ComboFix 08-11-21.03 - Sharron Washington 2008-11-21 20:27:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.317 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Sharron Washington\Application Data\FunWebProducts
c:\documents and settings\Sharron Washington\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\Common\helper.dll
c:\program files\Common\helper.sig
c:\program files\FunWebProducts
c:\program files\GetPack
c:\program files\GetPack\dictame.gz
c:\program files\GetPack\trgtame.gz
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\IE4 Error Log.txt
c:\windows\system32\msansspc.dll
c:\windows\system32\msziptools.dll
c:\windows\system32\wini1087100.exe
c:\windows\system32\WinNB55.dll
c:\windows\wiaserviv.log
c:\windows\wiaservv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NNSERV
-------\Service_NNServ
((((((((((((((((((((((((( Files Created from 2008-10-22 to 2008-11-22 )))))))))))))))))))))))))))))))
.
2008-11-19 22:39 . 2008-11-19 22:39
d-------- c:\documents and settings\Sharron Washington\Application Data\DivX
2008-11-19 22:37 . 2008-11-19 22:37 d-------- c:\program files\DivX
2008-11-19 22:37 . 2008-09-19 16:57 129,784 --------- c:\windows\system32\pxafs.dll
2008-11-19 22:37 . 2008-09-19 16:57 9,464 --------- c:\windows\system32\drivers\cdralw2k.sys
2008-11-19 22:37 . 2008-09-19 16:57 9,336 --------- c:\windows\system32\drivers\cdr4_xp.sys
2008-11-15 18:42 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2008-11-15 18:41 . 2008-11-15 18:41 d-------- c:\program files\Panda Security
2008-11-15 00:33 . 2008-11-15 21:14 d-------- c:\documents and settings\Sharron Washington\Application Data\HouseCall 6.6
2008-11-13 07:14 . 2008-11-13 07:14 268 --ah----- C:\sqmdata19.sqm
2008-11-13 07:14 . 2008-11-13 07:14 244 --ah----- C:\sqmnoopt19.sqm
2008-11-12 21:24 . 2008-11-12 21:24 280 --ah----- C:\sqmdata18.sqm
2008-11-12 21:24 . 2008-11-12 21:24 244 --ah----- C:\sqmnoopt18.sqm
2008-11-12 19:43 . 2008-11-12 19:43 268 --ah----- C:\sqmdata17.sqm
2008-11-12 19:43 . 2008-11-12 19:43 244 --ah----- C:\sqmnoopt17.sqm
2008-11-12 19:09 . 2008-10-24 06:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 19:08 . 2008-09-04 12:15 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-11-06 22:56 . 2008-11-06 22:56 268 --ah----- C:\sqmdata16.sqm
2008-11-06 22:56 . 2008-11-06 22:56 244 --ah----- C:\sqmnoopt16.sqm
2008-11-06 09:47 . 2008-11-06 09:47 268 --ah----- C:\sqmdata15.sqm
2008-11-06 09:47 . 2008-11-06 09:47 244 --ah----- C:\sqmnoopt15.sqm
2008-11-05 19:35 . 2008-11-05 19:35 268 --ah----- C:\sqmdata14.sqm
2008-11-05 19:35 . 2008-11-05 19:35 244 --ah----- C:\sqmnoopt14.sqm
2008-11-05 19:26 . 2008-11-05 19:26 268 --ah----- C:\sqmdata13.sqm
2008-11-05 19:26 . 2008-11-05 19:26 244 --ah----- C:\sqmnoopt13.sqm
2008-11-05 00:27 . 2008-11-05 00:27 268 --ah----- C:\sqmdata12.sqm
2008-11-05 00:27 . 2008-11-05 00:27 244 --ah----- C:\sqmnoopt12.sqm
2008-11-03 22:25 . 2008-11-03 22:25 268 --ah----- C:\sqmdata11.sqm
2008-11-03 22:25 . 2008-11-03 22:25 244 --ah----- C:\sqmnoopt11.sqm
2008-11-02 22:50 . 2008-11-02 22:50 268 --ah----- C:\sqmdata10.sqm
2008-11-02 22:50 . 2008-11-02 22:50 244 --ah----- C:\sqmnoopt10.sqm
2008-11-02 22:18 . 2008-11-02 22:18 d-------- c:\program files\Windows Defender
2008-11-02 21:08 . 2008-11-02 21:08 268 --ah----- C:\sqmdata09.sqm
2008-11-02 21:08 . 2008-11-02 21:08 244 --ah----- C:\sqmnoopt09.sqm
2008-10-28 17:36 . 2008-10-28 17:36 823,296 --a------ c:\windows\system32\divx_xx0c.dll
2008-10-28 17:36 . 2008-10-28 17:36 823,296 --a------ c:\windows\system32\divx_xx07.dll
2008-10-28 17:35 . 2008-10-28 17:35 815,104 --a------ c:\windows\system32\divx_xx0a.dll
2008-10-28 17:35 . 2008-10-28 17:35 802,816 --a------ c:\windows\system32\divx_xx11.dll
2008-10-28 17:35 . 2008-10-28 17:35 729,088 --a------ c:\windows\system32\divxdec.ax
2008-10-28 17:35 . 2008-10-28 17:35 684,032 --a------ c:\windows\system32\DivX.dll
2008-10-26 10:58 . 2008-10-26 10:58 d-------- c:\documents and settings\Sharron Washington\Application Data\GetModule
2008-10-23 19:12 . 2008-10-15 11:34 337,408 --------- c:\windows\system32\dllcache\netapi32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-22 01:27 --------- d-----w c:\program files\Common
2008-11-15 23:12 --------- d-----w c:\program files\Trend Micro
2008-11-03 02:17 --------- d-----w c:\documents and settings\All Users\Application Data\Aventail
2008-10-28 22:32 --------- d-----w c:\program files\Lx_cats
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 22:00 --------- d-----w c:\documents and settings\Sharron Washington\Application Data\Yahoo!
2008-10-05 01:16 --------- d-----w c:\program files\MSECache
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-12-13 58992]
"Norton Ghost 10.0"="c:\program files\Norton Ghost\Agent\GhostTray.exe" [2005-12-07 1537696]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-09-06 169984]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-08 110592]
"LXCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-04-27 69632]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-09-06 24576]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\lxcfcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-15 28544]
R2 MSCamSvc;MSCamSvc;"c:\program files\Microsoft LifeCam\MSCamS32.exe" [2006-10-13 207664]
S3 GameConsoleService;GameConsoleService;"c:\program files\WildTangent\Apps\Dell Game Console\GameConsoleService.exe" [2008-09-05 164600]
S3 MSHUSBVideo;NX6000 Filter Driver;c:\windows\system32\Drivers\nx6000.sys [2006-08-23 30512]
S3 NgFilter;Aventail VPN Filter;c:\windows\system32\DRIVERS\ngfilter.sys []
S3 NgLog;Aventail VPN Logging;c:\windows\system32\DRIVERS\nglog.sys []
S3 NgVpn;Aventail VPN Adapter;c:\windows\system32\DRIVERS\ngvpn.sys []
S3 NgWfp;Aventail VPN Callout;c:\windows\system32\DRIVERS\ngwfp.sys []
.
Contents of the 'Scheduled Tasks' folder
2008-11-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-21 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
2008-11-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -
Notify-fccdbBqO - fccdbBqO.dll
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-21 20:32:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Windows Defender\MsMpEng.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\gearsec.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Norton Ghost\Agent\VProSvc.exe
c:\progra~1\TRENDM~1\INTERN~1\PcCtlCom.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe
c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe
c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-11-21 20:36:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-22 01:36:27
Pre-Run: 31,392,899,072 bytes free
Post-Run: 38,213,734,400 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
211 --- E O F --- 2008-11-22 01:02:52