mgnickson
Topic Starter
Below is the log following a Combofix application. Do I need to do anything else?
ComboFix 10-01-14.02 - Mike 01/15/2010 0:11.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.104 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
FW: eTrust EZ Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mike\My Documents\ZbThumbnail.info
c:\windows\Fonts\acrsec.fon
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11942.exe
c:\windows\system32\12382.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\19169.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\21726.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\25667.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\41.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\bszip.dll
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\SYSTEM32\oVDNoUtv.ini
c:\windows\SYSTEM32\oVDNoUtv.ini2
c:\windows\system32\smss32.exe
c:\windows\system32\srcr.dat
c:\windows\system32\warning.html
c:\windows\system32\windows.txt
c:\windows\system32\winlogon32.exe
c:\windows\uguqahivafecuj.dll
c:\windows\unins000.dat
c:\windows\unins000.exe
.
((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.
2010-01-15 04:58 . 2009-05-13 21:30 13360 —-a-w- c:\windows\system32\drivers\sbaphd.sys
2010-01-15 02:29 . 2010-01-15 02:29 ——– d–h–w- c:\windows\PIF
2010-01-15 02:24 . 2009-08-11 00:06 69936 —-a-w- c:\windows\system32\drivers\sbapifs.sys
2010-01-14 14:15 . 2010-01-14 14:15 0 —-a-w- c:\windows\Vhizoxutu.bin
2010-01-14 14:15 . 2010-01-15 04:49 120 —-a-w- c:\windows\Lgeruxe.dat
2010-01-14 14:15 . 2010-01-14 14:15 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\{5093D286-E7B3-452F-B4AF-628E916F0B0D}
2010-01-13 08:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-13 03:23 . 2010-01-13 03:23 ——– d—–w- c:\program files\gs
2010-01-13 03:21 . 2010-01-13 03:21 ——– d—–w- c:\program files\PlotSoft
2010-01-13 03:21 . 2010-01-13 03:21 ——– d—–w- c:\documents and settings\All Users\Application Data\PlotSoft
2010-01-09 02:06 . 2010-01-09 02:06 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\Unity
2010-01-06 14:31 . 2010-01-06 14:31 ——– d—–w- c:\documents and settings\Mike\Application Data\PCPitstop
2010-01-06 14:31 . 2010-01-06 14:36 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-01-06 14:31 . 2010-01-06 14:31 ——– d—–w- c:\program files\PCPitstop
2010-01-06 13:52 . 2010-01-06 13:52 ——– d-sh–w- c:\documents and settings\Mike\IECompatCache
2010-01-05 12:55 . 2010-01-05 12:55 ——– d—–w- c:\documents and settings\Mike\Application Data\Malwarebytes
2010-01-05 03:05 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 03:05 . 2010-01-05 03:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-05 03:05 . 2010-01-05 12:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-05 03:05 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-04 22:02 . 2010-01-04 22:02 27984 —-a-w- c:\windows\system32\sbbd.exe
2010-01-04 14:10 . 2010-01-04 14:10 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-01-04 00:44 . 2010-01-04 00:44 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-30 20:26 . 2009-12-30 20:26 ——– d—–w- c:\program files\Mars
2009-12-20 00:55 . 2009-12-20 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-18 01:10 . 2009-12-18 01:10 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2009-12-18 00:57 . 2009-12-18 00:57 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-18 00:55 . 2009-12-18 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 20:27 . 2009-12-30 20:27 8854 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{574736E1-57BD-413B-8CA8-2945F94185CE}\UNINST_Uninstall_M_574736E157BD413B8CA82945F94185CE.exe
2009-12-30 20:27 . 2009-12-30 20:27 40960 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{574736E1-57BD-413B-8CA8-2945F94185CE}\ARPPRODUCTICON.exe
2009-12-25 02:38 . 2009-10-09 00:22 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-18 01:09 . 2005-04-14 00:06 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-18 00:55 . 2009-12-18 00:55 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-12-13 22:03 . 2009-06-06 11:58 20 —h–w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-11-25 13:36 . 2009-11-25 13:36 ——– d—–w- c:\documents and settings\Mike\Application Data\EPSON
2009-11-21 16:05 . 2008-03-29 00:45 56412 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-21 15:51 . 2004-08-04 10:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-21 14:52 . 2005-04-30 12:55 ——– d—–w- c:\documents and settings\Mike\Application Data\Apple Computer
2009-11-21 14:30 . 2009-11-21 14:29 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-21 14:30 . 2007-09-18 02:15 ——– d—–w- c:\program files\iTunes
2009-11-21 14:30 . 2005-04-30 12:54 ——– d—–w- c:\program files\iPod
2009-11-21 14:30 . 2007-08-03 15:24 ——– d—–w- c:\program files\Common Files\Apple
2009-11-21 14:27 . 2007-08-03 15:26 ——– d—–w- c:\program files\QuickTime
2009-11-21 14:21 . 2009-11-21 14:21 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-20 11:08 . 2009-12-18 00:58 38784 —-a-w- c:\documents and settings\Mike\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-20 11:08 . 2009-12-18 00:57 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-29 07:45 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 10:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 10:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2006-12-03 19:10 . 2006-11-02 02:46 56 –sha-r- c:\windows\SYSTEM32\95AC9DE08A.sys
2009-08-23 13:27 . 2006-11-02 02:41 3402 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2005-08-11 21:30 . 2005-08-11 21:30 81920 c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe
2005-08-11 21:30 . 2005-08-11 21:30 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
2005-08-11 21:30 . 2005-08-11 21:30 249856 c:\program files\Common Files\InstallShield\UpdateService\bak\isuspm.exe
2005-08-11 21:30 . 2005-08-11 21:30 249856 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
2005-05-05 22:38 . 2005-05-05 22:38 180269 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
2004-01-07 06:01 . 2004-01-07 06:01 110592 c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
2005-04-08 05:31 . 2004-10-12 21:54 57344 c:\program files\CyberLink\PowerDVD\bak\DVDLauncher.exe
2007-03-15 15:09 . 2007-03-15 15:09 460784 c:\program files\DellSupport\bak\DSAgnt.exe
2005-06-21 22:55 . 2005-05-18 18:49 282624 c:\program files\DIGStream\bak\digstream.exe
2005-06-21 22:56 . 2005-05-19 17:55 101888 c:\program files\ESPNRunTime\bak\DIGServices.exe
2007-09-07 20:55 . 2007-09-07 20:55 267064 c:\program files\iTunes\bak\iTunesHelper.exe
2009-11-12 21:33 . 2009-11-12 21:33 141600 c:\program files\iTunes\iTunesHelper.exe
2007-03-04 13:36 . 2006-12-15 08:23 75520 c:\program files\Java\jre1.5.0_11\bin\bak\jusched.exe
2005-05-07 02:51 . 2005-03-12 11:25 11776 c:\program files\MUSICMATCH\Musicmatch Jukebox\bak\mimboot.exe
2005-04-08 05:44 . 2005-03-12 11:25 110592 c:\program files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe
2005-10-06 02:31 . 2005-10-06 02:31 335872 c:\program files\Picasa2\bak\PicasaMediaDetector.exe
2007-06-29 10:24 . 2007-06-29 10:24 286720 c:\program files\QuickTime\bak\qttask.exe
2009-11-11 04:08 . 2009-11-11 04:08 417792 c:\program files\QuickTime\QTTask.exe
2007-03-15 16:57 . 2007-03-15 16:57 356197 c:\program files\SlySoft\AnyDVD\bak\AnyDVD.exe
2003-01-31 10:20 . 2005-10-18 19:33 1921024 c:\program files\Support.com\bin\bak\tgcmd.exe
2007-08-17 13:17 . 2006-05-02 19:51 3334144 c:\program files\Yahoo!\Messenger\bak\YAHOOM~1.EXE
2006-06-22 20:21 . 2006-06-22 20:21 5541888 c:\program files\Yahoo!\Yahoo! Music Engine\bak\YahooMusicEngine.exe
2004-08-04 10:00 . 2004-08-04 10:00 15360 c:\windows\SYSTEM32\bak\ctfmon.exe
2004-08-04 10:00 . 2008-04-14 00:12 15360 c:\windows\SYSTEM32\ctfmon.exe
1980-01-01 05:00 . 2005-10-14 18:46 77824 c:\windows\SYSTEM32\bak\hkcmd.exe
2004-08-20 20:51 . 2004-08-20 20:51 118784 c:\windows\SYSTEM32\hkcmd.exe
2005-10-14 18:50 . 2005-10-14 18:50 114688 c:\windows\SYSTEM32\bak\igfxpers.exe
1980-01-01 05:00 . 2005-10-14 18:49 94208 c:\windows\SYSTEM32\bak\igfxtray.exe
2004-08-20 20:55 . 2004-08-20 20:55 155648 c:\windows\SYSTEM32\igfxtray.exe
2005-04-08 05:48 . 2004-12-06 06:05 127035 c:\windows\SYSTEM32\dla\bak\tfswctrl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"TCOYFReminder"="c:\progra~1\TCOYF\tcoyftray.exe" [2006-09-19 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"weiyuan"="c:\windows\system32\weiyuan.exe" [N/A]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"igfxpers"="c:\windows\system32\igfxpers.exe" [N/A]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-06-14 1282048]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [N/A]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"smss32.exe"="c:\windows\system32\smss32.exe" [N/A]
"Frusaji"="c:\windows\uguqahivafecuj.dll" [N/A]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2010-01-04 959824]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-4-8 24576]
Dynex Wireless Networking Utility.lnk - c:\program files\Dynex Enhanced G USB Network Adapter\DynexWCUI.exe [2009-2-28 1462272]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-10-23 278528]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2004-08-20 20:51 118784 —-a-w- c:\windows\SYSTEM32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2004-08-20 20:55 155648 —-a-w- c:\windows\SYSTEM32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 sbaphd;sbaphd;c:\windows\SYSTEM32\DRIVERS\sbaphd.sys [01/14/2010 11:58 PM 13360]
R1 sbtis;sbtis;c:\windows\SYSTEM32\DRIVERS\sbtis.sys [01/12/2009 9:48 PM 202928]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [01/04/2010 5:02 PM 1012080]
R2 sbapifs;sbapifs;c:\windows\SYSTEM32\DRIVERS\sbapifs.sys [01/14/2010 9:24 PM 69936]
R2 SVKP;SVKP;c:\windows\SYSTEM32\SVKP.sys [10/26/2006 9:04 PM 2368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [01/10/2007 9:45 PM 24652]
R3 NdisWDM;Dynex Enhanced Wireless G USB Network Adapter Service;c:\windows\SYSTEM32\DRIVERS\NdisWDM.sys [02/28/2009 1:51 PM 198144]
S2 phnvcx;phnvcx;c:\windows\system32\svchost.exe -k phnvcx [08/04/2004 5:00 AM 14336]
S2 ProtectsStore;RtoAutos;c:\program files\NetMeeting\smss.exe –> c:\program files\NetMeeting\smss.exe [?]
S2 PssInsv;Prints Spoolers Services;c:\program files\System\svchost.exe –> c:\program files\System\svchost.exe [?]
S2 yhnvcxjc;yhnvcxjc;\??\c:\windows\system32\drivers\xbllsk.sys –> c:\windows\system32\drivers\xbllsk.sys [?]
S3 SBRE;SBRE;c:\windows\SYSTEM32\DRIVERS\SBREDrv.sys [10/13/2009 8:22 AM 95024]
S3 zsi_fmw;Stiletto Firmware Recovery;c:\windows\SYSTEM32\DRIVERS\zsi_fmw.sys [08/18/2009 8:02 PM 34176]
S3 zsi_fw;Stiletto 100 Firmware Upgrade Driver;c:\windows\SYSTEM32\DRIVERS\zsi_fw.sys [07/31/2006 10:32 PM 16768]
S3 zsi_zap;Stiletto ZAP Recovery Driver;c:\windows\SYSTEM32\DRIVERS\zsi_zap.sys [07/29/2006 5:22 PM 16896]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [01/06/2010 9:31 AM 85504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
phnvcx REG_MULTI_SZ phnvcx
.
Contents of the 'Scheduled Tasks' folder
2010-01-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: doginhispen.com
Trusted Zone: whataboutadog.com
Trusted Zone: musicmatch.com\online
DPF: ESPNJavaUtilsCab - hxxp://espn.go.com/livedraft/ESPNJavaUtils.cab
DPF: {81449547-EB5D-422E-8730-932DC5E412C8} - hxxp://www.howardstern.com/install/uvuplayer.cab
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\y1x13hd9.default\
FF - plugin: c:\documents and settings\Mike\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {5093D286-E7B3-452F-B4AF-628E916F0B0D} - c:\documents and settings\Mike\Local Settings\Application Data\{5093D286-E7B3-452F-B4AF-628E916F0B0D}
.
- - - - ORPHANS REMOVED - - - -
BHO-{7C4DEBE7-FB8A-43C7-B81B-808424465C10} - c:\windows\system32\vtUoNDVo.dll
ShellExecuteHooks-{FB703367-5B9A-4F41-B5C6-85F618DD9A57} - (no file)
AddRemove-Giggles-Shapes_is1 - c:\program files\Giggles Computer Funtime For Baby\Giggles-Shapes\unins000.exe
AddRemove-{184EB198-1DBA-46DB-B728-7A5FC13D5C2B}_is1 - c:\windows\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-15 00:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
weiyuan = c:\windows\system32\weiyuan.exe?????????????????X???????8?????A~?`??????|???P??????????|p??|????m??|
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(792)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(1668)
c:\windows\system32\WININET.dll
c:\program files\Sunbelt Software\VIPRE\oehook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
.
———————— Other Running Processes ————————
.
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-01-15 00:30:33 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-15 05:30
Pre-Run: 38,433,792,000 bytes free
Post-Run: 40,025,231,360 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 5427D6D2B3A84C3359013BCF9429C171
ComboFix 10-01-14.02 - Mike 01/15/2010 0:11.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.104 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
FW: eTrust EZ Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mike\My Documents\ZbThumbnail.info
c:\windows\Fonts\acrsec.fon
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11942.exe
c:\windows\system32\12382.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\19169.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\21726.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\25667.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\41.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\bszip.dll
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\SYSTEM32\oVDNoUtv.ini
c:\windows\SYSTEM32\oVDNoUtv.ini2
c:\windows\system32\smss32.exe
c:\windows\system32\srcr.dat
c:\windows\system32\warning.html
c:\windows\system32\windows.txt
c:\windows\system32\winlogon32.exe
c:\windows\uguqahivafecuj.dll
c:\windows\unins000.dat
c:\windows\unins000.exe
.
((((((((((((((((((((((((( Files Created from 2009-12-15 to 2010-01-15 )))))))))))))))))))))))))))))))
.
2010-01-15 04:58 . 2009-05-13 21:30 13360 —-a-w- c:\windows\system32\drivers\sbaphd.sys
2010-01-15 02:29 . 2010-01-15 02:29 ——– d–h–w- c:\windows\PIF
2010-01-15 02:24 . 2009-08-11 00:06 69936 —-a-w- c:\windows\system32\drivers\sbapifs.sys
2010-01-14 14:15 . 2010-01-14 14:15 0 —-a-w- c:\windows\Vhizoxutu.bin
2010-01-14 14:15 . 2010-01-15 04:49 120 —-a-w- c:\windows\Lgeruxe.dat
2010-01-14 14:15 . 2010-01-14 14:15 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\{5093D286-E7B3-452F-B4AF-628E916F0B0D}
2010-01-13 08:37 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-13 03:23 . 2010-01-13 03:23 ——– d—–w- c:\program files\gs
2010-01-13 03:21 . 2010-01-13 03:21 ——– d—–w- c:\program files\PlotSoft
2010-01-13 03:21 . 2010-01-13 03:21 ——– d—–w- c:\documents and settings\All Users\Application Data\PlotSoft
2010-01-09 02:06 . 2010-01-09 02:06 ——– d—–w- c:\documents and settings\Mike\Local Settings\Application Data\Unity
2010-01-06 14:31 . 2010-01-06 14:31 ——– d—–w- c:\documents and settings\Mike\Application Data\PCPitstop
2010-01-06 14:31 . 2010-01-06 14:36 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-01-06 14:31 . 2010-01-06 14:31 ——– d—–w- c:\program files\PCPitstop
2010-01-06 13:52 . 2010-01-06 13:52 ——– d-sh–w- c:\documents and settings\Mike\IECompatCache
2010-01-05 12:55 . 2010-01-05 12:55 ——– d—–w- c:\documents and settings\Mike\Application Data\Malwarebytes
2010-01-05 03:05 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 03:05 . 2010-01-05 03:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-05 03:05 . 2010-01-05 12:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-05 03:05 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-04 22:02 . 2010-01-04 22:02 27984 —-a-w- c:\windows\system32\sbbd.exe
2010-01-04 14:10 . 2010-01-04 14:10 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-01-04 00:44 . 2010-01-04 00:44 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-30 20:26 . 2009-12-30 20:26 ——– d—–w- c:\program files\Mars
2009-12-20 00:55 . 2009-12-20 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-18 01:10 . 2009-12-18 01:10 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2009-12-18 00:57 . 2009-12-18 00:57 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-18 00:55 . 2009-12-18 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-30 20:27 . 2009-12-30 20:27 8854 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{574736E1-57BD-413B-8CA8-2945F94185CE}\UNINST_Uninstall_M_574736E157BD413B8CA82945F94185CE.exe
2009-12-30 20:27 . 2009-12-30 20:27 40960 —-a-r- c:\documents and settings\Mike\Application Data\Microsoft\Installer\{574736E1-57BD-413B-8CA8-2945F94185CE}\ARPPRODUCTICON.exe
2009-12-25 02:38 . 2009-10-09 00:22 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-18 01:09 . 2005-04-14 00:06 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-18 00:55 . 2009-12-18 00:55 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-12-13 22:03 . 2009-06-06 11:58 20 —h–w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-11-25 13:36 . 2009-11-25 13:36 ——– d—–w- c:\documents and settings\Mike\Application Data\EPSON
2009-11-21 16:05 . 2008-03-29 00:45 56412 —ha-w- c:\windows\system32\mlfcache.dat
2009-11-21 15:51 . 2004-08-04 10:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-21 14:52 . 2005-04-30 12:55 ——– d—–w- c:\documents and settings\Mike\Application Data\Apple Computer
2009-11-21 14:30 . 2009-11-21 14:29 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-21 14:30 . 2007-09-18 02:15 ——– d—–w- c:\program files\iTunes
2009-11-21 14:30 . 2005-04-30 12:54 ——– d—–w- c:\program files\iPod
2009-11-21 14:30 . 2007-08-03 15:24 ——– d—–w- c:\program files\Common Files\Apple
2009-11-21 14:27 . 2007-08-03 15:26 ——– d—–w- c:\program files\QuickTime
2009-11-21 14:21 . 2009-11-21 14:21 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-20 11:08 . 2009-12-18 00:58 38784 —-a-w- c:\documents and settings\Mike\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-20 11:08 . 2009-12-18 00:57 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-29 07:45 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 10:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 10:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2006-12-03 19:10 . 2006-11-02 02:46 56 –sha-r- c:\windows\SYSTEM32\95AC9DE08A.sys
2009-08-23 13:27 . 2006-11-02 02:41 3402 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2005-08-11 21:30 . 2005-08-11 21:30 81920 c:\program files\Common Files\InstallShield\UpdateService\bak\issch.exe
2005-08-11 21:30 . 2005-08-11 21:30 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
2005-08-11 21:30 . 2005-08-11 21:30 249856 c:\program files\Common Files\InstallShield\UpdateService\bak\isuspm.exe
2005-08-11 21:30 . 2005-08-11 21:30 249856 c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
2005-05-05 22:38 . 2005-05-05 22:38 180269 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
2004-01-07 06:01 . 2004-01-07 06:01 110592 c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
2005-04-08 05:31 . 2004-10-12 21:54 57344 c:\program files\CyberLink\PowerDVD\bak\DVDLauncher.exe
2007-03-15 15:09 . 2007-03-15 15:09 460784 c:\program files\DellSupport\bak\DSAgnt.exe
2005-06-21 22:55 . 2005-05-18 18:49 282624 c:\program files\DIGStream\bak\digstream.exe
2005-06-21 22:56 . 2005-05-19 17:55 101888 c:\program files\ESPNRunTime\bak\DIGServices.exe
2007-09-07 20:55 . 2007-09-07 20:55 267064 c:\program files\iTunes\bak\iTunesHelper.exe
2009-11-12 21:33 . 2009-11-12 21:33 141600 c:\program files\iTunes\iTunesHelper.exe
2007-03-04 13:36 . 2006-12-15 08:23 75520 c:\program files\Java\jre1.5.0_11\bin\bak\jusched.exe
2005-05-07 02:51 . 2005-03-12 11:25 11776 c:\program files\MUSICMATCH\Musicmatch Jukebox\bak\mimboot.exe
2005-04-08 05:44 . 2005-03-12 11:25 110592 c:\program files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe
2005-10-06 02:31 . 2005-10-06 02:31 335872 c:\program files\Picasa2\bak\PicasaMediaDetector.exe
2007-06-29 10:24 . 2007-06-29 10:24 286720 c:\program files\QuickTime\bak\qttask.exe
2009-11-11 04:08 . 2009-11-11 04:08 417792 c:\program files\QuickTime\QTTask.exe
2007-03-15 16:57 . 2007-03-15 16:57 356197 c:\program files\SlySoft\AnyDVD\bak\AnyDVD.exe
2003-01-31 10:20 . 2005-10-18 19:33 1921024 c:\program files\Support.com\bin\bak\tgcmd.exe
2007-08-17 13:17 . 2006-05-02 19:51 3334144 c:\program files\Yahoo!\Messenger\bak\YAHOOM~1.EXE
2006-06-22 20:21 . 2006-06-22 20:21 5541888 c:\program files\Yahoo!\Yahoo! Music Engine\bak\YahooMusicEngine.exe
2004-08-04 10:00 . 2004-08-04 10:00 15360 c:\windows\SYSTEM32\bak\ctfmon.exe
2004-08-04 10:00 . 2008-04-14 00:12 15360 c:\windows\SYSTEM32\ctfmon.exe
1980-01-01 05:00 . 2005-10-14 18:46 77824 c:\windows\SYSTEM32\bak\hkcmd.exe
2004-08-20 20:51 . 2004-08-20 20:51 118784 c:\windows\SYSTEM32\hkcmd.exe
2005-10-14 18:50 . 2005-10-14 18:50 114688 c:\windows\SYSTEM32\bak\igfxpers.exe
1980-01-01 05:00 . 2005-10-14 18:49 94208 c:\windows\SYSTEM32\bak\igfxtray.exe
2004-08-20 20:55 . 2004-08-20 20:55 155648 c:\windows\SYSTEM32\igfxtray.exe
2005-04-08 05:48 . 2004-12-06 06:05 127035 c:\windows\SYSTEM32\dla\bak\tfswctrl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"TCOYFReminder"="c:\progra~1\TCOYF\tcoyftray.exe" [2006-09-19 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"weiyuan"="c:\windows\system32\weiyuan.exe" [N/A]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"igfxpers"="c:\windows\system32\igfxpers.exe" [N/A]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-06-14 1282048]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [N/A]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"smss32.exe"="c:\windows\system32\smss32.exe" [N/A]
"Frusaji"="c:\windows\uguqahivafecuj.dll" [N/A]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2010-01-04 959824]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-4-8 24576]
Dynex Wireless Networking Utility.lnk - c:\program files\Dynex Enhanced G USB Network Adapter\DynexWCUI.exe [2009-2-28 1462272]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
TotalMedia Backup Monitor.lnk - c:\program files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe [2008-10-23 278528]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2004-08-20 20:51 118784 —-a-w- c:\windows\SYSTEM32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2004-08-20 20:55 155648 —-a-w- c:\windows\SYSTEM32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 sbaphd;sbaphd;c:\windows\SYSTEM32\DRIVERS\sbaphd.sys [01/14/2010 11:58 PM 13360]
R1 sbtis;sbtis;c:\windows\SYSTEM32\DRIVERS\sbtis.sys [01/12/2009 9:48 PM 202928]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [01/04/2010 5:02 PM 1012080]
R2 sbapifs;sbapifs;c:\windows\SYSTEM32\DRIVERS\sbapifs.sys [01/14/2010 9:24 PM 69936]
R2 SVKP;SVKP;c:\windows\SYSTEM32\SVKP.sys [10/26/2006 9:04 PM 2368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [01/10/2007 9:45 PM 24652]
R3 NdisWDM;Dynex Enhanced Wireless G USB Network Adapter Service;c:\windows\SYSTEM32\DRIVERS\NdisWDM.sys [02/28/2009 1:51 PM 198144]
S2 phnvcx;phnvcx;c:\windows\system32\svchost.exe -k phnvcx [08/04/2004 5:00 AM 14336]
S2 ProtectsStore;RtoAutos;c:\program files\NetMeeting\smss.exe –> c:\program files\NetMeeting\smss.exe [?]
S2 PssInsv;Prints Spoolers Services;c:\program files\System\svchost.exe –> c:\program files\System\svchost.exe [?]
S2 yhnvcxjc;yhnvcxjc;\??\c:\windows\system32\drivers\xbllsk.sys –> c:\windows\system32\drivers\xbllsk.sys [?]
S3 SBRE;SBRE;c:\windows\SYSTEM32\DRIVERS\SBREDrv.sys [10/13/2009 8:22 AM 95024]
S3 zsi_fmw;Stiletto Firmware Recovery;c:\windows\SYSTEM32\DRIVERS\zsi_fmw.sys [08/18/2009 8:02 PM 34176]
S3 zsi_fw;Stiletto 100 Firmware Upgrade Driver;c:\windows\SYSTEM32\DRIVERS\zsi_fw.sys [07/31/2006 10:32 PM 16768]
S3 zsi_zap;Stiletto ZAP Recovery Driver;c:\windows\SYSTEM32\DRIVERS\zsi_zap.sys [07/29/2006 5:22 PM 16896]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [01/06/2010 9:31 AM 85504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
phnvcx REG_MULTI_SZ phnvcx
.
Contents of the 'Scheduled Tasks' folder
2010-01-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: doginhispen.com
Trusted Zone: whataboutadog.com
Trusted Zone: musicmatch.com\online
DPF: ESPNJavaUtilsCab - hxxp://espn.go.com/livedraft/ESPNJavaUtils.cab
DPF: {81449547-EB5D-422E-8730-932DC5E412C8} - hxxp://www.howardstern.com/install/uvuplayer.cab
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\y1x13hd9.default\
FF - plugin: c:\documents and settings\Mike\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {5093D286-E7B3-452F-B4AF-628E916F0B0D} - c:\documents and settings\Mike\Local Settings\Application Data\{5093D286-E7B3-452F-B4AF-628E916F0B0D}
.
- - - - ORPHANS REMOVED - - - -
BHO-{7C4DEBE7-FB8A-43C7-B81B-808424465C10} - c:\windows\system32\vtUoNDVo.dll
ShellExecuteHooks-{FB703367-5B9A-4F41-B5C6-85F618DD9A57} - (no file)
AddRemove-Giggles-Shapes_is1 - c:\program files\Giggles Computer Funtime For Baby\Giggles-Shapes\unins000.exe
AddRemove-{184EB198-1DBA-46DB-B728-7A5FC13D5C2B}_is1 - c:\windows\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-15 00:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
weiyuan = c:\windows\system32\weiyuan.exe?????????????????X???????8?????A~?`??????|???P??????????|p??|????m??|
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(792)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(1668)
c:\windows\system32\WININET.dll
c:\program files\Sunbelt Software\VIPRE\oehook.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
.
———————— Other Running Processes ————————
.
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-01-15 00:30:33 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-15 05:30
Pre-Run: 38,433,792,000 bytes free
Post-Run: 40,025,231,360 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 5427D6D2B3A84C3359013BCF9429C171