ComboFix 10-05-30.08 - User 2010/05/31 13:52:24.1.2 - x86
Microsoft® Windows Vistaâ„¢ Business 6.0.6002.2.1252.27.1033.18.2012.831 [GMT 2:00]
Running from: c:\users\Federico\Desktop\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
SP: Symantec Endpoint Protection *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\data
c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
c:\program files\pdfforge Toolbar\SeARchsettings.dll
c:\program files\QuickTime\Plugins\npqtplugin2.dll
c:\program files\QuickTime\Plugins\npqtplugin3.dll
c:\program files\QuickTime\Plugins\npqtplugin4.dll
c:\program files\QuickTime\Plugins\npqtplugin5.dll
c:\program files\QuickTime\Plugins\npqtplugin6.dll
c:\program files\QuickTime\Plugins\npqtplugin7.dll
.
((((((((((((((((((((((((( Files Created from 2010-04-28 to 2010-05-31 )))))))))))))))))))))))))))))))
.
2010-05-31 11:59 . 2010-05-31 11:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-31 09:09 . 2010-05-31 09:09 -------- d-----w- c:\users\Federico\AppData\Roaming\Malwarebytes
2010-05-31 08:16 . 2010-05-31 08:16 -------- d-----w- c:\users\User\AppData\Roaming\Malwarebytes
2010-05-31 08:16 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-31 08:16 . 2010-05-31 08:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-31 08:16 . 2010-05-31 08:16 -------- d-----w- c:\programdata\Malwarebytes
2010-05-31 08:16 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-28 13:45 . 2010-05-28 13:45 388096 ----a-r- c:\users\Federico\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-05-28 13:45 . 2010-05-28 13:45 -------- d-----w- c:\program files\Trend Micro
2010-05-26 11:47 . 2010-05-26 11:47 -------- d-----w- c:\users\Federico\AppData\Local\Adobe
2010-05-26 11:04 . 2010-05-31 11:07 -------- d-----w- c:\users\Federico\AppData\Roaming\skypePM
2010-05-26 11:02 . 2010-05-31 11:35 -------- d-----w- c:\users\Federico\AppData\Roaming\Skype
2010-05-26 10:43 . 2010-05-26 10:43 -------- d-----w- c:\users\Federico\AppData\Local\Mozilla
2010-05-26 10:41 . 2010-05-26 10:41 -------- d-----w- c:\users\Federico\AppData\Local\AIM Toolbar
2010-05-26 10:38 . 2010-05-26 10:38 -------- d-----w- c:\users\Federico\AppData\Roaming\Macrovision
2010-05-26 10:38 . 2010-05-26 10:38 -------- d-----w- c:\users\Federico\AppData\Local\PowerDVD DX
2010-05-26 10:38 . 2010-05-26 10:38 102424 ----a-w- c:\users\Federico\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-26 10:38 . 2010-05-26 10:38 -------- d-----w- c:\users\Federico\AppData\Roaming\Vodafone
2010-05-26 10:37 . 2010-05-26 10:37 -------- d-----w- c:\users\Federico\AppData\Roaming\DigitalPersona
2010-05-26 10:37 . 2010-05-26 10:37 -------- d-----w- c:\users\Federico\AppData\Local\DigitalPersona
2010-05-26 10:37 . 2010-05-28 13:45 -------- d-----w- c:\users\Federico\AppData\Local\VirtualStore
2010-05-26 09:59 . 2010-05-26 09:59 -------- d-----w- c:\program files\MSXML 4.0
2010-05-26 07:33 . 2010-04-23 14:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-25 11:51 . 2008-08-02 09:58 82432 ----a-w- c:\windows\system32\msxml4r.dll
2010-05-25 11:51 . 2008-08-02 09:58 44544 ----a-w- c:\windows\system32\msxml4a.dll
2010-05-25 11:51 . 2010-05-25 11:51 -------- d-----w- c:\program files\TeXnicCenter
2010-05-25 11:49 . 2010-05-25 11:49 -------- d-----w- c:\users\User\AppData\Local\Mozilla
2010-05-25 11:47 . 2010-05-25 11:47 -------- d-----w- c:\users\User\AppData\Local\MiKTeX
2010-05-25 11:47 . 2010-05-25 11:47 -------- d-----w- c:\programdata\MiKTeX
2010-05-25 11:44 . 2010-05-25 11:46 -------- d-----w- c:\program files\MiKTeX 2.6
2010-05-25 11:40 . 2010-05-25 11:40 -------- d-----w- c:\program files\Ghostgum
2010-05-25 11:40 . 2010-05-25 11:40 -------- d-----w- c:\program files\gs
2010-05-25 11:39 . 2010-05-31 11:58 -------- d-----w- c:\program files\pdfforge Toolbar
2010-05-25 11:39 . 2010-05-25 11:39 -------- d-----w- c:\program files\Application Updater
2010-05-25 11:38 . 2001-10-28 14:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2010-05-25 11:38 . 2010-05-25 11:40 -------- d-----w- c:\program files\PDFCreator
2010-05-25 11:38 . 1998-08-05 05:45 122128 ----a-w- c:\windows\system32\VB6IT.DLL
2010-05-25 11:38 . 1998-08-05 05:45 150528 ----a-w- c:\windows\system32\MSCMCIT.DLL
2010-05-25 11:38 . 1998-08-05 05:45 63488 ----a-w- c:\windows\system32\MSCC2IT.DLL
2010-05-25 11:38 . 1998-07-05 22:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2010-05-25 09:26 . 2010-05-25 09:26 -------- d-----w- c:\users\User\AppData\Roaming\Stata10
2010-05-25 09:24 . 2010-05-25 09:47 -------- d-----w- c:\program files\Stata10
2010-05-25 09:22 . 2010-05-25 09:22 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-05-25 09:21 . 2010-05-25 09:21 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-20 22:52 . 2010-05-20 22:52 -------- d-----w- C:\New Folder
2010-05-20 07:19 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-31 11:48 . 2009-10-24 15:07 -------- d-----w- c:\users\User\AppData\Roaming\skypePM
2010-05-28 14:22 . 2009-10-24 15:06 -------- d-----w- c:\users\User\AppData\Roaming\Skype
2010-05-21 01:18 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-21 01:01 . 2009-10-20 10:27 -------- d-----w- c:\programdata\Microsoft Help
2010-05-12 09:21 . 2009-10-20 10:37 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-04-11 16:51 . 2010-04-11 16:51 -------- d-----w- c:\programdata\WindowsSearch
2010-04-11 04:06 . 2010-04-11 04:06 -------- d-----w- c:\users\User\AppData\Roaming\acccore
2010-04-11 04:05 . 2010-04-11 04:05 -------- d-----w- c:\program files\AIM Toolbar
2010-04-11 04:05 . 2010-04-11 04:05 -------- d-----w- c:\programdata\AIM Toolbar
2010-04-11 04:05 . 2010-04-11 04:05 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-04-11 04:05 . 2010-04-11 04:05 -------- d-----w- c:\programdata\AIM
2010-04-11 04:05 . 2010-04-11 04:05 -------- d-----w- c:\program files\AIM
2010-04-11 04:05 . 2010-04-11 04:05 -------- d-----w- c:\program files\Common Files\AOL
2010-03-12 16:52 . 2010-03-12 16:52 94208 ----a-w- c:\programdata\AIM Toolbar\ieToolbar\resources\en-US\aimtbres.dll
2010-03-05 14:01 . 2010-04-14 14:15 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-03 01:48 . 2009-10-20 10:07 102424 ----a-w- c:\users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-21 22:35 . 2009-07-21 22:35 75 --sh--r- c:\windows\CT4CET.bin
2009-07-22 00:58 . 2009-04-11 16:25 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
2010-01-08 01:17 700416 ----a-w- c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B922D405-6D13-4A2B-AE89-08A030DA4402}"= "c:\program files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll" [2010-01-08 700416]
[HKEY_CLASSES_ROOT\clsid\{b922d405-6d13-4a2b-ae89-08a030da4402}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Aim"="c:\program files\AIM\aim.exe" [2010-03-08 3972440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-04-25 233472]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-04-25 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-04-25 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-04-25 150552]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-21 148888]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-11 3563520]
"DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2009-02-06 818240]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-01-09 405639]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-31 115560]
"hp 1000 firmware"="c:\program files\hp LaserJet 1000\fwdl.exe" [2001-12-15 36864]
"MobileConnect"="c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe" [2008-07-04 2072576]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-06 77824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SearchSettings"="c:\program files\pdfforge Toolbar\SearchSettings.exe" [2010-01-07 974848]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):73,7c,e7,00,dc,55,ca,01
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-01-07 380928]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 MSO_SpUsb_Service;SAGEM MorphoSmart Service Provider Usb Server;c:\windows\system32\Serv_SpUsb.exe [2005-09-30 86016]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2009-04-02 1049904]
S2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-07-04 14336]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-12-31 144128]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-05-27 102448]
S3 OA014Ufd;Creative Camera OA014 Upper Filter Driver;c:\windows\system32\DRIVERS\OA014Ufd.sys [2009-04-25 133632]
S3 OA014Vid;Creative Camera OA014 Function Driver;c:\windows\system32\DRIVERS\OA014Vid.sys [2009-04-25 271904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HsfXAudioService REG_MULTI_SZ HsfXAudioService
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-05-31 c:\windows\Tasks\User_Feed_Synchronization-{C6BC9E92-275E-4A21-8F13-D5AD57B02DB6}.job
- c:\windows\system32\msfeedssync.exe [2010-04-06 04:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/?src=aim&ncid=snsusaimc00000001
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\focc7nd2.default\
FF - plugin: c:\program files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-Symantec Antvirus
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-31 13:59
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(736)
c:\windows\system32\DPPWDFLT.dll
.
Completion time: 2010-05-31 14:02:01
ComboFix-quarantined-files.txt 2010-05-31 12:01
Pre-Run: 140 687 785 984 bytes free
Post-Run: 140 237 602 816 bytes free
- - End Of File - - 8533AC8C3B8A960F91ACA955B892BB48