Catbyte,
Here are the firs two logs. I finished the Kapersky scan but couldnt find a bottom screen that looked like your example. When I started looking for it, I got away from and somehow lost the %&*^#@!! scan results! I will re-run the scan today and send it to you later.
Thanx,
John
combofix log
ComboFix 09-09-04.02 - mom 2009-09-05 14:37.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.576 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\WINSPSys
c:\documents and settings\All Users\Application Data\WINSPSys\winps.cfg
c:\documents and settings\mom\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Protection Suite.lnk
c:\documents and settings\mom\Application Data\Windows Protection Suite
C:\kmd.exe
c:\program files\Mozilla Firefox\searchplugins\search.xml
c:\recycler\S-1-5-21-3767295689-2469820063-725406000-500
c:\windows\BM333f20f1.txt
c:\windows\Installer\1be98d0.msi
c:\windows\Installer\1be98d7.msi
c:\windows\Installer\1be98de.msi
c:\windows\Installer\bf71a4.msi
c:\windows\Installer\e5ec7.msi
.
((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 )))))))))))))))))))))))))))))))
.
2009-09-05 18:44 . 2009-09-05 18:44 ——– d-sh–w- c:\documents and settings\mom\Application Data\Windows Protection Suite
2009-09-05 18:44 . 2009-09-05 18:46 ——– d-sh–w- c:\documents and settings\All Users\Application Data\WINSPSys
2009-09-04 18:13 . 2009-09-04 18:13 0 —-a-w- c:\documents and settings\mom\settings.dat
2009-08-27 19:12 . 2009-08-27 19:12 ——– d—–w- c:\documents and settings\mom\Application Data\ScanSoft
2009-08-24 20:24 . 2009-08-24 20:24 ——– d—–w- c:\documents and settings\mom\Application Data\Obsidium
2009-08-24 19:54 . 2009-08-24 19:54 ——– d—–w- c:\program files\MSECache
2009-08-24 00:40 . 2009-08-24 00:40 604140 –sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-08-24 00:38 . 2009-08-24 00:38 94643 —-a-w- c:\windows\system32\drivers\klick.dat
2009-08-24 00:38 . 2009-08-24 00:38 105395 —-a-w- c:\windows\system32\drivers\klin.dat
2009-08-24 00:37 . 2009-08-24 00:37 ——– d—–w- c:\program files\Kaspersky Lab
2009-08-24 00:28 . 2009-08-24 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-08-22 14:12 . 2009-09-05 18:45 ——– d-sh–w- c:\documents and settings\All Users\Application Data\5be0bd5
2009-08-15 20:01 . 2009-08-15 20:01 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-15 20:01 . 2009-08-15 20:01 ——– d—–w- c:\program files\MSBuild
2009-08-15 20:00 . 2009-08-15 20:00 ——– d—–w- c:\program files\Reference Assemblies
2009-08-15 20:00 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 20:00 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 20:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-15 20:00 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 20:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-15 20:00 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-15 20:00 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 20:00 . 2009-08-15 20:00 ——– d—–w- C:\07505760ec7a6afecf4b2d2a750a0271
2009-08-15 20:00 . 2009-08-16 18:17 ——– d—–w- c:\windows\SxsCaPendDel
2009-08-15 17:39 . 2001-08-17 17:53 6784 -c–a-w- c:\windows\system32\dllcache\serscan.sys
2009-08-15 17:39 . 2001-08-17 17:53 6784 —-a-w- c:\windows\system32\drivers\serscan.sys
2009-08-15 17:39 . 2009-08-15 17:39 65 —-a-w- c:\windows\system32\bd7345n.dat
2009-08-15 17:37 . 2007-01-25 21:16 94208 ——w- c:\windows\system32\BrDctF2.dll
2009-08-15 17:37 . 2007-01-16 01:54 12288 ——w- c:\windows\system32\BrDctF2S.dll
2009-08-15 17:37 . 2007-01-15 20:09 12288 ——w- c:\windows\system32\BrDctF2L.dll
2009-08-15 17:37 . 2006-12-21 15:23 176128 —-a-w- c:\windows\system32\BROSNMP.DLL
2009-08-15 17:37 . 2008-01-26 00:36 63488 ——w- c:\windows\system32\BrNetSti.dll
2009-08-15 17:37 . 2007-10-15 23:06 58368 ——w- c:\windows\system32\BrWiaNCp.dll
2009-08-15 17:37 . 2007-10-15 23:06 41472 ——w- c:\windows\system32\Brnsplg.dll
2009-08-15 17:37 . 2009-08-15 17:37 ——– d—–w- C:\Brother
2009-08-15 17:37 . 2007-07-25 05:04 126976 ——w- c:\windows\system32\BrfxD05a.dll
2009-08-15 17:37 . 2003-11-28 22:57 0 —-a-w- c:\windows\brdfxspd.dat
2009-08-15 17:29 . 2009-08-15 17:29 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2009-08-15 17:29 . 2009-08-15 17:30 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-08-13 14:42 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-08 22:13 . 2009-08-08 22:13 ——– d—–r- c:\documents and settings\mom\Application Data\Brother
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\mom\Local Settings\Application Data\Scansoft
2009-08-08 20:53 . 2009-08-08 20:53 ——– d—–w- c:\program files\Nuance
2009-08-08 20:52 . 2009-08-08 20:52 ——– d—–w- c:\program files\ScanSoft
2009-08-08 20:51 . 2009-08-08 20:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Brother
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-05 18:44 . 2008-02-26 01:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-09-05 18:13 . 2008-11-27 23:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-01 13:28 . 2005-05-04 05:15 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-31 20:24 . 2005-05-04 05:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-28 19:45 . 2008-07-29 01:14 ——– d—–w- c:\documents and settings\mom\Application Data\Apple Computer
2009-08-26 18:49 . 2005-05-11 03:17 ——– d—–w- c:\program files\Java
2009-08-25 13:26 . 2006-03-05 21:25 63392 —-a-w- c:\documents and settings\mom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-24 20:23 . 2006-11-10 22:19 ——– d—–w- c:\program files\NetIntellGames
2009-08-24 00:32 . 2005-05-04 02:49 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-24 00:32 . 2008-01-30 02:52 ——– d—–w- c:\program files\Symantec
2009-08-24 00:32 . 2008-01-30 02:52 ——– d—–w- c:\program files\Symantec AntiVirus
2009-08-24 00:32 . 2005-05-04 02:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-15 17:37 . 2009-08-08 20:59 ——– d—–w- c:\program files\Brother
2009-08-15 17:37 . 2005-05-04 03:30 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-05 09:01 . 2003-03-31 12:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 09:23 . 2008-11-27 02:53 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-18 18:28 . 2007-11-14 02:05 59040 —-a-w- c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-17 19:01 . 2003-03-31 12:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 07:56 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 17:33 . 2005-05-07 00:06 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-03 19:48 . 2009-07-03 19:48 219664 —-a-w- c:\windows\system32\klogon.dll
2009-07-03 19:45 . 2009-07-03 19:45 27507 —-a-w- c:\windows\system32\drivers\klopp.dat
2009-06-29 16:12 . 2005-02-18 20:19 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2003-03-31 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-16 21:06 . 2009-05-09 22:21 256 —-a-w- c:\windows\system32\pool.bin
2009-06-16 14:36 . 2003-03-31 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2003-03-31 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 18:01 . 2009-06-15 18:01 128016 —-a-w- c:\windows\system32\drivers\kl1.sys
2009-06-12 12:31 . 2003-03-31 12:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2003-03-31 12:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2003-03-31 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-05-04 02:33 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2003-03-31 12:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-22 19:41 . 2005-05-04 03:54 67696 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-06-22 19:41 . 2005-05-04 03:54 54376 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-06-22 19:41 . 2006-11-24 01:57 34952 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-06-22 19:41 . 2006-11-24 01:57 46720 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-06-22 19:41 . 2005-05-04 03:54 172144 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-27 39408]
"Windows Protection Suite"="c:\documents and settings\All Users\Application Data\5be0bd5\WI5be0.exe" [2009-08-22 2177536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-06-05 615696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-11-10 236016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-11-06 741376]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Brother\\Brmfl07b\\FAXRX.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\5be0bd5\\WI5be0.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"54925:UDP"= 54925:UDP:Brother Network Scanner
R0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys –> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808]
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [2004-07-01 89749]
R0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [2004-07-01 9600]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-05-13 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-05-16 19472]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-07-03 33752]
S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCCFLTR.SYS [2005-05-03 13724]
S3 USBMON;USB Monitor Device Driver;c:\windows\system32\drivers\usbmon.sys [2002-06-24 162540]
S3 z520bus;Sony Ericsson 520 driver (WDM);c:\windows\system32\drivers\z520bus.sys [2005-07-26 57648]
S3 z520mdfl;Sony Ericsson 520 USB WMC Modem Filter;c:\windows\system32\drivers\z520mdfl.sys [2005-07-26 8336]
S3 z520mdm;Sony Ericsson 520 USB WMC Modem Drivers;c:\windows\system32\drivers\z520mdm.sys [2005-07-26 93488]
S3 z520mgmt;Sony Ericsson 520 USB WMC Device Management Drivers;c:\windows\system32\drivers\z520mgmt.sys [2005-07-26 84928]
S3 z520obex;Sony Ericsson 520 USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\z520obex.sys [2005-07-26 82864]
.
Contents of the 'Scheduled Tasks' folder
2009-08-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2008-12-17 c:\windows\Tasks\DriverRobot.job
- c:\program files\Driver Robot\DriverRobot.exe [2008-12-16 22:43]
2009-04-24 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p officejet 6100 series5E771253C1676EBED677BF361FDFC537825E15B8232469525.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 05:52]
2009-09-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-03 18:55]
2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1060284298-725345543-1006Core.job
- c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-27 01:59]
2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1060284298-725345543-1006UA.job
- c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-27 01:59]
2009-09-05 c:\windows\Tasks\User_Feed_Synchronization-{75A8A06E-8F5C-4394-A422-FF1FBEA51F04}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 23:36]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\HOMERunner.exe
Notify-NavLogon - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: 66.129.114.121
Trusted Zone: Realfast.com
Trusted Zone: Realfast2.com
Trusted Zone: Realfast2go.com
Trusted Zone: realtytools.com
Trusted Zone: toolkitcma.com
Trusted Zone: toolkitcma2.com
DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} - hxxp://www.daviencrod.org/controls/LTOCX14N.cab
DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://triad.mlxtempo.com/5.0.05.46/Control/IRCSharc.cab
DPF: {9841D1AE-9C0B-11D3-9452-00105A098C21} - hxxp://www.daviencrod.org/controls/prntpro2.CAB
FF - ProfilePath - c:\documents and settings\mom\Application Data\Mozilla\Firefox\Profiles\1a6gcvcl.default\
FF - prefs.js: browser.startup.homepage - google.com/ig
FF - component: c:\progra~1\MOZILL~2\extensions\[removed]\components\KavLinkFilter.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-05 14:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1060)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1912)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP3\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Brother\ControlCenter3\BrccMCtl.exe
c:\program files\Brother\Brmfcmon\BrMfimon.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
.
**************************************************************************
.
Completion time: 2009-09-05 14:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-05 18:49
ComboFix2.txt 2008-03-01 02:42
Pre-Run: 50,907,176,960 bytes free
Post-Run: 51,031,715,840 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
289 — E O F — 2009-09-02 00:19
MBAM log:
Malwarebytes' Anti-Malware 1.40
Database version: 2745
Windows 5.1.2600 Service Pack 3
2009-09-05 16:11:41
mbam-log-2009-09-05 (16-11-41).txt
Scan type: Quick Scan
Objects scanned: 109243
Time elapsed: 4 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba4271e-5c1e-48e2-b432-d8bf420dd31d} (Rogue.DeusCleaner) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (
http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-19\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (
http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (
http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-20\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (
http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (
http://www.Google.com/) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)