ComboFix 11-04-11.04 - Passoue 04/12/2011 13:00:19.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1982.1132 [GMT -4:00]
Running from: c:\users\Passoue\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\users\Passoue\AppData\Local\{A03BA7B7-6842-48B4-A94D-F64A9BF2AFCC}
c:\users\Passoue\AppData\Local\{A03BA7B7-6842-48B4-A94D-F64A9BF2AFCC}\chrome.manifest
c:\users\Passoue\AppData\Local\{A03BA7B7-6842-48B4-A94D-F64A9BF2AFCC}\chrome\content\_cfg.js
c:\users\Passoue\AppData\Local\{A03BA7B7-6842-48B4-A94D-F64A9BF2AFCC}\chrome\content\overlay.xul
c:\users\Passoue\AppData\Local\{A03BA7B7-6842-48B4-A94D-F64A9BF2AFCC}\install.rdf
.
.
((((((((((((((((((((((((( Files Created from 2011-03-12 to 2011-04-12 )))))))))))))))))))))))))))))))
.
.
2011-04-12 17:11 . 2011-04-12 17:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-12 17:11 . 2011-04-12 17:11 -------- d-----w- c:\users\Pouche\AppData\Local\temp
2011-04-12 17:11 . 2011-04-12 17:11 -------- d-----w- c:\users\Guest\AppData\Local\temp
2011-04-11 06:38 . 2011-04-11 06:38 -------- d-----w- c:\program files\Eraser
2011-04-11 05:44 . 2011-04-11 05:44 -------- d-----w- c:\program files\AMD
2011-04-11 05:42 . 2011-04-11 05:42 -------- d-----w- c:\windows\system32\vmm32
2011-04-11 04:52 . 2011-04-11 05:01 -------- d-----w- c:\program files\trend micro
2011-04-11 04:52 . 2011-04-11 04:52 -------- d-----w- C:\rsit
2011-04-11 04:12 . 2011-04-11 04:13 -------- d-----w- c:\users\oooooo
2011-04-11 04:04 . 2011-04-11 04:07 -------- d-----w- c:\users\uuuu
2011-04-11 00:04 . 2011-04-11 00:04 652296 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsTemplate\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2011-04-10 23:54 . 2011-04-10 23:54 644360 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-04-10 23:53 . 2011-04-10 23:53 416128 ----a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll
2011-04-05 15:21 . 2011-04-05 15:21 -------- d-----w- c:\windows\4-5-2011
2011-04-05 15:20 . 2011-04-05 15:20 -------- d-----w- c:\program files\ERUNT
2011-04-04 14:14 . 2011-04-10 23:53 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-04-04 14:14 . 2011-04-04 14:14 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-04-03 03:15 . 2011-04-03 03:24 -------- d-----w- c:\users\VIRUS
2011-04-02 22:49 . 2011-04-02 22:49 -------- d-----w- c:\users\Pouche\AppData\Roaming\Malwarebytes
2011-03-26 03:22 . 2011-03-26 03:22 -------- d-----w- c:\users\Passoue\AppData\Local\Apple Computer
2011-03-26 03:15 . 2011-03-26 03:25 -------- d-----w- c:\users\Passoue\AppData\Roaming\Apple Computer
2011-03-26 03:05 . 2011-03-26 03:06 -------- d-----w- c:\users\Pouche\AppData\Roaming\Apple Computer
2011-03-26 03:05 . 2011-03-26 03:05 -------- d-----w- c:\users\Pouche\AppData\Local\Apple Computer
2011-03-26 03:03 . 2011-03-26 03:03 -------- d-----w- c:\program files\iPod
2011-03-26 03:03 . 2011-03-26 03:04 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-26 03:03 . 2011-03-26 03:04 -------- d-----w- c:\program files\iTunes
2011-03-26 03:01 . 2011-03-26 03:03 -------- d-----w- c:\programdata\Apple Computer
2011-03-26 03:01 . 2011-03-26 03:01 -------- d-----w- c:\users\Pouche\AppData\Local\Apple
2011-03-26 03:01 . 2011-03-26 03:01 -------- d-----w- c:\program files\Apple Software Update
2011-03-26 02:58 . 2011-03-26 04:11 -------- d-----w- c:\program files\Bonjour
2011-03-26 02:58 . 2011-03-26 03:07 -------- d-----w- c:\programdata\Apple
2011-03-26 02:58 . 2011-03-26 03:03 -------- d-----w- c:\program files\Common Files\Apple
2011-03-15 05:05 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2011-03-15 05:05 . 2010-12-29 18:28 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-03-15 05:05 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2011-03-15 05:05 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-15 05:05 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-03-15 05:05 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 14:59 . 2011-03-07 14:59 724992 ----a-w- c:\windows\iun6002.exe
2011-02-10 07:25 . 2011-02-08 17:15 0 ----a-w- c:\users\Passoue\AppData\Local\Hvuzu.bin
2011-02-03 02:40 . 2010-06-23 00:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-21 05:55 . 2011-01-21 05:55 53248 ----a-r- c:\users\Passoue\AppData\Roaming\Microsoft\Installer\{6BA13EFC-E8D0-4D37-AF04-42796CF0E8F5}\ARPPRODUCTICON.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech BT Wizard"="LBTWiz.exe -silent" [X]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-15 4390912]
"Bluetooth HCI Monitor"="HCIMNTR.DLL" [2006-12-07 9728]
"Logitech Hardware Abstraction Layer"="c:\program files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2007-01-11 101136]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 16384]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 17920]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-22 30192]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-11 101136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"DLCQCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll" [2006-10-16 106496]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Eraser"="c:\progra~1\Eraser\Eraser.exe" [2010-11-05 980368]
.
c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\users\Pouche\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-13 715568]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2007-9-5 679936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl1cda211b;MpKsl1cda211b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8415841-A69D-43FB-A41E-A79BFC928BF5}\MpKsl1cda211b.sys
R1 MpKsl2c35e152;MpKsl2c35e152;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{71110B35-5F16-411E-B7AA-8A218A42A73B}\MpKsl2c35e152.sys
R1 MpKsl47375ab8;MpKsl47375ab8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CCBA984A-40A2-4F22-A6A4-D9B88CD3885E}\MpKsl47375ab8.sys
R1 MpKsl4b9d4252;MpKsl4b9d4252;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EFF7D1BB-BC05-4D24-B1DD-E991389B4D4D}\MpKsl4b9d4252.sys
R1 MpKsl7f8ef54a;MpKsl7f8ef54a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EFF7D1BB-BC05-4D24-B1DD-E991389B4D4D}\MpKsl7f8ef54a.sys
R1 MpKsl880bf3a6;MpKsl880bf3a6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F64305BF-08AB-4DE3-9D0B-9731C0FA62EB}\MpKsl880bf3a6.sys
R1 MpKsl8a07eb09;MpKsl8a07eb09;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{611F3B23-28C9-4C60-972D-A1FA0D74CFD5}\MpKsl8a07eb09.sys
R1 MpKsl97a9146a;MpKsl97a9146a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8415841-A69D-43FB-A41E-A79BFC928BF5}\MpKsl97a9146a.sys
R1 MpKsla251679e;MpKsla251679e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8FBFA3A6-C50E-4A4C-9B54-5863096728C5}\MpKsla251679e.sys
R1 MpKslae6e7016;MpKslae6e7016;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0398A1D2-618B-46C2-BC61-79305127536C}\MpKslae6e7016.sys
R1 MpKslb129cb65;MpKslb129cb65;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FFFB05A4-346B-4E4C-BA9E-29F4D8AA69EA}\MpKslb129cb65.sys
R1 MpKslbec9832a;MpKslbec9832a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{65079D8B-8D55-4B9B-8FD2-D3CBB0C5EFBE}\MpKslbec9832a.sys
R1 MpKsldfcbbb6c;MpKsldfcbbb6c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{407C721E-FD43-43E6-843D-DB62CA095D1A}\MpKsldfcbbb6c.sys
R1 MpKsle9fd661a;MpKsle9fd661a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F4297BAE-EF1F-4384-9AA9-FAB90B8EBDCC}\MpKsle9fd661a.sys
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-22 30192]
R3 ICDUSB3;ICDUSB3;c:\windows\system32\Drivers\ICDUSB3.sys [2008-08-18 11264]
S1 MpKsl2528189e;MpKsl2528189e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8415841-A69D-43FB-A41E-A79BFC928BF5}\MpKsl2528189e.sys
S1 MpKsl41b71cbf;MpKsl41b71cbf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8415841-A69D-43FB-A41E-A79BFC928BF5}\MpKsl41b71cbf.sys
S1 MpKsl8fbfed62;MpKsl8fbfed62;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8415841-A69D-43FB-A41E-A79BFC928BF5}\MpKsl8fbfed62.sys
S1 MpKsl900c654e;MpKsl900c654e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8415841-A69D-43FB-A41E-A79BFC928BF5}\MpKsl900c654e.sys
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - MpNWMon
*Deregistered* - NisDrv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-04-12 13:12
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCQCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-04-12 13:14:54
ComboFix-quarantined-files.txt 2011-04-12 17:14
.
Pre-Run: 228,363,984,896 bytes free
Post-Run: 229,487,517,696 bytes free
.
- - End Of File - - B927B483211ED6825B75EF63B5D58E3B