ComboFix log:
ComboFix 09-03-31.01 - User 2009-04-01 15:52:57.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1545 [GMT 10:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: Trend Micro Internet Security Pro *On-access scanning enabled* (Updated)
FW: Trend Micro Personal Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-03-01 to 2009-04-01 )))))))))))))))))))))))))))))))
.
2009-03-29 19:40 . 2009-03-29 19:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2009-03-29 19:07 . 2007-02-20 16:04 2,463,976 --a------ c:\windows\system32\NPSWF32.dll
2009-03-29 19:07 . 2007-02-20 16:04 190,696 --a------ c:\windows\system32\NPSWF32_FlashUtil.exe
2009-03-29 18:56 . 2009-03-29 18:56 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2009-03-15 19:34 . 2008-04-14 05:41 21,504 --a------ c:\windows\system32\hidserv.dll
2009-03-15 19:34 . 2008-04-14 05:41 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-31 23:30 --------- d-----w c:\program files\Lx_cats
2009-03-31 06:30 3,738 ----a-w c:\documents and settings\User\Application Data\wklnhst.dat
2009-03-29 09:13 --------- d-----w c:\program files\Common Files\Adobe
2009-02-23 08:12 40,000 ----a-w c:\documents and settings\User\Application Data\GDIPFONTCACHEV1.DAT
2009-02-14 02:49 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-14 00:44 --------- d-----w c:\program files\Windows Live Safety Center
2009-02-13 07:58 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-13 07:58 --------- d-----w c:\program files\EA GAMES
2009-02-11 00:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 00:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-07 00:50 --------- d-----w c:\program files\iTunes
2009-02-07 00:50 --------- d-----w c:\program files\iPod
2009-02-07 00:50 --------- d-----w c:\program files\Common Files\Apple
2009-02-07 00:50 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-07 00:50 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-07 00:49 --------- d-----w c:\program files\QuickTime
2009-02-06 10:28 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-02-05 07:03 --------- d-----w c:\program files\Lexmark 7100 Series
2009-02-05 07:02 --------- d-----w c:\program files\Microsoft Works
2009-02-05 07:01 --------- d-----w c:\program files\Metin2.us
2009-02-05 07:00 --------- d-----w c:\program files\PC Connectivity Solution
2009-02-05 07:00 --------- d-----w c:\program files\My Tribe
2009-02-05 06:27 --------- d-----w c:\documents and settings\All Users\Application Data\Trend Micro
2009-02-04 11:38 --------- d-----w c:\program files\Trend Micro
2009-02-04 10:50 --------- d-----w c:\documents and settings\User\Application Data\Malwarebytes
2009-02-04 10:50 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-10 212216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-01-27 29833347]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2009-01-27 301056]
"LXBXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-08-20 65536]
"lxbxmon.exe"="c:\program files\Lexmark 7100 Series\lxbxmon.exe" [2004-08-26 188416]
"FaxCenterServer4_in_1"="c:\program files\Lexmark 7100 Series\fm3032.exe" [2004-08-25 356352]
"EzPrint"="c:\program files\Lexmark 7100 Series\ezprint.exe" [2004-08-25 131072]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 110658]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 491520]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 372008]
"nwiz"="nwiz.exe" [2007-12-05 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1818624]
c:\documents and settings\User\Start Menu\Programs\Startup\
Bandwidth Meter.lnk - c:\program files\BandwidthMeter\BandwidthMeter.exe [2007-12-09 275968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 152992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.tscc"= c:\docume~1\User\Desktop\linh\MpcStar\Codecs\tscc\tsccvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.0.game"=
"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.4.game"=
"c:\\WINDOWS\\system32\\nwiz.exe"=
"c:\\WINDOWS\\system32\\dumprep.exe"=
"c:\\Program Files\\Microsoft Office\\Office10\\OSA.EXE"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\Program Files\\VIA\\VIAudioi\\HDADeck\\HDeck.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
"c:\\Program Files\\PC Connectivity Solution\\NclInstaller.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\WINDOWS\\system32\\lxbxcoms.exe"=
"c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
"c:\\Program Files\\Trend Micro\\TrendSecure\\TSCFCommander.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security\\UfNavi.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Windows Live\\WLLoginProxy.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Trend Micro\\TrendSecure\\TISProToolbar\\PlatformDependent\\ProToolbarComm.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Microsoft Works\\WkDStore.exe"=
"c:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Program Files\\Lexmark 7100 Series\\fm3032.exe"=
"c:\\Program Files\\BandwidthMeter\\BandwidthMeter.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbamgui.exe"=
"c:\\Program Files\\Trend Micro\\BM\\TMBMSRV.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"=
"c:\\WINDOWS\\system32\\wuauclt.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"c:\\Program Files\\Trend Micro\\TrendSecure\\TSCFPlatformCOMSvr.exe"=
"c:\\ComboFix\\nircmd.com"=
"c:\\Program Files\\QuickTime\\QTTask.exe"=
"c:\\Program Files\\Adobe\\Acrobat 5.0\\Reader\\AcroRd32.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"10475:TCP"= 10475:TCP:BitComet 10475 TCP
"10475:UDP"= 10475:UDP:BitComet 10475 UDP
"58436:TCP"= 58436:TCP:Pando Media Booster
"58436:UDP"= 58436:UDP:Pando Media Booster
R2 Security Activity Dashboard Service;Security Activity Dashboard Service;c:\program files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe [2009-02-04 181584]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2009-02-04 49680]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-08-15 36368]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\gnrnin.sys --> c:\windows\system32\drivers\gnrnin.sys [?]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-08-15 334352]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2008-10-24 238080]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0217854c-a32b-11dd-856e-002215ca1588}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wiskcpy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3255fa90-d484-11dd-85c9-002215ca1588}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wokaye.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70ea0947-ec26-11dd-8621-002215ca1588}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-OE - c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
HKLM-Run-UfSeAgnt.exe - c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe
HKU-Default-Run-OE - c:\program files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - c:\program files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\2h576wc2.default\
FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?wa=wsignin1.0&rpsnv=10&ct=1233469709&rver=5.5.4177.0&wp=MBI&wreply=http:%2F%2Fmail.live.com%2Fdefault.aspx%3Fn%3D943640088&id=64855
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFTMUFEHelper.dll
FF - component: c:\program files\Trend Micro\TrendSecure\TISProToolbar\FirefoxExtension\components\FFToolbarComm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-01 15:54:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
LXBXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1844237615-1343024091-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:31,da,da,37,3b,76,3e,d3,73,16,26,51,07,40,a2,bd,e9,15,0f,27,63,
79,52,b8,52,02,33,ba,b7,6c,13,85,3e,27,e3,7b,d0,b3,0c,d0,fc,e8,cc,ad,08,cb,\
"rkeysecu"=hex:89,16,62,15,e9,99,34,d0,66,54,ab,b5,1c,45,da,58
.
Completion time: 2009-04-01 15:56:21
ComboFix-quarantined-files.txt 2009-04-01 05:56:18
ComboFix2.txt 2009-02-27 08:26:31
Pre-Run: 426,397,032,448 bytes free
Post-Run: 427,915,059,200 bytes free
203 --- E O F --- 2009-03-11 08:26:11
Sign In
Create Account
This topic is locked

Back to top








