Combofix Log
ComboFix 09-04-01.01 - Lisa 2009-04-02 19:49:31.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.555 [GMT 1:00]
Running from: c:\documents and settings\Lisa\Desktop\ComboFix.exe
AV: PCguard Anti-Virus *On-access scanning disabled* (Updated)
FW: COMODO Firewall *enabled*
FW: PCguard Firewall *enabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\bkR11
c:\temp\bkR11\ftCa.log
c:\windows\Fonts\-
c:\windows\system32\adeeg.ini2
c:\windows\system32\agivjbsg.ini
c:\windows\system32\aknthkkq.ini
c:\windows\system32\ATHPRXY(2).DLL
c:\windows\system32\bfkgqutl.ini
c:\windows\system32\bhiacplh.ini
c:\windows\system32\cejypito.ini
c:\windows\system32\cixtupcd.ini
c:\windows\system32\cmvhgeus.ini
c:\windows\system32\drivers\npf.sys
c:\windows\system32\hdeyyhph.ini
c:\windows\system32\jdqjuxbd.ini
c:\windows\system32\jjllm.ini2
c:\windows\system32\knnmebhp.ini
c:\windows\system32\lhtwbnbv.ini
c:\windows\system32\litbkjkx.ini
c:\windows\system32\lllcipvg.ini
c:\windows\system32\mtjahvln.ini
c:\windows\system32\nojxyyfr.ini
c:\windows\system32\nvabgnhs.ini
c:\windows\system32\oxwynhbi.ini
c:\windows\system32\packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\qbvpggdm.ini
c:\windows\system32\qfpeasrn.ini
c:\windows\system32\rpmxsltt.ini
c:\windows\system32\sstwa.ini2
c:\windows\system32\TtwDNqru.ini
c:\windows\system32\TtwDNqru.ini2
c:\windows\system32\unyuojoe.ini
c:\windows\system32\uqyswrwm.ini
c:\windows\system32\uveujwyd.ini
c:\windows\system32\vaeewbiv.ini
c:\windows\system32\wanpacket.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\yadejtgn.ini
c:\windows\system32\ybsouxsw.ini
c:\windows\system32\yejbpdfa.ini
c:\windows\system32\yrnygtmd.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-03-02 to 2009-04-02 )))))))))))))))))))))))))))))))
.
2009-04-02 16:18 . 2009-03-09 02:53 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-04-01 12:36 . 2009-04-01 12:36 <DIR> d-------- c:\documents and settings\Shelley\Tracing
2009-03-10 18:49 . 2009-03-10 18:49 <DIR> d-------- c:\documents and settings\Lisa\DoctorWeb
2009-03-07 20:21 . 2009-03-07 20:22 <DIR> d-------- c:\program files\iTunes
2009-03-07 20:21 . 2009-03-07 20:21 <DIR> d-------- c:\program files\iPod
2009-03-07 20:21 . 2009-03-07 20:22 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-03-07 20:16 . 2009-03-07 20:16 <DIR> d-------- c:\program files\Bonjour
2009-03-07 20:14 . 2009-03-07 20:15 <DIR> d-------- c:\program files\QuickTime
2009-03-07 20:07 . 2009-03-07 20:07 <DIR> d-------- c:\program files\Common Files\Apple
2009-03-07 19:28 . 2009-04-02 19:42 <DIR> d-------- c:\documents and settings\Lisa\Tracing
2009-03-07 19:21 . 2009-03-07 19:21 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-03-07 19:21 . 2009-03-07 19:21 <DIR> d-------- c:\program files\Microsoft
2009-03-07 19:16 . 2009-03-07 19:16 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-03-06 04:01 . 2009-03-14 13:09 1,374 --a------ c:\windows\imsins.BAK
2009-03-05 23:52 . 2009-02-11 11:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-05 21:23 . 2009-03-09 05:19 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-05 21:03 . 2009-01-09 20:19 1,089,593 -----c--- c:\windows\system32\dllcache\ntprint.cat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 18:27 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-02 15:18 --------- d-----w c:\program files\Java
2009-03-16 21:40 --------- d-----w c:\documents and settings\Lisa\Application Data\uTorrent
2009-03-07 18:25 --------- d-----w c:\program files\Windows Live
2009-03-06 03:09 --------- d-----w c:\program files\Microsoft Silverlight
2009-03-05 22:52 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-05 20:28 --------- d-----w c:\program files\CCleaner
2009-02-11 10:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-09 11:13 1,846,784 ------w c:\windows\system32\win32k.sys
2009-02-06 18:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-05 19:30 --------- d-----w c:\program files\Reference Assemblies
2009-02-05 19:30 --------- d-----w c:\program files\MSBuild
2009-02-05 18:48 --------- d-----w c:\documents and settings\Shannon\Application Data\OpenOffice.org
2008-11-04 20:25 1,570 ----a-w c:\documents and settings\Shelley\Application Data\wklnhst.dat
2008-11-02 20:52 1,790 ----a-w c:\documents and settings\Lisa\Application Data\wklnhst.dat
2008-09-22 20:08 116,000 ----a-w c:\documents and settings\Lisa\Application Data\GDIPFONTCACHEV1.DAT
2008-08-21 10:59 93,048 ----a-w c:\documents and settings\Shelley\Application Data\GDIPFONTCACHEV1.DAT
2008-07-05 15:14 166 ----a-w c:\documents and settings\Shannon\Application Data\wklnhst.dat
2008-04-21 17:10 69,007,591 ----a-w c:\program files\Microsoft Office.zip
2006-05-03 09:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 -csh--r c:\windows\system32\msfDX.dll
2007-12-17 12:43 27,648 -csh--w c:\windows\system32\Smab0.dll
2008-10-31 18:11 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008103120081101\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [BU]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2005-06-20 1056768]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-08-07 2061552]
"-FreedomNeedsReboot"="c:\program files\Virgin Broadband\PCguard\ZkRunOnceR.exe" [2007-09-05 13552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SMSERIAL"="sm56hlpr.exe" [2005-06-06 c:\windows\sm56hlpr.exe]
"VTTrayp"="VTtrayp.exe" [2005-03-12 c:\windows\system32\VTTrayp.exe]
c:\documents and settings\Shannon\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
c:\documents and settings\Shelley\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
c:\documents and settings\Lisa\Start Menu\Programs\Startup\
wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2005-08-18 21504]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\power2go\CLMP3Enc.ACM
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\
0autocheck autochk *
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Activision\\SHReK the THiRD Demo\\SHReK the THiRD.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-05-28 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-05-28 55024]
S3 aaudstum;aaudstum;\??\c:\docume~1\Shannon\LOCALS~1\Temp\aaudstum.sys --> c:\docume~1\Shannon\LOCALS~1\Temp\aaudstum.sys [?]
S3 FXDRV;FXDRV;\??\d:\fxdrv.sys --> d:\Fxdrv.sys [?]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-12-29 10976]
S3 Radialpoint Security Services;Virgin Broadband PCguard;c:\windows\system32\dllhost.exe [2006-02-03 5120]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [2008-11-26 90408]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [2008-11-26 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [2008-11-26 122024]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [2008-11-26 115368]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [2008-11-26 25768]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [2008-11-26 111784]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [2008-11-26 117544]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-05-28 7408]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3e829769-edfa-11dc-956a-000e9bebbf9b}]
\Shell\AutoRun\command - I:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-04-02 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.virginmedia.com
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Settings,ProxyOverride = *.local
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\Lisa\Application Data\Mozilla\Firefox\Profiles\abar7yjz.default\
FF - prefs.js: browser.startup.homepage - hxxp://forums.moneysavingexpert.com/
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-02 19:51:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-04-02 19:54:17
ComboFix-quarantined-files.txt 2009-04-02 18:53:40
Pre-Run: 21,504,446,464 bytes free
Post-Run: 21,490,401,280 bytes free
224 --- E O F --- 2009-03-16 21:42:36