combilog.txt (11.57K)
Number of downloads: 2
ComboFix 11-03-31.03 - Sandra Roberts 01/04/2011 10:23:31.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.894.428 [GMT 1:00]
Running from: F:\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\tmp.tmp
D:\Autorun.inf
.
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((( Files Created from 2011-03-01 to 2011-04-01 )))))))))))))))))))))))))))))))
.
.
2011-04-01 08:59 . 2011-04-01 08:59 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2011-04-01 08:48 . 2011-04-01 08:48 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EE595CCC-7FE5-488D-B97E-21FC7A3C5DAF}\MpKsl677cd114.sys
2011-03-31 18:47 . 2011-03-31 18:47 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EE595CCC-7FE5-488D-B97E-21FC7A3C5DAF}\MpKsl6d230da2.sys
2011-03-31 14:22 . 2011-03-31 14:22 -------- d-----w- c:\documents and settings\Sandra Roberts\Application Data\ElevatedDiagnostics
2011-03-31 13:56 . 2011-03-23 09:11 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EE595CCC-7FE5-488D-B97E-21FC7A3C5DAF}\mpengine.dll
2011-03-31 13:56 . 2011-02-02 17:11 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-03-31 11:16 . 2011-03-31 11:15 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-31 10:11 . 2011-03-31 10:11 -------- d-----w- c:\documents and settings\Sandra Roberts\Local Settings\Application Data\PCHealth
2011-03-27 13:49 . 2011-03-27 13:49 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2011-03-23 18:56 . 2009-03-09 19:06 15688 ----a-w- c:\windows\system32\lsdelete.exe
2011-03-23 18:24 . 2011-03-23 18:24 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\PCHealth
2011-03-23 18:23 . 2011-03-23 18:24 -------- d-----w- c:\program files\Microsoft Security Client
2011-03-22 20:43 . 2011-03-22 20:43 -------- d-----w- c:\windows\5GQ09KT3CLV4DS1B
2011-03-22 19:37 . 2009-03-09 19:06 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-03-22 19:36 . 2011-03-22 19:36 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2011-03-22 19:36 . 2011-03-22 19:36 -------- d-----w- c:\program files\Lavasoft
2011-03-18 15:01 . 2011-03-18 15:01 -------- d-----w- c:\documents and settings\Ray Roberts\Application Data\Uniblue
2011-03-18 15:01 . 2011-03-18 15:01 -------- d-----w- c:\documents and settings\Ray Roberts\Local Settings\Application Data\PackageAware
2011-03-13 21:08 . 2011-03-18 14:49 -------- d-----w- c:\documents and settings\Ray Roberts\Tracing
2011-03-13 21:04 . 2011-03-13 21:04 -------- d-----w- c:\documents and settings\Ray Roberts\Local Settings\Application Data\Conduit
2011-03-13 21:04 . 2011-03-13 21:04 -------- d-----w- c:\documents and settings\Ray Roberts\Local Settings\Application Data\IncrediMail_MediaBar_2
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-31 11:15 . 2007-09-16 18:43 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-03-27 21:14 . 2010-12-13 20:05 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-01-21 14:44 . 2004-08-04 08:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-04 08:00 290048 ----a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07C92F45-3193-4FD9-AF54-B1925707C872}]
2010-08-31 19:19 86696 ----a-w- c:\program files\magentictb\magenticDx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B3312915-9368-4FE4-8D4E-B60E5B36D0FF}]
2010-08-31 19:19 262312 ----a-w- c:\program files\magentictb\auxi\magenticAu.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{07C92F45-3193-4FD9-AF54-B1925707C872}"= "c:\program files\magentictb\magenticDx.dll" [2010-08-31 86696]
.
[HKEY_CLASSES_ROOT\clsid\{07c92f45-3193-4fd9-af54-b1925707c872}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 344064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-06-29 269104]
"VX3000"="c:\windows\vVX3000.exe" [2006-06-29 707376]
"Network Error Advisor"="c:\program files\magentictb\ExeRunner.exe" [2010-03-31 58368]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-25 1205840]
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2007-10-29 303104]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, meciffff.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [22/03/2011 20:37 64160]
R1 MpKsl677cd114;MpKsl677cd114;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EE595CCC-7FE5-488D-B97E-21FC7A3C5DAF}\MpKsl677cd114.sys [01/04/2011 09:48 28752]
R1 MpKsl6d230da2;MpKsl6d230da2;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EE595CCC-7FE5-488D-B97E-21FC7A3C5DAF}\MpKsl6d230da2.sys [31/03/2011 19:47 28752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 20:06 951632]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [22/08/2005 10:06 231424]
S2 ELOADER;General Purpose USB Driver (adildr.sys);c:\windows\system32\drivers\adildr.sys [25/10/2007 15:13 56088]
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
.
2011-04-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 12:26]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.hp.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?b67645894ed646dcb66cde7d5b255605
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?b67645894ed646dcb66cde7d5b255605
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-RegistryBooster - c:\program files\Uniblue\RegistryBooster\launcher.exe
HKU-Default-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\UninstFl.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-01 10:32
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????????n??|?????? ???B?????????????hLC? ??????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-04-01 10:35:22
ComboFix-quarantined-files.txt 2011-04-01 09:35
.
Pre-Run: 51,551,461,376 bytes free
Post-Run: 53,173,604,352 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 9B8FA7CBC97B3DF2E7043210A32194E4
This post has been edited by SweetTech: 01 April 2011 - 07:32 PM
Reason for edit: expanded CF log.--ST

Help
This topic is locked

Back to top










