ComboFix 09-08-04.04 - PavieJ 10/08/2009 11:54.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.33.1033.18
.1014.506 [GMT 2:00]
Running from: c:\program files\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E
43226D3305
C}
FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-0
3DB9923DDB
6}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((
((((((((((
((( Other Deletions ))))))))))))))))))))))))))
))))))))))
))))))))))
)))
.
c:\windows\system32\lsprst
7.dll
c:\windows\system32\ssprs.
dll
.
((((((((((((((((((((((((( Files Created from 2009-07-10 to 2009-08-10 ))))))))))))))))))))))))))
)))))
.
2009-08-10 10:02 . 2009-08-10 10:03 53248 ----a-w- c:\temp\catchme.dll
2009-08-10 09:54 . 2009-08-10 09:54 -------- d-----w- c:\temp\WPDNSE
2009-08-10 07:34 . 2009-08-10 07:34 16384 ----atw- c:\temp\Perflib_Perfdata_3
b8.dat
2009-08-06 11:10 . 2009-08-06 11:10 3154932 ----a-r- c:\program files\ComboFix.exe
.
((((((((((((((((((((((((((
((((((((((
(((( Find3M Report ))))))))))))))))))))))))))
))))))))))
))))))))))
))))))
.
2009-08-10 08:18 . 2009-04-17 10:41 -------- d-----w- c:\documents and settings\PavieJ\Applicatio
n Data\HPAppData
2009-08-08 19:47 . 2008-04-14 10:59 12 ----a-w- c:\windows\bthservsdp.dat
2009-08-03 19:52 . 2008-12-10 17:18 -------- d-----w- c:\program files\Symantec AntiVirus
2009-07-21 12:41 . 2008-04-17 12:20 -------- d-----w- c:\documents and settings\PavieJ\Applicatio
n Data\U3
2009-07-16 06:53 . 2009-02-06 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverCure
2009-06-29 05:29 . 2008-04-18 13:37 77552 ----a-w- c:\documents and settings\PavieJ\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-26 14:06 . 2009-06-26 14:06 156968 ----a-w- c:\documents and settings\LocalService\Loca
l Settings\Application Data\FontCache3.0.0.0.dat
2009-06-26 14:04 . 2009-06-26 14:04 -------- d-----w- c:\program files\MSBuild
2009-06-26 14:04 . 2009-06-26 14:04 -------- d-----w- c:\program files\Reference Assemblies
2009-06-26 13:56 . 2009-06-26 13:56 -------- d-----w- c:\program files\MSXML 6.0
2009-06-26 12:57 . 2009-06-26 12:57 289080 ----a-w- c:\program files\AutodeskDesignRevSet
up.exe
2009-06-22 22:36 . 2009-06-22 22:36 -------- d-----w- c:\program files\ParetoLogic
2009-06-22 22:36 . 2009-05-17 22:33 2988592 ----a-w- c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\Driv
erCure\Tem
p\Update.e
xe
2009-05-25 12:07 . 2009-05-25 11:38 124416 ----a-w- c:\windows\hpqins00.dat
2009-05-18 22:58 . 2009-05-29 08:35 1693316 ----a-w- c:\windows\system32\esetup
.exe
2009-05-01 19:15 . 2009-05-01 19:15 2488008 ----a-w- c:\program files\mediacenter.exe
2009-04-21 12:00 . 2009-04-21 11:59 1880648 ----a-w- c:\program files\TeamViewer_Setup.exe
2009-03-11 14:15 . 2009-03-11 14:14 34175700 ----a-w- c:\program files\Citadon setup.exe
2009-02-09 09:21 . 2009-02-09 09:21 6561169 ----a-w- c:\program files\SecureClient_Cluster
_09012009.
zip
2009-02-06 22:51 . 2009-02-06 22:51 11562257 ----a-w- c:\program files\The-KMPlayer-FR-2412
08.exe
2009-02-06 20:33 . 2009-02-06 20:32 52307672 ----a-w- c:\program files\AVSVideoConverter.ex
e
2008-09-22 09:38 . 2008-09-22 09:38 27199528 ----a-w- c:\program files\eDrawingsFullEnglish
.exe
2008-06-02 14:35 . 2008-06-02 14:35 1271557 ----a-w- c:\program files\wrar371fr.exe
2008-04-18 13:04 . 2008-04-18 13:03 213316736 ----a-w- c:\program files\SetupDWGTrueView2009
_32bit_FRA
.exe
2008-04-14 14:35 . 2008-04-14 14:35 97694 ----a-w- c:\program files\install_Windows Media Player_.exe
2008-04-14 11:46 . 2008-04-14 11:46 16500592 ----a-w- c:\program files\DivXInstaller.exe
.
((((((((((((((((((((((((((
((( SnapShot@2009-08-06_11.27.
00 ))))))))))))))))))))))))))
))))))))))
)))))
.
- 2004-08-04 12:00 . 2009-08-05 19:17 72238 c:\windows\system32\perfc0
09.dat
+ 2004-08-04 12:00 . 2009-08-10 07:39 72238 c:\windows\system32\perfc0
09.dat
- 2006-08-08 10:50 . 2009-08-01 13:52 32768 c:\windows\system32\config
\systempro
file\Local
Settings\Temporary Internet Files\Content.IE5\index.da
t
+ 2006-08-08 10:50 . 2009-08-07 11:03 32768 c:\windows\system32\config
\systempro
file\Local
Settings\Temporary Internet Files\Content.IE5\index.da
t
- 2006-08-08 10:50 . 2009-08-01 13:52 32768 c:\windows\system32\config
\systempro
file\Local
Settings\History\History.I
E5\index.d
at
+ 2006-08-08 10:50 . 2009-08-07 11:03 32768 c:\windows\system32\config
\systempro
file\Local
Settings\History\History.I
E5\index.d
at
+ 2006-08-08 10:50 . 2009-08-07 11:03 32768 c:\windows\system32\config
\systempro
file\Cooki
es\index.d
at
- 2006-08-08 10:50 . 2009-08-01 13:52 32768 c:\windows\system32\config
\systempro
file\Cooki
es\index.d
at
- 2004-08-04 12:00 . 2009-08-05 19:17 444362 c:\windows\system32\perfh0
09.dat
+ 2004-08-04 12:00 . 2009-08-10 07:39 444362 c:\windows\system32\perfh0
09.dat
+ 2006-08-08 11:29 . 2009-08-10 07:34 296480 c:\windows\system32\FNTCAC
HE.DAT
- 2006-08-08 11:29 . 2009-07-18 11:12 296480 c:\windows\system32\FNTCAC
HE.DAT
.
((((((((((((((((((((((((((
((((((((((
( Reg Loading Points ))))))))))))))))))))))))))
))))))))))
))))))))))
))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
E\Microsof
t\Windows\
CurrentVer
sion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"DriverCure"="c:\program files\ParetoLogic\DriverCu
re\DriverC
ure.exe" [2009-04-26 3023640]
[HKEY_LOCAL_MACHINE\SOFTWA
RE\Microso
ft\Windows
\CurrentVe
rsion\Run]
"igfxtray"="c:\windows\sys
tem32\igfx
tray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\sy
stem32\hkc
md.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\sys
tem32\igfx
pers.exe" [2005-12-13 118784]
"SunJavaUpdateSched"="c:\p
rogram files\Java\jre6\bin\jusche
d.exe" [2008-12-16 136600]
"dla"="c:\windows\system32
\dla\tfswc
trl.exe" [2004-08-13 122939]
"UpdateManager"="c:\progra
m files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"Discovery User Input"="c:\discovery\User Input\userin32.exe" [2009-01-09 233472]
"Broadcom Wireless Manager UI"="c:\windows\system32\W
LTRAY.exe"
[2007-03-16 1392640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"bginfo"="c:\documents and settings\all users\application data\ech\bginfo.exe" [2008-02-06 963624]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-04-17 115560]
"SigmatelSysTrayApp"="stsy
stra.exe" - c:\windows\stsystra.exe [2005-11-16 397312]
"BluetoothAuthenticationAg
ent"="bthp
rops.cpl" - c:\windows\system32\bthpro
ps.cpl [2004-08-04 110592]
[HKEY_USERS\.DEFAULT\Softw
are\Micros
oft\Window
s\CurrentV
ersion\Run
]
"CTFMON.EXE"="c:\windows\s
ystem32\ct
fmon.exe" [2004-08-04 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Powerproject Startup.lnk - c:\program files\Asta\Asta Powerproject\Teamplan.exe [2007-2-13 3485785]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\poli
cies\syste
m]
"MaxGPOScriptWait"= 5 (0x5)
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\winlogon
\notify\ck
pNotify]
2008-01-29 14:14 24669 ----a-w- c:\windows\system32\ckpNot
ify.dll
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-1
6764\Scrip
ts\Logon\0
\0]
"Script"=CachedMode.vbs
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-1
6764\Scrip
ts\Logon\1
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ech
arris.loca
l\Scripts\
printers.b
at
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-3
2117\Scrip
ts\Logon\0
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ech
arris.loca
l\Scripts\
printers.b
at
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-3
2117\Scrip
ts\Logon\1
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ECH
ARRIS.LOCA
L\Scripts\
renamecato
sqlechq.vb
s
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-3
2117\Scrip
ts\Logon\1
\1]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ECH
ARRIS.LOCA
L\Scripts\
eolscript.
vbs
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-3
2117\Scrip
ts\Logon\1
\2]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ECH
ARRIS.LOCA
L\Scripts\
renameeart
hworksechq
.vbs
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-3
2117\Scrip
ts\Logon\2
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ECH
ARRIS.LOCA
L\Scripts\
nongmologi
nrebrandma
y09.vbs
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-3
2117\Scrip
ts\Logon\3
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ech
arris.loca
l\Scripts\
killgoogle
desktopale
rts.vbs
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-3
2117\Scrip
ts\Logon\3
\1]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ECH
ARRIS.LOCA
L\Scripts\
Fix_GDS_Ex
celerator.
vbs
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-3
2117\Scrip
ts\Logon\4
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ECH
ARRIS.LOCA
L\Scripts\
savlagchec
k.vbs
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-7
0174\Scrip
ts\Logon\0
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ech
arris.loca
l\Scripts\
printers.b
at
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-7
0174\Scrip
ts\Logon\1
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ECH
ARRIS.LOCA
L\Scripts\
wallpaper.
vbs
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-7
0186\Scrip
ts\Logon\0
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ech
arris.loca
l\Scripts\
printers.b
at
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\grou
p policy\state\S-1-5-21-1888
580068-407
2715215-30
66545148-7
0186\Scrip
ts\Logon\1
\0]
"Script"=\\ECHARRIS.LOCAL\
SysVol\ECH
ARRIS.LOCA
L\Scripts\
wallpaper.
vbs
[HKEY_LOCAL_MACHINE\SYSTEM
\CurrentCo
ntrolSet\C
ontrol\Saf
eBoot\Mini
mal\ccEvtM
gr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
\CurrentCo
ntrolSet\C
ontrol\Saf
eBoot\Mini
mal\ccSetM
gr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
\CurrentCo
ntrolSet\C
ontrol\Saf
eBoot\Mini
mal\Symant
ec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\securit
y center\Monitoring\Symantec
AntiVirus]
"DisableMonitoring"=dword:
00000001
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Auth
orizedAppl
ications\L
ist]
"%windir%\\system32\\sessm
gr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169
.254.2.0/2
55.255.255
.0:Enabled
:ActiveSyn
c RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:16
9.254.2.0/
255.255.25
5.0:Enable
d:ActiveSy
nc Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169
.254.2.0/2
55.255.255
.0:Enabled
:ActiveSyn
c Application
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
standardpr
ofile\Glob
allyOpenPo
rts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22
009
"26675:TCP"= 26675:TCP:169.254.2.0/255.
255.255.0:
Enabled:Ac
tiveSync Service
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\system32
\drivers\d
wvkbd.sys [15/02/2007 20:00 26624]
R1 FW1;SecuRemote Miniport;c:\windows\system
32\drivers
\fw.sys [29/01/2008 16:15 2235760]
R2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32
\drivers\o
mdrv.sys [29/01/2008 16:15 47504]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\
TeamViewer
_Service.e
xe [23/03/2009 11:35 185640]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\sy
stem32\dri
vers\vnasc
.sys [29/01/2008 16:15 121136]
R2 VPN-1;VPN-1 Module;c:\windows\system32
\drivers\v
pn.sys [29/01/2008 16:15 673872]
R3 DwMirror;DwMirror;c:\windo
ws\system3
2\drivers\
DamewareMi
ni.sys [07/02/2007 20:00 3712]
R3 EraserUtilRebootDrv;Eraser
UtilReboot
Drv;c:\pro
gram files\Common Files\Symantec Shared\EENGINE\EraserUtilR
ebootDrv.s
ys [09/03/2009 10:41 101936]
S3 COH_Mon;COH_Mon;c:\windows
\system32\
drivers\CO
H_Mon.sys [17/04/2009 09:24 23888]
S3 G3GRUMDM;G3G R USB Modem;c:\windows\system32\
drivers\g3
grumdm.sys
[26/09/2008 16:06 26496]
S3 G3GRUSER;G3G R USB Serial;c:\windows\system32
\drivers\g
3gruser.sy
s [26/09/2008 16:06 23296]
--- Other Services/Drivers In Memory ---
*Deregistered* - uphcleanhlp
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2009-02-06 c:\windows\Tasks\DriverCur
e.job
- c:\program files\ParetoLogic\DriverCu
re\DriverC
ure.exe [2009-04-26 12:44]
2009-08-05 c:\windows\Tasks\ParetoLog
ic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS
.dll [2009-01-21 05:36]
2009-06-26 c:\windows\Tasks\ParetoLog
ic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Par
eto_Update
.exe [2009-01-21 05:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://myportal.echarris.c
om
uInternet Connection Wizard,ShellNext = hxxp://echonew/live
uInternet Settings,ProxyServer = internetuk.echarris.local:
8080
uInternet Settings,ProxyOverride = *.echarris.com;*.local;10.
*;*.echarr
is.local;*
.epin-port
al.com;*.c
ephren.co.
uk;*.bcis.
co.uk;hxxp
://
www.tionestop.com;*.cadweb.net;http://www.rs-uk.co.uk;*.citadon.co.uk;http://echonew*;*.lehman.com;172.16.2.6;*.brixhamfishmarket.info;<l
ocal>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFIC
E11\EXCEL.
EXE/3000
Trusted Zone: citadon.com
Trusted Zone: echarris.com
Trusted Zone: echarris.local
Trusted Zone: uk1immstsweb1vm
Trusted Zone: uk1immtstweb1vm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\cla
sses\xmlds
o.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D
4730F4EE49
9} - hxxp://
www.bitdefender.fr/scan_fr/scan8/oscan8.cabDPF: {6BD88D94-03D2-4ABF-99A3-7
8E9C87DFCA
5} - hxxps://abw.echarris.com/a
gresso/api
/com/axmlc
omp.cab
FF - ProfilePath - c:\documents and settings\paviej\Applicatio
n Data\Mozilla\Firefox\Profi
les\1k703k
36.default
\
FF - prefs.js: browser.startup.homepage - hxxp://myportal.echarris.c
om/
FF - prefs.js: network.proxy.ftp - internetuk.echarris.local
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.gopher - internetuk.echarris.local
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.http - internetuk.echarris.local
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - internetuk.echarris.local
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - internetuk.echarris.local
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 1
.
**************************
**********
**********
**********
**********
********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-10 12:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
**********
**********
**********
**********
********
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1952)
c:\windows\system32\igfxde
v.dll
.
Completion time: 2009-08-10 12:06
ComboFix-quarantined-files
.txt 2009-08-10 10:06
ComboFix2.txt 2009-08-06 11:30
Pre-Run: 2,822,086,656 bytes free
Post-Run: 2,796,343,296 bytes free
217