ComboFix 12-11-04.01 - Owner 11/04/2012 13:32:41.9.4 - x86
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
FILE ::
"c:\documents and settings\Owner\My Documents\Downloads\iLividSetupV1 (1).exe"
"c:\documents and settings\Owner\My Documents\Downloads\iLividSetupV1 (2).exe"
"c:\documents and settings\Owner\My Documents\Downloads\iLividSetupV1.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Owner\My Documents\Downloads\iLividSetupV1 (1).exe
c:\documents and settings\Owner\My Documents\Downloads\iLividSetupV1 (2).exe
c:\documents and settings\Owner\My Documents\Downloads\iLividSetupV1.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-10-04 to 2012-11-04 )))))))))))))))))))))))))))))))
.
.
2012-11-04 17:01 . 2012-11-04 17:01 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2012-11-03 14:15 . 2012-11-03 14:15 ——– d—–w- c:\program files\ESET
2012-11-03 13:16 . 2012-11-03 13:16 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Sun
2012-11-03 13:14 . 2012-11-03 13:14 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2012-11-03 13:14 . 2012-11-04 17:01 ——– d—–w- c:\program files\McAfee Security Scan
2012-11-03 13:14 . 2012-11-03 13:14 ——– d—–w- c:\program files\Common Files\Java
2012-11-03 13:13 . 2012-11-03 13:13 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-11-03 13:13 . 2012-11-03 13:13 821736 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-11-03 13:13 . 2012-11-03 13:13 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-11-03 13:13 . 2012-11-03 13:13 ——– d—–w- c:\program files\Java
2012-11-03 13:13 . 2012-11-03 13:13 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2012-11-02 15:32 . 2012-11-02 15:32 ——– d—–w- c:\program files\ERUNT
2012-10-21 14:19 . 2012-10-27 14:08 ——– d—–w- c:\windows\SxsCaPendDel
2012-10-17 17:20 . 2012-10-17 17:20 ——– d—–w- c:\program files\Enigma Software Group
2012-10-17 17:19 . 2012-10-17 17:19 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2012-10-14 19:35 . 2012-10-14 19:35 ——– d—–w- c:\documents and settings\Owner\.frostwire5
2012-10-14 19:35 . 2012-10-14 19:35 ——– d—–w- c:\documents and settings\Owner\Application Data\DVDVideoSoftIEHelpers
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-03 13:13 . 2010-05-06 21:37 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-09-29 23:54 . 2012-03-10 14:16 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-08-28 15:14 . 2008-07-12 19:10 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2008-04-23 00:16 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2008-04-23 00:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2008-07-12 19:09 385024 ——w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2008-04-14 08:00 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:33 . 2008-04-14 08:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2008-04-14 04:01 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
1997-07-22 00:30 1045776 –sha-w- c:\windows\system32\Msjet35.dll
1997-06-23 08:00 123664 –sha-w- c:\windows\system32\Msjint35.dll
1997-06-23 17:06 24848 –sha-w- c:\windows\system32\Msjter35.dll
1997-06-23 17:06 252176 –sha-w- c:\windows\system32\Msrd2x35.dll
1997-06-23 17:06 287504 –sha-w- c:\windows\system32\Msxbse35.dll
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[7] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-01-22 2363392]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 313472]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2011-08-22 6276408]
"DownloadManager"="c:\program files\Download Manager\DownloadManager.exe" [2012-02-29 654336]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-03-10 39408]
"ManyCam"="c:\program files\ManyCam\Bin\ManyCam.exe" [2012-03-22 2103160]
"Spotify Web Helper"="c:\program files\Spotify\Data\SpotifyWebHelper.exe" [2012-10-28 1199576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2010-10-19 1439496]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"nwiz"="nwiz.exe" [BU]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-11-21 110184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-21 12669544]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"QuickBooksDB20"="c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe" [2009-08-18 678912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
.
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.1.121\SSScheduler.exe [2010-9-3 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 18 (0x12)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
"1947:TCP"= 1947:TCP:HASP SRM
"1947:UDP"= 1947:UDP:HASP SRM
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [3/10/2012 8:57 AM 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/10/2012 8:57 AM 337880]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/10/2012 8:57 AM 20696]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run –> c:\windows\system32\hasplms.exe -run [?]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [11/3/2012 8:18 AM 399432]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3/10/2012 9:16 AM 676936]
R2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe [1/27/2011 4:13 PM 226624]
R3 ManyCam;ManyCam Virtual Webcam;c:\windows\system32\drivers\mcvidrv.sys [12/20/2011 11:32 PM 32000]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [3/10/2012 9:16 AM 22856]
R3 mcaudrv_simple;ManyCam Virtual Microphone;c:\windows\system32\drivers\mcaudrv.sys [2/28/2012 12:26 AM 22400]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [9/15/2009 2:59 PM 38248]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [2/9/2010 5:59 PM 47360]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [10/19/2009 2:29 AM 9472]
S2 QuickBooksDB17;QuickBooksDB17;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 –> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 [?]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [10/2/2011 9:24 AM 6016]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys –> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.1.121\McCHSvc.exe [9/3/2010 1:45 AM 227232]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [10/2/2011 9:24 AM 20352]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [10/2/2011 9:24 AM 8320]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [10/2/2011 9:24 AM 23424]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [10/2/2011 9:24 AM 9472]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]
S4 QuickBooksDB20;QuickBooksDB20;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 –> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [?]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-01-22 16:06 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-19 20:42]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-19 20:42]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-10-07 20:27]
.
2012-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-2147235713-725345543-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-10-07 20:27]
.
2012-11-04 c:\windows\Tasks\MotoHelper Initial Update.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-10-26 c:\windows\Tasks\MotoHelper MUM.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-11-04 c:\windows\Tasks\MotoHelper Routing.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-10-26 c:\windows\Tasks\MotoHelper Update.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-11-04 c:\windows\Tasks\User_Feed_Synchronization-{D34A4223-3F9E-489B-8675-157936D04B47}.job
- c:\windows\system32\msfeedssync.exe [2008-07-12 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyOverride = ;192.168.*.*
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube to MP3 Converter - c:\documents and settings\Owner\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: DhcpNameServer = 75.75.76.76 75.75.75.75 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-11-04 13:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(872)
c:\windows\system32\nvLsp.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2012-11-04 13:46:49
ComboFix-quarantined-files.txt 2012-11-04 18:46
ComboFix2.txt 2012-10-28 17:31
ComboFix3.txt 2012-03-09 18:42
ComboFix4.txt 2012-03-08 21:56
ComboFix5.txt 2012-11-04 18:17
.
Pre-Run: 115,209,158,656 bytes free
Post-Run: 115,227,561,984 bytes free
.
- - End Of File - - E3F4573255F4A7E18E6E19B2C4B9F6A9