ComboFix 09-10-30.01 - Owner 10/31/2009 21:46.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1150.673 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-01 to 2009-11-01 )))))))))))))))))))))))))))))))
.
2009-11-01 01:50 . 2008-04-14 09:42 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2009-11-01 01:50 . 2008-04-14 09:42 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-31 14:24 . 2009-10-31 14:24 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-10-31 14:24 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-31 14:24 . 2009-10-31 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-31 14:24 . 2009-10-31 14:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-31 14:24 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-27 01:04 . 2009-10-28 04:23 -------- d-----w- c:\windows\system32\Icons
2009-10-27 00:45 . 2008-06-17 19:02 8461312 ----a-w- c:\windows\system32\shell32custom.dll
2009-10-13 22:08 . 2009-10-13 22:08 -------- d-----w- c:\program files\DIFX
2009-10-13 22:08 . 2009-10-13 22:08 -------- d-----w- c:\program files\Mars
2009-10-06 23:08 . 2009-10-08 01:24 -------- d-----w- C:\BasicDVD
2009-10-06 22:10 . 2009-10-06 22:10 -------- d-----w- c:\documents and settings\Ann\Application Data\ArcSoft
2009-10-06 22:01 . 2009-10-06 22:01 -------- d-----w- c:\windows\Hewlett-Packard
2009-10-06 22:01 . 2009-10-06 22:01 -------- d-----w- c:\program files\Simple Backup
2009-10-06 21:59 . 2009-10-06 21:59 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-10-06 21:59 . 2009-10-06 21:59 -------- d-----w- c:\program files\CyberLink
2009-10-06 21:59 . 2009-10-06 22:00 -------- d-----w- c:\program files\PowerDVD
2009-10-06 21:57 . 2009-10-06 21:57 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-10-06 21:57 . 2009-10-06 21:57 -------- d-----w- c:\program files\muvee autoProducer DVD Edition - HPC
2009-10-06 21:56 . 2009-10-06 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\muvee Technologies
2009-10-06 21:56 . 2002-10-01 13:22 9856 ----a-w- c:\windows\system32\drivers\pfc.sys
2009-10-06 21:55 . 2003-04-03 15:09 81920 ----a-w- c:\windows\system32\mplaw7.dll
2009-10-06 21:55 . 2003-04-03 15:09 81920 ----a-w- c:\windows\system32\mplaa6.dll
2009-10-06 21:55 . 2003-04-03 15:09 69632 ----a-w- c:\windows\system32\mplapx.dll
2009-10-06 21:55 . 2003-04-03 15:09 69632 ----a-w- c:\windows\system32\mplam6.dll
2009-10-06 21:55 . 2003-04-03 15:09 49152 ----a-w- c:\windows\system32\cpuinf32.dll
2009-10-06 21:55 . 2003-04-03 15:09 1675264 ----a-w- c:\windows\system32\mplva6.dll
2009-10-06 21:55 . 2003-04-03 15:09 1630208 ----a-w- c:\windows\system32\mplvw7.dll
2009-10-06 21:55 . 2003-04-03 15:09 1581056 ----a-w- c:\windows\system32\mplvm6.dll
2009-10-06 21:55 . 2003-04-03 15:09 1150976 ----a-w- c:\windows\system32\mplvpx.dll
2009-10-06 21:53 . 2009-10-06 21:53 -------- d-----w- c:\program files\RecordNow
2009-10-06 21:52 . 2009-10-06 22:02 -------- d-----w- c:\program files\HP DVD
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-24 13:59 . 2008-10-19 00:26 -------- d-----w- c:\program files\HotDocs
2009-10-20 16:35 . 2008-07-17 19:18 95896 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-08 00:12 . 2008-07-23 00:14 -------- d-----w- c:\documents and settings\Owner\Application Data\ArcSoft
2009-10-06 22:03 . 2008-07-17 18:45 -------- d-----w- c:\program files\Hewlett-Packard
2009-10-06 21:59 . 2008-07-17 18:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-06 21:54 . 2008-07-23 00:03 -------- d-----w- c:\program files\ArcSoft
2009-09-20 14:24 . 2009-04-08 22:46 -------- d-----w- c:\documents and settings\Owner\Application Data\GetRightToGo
2009-09-11 14:18 . 2002-08-29 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-11 01:28 . 2008-09-25 13:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-10 17:07 . 2008-07-17 19:52 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-04 21:03 . 2002-08-29 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:36 . 2002-08-29 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2009-06-15 04:03 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2002-08-29 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2002-08-29 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-16 22:24 . 2008-07-19 13:58 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-16 22:24 . 2008-07-19 13:58 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-16 22:24 . 2008-07-19 13:58 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-06 23:24 . 2008-07-17 19:10 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2007-07-30 23:19 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2008-07-17 19:10 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2007-07-30 23:19 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2008-07-17 20:01 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2002-08-29 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2008-07-17 19:10 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2008-09-25 16:06 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 23:23 . 2008-07-18 23:28 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 23:23 . 2008-07-17 20:01 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2002-08-29 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 00:44 . 2002-08-29 12:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2002-08-29 01:04 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-01-14 23:26 . 2009-01-14 23:26 55088 ----a-w- c:\program files\MFInstall.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-01 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-17 2025752]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2002-12-17 49152]
"DVDTray"="c:\program files\HP DVD\Umbrella\DVDTray.exe" [2003-07-23 69632]
"DVDBitSet"="c:\program files\HP DVD\Umbrella\DVDBitSet.exe" [2003-07-18 204800]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 22:24 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Themes"=2 (0x2)
"RoxLiveShare9"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"gusvc"=3 (0x3)
"ERSvc"=2 (0x2)
"CiSvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUpnpService9.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\TomTom HOME 2\\xulrunner\\TomTomHOMERuntime.exe"=
"c:\\Program Files\\Family Tree Maker 16\\Ftw.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/19/2008 9:58 AM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/19/2008 9:58 AM 108552]
R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [7/29/2008 3:35 PM 101528]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/20/2008 8:55 AM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/20/2008 8:55 AM 297752]
R2 OneTouch 4.0 Monitor;OneTouch 4.0 Monitor;c:\program files\Visioneer\OneTouch 4.0\OtService.exe [7/13/2007 1:21 AM 126976]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/7/2009 10:31 AM 92008]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/23/2005 7:06 AM 231424]
R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [7/29/2008 3:34 PM 24876]
S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [7/5/2009 1:23 PM 18864]
S3 hpusbwdm;HP DVD Movie Writer dc3000;c:\windows\system32\drivers\hpusbwdm.sys [8/5/2003 2:16 PM 1080064]
S3 pc100;Linksys EtherFast 10/100 PC Card NT Driver;c:\windows\system32\drivers\pc100nds.sys [7/17/2008 5:58 PM 30495]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
2009-11-01 c:\windows\Tasks\User_Feed_Synchronization-{C23D985C-1F1F-4017-8E73-DC4FAE802E39}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 22:36]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {2C9A45CA-14D5-47F3-9E9F-CCB553CE73AA} - hxxp://pmdownloads.lexisnexis.com/installs/tmbm9/pro/setup-files/install.cab
DPF: {76A2A0AB-38B7-46DB-8E47-F10CDE4D7920} - hxxp://aerial.leepa.org/ecwplugins/NCS.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-31 21:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\:õwjY*]
"DisplayName"="???\16?\11\09"
"DeviceDesc"="???\16?\11\09"
"ProviderName"="???\11?#@\11??"
"MFG"="???????"
"ReinstallString"=".10.1000.5"
"DeviceInstanceIds"=multi:"c:\\swsetup\\sp31101\\sbdrv\\smbus\\smbusati.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1692)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-11-01 21:56
ComboFix-quarantined-files.txt 2009-11-01 01:56
ComboFix2.txt 2009-03-29 16:18
Pre-Run: 39,162,159,104 bytes free
Post-Run: 39,079,444,480 bytes free
- - End Of File - - 858640B104B95B65BD3365DBAB1AFE6F