ComboFix 09-09-08.09 - matthew 09/09/2009 18:57.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.632 [GMT 1:00]
Running from: c:\documents and settings\matthew\Desktop\Combofix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\ltfil13n.DLL
.
((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.
2009-09-09 12:45 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-09-08 17:05 . 2009-09-08 17:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-08 16:52 . 2009-09-08 16:58 -------- d-----w- c:\documents and settings\matthew\.SunDownloadManager
2009-09-08 16:37 . 2009-09-08 16:37 -------- d-----w- c:\program files\Windows Installer Clean Up
2009-09-06 16:35 . 2009-09-06 16:35 -------- d-----w- c:\windows\system32\Adobe
2009-09-05 11:54 . 2009-09-05 11:54 -------- d-----w- c:\documents and settings\matthew\Local Settings\Application Data\PCHealth
2009-08-25 20:11 . 2009-08-25 20:11 -------- d-----w- c:\program files\Trend micro
2009-08-25 20:06 . 2009-08-25 20:07 -------- d-----w- c:\program files\ERUNT
2009-08-21 15:59 . 2009-08-21 15:59 82824 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-17 22:18 . 2009-08-17 22:30 -------- d-----w- c:\documents and settings\matthew\Application Data\The Path
2009-08-11 20:03 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-09 12:46 . 2009-06-08 09:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-08 17:05 . 2005-05-17 21:56 -------- d-----w- c:\program files\Java
2009-09-08 16:42 . 2008-11-11 16:23 -------- d-----w- c:\program files\MSECache
2009-09-06 16:31 . 2005-11-02 18:29 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-25 18:58 . 2009-06-08 09:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-25 18:29 . 2006-09-01 02:43 -------- d-----w- c:\program files\Common Files\Command Software
2009-08-20 16:40 . 2005-12-01 20:12 282 ----a-w- c:\windows\freedom.backup.dat
2009-08-20 16:39 . 2005-11-02 15:45 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Symantec
2009-08-16 05:49 . 2008-12-17 20:21 -------- d-----w- c:\program files\PeerGuardian2
2009-08-05 09:01 . 2004-08-04 08:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 08:03 . 2009-08-02 08:03 -------- d-----w- c:\program files\SixaxisDriver
2009-08-02 06:58 . 2005-05-17 21:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-02 06:53 . 2006-12-22 18:51 -------- d-----w- c:\program files\THQ
2009-08-01 06:51 . 2009-08-01 06:51 -------- d-----w- c:\program files\7-Zip
2009-07-31 01:27 . 2009-05-27 21:44 -------- d-----w- c:\documents and settings\matthew\Application Data\com.zipeg
2009-07-26 23:31 . 2006-09-16 14:23 -------- d-----w- c:\program files\Warcraft III
2009-07-17 19:01 . 2004-08-04 08:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 09:08 . 2004-08-04 08:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2004-08-04 08:00 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 08:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 08:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2004-08-04 08:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 08:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 08:00 76288 ----a-w- c:\windows\system32\telnet.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-09-06_16.10.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-17 21:54 . 2007-07-27 09:41 16760 c:\windows\system32\spmsg.dll
- 2004-08-07 13:10 . 2009-09-06 15:46 71912 c:\windows\system32\perfc009.dat
+ 2004-08-07 13:10 . 2009-09-09 17:56 71912 c:\windows\system32\perfc009.dat
+ 2009-09-06 16:45 . 2009-09-06 16:45 88589 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-09-06 16:35 . 2009-09-06 16:35 87617 c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
+ 2009-07-21 08:02 . 2009-07-21 08:02 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2009-07-21 06:59 . 2009-07-21 06:59 79488 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2009-07-21 08:04 . 2009-07-21 08:04 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2004-08-07 13:10 . 2009-09-09 17:56 442334 c:\windows\system32\perfh009.dat
- 2004-08-07 13:10 . 2009-09-06 15:46 442334 c:\windows\system32\perfh009.dat
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2004-08-04 08:00 . 2009-08-13 15:16 512000 c:\windows\system32\jscript.dll
- 2004-08-04 08:00 . 2008-05-09 10:53 512000 c:\windows\system32\jscript.dll
+ 2009-09-08 17:05 . 2009-09-08 17:05 149280 c:\windows\system32\javaws.exe
+ 2009-09-08 17:05 . 2009-09-08 17:05 145184 c:\windows\system32\javaw.exe
+ 2009-09-08 17:05 . 2009-09-08 17:05 145184 c:\windows\system32\java.exe
+ 2008-05-09 10:53 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 512000 c:\windows\system32\dllcache\jscript.dll
+ 2009-07-21 06:59 . 2009-07-21 06:59 132472 c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 2009-07-21 08:07 . 2009-07-21 08:07 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2009-07-21 08:17 . 2009-07-21 08:17 468408 c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe
+ 2009-07-21 08:07 . 2009-07-21 08:07 446464 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2009-07-21 08:02 . 2009-07-21 08:02 372736 c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2009-07-21 06:59 . 2009-07-21 06:59 714752 c:\windows\system32\Adobe\Shockwave 11\gi.dll
+ 2009-07-21 08:04 . 2009-07-21 08:04 614400 c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2009-07-21 08:18 . 2009-07-21 08:18 206264 c:\windows\system32\Adobe\Director\SwDir.dll
+ 2009-07-21 08:03 . 2009-07-21 08:03 131072 c:\windows\system32\Adobe\Director\np32dsw.dll
+ 2009-09-08 16:37 . 2009-09-08 16:37 472064 c:\windows\Installer\168758.msi
+ 2009-01-18 15:05 . 2009-01-18 15:05 675840 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\JP2KLib.dll
+ 2009-09-09 12:43 . 2009-09-09 12:43 208896 c:\windows\ERDNT\AutoBackup\09-09-2009\Users\00000002\UsrClass.dat
+ 2009-09-09 12:43 . 2005-10-20 11:02 163328 c:\windows\ERDNT\AutoBackup\09-09-2009\ERDNT.EXE
+ 2009-09-08 16:14 . 2009-09-08 16:14 208896 c:\windows\ERDNT\AutoBackup\08-09-2009\Users\00000002\UsrClass.dat
+ 2009-09-08 16:14 . 2005-10-20 11:02 163328 c:\windows\ERDNT\AutoBackup\08-09-2009\ERDNT.EXE
+ 2004-08-04 08:00 . 2009-05-20 11:44 2355200 c:\windows\system32\WMVCore.dll
+ 2004-08-04 08:00 . 2009-05-20 11:44 2355200 c:\windows\system32\dllcache\WMVCore.dll
+ 2009-07-21 07:07 . 2009-07-21 07:07 1011712 c:\windows\system32\Adobe\Shockwave 11\iml32.dll
+ 2009-07-21 06:59 . 2009-07-21 06:59 1886320 c:\windows\system32\Adobe\Shockwave 11\gt.exe
+ 2009-07-21 07:12 . 2009-07-21 07:12 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2009-09-06 16:37 . 2009-09-06 16:37 1697792 c:\windows\Installer\bdff0.msp
+ 2009-09-06 16:35 . 2009-09-06 16:35 6653952 c:\windows\Installer\bdfe2.msp
+ 2009-09-06 16:31 . 2009-09-06 16:31 3938816 c:\windows\Installer\bdfbe.msi
+ 2009-09-08 17:05 . 2009-09-08 17:05 1757696 c:\windows\Installer\10c01c.msi
+ 2008-12-18 15:48 . 2008-12-18 15:48 3645440 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\authplay.dll
+ 2005-12-02 16:43 . 2009-08-28 21:38 24689600 c:\windows\system32\MRT.exe
+ 2009-02-27 15:37 . 2009-02-27 15:37 20403568 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\AcroRd32.dll
+ 2009-09-09 12:43 . 2009-09-09 12:43 10133504 c:\windows\ERDNT\AutoBackup\09-09-2009\Users\00000001\ntuser.dat
+ 2009-09-08 16:14 . 2009-09-08 16:14 10125312 c:\windows\ERDNT\AutoBackup\08-09-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 339968]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 794624]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
c:\documents and settings\matthew\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-12-23 569405]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ImageMixer 3 SE Camera Monitor for SD.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor for SD.lnk
backup=c:\windows\pss\ImageMixer 3 SE Camera Monitor for SD.lnkCommon Startup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo fix.exe"=
"c:\\Program Files\\Lionhead Studios Ltd\\Black & White\\sdv2.testme.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ubi.com\\Core\\GS4.exe"=
"c:\\Program Files\\The Creative Assembly\\Rome - Total War\\RomeTW fixer.exe"=
"c:\\Program Files\\Valve\\Steam\\steam.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:warcraft
"427:UDP"= 427:UDP:SLP_Port(427)
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [22/03/2005 15:39 200192]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [26/04/2008 23:42 13352]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [02/08/2009 08:28 33792]
S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\drivers\xPADFL02.sys [02/08/2009 09:03 27904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-08-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34]
2009-08-20 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2004-08-04 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q305&bd=pavilion&pf=laptop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-09 19:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-09-09 19:07
ComboFix-quarantined-files.txt 2009-09-09 18:07
ComboFix2.txt 2009-09-06 16:12
ComboFix3.txt 2009-09-05 19:44
Pre-Run: 30,827,356,160 bytes free
Post-Run: 30,875,262,976 bytes free
234 --- E O F --- 2009-09-09 13:12