ComboFix 09-03-18.01 - Ben Sloan 2009-03-19 12:58:05.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.208 [GMT -4:00]
Running from: c:\documents and settings\Ben Sloan\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ben Sloan\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
FILE ::
C:\p3.bat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\p3.bat
.
((((((((((((((((((((((((( Files Created from 2009-02-19 to 2009-03-19 )))))))))))))))))))))))))))))))
.
2009-03-19 12:07 . 2009-03-19 12:09 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-19 12:07 . 2009-03-19 12:07 325,640 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-19 12:07 . 2009-03-19 12:07 107,912 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-19 12:07 . 2009-03-19 12:07 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-19 12:06 . 2009-03-19 12:06 <DIR> d-------- c:\program files\AVG
2009-03-19 12:04 . 2009-03-19 12:07 8,192 --a------ c:\documents and settings\MCAFEE~1.SLO
2009-03-19 08:15 . 2009-03-19 08:15 <DIR> d-------- c:\documents and settings\Ben Sloan\DoctorWeb
2009-03-19 08:06 . 2009-01-09 15:19 1,089,593 --------- c:\windows\system32\dllcache\ntprint.cat
2009-03-18 15:31 . 2009-03-18 15:32 <DIR> d-------- C:\Rooter$
2009-03-18 14:55 . 2009-03-18 14:55 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-18 14:55 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-18 14:55 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-18 14:53 . 2009-03-18 14:53 <DIR> d-------- c:\program files\ERUNT
2009-03-18 14:38 . 2009-03-18 14:38 <DIR> d-------- c:\windows\system32\XPSViewer
2009-03-18 14:37 . 2009-03-18 14:37 <DIR> d-------- c:\program files\Reference Assemblies
2009-03-18 14:37 . 2009-03-18 14:37 <DIR> d-------- c:\program files\MSBuild
2009-03-18 14:36 . 2009-03-18 14:37 <DIR> d-------- C:\20736f9aef997caa52
2009-03-18 14:36 . 2008-07-06 08:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-03-18 14:36 . 2008-07-06 08:06 1,676,288 --------- c:\windows\system32\dllcache\xpssvcs.dll
2009-03-18 14:36 . 2008-07-06 06:50 597,504 --------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-03-18 14:36 . 2008-07-06 08:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-03-18 14:36 . 2008-07-06 08:06 575,488 --------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-03-18 14:36 . 2008-07-06 08:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-03-18 14:36 . 2008-07-06 08:06 89,088 --------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-03-18 13:59 . 2009-03-18 13:59 <DIR> d-------- c:\program files\SysRestorePoint_v13
2009-03-18 13:56 . 2009-03-18 13:56 <DIR> d-------- c:\program files\PKWARE
2009-03-18 13:56 . 2009-03-18 13:56 <DIR> d-------- c:\program files\Common Files\PKWARE
2009-03-16 11:08 . 2009-03-16 11:08 <DIR> d-------- c:\documents and settings\McAfeeMVSUser\Application Data\Jasc Software Inc
2009-03-16 11:08 . 2009-03-16 11:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-16 11:07 . 2009-03-16 11:08 <DIR> d-------- c:\windows\system32\DRVSTORE
2009-03-16 11:07 . 2009-03-16 11:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-13 16:40 . 2009-03-16 11:08 <DIR> d--h----- c:\documents and settings\McAfeeMVSUser\Application Data\Gtek
2009-03-13 16:40 . 2009-03-19 12:07 <DIR> d-------- c:\documents and settings\McAfeeMVSUser
2009-03-13 16:36 . 2009-03-13 16:36 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-13 16:36 . 2009-03-13 16:36 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-13 16:35 . 2009-03-13 16:35 <DIR> d-------- c:\program files\Java
2009-03-13 09:33 . 2007-12-01 11:33 55,016 --a------ c:\windows\system32\drivers\mfetdik.sys
2009-03-12 14:44 . 2009-03-12 14:51 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-12 14:25 . 2009-03-19 12:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-12 11:17 . 2009-03-12 11:17 <DIR> d-------- c:\program files\Trend Micro
2009-03-11 15:42 . 2009-03-16 11:07 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-27 14:13 . 2009-02-27 14:13 <DIR> d-------- c:\documents and settings\Ben Sloan\Application Data\Malwarebytes
2009-02-27 14:13 . 2009-02-27 14:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-16 15:07 --------- d-----w c:\documents and settings\All Users\Application Data\yahoo!
2009-03-12 16:32 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-12 16:25 --------- d-----w c:\program files\Yahoo!
2009-02-12 15:40 --------- d-----w c:\documents and settings\All Users\Application Data\Citrix
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:13 1,846,784 ------w c:\windows\system32\dllcache\win32k.sys
2009-01-17 02:35 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-01-11 05:00 79,360 ------w c:\windows\system32\dllcache\iecompat.dll
2008-12-19 09:10 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2005-06-13 14:20 46,120 ----a-w c:\documents and settings\Ben Sloan\Application Data\GDIPFONTCACHEV1.DAT
2008-08-05 14:12 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080520080806\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-19_11.08.48.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-19 16:07:16 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys
+ 2009-03-19 16:52:15 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_448.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-10 77824]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"masqform.exe"="c:\program files\PureEdge\Viewer 6.0\masqform.exe" [2003-12-03 1052672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-28 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-13 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-19 1932568]
c:\documents and settings\Ben Sloan\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
HotSync Manager.lnk - c:\program files\Palm\HOTSYNC.EXE [2004-04-13 299008]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Palm\HOTSYNC.EXE [2004-04-13 299008]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-09-11 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-19 12:07 10520 c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Palm\\HOTSYNC.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-19 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-03-19 107912]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-19 298264]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 EngineServer;EngineServer;"c:\program files\McAfee\Managed VirusScan\VScan\EngineServer.exe" --> c:\program files\McAfee\Managed VirusScan\VScan\EngineServer.exe [?]
S3 Commander Service;Commander Service;c:\program files\Seagull\BarTender\7.75\CmdrSrv.exe [2006-09-11 1099368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2009-03-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.com/
FF - ProfilePath - c:\documents and settings\Ben Sloan\Application Data\Mozilla\Firefox\Profiles\j5ecnfx0.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-19 13:01:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-03-19 13:04:09
ComboFix-quarantined-files.txt 2009-03-19 17:03:18
ComboFix2.txt 2009-03-19 15:09:54
Pre-Run: 56,310,915,072 bytes free
Post-Run: 56,302,428,160 bytes free
168 --- E O F --- 2009-03-19 16:03:17