ComboFix 12-03-08.01 - Owner 03/08/2012 16:35:02.6.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2887 [GMT -5:00]
Running from: c:\documents and settings\Owner\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-02-08 to 2012-03-08 )))))))))))))))))))))))))))))))
.
.
2012-03-08 08:28 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-03-08 08:27 . 2011-12-17 19:46 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-03-08 08:27 . 2011-12-17 19:46 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-03-08 08:27 . 2011-12-17 19:46 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-03-08 08:25 . 2012-03-08 08:27 -------- dc-h--w- c:\windows\ie8
2012-03-07 22:33 . 2009-11-27 16:07 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll
2012-03-07 22:33 . 2009-11-27 16:07 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll
2012-03-07 22:32 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2012-03-07 22:27 . 2011-10-25 13:37 2148864 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2012-03-07 22:27 . 2011-10-25 13:33 2192768 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2012-03-07 22:27 . 2011-10-25 12:52 2069376 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2012-03-07 22:27 . 2011-10-25 12:52 2027008 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2012-03-07 22:24 . 2012-01-11 19:06 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-03-07 22:24 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-03-07 22:10 . 2008-04-14 08:00 42496 -c--a-w- c:\windows\system32\dllcache\davcdata.exe
2012-03-07 22:03 . 2008-04-14 08:00 281088 -c--a-w- c:\windows\system32\dllcache\pinball.exe
2012-03-07 22:03 . 2008-04-14 08:00 281088 ----a-w- c:\program files\Windows NT\pinball\PINBALL.EXE
2012-03-07 22:03 . 2008-04-14 08:00 131584 -c--a-w- c:\windows\system32\dllcache\sndrec32.exe
2012-03-07 22:03 . 2008-04-14 08:00 131584 ----a-w- c:\windows\system32\sndrec32.exe
2012-03-07 22:03 . 2009-12-16 18:43 343040 -c--a-w- c:\windows\system32\dllcache\mspaint.exe
2012-03-07 22:03 . 2009-12-16 18:43 343040 ----a-w- c:\windows\system32\mspaint.exe
2012-03-07 22:03 . 2008-04-14 08:00 539136 -c--a-w- c:\windows\system32\dllcache\dialer.exe
2012-03-07 22:03 . 2008-04-14 08:00 539136 ----a-w- c:\program files\Windows NT\dialer.exe
2012-03-07 22:03 . 2008-04-14 08:00 538624 -c--a-w- c:\windows\system32\dllcache\spider.exe
2012-03-07 22:03 . 2008-04-14 08:00 538624 ----a-w- c:\windows\system32\spider.exe
2012-03-07 22:03 . 2008-04-14 08:00 347136 ----a-w- c:\windows\system32\hypertrm.dll
2012-03-07 21:35 . 2008-04-14 08:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2012-03-07 21:35 . 2008-04-14 08:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2012-03-07 21:35 . 2008-04-14 08:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2012-03-07 21:35 . 2008-04-14 08:00 13312 ----a-w- c:\windows\system32\irclass.dll
2012-03-07 21:35 . 2008-04-14 08:00 16535 ----a-r- c:\windows\SET169.tmp
2012-03-07 21:35 . 2008-04-14 08:00 1088840 ----a-r- c:\windows\SET163.tmp
2012-03-07 21:35 . 2008-04-14 08:00 1296669 ----a-r- c:\windows\SET160.tmp
2012-03-07 13:04 . 2009-11-27 17:23 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll
2012-03-06 00:27 . 2012-03-06 00:27 -------- d-----w- C:\_OTL
2012-03-04 21:32 . 2012-03-04 21:32 -------- d-----w- c:\windows\system32\LogFiles
2012-03-03 19:55 . 2012-03-03 19:55 -------- d-----w- C:\TDSSKiller_Quarantine
2012-03-02 16:25 . 2012-03-02 16:25 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2012-03-02 16:25 . 2012-03-02 16:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-03-02 16:25 . 2012-03-02 16:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-02 16:25 . 2011-12-10 20:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- c:\program files\Download Manager
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\DownloadManager
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- c:\program files\Surf Canyon
2012-02-29 17:42 . 2012-02-29 17:52 -------- d-----w- c:\program files\RebateRobot
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- C:\skin
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- C:\defaults
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- C:\content
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\I Want This
2012-02-29 17:41 . 2012-03-07 22:37 -------- d-----w- c:\program files\I Want This
2012-02-27 21:04 . 2012-01-11 19:56 574424 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2012-02-27 21:04 . 2012-01-11 19:56 54328 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2012-02-27 21:04 . 2012-01-11 19:56 35264 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2012-02-27 21:00 . 2011-09-28 18:14 56840 ----a-w- c:\windows\system32\drivers\PCTBD.sys
2012-02-27 21:00 . 2012-01-11 21:19 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2012-02-27 21:00 . 2012-01-11 21:17 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys
2012-02-27 20:58 . 2012-02-27 20:58 -------- d-----w- c:\documents and settings\Owner\Application Data\TestApp
2012-02-10 19:59 . 2012-02-10 19:59 45056 ----a-w- c:\windows\scluins1.exe
2012-02-10 19:59 . 2012-02-10 19:59 36864 ----a-w- c:\windows\smon03.exe
2012-02-10 19:58 . 2012-02-10 21:22 -------- d-----w- c:\program files\Sophocles
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-27 20:31 . 2012-02-27 20:31 1182680 ----a-w- c:\windows\system32\drivers\TfKbMon.sys.old
2012-01-16 21:28 . 2011-06-24 19:16 149456 ----a-w- c:\windows\SGDetectionTool.dll
2012-01-16 21:28 . 2011-06-24 19:16 2246608 ----a-w- c:\windows\PCTBDCore.dll
2012-01-16 21:28 . 2011-06-24 19:16 1681360 ----a-w- c:\windows\PCTBDRes.dll
2012-01-16 21:28 . 2011-06-24 19:16 767952 ----a-w- c:\windows\BDTSupport.dll
2012-01-12 16:53 . 2008-04-14 08:00 1859968 ----a-w- c:\windows\system32\win32k.sys
2012-01-11 21:19 . 2011-06-24 18:33 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2012-01-11 21:14 . 2011-06-24 18:33 253352 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-12-17 19:46 . 2008-07-12 19:10 43520 ------w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2008-04-23 00:16 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2008-04-23 00:16 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2008-07-12 19:09 385024 ------w- c:\windows\system32\html.iec
1997-07-22 00:30 1045776 --sha-w- c:\windows\system32\Msjet35.dll
1997-06-23 08:00 123664 --sha-w- c:\windows\system32\Msjint35.dll
1997-06-23 17:06 24848 --sha-w- c:\windows\system32\Msjter35.dll
1997-06-23 17:06 252176 --sha-w- c:\windows\system32\Msrd2x35.dll
1997-06-23 17:06 287504 --sha-w- c:\windows\system32\Msxbse35.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[7] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot_2012-03-08_13.05.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-03-08 21:33 . 2012-03-08 21:33 16384 c:\windows\Temp\Perflib_Perfdata_5f8.dat
+ 2012-03-08 21:33 . 2012-03-08 21:33 16384 c:\windows\Temp\Perflib_Perfdata_238.dat
+ 2008-04-14 11:00 . 2012-03-08 21:38 72452 c:\windows\system32\perfc009.dat
- 2008-04-14 11:00 . 2012-03-08 12:53 72452 c:\windows\system32\perfc009.dat
- 2008-04-14 08:00 . 2008-04-14 08:00 62976 c:\windows\system32\drivers\cdrom.sys
+ 2008-04-14 08:00 . 2008-04-14 05:10 62976 c:\windows\system32\drivers\cdrom.sys
+ 2008-04-14 08:00 . 2008-04-14 05:10 62976 c:\windows\system32\dllcache\cdrom.sys
- 2008-04-14 11:00 . 2012-03-08 12:53 444702 c:\windows\system32\perfh009.dat
+ 2008-04-14 11:00 . 2012-03-08 21:38 444702 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66616350-A70C-4FF5-912E-A92B8076F6F7}]
c:\program files\RebateRobot\RebateRobot.dll [BU]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2011-05-09 08:49 176936 ----a-w- c:\program files\DVDVideoSoftTB\prxtbDVDV.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E5C66DD8-308B-4a4f-AF0A-3D04F25B5343}]
2009-11-07 06:07 297808 ----a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-01-22 2363392]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 313472]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2011-08-22 6276408]
"DownloadManager"="c:\program files\Download Manager\DownloadManager.exe" [2012-02-29 654336]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2010-10-19 1439496]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"nwiz"="nwiz.exe" [BU]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-11-21 110184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-21 12669544]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 18 (0x12)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
"1947:TCP"= 1947:TCP:HASP SRM
"1947:UDP"= 1947:UDP:HASP SRM
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [6/24/2011 1:33 PM 331880]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [6/24/2011 1:33 PM 342168]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [6/24/2011 1:33 PM 909728]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2/27/2012 4:04 PM 54328]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2/27/2012 4:04 PM 574424]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [6/24/2011 1:33 PM 253352]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2/27/2012 4:00 PM 185560]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [6/24/2011 2:16 PM 546768]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3/2/2012 11:25 AM 652360]
R2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe [1/27/2011 4:13 PM 226624]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [3/2/2012 11:25 AM 20464]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [9/15/2009 2:59 PM 38248]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [2/9/2010 5:59 PM 47360]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [2/27/2012 4:00 PM 56840]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [10/19/2009 2:29 AM 9472]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2011 3:42 PM 136176]
S2 QuickBooksDB17;QuickBooksDB17;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 --> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 [?]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [10/2/2011 9:24 AM 6016]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2011 3:42 PM 136176]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [10/2/2011 9:24 AM 20352]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [10/2/2011 9:24 AM 8320]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [10/2/2011 9:24 AM 23424]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [10/2/2011 9:24 AM 9472]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [6/24/2011 1:33 PM 70536]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [6/24/2011 1:32 PM 402336]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2/27/2012 4:04 PM 35264]
S3 ThreatFire;ThreatFire;c:\program files\PC Tools Security\TFEngine\TFService.exe service --> c:\program files\PC Tools Security\TFEngine\TFService.exe service [?]
S4 QuickBooksDB20;QuickBooksDB20;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 --> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [?]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-01-22 16:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2012-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-19 20:42]
.
2012-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-19 20:42]
.
2012-03-08 c:\windows\Tasks\MotoHelper Initial Update.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-02-29 c:\windows\Tasks\MotoHelper MUM.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-03-08 c:\windows\Tasks\MotoHelper Routing.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-02-29 c:\windows\Tasks\MotoHelper Update.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-03-07 c:\windows\Tasks\User_Feed_Synchronization-{D34A4223-3F9E-489B-8675-157936D04B47}.job
- c:\windows\system32\msfeedssync.exe [2008-07-12 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyOverride = *.local;192.168.*.*
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\wykhr570.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2086743&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Search Defender
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2086743&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20111124&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: PHPNukeEN Toolbar: {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - c:\program files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Browser Defender Toolbar: {cb84136f-9c44-433a-9048-c5cd9df1dc16} - c:\program files\PC Tools Security\BDT\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: FreeSoundRecorder Community Toolbar: {32b29df0-2237-4370-9a29-37cebb730e9b} - %profile%\extensions\{32b29df0-2237-4370-9a29-37cebb730e9b}
FF - Ext: DVDVideoSoftTB Community Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
FF - Ext: I Want This: crossriderapp2258@crossrider.com - %profile%\extensions\crossriderapp2258@crossrider.com
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-08 16:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(832)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'lsass.exe'(896)
c:\windows\system32\nvLsp.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2012-03-08 16:56:49
ComboFix-quarantined-files.txt 2012-03-08 21:56
ComboFix2.txt 2012-03-08 13:11
ComboFix3.txt 2012-01-01 16:23
ComboFix4.txt 2011-12-26 18:00
.
Pre-Run: 137,629,929,472 bytes free
Post-Run: 137,634,775,040 bytes free
.
- - End Of File - - B94A256742B1EAB7D9C404C2AA141899
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2887 [GMT -5:00]
Running from: c:\documents and settings\Owner\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-02-08 to 2012-03-08 )))))))))))))))))))))))))))))))
.
.
2012-03-08 08:28 . 2011-08-16 10:45 6144 -c----w- c:\windows\system32\dllcache\iecompat.dll
2012-03-08 08:27 . 2011-12-17 19:46 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2012-03-08 08:27 . 2011-12-17 19:46 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2012-03-08 08:27 . 2011-12-17 19:46 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2012-03-08 08:25 . 2012-03-08 08:27 -------- dc-h--w- c:\windows\ie8
2012-03-07 22:33 . 2009-11-27 16:07 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll
2012-03-07 22:33 . 2009-11-27 16:07 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll
2012-03-07 22:32 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2012-03-07 22:27 . 2011-10-25 13:37 2148864 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2012-03-07 22:27 . 2011-10-25 13:33 2192768 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2012-03-07 22:27 . 2011-10-25 12:52 2069376 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2012-03-07 22:27 . 2011-10-25 12:52 2027008 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2012-03-07 22:24 . 2012-01-11 19:06 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2012-03-07 22:24 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-03-07 22:10 . 2008-04-14 08:00 42496 -c--a-w- c:\windows\system32\dllcache\davcdata.exe
2012-03-07 22:03 . 2008-04-14 08:00 281088 -c--a-w- c:\windows\system32\dllcache\pinball.exe
2012-03-07 22:03 . 2008-04-14 08:00 281088 ----a-w- c:\program files\Windows NT\pinball\PINBALL.EXE
2012-03-07 22:03 . 2008-04-14 08:00 131584 -c--a-w- c:\windows\system32\dllcache\sndrec32.exe
2012-03-07 22:03 . 2008-04-14 08:00 131584 ----a-w- c:\windows\system32\sndrec32.exe
2012-03-07 22:03 . 2009-12-16 18:43 343040 -c--a-w- c:\windows\system32\dllcache\mspaint.exe
2012-03-07 22:03 . 2009-12-16 18:43 343040 ----a-w- c:\windows\system32\mspaint.exe
2012-03-07 22:03 . 2008-04-14 08:00 539136 -c--a-w- c:\windows\system32\dllcache\dialer.exe
2012-03-07 22:03 . 2008-04-14 08:00 539136 ----a-w- c:\program files\Windows NT\dialer.exe
2012-03-07 22:03 . 2008-04-14 08:00 538624 -c--a-w- c:\windows\system32\dllcache\spider.exe
2012-03-07 22:03 . 2008-04-14 08:00 538624 ----a-w- c:\windows\system32\spider.exe
2012-03-07 22:03 . 2008-04-14 08:00 347136 ----a-w- c:\windows\system32\hypertrm.dll
2012-03-07 21:35 . 2008-04-14 08:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2012-03-07 21:35 . 2008-04-14 08:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2012-03-07 21:35 . 2008-04-14 08:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2012-03-07 21:35 . 2008-04-14 08:00 13312 ----a-w- c:\windows\system32\irclass.dll
2012-03-07 21:35 . 2008-04-14 08:00 16535 ----a-r- c:\windows\SET169.tmp
2012-03-07 21:35 . 2008-04-14 08:00 1088840 ----a-r- c:\windows\SET163.tmp
2012-03-07 21:35 . 2008-04-14 08:00 1296669 ----a-r- c:\windows\SET160.tmp
2012-03-07 13:04 . 2009-11-27 17:23 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll
2012-03-06 00:27 . 2012-03-06 00:27 -------- d-----w- C:\_OTL
2012-03-04 21:32 . 2012-03-04 21:32 -------- d-----w- c:\windows\system32\LogFiles
2012-03-03 19:55 . 2012-03-03 19:55 -------- d-----w- C:\TDSSKiller_Quarantine
2012-03-02 16:25 . 2012-03-02 16:25 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2012-03-02 16:25 . 2012-03-02 16:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-03-02 16:25 . 2012-03-02 16:25 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-02 16:25 . 2011-12-10 20:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- c:\program files\Download Manager
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\DownloadManager
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- c:\program files\Surf Canyon
2012-02-29 17:42 . 2012-02-29 17:52 -------- d-----w- c:\program files\RebateRobot
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- C:\skin
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- C:\defaults
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- C:\content
2012-02-29 17:42 . 2012-02-29 17:42 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\I Want This
2012-02-29 17:41 . 2012-03-07 22:37 -------- d-----w- c:\program files\I Want This
2012-02-27 21:04 . 2012-01-11 19:56 574424 --s---w- c:\windows\system32\drivers\TfSysMon.sys
2012-02-27 21:04 . 2012-01-11 19:56 54328 --s---w- c:\windows\system32\drivers\TfFsMon.sys
2012-02-27 21:04 . 2012-01-11 19:56 35264 --s---w- c:\windows\system32\drivers\TfNetMon.sys
2012-02-27 21:00 . 2011-09-28 18:14 56840 ----a-w- c:\windows\system32\drivers\PCTBD.sys
2012-02-27 21:00 . 2012-01-11 21:19 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2012-02-27 21:00 . 2012-01-11 21:17 17848 ----a-w- c:\windows\system32\drivers\pctBTFix.sys
2012-02-27 20:58 . 2012-02-27 20:58 -------- d-----w- c:\documents and settings\Owner\Application Data\TestApp
2012-02-10 19:59 . 2012-02-10 19:59 45056 ----a-w- c:\windows\scluins1.exe
2012-02-10 19:59 . 2012-02-10 19:59 36864 ----a-w- c:\windows\smon03.exe
2012-02-10 19:58 . 2012-02-10 21:22 -------- d-----w- c:\program files\Sophocles
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-27 20:31 . 2012-02-27 20:31 1182680 ----a-w- c:\windows\system32\drivers\TfKbMon.sys.old
2012-01-16 21:28 . 2011-06-24 19:16 149456 ----a-w- c:\windows\SGDetectionTool.dll
2012-01-16 21:28 . 2011-06-24 19:16 2246608 ----a-w- c:\windows\PCTBDCore.dll
2012-01-16 21:28 . 2011-06-24 19:16 1681360 ----a-w- c:\windows\PCTBDRes.dll
2012-01-16 21:28 . 2011-06-24 19:16 767952 ----a-w- c:\windows\BDTSupport.dll
2012-01-12 16:53 . 2008-04-14 08:00 1859968 ----a-w- c:\windows\system32\win32k.sys
2012-01-11 21:19 . 2011-06-24 18:33 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2012-01-11 21:14 . 2011-06-24 18:33 253352 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-12-17 19:46 . 2008-07-12 19:10 43520 ------w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2008-04-23 00:16 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2008-04-23 00:16 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2008-07-12 19:09 385024 ------w- c:\windows\system32\html.iec
1997-07-22 00:30 1045776 --sha-w- c:\windows\system32\Msjet35.dll
1997-06-23 08:00 123664 --sha-w- c:\windows\system32\Msjint35.dll
1997-06-23 17:06 24848 --sha-w- c:\windows\system32\Msjter35.dll
1997-06-23 17:06 252176 --sha-w- c:\windows\system32\Msrd2x35.dll
1997-06-23 17:06 287504 --sha-w- c:\windows\system32\Msxbse35.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[7] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\ERDNT\cache\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot_2012-03-08_13.05.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-03-08 21:33 . 2012-03-08 21:33 16384 c:\windows\Temp\Perflib_Perfdata_5f8.dat
+ 2012-03-08 21:33 . 2012-03-08 21:33 16384 c:\windows\Temp\Perflib_Perfdata_238.dat
+ 2008-04-14 11:00 . 2012-03-08 21:38 72452 c:\windows\system32\perfc009.dat
- 2008-04-14 11:00 . 2012-03-08 12:53 72452 c:\windows\system32\perfc009.dat
- 2008-04-14 08:00 . 2008-04-14 08:00 62976 c:\windows\system32\drivers\cdrom.sys
+ 2008-04-14 08:00 . 2008-04-14 05:10 62976 c:\windows\system32\drivers\cdrom.sys
+ 2008-04-14 08:00 . 2008-04-14 05:10 62976 c:\windows\system32\dllcache\cdrom.sys
- 2008-04-14 11:00 . 2012-03-08 12:53 444702 c:\windows\system32\perfh009.dat
+ 2008-04-14 11:00 . 2012-03-08 21:38 444702 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66616350-A70C-4FF5-912E-A92B8076F6F7}]
c:\program files\RebateRobot\RebateRobot.dll [BU]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2011-05-09 08:49 176936 ----a-w- c:\program files\DVDVideoSoftTB\prxtbDVDV.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E5C66DD8-308B-4a4f-AF0A-3D04F25B5343}]
2009-11-07 06:07 297808 ----a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\prxtbDVDV.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2010-01-22 2363392]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 313472]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2011-08-22 6276408]
"DownloadManager"="c:\program files\Download Manager\DownloadManager.exe" [2012-02-29 654336]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2010-10-19 1439496]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"nwiz"="nwiz.exe" [BU]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-11-21 110184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-21 12669544]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 18 (0x12)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
"1947:TCP"= 1947:TCP:HASP SRM
"1947:UDP"= 1947:UDP:HASP SRM
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [6/24/2011 1:33 PM 331880]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [6/24/2011 1:33 PM 342168]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [6/24/2011 1:33 PM 909728]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2/27/2012 4:04 PM 54328]
R0 TFSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2/27/2012 4:04 PM 574424]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [6/24/2011 1:33 PM 253352]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [2/27/2012 4:00 PM 185560]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [6/24/2011 2:16 PM 546768]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3/2/2012 11:25 AM 652360]
R2 MotoHelper;MotoHelper Service;c:\program files\Motorola\MotoHelper\MotoHelperService.exe [1/27/2011 4:13 PM 226624]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [3/2/2012 11:25 AM 20464]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [9/15/2009 2:59 PM 38248]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [2/9/2010 5:59 PM 47360]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [2/27/2012 4:00 PM 56840]
S1 DumpDrv;Crash Dump Driver;c:\windows\system32\drivers\dumpdrv.sys [10/19/2009 2:29 AM 9472]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2011 3:42 PM 136176]
S2 QuickBooksDB17;QuickBooksDB17;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 --> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 [?]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [10/2/2011 9:24 AM 6016]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2011 3:42 PM 136176]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [10/2/2011 9:24 AM 20352]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [10/2/2011 9:24 AM 8320]
S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [10/2/2011 9:24 AM 23424]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [10/2/2011 9:24 AM 9472]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [6/24/2011 1:33 PM 70536]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [6/24/2011 1:32 PM 402336]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2/27/2012 4:04 PM 35264]
S3 ThreatFire;ThreatFire;c:\program files\PC Tools Security\TFEngine\TFService.exe service --> c:\program files\PC Tools Security\TFEngine\TFService.exe service [?]
S4 QuickBooksDB20;QuickBooksDB20;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 --> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB20 [?]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-01-22 16:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2012-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-19 20:42]
.
2012-03-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-19 20:42]
.
2012-03-08 c:\windows\Tasks\MotoHelper Initial Update.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-02-29 c:\windows\Tasks\MotoHelper MUM.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-03-08 c:\windows\Tasks\MotoHelper Routing.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-02-29 c:\windows\Tasks\MotoHelper Update.job
- c:\program files\Motorola\MotoHelper\MotoHelperUpdate.exe [2011-01-27 21:14]
.
2012-03-07 c:\windows\Tasks\User_Feed_Synchronization-{D34A4223-3F9E-489B-8675-157936D04B47}.job
- c:\windows\system32\msfeedssync.exe [2008-07-12 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyOverride = *.local;192.168.*.*
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\wykhr570.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2086743&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Search Defender
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2086743&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20111124&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: PHPNukeEN Toolbar: {dd02a4eb-4afd-4d60-99d8-e67f964ca813} - c:\program files\Mozilla Firefox\extensions\{dd02a4eb-4afd-4d60-99d8-e67f964ca813}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Browser Defender Toolbar: {cb84136f-9c44-433a-9048-c5cd9df1dc16} - c:\program files\PC Tools Security\BDT\Firefox
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: FreeSoundRecorder Community Toolbar: {32b29df0-2237-4370-9a29-37cebb730e9b} - %profile%\extensions\{32b29df0-2237-4370-9a29-37cebb730e9b}
FF - Ext: DVDVideoSoftTB Community Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - %profile%\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
FF - Ext: I Want This: crossriderapp2258@crossrider.com - %profile%\extensions\crossriderapp2258@crossrider.com
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-08 16:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(832)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'lsass.exe'(896)
c:\windows\system32\nvLsp.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Completion time: 2012-03-08 16:56:49
ComboFix-quarantined-files.txt 2012-03-08 21:56
ComboFix2.txt 2012-03-08 13:11
ComboFix3.txt 2012-01-01 16:23
ComboFix4.txt 2011-12-26 18:00
.
Pre-Run: 137,629,929,472 bytes free
Post-Run: 137,634,775,040 bytes free
.
- - End Of File - - B94A256742B1EAB7D9C404C2AA141899