ComboFix 09-03-25.02 - Owner 2009-03-26 19:52:45.6 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.763 [GMT 11:00]
Running from: c:\documents and settings\[removed]\desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\desktop\CFScript.txt
AV: Optus Internet Security Suite 2009 8.00 *On-access scanning disabled* (Updated)
FW: Optus Internet Security Suite 2009 8.00 *disabled*
.
((((((((((((((((((((((((( Files Created from 2009-02-26 to 2009-03-26 )))))))))))))))))))))))))))))))
.
2009-03-24 12:30 . 2009-03-24 12:34
d-------- C:\Combo-Fix
2009-03-24 12:28 . 2009-03-24 12:28 128 --a------ c:\windows\system32\perf.dat
2009-03-22 18:50 . 2009-03-22 18:50 d-------- C:\Inetpub
2009-03-22 08:18 . 2009-03-22 08:18 0 --a------ c:\documents and settings\Owner\Application Data\TrustDefender.dll
2009-03-19 19:54 . 2009-03-19 19:54 d-------- C:\System Utilities
2009-03-17 19:47 . 2007-06-17 01:00 14,336 --a------ c:\windows\system32\drivers\Amps2prt.sys
2009-03-17 19:47 . 2007-02-10 23:55 13,824 --a------ c:\windows\system32\drivers\Amusbprt.sys
2009-03-17 19:47 . 2006-04-11 13:56 10,240 --a------ c:\windows\system32\drivers\Arfumx86.sys
2009-03-17 19:47 . 2007-01-24 17:46 8,704 --a------ c:\windows\system32\drivers\Amfilter.sys
2009-03-03 11:45 . 2009-03-16 21:24 d-------- c:\program files\Eusing Free Registry Cleaner
2009-03-02 21:36 . 2009-03-02 21:36 33,408 --a--c--- c:\windows\system32\drivers\fsbts.sys
2009-03-02 21:05 . 2008-09-24 00:35 79,904 --a--c--- c:\windows\system32\drivers\fsdfw.sys
2009-02-26 22:04 . 2009-02-26 22:04 d-------- c:\program files\Kaspersky Anti Virus 6.0.2.621
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-26 04:02 --------- d-----w c:\program files\Optus Internet Security Suite
2009-03-22 21:12 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2009-03-22 06:32 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-21 09:44 --------- d-----w c:\program files\A4Tech
2009-03-21 09:38 --------- d-----w c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2009-03-18 09:56 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-18 05:43 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-18 05:43 --------- d-----w c:\program files\ATI Technologies
2009-03-08 08:50 --------- d-----w c:\program files\Google
2009-03-03 01:30 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-02 10:04 --------- d-----w c:\documents and settings\All Users\Application Data\F-Secure
2009-03-02 10:03 --------- d-----w c:\documents and settings\All Users\Application Data\fssg
2009-02-28 07:31 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-26 07:36 --------- dc----w c:\program files\Common Files\WindowsLiveInstaller
2009-02-26 07:36 --------- d-----w c:\program files\Winamp
2009-02-26 07:36 --------- d-----w c:\program files\Java
2009-02-26 07:36 --------- d-----w c:\program files\FinePixViewer
2009-02-26 07:36 --------- d-----w c:\program files\DVD Wizard Pro
2009-02-26 07:36 --------- d-----w c:\program files\DivX
2009-02-26 07:36 --------- d-----w c:\program files\Common Files\Vbox
2009-02-26 07:36 --------- d-----w c:\program files\Common Files\Ahead
2009-02-26 07:36 --------- d-----w c:\program files\Apple Software Update
2009-02-26 07:36 --------- d-----w c:\program files\Acoustica Spin It Again
2009-02-25 00:16 --------- d-----w c:\program files\SUPERAntiSpyware
2009-02-23 12:51 --------- d-----w c:\program files\Acoustica Shared Effects
2009-02-23 07:16 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-23 07:16 --------- d-----w c:\program files\SpywareBlaster
2009-02-21 21:22 --------- d-----w c:\program files\Windows Live
2009-02-16 11:11 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-12 10:58 --------- d-----w c:\documents and settings\All Users\Application Data\DriverCure
2009-02-12 07:55 --------- d-----w c:\program files\NCH Software
2009-02-12 07:55 --------- d-----w c:\program files\AGI
2009-02-12 07:55 --------- d-----w c:\program files\7-Zip
2009-02-12 07:55 --------- d-----w c:\documents and settings\Owner\Application Data\Uniblue
2009-02-12 07:55 --------- d-----w c:\documents and settings\Owner\Application Data\BitTorrent
2009-02-12 06:12 --------- d-----w c:\documents and settings\Administrator\Application Data\Sonic
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 08:03 307,576 -c--a-w c:\windows\WLXPGSS.SCR
2009-02-06 07:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-05 00:38 --------- d-----w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-02-03 05:55 --------- d-----w c:\program files\Common Files\xing shared
2009-02-03 05:55 --------- d-----w c:\program files\Common Files\Real
2009-02-03 05:54 --------- d-----w c:\program files\Real
2009-02-03 05:41 --------- d-----w c:\program files\AskBarDis
2009-02-03 05:40 --------- d-----w c:\documents and settings\Owner\Application Data\Foxit
2009-02-03 05:00 --------- d-----w c:\documents and settings\Owner\Application Data\DriverCure
2009-02-03 04:59 --------- d-----w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-02-03 01:37 --------- d-----w c:\program files\iTunes
2009-02-03 01:37 --------- d-----w c:\program files\iPod
2009-02-03 01:37 --------- d-----w c:\program files\Common Files\Apple
2009-02-03 01:37 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-03 01:31 --------- d-----w c:\program files\QuickTime
2009-02-01 12:49 --------- d-----w c:\program files\KYE
2009-02-01 12:49 --------- d-----w c:\program files\Common Files\snpstd
2009-01-31 05:42 8 -c--a-w c:\documents and settings\Owner\Application Data\usb.dat
2009-01-31 03:49 --------- d-----w c:\program files\MP3 Player Utilities
2009-01-29 22:47 --------- d-----w c:\program files\Microsoft Office Outlook Connector
2009-01-29 22:47 --------- d-----w c:\program files\Microsoft
2009-01-29 22:46 --------- d-----w c:\program files\Microsoft Sync Framework
2009-01-29 22:43 --------- d-----w c:\program files\Windows Live SkyDrive
2009-01-29 22:33 --------- d-----w c:\program files\Common Files\Windows Live
2009-01-29 07:37 --------- d-----w c:\program files\MSBuild
2009-01-29 07:36 --------- d-----w c:\program files\Reference Assemblies
2009-01-14 15:05 911,872 ----a-w c:\windows\system32\wininet.dll
2009-01-14 15:05 43,008 -c--a-w c:\windows\system32\licmgr10.dll
2009-01-14 15:04 18,944 -c--a-w c:\windows\system32\corpol.dll
2009-01-14 15:03 72,704 -c--a-w c:\windows\system32\admparse.dll
2009-01-14 15:03 71,680 -c--a-w c:\windows\system32\iesetup.dll
2009-01-14 15:03 420,352 -c--a-w c:\windows\system32\vbscript.dll
2009-01-14 15:01 34,304 -c--a-w c:\windows\system32\imgutil.dll
2009-01-14 15:00 48,128 -c--a-w c:\windows\system32\mshtmler.dll
2009-01-14 15:00 45,568 -c--a-w c:\windows\system32\mshta.exe
2009-01-14 14:50 156,160 -c--a-w c:\windows\system32\msls31.dll
2009-01-05 22:33 3,751,995 -c--a-w c:\windows\system32\GPhotos.scr
2008-12-31 06:04 691,560 -c--a-w c:\windows\system32\OGACheckControl.dll
2008-12-31 06:04 528,744 -c--a-w c:\windows\system32\OGAVerify.exe
2008-12-31 06:04 502,120 -c--a-w c:\windows\system32\OGAAddin.dll
2008-12-12 03:47 190 -c--a-w c:\documents and settings\Owner\Fix.reg
2008-05-19 06:18 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051920080520\index.dat
2008-05-19 06:19 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"TrustDefenderWD"="c:\program files\TrustDefender\TrustDefender\WinUserAppLauncher.exe" [2009-03-21 15528]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"F-Secure Manager"="c:\program files\Optus Internet Security Suite\Common\FSM32.EXE" [2008-09-24 182936]
"F-Secure TNB"="c:\program files\Optus Internet Security Suite\FSGUI\TNBUtil.exe" [2008-09-24 957024]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"iKeyWorks"="c:\program files\A4Tech\Keyboard\Ikeymain.exe" [2007-06-25 65536]
"HydraVisionDesktopManager"="c:\program files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 270336]
"HydraVisionViewport"="c:\program files\ATI Technologies\ATI HYDRAVISION\HydraMD.exe" [2003-09-15 364544]
"PCTVOICE"="pctspk.exe" [2001-08-17 c:\windows\system32\pctspk.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-01-14 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \[u]0[/u]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
-----c--- 2003-08-19 02:01 110592 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\kav\\kav7.0\\english\\setup.exe"=
"c:\\Program Files\\TrustDefender\\TrustDefender\\TrustDefender.exe"=
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2009-03-02 79904]
S0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2009-03-02 33408]
S1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Optus Internet Security Suite\HIPS\drivers\fshs.sys [2009-03-02 66720]
S1 TRIXX;TRIXX;c:\program files\TRIXX\TRIXXDriver.sys [2005-08-16 15360]
S2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [2005-12-15 75925]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-01-30 55136]
S2 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226656]
S2 TrustDefender;TrustDefender;c:\program files\TrustDefender\TrustDefender\TrustDefender.exe [2008-07-30 1683624]
S2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;c:\windows\system32\drivers\wf2ktunr.sys [2005-12-15 36423]
S2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;c:\windows\system32\drivers\wf2kXbar.sys [2005-12-15 10005]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [2009-03-17 14336]
S3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Optus Internet Security Suite\Anti-Virus\minifilter\fsgk.sys [2009-03-02 84608]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files\Optus Internet Security Suite\ORSP Client\fsorsp.exe [2009-03-02 55904]
S3 FwHookDrv;FwHookDrv;c:\program files\TrustDefender\TrustDefender\FwHookDrv.sys [2008-07-30 9896]
S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [2006-01-18 167424]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Optus Internet Security Suite\Anti-Virus\win2k\fsfilter.sys [2009-03-02 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Optus Internet Security Suite\Anti-Virus\win2k\fsrec.sys [2009-03-02 25184]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-03-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-26 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-03-26 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-03-26 c:\windows\Tasks\User_Feed_Synchronization-{BD0500D5-94D0-49A9-A55F-C28465FABBC6}.job
- c:\windows\system32\msfeedssync.exe [2009-01-15 02:01]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ninemsn.com.au/
LSP: c:\program files\Optus Internet Security Suite\FSPS\program\fslsp.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au/|http://rover.ebay.com/rover/1/710-47297-17704-0/4?mfe=startTab&mpre=http%3A%2F%2Fwww.ebay.co.uk%2F
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayFormSubmitObserver.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-26 19:55:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1214440339-413027322-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\System\ControlSet001\Control\ContentIndex\Language\Nbliu*]
"Locale"=dword:00000000
"WBreakerClass"="{369647e0-17b0-11ce-9950-00aa004bbb1f}"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(492)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\sirenacm.dll
.
Completion time: 2009-03-26 19:56:52
ComboFix-quarantined-files.txt 2009-03-26 08:56:50
ComboFix2.txt 2009-03-26 08:36:33
Pre-Run: 132,180,725,760 bytes free
Post-Run: 132,161,540,096 bytes free
341 --- E O F --- 2009-03-19 22:22:17