:02 1,975,296 --a--c--- c:\windows\system32\dllcache\iertutil.dll
2009-03-09 21:17 . 2009-01-15 05:22 1,228,800 --a--c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-09 21:17 . 2009-01-15 05:02 593,920 --a--c--- c:\windows\system32\dllcache\msfeeds.dll
2009-03-09 21:17 . 2009-01-15 04:35 445,440 --a--c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-03-09 21:17 . 2009-01-15 05:01 59,904 --a--c--- c:\windows\system32\dllcache\icardie.dll
2009-03-09 21:17 . 2009-01-15 05:01 54,272 --a--c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-09 21:17 . 2008-12-19 05:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-03-09 21:15 . 2009-03-09 21:15 325,640 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-09 21:15 . 2009-03-09 21:15 107,912 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-09 21:15 . 2009-03-09 21:15 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-09 21:14 . 2009-03-19 13:05 d-------- c:\windows\system32\drivers\Avg
2009-03-09 21:14 . 2009-03-09 21:14 d-------- c:\program files\AVG
2009-03-09 21:14 . 2009-03-09 21:14 d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-09 20:50 . 2009-03-09 20:50 d-------- c:\windows\system32\scripting
2009-03-09 20:50 . 2009-03-09 20:50 d-------- c:\windows\system32\en
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-07 01:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-03 22:30 237,568 ----a-w c:\windows\system32\config\systemprofile\NTUSER(2).DAT
2009-02-02 23:51 --------- d-----w c:\program files\Microsoft ActiveSync
2009-02-02 23:01 --------- d-----w c:\program files\VideoLAN
2009-02-02 22:38 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-02-02 22:38 348,160 ----a-w c:\windows\system32\msvcr71.dll
2009-02-02 22:34 --------- d-----w c:\program files\DivX
2009-02-02 22:26 --------- d-----w c:\program files\Common Files\Adobe
2009-01-30 23:26 --------- d-----w c:\program files\microsoft frontpage
2009-01-15 09:05 911,872 ----a-w c:\windows\system32\wininet.dll
2009-01-15 09:05 43,008 ----a-w c:\windows\system32\licmgr10.dll
2009-01-15 09:04 18,944 ----a-w c:\windows\system32\corpol.dll
2009-01-15 09:03 72,704 ----a-w c:\windows\system32\admparse.dll
2009-01-15 09:03 71,680 ----a-w c:\windows\system32\iesetup.dll
2009-01-15 09:03 420,352 ----a-w c:\windows\system32\vbscript.dll
2009-01-15 09:01 34,304 ----a-w c:\windows\system32\imgutil.dll
2009-01-15 09:00 48,128 ----a-w c:\windows\system32\mshtmler.dll
2009-01-15 09:00 45,568 ----a-w c:\windows\system32\mshta.exe
2009-01-15 08:50 156,160 ----a-w c:\windows\system32\msls31.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-04-01 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-04-01 126976]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-09 1932568]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"CTCheck"="c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-09 21:15 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"aspnet_state"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-09 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-03-09 107912]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-09 298264]
S3 zsi_fmw;Sansa Connect Firmware Recovery;c:\windows\system32\Drivers\zsi_fmw.sys --> c:\windows\system32\Drivers\zsi_fmw.sys [?]
S3 zsi_zap;Sansa Connect ZAP Recovery Driver;c:\windows\system32\Drivers\zsi_zap.sys --> c:\windows\system32\Drivers\zsi_zap.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-03-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 15:34]
2009-03-20 c:\windows\Tasks\User_Feed_Synchronization-{B409C876-6E01-4CD1-847F-D9947924312D}.job
- c:\windows\system32\msfeedssync.exe [2009-01-15 05:01]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
.
------- File Associations -------
.
inffile=c:\windows\System32\NOTEPAD.EXE "%1"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-20 03:32:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-03-20 3:35:13
ComboFix-quarantined-files.txt 2009-03-20 07:35:10
ComboFix2.txt 2009-03-19 18:55:53
ComboFix3.txt 2009-03-19 18:29:22
Pre-Run: 33,322,983,424 bytes free
Post-Run: 33,318,719,488 bytes free
232 --- E O F --- 2009-03-14 19:59:09