ComboFix 11-09-08.01 - Owner 08/09/2011 0:50.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2774 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Owner\Application Data\Adobe\plugs
c:\documents and settings\Owner\Application Data\Adobe\shed
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\SLAB.tmp.e42aac42.ini
c:\documents and settings\Owner\Local Settings\Application Data\ApplicationHistory\SLAC.tmp.28170b43.ini
c:\documents and settings\Owner\My Documents\iexplore.exe
c:\windows\system32\nvdispco3220150.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MOUSEDRIVER
.
.
((((((((((((((((((((((((( Files Created from 2011-08-08 to 2011-09-08 )))))))))))))))))))))))))))))))
.
.
2011-09-08 03:36 . 2011-09-08 03:36 12872 ----a-w- c:\windows\system32\bootdelete.exe
2011-09-08 03:26 . 2011-09-08 04:01 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-09-08 03:26 . 2011-09-08 03:26 -------- d-----w- c:\program files\Hitman Pro 3.5
2011-09-08 03:26 . 2011-09-08 03:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2011-09-08 00:48 . 2011-09-08 05:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-09-08 00:48 . 2011-09-08 00:50 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-09-07 22:52 . 2011-09-07 22:52 -------- d-----w- c:\documents and settings\Owner\Application Data\WhiteSmoke
2011-09-07 22:49 . 2011-09-07 22:49 21464 ----a-w- c:\program files\Mozilla Firefox\plc4.dll
2011-09-07 22:49 . 2011-09-07 22:49 20440 ----a-w- c:\program files\Mozilla Firefox\plds4.dll
2011-09-07 22:49 . 2011-09-07 22:49 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-09-07 22:49 . 2011-09-07 22:54 -------- d-----w- c:\program files\WhiteSmoke
2011-09-07 22:49 . 2011-09-07 22:49 712976 ----a-w- c:\program files\Mozilla Firefox\uninstall\helper.exe
2011-09-07 22:49 . 2011-09-07 22:49 166872 ----a-w- c:\program files\Mozilla Firefox\softokn3.dll
2011-09-07 22:49 . 2011-09-07 22:49 142296 ----a-w- c:\program files\Mozilla Firefox\ssl3.dll
2011-09-07 22:49 . 2011-09-07 22:49 109528 ----a-w- c:\program files\Mozilla Firefox\smime3.dll
2011-09-07 22:49 . 2011-09-07 22:49 269272 ----a-w- c:\program files\Mozilla Firefox\updater.exe
2011-09-07 22:49 . 2011-09-07 22:49 19416 ----a-w- c:\program files\Mozilla Firefox\xpcom.dll
2011-09-07 22:49 . 2011-09-07 22:49 15645656 ----a-w- c:\program files\Mozilla Firefox\xul.dll
2011-08-11 20:26 . 2011-08-11 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
2011-08-11 20:23 . 2011-08-11 20:23 -------- d-----w- c:\documents and settings\All Users\Uniblue
2011-08-11 20:23 . 2011-08-11 20:23 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\PackageAware
2011-08-11 20:20 . 2011-08-11 23:30 -------- d-----w- c:\documents and settings\Owner\Application Data\Uniblue
2011-08-11 20:20 . 2011-08-11 23:30 -------- d-----w- c:\program files\Uniblue
2011-08-11 19:47 . 2011-08-11 19:47 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Sun
2011-08-11 02:21 . 2011-08-11 02:21 -------- d-----w- c:\documents and settings\UpdatusUser\Application Data\Apple Computer
2011-08-11 01:44 . 2011-08-11 01:44 -------- d-----w- c:\program files\WinMend
2011-08-11 01:42 . 2011-09-08 01:08 -------- d-----w- c:\documents and settings\Owner\Application Data\RegClean
2011-08-10 22:17 . 2011-09-07 23:20 3064 ----a-w- c:\windows\system32\ASOROSet.bin
2011-08-10 22:12 . 2011-09-07 23:36 -------- d-----w- c:\documents and settings\Owner\Application Data\Systweak
2011-08-10 22:12 . 2011-07-07 18:26 17280 ----a-w- c:\windows\system32\roboot.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-07 19:41 . 2010-03-14 23:00 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-09-07 19:40 . 2010-03-14 23:00 202448 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-08-11 02:06 . 2010-03-10 20:49 128000 ----a-w- c:\windows\system32\javacpl.cpl
2011-08-11 02:06 . 2010-07-25 15:35 544656 ----a-w- c:\windows\system32\deployJava1.dll
2011-07-26 04:27 . 2011-06-22 01:46 403616 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-12 16:20 . 2011-07-12 16:20 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 16:20 . 2011-07-12 16:20 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-07 00:52 . 2011-07-26 04:16 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-07 00:52 . 2011-07-26 04:15 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-05 23:37 . 2011-07-05 23:37 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-05 23:37 . 2011-07-05 23:37 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-07-04 11:43 . 2010-07-04 09:58 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:43 . 2010-03-10 20:16 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-04 11:36 . 2011-07-23 06:41 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-04 11:36 . 2010-03-10 20:16 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-04 11:35 . 2010-03-10 20:16 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-04 11:35 . 2010-03-10 20:16 102616 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-07-04 11:35 . 2010-03-10 20:16 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-07-04 11:32 . 2010-03-10 20:16 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-04 11:32 . 2010-03-10 20:16 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-07-04 11:32 . 2010-03-10 20:16 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-05-04 00:02 . 2011-05-04 00:02 526208 ----a-w- c:\program files\Acoustica-Mixcraft-5-Installer.exe
2010-03-17 23:07 . 2010-03-17 23:07 7363784 -c--a-w- c:\program files\MSN-Messenger-7.0.0813.EXE
2010-03-12 03:48 . 2010-03-12 03:48 2599080 -c--a-w- c:\program files\GoogleToolbarInstaller_en32_signed.exe
2010-03-12 01:38 . 2010-03-12 01:38 8327264 -c--a-w- c:\program files\Firefox Setup 3.6.exe
2010-03-12 00:21 . 2010-03-12 00:21 98181416 -c--a-w- c:\program files\iTunesSetup.exe
2011-09-07 22:50 . 2011-09-07 22:50 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2010-02-22 18791456]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 286720]
"Nikon Transfer Monitor"="c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe" [2008-09-30 485208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-05-25 13895272]
"NvMediaCenter"="NvMCTray.dll" [2011-05-25 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-05-05 1632360]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Call of Duty\\CoDMP.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [10/03/2010 3:16 PM 309848]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [10/03/2010 3:16 PM 19544]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 3:33 AM 821664]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [26/07/2011 12:25 AM 2214504]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 2:10 AM 483688]
R2 uagqecsvc;Microsoft Forefront UAG Quarantine Enforcement Client;c:\program files\Microsoft Forefront UAG\Endpoint Components\3.1.0\uagqecsvc.exe [21/04/2011 3:58 PM 150928]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 11:23 PM 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 11:23 PM 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 11:23 PM 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 11:23 PM 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 2:10 AM 209768]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/03/2010 10:51 PM 135664]
S3 DMService;Microsoft Forefront UAG Endpoint Component Manager;c:\windows\DOWNLO~1\DMService.exe [21/04/2011 3:58 PM 487312]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [11/03/2010 10:51 PM 135664]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 10:37 PM 4640000]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [06/05/2008 5:06 PM 11520]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2011-09-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-03-12 19:44]
.
2011-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-12 03:51]
.
2011-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-12 03:51]
.
2011-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1326574676-682003330-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-27 15:36]
.
2011-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-583907252-1326574676-682003330-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-27 15:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT3007394
uInternet Settings,ProxyOverride = *.local
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
LSP: c:\progra~1\MIC3C8~1\ENDPOI~1\31265D~1.0\WhlLSP.dll
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\3gka7qed.default\
FF - prefs.js: browser.search.selectedEngine - Search the web
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-{09FF4DB8-7DE9-4D47-B7DB-915DB7D9A8CA} - c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}\bm_installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-09-08 01:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(416)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlcxcoms.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RunDLL32.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-09-08 01:10:23 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-08 06:10
.
Pre-Run: 311,448,051,712 bytes free
Post-Run: 311,299,420,160 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 083514687EFD68743A5D934BA3907946