ComboFix 09-10-15.04 - Janet 10/16/2009 19:41.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3061.2449 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_WINDOWS_HOSTS_CONTROLLER
((((((((((((((((((((((((( Files Created from 2009-09-16 to 2009-10-16 )))))))))))))))))))))))))))))))
.
2009-10-16 10:44 . 2009-10-16 10:44 ——– d—–w- c:\windows\ERUNT
2009-10-16 10:38 . 2009-10-16 11:13 ——– d—–w- C:\SDFix
2009-10-15 21:59 . 2009-10-15 21:59 ——– d—–w- C:\$AVG
2009-10-15 21:59 . 2009-10-15 21:59 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-10-15 21:59 . 2009-10-15 21:59 356616 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-15 21:59 . 2009-10-15 21:59 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-15 21:59 . 2009-10-15 21:59 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-15 21:59 . 2009-10-16 08:29 ——– d—–w- c:\windows\system32\drivers\Avg
2009-10-15 21:59 . 2009-10-15 21:59 ——– d—–w- c:\program files\AVG
2009-10-15 21:59 . 2009-10-15 21:59 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2009-10-14 15:59 . 2009-10-14 15:59 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-14 15:58 . 2009-10-16 08:39 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-10-14 15:58 . 2009-10-14 15:58 ——– d—–w- c:\documents and settings\Janet\Application Data\SUPERAntiSpyware.com
2009-10-14 13:10 . 2009-10-14 13:10 10752 —-a-w- c:\windows\DCEBoot.exe
2009-10-14 09:29 . 2009-10-14 09:29 ——– d—–w- c:\documents and settings\Janet\Application Data\Malwarebytes
2009-10-14 09:29 . 2009-09-10 06:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-14 09:29 . 2009-10-14 09:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-14 09:29 . 2009-09-10 06:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-10-14 09:29 . 2009-10-14 09:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-10-13 10:42 . 2009-04-02 23:08 50192 —-a-w- c:\windows\system32\drivers\tmactmon.sys
2009-10-13 10:42 . 2009-04-02 23:08 50192 —-a-w- c:\windows\system32\drivers\tmevtmgr.sys
2009-10-13 10:42 . 2009-04-02 23:08 153104 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-13 10:42 . 2009-10-13 10:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Trend Micro
2009-10-13 10:41 . 2009-10-13 10:42 ——– d—–w- c:\program files\Trend Micro
2009-10-13 10:36 . 2009-10-13 10:36 335376 —-a-w- c:\windows\system32\drivers\TM_CFW.sys
2009-10-13 10:36 . 2009-05-22 08:02 225296 —-a-w- c:\windows\system32\drivers\tmxpflt.sys
2009-10-13 10:36 . 2009-05-22 07:45 1220120 —-a-w- c:\windows\system32\drivers\vsapint.sys
2009-10-13 10:36 . 2009-10-13 10:36 80400 —-a-w- c:\windows\system32\drivers\tmtdi.sys
2009-10-13 10:36 . 2009-05-22 08:00 36368 —-a-w- c:\windows\system32\drivers\tmpreflt.sys
2009-10-10 05:26 . 2009-10-10 05:26 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-10-10 05:24 . 2009-07-28 08:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-05 08:55 . 2009-10-05 12:41 ——– d—–w- c:\documents and settings\Janet\.yed3
2009-10-03 00:45 . 2009-10-03 00:45 ——– d—–w- c:\program files\Paint.NET
2009-10-02 15:49 . 2009-10-02 15:49 ——– d—–w- c:\program files\MSXML 6.0
2009-09-26 16:46 . 2009-09-26 16:46 ——– d—–w- c:\documents and settings\Janet\Application Data\Media Player Classic
2009-09-23 16:17 . 2009-09-23 16:17 ——– d—–r- c:\documents and settings\Janet\Application Data\Brother
2009-09-23 15:58 . 2009-09-23 15:58 ——– d—–w- c:\documents and settings\Janet\Local Settings\Application Data\Scansoft
2009-09-23 15:53 . 2009-09-23 15:53 50 —-a-w- c:\windows\system32\bridf08b.dat
2009-09-23 15:53 . 2008-03-18 14:35 1522176 —-a-w- c:\windows\system32\BrWia08a.dll
2009-09-23 15:53 . 2007-12-24 14:24 45056 —-a-w- c:\windows\system32\BrUsi08a.dll
2009-09-23 15:53 . 2004-10-15 04:50 15295 —-a-w- c:\windows\system32\drivers\BrScnUsb.sys
2009-09-23 15:52 . 2007-12-13 14:16 73728 ——w- c:\windows\system32\BrDctF2.dll
2009-09-23 15:52 . 2007-12-13 14:16 5120 ——w- c:\windows\system32\BrDctF2L.dll
2009-09-23 15:52 . 2007-12-13 14:16 3072 ——w- c:\windows\system32\BrDctF2S.dll
2009-09-23 15:52 . 2006-12-28 05:39 176128 ——w- c:\windows\system32\BroSNMP.dll
2009-09-23 15:52 . 2008-01-25 07:21 167936 ——w- c:\windows\system32\NSSearch.dll
2009-09-23 15:52 . 2009-09-23 15:53 ——– d—–w- c:\program files\Brother
2009-09-23 15:52 . 2009-09-23 15:52 ——– d—–w- c:\documents and settings\Janet\Application Data\InstallShield
2009-09-23 15:51 . 2009-09-23 15:51 ——– d—–w- c:\program files\Nuance
2009-09-23 15:50 . 2009-09-23 15:50 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2009-09-23 15:50 . 2009-09-23 15:50 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-09-23 15:50 . 2009-09-23 15:50 ——– d—–w- c:\program files\ScanSoft
2009-09-23 15:49 . 2009-09-23 15:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Brother
2009-09-23 15:45 . 2004-08-03 15:01 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2009-09-23 15:45 . 2004-08-03 15:01 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2009-09-23 15:45 . 2004-08-03 15:08 31616 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-09-23 15:45 . 2004-08-03 15:08 31616 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2009-09-21 17:13 . 2009-09-21 17:13 ——– d—–w- c:\documents and settings\Janet\Application Data\Charles
2009-09-21 17:13 . 2009-09-21 17:13 ——– d—–w- c:\program files\Charles
2009-09-19 13:55 . 2009-10-13 12:27 ——– d—–w- c:\documents and settings\Janet\Application Data\FileZilla
2009-09-19 13:55 . 2009-10-11 11:44 ——– d—–w- c:\program files\FileZilla FTP Client
2009-09-18 13:36 . 2009-09-18 14:14 ——– d—–w- c:\documents and settings\Janet\.VirtualBox
2009-09-18 13:33 . 2009-07-10 09:51 115856 —-a-w- c:\windows\system32\drivers\VBoxDrv.sys
2009-09-18 13:33 . 2009-07-10 09:51 91472 —-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2009-09-18 13:33 . 2009-07-10 09:51 41424 —-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-16 11:46 . 2009-07-12 02:24 24944 —-a-w- c:\windows\system32\drivers\GVTDrv.sys
2009-10-16 11:45 . 2009-07-12 04:11 16608 —-a-w- c:\windows\gdrv.sys
2009-10-13 21:44 . 2009-07-12 04:54 ——– d—–w- c:\program files\BitComet
2009-10-13 10:39 . 2009-07-12 05:13 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-10-13 10:38 . 2009-07-12 05:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-10 06:34 . 2009-07-12 02:13 29768 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-10 04:47 . 2009-07-12 03:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-10-10 04:47 . 2009-07-12 03:16 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-10-04 06:22 . 2009-07-22 13:31 ——– d—–w- c:\documents and settings\Janet\Application Data\Orbit
2009-10-04 05:12 . 2009-07-15 10:36 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-10-02 15:52 . 2009-10-02 15:52 113024 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-10-02 15:51 . 2009-10-02 15:51 ——– d—–w- c:\program files\MSBuild
2009-10-02 15:51 . 2009-10-02 15:51 ——– d—–w- c:\program files\Reference Assemblies
2009-09-23 15:52 . 2009-07-12 01:52 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-09-20 09:01 . 2009-08-31 11:25 ——– d—–w- c:\program files\Mozilla Thunderbird
2009-09-18 13:33 . 2009-07-12 04:21 ——– d—–w- c:\program files\Sun
2009-09-18 13:27 . 2009-08-23 03:11 ——– d—–w- c:\program files\EmfPrinter
2009-09-18 13:25 . 2009-08-23 03:20 ——– d—–w- c:\program files\ImagePrinter
2009-09-15 14:56 . 2009-07-12 02:10 ——– d—–w- c:\program files\Common Files\Adobe
2009-09-15 10:23 . 2009-09-15 10:23 29332 —ha-w- c:\windows\system32\mlfcache.dat
2009-09-13 10:41 . 2009-09-13 10:41 ——– d—–w- c:\program files\Graphviz2.24
2009-09-13 10:28 . 2009-09-10 21:47 ——– d—–w- c:\documents and settings\Janet\Application Data\JGoodies
2009-09-12 17:55 . 2009-07-12 07:06 ——– d—–w- c:\program files\QvodPlayer
2009-09-11 16:11 . 2009-09-10 13:13 ——– d—–w- c:\documents and settings\Janet\Application Data\Download Manager
2009-09-11 13:29 . 2009-09-11 13:29 ——– d—–w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-09-11 13:20 . 2009-09-11 13:20 ——– d—–w- c:\documents and settings\All Users\Application Data\ALM
2009-09-11 13:17 . 2009-09-11 13:17 ——– d—–w- c:\program files\Adobe Media Player
2009-09-11 13:12 . 2009-09-11 13:12 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2009-09-10 13:28 . 2009-09-10 13:28 ——– d—–w- c:\documents and settings\Janet\Application Data\inkscape
2009-08-31 11:25 . 2009-08-31 11:25 ——– d—–w- c:\documents and settings\Janet\Application Data\Talkback
2009-08-31 11:25 . 2009-08-31 11:25 ——– d—–w- c:\documents and settings\Janet\Application Data\Thunderbird
2009-08-31 09:01 . 2009-07-12 06:28 ——– d—–w- c:\documents and settings\Janet\Application Data\MySQL
2009-08-29 02:34 . 2009-08-29 00:42 ——– d—–w- c:\documents and settings\Janet\Application Data\ICAClient
2009-08-29 01:29 . 2009-07-14 10:50 ——– d—–w- c:\program files\Google
2009-08-29 00:32 . 2009-08-29 00:32 ——– d—–w- c:\program files\Citrix
2009-08-23 04:55 . 2009-08-23 04:55 ——– d—–w- c:\program files\PDFCreator
2009-08-23 02:20 . 2009-08-23 02:15 ——– d—–w- c:\program files\JPEG Printer
2009-08-23 02:03 . 2009-08-23 02:03 ——– d—–w- c:\program files\MSECache
2009-08-20 10:13 . 2009-08-20 10:13 ——– d—–w- c:\documents and settings\Janet\Application Data\.visualvm
2006-02-28 12:00 . 2006-02-28 12:00 80300 –sha-r- c:\windows\system32\lsrycr.dll
.
——- Sigcheck ——-
[7] 2006-02-28 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2006-02-28 . C1783498EDB152656303B5D5BCABD86C . 359040 . . [5.1.2600.2180] . . c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Winsplit"="c:\green-programs\WinSplit Revolution\WinSplit.exe" [2009-02-27 3958784]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-10-13 492808]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-02-28 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2006-02-28 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-21 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-21 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-21 134656]
"EasyTuneVI"="c:\program files\GIGABYTE\ET6\ETcall.exe" [2007-07-26 20480]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-12 148888]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-02-27 570664]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2008-02-18 1629480]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2008-02-18 1057064]
"Microsoft Pinyin IME Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12L~1\imesc\IMSCMig.exe" [2008-04-11 38432]
"pdfFactory Pro Dispatcher v3"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2009-03-24 606208]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2008-02-19 1089536]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-12-21 86016]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-10-15 2007320]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2009-01-13 18084864]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"QvodPlayer"="c:\program files\QvodPlayer\QvodTerminal.exe" [2009-07-10 542088]
"OE"="c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe" [2009-10-13 492808]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2009-7-19 221247]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-15 21:59 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\QvodPlayer\\QvodTerminal.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20226:TCP"= 20226:TCP:BitComet 20226 TCP
"20226:UDP"= 20226:UDP:BitComet 20226 UDP
"3306:TCP"= 3306:TCP:MySQL Server
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"9991:TCP"= 9991:TCP:PORT2
"9999:TCP"= 9999:TCP:PORT1
"1013:TCP"= 1013:TCP:BS
"33180:TCP"= 33180:TCP:FD
"58848:TCP"= 58848:TCP:FD
"17093:TCP"= 17093:TCP:FD
"29532:TCP"= 29532:TCP:FD
"22577:TCP"= 22577:TCP:FD
"16491:TCP"= 16491:TCP:FD
"1262:TCP"= 1262:TCP:pnusa
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/16/2009 5:59 AM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/16/2009 5:59 AM 356616]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [9/18/2009 9:33 PM 115856]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [9/18/2009 9:33 PM 41424]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [10/16/2009 5:59 AM 906520]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/16/2009 5:59 AM 285392]
R2 ES lite Service;ES lite Service for program management.;c:\program files\Gigabyte\EasySaver\essvr.exe [7/12/2009 9:52 AM 68136]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt5x.sys [7/12/2009 10:22 AM 22016]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [10/13/2009 6:42 PM 50192]
R2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [10/13/2009 6:42 PM 497008]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [10/13/2009 6:36 PM 36368]
R2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [10/13/2009 6:42 PM 677128]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [10/13/2009 6:36 PM 335376]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [7/10/2009 5:51 PM 99472]
S2 esawkbbw;Helper System;c:\windows\system32\svchost.exe -k netsvcs [2/28/2006 8:00 PM 14336]
S2 NeroRegInCDSrv;Nero Registry InCD Service;c:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe –> c:\program files\Nero\Nero 7\InCD\NBHRegInCDSrv.exe [?]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;c:\windows\system32\drivers\RTLTEAMING.SYS [7/12/2009 10:22 AM 28800]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [7/12/2009 10:22 AM 17408]
S3 Tomcat6;Apache Tomcat 6;c:\program files\Apache Software Foundation\Tomcat 6.0\bin\tomcat6.exe [5/14/2009 7:15 AM 57344]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [9/18/2009 9:33 PM 91472]
SUnknown GVTDrv;GVTDrv; [x]
— Other Services/Drivers In Memory —
*NewlyCreated* - ESAWKBBW
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ffxkxky
gtjny
esawkbbw
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Download; by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab; video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Do&wnload; selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load; all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
FF - ProfilePath - c:\documents and settings\Janet\Application Data\Mozilla\Firefox\Profiles\u6if2y4k.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-16 19:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\docume~1\janet\LOCALS~1\Temp\~DFB4B5.tmp 311296 bytes
c:\windows\system32\GVTunner.ref 4 bytes
scan completed successfully
hidden files: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\esawkbbw]
"ServiceDll"="c:\windows\system32\lsrycr.dll"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1192)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(3576)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Trend Micro\BM\TMBMSRV.exe
c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Trend Micro\Internet Security\SfCtlCom.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Brother\ControlCenter3\BrccMCtl.exe
c:\program files\Brother\Brmfcmon\BrMfcMon.exe
c:\program files\APC\APC PowerChute Personal Edition\apcsystray.exe
.
**************************************************************************
.
Completion time: 2009-10-16 19:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-16 11:48
Pre-Run: 84,572,975,104 bytes free
Post-Run: 84,491,968,512 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
318