ComboFix 09-07-23.01 - Shaun 07/23/2009 15:44.1.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1624 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} FW: Trend Micro Personal Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\COUPON~1.OCX c:\windows\CouponPrinter.ocx c:\windows\Installer\13db0.msi c:\windows\Installer\13db6.msi c:\windows\Installer\13dbb.msi c:\windows\Installer\a1b9400.msi c:\windows\run.log c:\windows\system32\drivers\hjgruicvxyurhc.sys c:\windows\system32\hjgruihaoamdlu.dll c:\windows\system32\hjgruikbxvqoiv.dat c:\windows\system32\hjgruiwylnqykn.dll c:\windows\system32\hjgruiypqytrnx.dat c:\windows\system32\UACkkvqtudrikdwvjnms.dat c:\windows\system32\UACptlwfosnliawgwfxn.db . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_hjgruieidgguro ((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 ))))))))))))))))))))))))))))))) . 2009-07-22 20:27 . 2009-07-22 20:27 -------- d-----w- C:\rsit 2009-07-17 16:26 . 2009-07-17 16:26 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-07-17 16:25 . 2009-07-17 16:25 152576 ----a-w- c:\documents and settings\Shaun\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-07-16 17:47 . 2009-07-16 17:47 3775176 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-07-16 00:38 . 2009-07-16 00:44 -------- d-----w- C:\temp 2009-07-14 18:09 . 2008-04-14 00:12 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll 2009-07-14 18:09 . 2001-08-18 02:36 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll 2009-07-14 18:09 . 2008-04-14 00:12 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll 2009-07-14 18:09 . 2001-08-18 02:37 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe 2009-07-14 18:09 . 2001-08-18 02:37 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe 2009-07-14 18:09 . 2001-08-18 02:37 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe 2009-07-14 18:09 . 2001-08-17 16:11 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys 2009-07-14 18:09 . 2004-08-04 02:29 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys 2009-07-14 18:09 . 2004-08-04 02:29 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys 2009-07-14 18:07 . 2001-08-17 16:13 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys 2009-07-14 18:06 . 2001-08-17 17:28 794654 ----a-w- c:\windows\system32\dllcache\usr1801.sys 2009-07-14 18:05 . 2001-08-17 16:51 166784 ----a-w- c:\windows\system32\dllcache\tridxpm.sys 2009-07-14 18:04 . 2001-08-17 16:51 138528 ----a-w- c:\windows\system32\dllcache\tgiulnt5.sys 2009-07-14 18:03 . 2001-08-18 02:36 41472 ----a-w- c:\windows\system32\dllcache\sw_effct.dll 2009-07-14 18:02 . 2001-08-18 02:36 7168 ----a-w- c:\windows\system32\dllcache\EXCH_snprfdll.dll 2009-07-14 18:01 . 2001-08-17 16:12 94698 ----a-w- c:\windows\system32\dllcache\sk98xwin.sys 2009-07-14 18:00 . 2001-08-17 17:48 17664 ----a-w- c:\windows\system32\dllcache\sermouse.sys 2009-07-14 17:59 . 2001-08-18 02:36 62496 ----a-w- c:\windows\system32\dllcache\s3mtrio.dll 2009-07-14 17:58 . 2001-08-17 17:28 714762 ----a-w- c:\windows\system32\dllcache\r2mdmkxx.sys 2009-07-14 17:57 . 2001-08-17 18:07 19840 ----a-w- c:\windows\system32\dllcache\philtune.sys 2009-07-14 17:56 . 2001-08-17 18:05 25216 ----a-w- c:\windows\system32\dllcache\ovsound2.sys 2009-07-14 17:55 . 2001-08-17 17:47 9344 ----a-w- c:\windows\system32\dllcache\ntapm.sys 2009-07-14 17:54 . 2001-08-17 16:11 128000 ----a-w- c:\windows\system32\dllcache\n100325.sys 2009-07-14 17:53 . 2001-08-17 17:52 6528 ----a-w- c:\windows\system32\dllcache\miniqic.sys 2009-07-14 17:52 . 2001-08-17 16:12 70730 ----a-w- c:\windows\system32\dllcache\lne100tx.sys 2009-07-14 17:51 . 2008-04-14 00:12 151552 ----a-w- c:\windows\system32\dllcache\irftp.exe 2009-07-14 17:50 . 2001-08-18 02:34 9216 ----a-w- c:\windows\system32\dllcache\ibmsgnet.dll 2009-07-14 17:49 . 2001-08-17 17:52 5760 ----a-w- c:\windows\system32\dllcache\hpt4qic.sys 2009-07-14 17:48 . 2001-08-17 16:49 322432 ----a-w- c:\windows\system32\dllcache\g400m.sys 2009-07-14 17:47 . 2001-08-18 02:36 45568 ----a-w- c:\windows\system32\dllcache\esunib.dll 2009-07-14 17:46 . 2001-08-17 16:11 66591 ----a-w- c:\windows\system32\dllcache\el90xbc5.sys 2009-07-14 17:45 . 2001-08-17 16:13 37735 ----a-w- c:\windows\system32\dllcache\digiasyn.sys 2009-07-14 17:44 . 2001-08-17 18:56 170880 ----a-w- c:\windows\system32\dllcache\cl546x.dll 2009-07-14 17:43 . 2001-08-18 02:36 102400 ----a-w- c:\windows\system32\dllcache\binlsvc.dll 2009-07-13 03:32 . 2009-07-13 03:33 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google 2009-07-13 03:00 . 2009-03-24 20:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-07-13 01:14 . 2009-07-23 19:54 117760 ----a-w- c:\documents and settings\Shaun\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-07-13 01:13 . 2009-07-13 01:13 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-07-13 01:07 . 2009-07-13 01:12 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-07-13 01:07 . 2009-07-13 01:07 -------- d-----w- c:\documents and settings\Shaun\Application Data\SUPERAntiSpyware.com 2009-07-13 01:07 . 2009-07-13 01:07 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-07-11 16:45 . 2009-07-11 16:45 -------- d-----w- c:\documents and settings\Shaun\Application Data\Malwarebytes 2009-07-11 16:40 . 2009-07-13 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-11 16:40 . 2009-07-22 14:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-07-11 16:40 . 2009-07-13 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-07-11 16:40 . 2009-07-11 16:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-11 16:24 . 2009-07-11 16:24 -------- d-----w- c:\program files\CCleaner . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-22 14:27 . 2009-03-22 18:51 -------- d-----w- c:\program files\Microsoft Silverlight 2009-07-17 16:38 . 2007-12-28 09:08 -------- d-----w- c:\program files\Trend Micro 2009-07-17 16:26 . 2007-12-28 08:55 -------- d-----w- c:\program files\Java 2009-07-14 01:35 . 2008-09-07 23:56 10752 ----a-w- c:\windows\DCEBoot.exe 2009-06-21 13:23 . 2009-06-21 13:23 -------- d-----w- c:\documents and settings\Shaun\Application Data\Sonic Solutions 2009-06-16 14:36 . 2004-08-10 18:51 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-06-16 14:36 . 2004-08-10 18:51 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-06-10 17:12 . 2007-12-28 09:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-03 19:09 . 2004-08-10 18:51 1291264 ----a-w- c:\windows\system32\quartz.dll 2009-06-02 17:44 . 2008-10-25 15:35 1915520 ----a-w- c:\documents and settings\Shaun\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe 2009-05-22 05:02 . 2008-08-19 02:21 225296 ----a-w- c:\windows\system32\drivers\tmxpflt.sys 2009-05-22 05:00 . 2008-08-19 02:21 36368 ----a-w- c:\windows\system32\drivers\tmpreflt.sys 2009-05-22 04:45 . 2008-08-19 02:21 1220120 ----a-w- c:\windows\system32\drivers\vsapint.sys 2009-05-07 15:32 . 2004-08-10 18:51 345600 ----a-w- c:\windows\system32\localspl.dll 2009-04-29 04:56 . 2004-08-10 18:51 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2004-08-10 18:51 78336 ----a-w- c:\windows\system32\ieencode.dll 2007-12-28 08:59 . 2007-12-28 08:59 76 --sh--r- c:\windows\CT4CET.bin . ------- Sigcheck ------- [7] 2004-08-04 11:00 24576 39B1FFB03C2296323832ACBAE50D2AFF c:\windows\$NtServicePackUninstall$\userinit.exe [7] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\ServicePackFiles\i386\userinit.exe [-] 2008-04-14 00:12 26112 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\userinit.exe [-] 2008-04-14 00:12 26112 !HASH: COULD NOT OPEN FILE !!!!! c:\windows\system32\dllcache\userinit.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-28 68856] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\Shaun.exe" [2009-06-23 1830128] "OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2008-08-19 492808] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-10 851968] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-10 137752] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-10 162328] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-10 137752] "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-08-28 36864] "DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-09 2183168] "KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2007-08-30 205480] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184] "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-28 1838592] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-10 16384] "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-09-22 1398024] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648] "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393] "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960] "SetDefPrt"="c:\program files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 49152] "ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-01-07 864256] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-11 342312] "BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-03-26 615696] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-17 148888] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2007-07-10 405504] c:\documents and settings\Shaun\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-12-28 50688] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"= "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944] R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088] R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [8/18/2008 10:30 PM 52624] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [8/18/2008 10:21 PM 36368] R3 OEM02Afx;Provides a software interface to control audio effects of OEM002 camera.;c:\windows\system32\drivers\OEM02Afx.sys [12/28/2007 4:32 AM 141376] R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [12/28/2007 4:32 AM 235520] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [12/28/2007 4:32 AM 7424] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408] R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [8/18/2008 10:21 PM 333328] R3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [8/18/2008 10:31 PM 488768] R3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [8/18/2008 10:31 PM 648456] S2 rjldydf;rjldydf;c:\windows\system32\drivers\ksuliwo.sys --> c:\windows\system32\drivers\ksuliwo.sys [?] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3071228 uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 Trusted Zone: turbotax.com . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-23 15:53 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1292) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\System32\BCMLogon.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\WLTRYSVC.EXE c:\windows\system32\BCMWLTRY.EXE c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Photodex\ProShowGold\scsiaccess.exe c:\program files\Trend Micro\Internet Security\SfCtlCom.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\windows\system32\wdfmgr.exe c:\program files\Trend Micro\BM\TMBMSRV.exe c:\windows\system32\wscntfy.exe c:\windows\system32\igfxsrvc.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe c:\program files\Trend Micro\Internet Security\UfUpdUi.exe c:\program files\Trend Micro\Internet Security\SfFnUp.exe . ************************************************************************** . Completion time: 2009-07-23 16:01 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-23 20:01 Pre-Run: 23,695,298,560 bytes free Post-Run: 26,931,302,400 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect 244 --- E O F --- 2009-07-22 14:23