ComboFix 11-12-10.01 - Kids 12/11/2011 11:27:29.7.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.383.100 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\CSC\d6
.
.
((((((((((((((((((((((((( Files Created from 2011-11-11 to 2011-12-11 )))))))))))))))))))))))))))))))
.
.
2011-12-11 09:13 . 2011-12-11 09:13 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F3B1786D-3B17-4256-A7DF-E25A83FA33C2}\MpKsl42b207c3.sys
2011-12-11 09:11 . 2011-12-11 09:11 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F3B1786D-3B17-4256-A7DF-E25A83FA33C2}\offreg.dll
2011-12-11 09:11 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F3B1786D-3B17-4256-A7DF-E25A83FA33C2}\mpengine.dll
2011-11-21 01:36 . 2001-08-18 05:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2011-11-21 01:35 . 2008-04-14 12:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2011-11-21 01:35 . 2008-04-14 07:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2011-11-21 01:35 . 2008-04-14 07:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2011-11-19 00:57 . 2011-11-19 00:57 ——– d—–w- c:\program files\KingsIsle Entertainment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-10-16 17:48 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-10 14:22 . 2007-01-29 23:46 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 17:41 . 2007-10-09 19:03 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 17:41 . 2004-08-04 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 17:41 . 2004-08-04 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-09 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...10.0.1411" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Kids^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Kids\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-07-16 13:41 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5900:TCP"= 5900:TCP:vnc
"6129:TCP"= 6129:TCP:DameWare Mini Remote Control Service
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/6/2011 6:55 PM 64512]
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32\drivers\dwvkbd.sys [2/15/2007 2:00 AM 26624]
R1 MpKsl42b207c3;MpKsl42b207c3;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F3B1786D-3B17-4256-A7DF-E25A83FA33C2}\MpKsl42b207c3.sys [12/11/2011 2:13 AM 29904]
R1 MpKsl5cbd9de2;MpKsl5cbd9de2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BA727060-F3D6-4408-B308-80B4601F233B}\MpKsl5cbd9de2.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BA727060-F3D6-4408-B308-80B4601F233B}\MpKsl5cbd9de2.sys [?]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [10/15/2006 11:58 PM 547744]
R3 DwMirror;DwMirror;c:\windows\system32\drivers\DamewareMini.sys [2/7/2007 2:00 AM 3712]
S0 igxsf;igxsf; [x]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASDIFSV.SYS –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASKUTIL.SYS –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASKUTIL.SYS [?]
S2 gupdate1c9a06f5f609930;Google Update Service (gupdate1c9a06f5f609930);c:\program files\Google\Update\GoogleUpdate.exe [3/8/2009 9:27 PM 133104]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/8/2009 9:27 PM 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [5/25/2011 1:00 AM 2152152]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [5/25/2011 1:00 AM 15232]
S3 SASENUM;SASENUM;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASENUM.SYS –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\SuperAntiSpyware\SASENUM.SYS [?]
S4 MpKslfb0aaf25;MpKslfb0aaf25;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{68811444-8D2A-4D78-8082-3870B54A890B}\MpKslfb0aaf25.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{68811444-8D2A-4D78-8082-3870B54A890B}\MpKslfb0aaf25.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL052BC664
*NewlyCreated* - MPKSL07E03F84
*NewlyCreated* - MPKSL0C00A0F0
*NewlyCreated* - MPKSL159E3B35
*NewlyCreated* - MPKSL42B207C3
*NewlyCreated* - MPKSL60600C51
*NewlyCreated* - MPKSL6FB4A4AB
*NewlyCreated* - MPKSL7412F867
*NewlyCreated* - MPKSL8D3B9F0A
*NewlyCreated* - MPKSL8D6A0CFF
*NewlyCreated* - MPKSL9E077354
*NewlyCreated* - MPKSLD06F914B
*NewlyCreated* - MPKSLE6EDF879
*NewlyCreated* - MPKSLF9E59367
*NewlyCreated* - MPKSLFB0AAF25
*Deregistered* - MpKsl052bc664
*Deregistered* - MpKsl07e03f84
*Deregistered* - MpKsl0c00a0f0
*Deregistered* - MpKsl159e3b35
*Deregistered* - MpKsl60600c51
*Deregistered* - MpKsl6fb4a4ab
*Deregistered* - MpKsl7412f867
*Deregistered* - MpKsl8d3b9f0a
*Deregistered* - MpKsl8d6a0cff
*Deregistered* - MpKsl9e077354
*Deregistered* - MpKsld06f914b
*Deregistered* - MpKsle6edf879
*Deregistered* - MpKslf9e59367
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-05-25 07:40]
.
2011-12-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
2011-12-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-09 22:41]
.
2011-12-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-09 04:27]
.
2011-12-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-09 04:27]
.
2011-12-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 21:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.0.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-DameWare MRC Agent - c:\windows\system32\DWRCST.exe
Notify-68d0fca0579 - (no file)
MSConfigStartUp-CTFMON - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-11 11:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
- - - - - - - > 'explorer.exe'(4884)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-11 11:53:36
ComboFix-quarantined-files.txt 2011-12-11 18:53
.
Pre-Run: 3,264,917,504 bytes free
Post-Run: 3,919,728,640 bytes free
.
- - End Of File - - 6A45EAF794FE4A3A1F969636AE2402FB