Dear Satchfan,
I hope this is the proper report:
File name:
sfcfiles.dll
Submission date:
2011-06-10 17:44:00 (UTC)
Current status:
queued queued (#32) analysing finished
Result:
0/ 42 (0.0%)
VT Community
not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.06.11.00 2011.06.10 -
AntiVir 7.11.9.156 2011.06.10 -
Antiy-AVL 2.0.3.7 2011.06.10 -
Avast 4.8.1351.0 2011.06.10 -
Avast5 5.0.677.0 2011.06.10 -
AVG 10.0.0.1190 2011.06.10 -
BitDefender 7.2 2011.06.10 -
CAT-QuickHeal 11.00 2011.06.10 -
ClamAV 0.97.0.0 2011.06.10 -
Commtouch 5.3.2.6 2011.06.10 -
Comodo 9016 2011.06.10 -
DrWeb 5.0.2.03300 2011.06.10 -
eSafe 7.0.17.0 2011.06.09 -
eTrust-Vet 36.1.8379 2011.06.10 -
F-Prot 4.6.2.117 2011.06.10 -
F-Secure 9.0.16440.0 2011.06.10 -
Fortinet 4.2.257.0 2011.06.10 -
GData 22 2011.06.10 -
Ikarus T3.1.1.104.0 2011.06.10 -
Jiangmin 13.0.900 2011.06.10 -
K7AntiVirus 9.106.4798 2011.06.10 -
Kaspersky 9.0.0.837 2011.06.10 -
McAfee 5.400.0.1158 2011.06.10 -
McAfee-GW-Edition 2010.1D 2011.06.10 -
Microsoft 1.6903 2011.06.10 -
NOD32 6196 2011.06.10 -
Norman 6.07.10 2011.06.10 -
nProtect 2011-06-10.01 2011.06.10 -
Panda 10.0.3.5 2011.06.10 -
PCTools 7.0.3.5 2011.06.10 -
Prevx 3.0 2011.06.10 -
Rising 23.61.04.07 2011.06.10 -
Sophos 4.66.0 2011.06.10 -
SUPERAntiSpyware 4.40.0.1006 2011.06.10 -
Symantec 20111.1.0.186 2011.06.10 -
TheHacker 6.7.0.1.227 2011.06.10 -
TrendMicro 9.200.0.1012 2011.06.10 -
TrendMicro-HouseCall 9.200.0.1012 2011.06.10 -
VBA32 3.12.16.1 2011.06.10 -
VIPRE 9543 2011.06.10 -
ViRobot 2011.6.10.4505 2011.06.10 -
VirusBuster 14.0.75.2 2011.06.10 -
Additional information
Show all
MD5 : 600d58665d16bfbb776efefb0e80532d
SHA1 : c9719f14eab06cf0b5422bad7bee950a7c308768
SHA256: bc43d953e24b76a86aa7252a35ce408341fc14e6b1cb5a0c592a92ba4f9325ae
ssdeep: 3072:4UeE8F3PH/mvTKJrhqCaDfzqdK2D+P7KsLxvmzmekuNrR4:4w8FlmfzqQHLxvmzy
File size : 1614848 bytes
First seen: 2010-01-09 19:41:50
Last seen : 2011-06-10 17:44:00
TrID:
Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisherβ¦.: Microsoft Corporation
copyrightβ¦.: Β© Microsoft Corporation. All rights reserved.
productβ¦β¦: Microsoft_ Windows_ Operating System
description..: Windows 2000 System File Checker
original name:
internal name:
file version.: 5.1.2600.5512 (xpsp.080413-2111)
commentsβ¦..: n/a
signersβ¦β¦: -
signing date.: -
verifiedβ¦..: Unsigned
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x120D
timedatestampβ¦.: 0x48025222 (Sun Apr 13 18:34:10 2008)
machinetypeβ¦β¦: 0x14c (I386)
[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xCBF, 0xE00, 5.90, d3fe89394e3542961bec08f951a2b772
.data, 0x2000, 0x17E730, 0x17E800, 3.28, 5d80ab7c2b8cdbd61fd93d0e84a79990
.rsrc, 0x181000, 0x408, 0x600, 2.49, 6ad33d817c21d5547a4921c76c19efff
.reloc, 0x182000, 0xA230, 0xA400, 5.76, 31a909823c459f02f7ee7c2c9f09fc93
[[ 1 import(s) ]]
ntdll.dll: LdrDisableThreadCalloutsForDll, NtClose, NtQueryValueKey, NtOpenKey, RtlInitUnicodeString, RtlGetVersion, NtTerminateProcess, RtlUnhandledExceptionFilter, RtlUnwind, NtQueryVirtualMemory
[[ 1 export(s) ]]
SfcGetFiles
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 3584
CompanyName: Microsoft Corporation
EntryPoint: 0x120d
FileDescription: Windows 2000 System File Checker
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 1577 kB
FileSubtype: 0
FileType: Win32 DLL
FileVersion: 5.1.2600.5512 (xpsp.080413-2111)
FileVersionNumber: 5.1.2600.5512
ImageVersion: 5.1
InitializedDataSize: 1610240
InternalName:
LanguageCode: English (U.S.)
LinkerVersion: 7.1
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 5.1
ObjectFileType: Executable application
PEType: PE32
ProductVersionNumber: 5.1.2600.5512
Subsystem: Windows command line
SubsystemVersion: 4.1
Tag26005512: D
TimeStamp: 2008:04:13 20:34:10+02:00
UninitializedDataSize: 0
filesdll: j%ProductName
icrosoftCorporationAllrightsreserved: B OriginalFilename
lesdll: .LegalCopyright
rosoftWindowsOperatingSystem: @ProductVersion
VT Community
Now combofix:
ComboFix 11-06-06.07 - dx 06/10/2011 14:06:07.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.292 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-10 to 2011-06-10 )))))))))))))))))))))))))))))))
.
.
2011-06-10 00:33 . 2011-06-10 00:33 βββ dββw- c:\documents and settings\dx\Application Data\Malwarebytes
2011-06-10 00:33 . 2011-05-29 13:11 39984 β-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-10 00:33 . 2011-06-10 00:33 βββ dββw- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-10 00:33 . 2011-06-10 00:33 βββ dββw- c:\program files\Malwarebytes' Anti-Malware
2011-06-10 00:33 . 2011-05-29 13:11 22712 β-a-w- c:\windows\system32\drivers\mbam.sys
2011-06-09 00:36 . 2011-06-09 00:55 βββ dββw- c:\program files\Microsoft ActiveSync
2011-06-07 16:18 . 2011-06-10 18:01 βββ dββw- C:\32788R22FWJFW
2011-06-06 18:49 . 2011-06-06 18:49 βββ dββw- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2011-06-06 18:49 . 2011-06-06 18:49 βββ dββw- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-06-06 03:20 . 2011-06-06 03:20 388096 β-a-r- c:\documents and settings\dx\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-06-06 03:20 . 2011-06-06 03:20 βββ dββw- C:\Trend Micro
2011-06-05 04:04 . 2011-06-05 04:04 βββ dββw- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-06-04 23:24 . 2011-06-04 23:24 βββ dββw- c:\program files\Common Files\Java
2011-06-04 22:02 . 2001-08-18 02:36 5632 β-a-w- c:\windows\system32\ptpusb.dll
2011-06-04 22:02 . 2008-04-14 09:42 159232 β-a-w- c:\windows\system32\ptpusd.dll
2011-06-04 17:41 . 2011-06-04 17:41 βββ d-sβw- c:\documents and settings\NetworkService\UserData
2011-06-04 04:36 . 2011-06-04 04:36 βββ dββw- c:\documents and settings\dx\Application Data\894E5449700F3D86AF876350C9266F39
2011-06-04 04:31 . 2011-06-04 21:10 βββ dββw- c:\program files\7-Zip
2011-05-25 03:01 . 2011-05-25 03:01 βββ dββw- c:\documents and settings\dx\Application Data\Unity
2011-05-25 02:10 . 2011-05-25 02:10 βββ dββw- c:\documents and settings\dx\Local Settings\Application Data\Unity
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-12 14:44 . 2011-05-03 17:02 149456 β-a-w- c:\windows\SGDetectionTool.dll
2011-04-12 14:44 . 2011-05-03 17:02 2074576 β-a-w- c:\windows\PCTBDCore.dll
2011-04-12 14:44 . 2011-05-03 17:02 1533904 β-a-w- c:\windows\PCTBDRes.dll
2011-04-12 14:44 . 2011-05-03 17:02 767952 β-a-w- c:\windows\BDTSupport.dll
2011-04-25 16:43 . 2011-04-25 16:43 289592 β-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
.
.
ββ- Sigcheck ββ-
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-05-09 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2011-06-07_16.51.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-09-23 05:16 . 2005-09-23 05:16 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80u.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfcm80.dll
+ 2011-06-10 17:38 . 2011-06-10 17:38 16384 c:\windows\Temp\Perflib_Perfdata_430.dat
+ 2011-06-10 17:46 . 2011-06-10 17:46 16384 c:\windows\Temp\Perflib_Perfdata_15c.dat
+ 2010-12-03 00:16 . 2011-06-10 17:50 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-12-03 00:16 . 2011-06-10 17:50 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2011-06-09 01:53 . 2011-06-10 17:50 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-12-03 00:16 . 2011-06-07 14:40 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-09-23 03:48 . 2005-09-23 03:48 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 03:48 . 2005-09-23 03:48 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 1079808 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80u.dll
+ 2005-09-23 05:16 . 2005-09-23 05:16 1093632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_dec6ddd2\mfc80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor with AntiVirus"="c:\documents and settings\dx\Desktop\sdasetup(2).exe" [2011-05-03 513032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-08-15 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"ISTray"="c:\program files\Spyware Doctor\pctsGui.exe" [2011-04-12 1600984]
"PCTools FGuard"="c:\program files\Spyware Doctor\BDT\FGuard.exe" [2011-04-12 247760]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [5/3/2011 1:01 PM 263888]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [5/3/2011 1:27 PM 338880]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [5/3/2011 1:27 PM 656320]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [5/3/2011 2:13 PM 51984]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [5/3/2011 2:13 PM 69392]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [5/3/2011 1:01 PM 251560]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [5/3/2011 1:27 PM 233976]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [5/3/2011 1:02 PM 337872]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/9/2011 8:33 PM 366640]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [5/3/2011 1:26 PM 371472]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/9/2011 8:33 PM 22712]
R3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [5/3/2011 1:01 PM 70536]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [5/3/2011 2:13 PM 33552]
R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service β> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/9/2011 8:33 PM 39984]
.
β Other Services/Drivers In Memory β
.
*Deregistered* - PCTSDInjDriver32
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
.
ββ- Supplementary Scan ββ-
.
uStart Page = https://login.yahoo.com/config/login_verify2?&.src=ym
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 192.168.1.1 [removed]
FF - ProfilePath - c:\documents and settings\dx\Application Data\Mozilla\Firefox\Profiles\1t2fqt2o.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/login_verify2?.intl=us&.src=ym
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Browser Defender Toolbar: {cb84136f-9c44-433a-9048-c5cd9df1dc16} - c:\program files\Spyware Doctor\BDT\Firefox
FF - Ext: BlockSite: {dd3d7613-0246-469d-bc65-2a3cc1668adc} - %profile%\extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc}
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-10 14:23
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes β¦
.
scanning hidden autostart entries β¦
.
scanning hidden files β¦
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
βββββββ DLLs Loaded Under Running Processes βββββββ
.
- - - - - - - > 'winlogon.exe'(684)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
c:\program files\Spyware Doctor\TFEngine\TFNI.dll
.
- - - - - - - > 'lsass.exe'(740)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
.
- - - - - - - > 'explorer.exe'(6328)
c:\program files\Spyware Doctor\TFEngine\TfWah.dll
c:\program files\Spyware Doctor\TFEngine\TFNI.dll
c:\windows\system32\WSOCK32.dll
.
Completion time: 2011-06-10 14:33:00
ComboFix-quarantined-files.txt 2011-06-10 18:32
ComboFix2.txt 2011-06-09 01:53
ComboFix3.txt 2011-06-07 17:01
.
Pre-Run: 69,619,462,144 bytes free
Post-Run: 69,612,871,680 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 124056772631B8CA0505BDC7E48D0335
Malwarebytes:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6822
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
6/10/2011 2:45:14 PM
mbam-log-2011-06-10 (14-45-07).txt
Scan type: Quick scan
Objects scanned: 138984
Time elapsed: 3 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\documents and settings\dx\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (PUP.MightyMagoo) -> No action taken.
Files Infected:
(No malicious items detected)
I can see there's one file there that needs to be removed but I didn't want to remove it without your okay, so please just let me know what to do next. Thanks!
Also, the Ask toolbar is still here. Before, it wasn't showing up but now it's displayed right next to the address bar. It seems I've somehow made is worse, not better. Still, I can now use Google, click on links, and actually go where I'm supposed to, so that's a huge improvement. Thanks for bearing with me!!!