ComboFix 10-01-04.01 - Will 07/01/2010 20:55:03.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.522 [GMT 0:00]
Running from: c:\documents and settings\Will\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Will\Desktop\CFScript.txt
AV: Windows Live OneCare *On-access scanning disabled* (Updated) {427ADFC3-B354-4A51-BE34-A9D4218E45C4}
FW: Windows Live OneCare Firewall *disabled* {A3899D22-27E6-4A7E-AE4E-2C106646DAAB}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PFSVGAE
-------\Service_pfsvgae
((((((((((((((((((((((((( Files Created from 2009-12-07 to 2010-01-07 )))))))))))))))))))))))))))))))
.
2010-01-07 00:31 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-01-07 00:31 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2010-01-05 20:32 . 2010-01-05 20:33 -------- d-----w- C:\Malwarebytes' Anti-Malware
2009-12-31 10:18 . 2010-01-05 20:21 -------- d-----w- c:\documents and settings\Will\Local Settings\Application Data\lptdvl
2009-12-16 22:29 . 2009-12-16 22:42 -------- d-----w- c:\documents and settings\Will\.hydrogen
2009-12-16 22:27 . 2009-12-16 22:28 -------- d-----w- c:\program files\Hydrogen
2009-12-16 22:27 . 2009-12-16 22:27 -------- d-----w- c:\program files\SwiffRec
2009-12-16 22:24 . 2009-12-16 22:26 -------- d-----w- c:\program files\BestPractice
2009-12-16 22:22 . 2009-12-16 22:22 -------- d-----w- c:\program files\AudioBookCutter_0_5_0
2009-12-16 22:21 . 2009-12-16 22:21 -------- d-----w- c:\program files\7-Zip
2009-12-16 22:19 . 2009-12-16 22:19 -------- d-----w- c:\program files\ggseq-0.3.1
2009-12-16 22:17 . 2009-12-16 22:17 -------- d-----w- c:\program files\WinLame_pre4
2009-12-16 22:15 . 2009-12-16 22:15 -------- d-----w- c:\program files\lame_3.96.1
2009-12-13 16:23 . 2009-12-13 16:23 -------- d-----w- c:\documents and settings\All Users\Application Data\TomTom
2009-12-13 16:22 . 2009-12-13 16:22 -------- d-----w- c:\documents and settings\Will\Local Settings\Application Data\TomTom
2009-12-13 16:22 . 2009-12-13 16:22 -------- d-----w- c:\documents and settings\Will\Application Data\TomTom
2009-12-13 16:22 . 2009-12-13 16:22 -------- d-----w- c:\program files\TomTom International B.V
2009-12-13 16:22 . 2009-12-13 16:22 -------- d-----w- c:\program files\TomTom HOME 2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-07 21:13 . 2008-09-21 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki
2010-01-07 21:10 . 2007-03-01 14:05 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-07 20:57 . 2008-12-22 21:43 -------- d-----w- c:\program files\Microsoft Windows OneCare Live
2010-01-05 17:36 . 2008-12-31 15:48 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-05 17:35 . 2010-01-05 17:35 52224 ----a-w- c:\documents and settings\Will\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-05 17:35 . 2009-10-01 21:24 117760 ----a-w- c:\documents and settings\Will\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-30 14:55 . 2009-01-01 15:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-30 14:54 . 2009-01-01 15:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-16 08:18 . 2009-11-10 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2009-12-05 15:06 . 2006-09-20 09:20 -------- d-----w- c:\program files\Java
2009-12-05 15:03 . 2009-12-05 15:03 152576 ----a-w- c:\documents and settings\Will\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-05 15:02 . 2009-12-05 15:02 79488 ----a-w- c:\documents and settings\Will\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-10 22:20 . 2006-09-25 21:35 49000 ----a-w- c:\documents and settings\Will\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-10 22:19 . 2008-03-06 08:19 -------- d-----w- c:\program files\Windows Live
2009-11-10 22:19 . 2006-09-26 09:34 -------- d-----w- c:\program files\Windows Live Toolbar
2009-11-10 22:18 . 2009-11-10 22:18 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-11-10 22:11 . 2009-11-10 22:11 -------- d-----w- c:\program files\Microsoft
2009-11-10 22:11 . 2009-11-10 22:11 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-10 20:42 . 2009-11-10 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2009-10-29 07:45 . 2004-08-10 11:51 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 11:51 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 11:51 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-03 22:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-10 11:51 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 19:37 . 2009-10-12 19:25 110415 ----a-w- c:\windows\hpoins11.dat
2009-10-12 13:38 . 2004-08-10 11:51 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 11:51 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 04:17 . 2009-01-01 16:26 411368 ----a-w- c:\windows\system32\deploytk.dll
2008-10-07 07:00 . 2008-10-07 07:00 235296 ----a-w- c:\program files\MC
2008-11-16 23:42 . 2006-10-05 21:32 88 --sh--r- c:\windows\system32\64D3CEE666.sys
2008-05-19 20:22 . 2006-10-17 19:25 56 --sh--r- c:\windows\system32\66E6CED364.sys
2008-11-16 23:43 . 2006-10-05 21:32 5852 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-07-16 389120]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 68856]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-02-27 1032376]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 2321600]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"SigmatelSysTrayApp"="stsystra.exe" [2006-02-10 282624]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 98304]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-11-09 497240]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-09-20 26112]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 78960]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-09-20 169984]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2006-02-09 106496]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 29696]
"DSLSTATEXE"="c:\program files\BT Voyager 105 ADSL Modem\dslstat.exe" [2003-06-28 1658965]
"DSLAGENTEXE"="c:\program files\BT Voyager 105 ADSL Modem\dslagent.exe" [2003-08-19 16384]
"EPSON Stylus C64 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2003-05-27 99840]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2009-07-09 65240]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2009-09-04 158448]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
AOL 9.0 Tray Icon.lnk - c:\program files\AOL 9.0\aoltray.exe [2006-9-20 156784]
BT Broadband Basic Help.lnk - c:\program files\BT Broadband Basic Help\bin\matcli.exe [2006-10-31 200704]
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-9-20 7168]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2006-9-25 581632]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Sierra\\SWAT3\\Swat.icd"=
"c:\\Program Files\\Raven\\Star Trek Voyager Elite Force\\stvoyHM.exe"=
"c:\\Program Files\\EasyChat\\EasyChat.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27/11/2008 12:11 682232]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15/09/2009 10:42 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15/09/2009 10:42 74480]
R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [09/07/2009 11:15 26104]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [13/11/2009 11:31 92008]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [05/10/2006 22:11 13592]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15/09/2009 10:42 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-10-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.btbroadbandstart.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-07 21:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys sfsync02.sys hal.dll atapi.sys sptd.sys >>UNKNOWN [0x86D808A8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7660f28
\Driver\ACPI -> ACPI.sys @ 0xf73e3cb8
\Driver\atapi -> sfsync02.sys @ 0xf762d8b4
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2908)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
c:\windows\stsystra.exe
c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
c:\program files\Microsoft Windows OneCare Live\winss.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\SetPoint\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\BT Broadband Basic Help\bin\mpbtn.exe
.
**************************************************************************
.
Completion time: 2010-01-07 21:19:36 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-07 21:19
ComboFix2.txt 2010-01-07 00:34
Pre-Run: 38,101,262,336 bytes free
Post-Run: 37,971,996,672 bytes free
- - End Of File - - 8370B871BA0EBF97A30FBF75B9D4DEDC