ComboFix 11-01-16.04 - Rick 01/17/2011 13:25:12.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.248.115 [GMT -8:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Rick\Application Data\Adobe\AdobeUpdate .exe c:\documents and settings\Rick\Application Data\Adobe\plugs c:\documents and settings\Rick\Local Settings\Application Data\{4998BD21-2B0C-41F8-BC6A-8F4C4363828A} c:\documents and settings\Rick\Local Settings\Application Data\{4998BD21-2B0C-41F8-BC6A-8F4C4363828A}\chrome.manifest c:\documents and settings\Rick\Local Settings\Application Data\{4998BD21-2B0C-41F8-BC6A-8F4C4363828A}\chrome\content\_cfg.js c:\documents and settings\Rick\Local Settings\Application Data\{4998BD21-2B0C-41F8-BC6A-8F4C4363828A}\chrome\content\overlay.xul c:\documents and settings\Rick\Local Settings\Application Data\{4998BD21-2B0C-41F8-BC6A-8F4C4363828A}\install.rdf C:\Thumbs.db c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf c:\windows\system32\drivers\sst112.sys c:\windows\system32\drivers\sst112.tmp c:\windows\winhelp.ini . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_sst112 -------\Service_sst112 ((((((((((((((((((((((((( Files Created from 2010-12-17 to 2011-01-17 ))))))))))))))))))))))))))))))) . 2011-01-17 16:53 . 2011-01-17 16:53 -------- d-sh--w- c:\documents and settings\Rick\PrivacIE 2011-01-17 16:49 . 2011-01-17 16:49 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache 2011-01-17 16:49 . 2011-01-17 16:49 -------- d-sh--w- c:\documents and settings\Rick\IETldCache 2011-01-17 16:27 . 2011-01-17 16:30 -------- dc-h--w- c:\windows\ie8 2011-01-17 16:19 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll 2011-01-17 16:18 . 2010-11-06 00:26 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2011-01-17 16:18 . 2010-11-06 00:26 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2011-01-17 16:18 . 2010-11-06 00:26 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2011-01-17 16:18 . 2010-11-06 00:26 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll 2011-01-17 16:18 . 2010-11-06 00:26 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2011-01-17 16:18 . 2010-11-06 00:26 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll 2011-01-17 16:18 . 2010-11-06 00:26 11080704 -c----w- c:\windows\system32\dllcache\ieframe.dll 2011-01-02 04:03 . 2011-01-02 04:03 -------- d-----w- c:\documents and settings\Rick\Application Data\Malwarebytes 2011-01-02 04:03 . 2010-12-21 02:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-02 04:03 . 2011-01-02 04:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2011-01-02 04:03 . 2010-12-21 02:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-01-02 02:48 . 2011-01-02 02:48 0 ----a-w- c:\windows\Xkaleqozu.bin 2011-01-02 02:46 . 2011-01-02 03:26 420352 ----a-w- c:\documents and settings\All Users\Application Data\OhdJdWMdcsuw.dll 2011-01-01 02:49 . 2011-01-01 02:49 -------- d-----w- c:\documents and settings\Rick\Application Data\iJoysoft 2011-01-01 02:41 . 2011-01-01 02:44 -------- d-----w- c:\documents and settings\Rick\Application Data\GetRightToGo . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-11-18 18:12 . 2003-04-10 01:45 81920 ----a-w- c:\windows\system32\isign32.dll 2010-11-09 14:52 . 2003-10-28 04:09 249856 ----a-w- c:\windows\system32\odbc32.dll 2010-11-06 00:26 . 2004-08-24 03:32 916480 ----a-w- c:\windows\system32\wininet.dll 2010-11-06 00:26 . 2003-04-10 01:38 43520 ------w- c:\windows\system32\licmgr10.dll 2010-11-06 00:26 . 2003-04-10 01:38 1469440 ------w- c:\windows\system32\inetcpl.cpl 2010-11-03 12:25 . 2004-08-04 05:59 385024 ------w- c:\windows\system32\html.iec 2010-11-02 15:17 . 2003-04-10 01:38 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys 2010-10-28 13:13 . 2003-04-10 01:38 290048 ----a-w- c:\windows\system32\atmfd.dll 2010-10-26 13:25 . 2003-04-10 01:38 1853312 ----a-w- c:\windows\system32\win32k.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-30 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960] "VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672] "StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 155648] "nwiz"="nwiz.exe" [2003-03-04 323584] "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-03-04 4595712] "IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-03-11 155648] "HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-03-11 114688] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-03-01 315392] "ATIModeChange"="Ati2mdxx.exe" [2001-09-04 28672] "AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 88107] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 49152] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280] "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592] "iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2010-02-16 141608] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2010-02-18 177472] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-26 198160] c:\documents and settings\Jared\Start Menu\Programs\Startup\ PowerReg Scheduler V3.exe [2005-8-27 225280] PowerReg Scheduler.exe [2005-8-14 256000] c:\documents and settings\Rick\Start Menu\Programs\Startup\ Monitor My eRooms (V7).lnk - c:\program files\eRoom 7\ERClient7.exe [2005-7-10 153352] Monitor My ProjectSolve (V7).lnk - c:\program files\eRoom 7\ERClient7.exe [2005-7-10 153352] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - d:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 217194] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624] HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] Norton AntiVirus AutoProtect.lnk - d:\program files\Navnt\navapw32.exe [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"= "c:\\StubInstaller.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "d:\\Program Files\\iTunes\\iTunes.exe"= S2 gupdate1ca2673dcf70070;Google Update Service (gupdate1ca2673dcf70070);c:\program files\Google\Update\GoogleUpdate.exe [8/26/2009 9:37 AM 133104] S2 NAV Auto-Protect;NAV Auto-Protect;d:\progra~1\Navnt\navapsvc.exe --> d:\progra~1\Navnt\navapsvc.exe [?] S3 ETUSBW11;ETUSBW11.sys, EnterTech Co.,Ltd. USB MIC 1.1 Driver;c:\windows\system32\drivers\ETUSBW11.sys [1/10/2009 4:12 PM 17664] S3 NetDirect;TAP-Win32 NetDirect Adapter;c:\windows\system32\DRIVERS\NetDirect.sys --> c:\windows\system32\DRIVERS\NetDirect.sys [?] . Contents of the 'Scheduled Tasks' folder 2010-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2011-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-26 17:37] 2011-01-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-26 17:37] 2008-01-01 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job - c:\program files\Microsoft IntelliPoint\ipoint.exe [2007-02-05 23:52] 2003-12-06 c:\windows\Tasks\Registration reminder 1.job - c:\windows\System32\OOBE\oobebaln.exe [2003-04-10 00:12] 2003-12-06 c:\windows\Tasks\Registration reminder 2.job - c:\windows\System32\OOBE\oobebaln.exe [2003-04-10 00:12] 2003-12-06 c:\windows\Tasks\Registration reminder 3.job - c:\windows\System32\OOBE\oobebaln.exe [2003-04-10 00:12] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html Trusted Zone: edusoft.com\www Trusted Zone: intuit.com\ttlc Trusted Zone: turbotax.com DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - hxxp://download.sidestep.com/get/k00719/sb028.cab DPF: {67DDCD98-1120-47C3-B47E-A4E6820A571F} - hxxp://pbworldnet.com/components/intranet.CAB DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} - hxxps://ww2.projectsolve2.com/eRoomSetup/client.cab DPF: {7FA319FB-FFB9-4089-87EB-63179244E6E6} - hxxps://pbshares.pbworldnet.com/nortel_cacheable/NetDirect.cab DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} - hxxp://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab DPF: {A2505C6C-6F17-456F-89D2-4301FBDC6EC7} - hxxps://pbshares.pbworldnet.com/nortel_cacheable/iewiper.cab . - - - - ORPHANS REMOVED - - - - HKCU-Run-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe HKCU-Run-QAGENT - c:\progra~1\QUICK99\QAGENT.EXE HKCU-Run-EA Core - d:\program files\Electronic Arts\EADM\Core.exe HKCU-Run-ixy9Di9SYr - c:\docume~1\ALLUSE~1\APPLIC~1\ixy9Di9SYr.exe HKLM-Run-ViewMgr - c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe HKLM-Run-Norton Program Scheduler Event Checker - d:\progra~1\Navnt\npscheck.exe HKLM-Run-Registry Toolkit - c:\program files\Registry Toolkit\RegToolkit.exe HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe HKU-Default-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe AddRemove-Norton AntiVirus - d:\program files\Navnt\navnt.isu ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-01-17 14:06 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-3799378050-3284700033-2027782218-1005\Software\SecuROM\License information*] "datasecu"=hex:9d,6e,dc,0f,c8,fb,de,0a,5b,a5,ce,ab,01,d5,59,2d,b8,69,d1,d0,9c, e8,12,31,19,9a,7f,83,c3,31,62,a0,7b,28,1f,48,3f,b9,a7,34,6e,39,3c,58,2c,67,\ "rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\XP*] "DisplayName"="?\13?\13" "DeviceDesc"="?\13?\13" "ProviderName"="" "MFG"="???\\" "ReinstallString"="c:\\WINDOWS\\System32\\ReinstallBackups\\?\13\\DriverFiles\\.INF" "DeviceInstanceIds"=multi:"er\\xp_inf\\cx_08174.inf\00" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(1464) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe c:\windows\system32\wdfmgr.exe c:\windows\AGRSMMSG.exe c:\windows\system32\rundll32.exe c:\program files\HP\Digital Imaging\bin\hpqgalry.exe c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Internet Explorer\iexplore.exe c:\program files\Internet Explorer\iexplore.exe c:\program files\Internet Explorer\iexplore.exe c:\program files\Internet Explorer\iexplore.exe . ************************************************************************** . Completion time: 2011-01-17 14:31:46 - machine was rebooted ComboFix-quarantined-files.txt 2011-01-17 22:31 Pre-Run: 1,365,139,456 bytes free Post-Run: 1,460,514,816 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn - - End Of File - - BEA8F5BC207A236BA2243DC8A0B41584