Combofix_021209
ComboFix 09-02-12.03 - Thomas 2009-02-12 20:41:03.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.502 [GMT -5:00]
Running from: c:\documents and settings\Thomas\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-01-13 to 2009-02-13 )))))))))))))))))))))))))))))))
.
2009-02-11 21:58 . 2009-02-11 21:58 <DIR> d-------- c:\program files\iTunes
2009-02-11 21:58 . 2009-02-11 21:58 <DIR> d-------- c:\program files\iPod
2009-02-11 21:58 . 2009-02-11 21:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-11 21:56 . 2009-02-11 21:57 <DIR> d-------- c:\program files\QuickTime
2009-02-11 21:25 . 2009-02-11 21:25 250 --a------ c:\windows\gmer.ini
2009-02-11 20:48 . 2009-02-11 20:48 <DIR> d-------- c:\program files\Bonjour
2009-02-04 19:56 . 2009-02-04 19:56 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-04 19:56 . 2009-02-04 19:56 <DIR> d-------- c:\documents and settings\Thomas\Application Data\Malwarebytes
2009-02-04 19:56 . 2009-02-04 19:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-04 19:56 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 19:56 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-03 21:52 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2009-02-03 21:51 . 2008-04-13 20:12 159,232 --a------ c:\windows\system32\ptpusd.dll
2009-01-19 15:21 . 2009-01-21 17:21 53,874 --a------ c:\windows\Sysvxd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-12 02:58 --------- d-----w c:\program files\Common Files\Apple
2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\ArcSoft
2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\Apple Computer
2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\acccore
2009-01-19 18:39 --------- d-----w c:\documents and settings\Thomas\Application Data\5000 Series
2009-01-01 04:23 --------- d-----w c:\program files\Common Files\Adobe
2008-12-31 23:39 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-31 23:39 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-31 23:38 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-12-31 23:38 60,800 ----a-w c:\windows\system32\S32EVNT1.DLL
2008-12-31 23:38 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-12-31 23:38 10,563 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-12-31 23:38 --------- d-----w c:\program files\Symantec
2008-12-31 23:35 --------- d-----w c:\program files\Common Files\Software Center
2008-12-31 23:32 --------- d-----w c:\program files\Java
2008-12-31 23:31 --------- d-----w c:\program files\HP
2008-12-31 20:53 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-21 15:58 --------- d-----w c:\documents and settings\Thomas\Application Data\U3
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-12 16:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-12-12 16:11 61,440 ----a-w c:\windows\system32\dnssd.dll
2008-02-16 19:28 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2008-10-26 17:34 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102620081027\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-31 136600]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-02-16 118784]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-01-24 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-31 99376]
S3 WlanUIG;2Wire 802.11g USB Driver;c:\windows\system32\drivers\WlanUIG.sys [2004-04-08 347648]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
*NewlyCreated* - IPOD_SERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/?src=aim
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: turbotax.com
FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\irdw59wb.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.myspace.com/
FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\irdw59wb.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07075003.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npampx3.0.84.2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-12 20:42:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-02-12 20:43:25
ComboFix-quarantined-files.txt 2009-02-13 01:43:22
Pre-Run: 101,017,546,752 bytes free
Post-Run: 101,186,351,104 bytes free
131 --- E O F --- 2009-02-12 01:50:03