ComboFix 12-11-23.02 - Denno 11/24/2012 8:41.8.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.375 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2012-10-24 to 2012-11-24 )))))))))))))))))))))))))))))))
.
.
2012-11-24 03:25 . 2012-11-24 03:25 29904 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\MpKslb38225f8.sys
2012-11-23 14:16 . 2012-11-08 18:00 6812136 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\mpengine.dll
2012-11-22 14:14 . 2012-11-08 18:00 6812136 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-14 14:21 . 2012-11-14 14:21 โโโ dโโw- c:\documents and settings\Denno\Local Settings\Application Data\PCHealth
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-11-13 22:42 . 2012-11-13 22:43 โโโ dโโw- c:\program files\QuickTime
2012-11-13 22:42 . 2012-11-13 22:42 โโโ dโโw- c:\documents and settings\All Users\Application Data\Apple Computer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-31 19:37 . 2011-08-22 18:39 52648 โ-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-10-31 19:37 . 2011-08-22 18:39 83912 โ-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-10-31 19:37 . 2011-08-22 18:39 31144 โ-a-w- c:\windows\system32\LMIport.dll
2012-10-31 19:37 . 2011-08-22 18:38 92072 โ-a-w- c:\windows\system32\LMIinit.dll
2012-10-25 08:12 . 2012-10-25 08:12 94208 โ-a-w- c:\windows\system32\QuickTimeVR.qtx
2012-10-25 08:12 . 2012-10-25 08:12 69632 โ-a-w- c:\windows\system32\QuickTime.qts
2012-10-22 08:37 . 2004-08-04 10:00 1866368 โ-a-w- c:\windows\system32\win32k.sys
2012-10-02 18:04 . 2004-08-04 10:00 58368 โ-a-w- c:\windows\system32\synceng.dll
2012-09-29 23:54 . 2012-02-05 03:04 22856 โ-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-28 13:53 . 2012-09-28 13:53 336 โ-a-w- c:\windows\system32\register.bat
2012-08-31 02:03 . 2011-04-18 17:18 193552 โ-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2006-03-04 03:33 916992 โ-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2004-08-04 10:00 43520 โโw- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2004-08-04 10:00 1469440 โโw- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 10:00 385024 โโw- c:\windows\system32\html.iec
2012-10-26 21:35 . 2012-10-12 15:11 261600 โ-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDriveE Startup"="c:\program files\IDrive\IDrvieEStartup.exe" [2011-06-24 185800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 138008]
"pdfFactory Pro Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\2\fppdis1.exe" [2002-06-25 356352]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 16132608]
"EPSON Stylus Photo RX620 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"EPSON Stylus Photo RX620 Series (Copy 1)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-11 63048]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"CommonToolkitTray"="c:\program files\Fighters\Tray\FightersTray.exe" [2012-06-29 1454184]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2011-12-20 1197704]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"Logitech Utility"="LOGI_MWX.EXE" [2003-12-17 19968]
"Wondershare Helper Compact.exe"="c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2012-03-27 1686528]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-24 926896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Denno\Start Menu\Programs\Startup\
IDrive Tray.lnk - c:\program files\IDrive\IDriveEReg2ini.exe [2011-6-17 304584]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-6-9 113664]
Event Reminder.lnk - c:\program files\The Print Shop 23.1\Remind.exe [2010-6-21 344064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-10-31 19:37 92072 โ-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\WS_FTP Pro\\ftp95pro.exe"=
"c:\\Program Files\\FinalTorrent\\FinalTorrent.EXE"=
"c:\\Program Files\\FinalTorrent\\FTCheckForUpdates.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
R1 MpKslb38225f8;MpKslb38225f8;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\MpKslb38225f8.sys [11/23/2012 10:25 PM 29904]
R2 IDriveE Service;IDriveE Service;c:\program files\IDrive\IDriveE Service.exe [6/17/2011 11:41 PM 157128]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [7/6/2011 3:32 PM 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 6:04 PM 12856]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [12/20/2011 12:41 PM 215688]
R2 Suite Service;Suite Service;c:\program files\Fighters\FighterSuiteService.exe [8/9/2012 2:05 PM 1267816]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys โ> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
.
โ Other Services/Drivers In Memory โ
.
*NewlyCreated* - 38960777
*NewlyCreated* - MPKSLB38225F8
*Deregistered* - 38960777
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-11-24 c:\windows\Tasks\FinalTorrent Update Checker.job
- c:\program files\FinalTorrent\FTCheckForUpdates.exe [2011-11-25 20:24]
.
2012-11-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-30 14:48]
.
2012-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-30 14:48]
.
2012-11-21 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 21:25]
.
.
โโ- Supplementary Scan โโ-
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Denno\Application Data\Mozilla\Firefox\Profiles\kr5vho5v.default-1351571938447\
FF - prefs.js: browser.startup.homepage - www.google.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-11-24 08:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes โฆ
.
scanning hidden autostart entries โฆ
.
scanning hidden files โฆ
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
โโโโโโโ DLLs Loaded Under Running Processes โโโโโโโ
.
- - - - - - - > 'winlogon.exe'(700)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(3592)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-11-24 08:49:16
ComboFix-quarantined-files.txt 2012-11-24 13:49
ComboFix2.txt 2012-10-27 03:25
ComboFix3.txt 2012-10-26 21:33
ComboFix4.txt 2012-02-05 22:18
ComboFix5.txt 2012-11-24 13:38
.
Pre-Run: 273,337,069,568 bytes free
Post-Run: 273,434,615,808 bytes free
.
- - End Of File - - 8C89D9C760D6F3A84AC17A348B5F45E5
Malwarebytes said it didn't find anything malicious, and didn't offer removal
ComboFix 12-11-23.02 - Denno 11/24/2012 8:41.8.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.375 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2012-10-24 to 2012-11-24 )))))))))))))))))))))))))))))))
.
.
2012-11-24 03:25 . 2012-11-24 03:25 29904 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\MpKslb38225f8.sys
2012-11-23 14:16 . 2012-11-08 18:00 6812136 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\mpengine.dll
2012-11-22 14:14 . 2012-11-08 18:00 6812136 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-14 14:21 . 2012-11-14 14:21 โโโ dโโw- c:\documents and settings\Denno\Local Settings\Application Data\PCHealth
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-11-13 22:42 . 2012-11-13 22:43 โโโ dโโw- c:\program files\QuickTime
2012-11-13 22:42 . 2012-11-13 22:42 โโโ dโโw- c:\documents and settings\All Users\Application Data\Apple Computer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-31 19:37 . 2011-08-22 18:39 52648 โ-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-10-31 19:37 . 2011-08-22 18:39 83912 โ-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-10-31 19:37 . 2011-08-22 18:39 31144 โ-a-w- c:\windows\system32\LMIport.dll
2012-10-31 19:37 . 2011-08-22 18:38 92072 โ-a-w- c:\windows\system32\LMIinit.dll
2012-10-25 08:12 . 2012-10-25 08:12 94208 โ-a-w- c:\windows\system32\QuickTimeVR.qtx
2012-10-25 08:12 . 2012-10-25 08:12 69632 โ-a-w- c:\windows\system32\QuickTime.qts
2012-10-22 08:37 . 2004-08-04 10:00 1866368 โ-a-w- c:\windows\system32\win32k.sys
2012-10-02 18:04 . 2004-08-04 10:00 58368 โ-a-w- c:\windows\system32\synceng.dll
2012-09-29 23:54 . 2012-02-05 03:04 22856 โ-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-28 13:53 . 2012-09-28 13:53 336 โ-a-w- c:\windows\system32\register.bat
2012-08-31 02:03 . 2011-04-18 17:18 193552 โ-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2006-03-04 03:33 916992 โ-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2004-08-04 10:00 43520 โโw- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2004-08-04 10:00 1469440 โโw- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 10:00 385024 โโw- c:\windows\system32\html.iec
2012-10-26 21:35 . 2012-10-12 15:11 261600 โ-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDriveE Startup"="c:\program files\IDrive\IDrvieEStartup.exe" [2011-06-24 185800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 138008]
"pdfFactory Pro Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\2\fppdis1.exe" [2002-06-25 356352]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 16132608]
"EPSON Stylus Photo RX620 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"EPSON Stylus Photo RX620 Series (Copy 1)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-11 63048]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"CommonToolkitTray"="c:\program files\Fighters\Tray\FightersTray.exe" [2012-06-29 1454184]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2011-12-20 1197704]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"Logitech Utility"="LOGI_MWX.EXE" [2003-12-17 19968]
"Wondershare Helper Compact.exe"="c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2012-03-27 1686528]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-24 926896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Denno\Start Menu\Programs\Startup\
IDrive Tray.lnk - c:\program files\IDrive\IDriveEReg2ini.exe [2011-6-17 304584]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-6-9 113664]
Event Reminder.lnk - c:\program files\The Print Shop 23.1\Remind.exe [2010-6-21 344064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-10-31 19:37 92072 โ-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\WS_FTP Pro\\ftp95pro.exe"=
"c:\\Program Files\\FinalTorrent\\FinalTorrent.EXE"=
"c:\\Program Files\\FinalTorrent\\FTCheckForUpdates.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
R1 MpKslb38225f8;MpKslb38225f8;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\MpKslb38225f8.sys [11/23/2012 10:25 PM 29904]
R2 IDriveE Service;IDriveE Service;c:\program files\IDrive\IDriveE Service.exe [6/17/2011 11:41 PM 157128]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [7/6/2011 3:32 PM 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 6:04 PM 12856]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [12/20/2011 12:41 PM 215688]
R2 Suite Service;Suite Service;c:\program files\Fighters\FighterSuiteService.exe [8/9/2012 2:05 PM 1267816]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys โ> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
.
โ Other Services/Drivers In Memory โ
.
*NewlyCreated* - 38960777
*NewlyCreated* - MPKSLB38225F8
*Deregistered* - 38960777
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-11-24 c:\windows\Tasks\FinalTorrent Update Checker.job
- c:\program files\FinalTorrent\FTCheckForUpdates.exe [2011-11-25 20:24]
.
2012-11-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-30 14:48]
.
2012-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-30 14:48]
.
2012-11-21 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 21:25]
.
.
โโ- Supplementary Scan โโ-
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Denno\Application Data\Mozilla\Firefox\Profiles\kr5vho5v.default-1351571938447\
FF - prefs.js: browser.startup.homepage - www.google.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-11-24 08:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes โฆ
.
scanning hidden autostart entries โฆ
.
scanning hidden files โฆ
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
โโโโโโโ DLLs Loaded Under Running Processes โโโโโโโ
.
- - - - - - - > 'winlogon.exe'(700)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(3592)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-11-24 08:49:16
ComboFix-quarantined-files.txt 2012-11-24 13:49
ComboFix2.txt 2012-10-27 03:25
ComboFix3.txt 2012-10-26 21:33
ComboFix4.txt 2012-02-05 22:18
ComboFix5.txt 2012-11-24 13:38
.
Pre-Run: 273,337,069,568 bytes free
Post-Run: 273,434,615,808 bytes free
.
- - End Of File - - 8C89D9C760D6F3A84AC17A348B5F45E5
MSE was absent from the tray for some reason. (I called it up out of the main list)
During this last process Firefox wouldn't stay open, had to keep going back to it through the link in the e-mail.
I suppose I won't have a read on how the computer is behaving until I've used it a bit.
When the combofix scan was done I had a popup offering to install IE.
I think, but am not positive, that all I did to IE was restore FF as the default browser. I think something in the previous fixes made IE the default.
ComboFix 12-11-23.02 - Denno 11/24/2012 8:41.8.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.375 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2012-10-24 to 2012-11-24 )))))))))))))))))))))))))))))))
.
.
2012-11-24 03:25 . 2012-11-24 03:25 29904 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\MpKslb38225f8.sys
2012-11-23 14:16 . 2012-11-08 18:00 6812136 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\mpengine.dll
2012-11-22 14:14 . 2012-11-08 18:00 6812136 โ-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-14 14:21 . 2012-11-14 14:21 โโโ dโโw- c:\documents and settings\Denno\Local Settings\Application Data\PCHealth
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-11-13 22:43 . 2012-11-13 22:43 159744 โ-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-11-13 22:42 . 2012-11-13 22:43 โโโ dโโw- c:\program files\QuickTime
2012-11-13 22:42 . 2012-11-13 22:42 โโโ dโโw- c:\documents and settings\All Users\Application Data\Apple Computer
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-31 19:37 . 2011-08-22 18:39 52648 โ-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-10-31 19:37 . 2011-08-22 18:39 83912 โ-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-10-31 19:37 . 2011-08-22 18:39 31144 โ-a-w- c:\windows\system32\LMIport.dll
2012-10-31 19:37 . 2011-08-22 18:38 92072 โ-a-w- c:\windows\system32\LMIinit.dll
2012-10-25 08:12 . 2012-10-25 08:12 94208 โ-a-w- c:\windows\system32\QuickTimeVR.qtx
2012-10-25 08:12 . 2012-10-25 08:12 69632 โ-a-w- c:\windows\system32\QuickTime.qts
2012-10-22 08:37 . 2004-08-04 10:00 1866368 โ-a-w- c:\windows\system32\win32k.sys
2012-10-02 18:04 . 2004-08-04 10:00 58368 โ-a-w- c:\windows\system32\synceng.dll
2012-09-29 23:54 . 2012-02-05 03:04 22856 โ-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-28 13:53 . 2012-09-28 13:53 336 โ-a-w- c:\windows\system32\register.bat
2012-08-31 02:03 . 2011-04-18 17:18 193552 โ-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2006-03-04 03:33 916992 โ-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2004-08-04 10:00 43520 โโw- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2004-08-04 10:00 1469440 โโw- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2004-08-04 10:00 385024 โโw- c:\windows\system32\html.iec
2012-10-26 21:35 . 2012-10-12 15:11 261600 โ-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDriveE Startup"="c:\program files\IDrive\IDrvieEStartup.exe" [2011-06-24 185800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 138008]
"pdfFactory Pro Dispatcher v1"="c:\windows\System32\spool\DRIVERS\W32X86\2\fppdis1.exe" [2002-06-25 356352]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 16132608]
"EPSON Stylus Photo RX620 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"EPSON Stylus Photo RX620 Series (Copy 1)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE" [2004-05-20 98304]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-11 63048]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"CommonToolkitTray"="c:\program files\Fighters\Tray\FightersTray.exe" [2012-06-29 1454184]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2011-12-20 1197704]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-12 59280]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"Logitech Utility"="LOGI_MWX.EXE" [2003-12-17 19968]
"Wondershare Helper Compact.exe"="c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2012-03-27 1686528]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-24 926896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Denno\Start Menu\Programs\Startup\
IDrive Tray.lnk - c:\program files\IDrive\IDriveEReg2ini.exe [2011-6-17 304584]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-6-9 113664]
Event Reminder.lnk - c:\program files\The Print Shop 23.1\Remind.exe [2010-6-21 344064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-10-31 19:37 92072 โ-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\WS_FTP Pro\\ftp95pro.exe"=
"c:\\Program Files\\FinalTorrent\\FinalTorrent.EXE"=
"c:\\Program Files\\FinalTorrent\\FTCheckForUpdates.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
R1 MpKslb38225f8;MpKslb38225f8;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7D4BB32A-54EA-4A8E-ABA9-5E632ABB4ECF}\MpKslb38225f8.sys [11/23/2012 10:25 PM 29904]
R2 IDriveE Service;IDriveE Service;c:\program files\IDrive\IDriveE Service.exe [6/17/2011 11:41 PM 157128]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [7/6/2011 3:32 PM 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 6:04 PM 12856]
R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe [12/20/2011 12:41 PM 215688]
R2 Suite Service;Suite Service;c:\program files\Fighters\FighterSuiteService.exe [8/9/2012 2:05 PM 1267816]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys โ> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
.
โ Other Services/Drivers In Memory โ
.
*NewlyCreated* - 38960777
*NewlyCreated* - MPKSLB38225F8
*Deregistered* - 38960777
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-11-24 c:\windows\Tasks\FinalTorrent Update Checker.job
- c:\program files\FinalTorrent\FTCheckForUpdates.exe [2011-11-25 20:24]
.
2012-11-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-30 14:48]
.
2012-11-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-30 14:48]
.
2012-11-21 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 21:25]
.
.
โโ- Supplementary Scan โโ-
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Denno\Application Data\Mozilla\Firefox\Profiles\kr5vho5v.default-1351571938447\
FF - prefs.js: browser.startup.homepage - www.google.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-11-24 08:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes โฆ
.
scanning hidden autostart entries โฆ
.
scanning hidden files โฆ
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
โโโโโโโ DLLs Loaded Under Running Processes โโโโโโโ
.
- - - - - - - > 'winlogon.exe'(700)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(3592)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-11-24 08:49:16
ComboFix-quarantined-files.txt 2012-11-24 13:49
ComboFix2.txt 2012-10-27 03:25
ComboFix3.txt 2012-10-26 21:33
ComboFix4.txt 2012-02-05 22:18
ComboFix5.txt 2012-11-24 13:38
.
Pre-Run: 273,337,069,568 bytes free
Post-Run: 273,434,615,808 bytes free
.
- - End Of File - - 8C89D9C760D6F3A84AC17A348B5F45E5
Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.24.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Denno :: SHERIFFJOHN [administrator]
11/24/2012 8:59:40 AM
mbam-log-2012-11-24 (08-59-40).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 211411
Time elapsed: 2 minute(s), 56 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)