ComboFix log
------------
ComboFix 09-09-08.01 - drose 09/08/2009 15:26.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.1683 [GMT -4:00]
Running from: c:\documents and settings\drose\Desktop\anti-malware\Combo-Fix.exe
AV: AVG Anti-Virus Network Edition *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\drose\Application Data\.#
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\logevent.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-08-08 to 2009-09-08 )))))))))))))))))))))))))))))))
.
2009-09-08 03:07 . 2009-09-08 03:07 -------- d-----w- c:\documents and settings\drose\Application Data\Malwarebytes
2009-09-08 03:07 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 03:07 . 2009-09-08 03:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-08 03:07 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 03:07 . 2009-09-08 03:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-06 17:39 . 2009-09-06 17:39 -------- d-----w- C:\rsit
2009-09-05 19:08 . 2009-09-08 13:17 -------- d-----w- c:\program files\Trend Micro
2009-09-05 18:42 . 2009-09-05 18:46 -------- d-----w- c:\temp\Spybot
2009-09-04 20:50 . 2009-09-04 20:53 750 ----a-w- C:\fix_migration_property_files.bat
2009-09-04 15:05 . 2009-09-08 18:16 -------- d-----w- C:\STCDataMigration
2009-09-04 14:22 . 2009-09-04 14:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-09-03 19:07 . 2009-09-03 19:07 -------- d-sh--w- c:\documents and settings\drose\PrivacIE
2009-09-03 18:38 . 2009-09-03 18:42 -------- d-----w- c:\program files\office Convert Pdf to Document
2009-08-28 14:48 . 2009-08-28 14:50 -------- d-----w- c:\program files\paradox-dbase-reader
2009-08-28 14:38 . 2009-08-28 14:38 -------- d-----w- c:\documents and settings\drose\Application Data\DBF Manager
2009-08-26 20:22 . 2009-08-26 20:22 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-08-26 19:50 . 2009-08-26 19:50 -------- d-----w- c:\program files\OpenProj
2009-08-24 13:45 . 2009-08-24 13:45 -------- d-sh--w- c:\documents and settings\drose\IETldCache
2009-08-23 20:21 . 2009-07-03 17:09 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-08-23 20:21 . 2009-07-03 17:09 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-23 20:20 . 2009-08-23 20:20 -------- d-----w- c:\windows\ie8updates
2009-08-23 20:20 . 2009-07-01 07:08 101376 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-08-23 20:19 . 2009-08-23 20:20 -------- dc-h--w- c:\windows\ie8
2009-08-20 21:04 . 2009-08-20 21:04 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-20 21:04 . 2009-08-20 21:04 -------- d-----w- c:\program files\MSBuild
2009-08-20 21:04 . 2009-08-20 21:04 -------- d-----w- c:\program files\Reference Assemblies
2009-08-20 21:04 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-20 21:04 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-20 21:04 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-20 21:04 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-20 21:04 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-20 21:04 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-20 21:04 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-13 20:05 . 2009-08-13 20:05 -------- d-----w- c:\documents and settings\drose\Application Data\TourDeLiveCycle.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-13 20:05 . 2009-08-13 20:05 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-08-12 21:36 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-12 17:03 . 2009-08-28 15:08 -------- d-----w- c:\documents and settings\drose\Tracing
2009-08-12 17:03 . 2009-07-31 00:01 81736 ----a-w- c:\windows\system32\lmdimon8.dll
2009-08-12 17:02 . 2009-08-12 17:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Applications
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-08 19:47 . 2009-02-03 19:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-08 19:40 . 2008-10-02 18:47 -------- d-----w- c:\documents and settings\drose\Application Data\.purple
2009-09-05 18:41 . 2008-12-17 16:19 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-05 18:32 . 2008-12-17 16:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-03 21:19 . 2009-03-27 13:24 -------- d-----w- c:\documents and settings\drose\Application Data\DBDesigner4
2009-09-01 13:22 . 2009-07-20 22:11 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-21 19:32 . 2008-09-10 17:51 120408 ----a-w- c:\documents and settings\drose\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-21 18:53 . 2009-02-26 19:40 -------- d-----w- c:\documents and settings\drose\Application Data\gtk-2.0
2009-08-12 20:38 . 2005-09-10 04:49 -------- d-----w- c:\program files\Java
2009-08-05 09:01 . 2004-08-11 22:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-30 13:30 . 2009-05-02 18:23 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-07-30 13:30 . 2009-05-02 18:23 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-30 13:30 . 2008-10-07 20:36 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-29 21:21 . 2009-07-29 21:21 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-07-29 21:19 . 2005-09-10 04:51 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-29 21:00 . 2009-07-29 20:40 -------- d-----w- c:\documents and settings\drose\Application Data\Download Manager
2009-07-23 14:52 . 2009-07-23 14:52 -------- d-----w- c:\program files\Veetle
2009-07-17 19:01 . 2004-08-11 22:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 21:00 . 2009-07-15 21:00 -------- d-----w- c:\program files\Citrix
2009-07-15 21:00 . 2009-07-15 21:00 60744 ----a-w- c:\documents and settings\drose\g2mdlhlpx.exe
2009-07-13 15:10 . 2009-07-11 14:14 -------- d-----w- c:\program files\Cobian Backup 8
2009-07-12 16:21 . 2004-08-11 22:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-07 19:40 . 2009-07-07 19:40 3 ----a-w- c:\program files\option.txt
2009-07-03 17:09 . 2004-08-11 22:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-11 22:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-11 22:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-11 22:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-11 22:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-11 22:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-11 22:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-11 22:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-11 22:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-11 22:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2004-08-11 22:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-11 22:00 76288 ----a-w- c:\windows\system32\telnet.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-02 17:38 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-02 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-11-02 13:26 80384 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\drose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-10 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-06 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-06 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-06 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-01 344064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2007832]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"Cobian Backup 8 interface"="c:\program files\Cobian Backup 8\cbInterface.exe" [2007-09-27 2425856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Qualcomm\Eudora\EuShlExt.dll" [2005-08-09 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 13:30 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\documents and settings\drose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_12\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IBM\\Sametime Connect 7.5\\jre\\bin\\sametime75.exe"=
"c:\\eclipse\\eclipse.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre1.5.0_12\\bin\\javaw.exe"=
"c:\\oracle\\product\\10.2.0\\db_1\\jdk\\jre\\bin\\java.exe"=
"c:\\Program Files\\Java\\jdk1.5.0_12\\jre\\bin\\java.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Java\\jdk1.5.0_12\\bin\\java.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"67:UDP"= 67:UDP:0.0.0.0/255.255.255.255:Enabled

HCP Discovery Service
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/2/2009 2:23 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/2/2009 2:23 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/2/2009 2:23 PM 108552]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [2/26/2009 4:56 PM 8576]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [9/16/2008 12:03 PM 169312]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/30/2009 9:29 AM 297752]
R2 ComodoBackupService;ComodoBackupService;c:\program files\Comodo\BackUp\CmdBkSvc.exe [7/8/2009 5:42 PM 1023488]
R2 LogWatch;Event Log Watch;c:\windows\LogWatNT.exe [3/17/2008 6:08 PM 51712]
R2 MPI;MPI;c:\webapp\mpi-2.0.0-6\wrapper-assembly-2.0.0-6\nt\Wrapper.exe -s c:\webapp\mpi-2.0.0-6\wrapper-assembly-2.0.0-6\conf\wrapper.conf --> c:\webapp\mpi-2.0.0-6\wrapper-assembly-2.0.0-6\nt\Wrapper.exe -s c:\webapp\mpi-2.0.0-6\wrapper-assembly-2.0.0-6\conf\wrapper.conf [?]
R2 OracleOraDb10g_home1TNSListener;OracleOraDb10g_home1TNSListener;c:\oracle\product\10.2.0\db_1\BIN\TNSLSNR --> c:\oracle\product\10.2.0\db_1\BIN\TNSLSNR [?]
R2 OracleServiceUPGTEST;OracleServiceUPGTEST;c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE UPGTEST --> c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE UPGTEST [?]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate1c98631b7f1ee58;Google Update Service (gupdate1c98631b7f1ee58);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2009 3:00 PM 133104]
S3 MPI1915-1;MPI1915-1;c:\documents and settings\drose\Desktop\Build NH\MPI-Service-mssql-1.9.1-5-1\nt\Wrapper-1915-1.exe [3/31/2009 11:16 AM 135168]
S3 OracleDBConsoleMORBID;OracleDBConsoleMORBID;c:\oracle\product\10.2.0\db_1\BIN\nmesrvc.exe [5/26/2009 2:29 PM 24064]
S3 OracleServiceAK34;OracleServiceAK34;c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE AK34 --> c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE AK34 [?]
S3 OracleServiceMORBID;OracleServiceMORBID;c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE MORBID --> c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE MORBID [?]
S3 OracleServiceMPI;OracleServiceMPI;c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE MPI --> c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE MPI [?]
S3 Tomcat5;Apache Tomcat;c:\program files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe [8/28/2008 11:12 PM 57344]
S3 tomcat51;tomcat51;c:\program files\Apache Software Foundation\Tomcat 5.5-1\bin\tomcat51.exe [3/31/2009 12:04 PM 57344]
S4 OracleJobSchedulerAK34;OracleJobSchedulerAK34;c:\oracle\product\10.2.0\db_1\Bin\extjob.exe AK34 --> c:\oracle\product\10.2.0\db_1\Bin\extjob.exe AK34 [?]
S4 OracleJobSchedulerMORBID;OracleJobSchedulerMORBID;c:\oracle\product\10.2.0\db_1\Bin\extjob.exe MORBID --> c:\oracle\product\10.2.0\db_1\Bin\extjob.exe MORBID [?]
S4 OracleJobSchedulerMPI;OracleJobSchedulerMPI;c:\oracle\product\10.2.0\db_1\Bin\extjob.exe MPI --> c:\oracle\product\10.2.0\db_1\Bin\extjob.exe MPI [?]
S4 OracleJobSchedulerUPGTEST;OracleJobSchedulerUPGTEST;c:\oracle\product\10.2.0\db_1\Bin\extjob.exe UPGTEST --> c:\oracle\product\10.2.0\db_1\Bin\extjob.exe UPGTEST [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-19 14:44]
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 19:00]
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 19:00]
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3870249352-4182832932-996789922-1009Core.job
- c:\documents and settings\drose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-10 17:21]
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3870249352-4182832932-996789922-1009UA.job
- c:\documents and settings\drose\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-10 17:21]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Monopod - c:\tmp\a.exe
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {DD9128B7-A683-4A18-A678-03465B3827BB} = 10.0.1.32
FF - ProfilePath - c:\documents and settings\drose\Application Data\Mozilla\Firefox\Profiles\figdpvbk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Webster
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\documents and settings\drose\Application Data\Mozilla\Firefox\Profiles\figdpvbk.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\drose\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPCltInstall.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-08 15:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OracleOraDb10g_home1TNSListener]
"ImagePath"="c:\oracle\product\10.2.0\db_1\BIN\TNSLSNR "
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tomcat51]
"ImagePath"="\"c:\program files\Apache Software Foundation\Tomcat 5.5-1/bin/tomcat51.exe\" //RS//tomcat51"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3870249352-4182832932-996789922-1009\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FBA643C9-F947-A46F-4DA6-014D2E157898}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iacdhgaphncfkjcibj"=hex:63,61,65,62,63,62,00,7c
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3472)
c:\windows\system32\WININET.dll
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cobian Backup 8\cbService.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\webapp\mpi-2.0.0-6\wrapper-assembly-2.0.0-6\nt\Wrapper.exe
c:\program files\lotus\notes\ntmulti.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.EXE
c:\oracle\product\10.2.0\db_1\BIN\oracle.exe
c:\windows\system32\java.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
.
**************************************************************************
.
Completion time: 2009-09-08 15:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-08 19:52
Pre-Run: 110,163,091,456 bytes free
Post-Run: 114,148,024,320 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
343 --- E O F --- 2009-08-31 21:41