Combo Fix Log
ComboFix 09-09-08.02 - HP_Owner 09/12/2009 5:41.1.1 - NTFSx86
Running from: c:\documents and settings\HP_Owner\Desktop\Combo--Fix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Owner\Application Data\Microsoft\Windows\iexplorer.exe
c:\documents and settings\HP_Owner\Application Data\Microsoft\Windows\lsass.exe
c:\documents and settings\HP_Owner\Application Data\Microsoft\Windows\ms64.exe
c:\documents and settings\HP_Owner\Local Settings\Temporary Internet Files\21.tmp
C:\install.exe
c:\program files\Common Files\Real\WeatherBug\MiniBugTransporter.dll
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\system32\~.exe
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\ps2.bat
c:\windows\system32\windows32.exe
c:\windows\system32\wisdstr.exe
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
c:\windows\system32\drivers\beep.sys . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2009-08-12 to 2009-09-12 )))))))))))))))))))))))))))))))
.
2009-09-12 03:27 . 2009-09-12 03:46 -------- d-----w- c:\documents and settings\All Users\Application Data\TrackMania
2009-09-12 02:51 . 2009-09-12 02:57 -------- d-----w- c:\program files\TmUnitedForever
2009-09-12 02:39 . 2009-09-12 02:41 -------- d-----w- c:\program files\TrackMania United
2009-09-07 19:34 . 2009-09-07 19:34 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-07 19:34 . 2009-09-07 19:34 -------- d-----w- c:\program files\Viewpoint
2009-09-05 21:35 . 2009-09-07 19:34 -------- d-----w- c:\documents and settings\HP_Owner\.housecall6.6
2009-09-05 05:47 . 2009-09-05 05:47 -------- d-----w- c:\program files\Lavalys
2009-09-01 21:54 . 2009-09-01 21:54 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\GraveyardShift
2009-09-01 21:53 . 2009-09-01 21:53 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-01 21:52 . 2009-09-01 21:52 -------- d-----w- c:\program files\GoGii Games
2009-08-31 18:27 . 2009-08-31 18:27 -------- d-----w- c:\program files\Steinberg
2009-08-31 18:27 . 2009-08-31 18:27 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Antares
2009-08-31 18:27 . 2009-08-31 18:27 -------- d-----w- c:\program files\Antares Audio Technologies
2009-08-28 20:50 . 2009-08-29 20:57 -------- d-----w- c:\program files\osu!
2009-08-28 20:50 . 2009-08-28 20:50 -------- d-----w- c:\windows\osu!
2009-08-27 06:52 . 2009-08-27 16:31 -------- d-----w- c:\program files\De Blob
2009-08-25 14:23 . 2009-08-25 14:23 -------- d-----w- c:\windows\system32\Adobe
2009-08-24 16:39 . 2009-08-24 16:39 -------- d-----w- c:\program files\Tale of Tales
2009-08-24 16:39 . 2007-07-27 21:57 57449 ----a-w- c:\windows\system32\The Endless Forest 3.scr
2009-08-24 12:03 . 2009-08-24 12:03 -------- d-----w- c:\program files\The Marriage
2009-08-24 10:34 . 2009-08-24 10:34 -------- d-----w- c:\documents and settings\HP_Owner\bin
2009-08-24 10:32 . 2009-08-24 10:32 -------- d-----w- c:\program files\Colormental
2009-08-22 09:55 . 2009-08-22 09:55 -------- d-----w- c:\program files\Trend Micro
2009-08-21 10:58 . 2009-08-21 10:58 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\TeamViewer
2009-08-15 12:58 . 2009-08-15 12:58 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-15 12:58 . 2009-09-07 21:43 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\skypePM
2009-08-15 12:58 . 2009-09-07 22:23 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Skype
2009-08-15 12:58 . 2009-08-15 12:58 -------- d-----w- c:\program files\Common Files\Skype
2009-08-15 12:58 . 2009-08-15 12:58 -------- d-----r- c:\program files\Skype
2009-08-15 12:57 . 2009-08-15 12:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-12 09:38 . 2009-04-30 23:17 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\MxBoost
2009-09-12 06:40 . 2009-05-01 00:06 -------- d-----w- c:\program files\Warcraft III
2009-09-11 19:23 . 2009-04-30 23:20 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Azureus
2009-09-11 18:45 . 2009-05-06 12:30 -------- d-----w- c:\program files\Steam
2009-09-08 02:24 . 2009-04-30 23:09 -------- d-----w- c:\program files\Maxthon2
2009-09-06 15:34 . 2009-05-08 23:00 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\U3
2009-08-31 14:41 . 2006-02-16 11:03 -------- d-----w- c:\program files\Java
2009-08-26 13:05 . 2009-04-30 23:19 -------- d-----w- c:\program files\Vuze
2009-08-25 19:23 . 2009-05-01 00:10 78562 ----a-w- c:\windows\War3Unin.dat
2009-08-19 22:38 . 2009-05-20 00:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-01 00:07 . 2009-08-01 00:07 -------- d-----w- c:\program files\CEVO
2009-07-30 07:21 . 2009-07-30 07:21 -------- d-----w- c:\program files\uTorrent
2009-07-28 16:06 . 2009-07-28 16:06 0 ----a-w- c:\windows\system32\cid_store.dat
2009-07-25 09:23 . 2009-07-04 04:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-22 14:56 . 2009-07-22 14:56 -------- d-----w- c:\program files\Microsoft
2009-07-15 17:02 . 2009-05-17 15:31 -------- d-----w- c:\program files\Free Music Zilla
2009-06-15 22:22 . 2009-05-30 03:34 35304 ----a-w- c:\windows\DIIUnin.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-02-19 1262888]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-10 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-02-16 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-06-11 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-01-12 15961088]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CtHelper.exe [2009-03-04 19456]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 03:34 24576 ----a-w- c:\progra~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=myokent.dll
"MIDI3"=myokent.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Viewpoint Manager Service"=2 (0x2)
"Pml Driver HPZ12"=0 (0x0)
"ose"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"odserv"=3 (0x3)
"MDM"=2 (0x2)
"LightScribeService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"IDriverT"=3 (0x3)
"Creative Audio Engine Licensing Service"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Steam\\steamapps\\lilxaznxboix\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\lilxaznxboix\\counter-strike\\hl.exe"=
"c:\\Documents and Settings\\HP_Owner\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Maxthon2\\Modules\\MxDownloader\\MxDownloadServer.exe"=
"c:\\WINDOWS\\system32\\The Endless Forest 3.scr"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\HP_Owner\\Desktop\\Dyadin 2\\Dyadin 2\\Dyadin 2\\bin\\dyadin.exe"=
"c:\\Program Files\\TmUnitedForever\\TmForever.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6114:TCP"= 6114:TCP:6114t
"6114:UDP"= 6114:UDP:6114u
"6113:TCP"= 6113:TCP:6113t
"6113:UDP"= 6113:UDP:6113u
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
"56324:TCP"= 56324:TCP

ando Media Booster
"56324:UDP"= 56324:UDP

ando Media Booster
"4000:TCP"= 4000:TCP:4000t
"4000:UDP"= 4000:UDP:4000u
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2009-03-04 99352]
R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2009-03-04 555032]
R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS [2009-03-04 100888]
R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2009-03-04 100888]
R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2009-03-04 566296]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
R3 XDva269;XDva269;c:\windows\system32\XDva269.sys [x]
R3 XDva277;XDva277;c:\windows\system32\XDva277.sys [x]
R4 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-05-11 79360]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS [2009-03-04 99352]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS [2009-03-04 555032]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS [2009-03-04 566296]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2006-12-31 31616]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
HKLM-Run-PCDrProfiler - (no file)
HKLM-Run-CTXFIREG - CTxfiReg.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: aol.com\free
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-12 05:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-487398202-596544020-2533468191-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
@SACL=
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\myokent.dll
c:\windows\system32\Ati2evxx.dll
c:\progra~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
- - - - - - - > 'lsass.exe'(872)
c:\windows\system32\myokent.dll
- - - - - - - > 'explorer.exe'(3340)
c:\windows\system32\myokent.dll
c:\windows\system32\hnetcfg.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\hp\KBD\kbd.exe
.
**************************************************************************
.
Completion time: 2009-09-12 5:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-12 09:54
Pre-Run: 105,822,593,024 bytes free
Post-Run: 107,604,398,080 bytes free
238 --- E O F --- 2009-05-11 20:24