Have'nt had any redirects so far - no other problems noticed
ComboFix 10-04-10.02 - User 11/04/2010 8:33.3.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1482 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-03-10 to 2010-04-10 )))))))))))))))))))))))))))))))
.
2010-04-10 22:22 . 2009-10-25 18:32 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\NAVEX32A.DLL
2010-04-10 22:22 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\NAVENG.SYS
2010-04-10 22:22 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\NAVEX15.SYS
2010-04-10 22:22 . 2009-10-25 18:32 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\NAVENG32.DLL
2010-04-10 22:22 . 2009-12-09 09:00 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\CCERASER.DLL
2010-04-10 22:22 . 2009-10-25 18:32 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\EECTRL.SYS
2010-04-10 22:22 . 2009-10-25 18:32 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\ECMSVR32.DLL
2010-04-10 22:22 . 2009-10-25 18:32 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\ERASER.SYS
2010-04-10 08:14 . 2010-04-07 23:22 8832 —-a-w- c:\windows\system32\drivers\rasacd.sys
2010-04-10 08:14 . 2010-04-07 23:22 8832 —-a-w- C:\rasacd.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 -c–a-w- c:\windows\system32\dllcache\atapi.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 —-a-w- c:\windows\system32\drivers\ATAPI.SYS
2010-04-06 22:11 . 2008-04-14 12:00 96512 —-a-w- C:\atapi.sys
2010-04-05 22:15 . 2010-04-05 22:15 ——– d—–w- C:\tds old log
2010-04-05 21:30 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSvix86.sys
2010-04-05 21:30 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\Scxpx86.dll
2010-04-05 21:30 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSxpx86.dll
2010-04-05 21:30 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSviA64.sys
2010-04-05 21:30 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSXpx86.sys
2010-04-04 07:41 . 2010-04-04 07:41 ——– d—–w- c:\program files\Sophos
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-03-26 08:42 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSvix86.sys
2010-03-26 08:42 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\Scxpx86.dll
2010-03-26 08:42 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSxpx86.dll
2010-03-26 08:42 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSviA64.sys
2010-03-26 08:42 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSXpx86.sys
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\program files\EwisoftWeb
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\documents and settings\All Users\Application Data\EwisoftWeb
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-10 11:25 . 2009-03-10 06:23 ——– d—–w- c:\documents and settings\User\Application Data\AdobeUM
2010-04-09 09:59 . 2009-02-02 11:49 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-09 09:58 . 2009-02-02 11:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-07 23:22 . 2008-04-14 12:00 8832 —-a-w- c:\windows\system32\drivers\rasacd.old
2010-04-06 04:27 . 2008-04-14 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.old
2010-04-04 10:53 . 2009-01-23 07:06 ——– d—–w- c:\documents and settings\User\Application Data\LimeWire
2010-04-04 10:18 . 2009-05-21 03:39 ——– d—–w- c:\program files\Ultra QuickTime Converter
2010-04-02 06:15 . 2009-02-04 01:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-02 06:15 . 2009-06-01 10:11 5918776 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-03-29 13:46 . 2009-02-04 01:01 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 13:45 . 2009-02-04 01:01 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 21:44 . 2009-11-11 08:00 79488 —-a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-26 23:26 . 2010-02-26 23:26 ——– d—–w- c:\documents and settings\User\Application Data\AVG8
2010-02-25 07:43 . 2010-02-25 07:43 ——– d—–w- c:\program files\Trymedia
2010-02-25 06:24 . 2008-04-14 12:00 916480 ——w- c:\windows\system32\wininet.dll
2010-02-11 11:08 . 2009-05-17 02:26 ——– d—–w- c:\program files\Google
2010-01-18 03:36 . 2009-01-19 10:15 86480 —-a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-04-05_03.41.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-10 22:12 . 2010-04-10 22:12 16384 c:\windows\Temp\Perflib_Perfdata_708.dat
+ 2010-04-10 22:12 . 2010-04-10 22:12 16384 c:\windows\Temp\Perflib_Perfdata_68c.dat
- 2008-04-14 12:00 . 2010-04-05 00:31 75452 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2010-04-06 10:16 75452 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2010-04-07 23:22 8832 c:\windows\system32\dllcache\rasacd.sys
- 2008-04-14 12:00 . 2010-04-04 01:25 8832 c:\windows\system32\dllcache\rasacd.sys
+ 2008-04-14 12:00 . 2010-04-06 10:16 450960 c:\windows\system32\perfh009.dat
- 2008-04-14 12:00 . 2010-04-05 00:31 450960 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-17 39408]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"PE2CKFNT SE"="c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 25088]
c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 217194]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Photo Express Calendar Checker SE.lnk - c:\program files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2009-3-8 55296]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\programs\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1233:UDP"= 1233:UDP:Windows Media Format SDK (svchost.exe)
"1232:UDP"= 1232:UDP:Windows Media Format SDK (svchost.exe)
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1008000.029\SymEFA.sys [28/01/2010 10:22 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1008000.029\BHDrvx86.sys [28/01/2010 10:22 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1008000.029\cchpx86.sys [28/01/2010 10:21 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSXpx86.sys [6/04/2010 7:30 AM 329592]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [28/01/2010 10:21 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [26/08/2009 6:00 PM 102448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
.
Contents of the 'Scheduled Tasks' folder
2010-04-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
2010-04-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]
2010-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
2010-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
mSearch Bar = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-11 08:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(1372)
c:\windows\system32\WININET.dll
c:\oplimit\oahook32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-04-11 08:39:39
ComboFix-quarantined-files.txt 2010-04-10 22:39
ComboFix2.txt 2010-04-05 03:47
Pre-Run: 229,047,300,096 bytes free
Post-Run: 229,051,482,112 bytes free
- - End Of File - - FE88AF22A3ABFC54FEE40B8070F36FF9