Mr. Tomk;….
Here's the newest ComboFix report you asked for;…..
ComboFix 09-08-24.05 - Ron.M 08/25/2009 11:44.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.589 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ron.M\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 090825-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2009-07-25 to 2009-08-25 )))))))))))))))))))))))))))))))
.
2009-08-22 01:09 . 2009-08-03 20:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 01:09 . 2009-08-22 01:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 01:09 . 2009-08-03 20:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-20 02:23 . 2009-08-20 19:52 ——– d—–w- C:\Rooter$
2009-08-17 17:47 . 2009-08-17 17:47 ——– d—–w- c:\documents and settings\Ron.M\Application Data\Blitware
2009-08-16 21:40 . 2009-08-22 21:11 ——– d—–w- c:\documents and settings\Ron.M\Application Data\vlc
2009-08-11 21:30 . 2009-08-12 00:49 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-11 21:30 . 2009-08-12 00:49 ——– d—–w- c:\program files\NOS
2009-08-02 20:54 . 2009-08-02 20:54 16344 —ha-w- c:\windows\system32\mlfcache.dat
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\documents and settings\Ron.M\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
2009-08-02 20:19 . 2009-08-02 19:25 38208 —-a-w- c:\documents and settings\Ron.M\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\program files\Market Samurai
2009-08-02 20:19 . 2009-08-02 19:25 38208 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\program files\Common Files\Adobe AIR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-25 18:48 . 2009-04-26 21:54 ——– d—–w- c:\program files\DNA
2009-08-25 18:48 . 2009-04-26 21:54 ——– d—–w- c:\documents and settings\Ron.M\Application Data\DNA
2009-08-20 20:07 . 2009-04-30 21:32 1 —-a-w- c:\documents and settings\Ron.M\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-08-17 18:37 . 2009-04-13 22:14 ——– d—–w- c:\program files\Lx_cats
2009-08-17 16:10 . 2009-04-11 23:51 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-04-11 23:51 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-04-11 23:51 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-04-11 23:51 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-04-11 23:51 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-04-11 23:51 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-04-11 23:51 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-04-11 23:51 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-04-11 23:51 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-10 00:57 . 2009-04-26 21:54 ——– d—–w- c:\documents and settings\Ron.M\Application Data\BitTorrent
2009-08-05 18:09 . 2009-04-16 01:16 ——– d—–w- c:\program files\SpeedBit Video Accelerator
2009-08-05 09:01 . 2008-04-14 08:42 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-01 01:19 . 2009-05-16 22:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-25 17:53 . 2009-07-25 17:53 ——– d—–w- c:\program files\PCPitstop
2009-07-17 19:01 . 2008-04-14 08:41 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-15 02:59 . 2009-06-04 19:59 ——– d—–w- c:\program files\Free Offers from Freeze.com
2009-07-14 06:43 . 2008-04-14 08:42 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 01:00 . 2009-07-09 01:00 ——– d—–w- c:\program files\IGC
2009-07-09 01:00 . 2009-04-03 16:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-07 18:40 . 2009-07-07 19:29 801992 —-a-w- c:\documents and settings\All Users\Application Data\NetZero\Isp\NZHiSpeedUpdate.exe
2009-07-07 16:34 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverCure
2009-07-07 04:36 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\Ron.M\Application Data\DriverCure
2009-07-07 04:36 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-07-04 23:06 . 2009-07-04 23:06 ——– d—–w- c:\program files\QuickTime
2009-06-29 16:12 . 2008-04-14 08:42 827392 ——w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-07-22 05:33 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 08:41 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-26 09:41 . 2008-04-14 08:41 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:41 . 2008-04-14 08:42 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:41 . 2008-04-14 08:42 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:41 . 2008-04-14 08:42 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:41 . 2008-04-14 08:42 136704 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:41 . 2008-04-14 08:41 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 10:28 . 2008-04-14 03:01 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2008-04-14 08:42 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-14 08:41 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2008-04-14 08:42 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2008-04-14 08:42 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 16:19 . 2009-04-03 16:23 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2008-04-14 08:41 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:17 . 2008-04-14 08:42 134144 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-06 00:25 . 2009-06-06 00:25 1002044 —-a-w- c:\windows\system32\IDPExe.zip
2009-06-06 00:22 . 2009-06-06 00:22 1669117 —-a-w- c:\windows\system32\IDPSig.zip
2009-06-03 19:09 . 2008-04-14 08:42 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-29 01:23 . 2009-05-29 01:22 70984 —-a-w- c:\documents and settings\Ron.M\g2mdlhlpx.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-08-24_22.27.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-25 18:32 . 2009-08-25 18:32 167936 c:\windows\ERDNT\AutoBackup\8-25-2009\Users\00000002\UsrClass.dat
+ 2009-08-25 18:32 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\8-25-2009\ERDNT.EXE
+ 2009-08-25 18:32 . 2009-08-25 18:32 5967872 c:\windows\ERDNT\AutoBackup\8-25-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetZero_uoltray"="c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\exec.exe" [2008-05-07 1701376]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-04-26 321344]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-07-12 160592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-04 148888]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"LXCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 73728]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
c:\documents and settings\Ron.M\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Greenshot.lnk - c:\program files\Greenshot\Greenshot.exe [2009-5-16 528384]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/11/2009 4:51 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/11/2009 4:51 PM 20560]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [5/18/2009 1:16 PM 12672]
.
Contents of the 'Scheduled Tasks' folder
2009-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-602162358-1801674531-1005Core.job
- c:\documents and settings\Ron.M\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-25 20:37]
2009-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-602162358-1801674531-1005UA.job
- c:\documents and settings\Ron.M\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-25 20:37]
2009-08-25 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
2009-08-25 c:\windows\Tasks\User_Feed_Synchronization-{683CD518-5D3E-4546-AE4B-855F5DFEEAB7}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://my.netzero.net/s/sp?r=al&cf;=sp&ClientVersion;=8.4.0&mem;=ron.m&login;=3a0ba2a1607571fd0cce61dbca618e1b/ron.m:netzero.net/1239416131/30/sss.8.48463/&ts;=49dffd43&A;=739741990000009&B;=1212476400000&C;=1212476400000&D;=1222153200000&I;=8.NH4&N;=PLHSNAVUSERSSUSER&O;=I&UT;=
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
IE: Display All Images with Full Quality - c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\qsacc\appres.dll/228
IE: Display Image with Full Quality - c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\qsacc\appres.dll/227
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
TCP: {F4D53855-1F88-4FE7-873A-E5693E89EF5E} = 64.136.52.73 64.136.44.73
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-25 11:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCFCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-823518204-602162358-1801674531-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(516)
c:\progra~1\SPEEDB~1\sblsp.dll
c:\program files\SpeedBit Video Accelerator\ConfigDB.dll
c:\program files\SpeedBit Video Accelerator\Accelerator.dll
c:\windows\system32\WININET.dll
c:\program files\SpeedBit Video Accelerator\CommPipe.dll
c:\program files\SpeedBit Video Accelerator\Collector.dll
- - - - - - - > 'explorer.exe'(2328)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\qsacc\X1Exec.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-25 11:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-25 18:53
ComboFix2.txt 2009-08-24 22:28
Pre-Run: 30,930,800,640 bytes free
Post-Run: 30,886,395,904 bytes free
188 — E O F — 2009-08-24 21:12
Altho you did not ask for me to post the RootRepealReport , I'm assuming
you did not want it to just sit on my desktop…So here it is:….
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/25 12:05
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
——————-
Name: catchme.sys
Image Path: C:\ComboFix\catchme.sys
Address: 0xF78C6000 Size: 31744 File Visible: No Signed: -
Status: -
Name: Combo-Fix.sys
Image Path: Combo-Fix.sys
Address: 0xF760E000 Size: 60416 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA90FF000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AE2000 Size: 8192 File Visible: No Signed: -
Status: -
Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xF7B58000 Size: 6464 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA7C03000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f6b8
#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f574
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911fa52
#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f14c
#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f64e
#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f08c
#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f0f0
#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f76e
#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f72e
#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f8ae
==EOF==
THANK you for your help & removing my name from the item lists….
Have a GREAT day…..
Later…Ron.M…
