As requested:
Combo fix Log
ComboFix 09-05-30.03 - Christina 05/30/2009 20:19.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1447 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Christina\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_IVCLZBM
——-\Service_ivclzbm
——-\Service_jeswxd
——-\Service_mhjm
——-\Service_nxxp
——-\Service_pfmd
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.
2009-05-30 18:23 . 2009-05-30 18:23 ——– d–h–w c:\windows\PIF
2009-05-26 23:55 . 2009-05-26 23:55 3371383 —-a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-21 05:44 . 2009-05-09 17:07 2051864 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avgcorex.dll
2009-05-21 05:44 . 2009-05-09 17:07 354584 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avgxch32.dll
2009-05-21 05:44 . 2009-05-09 17:07 424472 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avgwdwsc.dll
2009-05-21 05:44 . 2009-05-09 17:07 312088 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avglngx.dll
2009-05-21 05:44 . 2009-05-09 17:07 177432 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avgmail.dll
2009-05-21 05:44 . 2009-05-09 17:07 3288344 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\setup.exe
2009-05-21 05:44 . 2009-05-09 17:07 486168 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avgrsx.exe
2009-05-21 05:43 . 2009-05-09 17:04 1437464 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avgupd.dll
2009-05-21 05:43 . 2009-05-09 17:04 755992 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avginet.dll
2009-05-18 15:59 . 2009-05-26 18:19 19096 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-18 15:59 . 2009-05-26 18:20 40160 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-18 15:59 . 2009-05-26 23:56 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-13 14:54 . 2009-05-09 17:07 2302232 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avguiadv.dll
2009-05-13 14:54 . 2009-05-09 17:07 3399960 —-a-w c:\documents and settings\All Users\Application Data\Avg8\update\backup\avgui.exe
2009-05-02 00:14 . 2009-05-02 00:14 ——– d—–w c:\program files\iPod
2009-05-02 00:13 . 2009-05-02 00:14 ——– d—–w c:\program files\iTunes
2009-05-02 00:13 . 2009-05-02 00:14 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-02 00:06 . 2009-05-02 00:06 75048 —-a-w c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-31 01:24 . 2008-02-19 17:17 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-30 03:19 . 2008-10-18 19:58 ——– d—–w c:\documents and settings\Christina\Application Data\Azureus
2009-05-18 16:38 . 2008-10-10 13:04 1324 —-a-w c:\windows\system32\d3d9caps.dat
2009-05-16 18:27 . 2008-12-25 07:07 ——– d—–w c:\documents and settings\All Users\Application Data\Avg8
2009-05-12 21:20 . 2008-02-28 03:53 ——– d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-12 21:10 . 2008-02-19 16:47 41859 —-a-w c:\windows\system32\nvModes.dat
2009-05-09 17:07 . 2008-12-25 07:30 11952 —-a-w c:\windows\system32\avgrsstx.dll
2009-05-09 17:07 . 2008-12-25 07:30 325896 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-09 17:07 . 2008-12-25 07:30 27784 —-a-w c:\windows\system32\drivers\avgmfx86.sys
2009-05-02 00:14 . 2008-03-04 05:12 ——– d—–w c:\program files\Common Files\Apple
2009-04-25 20:52 . 2009-04-25 20:52 4141117 —-a-w c:\documents and settings\Christina\Application Data\Azureus\plugins\vuzexcode\mediainfo.exe
2009-04-25 20:52 . 2009-04-25 20:52 6516755 —-a-w c:\documents and settings\Christina\Application Data\Azureus\plugins\vuzexcode\ffmpeg.exe
2009-04-25 20:51 . 2009-04-25 20:51 15884 —-a-w c:\documents and settings\Christina\Application Data\Azureus\plugins\azitunes\libProcessAccess.dll
2009-04-25 20:51 . 2009-04-25 20:51 102400 —-a-w c:\documents and settings\Christina\Application Data\Azureus\plugins\azitunes\jacob-1.14.3-x86.dll
2009-04-23 00:51 . 2009-04-19 05:58 280128 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-20 08:01 . 2008-02-19 17:15 ——– d—–w c:\program files\Microsoft Works
2009-04-19 06:17 . 2009-04-19 06:17 ——– d—–w c:\program files\Microsoft
2009-04-19 06:17 . 2009-04-19 06:16 ——– d—–w c:\program files\Windows Live
2009-04-19 06:17 . 2009-04-19 06:17 ——– d—–w c:\program files\Windows Live SkyDrive
2009-04-19 06:12 . 2009-04-19 06:12 ——– d—–w c:\program files\Common Files\Windows Live
2009-04-19 06:12 . 2008-02-25 15:46 72760 —-a-w c:\documents and settings\Christina\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-19 06:06 . 2009-04-19 06:06 ——– d—–w c:\program files\Microsoft LifeCam
2009-04-19 05:37 . 2008-02-28 03:57 ——– d—–w c:\program files\MSBuild
2009-04-19 05:33 . 2009-04-19 05:33 ——– d—–w c:\program files\Reference Assemblies
2009-04-11 01:57 . 2008-10-18 19:58 ——– d—–w c:\program files\Vuze
2009-03-19 21:32 . 2009-03-19 21:32 23400 —-a-w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 21:32 . 2008-01-29 17:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-17 19:24 . 2009-04-19 06:06 30560 —-a-w c:\windows\system32\drivers\nx6000.sys
2009-03-17 19:24 . 2009-04-19 06:06 186208 —-a-w c:\windows\system32\LCCoin20.dll
2009-03-06 14:22 . 2004-08-04 10:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-06 04:59 . 2009-03-27 00:31 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-03-06 04:59 . 2008-03-04 05:12 36864 —-a-w c:\windows\system32\drivers\usbaapl.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="1" [X]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8429568]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-03 851968]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-11 2183168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-11-01 189736]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-04 111936]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-09 1947928]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-03-17 157552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2005-08-24 442455]
"NVHotkey"="nvHotkey.dll" - c:\windows\system32\nvhotkey.dll [2007-06-06 67584]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-06 1626112]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2007-06-06 405504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"NoActiveDesktopChanges"="00000000" [X]
"NoActiveDesktop"="0 (0x0)" [X]
"NoSaveSettings"="0 (0x0)" [X]
"ClassicShell"="0 (0x0)" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AT&T Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2008-2-28 217088]
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-2-19 7168]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-2-19 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-26 20:32 10536 —-a-w c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-09 17:07 11952 —-a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ASKService"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/25/2008 2:30 AM 325896]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/25/2008 2:29 AM 298776]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [8/23/2007 7:29 PM 5376]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX2000/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [4/19/2009 1:06 AM 30560]
S3 pcistub;pcistub;\??\c:\windows\system32\pcistub.sys –> c:\windows\system32\pcistub.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2008-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Christina\Application Data\Mozilla\Firefox\Profiles\dzyinj89.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-30 20:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
NoActiveDesktopChanges = 3F 00 00 00
NoActiveDesktop = 63
NoSaveSettings = 63
ClassicShell = 63
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(880)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(2604)
c:\program files\RocketDock\RocketDock.dll
c:\progra~1\SBCSEL~1\SMARTB~1\SBHook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\SBC Self Support Tool\bin\mpbtn.exe
c:\program files\Dell Network Assistant\ezi_hnm2.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Java\jre1.6.0_05\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-05-31 20:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-31 01:32
ComboFix2.txt 2009-05-30 23:00
Pre-Run: 78,552,444,928 bytes free
Post-Run: 78,533,963,776 bytes free
225 — E O F — 2009-05-12 21:20
Gooredfix Log
GooredFix v1.92 by jpshortstuff
Log created at 20:44 on 30/05/2009 running Option #1 (Christina)
Firefox version 3.0.10 (en-US)
=====Suspect Goored Entries=====
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{9B83A05F-8DC4-4832-8702-023AC3B35821}"="C:\Documents and Settings\Ronald\Local Settings\Application Data\{9B83A05F-8DC4-4832-8702-023AC3B35821}\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{DD12ADD3-202D-427E-A5C2-E71AB4656A2F}"="C:\Documents and Settings\Doomsday\Local Settings\Application Data\{DD12ADD3-202D-427E-A5C2-E71AB4656A2F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{1B560433-93BF-43E4-8DE7-C206824A62A9}"="C:\Documents and Settings\Christina\Local Settings\Application Data\{1B560433-93BF-43E4-8DE7-C206824A62A9}"
=====Dumping Registry Values=====
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{9B83A05F-8DC4-4832-8702-023AC3B35821}"="C:\Documents and Settings\Ronald\Local Settings\Application Data\{9B83A05F-8DC4-4832-8702-023AC3B35821}\"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{DD12ADD3-202D-427E-A5C2-E71AB4656A2F}"="C:\Documents and Settings\Doomsday\Local Settings\Application Data\{DD12ADD3-202D-427E-A5C2-E71AB4656A2F}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{1B560433-93BF-43E4-8DE7-C206824A62A9}"="C:\Documents and Settings\Christina\Local Settings\Application Data\{1B560433-93BF-43E4-8DE7-C206824A62A9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{1d5287d1-8a92-0001-1f31-1cec198018d8}"="C:\Program Files\AVG\AVG8\ToolbarFF"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"
Malwarebytes Log
Malwarebytes' Anti-Malware 1.37
Database version: 2198
Windows 5.1.2600 Service Pack 3
5/30/2009 8:50:41 PM
mbam-log-2009-05-30 (20-50-41).txt
Scan type: Quick Scan
Objects scanned: 101303
Time elapsed: 4 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
No Malicious items were detected in the Malwarebytes scan.