ComboFix 09-01-01.02 - BridgetIrene 2009-01-02 10:57:24.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1618 [GMT -6:00]
Running from: c:\documents and settings\BridgetIrene\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090102-0] *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system32\drivers\seneka.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_seneka
((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.
2009-01-02 10:12 . 2009-01-02 10:22 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-02 10:12 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-02 10:12 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-02 01:46 . 2009-01-02 01:46 33,832 --a------ c:\windows\system32\yptmjuyf.exe
2008-12-31 10:53 . 2008-10-07 13:33 201,157 --a------ c:\windows\system32\nvapps.nvb
2008-12-31 10:52 . 2008-12-31 10:52 <DIR> d-------- C:\NVIDIA
2008-12-31 10:10 . 2008-12-31 10:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-31 10:09 . 2008-12-31 10:09 <DIR> d-------- c:\program files\Hewlett-Packard
2008-12-31 10:08 . 2007-11-06 20:10 271,704 -ra------ c:\windows\system32\hpzids01.dll
2008-12-31 10:08 . 2007-01-17 10:37 49,920 -ra------ c:\windows\system32\drivers\HPZid412.sys
2008-12-31 10:08 . 2007-01-17 10:37 16,496 -ra------ c:\windows\system32\drivers\HPZipr12.sys
2008-12-31 10:07 . 2007-10-31 04:35 729,088 -ra------ c:\windows\system32\hpwwiax4.dll
2008-12-31 10:07 . 2007-10-31 04:35 593,920 -ra------ c:\windows\system32\hpwtscl3.dll
2008-12-31 10:07 . 2007-01-17 10:37 364,544 -ra------ c:\windows\system32\hppldcoi.dll
2008-12-31 10:07 . 2007-01-17 10:37 309,760 -ra------ c:\windows\system32\difxapi.dll
2008-12-31 10:07 . 2007-01-17 10:31 294,912 -ra------ c:\windows\system32\hpovst11.dll
2008-12-31 09:59 . 2008-12-31 10:11 176,592 --a------ c:\windows\hpwins19.dat
2008-12-31 09:59 . 2008-01-07 08:08 997 -ra------ c:\windows\hpwmdl19.dat
2008-12-30 19:58 . 2008-12-30 20:04 <DIR> d-------- c:\windows\SxsCaPendDel
2008-12-23 15:14 . 2008-12-23 15:14 <DIR> d-------- c:\program files\Auslogics
2008-12-23 15:14 . 2008-12-23 15:14 <DIR> d-------- c:\documents and settings\BridgetIrene\Application Data\Auslogics
2008-12-23 13:17 . 2008-12-23 13:17 <DIR> d-------- c:\program files\CCleaner
2008-12-23 12:14 . 2008-12-23 12:14 <DIR> d-------- c:\documents and settings\BridgetIrene\Application Data\VSRevoGroup
2008-12-23 12:11 . 2008-12-23 12:11 <DIR> d-------- c:\program files\VS Revo Group
2008-12-23 10:40 . 2008-12-23 10:40 <DIR> d-------- c:\program files\CleanUp!
2008-12-21 23:47 . 2008-12-21 23:47 <DIR> d-------- c:\program files\Alwil Software
2008-12-21 23:24 . 2008-12-21 23:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2008-12-21 13:03 . 2008-12-21 13:03 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-21 13:03 . 2008-12-21 13:03 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-18 23:04 . 2008-12-18 23:04 <DIR> d-------- c:\documents and settings\BridgetIrene\Application Data\Malwarebytes
2008-12-18 23:04 . 2008-12-18 23:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-15 22:06 . 2008-12-15 22:06 <DIR> d-------- c:\program files\Trend Micro
2008-12-05 11:20 . 2008-12-05 11:37 27,769 --a------ C:\tif2pdf.jpg.0
2008-12-05 11:19 . 2008-12-05 11:36 489 --a------ c:\windows\Image2PDF.INI
2008-12-05 11:19 . 2008-12-05 11:36 56 --ah----- C:\image2pdf.ini
2008-12-05 11:18 . 2008-12-05 11:37 <DIR> d-------- c:\program files\VeryPDF Image2PDF v3.2
2008-12-05 11:18 . 2008-12-05 11:35 1,024 --a------ c:\windows\system32\Image2PDF.dat
2008-12-03 16:30 . 2008-12-03 16:30 527,254 --a------ c:\windows\FontData.fdb
2008-12-03 15:50 . 2008-12-03 16:25 2,516 --ahs---- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2008-12-03 15:50 . 2008-12-03 16:24 88 -r-hs---- c:\documents and settings\All Users\Application Data\2C41BFC2EC.sys
2008-12-03 15:40 . 2008-12-03 15:40 <DIR> d-------- c:\documents and settings\BridgetIrene\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-31 16:11 --------- d-----w c:\program files\HP
2008-12-31 16:10 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-12-31 02:38 --------- d-----w c:\program files\Common Files\HP
2008-12-21 19:03 --------- d-----w c:\program files\Java
2008-12-21 18:59 --------- d-----w c:\program files\Google
2008-12-21 18:50 --------- d-----w c:\program files\Common Files\Corel
2008-12-21 18:49 --------- d-----w c:\program files\Corel
2008-12-21 18:49 --------- d-----w c:\documents and settings\BridgetIrene\Application Data\Corel
2008-12-21 18:47 --------- d-----w c:\documents and settings\All Users\Application Data\Corel
2008-12-21 18:35 --------- d-----w c:\program files\Three Rings Design
2008-12-21 18:32 --------- d-----w c:\program files\LD Supreme
2008-12-19 05:36 --------- d-----w c:\documents and settings\BridgetIrene\Application Data\Twain
2008-12-15 18:41 --------- d-----w c:\program files\LucasArts
2008-12-15 18:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-15 18:24 --------- d-----w c:\program files\Steam
2008-12-15 18:24 --------- d-----w c:\program files\Common Files\Ahead
2008-12-15 18:24 --------- d-----w c:\program files\Ahead
2008-12-15 18:07 --------- d-----w c:\program files\Microsoft Games
2008-12-15 17:30 --------- d-----w c:\program files\GameSpy Arcade
2008-12-15 17:29 --------- d-----w c:\program files\DivX
2008-11-30 20:02 11,690 -csha-w c:\windows\system32\KGyGaAvL.sys
2008-11-30 19:17 --------- d-----w c:\documents and settings\BridgetIrene\Application Data\Yahoo!
2008-11-30 03:15 --------- d-----w c:\documents and settings\KIDS\Application Data\Yahoo!
2008-11-30 03:15 --------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-11-30 03:12 --------- d-----w c:\program files\Yahoo!
2008-11-24 02:09 --------- d-----w c:\program files\Viewpoint
2008-11-24 02:09 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 20:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 20:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 20:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-10-02 16:07 453,152 -c--a-w c:\windows\system32\NVUNINST.EXE
2008-07-13 16:39 32 -c--a-r c:\documents and settings\All Users\hash.dat
2008-09-02 12:08 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090220080903\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 c:\windows\SOUNDMAN.EXE]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-05 c:\windows\ALCWZRD.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwuSchd2.exe"=
"c:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe"=
"c:\\Program Files\\Windows Defender\\MSASCui.exe"=
"c:\\Program Files\\Adobe\\Reader 8.0\\Reader\\reader_sl.exe"=
"c:\\Program Files\\Common Files\\Ulead Systems\\AutoDetector\\Monitor.exe"=
"c:\\Program Files\\PureEdge\\Viewer 6.5\\masqform.exe"=
"c:\\WINDOWS\\ALCMTR.EXE"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-21 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-21 20560]
R2 WENCRNT4;WENCRNT4;\??\c:\windows\system32\Drivers\WENCRNT4.SYS [2007-04-27 114944]
R2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{905471f2-0c16-11dd-b6bc-0011d81a971d}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{d72454df-aeb9-11dc-b693-0011d81a971d}]
\Shell\Auto\command - J:\auto.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
\Shell\explore\Command - J:\RavMon.exe -e
\Shell\open\Command - J:\RavMon.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-01-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-01-02 c:\windows\Tasks\nojqluaz.job
- c:\windows\system32\rundll32.exe [2008-04-13 18:12]
.
- - - - ORPHANS REMOVED - - - -
Notify-hgGVpoLb - hgGVpoLb.dll
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
Trusted Zone: *.antimalwareguard.com
Trusted Zone: *.gomyhit.com
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
O16 -: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-02 10:59:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-02 11:01:04
ComboFix-quarantined-files.txt 2009-01-02 17:00:25
ComboFix2.txt 2008-12-23 00:22:37
Pre-Run: 203,841,458,176 bytes free
Post-Run: 203,827,019,776 bytes free
211 --- E O F --- 2009-01-01 20:29:43