ComboFix 09-07-14.08 - Vahab 07/15/2009 22:36.8.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.601 [GMT -5:00]
Running from: i:\documents and settings\Vahab\Desktop\ComboFix.exe
Command switches used :: i:\documents and settings\Vahab\Desktop\CFScript.txt
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
FILE ::
"i:\program files\Onlineeye\gmxffcsrv.exe"
"i:\windows\2232132.bat"
"i:\windows\system32\drivers\bvfadxvt.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
i:\windows\2232132.bat
i:\windows\system32\wbem\proquota.exe
.
--------------- FCopy ---------------
i:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\p roquota.exe --> i:\windows\system32\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GMXFWSVC
-------\Service_acvvb
-------\Service_gmxfwsvc
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.
2009-07-16 03:36 . 2008-04-14 00:12 50176 ----a-w- i:\windows\system32\proquota.exe
2009-07-08 18:59 . 2009-07-08 19:08 -------- d-----w- I:\New Folder
2009-07-08 09:46 . 2009-07-08 09:46 -------- d-----w- I:\rsit
2009-07-05 09:48 . 2009-07-05 09:48 -------- d-----w- I:\Big Bang Theory S02 Full
2009-06-23 20:01 . 2009-06-23 20:50 -------- d-----w- I:\Ben Kweller - Changing Horses - 2009 (rhsiv)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 00:49 . 2008-05-08 04:14 1878984 ----a-w- i:\documents and settings\Vahab\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-07-15 21:12 . 2008-07-01 12:44 -------- d-----w- i:\documents and settings\All Users\Application Data\Google Updater
2009-07-08 08:45 . 2008-12-19 21:24 -------- d-----w- i:\program files\Malwarebytes' Anti-Malware
2009-07-08 08:45 . 2009-03-01 18:24 3561743 ----a-w- i:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-17 16:27 . 2008-12-19 21:24 38160 ----a-w- i:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 16:27 . 2008-12-19 21:24 19096 ----a-w- i:\windows\system32\drivers\mbam.sys
2009-06-10 19:00 . 2009-05-07 19:23 1290584 ----a-w- i:\documents and settings\All Users\Application Data\Symantec\SyKnAppS\SyKnAppS.dll
2009-06-10 19:00 . 2009-05-07 19:23 149768 ----a-w- i:\windows\system32\drivers\WpsHelper.sys
2009-06-10 14:42 . 2008-09-15 01:27 -------- d-----w- i:\program files\SUPERAntiSpyware
2009-06-10 13:36 . 2009-06-10 13:33 -------- d-----w- i:\program files\Common Files\Symantec Shared
2009-06-10 13:36 . 2009-06-10 13:33 -------- d-----w- i:\documents and settings\All Users\Application Data\Symantec
2009-06-10 13:35 . 2009-06-10 13:33 -------- d-----w- i:\program files\Symantec
2009-06-10 13:35 . 2009-06-10 13:34 805 ----a-w- i:\windows\system32\drivers\SYMEVENT.INF
2009-06-10 13:35 . 2009-06-10 13:34 60800 ----a-w- i:\windows\system32\S32EVNT1.DLL
2009-06-10 13:35 . 2009-06-10 13:34 123952 ----a-w- i:\windows\system32\drivers\SYMEVENT.SYS
2009-06-10 13:35 . 2009-06-10 13:34 10563 ----a-w- i:\windows\system32\drivers\SYMEVENT.CAT
2009-05-24 21:38 . 2008-03-25 05:26 -------- d-----w- i:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-22 17:53 . 2009-04-22 17:53 107088 ----a-w- i:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-22 17:48 . 2009-04-22 17:45 52770576 ----a-w- i:\documents and settings\Vahab\Application Data\Sony Setup\64993CD0-67D1-4244-A2BC-FD73F4DA5B62\dotnetfx3.exe
2009-04-18 07:52 . 2009-04-09 02:30 0 ----a-w- i:\windows\Lmeci.bin
2008-05-30 19:37 . 2008-05-30 19:37 148847 ----a-w- i:\program files\DEC2006_XACT_x86.cab
2008-05-30 19:36 . 2008-05-30 19:36 13267416 ----a-w- i:\program files\dxnt.cab
2008-05-30 19:36 . 2008-05-30 19:36 4165878 ----a-w- i:\program files\Apr2006_MDX1_x86_Archive.cab
2008-05-30 19:36 . 2008-05-30 19:36 1805306 ----a-w- i:\program files\Nov2007_d3dx9_36_x64.cab
2008-05-30 19:36 . 2008-05-30 19:36 1803408 ----a-w- i:\program files\AUG2007_d3dx9_35_x64.cab
2008-05-30 19:34 . 2008-05-30 19:34 528392 ----a-w- i:\program files\DXSETUP.exe
2009-04-02 01:04 . 2009-04-02 01:04 61038 ----a-w- i:\program files\mozilla firefox\components\jar50.dll
2009-04-02 01:04 . 2009-04-02 01:04 49256 ----a-w- i:\program files\mozilla firefox\components\jsd3250.dll
2009-04-02 01:04 . 2009-04-02 01:04 166000 ----a-w- i:\program files\mozilla firefox\components\xpinstal.dll
.
------- Sigcheck -------
[7] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 i:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[7] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 i:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 i:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D i:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E i:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2004-08-04 04:14 359040 9F4B36614A0FC234525BA224957DE55C i:\windows\$NtUninstallKB917953$\tcpip.sys
[7] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 i:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2008-07-08 03:23 360064 90CAFF4B094573449A0872A0F919B178 i:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 i:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\t cpip.sys
[-] 2008-10-22 03:11 360320 3ADCE4790F591BF160A94F6F08039577 i:\windows\system32\dllcache\TCPIP.SYS
[-] 2008-10-22 03:11 360320 3ADCE4790F591BF160A94F6F08039577 i:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( SnapShot@2009-07-08_19.21.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-16 03:45 . 2009-07-16 03:45 16384 i:\windows\Temp\Perflib_Perfdata_7f0.dat
+ 2009-07-16 03:45 . 2009-07-16 03:45 16384 i:\windows\Temp\Perflib_Perfdata_5a8.dat
+ 2009-07-14 06:58 . 2009-07-15 21:16 32768 i:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-10-06 00:45 . 2009-07-15 21:16 32768 i:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-06 00:45 . 2009-07-08 17:24 32768 i:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-10-06 00:45 . 2009-07-15 21:16 32768 i:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-10-06 00:45 . 2009-07-08 17:24 32768 i:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2004-03-11 4841472]
"LVCOMS"="i:\program files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022]
"LogitechGalleryRepair"="i:\program files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 155648]
"LogitechImageStudioTray"="i:\program files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 61440]
"TkBellExe"="i:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-11-21 180269]
"VAIO Update 3"="i:\program files\Sony\VAIO Update 3\VAIOUpdt.exe" [2007-05-16 551032]
"SunJavaUpdateSched"="i:\program files\Java\jre6\bin\jusched.exe" [2008-08-25 144792]
"QuickTime Task"="i:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"Adobe Reader Speed Launcher"="i:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"ccApp"="i:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-05-07 115560]
"AGRSMMSG"="AGRSMMSG.exe" - i:\windows\AGRSMMSG.exe [2003-05-23 88363]
"BluetoothAuthenticationAgent"="bthprops.cpl" - i:\windows\system32\bthprops.cpl [2004-08-04 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="i:\program files\MySpace\IM\MySpaceIM.exe" [2008-02-01 8699904]
i:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - i:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\expl orer]
"NoSetActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtM gr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetM gr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symant ec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"i:\\Program Files\\AIM\\aim.exe"=
"i:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"i:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"i:\\Program Files\\BitLord\\BitLord.exe"=
"i:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"i:\\Program Files\\MSN Messenger\\livecall.exe"=
"i:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"i:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"i:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"i:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"i:\\WINDOWS\\system32\\spoolsv.exe"=
"i:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"i:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"i:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"i:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"8085:TCP"= 8085:TCP:sys
R2 Viewpoint Manager Service;Viewpoint Manager Service;i:\program files\Viewpoint\Common\ViewpointService.exe [10/6/2007 1:26 PM 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;i:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/24/2009 8:36 PM 101936]
S3 COH_Mon;COH_Mon;i:\windows\system32\drivers\COH_Mon.sys [5/7/2009 2:23 PM 23888]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
szwnxoys
.
Contents of the 'Scheduled Tasks' folder
2009-06-30 i:\windows\Tasks\AppleSoftwareUpdate.job
- i:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:57]
2009-07-16 i:\windows\Tasks\Google Software Updater.job
- i:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-16 07:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
FF - ProfilePath - i:\documents and settings\Vahab\Application Data\Mozilla\Firefox\Profiles\djbdybif.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.google.com
FF - component: i:\program files\Mozilla Firefox\components\xpinstal.dll
---- FIREFOX POLICIES ----
i:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
i:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
i:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
i:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
i:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-15 22:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(840)
i:\windows\system32\WPDShServiceObj.dll
i:\windows\system32\PortableDeviceTypes.dll
i:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
i:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
i:\program files\Common Files\Symantec Shared\ccSvcHst.exe
i:\program files\Bonjour\mDNSResponder.exe
i:\program files\Java\jre6\bin\jqs.exe
i:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
i:\windows\system32\nvsvc32.exe
i:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
i:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
i:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-16 22:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-16 03:50
ComboFix2.txt 2009-07-13 04:26
ComboFix3.txt 2009-07-08 19:26
Pre-Run: 4,737,982,464 bytes free
Post-Run: 4,718,559,232 bytes free
207 --- E O F --- 2009-02-12 07:37