Shanna
Topic Starter
Could someone please read through my Combofix log and tell me if my computer is clean?
I'm sorry for not following the rules! My computer was infected with a virus, and a friend told me to run Combofix. It was only after I ran the program that I realized I would need a specialist to review my log file. I came to this forum and then saw the "Do not run Combofix without explicit instruction" note…. sorry …
Here was my original problem: I kept getting a popup telling me that my computer was infected, and urging me to download their anti-virus program. I didn't - I tried to download and run a Norton product instead. However, my computer couldn't connect to the Norton site to update the virus definitions. I could connect to the internet, but I couldn't browse to Norton, AVG, McAfree, or other antivirus product sites. Also, if I clicked on links from a Google search result site, I would get redirected to odd locations.
The problem *seems* to be fixed since running Combofix, but the instructions strongly recommended having the log file reviewed … I would really appreciate it if someone could help me out. (File attached)
Please don't attach the scan results unless asked to. Copy/Paste them.
ComboFix 10-02-03.04 - srenzi 02/03/2010 21:54:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.284 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\captcha.dll
c:\program files\webserver
c:\windows\010112010146101105.rx
c:\windows\010112010146114101.xxe
c:\windows\01011201014650115.xxe
c:\windows\0101120101465348.xxe
c:\windows\Downloaded Program Files\MyWebEx
c:\windows\Downloaded Program Files\MyWebEx\419\atarm.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atas32.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atasanot.exe
c:\windows\Downloaded Program Files\MyWebEx\419\atasctrl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atasnt40.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atcarmcl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atdl2006.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atjpeg60.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atkbctl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atlchat.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atmemmgr.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atnetext.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atpack.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\attp.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atwbxui5.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmcliun.exe
c:\windows\Downloaded Program Files\MyWebEx\419\mwmproxy.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmtrace.txt
c:\windows\Downloaded Program Files\MyWebEx\419\mwmupd.exe
c:\windows\Downloaded Program Files\MyWebEx\419\ratrace.dll
c:\windows\Downloaded Program Files\MyWebEx\419\raurl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\uilibres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\wbxcrypt.dll
c:\windows\Downloaded Program Files\MyWebEx\419\webexmgr.dll
c:\windows\fdgg34353edfgdfdf
c:\windows\pp14.exe
c:\windows\rdr_1264952508.exe
c:\windows\system32\drivers\fio32.sys
c:\windows\system32\fio32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_FIOO32
——-\Service_fioo32
——-\Service_SfX
——-\Legacy_fio32
——-\Service_fio32
((((((((((((((((((((((((( Files Created from 2010-01-04 to 2010-02-04 )))))))))))))))))))))))))))))))
.
2010-01-31 21:56 . 2010-01-31 21:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-31 21:42 . 2010-01-31 21:42 ——– d—–w- c:\documents and settings\srenzi\Local Settings\Application Data\Downloaded Installations
2010-01-31 21:31 . 2010-01-31 21:31 ——– d—–w- c:\program files\Times Reader
2010-01-31 21:31 . 2010-01-31 21:31 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-31 21:30 . 2010-01-31 21:38 ——– d—–w- c:\documents and settings\srenzi\Local Settings\Application Data\Adobe
2010-01-31 21:30 . 2010-02-02 03:04 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-31 15:28 . 2010-02-02 03:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-01-31 15:28 . 2010-01-31 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-31 15:25 . 2010-01-31 15:25 ——– d—–w- c:\documents and settings\All Users\Symantec Temporary Files
2010-01-31 14:37 . 2010-01-31 14:37 1 —-a-w- c:\windows\conf21113.dat
2010-01-30 15:08 . 1998-04-25 10:32 210944 —-a-w- c:\windows\system32\MSVCRT10.DLL
2010-01-30 15:08 . 1998-04-25 10:32 212480 —-a-w- c:\windows\system32\pcdlib32.dll
2010-01-30 15:08 . 2010-01-30 15:08 ——– d—–w- C:\KPCMS
2010-01-30 15:08 . 1998-04-25 10:32 40129 —-a-w- c:\windows\iccsigs.dat
2010-01-30 15:08 . 1998-06-05 16:42 197120 —-a-w- c:\windows\kpcp32.dll
2010-01-30 15:08 . 1998-04-25 10:32 58368 —-a-w- c:\windows\pfpick.dll
2010-01-30 15:08 . 1998-04-25 10:32 37376 —-a-w- c:\windows\kpsys32.dll
2010-01-30 15:08 . 1998-04-25 10:32 20992 —-a-w- c:\windows\icccodes.dll
2010-01-30 15:08 . 1998-01-20 14:12 133120 —-a-w- c:\windows\sprof32.dll
2010-01-30 15:07 . 2010-01-30 15:07 ——– d—–w- c:\windows\system32\COLOR
2010-01-30 15:03 . 1998-04-25 10:19 299520 —-a-w- c:\windows\uninst.exe
2010-01-19 03:05 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-04 03:22 . 2007-03-30 00:42 ——– d—–w- c:\documents and settings\srenzi\Application Data\Skype
2010-02-04 03:21 . 2008-03-27 12:46 ——– d—–w- c:\documents and settings\srenzi\Application Data\skypePM
2010-02-04 03:06 . 2006-08-16 02:37 12 —-a-w- c:\windows\bthservsdp.dat
2010-02-01 03:00 . 2008-11-16 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Retrospect
2010-01-31 21:35 . 2006-05-19 23:43 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-31 21:30 . 2010-01-31 21:30 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-31 21:16 . 2007-03-30 00:50 82920 —-a-w- c:\documents and settings\srenzi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 21:16 . 2007-05-27 13:30 110197 -c–a-w- c:\windows\hpoins08.dat
2010-01-31 21:06 . 2007-04-04 03:25 ——– d—–w- c:\documents and settings\srenzi\Application Data\AdobeUM
2010-01-31 15:34 . 2005-02-02 08:21 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-31 15:34 . 2005-05-31 17:20 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-01-31 15:32 . 2009-07-15 15:21 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-01-21 00:21 . 2009-11-11 13:03 79488 —-a-w- c:\documents and settings\srenzi\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-19 03:25 . 2007-11-08 01:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-21 19:14 . 2004-08-11 22:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 22:44 . 2006-06-21 05:30 ——– d—–w- c:\program files\PowerArchiver
2009-12-16 19:42 . 2009-12-18 22:38 872960 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 19:42 . 2009-12-18 22:38 43008 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 19:42 . 2009-12-18 22:38 340480 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 19:41 . 2009-12-18 22:38 346624 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-20 11:08 . 2010-01-31 21:31 38784 —-a-w- c:\documents and settings\srenzi\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2006-08-31 20:51 . 2006-08-31 20:51 3711728 —-a-w- c:\program files\powarc963.exe
2006-07-06 00:20 . 2006-07-06 00:20 3988 —-a-w- c:\program files\pgupta.zip
2006-06-30 04:34 . 2006-06-30 04:32 13926456 —-a-w- c:\program files\snagit.exe
2006-06-13 23:07 . 2006-06-13 23:07 71932 —-a-w- c:\program files\Floresense_WorldClock.zip
2006-06-08 05:47 . 2006-06-08 05:47 15818536 —-a-w- c:\program files\Install_Messenger_Beta(2).exe
2006-06-02 05:43 . 2006-06-02 05:42 397352 —-a-w- c:\program files\msgr75us.exe
2006-06-02 05:42 . 2006-06-02 05:42 5118288 —-a-w- c:\program files\Firefox Setup 1.5.0.4.exe
2008-03-05 22:00 . 2006-08-31 18:02 27976 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-03-05 22:00 . 2006-08-31 18:02 125848 —-a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-03-05 22:00 . 2008-03-05 22:00 46408 —-a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2008-03-05 22:00 . 2006-08-31 18:02 98712 —-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2007-08-02 15:41 . 2006-08-31 18:02 94208 —-a-w- c:\program files\mozilla firefox\plugins\mwmcli.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-13 136600]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-02 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"SigmatelSysTrayApp"="stsystra.exe" [2006-01-09 417792]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048]
"openvpn-gui"="c:\program files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 99328]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2004-02-27 61440]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-05-20 188416]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"\\us-fs\EPSON Stylus Photo R1800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE" [2004-09-08 98304]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"WD Button Manager"="WDBtnMgr.exe" [2008-11-16 335872]
"SetIcon"="\Program Files\WDC\SetIcon.exe" [2004-04-28 42496]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
c:\documents and settings\pgupta\Start Menu\Programs\Startup\
World Clock 2001.LNK - c:\program files\Zada Solutions\World Clock\zsWldClk.exe [2000-8-22 684032]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 45056]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-5-19 24576]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-27 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-24 13:27 87352 —-a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1292428093-839522115-1109\Scripts\Logon\0\0]
"Script"=all-au.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1292428093-839522115-1297\Scripts\Logon\0\0]
"Script"=all.bat
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Codename Max\\max.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\msncall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"53:TCP"= 53:TCP:webserver
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [6/7/2007 7:10 AM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [6/7/2007 7:10 AM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/7/2007 7:06 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/31/2009 3:40 PM 133104]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [6/23/2004 8:54 PM 23552]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder
2010-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-31 20:39]
2010-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-31 20:39]
2010-02-04 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]
2010-01-28 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyServer = 192.168.10.101:3128
uInternet Settings,ProxyOverride = maddmzmm1.ingdirect.es;;*.local
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: memetrics.com\project
DPF: {1D95A7C7-3282-4DB7-9A48-7C39CE152A19} - hxxps://myemail.t-mobile.com/html/web/client_tools/TOImport.cab
DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxp://project.memetrics.com/projectserver/objects/pjclient.cab
DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxp://project.memetrics.com/projectserver/objects/1033/pjcintl.cab
FF - ProfilePath - c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_us&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-03 22:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(864)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\windows\system32\LMIinit.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(1232)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\progra~1\Dantz\RETROS~1\retrorun.exe
c:\progra~1\Dantz\RETROS~1\wdsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\stsystra.exe
c:\program files\Apoint\HidFind.exe
c:\program files\Apoint\Apntex.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\WDBtnMgr.exe
c:\program files\WDC\SetIcon.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\program files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\HPBPRO.EXE
.
**************************************************************************
.
Completion time: 2010-02-03 22:32:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-04 03:32
Pre-Run: 12,537,458,688 bytes free
Post-Run: 12,724,928,512 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - CF9C08E1CE84032AD31887C386DE6978
I'm sorry for not following the rules! My computer was infected with a virus, and a friend told me to run Combofix. It was only after I ran the program that I realized I would need a specialist to review my log file. I came to this forum and then saw the "Do not run Combofix without explicit instruction" note…. sorry …
Here was my original problem: I kept getting a popup telling me that my computer was infected, and urging me to download their anti-virus program. I didn't - I tried to download and run a Norton product instead. However, my computer couldn't connect to the Norton site to update the virus definitions. I could connect to the internet, but I couldn't browse to Norton, AVG, McAfree, or other antivirus product sites. Also, if I clicked on links from a Google search result site, I would get redirected to odd locations.
The problem *seems* to be fixed since running Combofix, but the instructions strongly recommended having the log file reviewed … I would really appreciate it if someone could help me out. (File attached)
Please don't attach the scan results unless asked to. Copy/Paste them.
ComboFix 10-02-03.04 - srenzi 02/03/2010 21:54:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.284 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\captcha.dll
c:\program files\webserver
c:\windows\010112010146101105.rx
c:\windows\010112010146114101.xxe
c:\windows\01011201014650115.xxe
c:\windows\0101120101465348.xxe
c:\windows\Downloaded Program Files\MyWebEx
c:\windows\Downloaded Program Files\MyWebEx\419\atarm.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atas32.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atasanot.exe
c:\windows\Downloaded Program Files\MyWebEx\419\atasctrl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atasnt40.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atcarmcl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atdl2006.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atjpeg60.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atkbctl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atlchat.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atmemmgr.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atnetext.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atpack.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\attp.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atwbxui5.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmcliun.exe
c:\windows\Downloaded Program Files\MyWebEx\419\mwmproxy.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmtrace.txt
c:\windows\Downloaded Program Files\MyWebEx\419\mwmupd.exe
c:\windows\Downloaded Program Files\MyWebEx\419\ratrace.dll
c:\windows\Downloaded Program Files\MyWebEx\419\raurl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\uilibres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\wbxcrypt.dll
c:\windows\Downloaded Program Files\MyWebEx\419\webexmgr.dll
c:\windows\fdgg34353edfgdfdf
c:\windows\pp14.exe
c:\windows\rdr_1264952508.exe
c:\windows\system32\drivers\fio32.sys
c:\windows\system32\fio32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_FIOO32
——-\Service_fioo32
——-\Service_SfX
——-\Legacy_fio32
——-\Service_fio32
((((((((((((((((((((((((( Files Created from 2010-01-04 to 2010-02-04 )))))))))))))))))))))))))))))))
.
2010-01-31 21:56 . 2010-01-31 21:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-31 21:42 . 2010-01-31 21:42 ——– d—–w- c:\documents and settings\srenzi\Local Settings\Application Data\Downloaded Installations
2010-01-31 21:31 . 2010-01-31 21:31 ——– d—–w- c:\program files\Times Reader
2010-01-31 21:31 . 2010-01-31 21:31 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-31 21:30 . 2010-01-31 21:38 ——– d—–w- c:\documents and settings\srenzi\Local Settings\Application Data\Adobe
2010-01-31 21:30 . 2010-02-02 03:04 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-31 15:28 . 2010-02-02 03:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-01-31 15:28 . 2010-01-31 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-31 15:25 . 2010-01-31 15:25 ——– d—–w- c:\documents and settings\All Users\Symantec Temporary Files
2010-01-31 14:37 . 2010-01-31 14:37 1 —-a-w- c:\windows\conf21113.dat
2010-01-30 15:08 . 1998-04-25 10:32 210944 —-a-w- c:\windows\system32\MSVCRT10.DLL
2010-01-30 15:08 . 1998-04-25 10:32 212480 —-a-w- c:\windows\system32\pcdlib32.dll
2010-01-30 15:08 . 2010-01-30 15:08 ——– d—–w- C:\KPCMS
2010-01-30 15:08 . 1998-04-25 10:32 40129 —-a-w- c:\windows\iccsigs.dat
2010-01-30 15:08 . 1998-06-05 16:42 197120 —-a-w- c:\windows\kpcp32.dll
2010-01-30 15:08 . 1998-04-25 10:32 58368 —-a-w- c:\windows\pfpick.dll
2010-01-30 15:08 . 1998-04-25 10:32 37376 —-a-w- c:\windows\kpsys32.dll
2010-01-30 15:08 . 1998-04-25 10:32 20992 —-a-w- c:\windows\icccodes.dll
2010-01-30 15:08 . 1998-01-20 14:12 133120 —-a-w- c:\windows\sprof32.dll
2010-01-30 15:07 . 2010-01-30 15:07 ——– d—–w- c:\windows\system32\COLOR
2010-01-30 15:03 . 1998-04-25 10:19 299520 —-a-w- c:\windows\uninst.exe
2010-01-19 03:05 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-04 03:22 . 2007-03-30 00:42 ——– d—–w- c:\documents and settings\srenzi\Application Data\Skype
2010-02-04 03:21 . 2008-03-27 12:46 ——– d—–w- c:\documents and settings\srenzi\Application Data\skypePM
2010-02-04 03:06 . 2006-08-16 02:37 12 —-a-w- c:\windows\bthservsdp.dat
2010-02-01 03:00 . 2008-11-16 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Retrospect
2010-01-31 21:35 . 2006-05-19 23:43 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-31 21:30 . 2010-01-31 21:30 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-31 21:16 . 2007-03-30 00:50 82920 —-a-w- c:\documents and settings\srenzi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 21:16 . 2007-05-27 13:30 110197 -c–a-w- c:\windows\hpoins08.dat
2010-01-31 21:06 . 2007-04-04 03:25 ——– d—–w- c:\documents and settings\srenzi\Application Data\AdobeUM
2010-01-31 15:34 . 2005-02-02 08:21 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-31 15:34 . 2005-05-31 17:20 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-01-31 15:32 . 2009-07-15 15:21 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-01-21 00:21 . 2009-11-11 13:03 79488 —-a-w- c:\documents and settings\srenzi\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-19 03:25 . 2007-11-08 01:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-21 19:14 . 2004-08-11 22:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 22:44 . 2006-06-21 05:30 ——– d—–w- c:\program files\PowerArchiver
2009-12-16 19:42 . 2009-12-18 22:38 872960 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 19:42 . 2009-12-18 22:38 43008 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 19:42 . 2009-12-18 22:38 340480 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 19:41 . 2009-12-18 22:38 346624 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-20 11:08 . 2010-01-31 21:31 38784 —-a-w- c:\documents and settings\srenzi\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2006-08-31 20:51 . 2006-08-31 20:51 3711728 —-a-w- c:\program files\powarc963.exe
2006-07-06 00:20 . 2006-07-06 00:20 3988 —-a-w- c:\program files\pgupta.zip
2006-06-30 04:34 . 2006-06-30 04:32 13926456 —-a-w- c:\program files\snagit.exe
2006-06-13 23:07 . 2006-06-13 23:07 71932 —-a-w- c:\program files\Floresense_WorldClock.zip
2006-06-08 05:47 . 2006-06-08 05:47 15818536 —-a-w- c:\program files\Install_Messenger_Beta(2).exe
2006-06-02 05:43 . 2006-06-02 05:42 397352 —-a-w- c:\program files\msgr75us.exe
2006-06-02 05:42 . 2006-06-02 05:42 5118288 —-a-w- c:\program files\Firefox Setup 1.5.0.4.exe
2008-03-05 22:00 . 2006-08-31 18:02 27976 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-03-05 22:00 . 2006-08-31 18:02 125848 —-a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-03-05 22:00 . 2008-03-05 22:00 46408 —-a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2008-03-05 22:00 . 2006-08-31 18:02 98712 —-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2007-08-02 15:41 . 2006-08-31 18:02 94208 —-a-w- c:\program files\mozilla firefox\plugins\mwmcli.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-13 136600]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-02 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"SigmatelSysTrayApp"="stsystra.exe" [2006-01-09 417792]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048]
"openvpn-gui"="c:\program files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 99328]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2004-02-27 61440]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-05-20 188416]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"\\us-fs\EPSON Stylus Photo R1800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE" [2004-09-08 98304]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"WD Button Manager"="WDBtnMgr.exe" [2008-11-16 335872]
"SetIcon"="\Program Files\WDC\SetIcon.exe" [2004-04-28 42496]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
c:\documents and settings\pgupta\Start Menu\Programs\Startup\
World Clock 2001.LNK - c:\program files\Zada Solutions\World Clock\zsWldClk.exe [2000-8-22 684032]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 45056]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-5-19 24576]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-27 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-24 13:27 87352 —-a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1292428093-839522115-1109\Scripts\Logon\0\0]
"Script"=all-au.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1292428093-839522115-1297\Scripts\Logon\0\0]
"Script"=all.bat
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Codename Max\\max.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\msncall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"53:TCP"= 53:TCP:webserver
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [6/7/2007 7:10 AM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [6/7/2007 7:10 AM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/7/2007 7:06 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/31/2009 3:40 PM 133104]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [6/23/2004 8:54 PM 23552]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder
2010-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-31 20:39]
2010-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-31 20:39]
2010-02-04 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]
2010-01-28 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyServer = 192.168.10.101:3128
uInternet Settings,ProxyOverride = maddmzmm1.ingdirect.es;;*.local
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: memetrics.com\project
DPF: {1D95A7C7-3282-4DB7-9A48-7C39CE152A19} - hxxps://myemail.t-mobile.com/html/web/client_tools/TOImport.cab
DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxp://project.memetrics.com/projectserver/objects/pjclient.cab
DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxp://project.memetrics.com/projectserver/objects/1033/pjcintl.cab
FF - ProfilePath - c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_us&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-03 22:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(864)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\windows\system32\LMIinit.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(1232)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\progra~1\Dantz\RETROS~1\retrorun.exe
c:\progra~1\Dantz\RETROS~1\wdsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\stsystra.exe
c:\program files\Apoint\HidFind.exe
c:\program files\Apoint\Apntex.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\WDBtnMgr.exe
c:\program files\WDC\SetIcon.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\program files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\HPBPRO.EXE
.
**************************************************************************
.
Completion time: 2010-02-03 22:32:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-04 03:32
Pre-Run: 12,537,458,688 bytes free
Post-Run: 12,724,928,512 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - CF9C08E1CE84032AD31887C386DE6978