ComboFix 09-01-06.02 - Matt 2009-01-07 11:26:45.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1441 [GMT -5:00]
Running from: c:\documents and settings\Matt\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\msvcsv60.dll
c:\windows\system32\wdmaud.sys
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((( Files Created from 2008-12-07 to 2009-01-07 )))))))))))))))))))))))))))))))
.
2009-01-02 11:28 . 2009-01-02 11:28 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-02 11:28 . 2009-01-02 11:28 1,409 --a------ c:\windows\QTFont.for
2009-01-01 14:18 . 2009-01-05 10:09 <DIR> d-------- c:\program files\My Journal
2008-12-24 14:49 . 2009-01-06 16:58 <DIR> d-------- c:\program files\EsetOnlineScanner
2008-12-24 09:48 . 2008-12-24 09:48 133,120 --a------ c:\windows\ifeqowaqifi.dll
2008-12-24 09:36 . 2008-12-24 09:36 40,448 --a------ c:\windows\Ajowofuqoqiwo.dll
2008-12-19 20:38 . 2008-12-19 20:39 <DIR> d-------- c:\program files\Magic M4A to MP3 Converter
2008-12-17 23:56 . 2008-12-17 23:56 <DIR> d-------- c:\documents and settings\LocalService\Application Data\McAfee
2008-12-11 16:14 . 2008-12-11 16:14 <DIR> d-------- c:\documents and settings\Matt\Application Data\McAfee
2008-12-08 21:38 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-08 21:38 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-08 16:22 . 2008-12-08 16:22 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-08 15:05 . 2008-12-08 15:05 <DIR> d-------- c:\windows\ERUNT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 02:38 --------- d-----w c:\documents and settings\Matt\Application Data\SendSpace Wizard
2009-01-06 18:18 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-04 23:38 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-04 23:38 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-03 21:19 --------- d-----w c:\documents and settings\Matt\Application Data\BitTorrent
2008-12-20 23:25 --------- d-----w c:\program files\ZSNES
2008-12-13 01:31 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-11 22:25 --------- d-----w c:\documents and settings\Matt\Application Data\Move Networks
2008-12-11 21:18 --------- d-----w c:\program files\Common
2008-12-11 21:13 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-11-24 19:16 27,904 ----a-w c:\windows\system32\drivers\ndisprot.sys
2008-11-23 05:35 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\GetModule
2008-11-20 21:46 --------- d-----w c:\program files\AIM
2008-11-20 21:45 --------- d-----w c:\documents and settings\Matt\Application Data\Aim
2008-11-20 21:33 --------- d-----w c:\documents and settings\Matt\Application Data\acccore
2008-11-20 21:32 --------- d-----w c:\documents and settings\All Users\Application Data\AOL OCP
2008-11-20 21:31 --------- d-----w c:\program files\AIM6
2008-11-20 21:30 --------- d-----w c:\program files\Common Files\AOL
2008-11-20 21:30 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2008-11-20 21:30 --------- d-----w c:\documents and settings\All Users\Application Data\acccore
2008-11-12 04:26 --------- d-----w c:\program files\DivX
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-10-28 22:35 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-10-28 22:35 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\DivX.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-03-03 14:44 5,606,552 ----a-w c:\program files\touchpad_driver_syn_24844A.exe
2008-09-12 14:28 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090120080908\index.dat
2008-09-12 14:28 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008091220080913\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-12-09 234856]
"E-MU USB Audio Control Panel"="c:\program files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe" [2006-11-17 274432]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-07 761946]
"Toshiba Hotkey Utility"="c:\program files\Toshiba\Windows Utilities\Hotkey.exe" [2006-08-01 1773568]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-12-06 1077322]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 122880]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 151552]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-01-04 1269392]
"McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 4838952]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"NDSTray.exe"="NDSTray.exe" [BU]
"TPSMain"="TPSMain.exe" [2005-05-31 c:\windows\system32\TPSMain.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 c:\windows\RTHDCPL.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-08-21 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=vjcprx.dll ozinwz.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"= xgusb.cpl
"midi4"= xgusb.cpl
"msacm.ac3filter"= ac3filter.acm
"aux3"= wdmaud.sys
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcsysmon.exe"=
R4 emaudsv;E-MU Audio Service;c:\windows\system32\emaudsv.exe [2006-11-20 10240]
R4 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [2006-06-28 98816]
S3 emusba10;E-MU USB-Audio 1.0 Driver;c:\windows\system32\drivers\emusba10.sys [2006-11-20 142208]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [2008-11-24 27904]
S4 OUJZPWWJ;OUJZPWWJ;\??\c:\windows\system32\drivers\OUJZPWWJ.sys --> c:\windows\system32\drivers\OUJZPWWJ.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2008-12-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-09-08 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-09-08 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORPHANS REMOVED - - - -
BHO-{207080AD-FF16-438F-A5B8-E3ED225FDDC7} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://us.mcafee.com/root/forgotPassword.asp?affid=390-6&langid=1&close=true&RW=1
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-07 11:28:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = c:\program files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(596)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\xgusb.cpl
- - - - - - - > 'lsass.exe'(652)
c:\windows\system32\xgusb.cpl
.
Completion time: 2009-01-07 11:30:20
ComboFix-quarantined-files.txt 2009-01-07 16:29:49
Pre-Run: 4,285,702,144 bytes free
Post-Run: 4,278,894,592 bytes free
174 --- E O F --- 2008-12-18 20:01:17