ComboFix 10-12-28.02 - David 12/29/2010 1:43.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3454.2840 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: Norton Security Suite *Enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_Security
((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-29 )))))))))))))))))))))))))))))))
.
2010-12-29 02:44 . 2010-12-29 02:44 ——– d-sh–w- c:\documents and settings\David\PrivacIE
2010-12-29 02:34 . 2010-12-29 02:34 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-12-29 02:34 . 2010-12-29 02:34 ——– d-sh–w- c:\documents and settings\David\IETldCache
2010-12-29 02:25 . 2010-12-29 02:28 ——– dc-h–w- c:\windows\ie8
2010-12-29 02:18 . 2010-10-18 11:10 7680 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-12-29 02:17 . 2010-11-06 00:26 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-12-29 02:17 . 2010-11-06 00:26 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-12-29 02:17 . 2010-11-06 00:26 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-12-28 22:19 . 2010-12-28 22:19 ——– d—–w- c:\documents and settings\Administrator
2010-12-28 21:11 . 2010-12-28 21:11 ——– d—–w- c:\documents and settings\David\Application Data\ElevatedDiagnostics
2010-12-20 01:50 . 2010-12-20 01:50 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-12-20 01:45 . 2010-12-20 01:45 ——– d—–w- c:\documents and settings\David\Local Settings\Application Data\Temp
2010-12-18 06:21 . 2010-12-18 06:21 ——– d—–w- c:\documents and settings\David\Application Data\FileOpen
2010-12-18 06:21 . 2010-12-18 06:21 ——– d—–w- c:\documents and settings\All Users\Application Data\FileOpen
2010-12-18 06:21 . 2010-12-18 06:21 ——– d—–w- c:\program files\FileOpen
2010-12-16 03:35 . 2010-11-02 15:17 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-16 03:26 . 2010-10-11 14:59 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
2010-12-11 23:57 . 2010-12-11 23:57 ——– d—–w- c:\program files\WMP Playlist
2010-12-11 23:57 . 2005-08-24 22:25 221184 —-a-w- c:\windows\system32\JwldButn2b.ocx
2010-12-06 20:14 . 2010-12-06 20:14 ——– d—–w- c:\documents and settings\David\Application Data\Blackberry Desktop
2010-12-06 20:04 . 2010-12-06 20:04 ——– d—–w- c:\documents and settings\LocalService\Application Data\Roxio
2010-12-06 20:04 . 2010-12-06 20:04 ——– d—–w- c:\documents and settings\David\Application Data\Roxio
2010-12-06 19:58 . 2010-12-06 19:58 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2010-12-06 19:56 . 2010-12-06 19:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Roxio
2010-12-06 19:56 . 2010-12-06 19:56 ——– d—–w- c:\program files\Roxio
2010-12-06 19:56 . 2010-12-06 19:56 ——– d—–w- c:\program files\Common Files\Sonic Shared
2010-12-06 19:56 . 2010-12-06 19:57 ——– d—–w- c:\program files\Common Files\Roxio Shared
2010-12-06 19:53 . 2010-12-06 19:53 ——– d—–w- c:\program files\Research In Motion
2010-12-06 19:47 . 2010-12-24 19:01 256 —-a-w- c:\windows\system32\pool.bin
2010-12-06 19:47 . 2010-12-06 19:47 ——– d—–w- c:\documents and settings\David\Application Data\Research In Motion
2010-12-06 19:46 . 2007-01-18 15:24 26496 —-a-r- c:\windows\system32\drivers\RimSerial.sys
2010-12-06 19:45 . 2010-12-06 19:54 ——– d—–w- c:\program files\Common Files\Research In Motion
2010-12-06 04:45 . 2010-12-06 04:45 ——– d—–w- c:\program files\Flip Video
2010-11-29 22:38 . 2010-11-29 22:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 22:38 . 2010-11-29 22:38 69632 —-a-w- c:\windows\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:12 . 2003-12-27 18:07 81920 —-a-w- c:\windows\system32\isign32.dll
2010-11-06 00:26 . 2004-02-06 22:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2003-12-28 00:42 43520 ——w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2003-12-28 00:42 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-04 05:59 385024 ——w- c:\windows\system32\html.iec
2010-11-03 11:54 . 2010-11-03 11:54 2471264 —-a-w- c:\windows\system32\AutoPartNt.exe
2010-11-03 05:08 . 2010-11-03 05:08 594208 —-a-w- c:\windows\system32\drivers\timntr.sys
2010-11-03 05:08 . 2010-11-03 05:08 170272 —-a-w- c:\windows\system32\drivers\snapman.sys
2010-11-03 03:32 . 2010-11-03 03:30 16384 —-a-w- c:\windows\system32\lgfwunis.exe
2010-11-03 03:17 . 2004-05-29 17:15 505128 —-a-w- c:\windows\system32\msvcp71.dll
2010-11-03 03:17 . 2004-05-29 17:15 353576 —-a-w- c:\windows\system32\msvcr71.dll
2010-11-02 15:17 . 2003-12-28 00:43 40960 —-a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2003-12-28 00:40 290048 —-a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2003-12-28 00:44 1853312 —-a-w- c:\windows\system32\win32k.sys
2010-10-06 04:12 . 2010-10-06 04:12 14601 —-a-w- c:\windows\system32\drivers\FIDE.SYS
2004-02-02 18:09 . 2004-02-02 18:09 775214 —-a-w- c:\program files\indiv1218.exe
2004-01-29 07:50 . 2004-01-29 07:50 48958816 —-a-w- c:\program files\msprod2.exe
2003-12-28 03:12 . 2003-12-28 03:12 23616646 —-a-w- c:\program files\wxp-w2k-catalyst-7-962-031202m1-012924c.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-12-29_05.59.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-26 08:12 . 2010-12-29 06:52 508712992 c:\windows\SYSTEM32\DRIVERS\fidbox.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-04-04 774144]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-06-07 2605424]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-02-28 519584]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinDefend"=2 (0x2)
"ITMRTSVC"=2 (0x2)
"PcCtlCom"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"odserv"=3 (0x3)
"N360"=2 (0x2)
"iPod Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"1&1 EasyLogin"=c:\program files\1&1\1&1 EasyLogin\EasyLogin.exe
"Picasa Media Detector"=c:\program files\Picasa2\PicasaMediaDetector.exe
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /systrayIcon:on /fl:on /fr:on /appData:on
"USBToolTip"="c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ASUS\\AsusUpdate\\Update.exe"=
"c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1038:TCP"= 1038:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
R1 is-9B2B6drv;is-9B2B6drv;c:\windows\SYSTEM32\DRIVERS\88035407.sys [1/18/2009 3:54 AM 148496]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/19/2010 8:45 PM 136176]
S3 ASUSHWIO;ASUSHWIO;\??\c:\windows\System32\drivers\ASUSHWIO.sys –> c:\windows\System32\drivers\ASUSHWIO.sys [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [3/25/2010 9:25 AM 30969208]
S3 MTK;Media Technology Kernel Driver;c:\windows\SYSTEM32\DRIVERS\FIDE.SYS [10/5/2010 11:12 PM 14601]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S3 PinnacleMarvinAVS;Pinnacle AVStream Service for MovieBox Deluxe, 500-USB and 700-USB;c:\windows\SYSTEM32\DRIVERS\MarvinAVS.sys [5/26/2008 1:40 AM 434176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 17:24 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-12-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
2010-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-20 01:44]
2010-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-20 01:44]
2010-12-29 c:\windows\Tasks\User_Feed_Synchronization-{AF6777B1-9D60-49A1-ACDC-7887CE1F1C3F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\uqkpa3vn.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch⁡=14542
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/home?AF=14542
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=adbartrp⁡=14542&q;=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Facemoods: [removed] - %profile%\extensions\[removed]
FF - Ext: Babylon-English Toolbar: {ce18769b-c7fa-42d2-860d-17c4662c70ad} - %profile%\extensions\{ce18769b-c7fa-42d2-860d-17c4662c70ad}
.
.
——- File Associations ——-
.
txtfile=c:\windows\NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-29 01:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
"ImagePath"="\"c:\documents and settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_18.05.2008_00-35
[1].exe\" -r"
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\setup_7.0.0.180_18.05.2008_00-35[1]]
"ImagePath"="\"c:\documents and settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_18.05.2008_00-35
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(804)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3940)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~3\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Flip Video\FlipShare\FlipShareService.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-12-29 01:58:09 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-29 06:58
ComboFix2.txt 2010-12-29 06:05
ComboFix3.txt 2008-05-26 15:09
Pre-Run: 703,370,501,120 bytes free
Post-Run: 703,350,775,296 bytes free
- - End Of File - - A75DA7B01E9FB5E9EC715BE653012783