ComboFix 09-10-04.01 - Owner 10/04/2009 19:56.1.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.511.170 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Installer\123ee.msi c:\windows\Installer\195ea.msi c:\windows\system32\iAlmcoin.dll c:\windows\system32\ps2.bat D:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2009-09-04 to 2009-10-04 ))))))))))))))))))))))))))))))) . 2009-10-04 23:42 . 2009-10-04 23:42 -------- d-----w- c:\program files\Trend Micro 2009-10-04 13:04 . 2004-03-30 01:48 40960 -c----w- c:\windows\system32\dllcache\evtgprov.dll 2009-10-04 13:04 . 2004-03-30 01:48 73728 -c--a-w- c:\windows\system32\dllcache\nmcom.dll 2009-10-04 13:04 . 2004-03-30 01:48 548352 -c--a-w- c:\windows\system32\dllcache\rtcdll.dll 2009-10-04 13:04 . 2004-03-30 01:48 548352 ----a-w- c:\windows\system32\rtcdll.dll 2009-10-04 13:04 . 2004-03-30 01:48 253952 -c--a-w- c:\windows\system32\dllcache\mst120.dll 2009-10-04 13:04 . 2004-03-30 01:48 593408 -c--a-w- c:\windows\system32\dllcache\h323msp.dll 2009-10-04 13:04 . 2004-03-30 01:48 593408 ----a-w- c:\windows\system32\h323msp.dll 2009-10-04 13:04 . 2004-03-30 01:48 439808 -c--a-w- c:\windows\system32\dllcache\ipnathlp.dll 2009-10-04 13:04 . 2004-03-30 01:48 439808 ----a-w- c:\windows\system32\ipnathlp.dll 2009-10-04 13:04 . 2004-03-30 01:48 364544 -c--a-w- c:\windows\system32\dllcache\callcont.dll 2009-10-04 13:02 . 2004-04-11 04:04 593408 -c----w- c:\windows\system32\dllcache\xpsp2res.dll 2009-10-04 12:51 . 2002-12-12 14:34 208896 ----a-w- c:\windows\system32\wmpns.dll 2009-10-04 08:38 . 2004-02-14 05:02 -------- d---a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft 2009-10-04 08:38 . 2001-08-17 20:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys 2009-10-04 08:38 . 2002-08-29 10:40 20480 ----a-w- c:\windows\system32\hidserv.dll 2009-10-04 08:38 . 2001-08-17 21:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys 2009-10-04 08:38 . 2001-08-17 20:48 13952 ----a-w- c:\windows\system32\drivers\kbdhid.sys 2009-10-04 08:38 . 2002-08-29 08:32 28160 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2009-10-04 08:37 . 2001-08-17 19:12 16074 ----a-w- c:\windows\system32\drivers\FA312nd5.sys 2009-10-04 07:29 . 2009-10-04 23:41 248 ----a-w- c:\windows\system\hpsysdrv.dat 2009-10-04 07:17 . 2009-10-04 23:41 -------- dcsha-r- c:\windows\system32\dllcache 2009-10-04 04:28 . 2004-09-01 22:27 209280 -c--a-w- c:\windows\system32\dllcache\update.sys 2009-10-04 04:28 . 2005-10-20 22:33 991232 ----a-w- c:\windows\system32\esent.dll 2009-10-04 04:27 . 2009-10-04 04:27 260096 -c--a-w- c:\windows\system32\dllcache\mstask.dll 2009-10-04 04:27 . 2009-10-04 04:27 260096 ----a-w- c:\windows\system32\mstask.dll 2009-10-04 04:27 . 2009-10-04 04:27 172544 -c--a-w- c:\windows\system32\dllcache\schedsvc.dll 2009-10-04 04:27 . 2009-10-04 04:27 172544 ----a-w- c:\windows\system32\schedsvc.dll 2009-10-04 04:27 . 2009-10-04 04:27 10752 -c--a-w- c:\windows\system32\dllcache\mstinit.exe 2009-10-04 04:27 . 2009-10-04 04:27 10752 ----a-w- c:\windows\system32\mstinit.exe 2009-10-04 04:27 . 2006-07-14 15:53 307200 -c--a-w- c:\windows\system32\dllcache\netapi32.dll 2009-10-04 04:05 . 2009-10-04 04:05 -------- d-----w- c:\documents and settings\LocalService\Application Data\SiteAdvisor 2009-10-04 04:04 . 2009-10-04 04:06 -------- d-----w- c:\program files\SiteAdvisor 2009-10-04 04:04 . 2009-10-04 04:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SiteAdvisor 2009-10-04 04:04 . 2009-10-04 04:04 -------- d-----w- c:\documents and settings\Owner\Application Data\SiteAdvisor 2009-10-04 04:03 . 2007-11-22 10:44 33832 ----a-w- c:\windows\system32\drivers\mferkdk.sys 2009-10-04 04:03 . 2007-12-02 16:51 40488 ----a-w- c:\windows\system32\drivers\mfesmfk.sys 2009-10-04 04:03 . 2007-11-22 10:44 79304 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2009-10-04 04:03 . 2007-11-22 10:44 35240 ----a-w- c:\windows\system32\drivers\mfebopk.sys 2009-10-04 04:03 . 2007-11-22 10:44 201320 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2009-10-04 04:03 . 2007-07-13 13:20 113952 ----a-w- c:\windows\system32\drivers\Mpfp.sys 2009-10-04 04:02 . 2009-10-04 04:03 -------- d-----w- c:\program files\McAfee.com 2009-10-04 04:02 . 2009-10-04 04:03 -------- d-----w- c:\program files\Common Files\McAfee 2009-10-04 04:02 . 2009-10-04 23:41 -------- d-----w- c:\program files\McAfee 2009-10-04 04:02 . 2005-06-28 14:21 22752 ----a-w- c:\windows\system32\spupdsvc.exe 2009-10-04 04:02 . 2009-10-04 12:52 -------- d--h--w- c:\windows\$hf_mig$ 2009-10-04 04:01 . 2009-10-04 04:01 -------- d-----w- c:\windows\system32\bits 2009-10-04 04:00 . 2004-07-01 22:08 7680 -c----w- c:\windows\system32\dllcache\bitsprx2.dll 2009-10-04 04:00 . 2004-07-01 22:08 7680 ------w- c:\windows\system32\bitsprx2.dll 2009-10-04 04:00 . 2004-07-01 22:08 7168 -c----w- c:\windows\system32\dllcache\bitsprx3.dll 2009-10-04 04:00 . 2004-07-01 22:08 7168 ------w- c:\windows\system32\bitsprx3.dll 2009-10-04 04:00 . 2004-07-01 22:08 361984 -c--a-w- c:\windows\system32\dllcache\qmgr.dll 2009-10-04 04:00 . 2004-07-01 22:08 331776 -c--a-w- c:\windows\system32\dllcache\winhttp.dll 2009-10-04 04:00 . 2004-07-01 22:08 331776 ----a-w- c:\windows\system32\winhttp.dll 2009-10-04 04:00 . 2004-07-01 22:08 17408 -c--a-w- c:\windows\system32\dllcache\qmgrprxy.dll 2009-10-04 04:00 . 2004-07-01 22:08 17408 ----a-w- c:\windows\system32\qmgrprxy.dll 2009-10-04 03:59 . 2009-10-04 04:05 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-10-04 03:58 . 2008-10-16 18:13 202776 ----a-w- c:\windows\system32\wuweb.dll 2009-10-04 03:58 . 2008-10-16 18:12 323608 ----a-w- c:\windows\system32\wucltui.dll 2009-10-04 03:58 . 2008-10-16 18:12 561688 ----a-w- c:\windows\system32\wuapi.dll 2009-10-04 03:58 . 2008-10-16 18:08 34328 ----a-w- c:\windows\system32\wups.dll 2009-10-04 03:58 . 2004-08-03 18:03 186136 ----a-w- c:\windows\system32\wuaueng1.dll 2009-10-04 03:58 . 2004-08-03 18:01 167704 ----a-w- c:\windows\system32\wuauclt1.exe 2009-10-04 03:53 . 2009-10-04 03:53 -------- d-s---w- c:\documents and settings\Owner\UserData 2009-10-04 03:48 . 2009-10-04 03:48 -------- d-----w- C:\WUTemp 2009-10-04 03:48 . 2003-08-25 22:06 182880 ----a-w- c:\windows\system32\iuenginenew.dll 2009-10-04 03:48 . 2009-10-04 03:48 -------- d-----w- c:\documents and settings\Owner\Application Data\Creative 2009-10-04 03:47 . 2003-10-11 12:31 128 ----a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\fusioncache.dat 2009-10-04 03:47 . 2003-10-14 12:24 -------- d---a-w- c:\windows\system32\config\systemprofile\Application Data\interMute 2009-10-04 03:47 . 2003-10-14 12:21 -------- d---a-w- c:\windows\system32\config\systemprofile\Application Data\Symantec 2009-10-04 03:47 . 2003-10-11 12:47 -------- d---a-w- c:\windows\system32\config\systemprofile\Application Data\SampleView 2009-10-04 03:47 . 2003-10-11 12:31 -------- d---a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory 2009-10-04 03:47 . 2003-10-11 12:19 -------- d---a-w- c:\windows\system32\config\systemprofile\WINDOWS 2009-10-04 03:47 . 2003-10-11 11:57 -------- d---a-w- c:\windows\system32\config\systemprofile\Application Data\Sonic 2009-10-04 03:47 . 2003-10-11 10:09 -------- d---a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000} 2009-10-04 03:46 . 2003-10-21 23:06 32256 -c--a-w- c:\windows\system32\dllcache\msgsvc.dll 2009-10-04 03:46 . 2003-10-21 23:06 32256 ----a-w- c:\windows\system32\msgsvc.dll 2009-10-04 03:45 . 2003-09-03 14:01 10368 ----a-w- c:\windows\system32\drivers\pfc.sys 2009-10-04 03:45 . 2003-04-03 15:09 1630208 ----a-w- c:\windows\system32\mplvw7.dll 2009-10-04 03:45 . 2003-04-03 15:09 1150976 ----a-w- c:\windows\system32\mplvpx.dll 2009-10-04 03:45 . 2003-04-03 15:09 81920 ----a-w- c:\windows\system32\mplaw7.dll 2009-10-04 03:45 . 2003-04-03 15:09 81920 ----a-w- c:\windows\system32\mplaa6.dll 2009-10-04 03:45 . 2003-04-03 15:09 69632 ----a-w- c:\windows\system32\mplapx.dll 2009-10-04 03:45 . 2003-04-03 15:09 69632 ----a-w- c:\windows\system32\mplam6.dll 2009-10-04 03:45 . 2003-04-03 15:09 49152 ----a-w- c:\windows\system32\cpuinf32.dll 2009-10-04 03:45 . 2003-04-03 15:09 1675264 ----a-w- c:\windows\system32\mplva6.dll 2009-10-04 03:45 . 2003-04-03 15:09 1581056 ----a-w- c:\windows\system32\mplvm6.dll 2009-10-04 03:45 . 1995-07-31 17:44 212480 ----a-w- c:\windows\PCDLIB32.DLL 2009-10-04 03:45 . 2009-10-04 03:45 -------- d-----w- c:\program files\ArcSoft 2009-10-04 03:43 . 2002-10-09 05:09 10477 ------w- c:\windows\system32\pfmodnt.sys 2009-10-04 03:43 . 2009-10-04 03:43 -------- d-----w- c:\program files\Multimedia Card Reader 2009-10-04 03:42 . 2009-10-04 03:42 -------- d-----w- c:\windows\Downloaded Installations 2009-10-04 03:42 . 2001-08-17 17:58 25472 ----a-w- c:\windows\system32\drivers\AGP440.SYS 2009-10-04 03:42 . 2002-08-29 05:32 135552 ----a-w- c:\windows\system32\drivers\usbport.sys 2009-10-04 03:42 . 2002-08-29 05:32 19328 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2009-10-04 03:42 . 2001-08-18 02:36 67072 ----a-w- c:\windows\system32\usbui.dll 2009-10-04 03:42 . 2002-08-29 05:32 51968 ----a-w- c:\windows\system32\drivers\usbhub.sys 2009-10-04 03:42 . 2002-10-24 19:59 87040 ----a-w- c:\windows\system32\drivers\atapi.sys 2009-10-04 03:42 . 2002-08-29 05:27 23680 ----a-w- c:\windows\system32\drivers\pciidex.sys 2009-10-04 03:42 . 2001-08-17 17:51 3328 ----a-w- c:\windows\system32\drivers\pciide.sys 2009-10-04 03:41 . 2002-08-29 05:09 62976 ----a-w- c:\windows\system32\drivers\pci.sys 2009-10-04 03:41 . 2001-08-17 17:58 35840 ----a-w- c:\windows\system32\drivers\isapnp.sys 2009-10-04 03:40 . 2003-10-11 12:19 -------- d---a-w- c:\documents and settings\Default User\WINDOWS . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-04 13:10 . 2004-02-14 04:55 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-0000000A-00001102-00000004-10091102}.dat 2009-10-04 13:10 . 2004-02-14 04:55 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-0000000A-00001102-00000004-10091102}.dat 2009-10-04 04:01 . 2003-10-14 12:21 -------- d---a-w- c:\documents and settings\All Users\Application Data\Symantec 2009-10-04 03:49 . 2009-10-04 03:49 3974 --sha-r- c:\windows\system32\drivers\HP_D7222M-ABA A450Y_YW_Pavi_QMXP407_E41NAheBLU4_4_I P4SD-LA _SASUSTeK Computer INC._VRev 1.xx_B3.20_T040128_WXH1_L409_M512_J164_7Intel_8Pentium 4_93_1104C8023_N100B0020_P_Z_K_A11020004_U808624D2_G10DE0322_O_DHWP2585.MRK 2009-10-04 03:45 . 2003-10-11 12:02 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-10-04 03:44 . 2009-10-04 03:43 -------- d-----w- c:\program files\Creative 2009-10-04 03:44 . 2009-10-04 03:44 184 ----a-w- c:\windows\system32\e000001.dat . ------- Sigcheck ------- [-] 2002-11-27 16:03 . 36678803A8030EE9A771935CFC1848BD . 52224 . . [9.0.1.56] . . c:\windows\system32\mspmsnsv.dll c:\windows\system32\wscntfy.exe ... is missing !! c:\windows\system32\xmlprov.dll ... is missing !! . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-11-15 1670144] "NVIEW"="nview.dll" - c:\windows\system32\nview.dll [2003-08-19 852038] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-08-19 4841472] "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-08 52736] "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688] "CamMonitor"="c:\program files\HP\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 90112] "HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-05-23 483328] "KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440] "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-11-04 45056] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-10-11 151597] "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992] "PS2"="c:\windows\system32\ps2.exe" [2002-10-17 81920] "Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2003-08-15 139264] "CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152] "CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "Reminder"="c:\windows\Creator\Remind_XP.exe" [2003-06-18 118784] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-04 582992] "SiteAdvisor"="c:\program files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-24 36640] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-08-19 323584] "CTHelper"="CTHELPER.EXE" - c:\windows\system32\cthelper.exe [2003-05-29 28672] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "CMSRegOW.exe"="c:\program files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\CMSRegOW.exe" [2003-06-16 57344] "SetDefaultMidi"="MIDIDEF.EXE" - c:\windows\mididef.exe [2002-12-04 49152] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-7-7 45056] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" S2 mrtRate;mrtRate; [x] . Contents of the 'Scheduled Tasks' folder 2009-10-04 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-04 17:32] 2009-10-04 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-04 17:32] . . ------- Supplementary Scan ------- . uStart Page = hxxp://us10.hpwis.com/ uDefault_Search_URL = hxxp://srch-us10.hpwis.com/ mStart Page = hxxp://us10.hpwis.com/ mSearch Bar = hxxp://srch-us10.hpwis.com/ uInternet Settings,ProxyOverride = localhost IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm LSP: SpSubLSP.dll . - - - - ORPHANS REMOVED - - - - HKCU-Run-RecordNow! - (no file) HKLM-Run-HPHUPD05 - c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe HKLM-Run-VTTimer - VTTimer.exe AddRemove-Creative Driver - c:\windows\System32\ctdrvins ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-04 20:00 Windows 5.1.2600 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(552) c:\windows\system32\ODBC32.dll - - - - - - - > 'lsass.exe'(616) c:\windows\system32\SpSubLSP.dll c:\windows\System32\dssenh.dll . Completion time: 2009-10-05 20:01 ComboFix-quarantined-files.txt 2009-10-05 00:01 Pre-Run: 141,927,772,160 bytes free Post-Run: 141,979,017,216 bytes free 217 --- E O F --- 2009-10-04 13:09