ComboFix 11-03-17.02 - Administrator 03/18/2011 15:02:55.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1617 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\HPPDEVX.DLL.log
c:\windows\AnarchyIRCLib.dll
c:\windows\lsasc.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-02-18 to 2011-03-18 )))))))))))))))))))))))))))))))
.
.
2011-03-16 12:12 . 2011-03-16 12:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-03-16 09:12 . 2009-07-27 23:17 135168 -c----w- c:\windows\system32\dllcache\shsvcs.dll
2011-03-16 08:58 . 2011-03-16 08:58 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-03-15 10:33 . 2011-03-15 10:33 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2011-03-09 05:54 . 2011-02-09 13:53 270848 -c----w- c:\windows\system32\dllcache\sbe.dll
2011-03-09 05:54 . 2011-02-09 13:53 186880 -c----w- c:\windows\system32\dllcache\encdec.dll
2011-03-09 05:54 . 2011-02-02 07:58 2067456 -c----w- c:\windows\system32\dllcache\lhmstscx.dll
2011-03-09 05:54 . 2011-01-27 11:57 677888 -c----w- c:\windows\system32\dllcache\lhmstsc.exe
2011-03-04 09:52 . 2010-03-13 11:49 125952 --sha-r- c:\windows\ctxfix.exe
2011-02-28 10:42 . 2011-02-28 10:42 -------- d-----w- c:\documents and settings\Administrator\Application Data\Monotype Imaging
2011-02-28 10:34 . 2011-02-28 10:34 -------- d-----w- c:\documents and settings\LocalService\Application Data\Monotype Imaging
2011-02-28 10:33 . 2010-11-25 13:49 28672 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\TSKppr.dll
2011-02-28 10:33 . 2010-11-25 13:49 61440 ----a-w- c:\windows\system32\TSKMON.DLL
2011-02-17 10:36 . 2011-02-17 10:36 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-02-17 10:18 . 2011-02-17 10:18 -------- d-----w- c:\program files\InCode Solutions
2011-02-17 09:28 . 2010-08-27 05:57 99840 -c----w- c:\windows\system32\dllcache\srvsvc.dll
2011-02-17 09:27 . 2008-05-09 10:53 90112 -c----w- c:\windows\system32\dllcache\wshext.dll
2011-02-17 09:27 . 2008-05-09 10:53 172032 -c----w- c:\windows\system32\dllcache\scrrun.dll
2011-02-17 09:27 . 2008-05-09 10:53 180224 -c----w- c:\windows\system32\dllcache\scrobj.dll
2011-02-17 09:27 . 2008-05-09 08:45 135168 -c----w- c:\windows\system32\dllcache\cscript.exe
2011-02-17 09:27 . 2008-05-08 11:24 155648 -c----w- c:\windows\system32\dllcache\wscript.exe
2011-02-17 09:27 . 2010-11-18 18:12 81920 -c----w- c:\windows\system32\dllcache\isign32.dll
2011-02-17 09:27 . 2010-08-17 13:17 58880 -c----w- c:\windows\system32\dllcache\spoolsv.exe
2011-02-17 09:27 . 2011-01-21 14:44 439296 -c----w- c:\windows\system32\dllcache\shimgvw.dll
2011-02-17 09:26 . 2010-07-16 12:05 1288192 -c----w- c:\windows\system32\dllcache\ole32.dll
2011-02-17 09:26 . 2010-06-18 17:45 293376 -c----w- c:\windows\system32\dllcache\winsrv.dll
2011-02-17 09:25 . 2010-04-16 15:36 406016 -c----w- c:\windows\system32\dllcache\usp10.dll
2011-02-17 09:25 . 2010-11-09 14:52 249856 -c----w- c:\windows\system32\dllcache\odbc32.dll
2011-02-17 09:25 . 2010-11-09 14:52 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2011-02-17 09:25 . 2010-11-09 14:52 200704 -c----w- c:\windows\system32\dllcache\msadox.dll
2011-02-17 09:25 . 2010-11-09 14:52 180224 -c----w- c:\windows\system32\dllcache\msadomd.dll
2011-02-17 09:25 . 2010-11-09 14:52 143360 -c----w- c:\windows\system32\dllcache\msadco.dll
2011-02-17 09:25 . 2010-11-09 14:52 102400 -c----w- c:\windows\system32\dllcache\msjro.dll
2011-02-17 09:25 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-02-17 09:25 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-02-17 09:24 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-02-17 09:22 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-02-17 09:18 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-02-16 14:22 . 2011-02-16 14:22 -------- d-----w- c:\program files\UPHClean
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-09 13:53 . 2004-08-03 23:56 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-03 23:56 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2009-11-14 11:32 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-21 14:44 . 2004-08-03 23:56 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-03 23:56 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2007-03-21 10:10 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2007-03-21 10:09 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59 . 2007-03-21 10:10 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2007-03-21 10:11 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2004-08-03 23:56 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2007-03-21 10:09 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 17:09 . 2011-02-16 13:02 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2011-02-16 13:02 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-20 12:55 . 2007-03-21 10:11 385024 ----a-w- c:\windows\system32\html.iec
2010-03-13 11:49 125952 --sha-r- c:\windows\ctxfix.exe
2008-04-14 04:42 64000 --sha-r- c:\windows\system32\cleanmgr.exe
2008-04-14 04:42 180224 --sha-r- c:\windows\system32\dwwin.exe
2008-04-14 04:42 1200640 --sha-r- c:\windows\system32\ntbackup.exe
2008-04-14 04:42 380416 --sha-r- c:\windows\system32\Restore\rstrui.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-18 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-18 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-18 141848]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-03-05 1044480]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"IE7-11"="advpack.dll" [2009-03-08 128512]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 22:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 03:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTXFIXH]
2010-03-13 11:49 125952 --sha-r- c:\windows\ctxfix.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 23:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 14:50 54576 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPUsageTracking]
2008-05-07 09:38 36864 ----a-w- c:\program files\HP\HP UT\bin\hppusg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 04:42 1695232 --sh--w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToolBoxFX]
2008-04-02 11:06 53248 ----a-w- c:\program files\HP\ToolboxFX\bin\HPTLBXFX.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2004-12-20 18:41 33792 ----a-w- c:\program files\Winamp\winampa.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [11/14/2009 1:12 PM 24064]
R3 k57w2k;Broadcom NetLink (TM) Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [11/14/2009 1:32 PM 176640]
S4 gupdate;Google Update Service (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: Iz&vezi u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-HPPQVideo - c:\program files\HP\ScheduledLaunch\HP LaserJet P2050 Series\bin\hppschlnch.exe -r SOFTWARE\Hewlett-Packard\ScheduledLaunch\LJ_P2050_Series -f PQOptimizerVideo.xml
Notify-avgrsstarter - (no file)
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-18 15:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-484763869-1004336348-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,79,53,97,25,0f,b3,e8,46,be,cf,08,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,79,53,97,25,0f,b3,e8,46,be,cf,08,\
.
Completion time: 2011-03-18 15:05:28
ComboFix-quarantined-files.txt 2011-03-18 14:05
.
Pre-Run: 46,501,826,560 bytes free
Post-Run: 47,459,467,264 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30
.
- - End Of File - - F95A2842E8E3DA59723967B7FF418BD7