GooredFix v1.92 by jpshortstuff
Log created at 23:00 on 30/03/2009 running Option #2 (admin)
Firefox version 3.0.8 (en-US)
=====Goored Deletions=====
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{E6F5E278-4B46-4D14-B5C5-167074FDC776}"="C:\Documents and Settings\admin\Local Settings\Application Data\{E6F5E278-4B46-4D14-B5C5-167074FDC776}\"
->Backing up value... Done.
->Deleting value... Done.
C:\Documents and Settings\admin\Local Settings\Application Data\{E6F5E278-4B46-4D14-B5C5-167074FDC776}
->Backing up folder... Done.
->Emptying folder... Done.
->Deleting folder... Done.
=====Dumping Registry Values=====
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"
ComboFix 09-03-30.01 - admin 2009-03-30 23:15:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.219 [GMT -4:00]
Running from: c:\documents and settings\admin\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090330-0] *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\test.ttt
c:\windows\system32\uniq.tll
c:\windows\system32\win32hlp.cnf
.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-31 )))))))))))))))))))))))))))))))
.
2009-03-29 20:42 . 2004-03-29 16:23 90,112 --a------ c:\windows\unvise32.exe
2009-03-29 20:41 . 2009-03-29 20:42 <DIR> d-------- c:\program files\The Rosetta Stone
2009-03-29 14:25 . 2009-03-29 20:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2009-03-29 14:24 . 2009-03-29 14:24 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2009-03-23 19:08 . 2009-03-23 19:13 <DIR> d-------- c:\program files\UltraVNC
2009-03-16 00:40 . 2009-03-16 00:40 <DIR> d-------- c:\program files\Trend Micro
2009-03-15 23:53 . 2009-03-15 23:53 <DIR> d-------- c:\documents and settings\Administrator
2009-03-14 19:21 . 2009-03-14 19:21 <DIR> d--h----- c:\windows\system32\GroupPolicy
2009-03-14 18:53 . 2009-03-14 18:53 <DIR> d-------- c:\program files\Alwil Software
2009-03-14 18:53 . 2003-03-18 16:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2009-03-14 17:46 . 2009-03-14 17:46 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-14 17:46 . 2009-03-14 17:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-14 17:46 . 2009-03-14 17:46 <DIR> d-------- c:\documents and settings\admin\Application Data\Malwarebytes
2009-03-14 17:46 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-14 17:46 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-14 17:36 . 2008-04-14 06:42 26,112 --a--c--- c:\windows\system32\dllcache\userinit.exe
2009-03-14 17:35 . 2009-03-14 17:35 2 --a------ C:\338000835
2009-03-13 19:14 . 2007-07-27 04:26 37,768 -ra------ c:\windows\system32\drivers\wceusbsh.sys
2009-03-13 19:14 . 2007-07-27 04:26 37,768 -ra------ c:\windows\system32\drivers\OLD243.tmp
2009-03-13 19:14 . 2008-04-14 00:15 31,744 --a--c--- c:\windows\system32\dllcache\wceusbsh.sys
2009-03-09 19:22 . 2009-03-09 19:22 <DIR> d-------- c:\program files\Alex Feinman
2009-03-08 19:07 . 2009-03-08 19:07 <DIR> d-------- c:\program files\ATI Technologies
2009-02-16 18:44 . 2009-02-16 18:53 <DIR> d-------- c:\program files\Google
2009-02-16 18:44 . 2009-03-30 18:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\Google Updater
2009-02-11 00:10 . 2009-02-11 00:10 <DIR> d-------- c:\documents and settings\admin\Application Data\Aim
2009-02-11 00:09 . 2009-02-11 00:11 <DIR> d-------- c:\program files\AIM
2009-02-01 03:37 . 2009-02-01 03:37 <DIR> d-------- c:\program files\MagicISO
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-31 02:30 --------- d-----w c:\documents and settings\admin\Application Data\uTorrent
2009-02-11 04:09 --------- d-----w c:\program files\Common Files\AOL
2009-02-11 04:09 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-01 07:46 --------- d-----w c:\program files\DivX
2009-02-01 00:15 --------- d-----w c:\documents and settings\admin\Application Data\U3
2009-01-30 02:09 --------- d-----w c:\documents and settings\admin\Application Data\AdobeUM
2009-01-30 02:08 --------- d-----w c:\program files\Common Files\Adobe
2008-12-11 04:17 472,576 ----a-w c:\windows\Radeon Omega Drivers v4.8.442 Uninstall.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-29 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-30 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 c:\windows\AGRSMMSG.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 16:37 34344 c:\program files\Lenovo\HOTKEY\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-03-17 16:02 34080 c:\program files\Lenovo\HOTKEY\tphklock.dll
[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^adobe reader speed launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
R1 aswsp;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-03-14 114768]
R2 aswfsblk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-03-14 20560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-12-19 24652]
S1 48a05659;48a05659;c:\windows\system32\drivers\48a05659.sys --> c:\windows\system32\drivers\48a05659.sys [?]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys --> c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{46531850-0cfc-11de-882f-0015e975088d}]
\Shell\AutoRun\command - e:\wd_windows_tools\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b4030f5-bea7-11dd-8821-e784ef23b244}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-03-31 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-26 00:01]
2009-03-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1563985344-1343024091-1003.job
- c:\documents and settings\admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-29 19:21]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\vd4z7kpt.default\
FF - plugin: c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\vd4z7kpt.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\admin\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-30 23:20:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(572)
c:\windows\system32\Ati2evxx.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-30 23:23:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-31 03:22:56
Pre-Run: 25,695,166,464 bytes free
Post-Run: 25,646,006,272 bytes free
147
Add-remove
µTorrent
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.7
Agere Systems AC'97 Modem
AOL Instant Messenger
Apple Software Update
ATI - Software Uninstall Utility
ATI Display Driver
AutoUpdate
avast! Antivirus
DivX Codec
DivX Converter
DivX Player
DivX Version Checker
Google Chrome
Google Updater
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Intel® PRO Network Connections Drivers
ISO Recorder
Java 6 Update 10
Magic ISO Maker v5.5 (build 0273)
Malwarebytes' Anti-Malware
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Mozilla Firefox (3.0.8)
On Screen Display
QuickTime
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
SoundMAX
The Rosetta Stone
ThinkPad Power Management Driver
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
VC80CRTRedist - 8.0.50727.762
Viewpoint Media Player
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver