fakestree1
New CF log:
ComboFix 09-01-11.04 - Owner 2009-01-13 10:00:17.8 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.286 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\DU99.exe
C:\LQXMy.bat
C:\x64.bat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DU99.exe
C:\LQXMy.bat
C:\x64.bat
.
((((((((((((((((((((((((( Files Created from 2008-12-13 to 2009-01-13 )))))))))))))))))))))))))))))))
.
2009-01-12 10:39 . 2009-01-12 10:39 d——– C:\2f29a9a78662c795ea1d3df5e9c77992
2009-01-12 10:16 . 2008-10-24 06:21 455,296 ——— c:\windows\SYSTEM32\dllcache\mrxsmb.sys
2009-01-12 10:15 . 2008-09-04 12:15 1,106,944 ——— c:\windows\SYSTEM32\dllcache\msxml3.dll
2009-01-10 10:26 . 2009-01-10 10:26 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-10 10:26 . 2009-01-10 10:26 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2009-01-10 10:26 . 2009-01-10 10:26 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-10 10:26 . 2009-01-04 18:38 38,496 –a—— c:\windows\SYSTEM32\drivers\mbamswissarmy.sys
2009-01-10 10:26 . 2009-01-04 18:38 15,504 –a—— c:\windows\SYSTEM32\drivers\mbam.sys
2009-01-03 16:29 . 2009-01-03 16:29 d——– c:\documents and settings\Owner\Application Data\SoftwareDetectionScripts
2009-01-03 16:28 . 2009-01-13 09:52 d——– c:\documents and settings\All Users\Application Data\temp
2009-01-03 16:11 . 2009-01-03 16:11 d——– c:\program files\Verizon
2009-01-03 16:10 . 2009-01-03 16:10 d——– c:\program files\SpywareBlaster
2009-01-03 16:10 . 2009-01-03 16:10 d——– c:\program files\Soulseek
2009-01-03 16:10 . 2009-01-03 16:10 d——– c:\program files\hp center
2009-01-03 16:10 . 2009-01-03 16:10 d——– c:\program files\BackWeb
2009-01-03 16:09 . 2009-01-03 16:10 d——– c:\program files\CCleaner
2008-12-27 22:47 . 2009-01-03 16:10 d——– c:\program files\SoulseekNS(2)
2008-12-15 18:31 . 2009-01-03 16:12 d——– C:\9c67ec03b1f4dc47f9b634114e
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 23:37 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-01-03 21:11 ——— d—–w c:\program files\Common Files\Motive
2009-01-03 21:10 ——— d—–w c:\documents and settings\Owner\Application Data\Lavasoft
2009-01-03 21:10 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-25 15:49 ——— d—–w c:\program files\Lavasoft
2008-12-13 06:40 3,593,216 —-a-w c:\windows\SYSTEM32\dllcache\mshtml.dll
2008-10-23 12:36 286,720 —-a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720 ——w c:\windows\SYSTEM32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\SYSTEM32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\SYSTEM32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\SYSTEM32\muweb.dll
2008-10-16 13:11 70,656 ——w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\SYSTEM32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ——w c:\windows\SYSTEM32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\SYSTEM32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 —-a-w c:\windows\SYSTEM32\dllcache\ieakui.dll
2001-07-22 02:45 94,784 –sh–w c:\windows\twain.dll
2008-04-14 00:12 50,688 –sh–w c:\windows\twain_32.dll
2008-04-14 00:11 1,028,096 –sh–w c:\windows\SYSTEM32\mfc42.dll
2008-04-14 00:12 57,344 –sha-w c:\windows\SYSTEM32\msvcirt.dll
2008-04-14 00:12 413,696 –sha-w c:\windows\SYSTEM32\msvcp60.dll
2008-04-14 00:12 343,040 –sha-w c:\windows\SYSTEM32\msvcrt.dll
2008-04-14 00:12 551,936 –sha-w c:\windows\SYSTEM32\oleaut32.dll
2008-04-14 00:12 84,992 –sh–w c:\windows\SYSTEM32\olepro32.dll
2008-04-14 00:12 11,776 –sh–w c:\windows\SYSTEM32\regsvr32.exe
2008-05-07 14:58 32,768 –sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050720080508\index.dat
2008-05-09 15:03 32,768 –sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050920080510\index.dat
.
((((((((((((((((((((((((((((( snapshot_2009-01-12_11.13.16.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 13:00:00 28,672 —-a-w c:\windows\NIRCMD.exe
+ 2000-08-31 13:00:00 29,696 —-a-w c:\windows\NIRCMD.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [2000-08-15 28739]
"MoneyAgent"="c:\program files\Microsoft Money\System\Money Express.exe" [2000-07-19 176183]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2004-12-20 405504]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-09-30 4603904]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
"PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-08-17 196608]
"checktime"="c:\program files\HPSelect\Frontend\ct.exe" [2001-08-13 45056]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-09-30 86016]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-09-28 936960]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"nwiz"="nwiz.exe" [2004-09-30 c:\windows\SYSTEM32\nwiz.exe]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
AutoPlay.exe [2001-08-27 36864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hp center UI.lnk - c:\program files\hp center\137903\Shadow\ShadowBar.exe [2001-09-05 69632]
hp center.lnk - c:\program files\hp center\137903\Program\BackWeb-137903.exe [2001-09-05 16384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"VIDC.DVSD"= miroDV2avi.DLL
"VIDC.PIM1"= pclepim1.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1133562415\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1133562415\\ee\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
R4 PackethSvc;Virtual NIC Service;c:\windows\SYSTEM32\PackethSvc.exe [2002-01-27 64512]
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\9eb6e1oa.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 10:05:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-13 10:11:12
ComboFix-quarantined-files.txt 2009-01-13 15:10:10
ComboFix2.txt 2009-01-12 16:18:05
ComboFix3.txt 2009-01-12 03:17:15
Pre-Run: 18,129,154,048 bytes free
Post-Run: 18,110,689,280 bytes free
165
New Hijack This log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19, on 2009-01-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\bwgo0000ae31.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1126228680968
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
–
End of file - 5625 bytes
Other than the monitor freezing up sometimes (which just might have to do with this being an old computer), the computer's been behaving well. Though I should point out the screen hasn't frozen since I performed this new ComboFix.
ComboFix 09-01-11.04 - Owner 2009-01-13 10:00:17.8 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.286 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\DU99.exe
C:\LQXMy.bat
C:\x64.bat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DU99.exe
C:\LQXMy.bat
C:\x64.bat
.
((((((((((((((((((((((((( Files Created from 2008-12-13 to 2009-01-13 )))))))))))))))))))))))))))))))
.
2009-01-12 10:39 . 2009-01-12 10:39 d——– C:\2f29a9a78662c795ea1d3df5e9c77992
2009-01-12 10:16 . 2008-10-24 06:21 455,296 ——— c:\windows\SYSTEM32\dllcache\mrxsmb.sys
2009-01-12 10:15 . 2008-09-04 12:15 1,106,944 ——— c:\windows\SYSTEM32\dllcache\msxml3.dll
2009-01-10 10:26 . 2009-01-10 10:26 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-10 10:26 . 2009-01-10 10:26 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2009-01-10 10:26 . 2009-01-10 10:26 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-10 10:26 . 2009-01-04 18:38 38,496 –a—— c:\windows\SYSTEM32\drivers\mbamswissarmy.sys
2009-01-10 10:26 . 2009-01-04 18:38 15,504 –a—— c:\windows\SYSTEM32\drivers\mbam.sys
2009-01-03 16:29 . 2009-01-03 16:29 d——– c:\documents and settings\Owner\Application Data\SoftwareDetectionScripts
2009-01-03 16:28 . 2009-01-13 09:52 d——– c:\documents and settings\All Users\Application Data\temp
2009-01-03 16:11 . 2009-01-03 16:11 d——– c:\program files\Verizon
2009-01-03 16:10 . 2009-01-03 16:10 d——– c:\program files\SpywareBlaster
2009-01-03 16:10 . 2009-01-03 16:10 d——– c:\program files\Soulseek
2009-01-03 16:10 . 2009-01-03 16:10 d——– c:\program files\hp center
2009-01-03 16:10 . 2009-01-03 16:10 d——– c:\program files\BackWeb
2009-01-03 16:09 . 2009-01-03 16:10 d——– c:\program files\CCleaner
2008-12-27 22:47 . 2009-01-03 16:10 d——– c:\program files\SoulseekNS(2)
2008-12-15 18:31 . 2009-01-03 16:12 d——– C:\9c67ec03b1f4dc47f9b634114e
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 23:37 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-01-03 21:11 ——— d—–w c:\program files\Common Files\Motive
2009-01-03 21:10 ——— d—–w c:\documents and settings\Owner\Application Data\Lavasoft
2009-01-03 21:10 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-25 15:49 ——— d—–w c:\program files\Lavasoft
2008-12-13 06:40 3,593,216 —-a-w c:\windows\SYSTEM32\dllcache\mshtml.dll
2008-10-23 12:36 286,720 —-a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720 ——w c:\windows\SYSTEM32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\SYSTEM32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\SYSTEM32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\SYSTEM32\muweb.dll
2008-10-16 13:11 70,656 ——w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\SYSTEM32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ——w c:\windows\SYSTEM32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\SYSTEM32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 —-a-w c:\windows\SYSTEM32\dllcache\ieakui.dll
2001-07-22 02:45 94,784 –sh–w c:\windows\twain.dll
2008-04-14 00:12 50,688 –sh–w c:\windows\twain_32.dll
2008-04-14 00:11 1,028,096 –sh–w c:\windows\SYSTEM32\mfc42.dll
2008-04-14 00:12 57,344 –sha-w c:\windows\SYSTEM32\msvcirt.dll
2008-04-14 00:12 413,696 –sha-w c:\windows\SYSTEM32\msvcp60.dll
2008-04-14 00:12 343,040 –sha-w c:\windows\SYSTEM32\msvcrt.dll
2008-04-14 00:12 551,936 –sha-w c:\windows\SYSTEM32\oleaut32.dll
2008-04-14 00:12 84,992 –sh–w c:\windows\SYSTEM32\olepro32.dll
2008-04-14 00:12 11,776 –sh–w c:\windows\SYSTEM32\regsvr32.exe
2008-05-07 14:58 32,768 –sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050720080508\index.dat
2008-05-09 15:03 32,768 –sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050920080510\index.dat
.
((((((((((((((((((((((((((((( snapshot_2009-01-12_11.13.16.89 )))))))))))))))))))))))))))))))))))))))))
.
- 2000-08-31 13:00:00 28,672 —-a-w c:\windows\NIRCMD.exe
+ 2000-08-31 13:00:00 29,696 —-a-w c:\windows\NIRCMD.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [2000-08-15 28739]
"MoneyAgent"="c:\program files\Microsoft Money\System\Money Express.exe" [2000-07-19 176183]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2004-12-20 405504]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-09-30 4603904]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
"PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-08-17 196608]
"checktime"="c:\program files\HPSelect\Frontend\ct.exe" [2001-08-13 45056]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-09-30 86016]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-09-28 936960]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"nwiz"="nwiz.exe" [2004-09-30 c:\windows\SYSTEM32\nwiz.exe]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
AutoPlay.exe [2001-08-27 36864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hp center UI.lnk - c:\program files\hp center\137903\Shadow\ShadowBar.exe [2001-09-05 69632]
hp center.lnk - c:\program files\hp center\137903\Program\BackWeb-137903.exe [2001-09-05 16384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"VIDC.DVSD"= miroDV2avi.DLL
"VIDC.PIM1"= pclepim1.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1133562415\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1133562415\\ee\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
R4 PackethSvc;Virtual NIC Service;c:\windows\SYSTEM32\PackethSvc.exe [2002-01-27 64512]
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\9eb6e1oa.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 10:05:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-13 10:11:12
ComboFix-quarantined-files.txt 2009-01-13 15:10:10
ComboFix2.txt 2009-01-12 16:18:05
ComboFix3.txt 2009-01-12 03:17:15
Pre-Run: 18,129,154,048 bytes free
Post-Run: 18,110,689,280 bytes free
165
New Hijack This log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19, on 2009-01-13
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\bwgo0000ae31.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1126228680968
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
–
End of file - 5625 bytes
Other than the monitor freezing up sometimes (which just might have to do with this being an old computer), the computer's been behaving well. Though I should point out the screen hasn't frozen since I performed this new ComboFix.