ComboFix 09-02-21.01 - Kishkoway 2009-02-23 0:28:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.635 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\feba1_g.dll
.
((((((((((((((((((((((((( Files Created from 2009-01-23 to 2009-02-23 )))))))))))))))))))))))))))))))
.
2009-02-22 22:12 . 2009-02-22 22:12 d——– c:\windows\LastGood
2009-02-17 16:01 . 2009-02-17 16:01 d——– C:\_OTMoveIt
2009-02-16 14:30 . 2009-02-16 14:30 250 –a—— c:\windows\gmer.ini
2009-02-16 02:27 . 2009-02-16 02:27 d——– c:\documents and settings\Jennifer\Application Data\SUPERAntiSpyware.com
2009-02-09 07:30 . 2009-02-19 15:25 54,156 –ah—– c:\windows\QTFont.qfn
2009-02-09 07:30 . 2009-02-09 07:30 1,409 –a—— c:\windows\QTFont.for
2009-02-07 16:06 . 2009-01-15 08:19 206,793 –a—— c:\windows\system32\nvapps.nvb
2009-02-03 18:41 . 2008-10-16 15:38 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2009-02-03 18:41 . 2007-04-17 04:32 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2009-02-03 18:41 . 2007-03-08 00:10 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2009-02-03 18:41 . 2008-10-15 02:06 633,632 —–c— c:\windows\system32\dllcache\iexplore.exe
2009-02-03 18:41 . 2008-10-16 15:38 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2009-02-03 18:41 . 2008-10-16 15:38 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2009-02-03 18:41 . 2008-10-16 15:38 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2009-02-03 18:41 . 2008-10-16 15:38 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2009-02-03 18:41 . 2008-10-16 15:38 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2009-02-03 18:41 . 2008-10-16 08:11 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2009-02-03 16:22 . 2009-02-03 16:22 d——– C:\ERDNT
2009-02-03 15:35 . 2009-02-03 15:35 d——– c:\program files\Linksys
2009-02-03 15:29 . 2009-02-03 15:29 21,361 –a—— c:\windows\system32\drivers\AegisP.sys
2009-02-03 15:29 . 2008-08-07 14:42 16,512 –a—— c:\windows\system32\drivers\RAPIProtocol.sys
2009-02-03 15:22 . 2009-02-03 15:22 d——– C:\Linksys Driver
2009-02-03 14:46 . 2009-02-03 14:25 4,490,712 –a—— C:\WindowsUpdateAgent20-x86.exe
2009-02-03 14:46 . 2009-02-03 14:30 1,266,056 –a—— C:\WindowsXP-KB927891.exe
2009-02-03 14:41 . 2009-02-03 14:41 d——– c:\documents and settings\Administrator
2009-02-03 10:23 . 2009-02-03 10:24 d——– c:\program files\Realtek AC97
2009-02-03 10:14 . 2009-02-03 10:14 d——– c:\documents and settings\All Users\Application Data\NortonInstaller
2009-02-03 10:14 . 2009-02-03 13:09 d——– c:\documents and settings\All Users\Application Data\Norton
2009-02-02 12:27 . 2009-02-07 16:08 d——– c:\windows\nview
2009-02-02 12:27 . 2009-02-19 15:18 200,411 –a—— c:\windows\system32\nvapps.xml
2009-02-02 10:46 . 2009-01-07 11:28 453,152 –a—— c:\windows\system32\NVUNINST.EXE
2009-02-02 10:46 . 2009-01-15 08:19 453,152 –a—— c:\windows\system32\nvudisp.exe
2009-02-02 10:46 . 2009-01-15 08:19 18,725 –a—— c:\windows\system32\nvdisp.nvu
2009-02-02 10:45 . 2009-02-02 12:10 d——– C:\NVIDIA
2009-02-02 10:42 . 2009-02-02 10:42 552 –a—— c:\windows\system32\d3d8caps.dat
2009-02-02 10:41 . 2009-02-02 10:41 d——– c:\program files\SystemRequirementsLab
2009-02-02 10:40 . 2009-02-02 10:41 d——– c:\documents and settings\Jennifer\Application Data\SystemRequirementsLab
2009-02-01 15:48 . 2004-05-04 11:53 1,645,320 –a—— c:\windows\system32\gdiplus.dll
2009-01-30 22:17 . 2009-01-30 22:17 d——– c:\windows\Logs
2009-01-30 15:49 . 2009-01-30 16:48 d——– c:\windows\system32\NtmsData
2009-01-30 04:12 . 2009-01-30 08:42 d——– c:\documents and settings\Jennifer\Application Data\SecondLife
2009-01-30 03:31 . 2009-01-30 03:31 23 –a—— c:\windows\system32\cccfffec3_g.ocx
2009-01-30 02:31 . 2009-02-19 19:54 d——– c:\documents and settings\Jennifer\Tracing
2009-01-30 02:30 . 2009-01-30 02:30 d——– c:\program files\Microsoft
2009-01-30 02:29 . 2009-01-30 02:29 d——– c:\program files\Windows Live SkyDrive
2009-01-30 02:21 . 2009-01-30 02:21 d——– c:\program files\Common Files\Windows Live
2009-01-29 17:29 . 2009-01-29 18:56 d——– c:\documents and settings\Jennifer\.housecall6.6
2009-01-29 13:39 . 2001-08-17 14:07 101,888 –a–c— c:\windows\system32\dllcache\adpu160m.sys
2009-01-29 13:39 . 2001-08-17 12:11 46,112 –a–c— c:\windows\system32\dllcache\adptsf50.sys
2009-01-29 13:29 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-01-29 09:36 . 2009-01-29 09:36 d——– c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-01-29 09:35 . 2009-02-05 19:05 d——– c:\windows\system32\CatRoot_bak
2009-01-28 02:17 . 2009-02-02 10:44 1,324 –a—— c:\windows\system32\d3d9caps.dat
2009-01-28 01:58 . 2009-01-28 01:58 0 –a—— c:\windows\ativpsrm.bin
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-23 03:12 ——— d—–w c:\program files\Windows Live Safety Center
2009-02-16 20:54 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-16 20:53 ——— d—–w c:\program files\SpywareBlaster
2009-02-16 09:51 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-16 07:25 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-16 06:59 ——— d—–w c:\program files\CA Yahoo! Anti-Spy
2009-02-15 01:48 ——— d—–w c:\program files\Common Files\Real
2009-02-11 15:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-09 17:58 ——— d—–w c:\documents and settings\Jennifer\Application Data\Skype
2009-02-03 20:29 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-03 18:09 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-02-03 15:14 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-01-30 07:29 ——— d—–w c:\program files\Windows Live
2009-01-30 06:44 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-09 08:18 410,984 —-a-w c:\windows\system32\deploytk.dll
2008-12-04 15:36 3,396 –sha-w c:\windows\system32\dllcache\winsvcmgmnt.dll
2008-12-03 03:37 49,480 —-a-w c:\windows\system32\sirenacm.dll
2008-12-01 19:53 45,056 —-a-w c:\windows\system32\amdcalrt.dll
2008-12-01 19:53 45,056 —-a-w c:\windows\system32\amdcalcl.dll
2008-12-01 19:50 3,252,224 —-a-w c:\windows\system32\Amdcaldd.dll
2006-08-15 03:28 24,096 -c–a-w c:\documents and settings\Jennifer\Application Data\GDIPFONTCACHEV1.DAT
2008-01-15 14:13 861 –sha-w c:\windows\system32\dllcache\aamonit.dll
2008-01-15 14:13 847,872 –sha-r c:\windows\system32\dllcache\libeay32.dll
2008-01-15 14:13 159,744 –sha-r c:\windows\system32\dllcache\ssleay32.dll
2008-01-15 14:13 64,000 –sha-r c:\windows\system32\dllcache\syschk32.dll
2008-01-15 14:13 488 –sha-r c:\windows\system32\dllcache\winsvcf.dll
2008-01-15 14:13 895 –sha-r c:\windows\system32\dllcache\winsvcn.dll
2007-07-31 22:42 55,296 -csha-r c:\windows\system32\spool\drivers\raddrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SyncuraCheckedOutByMe]
@="{B1670A4E-8739-4369-93C9-6189604E9B1B}"
[HKEY_CLASSES_ROOT\CLSID\{B1670A4E-8739-4369-93C9-6189604E9B1B}]
2007-07-24 13:24 94208 –a—— e:\syncura\IconOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SyncuraCheckedOutByTeammate]
@="{5264C1EB-A377-4A85-8915-06D2677DF586}"
[HKEY_CLASSES_ROOT\CLSID\{5264C1EB-A377-4A85-8915-06D2677DF586}]
2007-07-24 13:24 94208 –a—— e:\syncura\IconOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SyncuraError]
@="{5B212F72-31AA-4ECA-AF53-6F8230F8ACAE}"
[HKEY_CLASSES_ROOT\CLSID\{5B212F72-31AA-4ECA-AF53-6F8230F8ACAE}]
2007-07-24 13:24 94208 –a—— e:\syncura\IconOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SyncuraSharedFile]
@="{B5BB3723-9098-496A-8ABE-FDD8CBECDA14}"
[HKEY_CLASSES_ROOT\CLSID\{B5BB3723-9098-496A-8ABE-FDD8CBECDA14}]
2007-07-24 13:24 94208 –a—— e:\syncura\IconOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 4662776]
"SUPERAntiSpyware"="E:\SUPERAntiSpyware.exe" [2009-01-15 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"WinampAgent"="e:\winamp\winampa.exe" [2007-10-10 36352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-09 136600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"nwiz"="nwiz.exe" [2009-01-15 c:\windows\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-05-16 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2005-02-24 573440]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Syncura Document Sharing Service.lnk.disabled [2009-02-01 436]
Wireless Network Monitor.lnk - c:\program files\Linksys\WUSB100\WUSB100.exe [2007-10-30 5677056]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "E:\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 E:\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=e:\spybot - search & destroy\TeaTimer.exe
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\SAM\\SAMBC.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"e:\\Soulseek\\SoulseekNS\\slsk.exe"=
"c:\\Documents and Settings\\Jennifer\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\SecondLifeReleaseCandidate\\SLVoice.exe"=
"e:\\Syncura\\Syncura.exe"=
"e:\\Phone\\Skype.exe"=
"e:\\SiSoftware Sandra Lite 2009.SP2\\RpcAgentSrv.exe"=
"e:\\SiSoftware Sandra Lite 2009.SP2\\WNt500x86\\RpcSandraSrv.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:WoW
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 SASDIFSV;SASDIFSV;E:\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;E:\SASKUTIL.SYS [2009-01-15 55024]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s –> c:\program files\Firebird\Firebird_1_5\bin\fbguard.exe -s [?]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s –> c:\program files\Firebird\Firebird_1_5\bin\fbserver.exe -s [?]
R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-07-28 517632]
R3 SASENUM;SASENUM;E:\SASENUM.SYS [2009-01-15 7408]
S2 PostgreSQL;PostgreSQL Database Server;"c:\program files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe" runservice -N "PostgreSQL" -D "c:\program files\PostgreSQL\8.0-beta2-dev3\data\" –> c:\program files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe [?]
S3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [2005-02-24 44544]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;e:\sisoftware sandra lite 2009.sp2\RpcAgentSrv.exe [2009-02-15 98488]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\WUSB100Setup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.
- - - - ORPHANS REMOVED - - - -
Notify-AtiExtEvent - (no file)
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab
FF - ProfilePath - c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-amo&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
FF - plugin: c:\documents and settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07051001.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: e:\divx web player\DivX\DivX Content Uploader\npUpload.dll
FF - plugin: e:\divx web player\DivX\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: e:\divx web player\DivX\DivX Web Player\npdivx32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-23 00:30:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-823518204-507921405-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(504)
E:\SASWINLO.dll
.
Completion time: 2009-02-23 0:33:08
ComboFix-quarantined-files.txt 2009-02-23 05:32:22
ComboFix2.txt 2008-12-09 18:42:45
Pre-Run: 3,210,805,248 bytes free
Post-Run: 3,267,678,208 bytes free
239 — E O F — 2009-02-05 21:28:47