ComboFix 09-04-19.05 - Dave 04/19/2009 11:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.242 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dave\Application Data\inst.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-19 to 2009-04-19 )))))))))))))))))))))))))))))))
.
2009-04-18 01:45 . 2009-04-18 01:45 ——– d—–w C:\_OTMoveIt
2009-04-18 01:37 . 2009-04-18 01:37 73728 —-a-w c:\windows\system32\javacpl.cpl
2009-04-18 01:37 . 2009-04-18 01:37 410984 —-a-w c:\windows\system32\deploytk.dll
2009-04-17 21:45 . 2009-04-17 21:48 ——– d—–w c:\documents and settings\Dave\Application Data\Mp3tag
2009-04-17 20:21 . 2009-04-17 20:22 ——– d—–w C:\Rooter$
2009-04-17 16:00 . 2009-04-17 16:00 54156 —ha-w c:\windows\QTFont.qfn
2009-04-17 16:00 . 2009-04-17 16:00 1409 —-a-w c:\windows\QTFont.for
2009-04-16 21:40 . 2009-04-16 21:40 ——– d—–w c:\documents and settings\Dave\Application Data\Malwarebytes
2009-04-16 21:40 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-16 21:40 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-16 21:40 . 2009-04-16 21:40 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-15 21:52 . 2009-04-15 21:53 ——– d—–w C:\music
2009-04-07 22:14 . 2009-04-13 16:57 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-07 00:15 . 2009-02-13 15:31 55640 —-a-w c:\windows\system32\drivers\avgntflt.sys
2009-04-06 01:39 . 2009-04-07 22:54 ——– d–h–w C:\$AVG8.VAULT$
2009-04-04 14:48 . 2009-04-04 14:48 ——– d—–w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-03-22 22:07 . 2009-03-22 22:08 ——– d—–w c:\documents and settings\Dave\Local Settings\Application Data\Deployment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-19 14:32 . 2007-10-16 21:09 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-19 13:43 . 2007-10-10 17:02 ——– d—–w c:\documents and settings\Dave\Application Data\OpenOffice.org2
2009-04-18 01:37 . 2005-12-15 01:46 ——– d—–w c:\program files\Java
2009-04-17 23:53 . 2009-04-17 23:53 ——– d—–w c:\program files\TagScanner
2009-04-17 21:51 . 2009-04-17 21:48 ——– d—–w c:\program files\The GodFather
2009-04-17 21:45 . 2009-04-17 21:45 ——– d—–w c:\program files\Mp3tag
2009-04-17 21:18 . 2007-09-26 16:00 ——– d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2009-04-17 20:22 . 2009-04-17 20:22 2587 —-a-w C:\Rooter.txt
2009-04-16 21:40 . 2009-04-16 21:40 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-16 14:31 . 2007-10-16 21:06 ——– d—–w c:\documents and settings\Dave\Application Data\VideoReDoPlus
2009-04-14 00:06 . 2007-10-06 00:07 ——– d—–w c:\program files\SpywareBlaster
2009-04-13 20:36 . 2009-03-28 12:31 ——– d—–w c:\program files\FLAC
2009-04-13 16:57 . 2009-01-18 23:43 ——– d—–w c:\program files\Gabest
2009-04-13 16:57 . 2009-04-13 16:57 ——– d—–w c:\program files\AVG
2009-04-13 16:53 . 2007-10-06 00:09 ——– d—–w c:\program files\SpywareGuard
2009-04-12 14:31 . 2009-04-12 14:31 ——– d—–w c:\program files\Trend Micro
2009-04-07 01:07 . 2009-04-05 18:55 731 ——w C:\Win32.Worm.Downladup.Gen.log
2009-04-06 02:07 . 2005-08-17 02:54 ——– d—–w c:\program files\DIGStream
2009-04-04 14:57 . 2009-04-04 14:57 ——– d—–w c:\program files\AudioShell
2009-04-01 23:04 . 2009-03-30 13:13 732 —-a-w C:\muxman.log
2009-03-29 22:08 . 2009-01-18 23:49 ——– d—–w c:\program files\VisualSubSync
2009-03-29 22:08 . 2009-03-29 22:05 ——– d—–w c:\program files\URUSoft
2009-03-18 16:18 . 2007-10-06 00:08 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-03-18 16:18 . 2007-10-06 00:08 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-16 13:46 . 2005-12-15 01:55 ——– d—–w c:\documents and settings\All Users\Application Data\QuickTime
2009-03-02 04:46 . 2008-09-18 23:37 ——– d—–w c:\program files\WinFF
2009-03-02 00:41 . 2008-02-01 03:00 ——– d—–w c:\documents and settings\Dave\Application Data\Winff
2009-02-26 16:15 . 2009-02-26 16:15 ——– d—–w c:\documents and settings\Dave\Application Data\RipIt4Me
2009-02-23 22:54 . 2008-02-09 17:23 ——– d—–w c:\documents and settings\Dave\Application Data\dvdcss
2009-02-09 10:19 . 2007-03-08 13:47 1846272 ——w c:\windows\system32\dllcache\win32k.sys
2009-02-09 10:19 . 2005-08-16 10:18 1846272 —-a-w c:\windows\system32\win32k.sys
2009-01-24 02:05 . 2009-01-24 02:05 685056 —-a-w c:\windows\is-22L6P.exe
2008-08-02 23:48 . 2008-08-02 23:48 47360 —-a-w c:\documents and settings\Dave\Application Data\pcouffin.sys
2008-05-22 17:18 . 2007-09-26 16:20 27264 —-a-w c:\documents and settings\Dave\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-10-03 02:56 . 2007-09-26 04:59 127 —-a-w c:\documents and settings\Dave\Local Settings\Application Data\fusioncache.dat
2005-08-17 02:52 . 2005-08-17 02:52 136 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2005-05-13 21:12 . 2005-05-13 21:12 217073 –sha-r c:\windows\meta4.exe
2005-10-24 15:13 . 2005-10-24 15:13 66560 –sha-r c:\windows\MOTA113.exe
2008-08-07 03:13 . 2008-08-07 03:11 24 –sh–w c:\windows\S5EBCFEA5.tmp
2005-10-14 01:27 . 2005-10-14 01:27 422400 –sha-r c:\windows\x2.64.exe
2005-07-14 16:31 . 2005-07-14 16:31 27648 –sha-r c:\windows\system32\AVSredirect.dll
2005-06-26 19:32 . 2005-06-26 19:32 616448 –sha-r c:\windows\system32\cygwin1.dll
2005-06-22 02:37 . 2005-06-22 02:37 45568 –sha-r c:\windows\system32\cygz.dll
2004-01-25 04:00 . 2004-01-25 04:00 70656 –sha-r c:\windows\system32\i420vfw.dll
2006-04-27 14:24 . 2006-04-27 14:24 2945024 –sha-r c:\windows\system32\Smab.dll
2005-02-28 17:16 . 2005-02-28 17:16 240128 –sha-r c:\windows\system32\x.264.exe
2004-01-25 04:00 . 2004-01-25 04:00 70656 –sha-r c:\windows\system32\yv12vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Ahead\Ahead\data\Xtras\mssysmgr.exe" [2004-05-12 196608]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-12-15 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-12-15 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-13 1117184]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-05-12 270336]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-18 148888]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]
c:\documents and settings\Dave\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-9-29 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-12-14 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
R3 KBCAM;JamC@m USB service;c:\windows\system32\Drivers\KBCAM.sys [2000-10-09 16384]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - c:\program files\Qualcomm\Eudora\EuShlExt.dll
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
TCP: {4AEEE83A-196B-45D4-A779-1303EEFF36B8} = 64.136.173.5 64.136.164.77
FF - ProfilePath - c:\documents and settings\Dave\Application Data\Mozilla\Firefox\Profiles\96u2iqfh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-19 11:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-04-19 11:04
ComboFix-quarantined-files.txt 2009-04-19 15:04
Pre-Run: 59,166,924,800 bytes free
Post-Run: 59,152,281,600 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
158 — E O F — 2009-03-22 12:27