combofix log
ComboFix 10-09-09.03 - user 09/10/2010 18:42:52.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1526.992 [GMT -7:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100909-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\user\Application Data\facemoods.com
c:\program files\facemoods.com
c:\program files\facemoods.com\facemoods\1.4.8.1\bh\facemoods.dll
c:\program files\facemoods.com\facemoods\1.4.8.1\facemoods.crx
c:\program files\facemoods.com\facemoods\1.4.8.1\facemoods.png
c:\program files\facemoods.com\facemoods\1.4.8.1\facemoodsApp.dll
c:\program files\facemoods.com\facemoods\1.4.8.1\facemoodsEng.dll
c:\program files\facemoods.com\facemoods\1.4.8.1\facemoodssrv.exe
c:\program files\facemoods.com\facemoods\1.4.8.1\facemoodsTlbr.dll
c:\program files\facemoods.com\facemoods\1.4.8.1\uninstall.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_amsint32
((((((((((((((((((((((((( Files Created from 2010-08-11 to 2010-09-11 )))))))))))))))))))))))))))))))
.
2010-09-11 00:48 . 2010-09-11 00:48 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\AskToolbar
2010-09-10 16:13 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-10 16:13 . 2010-09-10 16:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-10 16:13 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-10 01:01 . 2010-09-10 01:01 6144 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\sp_rsdel.exe
2010-09-10 01:01 . 2010-09-10 01:01 5632 ----a-w- c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys
2010-09-10 01:01 . 2010-09-10 01:24 -------- d-----w- c:\documents and settings\user\Application Data\Spyware Terminator
2010-09-10 01:01 . 2010-09-10 01:01 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-09-10 01:01 . 2010-09-10 20:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-09-10 01:01 . 2010-09-10 01:07 -------- d-----w- c:\program files\Spyware Terminator
2010-09-09 21:34 . 2010-09-09 21:34 -------- d-----w- C:\_OTS
2010-09-09 20:08 . 2010-09-09 20:08 -------- d-----w- c:\documents and settings\user\Application Data\Malwarebytes
2010-09-09 20:08 . 2010-09-09 20:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-09 20:04 . 2010-09-09 20:04 -------- d-----w- c:\program files\Ask.com
2010-09-09 20:04 . 2010-09-09 20:04 -------- d-----w- c:\program files\BitTorrent
2010-09-09 20:04 . 2010-09-11 01:53 -------- d-----w- c:\documents and settings\user\Application Data\BitTorrent
2010-09-05 21:48 . 2010-09-05 21:48 4096 ----a-w- c:\windows\d3dx.dat
2010-09-05 21:48 . 2010-09-09 01:13 -------- d-----w- c:\documents and settings\user\Application Data\Wildfire
2010-09-05 18:58 . 2010-09-05 18:58 -------- d-----w- c:\program files\Common Files\Sandlot Shared
2010-09-05 18:58 . 2010-09-05 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Sandlot Games
2010-09-04 20:19 . 2010-09-04 20:19 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Help
2010-08-28 19:57 . 2010-09-06 19:26 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\NFS Underground 2
2010-08-28 19:57 . 2010-08-28 19:57 -------- d-----w- c:\program files\Common Files\DirectX
2010-08-28 19:13 . 2010-08-28 19:55 -------- d-----w- C:\Need for Speed Underground 2
2010-08-18 22:43 . 2008-04-14 07:21 101120 ----a-w- c:\windows\system32\drivers\bthpan.sys
2010-08-18 22:43 . 2008-04-14 07:16 59136 ----a-w- c:\windows\system32\drivers\rfcomm.sys
2010-08-18 22:43 . 2008-04-14 12:42 151552 ----a-w- c:\windows\system32\irftp.exe
2010-08-18 22:43 . 2008-04-14 12:41 28160 ----a-w- c:\windows\system32\irmon.dll
2010-08-18 22:43 . 2008-04-14 07:16 17024 ----a-w- c:\windows\system32\drivers\BthEnum.sys
2010-08-18 22:43 . 2008-04-14 12:42 8192 ----a-w- c:\windows\system32\wshirda.dll
2010-08-18 22:43 . 2008-04-14 07:16 273024 ----a-w- c:\windows\system32\drivers\bthport.sys
2010-08-18 22:43 . 2008-04-14 07:16 18944 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-09 19:53 . 2010-07-18 05:15 -------- d-----w- c:\documents and settings\user\Application Data\FrostWire
2010-09-09 00:49 . 2010-07-07 18:07 -------- d-----w- c:\program files\QuickTime
2010-09-08 18:51 . 2010-07-07 18:43 90480 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-06 23:44 . 2010-07-07 21:44 -------- d-----w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2010-08-28 18:25 . 2010-07-07 23:13 40 ----a-w- c:\windows\RSoftInfo.dat
2010-08-11 18:15 . 2010-08-11 18:14 -------- d-----w- c:\program files\RocketDock
2010-08-04 18:17 . 2010-07-08 02:29 25 ----a-w- c:\windows\popcinfot.dat
2010-07-21 22:10 . 2010-07-21 22:10 10 ----a-w- c:\windows\popcinfo.dat
2010-07-21 02:42 . 2010-07-07 18:02 -------- d-----w- c:\documents and settings\user\Application Data\Skype
2010-07-20 23:14 . 2010-07-07 18:09 -------- d-----w- c:\documents and settings\user\Application Data\Apple Computer
2010-07-20 21:12 . 2010-07-07 18:10 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-19 21:38 . 2010-07-19 21:35 -------- d-----w- c:\documents and settings\user\Application Data\Canon
2010-07-19 19:15 . 2010-07-19 19:15 -------- d-----w- c:\documents and settings\user\Application Data\Yahoo!
2010-07-18 18:39 . 2010-07-18 18:39 -------- d-----w- c:\documents and settings\user\Application Data\Media Player Classic
2010-07-18 05:04 . 2010-07-18 05:04 -------- d-----w- c:\documents and settings\user\Application Data\vlc
2010-07-14 22:32 . 2010-07-14 22:32 -------- d-----w- c:\documents and settings\user\Application Data\funkitron
2010-07-09 00:00 . 2010-07-07 17:30 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-07-07 18:09 . 2010-07-07 18:04 119986 ----a-w- c:\documents and settings\user\Application Data\Facebook\uninstall.exe
2010-07-07 18:06 . 2010-07-07 18:06 0 ----a-w- c:\windows\nsreg.dat
2010-07-07 18:03 . 2010-07-07 18:03 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-07 17:26 . 2010-07-07 17:26 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.
------- Sigcheck -------
[-] 2009-01-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 22:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinTimer"="c:\program files\Breakpoint Computers\WinTimer\WinTimer.exe" [2010-12-05 835584]
"L09AXLRD_11467890"="c:\program files\Microsoft Student\Microsoft Student with Encarta Premium 2009 DVD\EDICT.EXE" [2008-06-03 351000]
"BitTorrent"="c:\program files\BitTorrent\BitTorrent.exe" [2010-09-09 3007344]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2010-09-10 3037696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2008-07-25 868352]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-06 1922376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 114096]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 515408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]
c:\documents and settings\user\Start Menu\Programs\Startup\
Shortcut to RocketDock.exe.lnk - c:\program files\RocketDock\RocketDock.exe [2010-8-11 569344]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-18 15:58 114096 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:42 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-07-07 18:06 213488 ----atw- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 07:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2009-09-08 04:10 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2009-09-08 04:11 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2009-09-08 04:11 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-09 04:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2010-04-29 23:59 5248312 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-05 08:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2009-09-08 04:13 77824 ----a-w- c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 18:43 317672 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
2004-12-20 18:41 33792 ----a-w- c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Documents and Settings\\user\\My Documents\\Downloads\\Facemoods (5).exe"=
"\\\\Workstation1\\c\\dotahotkeys.exe"=
"c:\\Program Files\\RocketDock\\RocketDock.exe"=
"c:\\Program Files\\USB Disk Security\\USBGuard.exe"=
"c:\\Program Files\\Canon\\MyPrinter\\BJMyPrt.exe"=
"c:\\Documents and Settings\\user\\Local Settings\\Application Data\\Google\\Update\\1.2.183.29\\GoogleCrashHandler.exe"=
"c:\\WINDOWS\\notepad.exe"=
"c:\\Program Files\\BitTorrent\\BitTorrent.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Documents and Settings\\user\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\WINDOWS\\system32\\cmd.exe"=
"d:\\games\\warcraft iii\\war3.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbamgui.exe"=
"c:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe"=
"c:\\DOCUME~1\\user\\LOCALS~1\\Temp\\winhjcax.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/7/2010 11:21 AM 114768]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [9/9/2010 6:01 PM 142592]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/7/2010 11:21 AM 20560]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/10/2010 9:13 AM 304464]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/10/2010 9:13 AM 20952]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - AMSINT32
.
Contents of the 'Scheduled Tasks' folder
2010-08-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2010-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-602162358-1177238915-1003Core.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-07 18:06]
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1085031214-602162358-1177238915-1003UA.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-07 18:06]
2010-09-11 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-26 22:23]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.facemoods.com/?a=wfxt1
mStart Page = hxxp://start.facemoods.com/?a=wfxt1
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
BHO-{64182481-4F71-486b-A045-B233BD0DA8FC} - c:\program files\facemoods.com\facemoods\1.4.8.1\bh\facemoods.dll
Toolbar-{DB4E9724-F518-4dfd-9C7C-78B52103CAB9} - c:\program files\facemoods.com\facemoods\1.4.8.1\facemoodsTlbr.dll
HKLM-Run-facemoods - c:\program files\facemoods.com\facemoods\1.4.8.1\facemoodssrv.exe
AddRemove-facemoods - c:\program files\facemoods.com\facemoods\1.4.8.1\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-10 18:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2324)
c:\program files\RocketDock\RocketDock.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\docume~1\user\LOCALS~1\Temp\winhjcax.exe
.
**************************************************************************
.
Completion time: 2010-09-10 18:59:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-11 01:59
Pre-Run: 687,747,072 bytes free
Post-Run: 467,709,952 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 78273062401612D67AC663D287995B27