Hi
here is the new Combofix Log now
ComboFix 09-08-31.04 - musical 09/01/2009 22:43.2.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.652 [GMT 5.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090831-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
.
2009-08-29 05:28 . 2009-08-29 05:28 ——– d–h–w- c:\windows\PIF
2009-08-22 08:21 . 2009-08-17 16:04 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-22 08:21 . 2009-08-17 16:04 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-22 08:21 . 2009-08-17 16:03 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-22 08:21 . 2009-08-17 16:02 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-22 08:21 . 2009-08-17 16:05 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-22 08:21 . 2009-08-17 16:05 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-22 08:21 . 2009-08-17 16:06 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-22 08:21 . 2009-08-17 16:06 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-22 08:20 . 2009-08-17 16:10 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-22 08:20 . 2003-03-18 21:20 1060864 —-a-w- c:\windows\system32\MFC71.dll
2009-08-22 08:20 . 2009-08-22 08:20 ——– d—–w- c:\program files\Alwil Software
2009-08-22 07:44 . 2009-08-22 07:44 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-08-22 07:44 . 2009-08-22 07:44 ——– d—–w- c:\program files\NOS
2009-08-22 07:44 . 2009-08-22 07:44 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-22 07:44 . 2009-08-07 07:14 30400 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-08-22 07:44 . 2009-08-07 07:14 22848 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-08-22 07:44 . 2009-08-07 07:14 19792 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-08-20 09:37 . 2009-08-20 09:37 ——– d—–w- c:\program files\SpywareGuard
2009-08-20 09:14 . 2009-08-20 09:14 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-20 09:14 . 2009-08-20 09:14 ——– d—–w- c:\program files\SpywareBlaster
2009-08-20 09:14 . 2005-08-25 13:48 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL
2009-08-20 06:54 . 1998-10-29 11:15 306688 —-a-w- c:\windows\IsUninst.exe
2009-08-19 20:33 . 2009-08-19 20:33 ——– d—–w- c:\program files\Trend Micro
2009-08-19 16:13 . 2009-08-19 16:13 ——– d—–w- c:\program files\CCleaner
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\documents and settings\musical\Application Data\Malwarebytes
2009-08-19 15:00 . 2009-08-03 08:06 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-19 15:00 . 2009-08-03 08:06 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 14:23 . 2009-08-19 14:23 ——– d—–w- c:\documents and settings\musical\Application Data\WinPatrol
2009-08-19 14:23 . 2009-07-31 08:25 0 —-a-w- c:\documents and settings\musical\Application Data\WinPatrol\Config.sys
2009-08-19 14:23 . 2009-07-31 08:25 0 —-a-w- c:\documents and settings\musical\Application Data\WinPatrol\Autoexec.bat
2009-08-19 14:23 . 2009-08-19 14:23 ——– d—–w- c:\program files\BillP Studios
2009-08-19 11:46 . 2009-08-19 11:46 ——– d—–w- c:\program files\ERUNT
2009-08-19 10:59 . 2009-08-19 10:59 0 —-a-w- c:\windows\nsreg.dat
2009-08-19 10:57 . 2009-08-19 10:57 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Mozilla
2009-08-17 07:53 . 2009-08-17 07:53 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-08-17 07:53 . 2009-08-17 07:53 ——– d—–w- c:\program files\DivX
2009-08-15 09:21 . 2009-08-15 09:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Apple
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\program files\Apple Software Update
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-08-15 09:18 . 2009-08-15 09:18 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Apple Computer
2009-08-14 21:43 . 2009-08-14 21:43 ——– d—–w- c:\program files\Common Files\xing shared
2009-08-14 21:43 . 2009-08-14 21:43 ——– d—–w- c:\program files\Common Files\Real
2009-08-11 19:14 . 2009-08-11 19:14 ——– d—–w- c:\documents and settings\musical\Application Data\vlc
2009-08-11 18:20 . 2009-08-11 18:20 ——– d—–w- c:\documents and settings\musical\Application Data\dvdcss
2009-08-11 18:19 . 2009-08-11 18:19 ——– d—–w- c:\program files\VideoLAN
2009-08-08 11:06 . 2009-03-09 09:57 453456 —-a-w- c:\windows\system32\d3dx10_41.dll
2009-08-08 11:06 . 2009-03-09 09:57 1846632 —-a-w- c:\windows\system32\D3DCompiler_41.dll
2009-08-08 11:06 . 2009-03-09 09:57 4178264 —-a-w- c:\windows\system32\D3DX9_41.dll
2009-08-07 19:31 . 2006-12-07 05:15 110592 —-a-w- c:\documents and settings\musical\Application Data\U3\temp\cleanup.exe
2009-08-07 19:19 . 2009-08-07 19:19 ——– d—–w- C:\Sun
2009-08-07 18:59 . 2006-12-07 05:15 3096576 —ha-w- c:\documents and settings\musical\Application Data\U3\temp\Launchpad Removal.exe
2009-08-07 18:58 . 2009-08-07 18:58 ——– d—–w- c:\documents and settings\musical\Application Data\U3
2009-08-07 16:40 . 2009-08-07 16:40 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Identities
2009-08-07 16:25 . 2009-08-07 16:25 ——– d—–w- c:\windows\system32\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-14 21:43 . 2009-07-31 12:47 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-08-14 21:43 . 2009-07-31 12:47 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-08-10 14:46 . 2004-07-17 05:06 12464 —-a-w- c:\windows\system32\drivers\secdrv.sys
2009-08-02 07:09 . 2009-08-02 07:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Propellerhead Software
2009-08-02 07:09 . 2009-08-02 07:09 233472 —-a-w- c:\windows\system32\REX Shared Library.dll
2009-08-02 07:09 . 2009-08-02 07:09 225280 —-a-w- c:\windows\system32\ReWire.dll
2009-08-02 07:09 . 2009-08-02 07:09 ——– d—–w- c:\documents and settings\musical\Application Data\Propellerhead Software
2009-08-02 07:05 . 2009-08-02 07:05 ——– d—–w- c:\documents and settings\All Users\Application Data\DFX
2009-08-02 07:05 . 2009-08-02 07:05 ——– d—–w- c:\program files\Common Files\DFX
2009-08-02 06:48 . 2009-08-02 06:47 ——– d—–w- c:\program files\BitLord
2009-07-31 20:23 . 2009-07-31 20:23 1024 —h–r- c:\windows\system32\ntiembed.dll
2009-07-31 20:20 . 2009-07-31 20:19 ——– d—–w- c:\program files\NewTech Infosystems
2009-07-31 20:19 . 2009-07-31 20:19 1024 —h–r- c:\windows\system32\NTIMPEG2.dll
2009-07-31 20:19 . 2009-07-31 20:19 1024 —h–r- c:\windows\system32\NTICDMK32.dll
2009-07-31 20:19 . 2009-07-31 20:19 6912 —-a-w- c:\windows\system32\drivers\NTIDrvr.sys
2009-07-31 15:34 . 2009-07-31 15:34 ——– d—–w- c:\program files\Common Files\Ahead
2009-07-31 15:34 . 2009-07-31 15:34 ——– d—–w- c:\program files\Ahead
2009-07-31 15:20 . 2009-07-31 15:20 ——– d—–w- c:\program files\WIDCOMM
2009-07-31 12:55 . 2009-07-31 12:55 12328 —-a-w- c:\documents and settings\musical\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-31 12:55 . 2009-07-31 12:55 ——– d—–w- c:\program files\Symantec
2009-07-31 12:55 . 2009-07-31 12:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-31 12:54 . 2009-07-31 12:54 ——– d—–w- c:\program files\NavNT
2009-07-31 11:38 . 2009-07-31 11:38 ——– d—–w- c:\program files\Broadcom
2009-07-31 11:35 . 2009-07-31 11:35 17801 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-31 10:15 . 2009-07-31 08:24 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-31 09:10 . 2009-07-31 09:10 ——– d—–w- c:\documents and settings\musical\Application Data\Intel
2009-07-31 09:08 . 2009-07-31 09:08 ——– d—–w- c:\program files\Intel
2009-07-31 08:56 . 2009-07-31 08:56 ——– d—–w- c:\documents and settings\musical\Application Data\AdobeUM
2009-07-31 08:56 . 2009-07-31 08:56 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-31 08:39 . 2009-07-31 08:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-31 08:39 . 2009-07-31 08:39 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-31 08:26 . 2009-07-31 08:26 ——– d—–w- c:\program files\microsoft frontpage
2009-07-31 08:20 . 2009-07-31 08:20 21640 —-a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-08-30_04.34.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-01 16:14 . 2009-09-01 16:14 16384 c:\windows\Temp\Perflib_Perfdata_784.dat
+ 2004-08-03 16:45 . 2004-08-03 16:45 574592 c:\windows\system32\drivers\ntfs.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-03-22 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-03-22 126976]
"QuickTime Task"="d:\quicktime7.62\qttask.exe" [2009-05-26 413696]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-07-27 341312]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-14 198160]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-04-15 88202]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-01 77824]
c:\documents and settings\musical\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-5-25 565309]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"btwdins"=2 (0x2)
"wuauserv"=2 (0x2)
"Themes"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"d:\\pd\\bin\\pd.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/22/2009 1:51 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/22/2009 1:51 PM 20560]
S3 getPlusHelper;getPlus® Helper;c:\windows\System32\svchost.exe -k getPlusHelper [8/3/2004 11:56 PM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.imdb.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\
FF - component: d:\realplayer11\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: d:\acrobat 6.0\Reader\browser\nppdf32.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin2.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin3.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin4.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin5.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin6.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin7.dll
FF - plugin: d:\realplayer11\Netscape6\nppl3260.dll
FF - plugin: d:\realplayer11\Netscape6\nprjplug.dll
FF - plugin: d:\realplayer11\Netscape6\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-01 22:46
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(608)
c:\windows\System32\BCMLogon.dll
c:\windows\system32\NavLogon.dll
.
Completion time: 2009-09-01 22:47
ComboFix-quarantined-files.txt 2009-09-01 17:17
ComboFix2.txt 2009-08-30 04:36
Pre-Run: 15,294,414,848 bytes free
Post-Run: 15,267,856,384 bytes free
203