ComboFix 10-09-30.03 - Steve 09/30/2010 21:08:59.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.708 [GMT -4:00]
Running from: c:\documents and settings\Steve\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Sara\Application Data\Dealio
c:\documents and settings\Sara\Application Data\Dealio\dinstallhelper.1818FBFE99364C369601148EBAB051B6.dll
c:\documents and settings\Steve\System
c:\documents and settings\Steve\System\win_qs.jqx
c:\documents and settings\Steve\System\win_qs8.jqx
c:\program files\INSTALL.LOG
c:\windows\Downloaded Program Files\Install.inf
c:\windows\Downloaded Program Files\UWAS6_0001_N69M0703NetInstaller.exe
c:\windows\MailSwitch.ocx
c:\windows\system32\dumphive.exe
c:\windows\system32\NSIS.Library.RegTool.v2.{94ADD5E5-25E5-4D3D-85CC-6D4381E048B3}.exe
c:\windows\system32\Process.exe
c:\windows\system32\ReadMe.txt
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
Infected copy of c:\windows\system32\drivers\netbt.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_USNJSVC
-------\Service_usnjsvc
((((((((((((((((((((((((( Files Created from 2010-09-01 to 2010-10-01 )))))))))))))))))))))))))))))))
.
2010-09-17 16:04 . 2010-09-17 16:04 -------- d-----w- c:\documents and settings\Anne\Local Settings\Application Data\Temp
2010-09-12 00:22 . 2008-12-20 00:08 27784 ----a-w- c:\windows\system32\drivers\point32.sys
2010-09-12 00:18 . 2010-09-12 00:19 -------- d-----w- c:\program files\Microsoft IntelliPoint
2010-09-05 23:08 . 2010-05-21 18:14 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-09-05 23:06 . 2010-09-05 23:06 -------- d-----w- c:\documents and settings\Steve\Application Data\PIV
2010-09-04 14:24 . 2010-09-04 14:34 -------- d-----w- c:\program files\AutoCAD 2004
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-30 02:47 . 2009-04-13 23:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-09-19 19:54 . 2008-11-07 00:48 -------- d-----w- c:\documents and settings\Sara\Application Data\U3
2010-09-19 02:16 . 2010-01-06 22:53 79988 ---ha-w- c:\windows\system32\mlfcache.dat
2010-09-17 16:07 . 2008-11-07 02:41 -------- d-----w- c:\program files\Google
2010-09-16 02:40 . 2008-11-07 03:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-16 02:39 . 2008-11-07 00:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-12 16:16 . 2002-12-25 18:14 98224 -c--a-w- c:\documents and settings\Steve\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-12 13:11 . 2002-12-26 16:16 98224 ----a-w- c:\documents and settings\Lauren\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-12 00:36 . 2008-11-07 02:40 -------- d-----w- c:\program files\Enigma Software Group
2010-09-11 00:42 . 2010-07-04 00:53 -------- d-----w- c:\program files\RegiCleanse System Optimizer
2010-09-05 22:55 . 2002-12-26 02:06 97832 -c--a-w- c:\documents and settings\Anne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-04 14:34 . 2008-11-07 00:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2010-09-04 14:33 . 2009-06-22 22:28 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-08-27 23:21 . 2008-11-07 02:53 -------- d-----w- c:\program files\Punch! Pro
2010-08-27 02:13 . 2008-11-07 02:46 -------- d-----w- c:\program files\Lavasoft
2010-08-27 02:13 . 2010-08-23 15:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-08-23 15:38 . 2008-11-07 01:44 -------- d-----w- c:\documents and settings\Steve\Application Data\Lavasoft
2010-08-23 15:37 . 2010-08-23 15:37 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-08-23 14:42 . 2010-03-28 22:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-08-23 14:40 . 2008-11-07 02:35 -------- d-----w- c:\program files\Common Files\Symantec Shared
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-13 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-09-14 50688]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-15 28672]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"iRiver Updater"="\Updater.exe" [2005-10-14 212992]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-01-07 1468296]
c:\documents and settings\Sara\Start Menu\Programs\Startup\
NETGEAR WG511v2 Wireless Assistant.lnk - c:\documents and settings\Sara\Application Data\Microsoft\Installer\{B93D24B3-928D-4805-B379-4AA47CB3794E}\NewShortcut1_1.exe [2009-1-29 2238]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\Steve\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2006-9-3 118784]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ 'autocheck autochk *'
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 7.0 Tray Icon.lnk]
backup=c:\windows\pss\America Online 7.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSNMSGRE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSNMSGRR
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSNMSGRS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSNMSGRS1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV Agent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\1130887990\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1130887990\\ee\\aim6.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\AOL\\1130887990\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\SAGENT4.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3083:UDP"= 3083:UDP:Windows Media Format SDK (firefox.exe)
"3082:UDP"= 3082:UDP:Windows Media Format SDK (firefox.exe)
"3093:UDP"= 3093:UDP:Windows Media Format SDK (firefox.exe)
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/8/2008 9:39 PM 24652]
S2 gupdate1c9bc8d4b0c8b8;Google Update Service (gupdate1c9bc8d4b0c8b8);c:\program files\Google\Update\GoogleUpdate.exe [4/13/2009 7:10 PM 133104]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-09-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
2010-10-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-13 23:09]
2010-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 23:09]
2010-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 23:09]
.
.
------- Supplementary Scan -------
.
uStart Page = www.comcast.net/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.yahoo.com/?fr=fp-grpj
mWindow Title = Microsoft Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:5577
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &AOL Toolbar Search
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
Trusted Zone: gscu.org\www
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} - hxxp://makriscam2.viewnetcam.com:50001/SysCamInst.cab
DPF: {BBF0D44D-14E6-4DB3-8211-AEF1ABA7EE84} - hxxp://esupport.cabinetvision.com/ATLWebKeyButton.CAB
FF - ProfilePath - c:\documents and settings\Steve\Application Data\Mozilla\Firefox\Profiles\ye1diger.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\documents and settings\Sara\My Documents\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\documents and settings\Sara\My Documents\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{2E5FB546-5BFA-0E5F-A59B-0CD58553E0CC} - (no file)
BHO-{2E5FB546-5BFA-0E5F-A59B-0CD58553E0CC} - (no file)
BHO-{91D8B88F-5E33-56C7-3F9F-5C80014A0F9D} - (no file)
BHO-{A69C26CD-9420-998F-7C76-C289102F32CD} - (no file)
HKCU-Run-Weebwbq - c:\docume~1\Steve\APPLIC~1\DOBE~1\ANREGW~1.EXE
HKCU-Run-Performance Center - c:\program files\Ascentive\Performance Center\APCMain.exe
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
SafeBoot-mvhcmvs32
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-30 21:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON Stylus Photo R300 Series = c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"?????D????????????IB~????????????????p????????????????????JB~????p???????????8?????????????C~????p?????????C~p??????????????|???????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3737216988-2114774166-2095096434-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3620)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\BCMSMMSG.exe
C:\Updater.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-09-30 21:32:27 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-01 01:32
Pre-Run: 73,543,569,408 bytes free
Post-Run: 80,849,477,632 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - FA326B759A12B8E1A2A4DC92DB148E60