combofix log
ComboFix 11-05-22.02 - chaadmin 05/23/2011 13:20:00.19.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1549 [GMT -5:00]
Running from: c:\documents and settings\chaadmin\Desktop\Program Installs\ComboFix.exe
AV: AVG Anti-Virus Network Edition *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-04-23 to 2011-05-23 )))))))))))))))))))))))))))))))
.
.
2011-05-18 22:54 . 2011-05-18 22:54 -------- d-----w- c:\documents and settings\chaadmin\Local Settings\Application Data\Cisco
2011-05-18 22:50 . 2011-05-18 22:55 -------- d-----w- c:\program files\Cisco
2011-05-18 22:50 . 2011-05-18 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Cisco
2011-05-18 21:54 . 2011-05-18 21:54 -------- d-----w- c:\program files\ESET
2011-05-18 19:51 . 2011-05-18 19:51 -------- d-----w- c:\program files\ERUNT
2011-05-17 21:02 . 2011-05-20 00:11 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-05-17 21:02 . 2011-05-17 21:03 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2011-05-17 21:02 . 2011-05-17 21:02 -------- d-----w- c:\documents and settings\Default User\Application Data\Apple Computer
2011-05-17 21:01 . 2011-05-17 21:02 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Apple Computer
2011-05-16 19:24 . 2011-05-16 19:24 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-11 16:32 . 2011-05-11 16:32 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2011-05-11 14:50 . 2011-05-11 14:50 -------- d-----w- c:\program files\Common Files\Java
2011-05-09 20:55 . 2011-05-09 20:58 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2011-05-06 19:02 . 2011-05-06 19:02 -------- d-----w- c:\program files\iPod
2011-05-06 19:02 . 2011-05-06 19:03 -------- d-----w- c:\program files\iTunes
2011-05-06 18:59 . 2011-05-06 18:59 -------- d-----w- c:\program files\Apple Software Update
2011-05-06 18:58 . 2011-05-06 18:58 -------- d-----w- c:\program files\Bonjour
2011-05-06 17:15 . 2011-05-06 17:16 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-05-05 22:13 . 2011-05-05 22:13 -------- d-----w- c:\documents and settings\chaadmin\Application Data\AVCWare
2011-05-05 22:13 . 2011-05-05 22:13 -------- d-----w- c:\program files\AVCWare
2011-05-05 22:13 . 2011-05-05 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\AVCWare
2011-05-04 16:23 . 2011-05-04 16:23 0 ----a-w- c:\windows\Yhaxu.bin
2011-05-02 17:19 . 2011-04-14 16:26 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-02 17:19 . 2011-04-14 16:25 781272 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-02 17:19 . 2011-04-14 16:25 1874904 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-05-02 17:19 . 2011-04-14 16:25 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-02 17:18 . 2011-04-14 16:25 465880 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-02 17:18 . 2011-04-14 16:25 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-05-02 17:18 . 2010-01-01 08:00 1974616 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-05-02 17:18 . 2010-01-01 08:00 1892184 ----a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-06 21:20 . 2011-04-06 21:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 21:20 . 2011-04-06 21:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-03-07 05:33 . 2009-03-31 23:08 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-04 05:56 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-04 04:17 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2010-03-31 17:48 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 23:06 . 2004-08-04 05:56 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2004-08-04 05:56 43520 ----a-w- c:\windows\system32\licmgr10.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2011-04-14 16:26 . 2011-05-02 17:19 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-05-04_19.42.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 06:19 . 2007-11-07 06:19 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90kor.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 47104 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90jpn.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 59392 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90ita.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 60416 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90fra.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 59392 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90esp.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 59392 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90esn.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90enu.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 60928 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90deu.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 41984 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90cht.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 41472 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_11f3ea3a\mfc90chs.dll
+ 2007-11-07 03:51 . 2007-11-07 03:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfcm90u.dll
+ 2007-11-07 03:51 . 2007-11-07 03:51 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfcm90.dll
+ 2011-05-23 17:42 . 2011-05-23 17:42 16384 c:\windows\temp\Perflib_Perfdata_5c4.dat
+ 2011-02-11 13:44 . 2011-02-11 13:44 28920 c:\windows\system32\vpnevents.dll
+ 2011-02-11 13:27 . 2011-02-11 13:27 19680 c:\windows\system32\drivers\vpnva.sys
+ 2011-05-06 18:59 . 2011-05-06 18:59 27136 c:\windows\Installer\{C41300B9-185D-475E-BFEC-39EF732F19B1}\AppleSoftwareUpdateIco.exe
+ 2011-05-18 22:55 . 2011-05-18 22:55 12390 c:\windows\Installer\{80B70B4B-C90C-4938-A956-76F5021DE412}\DART.exe
+ 2011-02-11 13:45 . 2011-02-11 13:45 8952 c:\windows\system32\vpncategories.dll
- 2009-06-10 16:20 . 2010-12-27 22:00 2644 c:\windows\system32\d3d9caps.dat
+ 2009-06-10 16:20 . 2011-05-20 19:23 2644 c:\windows\system32\d3d9caps.dat
+ 2007-11-07 06:19 . 2007-11-07 06:19 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_312cf0e9\atl90.dll
+ 2011-05-16 19:24 . 2011-05-16 19:24 239776 c:\windows\system32\Macromed\Flash\FlashUtil10q_Plugin.exe
+ 2011-05-11 14:49 . 2011-02-03 02:40 157472 c:\windows\system32\javaws.exe
- 2011-01-12 19:03 . 2010-11-13 00:53 157472 c:\windows\system32\javaws.exe
+ 2011-05-11 14:49 . 2011-02-03 02:40 145184 c:\windows\system32\javaw.exe
- 2011-01-12 19:03 . 2010-11-13 00:53 145184 c:\windows\system32\javaw.exe
+ 2011-05-11 14:49 . 2011-02-03 02:40 145184 c:\windows\system32\java.exe
- 2011-01-12 19:03 . 2010-11-13 00:53 145184 c:\windows\system32\java.exe
+ 2011-01-12 19:03 . 2011-02-03 02:40 472808 c:\windows\system32\deployJava1.dll
- 2011-01-12 19:03 . 2010-11-13 00:53 472808 c:\windows\system32\deployJava1.dll
+ 2011-05-11 14:50 . 2011-05-11 14:50 180224 c:\windows\Installer\dde88.msi
+ 2011-05-06 18:56 . 2011-05-06 18:56 811520 c:\windows\Installer\9d0145.msi
+ 2011-05-18 22:55 . 2011-05-18 22:55 398848 c:\windows\Installer\5a20e8.msi
+ 2011-05-18 22:51 . 2011-05-18 22:51 435712 c:\windows\Installer\5a20e3.msi
+ 2011-05-05 22:13 . 2011-05-05 22:13 228352 c:\windows\Installer\56e40c.msi
+ 2011-05-06 19:04 . 2011-05-17 21:02 380928 c:\windows\Installer\{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}\iTunesIco.exe
+ 2011-05-18 19:51 . 2011-05-18 19:51 409600 c:\windows\ERDNT\5-18-2011\Users\00000002\UsrClass.dat
+ 2011-05-18 19:51 . 2005-10-20 17:02 163328 c:\windows\ERDNT\5-18-2011\ERDNT.EXE
+ 2007-11-07 06:19 . 2007-11-07 06:19 1162744 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfc90u.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 1156600 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_a173767a\mfc90.dll
+ 2010-01-27 01:07 . 2011-05-16 19:24 6271136 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2011-04-14 14:46 . 2011-04-14 14:46 3854848 c:\windows\Installer\dde6f.msp
+ 2011-05-06 19:04 . 2011-05-06 19:04 6523904 c:\windows\Installer\9d0b71.msi
+ 2011-05-06 18:59 . 2011-05-06 18:59 1554944 c:\windows\Installer\9d0199.msi
+ 2011-05-06 18:58 . 2011-05-06 18:58 1984000 c:\windows\Installer\9d0168.msi
+ 2011-05-18 19:51 . 2011-05-18 19:51 9678848 c:\windows\ERDNT\5-18-2011\Users\00000001\NTUSER.DAT
+ 2011-03-13 01:02 . 2011-03-13 01:02 15139328 c:\windows\Installer\dde70.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
[BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 01:34 87352 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^chaadmin^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\chaadmin\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 -c----w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2006-03-24 02:13 77824 -c--a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2006-03-24 02:17 118784 -c--a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2006-03-24 01:17 94208 -c--a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-27 06:22 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2008-08-11 18:41 63048 ----a-w- c:\program files\LogMeIn\x86\LogMeInSystray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetSoft]
2009-04-20 17:56 31232 ----a-w- c:\combofix\iexplore.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-02-18 18:44 13680640 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-02-18 18:44 86016 -c--a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2009-02-18 18:44 1657376 -c--a-w- c:\windows\system32\nwiz.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Medisoft\\Bin\\MAPA.EXE"=
.
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\dddsk.sys [2/16/2011 4:03 PM 22312]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [8/11/2008 1:41 PM 12856]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [2/11/2011 8:41 AM 603896]
R3 HPPLSBULK;HPPLSBULK;c:\windows\system32\drivers\hpplsbulk.sys [2/2/2005 5:29 PM 9344]
R3 radpms;Driver for RADPMS Device;c:\windows\system32\drivers\radpms.sys [8/11/2008 1:40 PM 12192]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG8\Toolbar\ToolbarBroker.exe --> c:\program files\AVG\AVG8\Toolbar\ToolbarBroker.exe [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [3/25/2010 10:25 AM 30969208]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
itlsvc REG_MULTI_SZ itlperf
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
2011-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-940683282-2589845998-2305105441-1117Core.job
- c:\documents and settings\chaadmin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-05-18 20:03]
.
2011-05-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-940683282-2589845998-2305105441-1117UA.job
- c:\documents and settings\chaadmin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-05-18 20:03]
.
2011-05-23 c:\windows\Tasks\User_Feed_Synchronization-{B66BD46A-3331-4767-AFE7-C0EDB30A6FB7}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local;<local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: windowsupdate.com
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
FF - ProfilePath - c:\documents and settings\chaadmin\Application Data\Mozilla\Firefox\Profiles\p3v07jl6.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-23 13:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(452)
c:\windows\system32\LMIinit.dll
.
- - - - - - - > 'explorer.exe'(1796)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2011-05-23 13:33:10
ComboFix-quarantined-files.txt 2011-05-23 18:32
ComboFix2.txt 2011-05-19 17:12
ComboFix3.txt 2011-05-18 17:57
ComboFix4.txt 2011-05-13 17:08
ComboFix5.txt 2011-05-23 18:15
.
Pre-Run: 11,680,219,136 bytes free
Post-Run: 12,361,932,800 bytes free
.
- - End Of File - - D8B68F09708B1853A9C286A985FF8ABC