ComboFix 09-12-05.02 - Todd 12/05/2009 16:21.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3063.2292 [GMT -7:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\TEMP\logishrd\LVPrcInj01.dll . ((((((((((((((((((((((((( Files Created from 2009-11-05 to 2009-12-05 ))))))))))))))))))))))))))))))) . 2009-12-01 18:34 . 2009-12-01 06:54 15880 ----a-w- c:\windows\system32\lsdelete.exe 2009-12-01 15:37 . 2009-12-05 23:41 -------- d-----w- c:\windows\system32\CatRoot2 2009-12-01 06:52 . 2009-12-01 06:52 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6} 2009-12-01 06:52 . 2009-10-03 08:15 2924848 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe 2009-12-01 06:51 . 2009-12-01 06:51 -------- d-----w- c:\program files\Lavasoft 2009-12-01 05:53 . 2009-12-01 06:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-12-01 05:53 . 2009-12-01 05:59 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-12-01 04:28 . 2009-12-01 04:28 -------- d-----w- c:\windows\system32\wbem\Repository 2009-12-01 04:13 . 2009-12-01 04:13 -------- d--h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864} 2009-12-01 04:12 . 2009-12-01 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion 2009-11-25 01:20 . 2009-11-25 01:20 -------- d-----w- c:\program files\Enigma Software Group 2009-11-23 23:20 . 2009-11-23 23:20 -------- d-----w- c:\program files\Trend Micro 2009-11-23 19:36 . 2009-11-23 21:07 358432 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-11-23 19:36 . 2009-11-23 21:07 22048 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-11-20 12:29 . 2009-11-20 12:29 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-11-11 05:12 . 2009-11-11 05:12 -------- d-----w- c:\documents and settings\Todd\Local Settings\Application Data\PSU 2009-11-11 03:42 . 2009-09-10 12:46 482408 ----a-w- c:\windows\ssndii.exe 2009-11-11 03:42 . 2009-11-18 05:40 -------- d-----w- c:\program files\SamsungPrinterLiveUpdate 2009-11-11 03:42 . 2009-11-11 03:42 -------- d-----w- c:\windows\Samsung 2009-11-11 03:42 . 2009-11-11 03:42 -------- d-----w- c:\temp\ML-2850_SP 2009-11-11 03:23 . 2009-11-11 03:23 -------- d-----w- c:\temp\ML-2850_Win7_Print 2009-11-10 14:22 . 2009-11-10 14:22 -------- d-----w- c:\program files\Common Files\Skype . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-05 23:41 . 2009-09-09 21:43 -------- d-----w- c:\documents and settings\Todd\Application Data\Skype 2009-12-05 23:37 . 2008-08-28 04:35 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs 2009-12-05 23:37 . 2008-08-28 04:35 0 ----a-w- c:\windows\system32\drivers\logiflt.iad 2009-12-05 22:57 . 2009-09-10 21:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-12-05 22:57 . 2009-09-10 21:01 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-12-05 14:46 . 2009-03-26 23:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2009-12-03 23:14 . 2009-09-10 21:00 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-03 23:13 . 2009-09-10 21:00 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-12-01 06:51 . 2008-04-23 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2009-12-01 04:23 . 2009-09-29 10:43 -------- d-----w- c:\documents and settings\Todd\Application Data\HPAppData 2009-11-29 08:44 . 2008-07-14 23:30 -------- d-----w- c:\program files\Sprint Instinct Applications 2009-11-25 01:43 . 2009-09-29 04:13 -------- d-----w- c:\program files\Yahoo! 2009-11-23 21:07 . 2009-11-23 19:36 6920 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-11-23 21:07 . 2009-11-23 19:36 3140 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-11-21 22:18 . 2005-05-26 01:55 -------- d-----w- c:\program files\Google 2009-11-20 22:51 . 2005-03-09 06:38 -------- d-----w- c:\program files\vb2000 2009-11-20 02:41 . 2007-03-14 16:49 -------- d-----w- c:\program files\McAfee 2009-11-18 15:08 . 2009-09-30 04:36 -------- d-----w- c:\documents and settings\Todd\Application Data\HpUpdate 2009-11-11 03:23 . 2008-07-14 23:45 -------- d-----w- c:\program files\Samsung 2009-11-10 14:22 . 2009-09-10 05:23 -------- d-----r- c:\program files\Skype 2009-11-10 14:22 . 2008-08-28 04:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2009-11-09 00:03 . 2009-09-13 02:49 -------- d-----w- c:\documents and settings\Todd\Application Data\vlc 2009-11-04 20:10 . 2009-10-04 23:58 16384 ----a-w- c:\windows\system32\lgfwunis.exe 2009-11-04 05:40 . 2005-01-12 21:53 -------- d-----w- c:\program files\Java 2009-11-04 05:39 . 2009-11-04 05:39 152576 ----a-w- c:\documents and settings\Todd\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2009-11-03 03:42 . 2009-10-02 20:41 195456 ------w- c:\windows\system32\MpSigStub.exe 2009-10-14 14:41 . 2005-03-09 03:08 -------- d-----w- c:\program files\Common Files\Adobe 2009-10-12 17:33 . 2007-09-19 17:41 -------- d-----w- c:\documents and settings\Todd\Application Data\LimeWire 2009-10-11 11:17 . 2009-03-07 04:03 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-10-07 03:53 . 2009-10-07 03:49 68027 ----a-w- c:\windows\hpqins13.dat 2009-10-06 10:51 . 2009-10-06 10:51 26624 ----a-w- c:\windows\system32\ml285pl3.dll 2009-09-29 04:16 . 2009-09-29 04:01 188864 ----a-w- c:\windows\hpwins22.dat 2009-09-23 12:55 . 2009-12-01 06:54 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys 2009-09-16 16:22 . 2007-03-14 17:23 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys 2009-09-16 16:22 . 2007-03-14 17:23 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys 2009-09-16 16:22 . 2007-03-14 17:23 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys 2009-09-16 16:22 . 2007-03-14 17:23 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys 2009-09-16 16:22 . 2007-03-14 17:23 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys 2009-09-11 15:59 . 2009-09-11 15:59 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe 2009-09-11 14:18 . 2004-08-04 07:56 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-11 09:50 . 2009-09-11 09:50 81920 ----a-w- c:\windows\system32\ssdevm.dll . ((((((((((((((((((((((((((((( SnapShot@2009-12-05_04.50.40 ))))))))))))))))))))))))))))))))))))))))) . + 2009-12-05 23:38 . 2009-12-05 23:38 16384 c:\windows\Temp\Perflib_Perfdata_ad4.dat + 2004-08-09 20:44 . 2009-12-05 23:43 71904 c:\windows\system32\perfc009.dat - 2004-08-09 20:44 . 2009-12-05 04:53 71904 c:\windows\system32\perfc009.dat + 2005-01-12 22:00 . 2009-12-05 23:38 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat - 2005-01-12 22:00 . 2009-12-05 04:48 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat + 2005-01-12 22:00 . 2009-12-05 23:38 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2005-01-12 22:00 . 2009-12-05 04:48 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat - 2005-01-12 22:00 . 2009-12-05 04:48 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2005-01-12 22:00 . 2009-12-05 23:38 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat + 2004-08-09 20:44 . 2009-12-05 23:43 444028 c:\windows\system32\perfh009.dat - 2004-08-09 20:44 . 2009-12-05 04:53 444028 c:\windows\system32\perfh009.dat + 2009-07-02 16:18 . 2009-12-05 23:38 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat - 2009-07-02 16:18 . 2009-12-05 04:48 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-29 68856] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328] "Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2009-09-12 614400] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] c:\documents and settings\All Users\Start Menu\Programs\Startup\ APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2005-3-25 209016] Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-2 546288] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Todd^Start Menu^Programs^Startup^HotSync Manager.lnk] path=c:\documents and settings\Todd\Start Menu\Programs\Startup\HotSync Manager.lnk backup=c:\windows\pss\HotSync Manager.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Todd^Start Menu^Programs^Startup^Sprint media monitor.lnk] path=c:\documents and settings\Todd\Start Menu\Programs\Startup\Sprint media monitor.lnk backup=c:\windows\pss\Sprint media monitor.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Palm\\HOTSYNC.EXE"= "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"= "c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqfxt08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 $sys$cor;$sys$cor;c:\windows\system32\drivers\$sys$cor.sys [10/6/2004 7:11 AM 18432] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [11/30/2009 11:54 PM 64288] R1 $sys$crater;$sys$crater;c:\windows\system32\$sys$filesystem\crater.sys [10/7/2004 12:57 AM 11904] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 4:17 AM 1184912] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592] S2 gupdate1c9ae6a9168b1b6;Google Update Service (gupdate1c9ae6a9168b1b6);c:\program files\Google\Update\GoogleUpdate.exe [3/26/2009 4:28 PM 133104] S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?] S3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [1/12/2005 3:28 PM 32640] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2007-12-05 18:27 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchMigratedDefaultURL = hxxp://sidesearch.lycos.com/?query={searchTerms}&npl=& mSearch Bar = hxxp://go.compaq.com/1Q00CDT/0409/bl8.asp uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Trusted Zone: turbotax.com DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\Todd\Application Data\Mozilla\Firefox\Profiles\r4v7e8ua.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official|http://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service e:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-05 16:40 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(688) c:\windows\system32\WININET.dll - - - - - - - > 'lsass.exe'(752) c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(3284) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\mshtml.dll c:\windows\system32\msls31.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Nero\Nero 7\InCD\InCDsrv.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\Skype\Phone\Skype.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\progra~1\McAfee\VIRUSS~1\mcshield.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\APC\APC PowerChute Personal Edition\apcsystray.exe c:\program files\McAfee\MPF\MPFSrv.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\program files\Windows Media Player\WMPNetwk.exe c:\program files\Canon\CAL\CALMAIN.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\Lavasoft\Ad-Aware\AAWTray.exe . ************************************************************************** . Completion time: 2009-12-05 16:52 - machine was rebooted ComboFix-quarantined-files.txt 2009-12-05 23:51 ComboFix2.txt 2009-12-05 05:02 Pre-Run: 26,738,237,440 bytes free Post-Run: 26,680,217,600 bytes free - - End Of File - - 0CCA52F634561B69D237CABE242BA343