ComboFix 12-09-04.02 - Compaq_Owner 09/04/2012 14:54:54.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.396 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Owner\Desktop\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_71777363
——-\Service_71777363
.
.
((((((((((((((((((((((((( Files Created from 2012-08-04 to 2012-09-04 )))))))))))))))))))))))))))))))
.
.
2012-09-03 20:49 . 2012-09-03 20:49 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\ImgBurn
2012-09-03 20:46 . 2012-09-03 20:46 ——– d—–w- c:\program files\ImgBurn
2012-09-02 20:14 . 2012-09-02 20:14 ——– d—–w- C:\_OTL
2012-09-01 22:52 . 2012-09-01 22:52 73696 —-a-w- c:\program files\Mozilla Firefox\breakpadinjector.dll
2012-08-31 18:09 . 2012-08-31 18:09 ——– d—–w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Sun
2012-08-31 14:55 . 2012-08-31 14:55 ——– d—–w- c:\program files\ESET
2012-08-31 14:13 . 2012-08-31 14:13 ——– d—–w- c:\program files\Common Files\Java
2012-08-31 14:13 . 2012-08-31 14:12 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-08-31 14:13 . 2012-08-31 14:12 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-08-31 14:11 . 2012-08-31 14:11 ——– d—–w- c:\program files\Java
2012-08-31 14:06 . 2012-08-31 14:06 ——– d—–w- C:\Sun
2012-08-29 22:41 . 2012-08-29 22:41 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2012-08-29 21:20 . 2012-08-29 21:20 ——– d—–w- c:\documents and settings\Compaq_Owner\Application Data\McAfee
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-29 18:58 . 2012-08-29 18:58 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-08-29 18:58 . 2012-07-03 18:46 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 00:29 . 2012-08-29 17:35 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-08-28 00:29 . 2012-08-28 00:29 ——– d—–w- c:\program files\AVAST Software
2012-08-27 15:23 . 2012-08-27 15:23 ——– d—–w- c:\documents and settings\Compaq_Owner\DoctorWeb
2012-08-21 21:30 . 2012-08-30 19:45 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-31 14:12 . 2004-08-09 09:05 93672 -c–a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-31 14:12 . 2010-09-20 14:19 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-17 20:43 . 2012-07-15 12:33 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-17 20:43 . 2012-02-15 21:16 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2004-08-09 05:41 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 15:07 . 2004-08-09 04:28 832512 —-a-w- c:\windows\system32\wininet.dll
2012-07-03 15:07 . 2004-08-09 04:28 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2012-07-03 15:07 . 2004-08-09 04:28 78336 —-a-w- c:\windows\system32\ieencode.dll
2012-07-03 15:07 . 2004-08-09 04:28 17408 ——w- c:\windows\system32\corpol.dll
2012-07-03 13:40 . 2004-08-09 04:28 1866112 —-a-w- c:\windows\system32\win32k.sys
2005-02-16 17:06 . 2006-11-25 03:30 218112 -c–a-w- c:\program files\HijackThis.exe
2012-09-01 22:52 . 2012-03-24 01:43 266720 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 19:01 . 2011-02-28 22:21 24376 —-a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-30_19.46.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-09-04 20:06 . 2012-09-04 20:06 16384 c:\windows\temp\Perflib_Perfdata_3b4.dat
+ 2012-09-03 00:10 . 2012-09-04 20:04 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-08-09 05:47 . 2012-09-04 20:04 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-08-09 05:47 . 2012-08-30 15:54 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2012-09-04 20:00 . 2012-09-04 20:04 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2005-05-26 10:19 . 2012-06-04 22:35 222448 c:\windows\system32\muweb.dll
+ 2012-08-31 14:13 . 2012-08-31 14:12 246760 c:\windows\system32\javaws.exe
+ 2012-08-31 14:13 . 2012-08-31 14:12 174056 c:\windows\system32\javaw.exe
+ 2012-08-31 14:12 . 2012-08-31 14:12 174056 c:\windows\system32\java.exe
+ 2012-08-31 14:13 . 2012-08-31 14:13 176128 c:\windows\Installer\76567.msi
+ 2012-08-31 14:12 . 2012-08-31 14:12 873984 c:\windows\Installer\76562.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-01 39408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
"2wSysTray"="c:\program files\2Wire\2PortalMon.exe" [2004-09-15 393216]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-22 1318816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"VTTimer"="VTTimer.exe" [2004-01-16 49152]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-12-18 278528]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
c:\documents and settings\Compaq_Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [N/A]
AT&T Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2007-6-17 217088]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-28 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-28 53248]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
2003-07-14 19:30 98304 -c–a-w- c:\program files\SBC Yahoo!\Connection Manager\IP Insight\ipmon32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-03-01 03:05 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/20/2009 7:31 PM 64288]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2/28/2011 5:21 PM 89792]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/29/2012 1:58 PM 655944]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [1/22/2009 12:51 PM 95200]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2/28/2011 5:21 PM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [2/28/2011 5:21 PM 161632]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2/28/2011 5:21 PM 151880]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2/28/2011 5:21 PM 57600]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/29/2012 1:58 PM 22344]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2/28/2011 5:21 PM 340920]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S2 0015421346290574mcinstcleanup;McAfee Application Installer Cleanup (0015421346290574);c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\001542~1.EXE -cleanup -nolog [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [7/15/2012 7:33 AM 250056]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:31 AM 135664]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2/28/2011 5:21 PM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2/28/2011 5:21 PM 87656]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/8/2012 11:38 AM 114144]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-15 20:43]
.
2012-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
2012-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 15:31]
.
.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\mrook2ld.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://att.my.yahoo.com/
FF - user.js: yahoo.homepage.dontask - true);user_pref(yahoo.ytff.general.dontshowhpoffer, true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-09-04 15:09
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2508)
c:\windows\system32\WININET.dll
c:\progra~1\SBCSEL~1\SMARTB~1\SBHook.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\VTTimer.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\SBC Self Support Tool\bin\mpbtn.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
.
**************************************************************************
.
Completion time: 2012-09-04 15:18:48 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-04 20:18
ComboFix2.txt 2012-09-04 19:24
ComboFix3.txt 2012-08-30 21:50
ComboFix4.txt 2012-08-30 19:48
.
Pre-Run: 96,008,273,920 bytes free
Post-Run: 95,918,452,736 bytes free
.
- - End Of File - - 0D3FBA44B7CF087215695CF0DD384DB8