ComboFix 09-03-25.02 - Owner 2009-03-26 19:52:45.6 - NTFSx86 NETWORK Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.763 [GMT 11:00] Running from: c:\documents and settings\[removed]\desktop\ComboFix.exe Command switches used :: c:\documents and settings\Owner\desktop\CFScript.txt AV: Optus Internet Security Suite 2009 8.00 *On-access scanning disabled* (Updated) FW: Optus Internet Security Suite 2009 8.00 *disabled* . ((((((((((((((((((((((((( Files Created from 2009-02-26 to 2009-03-26 ))))))))))))))))))))))))))))))) . 2009-03-24 12:30 . 2009-03-24 12:34 d-------- C:\Combo-Fix 2009-03-24 12:28 . 2009-03-24 12:28 128 --a------ c:\windows\system32\perf.dat 2009-03-22 18:50 . 2009-03-22 18:50 d-------- C:\Inetpub 2009-03-22 08:18 . 2009-03-22 08:18 0 --a------ c:\documents and settings\Owner\Application Data\TrustDefender.dll 2009-03-19 19:54 . 2009-03-19 19:54 d-------- C:\System Utilities 2009-03-17 19:47 . 2007-06-17 01:00 14,336 --a------ c:\windows\system32\drivers\Amps2prt.sys 2009-03-17 19:47 . 2007-02-10 23:55 13,824 --a------ c:\windows\system32\drivers\Amusbprt.sys 2009-03-17 19:47 . 2006-04-11 13:56 10,240 --a------ c:\windows\system32\drivers\Arfumx86.sys 2009-03-17 19:47 . 2007-01-24 17:46 8,704 --a------ c:\windows\system32\drivers\Amfilter.sys 2009-03-03 11:45 . 2009-03-16 21:24 d-------- c:\program files\Eusing Free Registry Cleaner 2009-03-02 21:36 . 2009-03-02 21:36 33,408 --a--c--- c:\windows\system32\drivers\fsbts.sys 2009-03-02 21:05 . 2008-09-24 00:35 79,904 --a--c--- c:\windows\system32\drivers\fsdfw.sys 2009-02-26 22:04 . 2009-02-26 22:04 d-------- c:\program files\Kaspersky Anti Virus 6.0.2.621 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-26 04:02 --------- d-----w c:\program files\Optus Internet Security Suite 2009-03-22 21:12 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip 2009-03-22 06:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-03-21 09:44 --------- d-----w c:\program files\A4Tech 2009-03-21 09:38 --------- d-----w c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com 2009-03-18 09:56 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater 2009-03-18 05:43 --------- d--h--w c:\program files\InstallShield Installation Information 2009-03-18 05:43 --------- d-----w c:\program files\ATI Technologies 2009-03-08 08:50 --------- d-----w c:\program files\Google 2009-03-03 01:30 --------- d-----w c:\program files\Spybot - Search & Destroy 2009-03-02 10:04 --------- d-----w c:\documents and settings\All Users\Application Data\F-Secure 2009-03-02 10:03 --------- d-----w c:\documents and settings\All Users\Application Data\fssg 2009-02-28 07:31 --------- d-----w c:\program files\Microsoft Silverlight 2009-02-26 07:36 --------- dc----w c:\program files\Common Files\WindowsLiveInstaller 2009-02-26 07:36 --------- d-----w c:\program files\Winamp 2009-02-26 07:36 --------- d-----w c:\program files\Java 2009-02-26 07:36 --------- d-----w c:\program files\FinePixViewer 2009-02-26 07:36 --------- d-----w c:\program files\DVD Wizard Pro 2009-02-26 07:36 --------- d-----w c:\program files\DivX 2009-02-26 07:36 --------- d-----w c:\program files\Common Files\Vbox 2009-02-26 07:36 --------- d-----w c:\program files\Common Files\Ahead 2009-02-26 07:36 --------- d-----w c:\program files\Apple Software Update 2009-02-26 07:36 --------- d-----w c:\program files\Acoustica Spin It Again 2009-02-25 00:16 --------- d-----w c:\program files\SUPERAntiSpyware 2009-02-23 12:51 --------- d-----w c:\program files\Acoustica Shared Effects 2009-02-23 07:16 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP 2009-02-23 07:16 --------- d-----w c:\program files\SpywareBlaster 2009-02-21 21:22 --------- d-----w c:\program files\Windows Live 2009-02-16 11:11 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2009-02-12 10:58 --------- d-----w c:\documents and settings\All Users\Application Data\DriverCure 2009-02-12 07:55 --------- d-----w c:\program files\NCH Software 2009-02-12 07:55 --------- d-----w c:\program files\AGI 2009-02-12 07:55 --------- d-----w c:\program files\7-Zip 2009-02-12 07:55 --------- d-----w c:\documents and settings\Owner\Application Data\Uniblue 2009-02-12 07:55 --------- d-----w c:\documents and settings\Owner\Application Data\BitTorrent 2009-02-12 06:12 --------- d-----w c:\documents and settings\Administrator\Application Data\Sonic 2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys 2009-02-06 08:03 307,576 -c--a-w c:\windows\WLXPGSS.SCR 2009-02-06 07:52 49,504 ----a-w c:\windows\system32\sirenacm.dll 2009-02-05 00:38 --------- d-----w c:\documents and settings\All Users\Application Data\NCH Swift Sound 2009-02-03 05:55 --------- d-----w c:\program files\Common Files\xing shared 2009-02-03 05:55 --------- d-----w c:\program files\Common Files\Real 2009-02-03 05:54 --------- d-----w c:\program files\Real 2009-02-03 05:41 --------- d-----w c:\program files\AskBarDis 2009-02-03 05:40 --------- d-----w c:\documents and settings\Owner\Application Data\Foxit 2009-02-03 05:00 --------- d-----w c:\documents and settings\Owner\Application Data\DriverCure 2009-02-03 04:59 --------- d-----w c:\documents and settings\All Users\Application Data\ParetoLogic 2009-02-03 01:37 --------- d-----w c:\program files\iTunes 2009-02-03 01:37 --------- d-----w c:\program files\iPod 2009-02-03 01:37 --------- d-----w c:\program files\Common Files\Apple 2009-02-03 01:37 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2009-02-03 01:31 --------- d-----w c:\program files\QuickTime 2009-02-01 12:49 --------- d-----w c:\program files\KYE 2009-02-01 12:49 --------- d-----w c:\program files\Common Files\snpstd 2009-01-31 05:42 8 -c--a-w c:\documents and settings\Owner\Application Data\usb.dat 2009-01-31 03:49 --------- d-----w c:\program files\MP3 Player Utilities 2009-01-29 22:47 --------- d-----w c:\program files\Microsoft Office Outlook Connector 2009-01-29 22:47 --------- d-----w c:\program files\Microsoft 2009-01-29 22:46 --------- d-----w c:\program files\Microsoft Sync Framework 2009-01-29 22:43 --------- d-----w c:\program files\Windows Live SkyDrive 2009-01-29 22:33 --------- d-----w c:\program files\Common Files\Windows Live 2009-01-29 07:37 --------- d-----w c:\program files\MSBuild 2009-01-29 07:36 --------- d-----w c:\program files\Reference Assemblies 2009-01-14 15:05 911,872 ----a-w c:\windows\system32\wininet.dll 2009-01-14 15:05 43,008 -c--a-w c:\windows\system32\licmgr10.dll 2009-01-14 15:04 18,944 -c--a-w c:\windows\system32\corpol.dll 2009-01-14 15:03 72,704 -c--a-w c:\windows\system32\admparse.dll 2009-01-14 15:03 71,680 -c--a-w c:\windows\system32\iesetup.dll 2009-01-14 15:03 420,352 -c--a-w c:\windows\system32\vbscript.dll 2009-01-14 15:01 34,304 -c--a-w c:\windows\system32\imgutil.dll 2009-01-14 15:00 48,128 -c--a-w c:\windows\system32\mshtmler.dll 2009-01-14 15:00 45,568 -c--a-w c:\windows\system32\mshta.exe 2009-01-14 14:50 156,160 -c--a-w c:\windows\system32\msls31.dll 2009-01-05 22:33 3,751,995 -c--a-w c:\windows\system32\GPhotos.scr 2008-12-31 06:04 691,560 -c--a-w c:\windows\system32\OGACheckControl.dll 2008-12-31 06:04 528,744 -c--a-w c:\windows\system32\OGAVerify.exe 2008-12-31 06:04 502,120 -c--a-w c:\windows\system32\OGAAddin.dll 2008-12-12 03:47 190 -c--a-w c:\documents and settings\Owner\Fix.reg 2008-05-19 06:18 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051920080520\index.dat 2008-05-19 06:19 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "TrustDefenderWD"="c:\program files\TrustDefender\TrustDefender\WinUserAppLauncher.exe" [2009-03-21 15528] "snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088] "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000] "F-Secure Manager"="c:\program files\Optus Internet Security Suite\Common\FSM32.EXE" [2008-09-24 182936] "F-Secure TNB"="c:\program files\Optus Internet Security Suite\FSGUI\TNBUtil.exe" [2008-09-24 957024] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "iKeyWorks"="c:\program files\A4Tech\Keyboard\Ikeymain.exe" [2007-06-25 65536] "HydraVisionDesktopManager"="c:\program files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 270336] "HydraVisionViewport"="c:\program files\ATI Technologies\ATI HYDRAVISION\HydraMD.exe" [2003-09-15 364544] "PCTVOICE"="pctspk.exe" [2001-08-17 c:\windows\system32\pctspk.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160] c:\documents and settings\All Users\Start Menu\Programs\Startup\ WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-01-14 525664] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "SynchronousMachineGroupPolicy"= 0 (0x0) "SynchronousUserGroupPolicy"= 0 (0x0) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \[u]0[/u] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager] -----c--- 2003-08-19 02:01 110592 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\kav\\kav7.0\\english\\setup.exe"= "c:\\Program Files\\TrustDefender\\TrustDefender\\TrustDefender.exe"= R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2009-03-02 79904] S0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-03-02 33408] S1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Optus Internet Security Suite\HIPS\drivers\fshs.sys [2009-03-02 66720] S1 TRIXX;TRIXX;c:\program files\TRIXX\TRIXXDriver.sys [2005-08-16 15360] S2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [2005-12-15 75925] S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-01-30 55136] S2 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360] S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226656] S2 TrustDefender;TrustDefender;c:\program files\TrustDefender\TrustDefender\TrustDefender.exe [2008-07-30 1683624] S2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;c:\windows\system32\drivers\wf2ktunr.sys [2005-12-15 36423] S2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;c:\windows\system32\drivers\wf2kXbar.sys [2005-12-15 10005] S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592] S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [2009-03-17 14336] S3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Optus Internet Security Suite\Anti-Virus\minifilter\fsgk.sys [2009-03-02 84608] S3 FSORSPClient;F-Secure ORSP Client;c:\program files\Optus Internet Security Suite\ORSP Client\fsorsp.exe [2009-03-02 55904] S3 FwHookDrv;FwHookDrv;c:\program files\TrustDefender\TrustDefender\FwHookDrv.sys [2008-07-30 9896] S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [2006-01-18 167424] S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Optus Internet Security Suite\Anti-Virus\win2k\fsfilter.sys [2009-03-02 39776] S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Optus Internet Security Suite\Anti-Virus\win2k\fsrec.sys [2009-03-02 25184] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-03-23 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34] 2009-03-26 c:\windows\Tasks\OGADaily.job - c:\windows\system32\OGAVerify.exe [2008-12-31 17:04] 2009-03-26 c:\windows\Tasks\OGALogon.job - c:\windows\system32\OGAVerify.exe [2008-12-31 17:04] 2009-03-26 c:\windows\Tasks\User_Feed_Synchronization-{BD0500D5-94D0-49A9-A55F-C28465FABBC6}.job - c:\windows\system32\msfeedssync.exe [2009-01-15 02:01] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ninemsn.com.au/ LSP: c:\program files\Optus Internet Security Suite\FSPS\program\fslsp.dll DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\ FF - prefs.js: browser.search.defaulturl - FF - prefs.js: browser.search.selectedEngine - FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au/|http://rover.ebay.com/rover/1/710-47297-17704-0/4?mfe=startTab&mpre=http%3A%2F%2Fwww.ebay.co.uk%2F FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayFormSubmitObserver.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll ---- FIREFOX POLICIES ---- . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-26 19:55:21 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-1214440339-413027322-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_LOCAL_MACHINE\System\ControlSet001\Control\ContentIndex\Language\Nbliu*] "Locale"=dword:00000000 "WBreakerClass"="{369647e0-17b0-11ce-9950-00aa004bbb1f}" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(492) c:\windows\system32\Ati2evxx.dll c:\windows\system32\sirenacm.dll . Completion time: 2009-03-26 19:56:52 ComboFix-quarantined-files.txt 2009-03-26 08:56:50 ComboFix2.txt 2009-03-26 08:36:33 Pre-Run: 132,180,725,760 bytes free Post-Run: 132,161,540,096 bytes free 341 --- E O F --- 2009-03-19 22:22:17