SJunk
Topic Starter
Just now able to get back to computer repair (think taxes and kids!). I have followed all the instructions and have copied the ComboFix log below. The computer seems to be running fine now.
Questions: What was the problem? Are all infections cleaned from this machine now? Can I be sure that there is no root kit, packet sniffer or keylogger on this computer now?
Thank you so much!
Jennifer
ps-love the name of the website!
Here is the prior thread link that was closed a couple of days ago: http://forums.whatthetech.com/Possible_Tro…on_t111550.html
ComboFix 10-04-21.01 - Parents 04/21/2010 14:06:35.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.907 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\temp\brr
c:\windows\desktop
c:\windows\system32\Data
c:\windows\system32\service
c:\windows\system32\service\12082009_TIS17_SfFniAU.log
c:\windows\system32\service\27062009_TIS17_SfFniAU.log
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-03-21 to 2010-04-21 )))))))))))))))))))))))))))))))
.
2010-04-10 23:08 . 2010-04-10 23:08 ——– d—–w- c:\program files\ERUNT
2010-04-10 22:51 . 2008-03-06 16:51 3840 —-a-w- c:\windows\system32\drivers\BANTExt.sys
2010-04-10 22:28 . 2010-04-10 22:33 ——– d—–w- c:\documents and settings\Administrator\Application Data\HPAppData
2010-04-10 21:02 . 2010-04-10 21:05 23112 —-a-w- c:\windows\hpqins15.dat
2010-04-10 20:59 . 2010-04-21 19:01 ——– d—–w- c:\documents and settings\Parents\Application Data\HpUpdate
2010-04-10 20:59 . 2010-04-10 20:59 ——– d—–w- c:\windows\Hewlett-Packard
2010-04-07 21:17 . 2010-04-07 21:17 ——– d—–w- c:\documents and settings\Andrew\Application Data\HPAppData
2010-04-07 20:50 . 2010-04-13 19:03 ——– d—–w- c:\documents and settings\Parents\Application Data\HPAppData
2010-04-07 20:44 . 2010-04-07 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\WEBREG
2010-04-07 20:43 . 2010-04-07 20:46 ——– d—–w- c:\documents and settings\Parents\Application Data\HP
2010-04-07 20:42 . 2008-10-28 10:31 16496 —-a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-04-07 20:42 . 2008-10-28 10:31 49920 —-a-r- c:\windows\system32\drivers\HPZid412.sys
2010-04-07 20:41 . 2008-10-06 20:38 121344 —-a-w- c:\windows\system32\hpf3l083.dll
2010-04-07 20:41 . 2008-10-06 20:37 315392 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp083.dll
2010-04-07 20:41 . 2008-10-29 18:56 271704 —-a-r- c:\windows\system32\hpzids01.dll
2010-04-07 20:41 . 2008-10-28 10:31 21568 —-a-r- c:\windows\system32\drivers\HPZius12.sys
2010-04-07 20:41 . 2008-10-29 18:57 974848 —-a-r- c:\windows\system32\hpost_p02b.dll
2010-04-07 20:41 . 2008-10-29 18:57 307200 —-a-r- c:\windows\system32\hposc_p02a.dll
2010-04-07 20:41 . 2008-10-28 10:31 372736 —-a-r- c:\windows\system32\hppldcoi.dll
2010-04-07 20:41 . 2008-10-28 10:31 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-04-07 20:41 . 2008-10-29 18:57 737280 —-a-r- c:\windows\system32\hposwia_p02b.dll
2010-04-07 18:28 . 2010-04-07 18:28 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-04-07 18:06 . 2010-04-07 18:06 ——– d—–w- c:\program files\Common Files\HP
2010-04-07 18:05 . 2010-04-07 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-04-07 18:05 . 2010-04-07 18:05 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2010-04-07 18:04 . 2010-04-10 21:00 ——– d—–w- c:\program files\HP
2010-04-07 18:04 . 2008-04-13 17:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-04-07 18:04 . 2008-04-13 17:45 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-07 17:57 . 2010-04-07 20:44 161787 —-a-w- c:\windows\hpoins36.dat
2010-04-07 17:57 . 2009-06-24 09:40 652 ——w- c:\windows\hpomdl36.dat
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\documents and settings\Parents\Application Data\Sunbelt
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Sunbelt
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\program files\Sunbelt Software
2010-04-07 12:21 . 2010-02-24 15:16 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\documents and settings\Parents\Application Data\Malwarebytes
2010-04-07 04:40 . 2010-03-30 05:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-07 04:40 . 2010-03-30 05:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-07 04:12 . 2010-04-07 04:12 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-04-07 04:12 . 2010-04-07 04:12 ——– d—–w- c:\program files\IObit
2010-04-07 03:54 . 2010-04-07 03:54 ——– d—–w- c:\program files\CCleaner
2010-04-06 22:18 . 2010-04-06 22:18 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2010-04-06 22:18 . 2010-04-06 22:18 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2010-04-06 15:54 . 2010-04-06 15:54 503808 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\msvcp71.dll
2010-04-06 15:54 . 2010-04-06 15:54 499712 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\jmc.dll
2010-04-06 15:54 . 2010-04-06 15:54 348160 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\msvcr71.dll
2010-04-06 15:54 . 2010-04-06 15:54 61440 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-572568a5-n\decora-sse.dll
2010-04-06 15:54 . 2010-04-06 15:54 12800 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-572568a5-n\decora-d3d.dll
2010-04-06 15:06 . 2010-04-06 15:06 ——– d—–w- c:\documents and settings\Parents\Local Settings\Application Data\Temp
2010-04-06 14:50 . 2009-10-23 15:28 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-03-24 08:04 . 2010-03-24 18:17 952768 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AdobeARM.exe
2010-03-24 08:04 . 2010-03-24 18:17 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AdobeExtractFiles.dll
2010-03-24 08:04 . 2010-03-24 18:17 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\ReaderUpdater.exe
2010-03-24 08:04 . 2010-03-24 18:17 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AcrobatUpdater.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-10 21:11 . 2004-02-28 23:49 ——– d—–w- c:\program files\Common Files\Adobe
2010-04-07 22:12 . 2007-11-03 01:09 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-07 21:15 . 2009-07-24 18:21 41960 -c–a-w- c:\documents and settings\Andrew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-07 20:43 . 2004-01-23 01:11 41960 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-07 16:35 . 2004-01-23 00:58 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-07 16:34 . 2007-05-17 14:41 ——– d—–w- c:\program files\FinePixViewer
2010-04-07 16:33 . 2007-05-17 14:42 ——– d—–w- c:\documents and settings\Parents\Application Data\FUJIFILM
2010-04-07 16:10 . 2007-07-22 16:39 ——– d—–w- c:\program files\Common Files\Apple
2010-04-07 16:04 . 2009-09-14 17:23 ——– d—–w- c:\program files\QuickTime
2010-04-07 15:21 . 2009-02-22 20:31 ——– d—–w- c:\program files\Windows Live
2010-04-06 23:29 . 2004-02-29 03:02 ——– d—–w- c:\program files\Google
2010-04-06 22:01 . 2004-01-27 20:43 41576 —-a-w- c:\documents and settings\Kids\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-06 15:53 . 2004-01-23 00:31 ——– d—–w- c:\program files\Java
2010-04-06 15:19 . 2008-02-03 01:23 ——– d—–w- c:\documents and settings\Parents\Application Data\StarOffice8
2010-03-10 06:15 . 2002-08-29 11:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 09:28 . 2009-02-22 19:30 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-25 06:24 . 2004-02-06 23:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-08-29 11:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 1980-01-01 06:00 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 1980-01-01 06:00 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2003-07-10 18:19 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2003-06-30 22:30 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2004-08-04 07:56 . 2005-02-17 17:35 73728 -csha-w- c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2004-05-28 323584]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-11-03 4800512]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 17:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher 2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk
backup=c:\windows\pss\Exif Launcher 2.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Parents^Start Menu^Programs^Startup^Folding@Home 5.03.lnk]
path=c:\documents and settings\Parents\Start Menu\Programs\Startup\Folding@Home 5.03.lnk
backup=c:\windows\pss\Folding@Home 5.03.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
2002-04-03 07:01 135264 —-a-w- c:\program files\Creative\SBLive\Diagnostics\diagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2003-08-13 16:27 28672 —-a-w- c:\windows\SYSTEM32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 07:00 90112 -c—-w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
R2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [9/14/2009 1:19 PM 10384]
R2 tmpreflt;tmpreflt;c:\windows\SYSTEM32\DRIVERS\tmpreflt.sys [9/14/2009 1:52 PM 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R2 WMP300NSvc;WMP300NSvc;c:\program files\Linksys\WMP300N\WLService.exe [11/14/2008 12:23 AM 53307]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\SYSTEM32\DRIVERS\TM_CFW.sys [9/14/2009 1:52 PM 339984]
R3 tmevtmgr;tmevtmgr;c:\windows\SYSTEM32\DRIVERS\tmevtmgr.sys [9/14/2009 1:55 PM 50704]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [9/14/2009 1:56 PM 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [9/14/2009 1:56 PM 689416]
R3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;c:\windows\SYSTEM32\DRIVERS\WMP300Nv1.sys [11/14/2008 12:18 AM 822400]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys –> c:\windows\system32\drivers\SBREdrv.sys [?]
S3 P1130VID;Creative WebCam NX Pro;c:\windows\SYSTEM32\DRIVERS\P1130Vid.sys [10/19/2006 10:05 PM 90229]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-02-01 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\SYSTEM32\cleanmgr.exe [2002-08-29 00:12]
2010-04-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
2010-04-21 c:\windows\Tasks\User_Feed_Synchronization-{87256BA6-AB36-408B-A11D-9D8824DECCB8}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Parents\Application Data\Mozilla\Firefox\Profiles\6jph20mi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://webmail.central.cox.net/
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-PCMService - c:\program files\Dell\Media Experience\PCMService.exe
MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-RoxioAudioCentral - c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
MSConfigStartUp-SBAMTray - c:\program files\Sunbelt Software\CounterSpy\SBAMTray.exe
MSConfigStartUp-SDTray - c:\program files\Spyware Doctor\SDTrayApp.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
AddRemove-101 Dalmatians StoryBook - c:\disney\101_ASB\101_DEL95.EXE
AddRemove-Adobe Flash Player ActiveX - c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(960)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2010-04-21 14:13:39
ComboFix-quarantined-files.txt 2010-04-21 19:13
Pre-Run: 53,213,671,424 bytes free
Post-Run: 53,182,865,408 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 9006F47018615680F4B4F6FA4ED6BBAB
Questions: What was the problem? Are all infections cleaned from this machine now? Can I be sure that there is no root kit, packet sniffer or keylogger on this computer now?
Thank you so much!
Jennifer
ps-love the name of the website!
Here is the prior thread link that was closed a couple of days ago: http://forums.whatthetech.com/Possible_Tro…on_t111550.html
ComboFix 10-04-21.01 - Parents 04/21/2010 14:06:35.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.907 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\temp\brr
c:\windows\desktop
c:\windows\system32\Data
c:\windows\system32\service
c:\windows\system32\service\12082009_TIS17_SfFniAU.log
c:\windows\system32\service\27062009_TIS17_SfFniAU.log
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-03-21 to 2010-04-21 )))))))))))))))))))))))))))))))
.
2010-04-10 23:08 . 2010-04-10 23:08 ——– d—–w- c:\program files\ERUNT
2010-04-10 22:51 . 2008-03-06 16:51 3840 —-a-w- c:\windows\system32\drivers\BANTExt.sys
2010-04-10 22:28 . 2010-04-10 22:33 ——– d—–w- c:\documents and settings\Administrator\Application Data\HPAppData
2010-04-10 21:02 . 2010-04-10 21:05 23112 —-a-w- c:\windows\hpqins15.dat
2010-04-10 20:59 . 2010-04-21 19:01 ——– d—–w- c:\documents and settings\Parents\Application Data\HpUpdate
2010-04-10 20:59 . 2010-04-10 20:59 ——– d—–w- c:\windows\Hewlett-Packard
2010-04-07 21:17 . 2010-04-07 21:17 ——– d—–w- c:\documents and settings\Andrew\Application Data\HPAppData
2010-04-07 20:50 . 2010-04-13 19:03 ——– d—–w- c:\documents and settings\Parents\Application Data\HPAppData
2010-04-07 20:44 . 2010-04-07 20:44 ——– d—–w- c:\documents and settings\All Users\Application Data\WEBREG
2010-04-07 20:43 . 2010-04-07 20:46 ——– d—–w- c:\documents and settings\Parents\Application Data\HP
2010-04-07 20:42 . 2008-10-28 10:31 16496 —-a-r- c:\windows\system32\drivers\HPZipr12.sys
2010-04-07 20:42 . 2008-10-28 10:31 49920 —-a-r- c:\windows\system32\drivers\HPZid412.sys
2010-04-07 20:41 . 2008-10-06 20:38 121344 —-a-w- c:\windows\system32\hpf3l083.dll
2010-04-07 20:41 . 2008-10-06 20:37 315392 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp083.dll
2010-04-07 20:41 . 2008-10-29 18:56 271704 —-a-r- c:\windows\system32\hpzids01.dll
2010-04-07 20:41 . 2008-10-28 10:31 21568 —-a-r- c:\windows\system32\drivers\HPZius12.sys
2010-04-07 20:41 . 2008-10-29 18:57 974848 —-a-r- c:\windows\system32\hpost_p02b.dll
2010-04-07 20:41 . 2008-10-29 18:57 307200 —-a-r- c:\windows\system32\hposc_p02a.dll
2010-04-07 20:41 . 2008-10-28 10:31 372736 —-a-r- c:\windows\system32\hppldcoi.dll
2010-04-07 20:41 . 2008-10-28 10:31 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-04-07 20:41 . 2008-10-29 18:57 737280 —-a-r- c:\windows\system32\hposwia_p02b.dll
2010-04-07 18:28 . 2010-04-07 18:28 ——– d—–w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-04-07 18:06 . 2010-04-07 18:06 ——– d—–w- c:\program files\Common Files\HP
2010-04-07 18:05 . 2010-04-07 20:43 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-04-07 18:05 . 2010-04-07 18:05 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2010-04-07 18:04 . 2010-04-10 21:00 ——– d—–w- c:\program files\HP
2010-04-07 18:04 . 2008-04-13 17:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-04-07 18:04 . 2008-04-13 17:45 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-07 17:57 . 2010-04-07 20:44 161787 —-a-w- c:\windows\hpoins36.dat
2010-04-07 17:57 . 2009-06-24 09:40 652 ——w- c:\windows\hpomdl36.dat
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\documents and settings\Parents\Application Data\Sunbelt
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Sunbelt
2010-04-07 14:42 . 2010-04-07 14:42 ——– d—–w- c:\program files\Sunbelt Software
2010-04-07 12:21 . 2010-02-24 15:16 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\documents and settings\Parents\Application Data\Malwarebytes
2010-04-07 04:40 . 2010-03-30 05:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-07 04:40 . 2010-04-07 04:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-07 04:40 . 2010-03-30 05:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-07 04:12 . 2010-04-07 04:12 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-04-07 04:12 . 2010-04-07 04:12 ——– d—–w- c:\program files\IObit
2010-04-07 03:54 . 2010-04-07 03:54 ——– d—–w- c:\program files\CCleaner
2010-04-06 22:18 . 2010-04-06 22:18 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2010-04-06 22:18 . 2010-04-06 22:18 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2010-04-06 15:54 . 2010-04-06 15:54 503808 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\msvcp71.dll
2010-04-06 15:54 . 2010-04-06 15:54 499712 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\jmc.dll
2010-04-06 15:54 . 2010-04-06 15:54 348160 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7a4ea8ed-n\msvcr71.dll
2010-04-06 15:54 . 2010-04-06 15:54 61440 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-572568a5-n\decora-sse.dll
2010-04-06 15:54 . 2010-04-06 15:54 12800 —-a-w- c:\documents and settings\Parents\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-572568a5-n\decora-d3d.dll
2010-04-06 15:06 . 2010-04-06 15:06 ——– d—–w- c:\documents and settings\Parents\Local Settings\Application Data\Temp
2010-04-06 14:50 . 2009-10-23 15:28 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-03-24 08:04 . 2010-03-24 18:17 952768 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AdobeARM.exe
2010-03-24 08:04 . 2010-03-24 18:17 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AdobeExtractFiles.dll
2010-03-24 08:04 . 2010-03-24 18:17 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\ReaderUpdater.exe
2010-03-24 08:04 . 2010-03-24 18:17 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\26554\AcrobatUpdater.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-10 21:11 . 2004-02-28 23:49 ——– d—–w- c:\program files\Common Files\Adobe
2010-04-07 22:12 . 2007-11-03 01:09 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-07 21:15 . 2009-07-24 18:21 41960 -c–a-w- c:\documents and settings\Andrew\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-07 20:43 . 2004-01-23 01:11 41960 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-07 16:35 . 2004-01-23 00:58 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-07 16:34 . 2007-05-17 14:41 ——– d—–w- c:\program files\FinePixViewer
2010-04-07 16:33 . 2007-05-17 14:42 ——– d—–w- c:\documents and settings\Parents\Application Data\FUJIFILM
2010-04-07 16:10 . 2007-07-22 16:39 ——– d—–w- c:\program files\Common Files\Apple
2010-04-07 16:04 . 2009-09-14 17:23 ——– d—–w- c:\program files\QuickTime
2010-04-07 15:21 . 2009-02-22 20:31 ——– d—–w- c:\program files\Windows Live
2010-04-06 23:29 . 2004-02-29 03:02 ——– d—–w- c:\program files\Google
2010-04-06 22:01 . 2004-01-27 20:43 41576 —-a-w- c:\documents and settings\Kids\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-06 15:53 . 2004-01-23 00:31 ——– d—–w- c:\program files\Java
2010-04-06 15:19 . 2008-02-03 01:23 ——– d—–w- c:\documents and settings\Parents\Application Data\StarOffice8
2010-03-10 06:15 . 2002-08-29 11:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 09:28 . 2009-02-22 19:30 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-25 06:24 . 2004-02-06 23:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-08-29 11:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 1980-01-01 06:00 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 1980-01-01 06:00 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2003-07-10 18:19 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2003-06-30 22:30 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2004-08-04 07:56 . 2005-02-17 17:35 73728 -csha-w- c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2004-05-28 323584]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-11-03 4800512]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 17:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher 2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk
backup=c:\windows\pss\Exif Launcher 2.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Parents^Start Menu^Programs^Startup^Folding@Home 5.03.lnk]
path=c:\documents and settings\Parents\Start Menu\Programs\Startup\Folding@Home 5.03.lnk
backup=c:\windows\pss\Folding@Home 5.03.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
2002-04-03 07:01 135264 —-a-w- c:\program files\Creative\SBLive\Diagnostics\diagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
2003-08-13 16:27 28672 —-a-w- c:\windows\SYSTEM32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 07:00 90112 -c—-w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
R2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [9/14/2009 1:19 PM 10384]
R2 tmpreflt;tmpreflt;c:\windows\SYSTEM32\DRIVERS\tmpreflt.sys [9/14/2009 1:52 PM 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R2 WMP300NSvc;WMP300NSvc;c:\program files\Linksys\WMP300N\WLService.exe [11/14/2008 12:23 AM 53307]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\SYSTEM32\DRIVERS\TM_CFW.sys [9/14/2009 1:52 PM 339984]
R3 tmevtmgr;tmevtmgr;c:\windows\SYSTEM32\DRIVERS\tmevtmgr.sys [9/14/2009 1:55 PM 50704]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [9/14/2009 1:56 PM 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [9/14/2009 1:56 PM 689416]
R3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;c:\windows\SYSTEM32\DRIVERS\WMP300Nv1.sys [11/14/2008 12:18 AM 822400]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys –> c:\windows\system32\drivers\SBREdrv.sys [?]
S3 P1130VID;Creative WebCam NX Pro;c:\windows\SYSTEM32\DRIVERS\P1130Vid.sys [10/19/2006 10:05 PM 90229]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-02-01 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\SYSTEM32\cleanmgr.exe [2002-08-29 00:12]
2010-04-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
2010-04-21 c:\windows\Tasks\User_Feed_Synchronization-{87256BA6-AB36-408B-A11D-9D8824DECCB8}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Parents\Application Data\Mozilla\Firefox\Profiles\6jph20mi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://webmail.central.cox.net/
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-PCMService - c:\program files\Dell\Media Experience\PCMService.exe
MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-RoxioAudioCentral - c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
MSConfigStartUp-SBAMTray - c:\program files\Sunbelt Software\CounterSpy\SBAMTray.exe
MSConfigStartUp-SDTray - c:\program files\Spyware Doctor\SDTrayApp.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
AddRemove-101 Dalmatians StoryBook - c:\disney\101_ASB\101_DEL95.EXE
AddRemove-Adobe Flash Player ActiveX - c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(960)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2010-04-21 14:13:39
ComboFix-quarantined-files.txt 2010-04-21 19:13
Pre-Run: 53,213,671,424 bytes free
Post-Run: 53,182,865,408 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 9006F47018615680F4B4F6FA4ED6BBAB