ComboFix 10-03-04.02 - Compaq_Owner 03/04/2010 21:16:09.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.166 [GMT -5:00] Running from: c:\documents and settings\[removed]\My Documents\What the Tech\8-ComboFix.exe AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-2818039499-136864462-2478682702-1000 c:\recycler\S-1-5-21-1495973555-2648357843-2704818806-1006 c:\recycler\S-1-5-21-1776776874-2133223820-870459611-1009 c:\recycler\S-1-5-21-3292051158-853124604-1004941977-1009 c:\recycler\S-1-5-21-571547183-3323540573-1447636342-1010 c:\recycler\S-1-5-21-884105296-3116323169-961226105-1009 c:\windows\EventSystem.log c:\windows\jestertb.dll c:\windows\viassary-hp.reg D:\Autorun.inf J:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2010-02-05 to 2010-03-05 ))))))))))))))))))))))))))))))) . 2010-03-01 02:33 . 2010-03-01 02:33 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\PCHealth 2010-02-28 20:08 . 2010-02-28 20:08 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes 2010-02-28 20:08 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-28 20:08 . 2010-02-28 20:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-02-28 20:08 . 2010-02-28 20:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-02-28 20:08 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-02-28 19:55 . 2010-02-28 19:56 -------- d-----w- c:\program files\ERUNT 2010-02-28 09:09 . 2010-02-28 09:09 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth 2010-02-28 08:15 . 2010-02-28 08:15 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2 2010-02-23 23:22 . 2010-02-24 14:16 181632 ------w- c:\windows\system32\MpSigStub.exe 2010-02-23 23:20 . 2010-02-23 23:20 -------- d-----w- c:\program files\Microsoft Security Essentials 2010-02-23 22:56 . 2009-08-07 00:23 215920 ----a-w- c:\windows\system32\muweb.dll 2010-02-23 22:56 . 2009-08-07 00:23 274288 ----a-w- c:\windows\system32\mucltui.dll 2010-02-23 22:51 . 2010-02-23 22:51 -------- d-----w- c:\windows\system32\wbem\Repository 2010-02-17 04:01 . 2010-02-17 04:01 1063320 ----a-w- c:\documents and settings\Compaq_Owner\gotomypc_533.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-05 02:39 . 2009-07-01 17:10 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-03-05 02:36 . 2009-07-01 17:10 -------- d-----w- c:\program files\Spyware Doctor 2010-03-04 17:43 . 2008-06-22 19:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2010-03-04 16:45 . 2009-06-26 14:09 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Skype 2010-03-04 13:12 . 2009-06-26 14:14 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\skypePM 2010-03-01 02:42 . 2009-09-03 02:58 -------- d-----w- c:\program files\Winamp 2010-02-28 21:02 . 2008-05-03 00:31 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\LimeWire 2010-02-28 19:39 . 2007-02-10 21:15 59 ----a-w- c:\windows\wpd99.drv 2010-02-28 19:39 . 2007-02-10 21:15 -------- d-----w- c:\documents and settings\All Users\Application Data\pdf995 2010-02-28 19:10 . 2006-06-17 05:07 -------- d-----w- c:\program files\Java 2010-02-28 19:05 . 2010-02-28 19:05 152576 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2010-02-28 19:05 . 2010-02-28 19:05 79488 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-02-28 14:22 . 2008-04-29 01:19 311776 ----a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-02-28 14:16 . 2008-04-30 23:46 -------- d-----w- c:\program files\Microsoft Silverlight 2010-02-01 18:48 . 2006-06-17 05:26 -------- d-----w- c:\program files\Common Files\Real 2010-02-01 18:47 . 2010-02-01 18:47 -------- d-----w- c:\program files\Common Files\xing shared 2010-02-01 18:47 . 2003-03-19 10:14 499712 ----a-w- c:\windows\system32\msvcp71.dll 2010-02-01 18:47 . 2003-02-21 18:42 348160 ----a-w- c:\windows\system32\msvcr71.dll 2010-01-29 18:36 . 2006-06-17 05:34 -------- d-----w- c:\program files\Common Files\Adobe 2009-12-31 16:50 . 2004-08-04 11:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-22 22:51 . 2009-12-22 22:49 249856 ------w- c:\windows\Setup1.exe 2009-12-22 22:51 . 2009-12-22 22:49 73216 ----a-w- c:\windows\ST6UNST.EXE 2009-12-21 19:14 . 2004-08-04 11:00 916480 ----a-w- c:\windows\system32\wininet.dll 2009-12-16 18:43 . 2004-08-04 11:00 343040 ----a-w- c:\windows\system32\mspaint.exe 2009-12-14 19:15 . 2009-12-14 19:15 2146304 ----a-w- c:\windows\system32\GPhotos.scr 2009-12-14 07:08 . 2004-08-04 11:00 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-08 19:27 . 2004-08-04 11:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 . 2004-08-04 11:00 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-24 68856] "EPSON Stylus CX7800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAFA.EXE" [2005-04-07 98304] "Google Update"="c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-26 133104] "FBackup Scheduler"="c:\program files\Softland\FBackup 4\fbaSched.exe" [2010-01-20 2011312] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2006-03-08 16010240] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-25 7311360] "nwiz"="nwiz.exe" [2006-01-25 1519616] "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568] "HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856] "HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152] "EPSON Stylus CX7800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAFA.EXE" [2005-04-07 98304] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696] "ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-07-17 64000] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-07-01 30192] "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-09-22 1243088] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-02-01 198160] "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Event Reminder.lnk - c:\program files\PrintMaster Platinum 18\Remind.exe [2007-9-9 344064] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/1/2009 12:10 PM 207280] R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [11/11/2009 12:04 AM 358600] S2 gupdate1c9f667dba81f24;Google Update Service (gupdate1c9f667dba81f24);c:\program files\Google\Update\GoogleUpdate.exe [6/26/2009 9:09 AM 133104] S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [9/5/2006 8:38 PM 30192] --- Other Services/Drivers In Memory --- *Deregistered* - PCTSDInjDriver32 . Contents of the 'Scheduled Tasks' folder 2010-03-04 c:\windows\Tasks\fba_Nara's Mirror Backup.job - c:\program files\Softland\FBackup 4\fbaSchedStarter.exe [2009-12-23 16:48] 2010-03-05 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-12 01:07] 2010-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 14:09] 2010-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 14:09] 2010-03-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1423889170-2883610794-949276770-1009Core.job - c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-05 19:28] 2010-03-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1423889170-2883610794-949276770-1009UA.job - c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-05 19:28] 2010-03-05 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-02 22:36] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.weshalldance.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PRESARIO&pf=desktop uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PRESARIO&pf=desktop uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add To Compaq Organize... - c:\progra~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 . . ------- File Associations ------- . . - - - - ORPHANS REMOVED - - - - URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) HKCU-Run-Performance Center - c:\program files\Ascentive\Performance Center\ApcMain.exe HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe HKCU-Run-mnumsg.exe - c:\program files\MyShoppingGenie\mnumsg.exe HKLM-Run-PCDrProfiler - (no file) AddRemove-Spyware Doctor - c:\program files\Spyware Doctor\unins000.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-04 21:39 Windows 5.1.2600 Service Pack 3 NTFS detected NTDLL code modification: ZwClose scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(2780) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Microsoft Security Essentials\MsMpEng.exe c:\program files\Google\Update\1.2.183.17\GoogleCrashHandler.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\nvsvc32.exe c:\program files\Spyware Doctor\pctsSvc.exe c:\windows\RTHDCPL.EXE c:\windows\system\hpsysdrv.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2010-03-04 21:47:00 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-05 02:46 Pre-Run: 138,323,107,840 bytes free Post-Run: 142,202,818,560 bytes free - - End Of File - - 48B21DF6844451C5CC9D087CAA5C44BD