combofix.txt
ComboFix 08-10-25.01 - danfarsht 2008-10-26 11:56:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.155 [GMT -6:00]
Running from: C:\Documents and Settings\danfarsht\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\danfarsht\My Documents\My Documents.url
C:\Documents and Settings\danfarsht\My Documents\My Music\My Music.url
C:\Documents and Settings\danfarsht\My Documents\My Pictures\My Pictures.url
C:\Documents and Settings\danfarsht\My Documents\My Videos\My Video.url
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\drivers\fad.sys
.
((((((((((((((((((((((((( Files Created from 2008-09-26 to 2008-10-26 )))))))))))))))))))))))))))))))
.
2008-10-23 19:08 . 2008-10-23 19:08 410,976 --a------ C:\WINDOWS\SYSTEM32\deploytk.dll
2008-10-23 19:08 . 2008-10-23 19:08 73,728 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-10-17 18:59 . 2008-10-17 18:59 <DIR> d-------- C:\rsit
2008-10-16 20:03 . 2008-10-16 20:03 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-10-16 19:53 . 2008-10-16 19:53 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-10-16 19:53 . 2008-10-16 19:53 <DIR> d-------- C:\Documents and Settings\danfarsht\Application Data\SUPERAntiSpyware.com
2008-10-16 19:53 . 2008-10-16 19:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-10-16 19:52 . 2008-10-16 19:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-15 19:07 . 2008-10-16 20:05 2,544 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2008-10-14 19:55 . 2008-10-14 19:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-12 10:06 . 2008-10-12 10:06 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-10-12 10:03 . 2008-10-12 10:03 <DIR> d-------- C:\Program Files\Webroot
2008-10-12 10:03 . 2008-10-12 10:03 <DIR> d-------- C:\Documents and Settings\danfarsht\Application Data\Webroot
2008-10-12 10:03 . 2008-10-12 10:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-10-12 10:03 . 2008-07-28 18:15 1,538,928 --a------ C:\WINDOWS\WRSetup.dll
2008-10-11 08:37 . 2008-10-14 19:26 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-28 09:40 . 2008-09-28 09:40 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 21:03 --------- d-----w C:\Program Files\Lx_cats
2008-10-24 01:08 --------- d-----w C:\Program Files\Java
2008-10-20 01:05 --------- d-----w C:\Program Files\McAfee.com
2008-10-20 01:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-10-15 16:57 332,800 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-12 02:12 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-11 14:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-03 17:41 6,066,176 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-09-16 01:36 --------- d-----w C:\Documents and Settings\danfarsht\Application Data\Viewpoint
2008-09-15 11:57 1,846,016 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys
2008-09-15 11:57 1,846,016 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys
2008-09-11 00:26 --------- d-----w C:\Documents and Settings\danfarsht\Application Data\AdobeUM
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-28 10:04 333,056 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\srv.sys
2008-08-28 08:00 74,752 ----a-w C:\WINDOWS\SYSTEM32\msw3prt.dll
2008-08-28 08:00 74,752 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msw3prt.dll
2008-08-28 08:00 104,448 ----a-w C:\WINDOWS\SYSTEM32\win32spl.dll
2008-08-28 08:00 104,448 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\win32spl.dll
2008-08-27 08:24 3,593,216 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2008-08-25 08:38 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-08-25 08:37 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-08-23 05:56 635,848 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2008-08-23 05:54 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2008-08-14 10:00 2,180,352 ----a-w C:\WINDOWS\SYSTEM32\ntoskrnl.exe
2008-08-14 10:00 2,180,352 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-08-14 09:58 2,136,064 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-08-14 09:51 138,368 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\afd.sys
2008-08-14 09:22 2,057,728 ----a-w C:\WINDOWS\SYSTEM32\ntkrnlpa.exe
2008-08-14 09:22 2,057,728 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-08-14 09:22 2,015,744 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ntkrpamp.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-14 68856]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 307200]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 126976]
"lxcqmon.exe"="C:\Program Files\Lexmark 9300 Series\lxcqmon.exe" [2006-10-23 286720]
"Lexmark 9300 Series Fax Server"="C:\Program Files\Lexmark 9300 Series\fm3032.exe" [2006-10-26 299008]
"EzPrint"="C:\Program Files\Lexmark 9300 Series\ezprint.exe" [2006-10-06 77824]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-10-23 136600]
"LXCQCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCQtime.dll" [2006-10-15 106496]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-07-28 5418864]
C:\Documents and Settings\danfarsht\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\palmOne\HOTSYNC.EXE [2004-04-13 299008]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
SideACT!.lnk - C:\Program Files\Symantec\ACT\SideACT.exe [2004-02-11 213048]
VPN Client.lnk - c:\WINDOWS\Installer\{D25122BC-A60E-4663-B602-B01718F12044}\Icon3E5562ED7.ico [2007-04-25 6144]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 01:56 15360 C:\WINDOWS\SYSTEM32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2003-08-06 01:04 114741 C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2005-10-19 07:59 126976 C:\WINDOWS\SYSTEM32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2005-10-19 07:59 155648 C:\WINDOWS\SYSTEM32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2003-10-06 10:05 53248 c:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
--a------ 2003-10-06 10:05 118784 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--------- 2003-08-26 19:47 204800 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2004-01-07 15:51 26112 C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
--a------ 2003-02-13 01:01 155648 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
"DwlClient"=C:\Program Files\Common Files\Dell\EUSW\Support.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\ICWin310\\j2re1.4.0_01\\bin\\java.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"C:\\WINDOWS\\SYSTEM32\\lxcqcoms.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
R0 ssfs0bbc;ssfs0bbc;C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys [2008-07-28 29808]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-23 152984]
R2 lxcq_device;lxcq_device;C:\WINDOWS\system32\lxcqcoms.exe [2006-11-06 532480]
.
Contents of the 'Scheduled Tasks' folder
2008-10-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-10-24 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-28 18:15]
2008-10-24 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2008-07-28 18:15]
2008-10-24 C:\WINDOWS\Tasks\wrSpySweeperFullSweep.job
- A:\","C:\","D:\","E:\","F:\" []
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-QBCMAgent - C:\Program Files\Intuit\QuickBooks Customer Manager\QBCMAgent.exe
MSConfigStartUp-VirusScan Online - c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKCU-Main,Search Page = hxxp://windiwsfsearch.com
R0 -: HKLM-Main,Search Bar =
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-26 15:05:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\SYSTEM32\INETSRV\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.exe
.
**************************************************************************
.
Completion time: 2008-10-26 19:18:39 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-27 01:17:19
Pre-Run: 44,250,796,032 bytes free
Post-Run: 44,646,064,128 bytes free
221 --- E O F --- 2008-10-25 00:01:37