ComboFix 09-07-09.06 - Wanda_2 07/09/2009 18:39.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1982.1328 [GMT -4:00]
Running from: c:\documents and settings\Wanda_2\Desktop\ComboFix.exe
AV: Avanquest VirusScanner Pro *On-access scanning enabled* (Updated) {6A383D4C-7657-408f-BD0D-B379B5C7C3BE}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\N1
c:\documents and settings\All Users\Application Data\N1\N1.cab
c:\documents and settings\All Users\Application Data\Software Licensors
c:\documents and settings\All Users\Application Data\Software Licensors\Antispyware PRO XP\LOG\20080917213242821.log
c:\documents and settings\Guest\Application Data\alot
c:\documents and settings\Lexi_2\Application Data\FunWebProducts
c:\documents and settings\Lexi_2\Application Data\FunWebProducts\Data\Lexi_2\avatar.dat
c:\documents and settings\Lexi_2\Application Data\FunWebProducts\Data\Lexi_2\register.dat
c:\documents and settings\Lexi_2\Application Data\FunWebProducts\Data\Lexi_2\zbucks.dat
c:\documents and settings\Wanda_2\Application Data\alot
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\5.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\5.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\5.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\5.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Cache\00048644
c:\program files\MyWebSearch\bar\Cache\000489DD
c:\program files\MyWebSearch\bar\Cache\00048A9B.bin
c:\program files\MyWebSearch\bar\Cache\00048B78.bin
c:\program files\MyWebSearch\bar\Cache\00048C22.bin
c:\program files\MyWebSearch\bar\Cache\00048CC2.bin
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\windows\010112010146118114.dat
c:\windows\COUPON~1.OCX
c:\windows\Installer\598c3.msi
c:\windows\Installer\6ce6d.msi
c:\windows\sysguard.exe
c:\windows\system32\iehelper.dll
c:\windows\system32\Ijl11.dll
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\mfc45.dll
c:\windows\system32\msxml71.dll
c:\windows\system32\tmp.reg
c:\windows\system32\twain.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_Boonty Games
((((((((((((((((((((((((( Files Created from 2009-06-09 to 2009-07-09 )))))))))))))))))))))))))))))))
.
2009-07-09 13:38 . 2009-07-09 13:38 -------- d-----w- c:\documents and settings\Wanda_2\Application Data\Malwarebytes
2009-07-09 13:38 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-09 13:38 . 2009-07-09 18:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-09 13:38 . 2009-07-09 13:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-09 13:38 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-09 13:28 . 2009-07-09 13:28 -------- d-----w- c:\program files\STOPzilla!
2009-07-09 11:15 . 2009-07-09 11:15 -------- d-----w- c:\documents and settings\Wanda_2\DoctorWeb
2009-07-07 18:14 . 2009-07-07 18:23 -------- d-----w- c:\windows\BDOSCAN8
2009-07-07 15:33 . 2009-07-07 15:33 -------- d-----w- c:\program files\ESET
2009-07-07 15:01 . 2009-07-07 15:01 -------- d-----w- c:\documents and settings\All Users\Application Data\CA
2009-07-07 14:23 . 2009-07-07 14:27 -------- d-----w- c:\documents and settings\Wanda_2\.housecall6.6
2009-07-06 14:50 . 2009-07-06 14:50 -------- d-----w- c:\program files\Trend Micro
2009-07-02 00:01 . 2009-07-09 11:07 -------- d-----w- c:\documents and settings\All Users\Application Data\13482564
2009-07-01 17:45 . 2009-07-01 17:45 -------- d-----w- c:\program files\drv
2009-06-17 16:58 . 2009-06-17 16:58 -------- d-----w- c:\documents and settings\Guest\Application Data\PlayFirst
2009-06-15 22:40 . 2009-07-02 15:23 -------- d-----w- c:\program files\iWin Games
2009-06-12 01:03 . 2009-06-12 01:03 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-11 03:54 . 2009-04-30 21:22 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 03:54 . 2009-04-30 21:22 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-09 22:57 . 2008-09-09 01:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-09 22:48 . 2008-09-09 01:45 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-07-09 22:47 . 2009-07-09 22:47 280 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-07-09 18:19 . 2009-01-20 01:45 -------- d-----w- c:\documents and settings\Lexi_2\Application Data\DNA
2009-07-09 16:06 . 2009-01-20 01:45 -------- d-----w- c:\program files\DNA
2009-07-09 14:13 . 2009-03-23 15:30 -------- d-----w- c:\program files\Spyware Doctor
2009-06-30 23:16 . 2008-11-03 02:48 -------- d-----w- c:\program files\iWin.com
2009-06-30 23:16 . 2008-04-19 04:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-30 23:12 . 2008-09-21 03:08 -------- d-----w- c:\program files\Barbie(R) idesign(TM) Ultimate Stylist(TM)
2009-06-30 23:11 . 2008-11-14 19:10 -------- d-----w- c:\program files\VIVA MEDIA
2009-06-11 08:04 . 2008-04-19 04:44 -------- d-----w- c:\program files\Microsoft Works
2009-06-04 17:19 . 2008-11-03 13:04 -------- d-----w- c:\documents and settings\Wanda_2\Application Data\iWin
2009-06-04 00:15 . 2008-11-05 18:53 -------- d-----w- c:\documents and settings\Lexi_2\Application Data\PlayFirst
2009-06-04 00:15 . 2008-09-27 03:07 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-06-03 23:11 . 2008-11-03 03:15 -------- d-----w- c:\documents and settings\Lexi_2\Application Data\iWin
2009-06-02 02:45 . 2009-06-02 02:45 -------- d-----w- c:\documents and settings\Lexi_2\Application Data\Template
2009-05-28 18:16 . 2009-05-28 18:16 17408 ----a-r- c:\windows\system32\SZIO5.dll
2009-05-28 18:15 . 2009-05-28 18:15 294912 ----a-r- c:\windows\system32\SZBase5.dll
2009-05-28 18:14 . 2009-05-28 18:14 540672 ----a-r- c:\windows\system32\SZComp5.dll
2009-05-13 05:15 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 18:13 . 2009-05-12 18:13 61328 ----a-r- c:\windows\system32\drivers\SZKG.sys
2009-05-10 15:47 . 2009-05-10 15:47 0 ----a-w- c:\documents and settings\Wanda_2\Application Data\wklnhst.dat
2009-05-10 15:47 . 2008-09-23 13:52 55992 ----a-w- c:\documents and settings\Wanda_2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-10 15:39 . 2009-05-10 15:39 50 ----a-w- c:\windows\system32\bridf08b.dat
2009-05-10 15:37 . 2009-05-10 15:37 10134 ----a-r- c:\documents and settings\Wanda_2\Application Data\Microsoft\Installer\{2BC2781A-F7F6-452E-95EB-018A522F1B2C}\ARPPRODUCTICON.exe
2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-20 14:22 . 2009-03-23 15:31 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-04-17 12:26 . 2004-08-10 17:51 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-10 17:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-13 22:17 . 2009-03-08 02:37 466944 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\pfHarness\pfHarness.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-10 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-07 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-07 81920]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ500 0MUI.exe" [2008-02-15 1052672]
"VirusScannerPro"="c:\progra~1\AVANQU~1\Fix-It\MemCheck.exe" [2008-08-26 173312]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-12 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-12 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2008-02-19 1089536]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-12-21 86016]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-04-07 1626112]
c:\documents and settings\Wanda_2\Start Menu\Programs\Startup\
iWin Desktop Alerts.lnk - c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe [2008-11-2 108544]
c:\documents and settings\Lexi_2\Start Menu\Programs\Startup\
iWin Desktop Alerts.lnk - c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe [2008-11-2 108544]
c:\documents and settings\Guest\Start Menu\Programs\Startup\
iWin Desktop Alerts.lnk - c:\documents and settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe [2008-11-2 108544]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-11-30 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-09-20 01:47 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxs ervice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcore service]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Jewel^Start Menu^Programs^Startup^IMVU.lnk]
backup=c:\windows\pss\IMVU.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1208580525\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
R0 Achernar;Achernar - SCSI Command Filters;c:\windows\system32\drivers\Achernar.sys [7/20/2008 4:33 PM 16855]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/23/2009 11:31 AM 130936]
R0 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [6/4/2009 12:11 PM 78104]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [2/28/2008 6:57 PM 18944]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/23/2009 11:30 AM 348752]
R2 tmpreflt;tmpreflt;c:\progra~1\AVANQU~1\Fix-It\tmpreflt.sys [8/31/2007 2:36 PM 32528]
R3 Aldebaran;Aldebaran - SCSI Command Filters;c:\windows\system32\drivers\Aldebaran.sys [7/20/2008 4:33 PM 21808]
R3 MailScan;MailScan;c:\progra~1\AVANQU~1\Fix-It\MailScan.sys [8/26/2008 5:14 PM 20496]
S3 JL2005;JL2005A Camera;c:\windows\system32\drivers\toywdm.sys [10/8/2005 6:22 PM 71512]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MAILSCAN
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-07-09 c:\windows\Tasks\User_Feed_Synchronization-{693C586D-CC8A-4A8C-A683-B2CD2CD201FC}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\5.bin\M3PLUGIN.DLL
HKLM-Run-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\5.bin\m3SrchMn.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.myembarq.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
IE: &Search -
http://edits.mywebsearch.com/toolbar...tml?p=ZJman000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949}
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} - hxxps://disneyblast.go.com/v3/setup/activex/DIGHardwareControl.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-09 18:57
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(652)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
- - - - - - - > 'lsass.exe'(708)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
- - - - - - - > 'explorer.exe'(3784)
c:\windows\system32\WININET.dll
c:\program files\Spyware Doctor\pctgmhk.dll
c:\progra~1\AVANQU~1\Fix-It\WinHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVANQU~1\Fix-It\mxtask.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\progra~1\AVANQU~1\Fix-It\mxtask.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Brother\ControlCenter3\BrccMCtl.exe
c:\program files\Brother\Brmfcmon\BrMfcMon.exe
.
**************************************************************************
.
Completion time: 2009-07-09 19:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-09 23:01
Pre-Run: 128,545,095,680 bytes free
Post-Run: 132,905,893,888 bytes free
256 --- E O F --- 2009-07-02 12:39