ComboFix 09-10-01.05 - Helen Melon 04/10/2009 1:02.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1014.608 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\jgh.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\ojyf.reg
c:\documents and settings\All Users\Application Data\upirumifug.inf
c:\documents and settings\ALLUSE~\Google
c:\documents and settings\Helen Melon\Application Data\jove.reg
c:\documents and settings\Helen Melon\Application Data\lizkavd.exe
c:\documents and settings\Helen Melon\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Helen Melon\Application Data\vulebubume.inf
c:\documents and settings\Helen Melon\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Helen Melon\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Helen Melon\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
C:\p2hhr.bat
c:\program files\Common Files\ipojow.com
c:\recycler\S-1-5-21-2626753545-2741395014-3987291170-1003
c:\recycler\S-1-5-21-3610190352-1894798032-2927353088-1003
c:\recycler\S-1-5-21-4272118574-3248610337-857847958-1003
c:\windows\ahubynin.dl
c:\windows\cosohyqibu.pif
c:\windows\eravoky.ban
c:\windows\ibahehujuk._dl
c:\windows\Installer\1a1aca3.msp
c:\windows\Installer\6372cd.msp
c:\windows\Installer\b2aecc.msp
c:\windows\myxohece.bat
c:\windows\nuhy.dll
c:\windows\system32\drivers\SKYNETbqbuypib.sys
c:\windows\system32\drivers\UAChrxoirrslk.sys
c:\windows\system32\gazifunu.inf
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\nsprs.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\serauth1.dll
c:\windows\system32\serauth2.dll
c:\windows\system32\SKYNETmlwapboe.dll
c:\windows\system32\SKYNETnnowxrsm.dll
c:\windows\system32\SKYNETrjoehelu.dat
c:\windows\system32\SKYNETwfvpijtv.dll
c:\windows\system32\SKYNETxmqsnswe.dat
c:\windows\system32\UAChoykrhvtnl.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACltyblwhdnq.dll
c:\windows\system32\UACqowyerbnep.dll
c:\windows\system32\UACrsbvpwmeta.log
c:\windows\system32\UACtqtyikfwfv.dll
c:\windows\system32\UACwrbilvkjsr.db
c:\windows\system32\UACypixmkmodm.dll
c:\windows\system32\wbem\proquota.exe
c:\windows\vixa.reg
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_SKYNEToppfakdv
——-\Legacy_SKYNEToppfakdv
——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-09-04 to 2009-10-04 )))))))))))))))))))))))))))))))
.
2009-10-04 00:08 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2009-10-03 13:09 . 2009-10-03 13:09 ——– d—–w- c:\windows\ERUNT
2009-10-03 13:01 . 2009-10-03 13:09 ——– d—–w- C:\SDFix
2009-10-03 12:56 . 2009-10-03 12:56 ——– d—–w- C:\_OTM
2009-10-03 12:32 . 2009-10-03 12:32 293 —-a-w- C:\MGlogs.zip
2009-10-03 12:32 . 2009-10-03 12:32 ——– d—–w- C:\MGtools
2009-10-03 12:05 . 2009-10-03 12:05 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-10-03 02:26 . 2008-12-11 07:38 159600 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-10-03 02:26 . 2009-08-24 13:05 206256 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-03 02:26 . 2009-08-19 10:01 86888 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-03 02:25 . 2009-10-03 02:29 ——– d—–w- c:\program files\Common Files\PC Tools
2009-10-03 02:25 . 2008-12-10 10:36 64392 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-10-03 02:25 . 2009-10-03 02:29 ——– d—–w- c:\program files\Spyware Doctor
2009-10-03 02:25 . 2009-10-03 02:25 ——– d—–w- c:\documents and settings\Helen Melon\Application Data\PC Tools
2009-10-03 02:25 . 2009-10-03 02:25 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-10-03 02:25 . 2009-10-03 02:49 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-03 02:00 . 2009-10-03 02:00 256 —-a-w- c:\windows\system32\nk.dat
2009-10-03 01:58 . 2009-10-03 01:58 45 —-a-w- c:\windows\system32\ca.dat
2009-10-03 01:50 . 2009-10-03 01:50 1 —-a-w- c:\windows\system32\xd.dat
2009-10-03 01:50 . 2009-10-03 01:50 1 —-a-w- c:\windows\system32\jc.dat
2009-10-03 01:50 . 2009-10-03 01:50 1 —-a-w- c:\windows\system32\idm.dat
2009-10-03 01:50 . 2009-10-03 01:50 1 —-a-w- c:\windows\system32\c2d.dat
2009-10-03 01:49 . 2009-10-03 01:49 46080 —-a-w- c:\windows\system32\nspr02.dll
2009-10-03 01:48 . 2009-10-03 01:48 ——– d-sh–w- c:\documents and settings\Helen Melon\PrivacIE
2009-10-03 01:48 . 2009-10-03 01:48 46080 —-a-w- c:\windows\system32\nspr01.dll
2009-10-03 01:39 . 2009-10-03 01:39 199868 —-a-w- C:\hufa.exe
2009-10-03 01:39 . 2009-10-03 01:39 19456 —-a-w- C:\erupquii.exe
2009-10-03 01:39 . 2009-10-03 01:39 5632 —-a-w- C:\efbcmkj.exe
2009-10-03 01:39 . 2009-10-03 01:39 45568 —-a-w- C:\oaksorc.exe
2009-10-03 00:48 . 2009-10-03 00:50 ——– d—–w- c:\program files\Wise Registry Cleaner
2009-10-03 00:42 . 2009-10-03 01:04 ——– d—–w- c:\program files\Wise Disk Cleaner
2009-09-28 23:26 . 2009-10-03 01:29 ——– d—–w- c:\documents and settings\Helen Melon\Application Data\vlc
2009-09-28 23:24 . 2009-09-28 23:24 ——– d—–w- c:\program files\VideoLAN
2009-09-25 21:56 . 2009-09-25 21:56 11264 —-a-w- c:\windows\system32\lpomf.dll
2009-09-19 23:31 . 2009-09-19 23:32 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-09-19 19:10 . 2009-09-19 19:10 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-09-19 19:08 . 2009-10-03 14:21 0 —-a-w- c:\windows\win32k.sys
2009-09-19 01:30 . 2009-09-19 01:30 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2009-09-19 01:21 . 2009-09-19 01:21 1 —-a-w- c:\windows\system32\q1.dat
2009-09-19 01:03 . 2009-09-19 01:08 ——– d—–w- c:\documents and settings\Helen Melon\Application Data\Spotify
2009-09-19 01:03 . 2009-09-19 01:04 ——– d—–w- c:\documents and settings\Helen Melon\Local Settings\Application Data\Spotify
2009-09-19 01:03 . 2009-09-19 01:03 ——– d—–w- c:\program files\Spotify
2009-09-16 23:19 . 2009-09-19 00:37 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-09-15 22:45 . 2009-09-15 22:45 44032 —-a-w- c:\windows\system32\yxhl0.dll
2009-09-11 00:46 . 2009-06-21 21:44 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-04 00:09 . 2007-07-09 17:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Kontiki
2009-10-03 12:57 . 2009-08-16 16:51 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-10-03 12:39 . 2009-08-14 23:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-03 01:49 . 2009-10-03 01:49 16609 —-a-w- c:\documents and settings\Helen Melon\Application Data\howyreqyce.dat
2009-10-03 01:49 . 2009-10-03 01:49 17136 —-a-w- c:\program files\Common Files\cuhupodi.lib
2009-10-03 01:07 . 2006-02-22 18:21 ——– d—–w- c:\program files\Java
2009-09-27 23:36 . 2009-08-14 00:14 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-09-26 19:08 . 2006-07-30 14:02 49544 —-a-w- c:\documents and settings\Helen Melon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-26 19:08 . 2008-01-22 20:41 ——– d—–w- c:\program files\Windows Live
2009-09-12 17:53 . 2009-01-06 00:29 ——– d—–w- c:\program files\Microsoft Silverlight
2009-09-10 13:54 . 2009-08-16 16:51 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 13:53 . 2009-08-16 16:51 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-26 00:27 . 2007-11-17 16:45 ——– d—–w- c:\program files\DivX
2009-08-26 00:26 . 2009-08-26 00:26 4780600 —-a-w- C:\DivXWebPlayerInstaller.exe
2009-08-23 14:45 . 2008-12-25 00:07 ——– d—–w- c:\program files\Kontiki
2009-08-23 13:59 . 2009-08-23 13:59 267152 —-a-w- C:\zaSetup_en.exe
2009-08-22 16:14 . 2009-08-22 16:14 ——– d—–w- c:\program files\MSBuild
2009-08-22 16:13 . 2009-08-22 16:13 ——– d—–w- c:\program files\Reference Assemblies
2009-08-22 16:07 . 2009-08-22 16:07 ——– d—–w- c:\program files\MSXML 6.0
2009-08-17 00:15 . 2009-08-17 00:15 1144168 —-a-w- C:\wlsetup-custom.exe
2009-08-16 18:45 . 2009-08-16 18:45 ——– d—–w- c:\documents and settings\Helen Melon\Application Data\Malwarebytes
2009-08-16 17:01 . 2009-08-16 17:01 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-16 17:01 . 2009-08-16 16:59 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-08-16 16:59 . 2009-08-16 16:59 ——– d—–w- c:\documents and settings\Helen Melon\Application Data\SUPERAntiSpyware.com
2009-08-16 16:59 . 2007-08-20 14:38 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-16 16:59 . 2009-08-16 16:57 6881824 —-a-w- C:\SAS.exe
2009-08-16 16:54 . 2009-08-16 16:54 1343913 —-a-w- C:\MGtools.exe
2009-08-16 16:54 . 2009-08-16 16:54 464491 —-a-w- C:\RootRepeal.zip
2009-08-16 16:51 . 2009-08-16 16:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-16 16:30 . 2009-08-16 16:30 ——– d—–w- c:\program files\CCleaner
2009-08-16 16:28 . 2009-08-16 16:28 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-15 00:26 . 2009-08-15 00:25 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-15 00:25 . 2009-08-15 00:25 ——– d—–w- c:\program files\Lavasoft
2009-08-14 23:53 . 2009-08-14 23:51 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-14 05:58 . 2009-10-03 02:26 7396 —-a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-14 00:14 . 2009-08-14 00:14 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-14 00:14 . 2009-08-14 00:14 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-14 00:14 . 2009-08-14 00:14 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-14 00:14 . 2007-08-20 14:22 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-14 00:14 . 2009-08-14 00:14 ——– d—–w- c:\program files\AVG
2009-08-14 00:10 . 2009-08-14 00:10 ——– d—–w- c:\documents and settings\Helen Melon\Application Data\AVG8
2009-08-05 09:01 . 2006-02-22 03:32 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-26 15:44 . 2009-07-26 15:44 48448 —-a-w- c:\windows\system32\sirenacm.dll
2009-07-17 19:01 . 2006-02-22 03:32 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2006-02-22 03:33 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C2CEB3AB-FEEC-45F5-8ADE-B2C33A60D85D}]
2009-10-03 01:49 46080 —-a-w- c:\windows\system32\nspr02.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-02-27 1032376]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-10 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\773dd7e9-39a0-43e3-ace2-d4d35dc916eb.exe" [2009-08-05 1830128]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-05 282624]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 49152]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-05 180269]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-04-29 45056]
"PDService.exe"="c:\program files\Utimaco\SafeGuard PrivateDisk\pdservice.exe" [2004-07-06 40960]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-11 151552]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2005-10-19 184320]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-14 2007832]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-06-29 14720000]
"Mouse Suite 98 Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2002-03-14 45056]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-14 00:14 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 17:42 73728 —-a-w- c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [15/08/2009 01:26 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [03/10/2009 03:26 206256]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [14/08/2009 01:14 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [14/08/2009 01:14 108552]
R1 PrivateDisk;PrivateDisk;c:\windows\system32\drivers\privatediskm.sys [06/07/2004 15:07 45627]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/08/2009 16:06 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/08/2009 16:06 74480]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [14/08/2009 01:14 297752]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [14/08/2009 01:14 908056]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 15:49 1028432]
S3 DMSKSSRh;DMSKSSRh;\??\c:\docume~1\HELENM~1\LOCALS~1\Temp\DMSKSSRh.sys –> c:\docume~1\HELENM~1\LOCALS~1\Temp\DMSKSSRh.sys [?]
S3 P1001VID;Creative WebCam (WDM);c:\windows\system32\drivers\P1001Vid.sys [02/08/2006 14:09 395224]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/08/2009 16:06 7408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [03/10/2009 03:25 348824]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{69504635-DE84-4739-8D13-2B5C5616807F}]
rundll32 nspr02.dll,laspi
.
Contents of the 'Scheduled Tasks' folder
2009-10-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 00:26]
2009-10-03 c:\windows\Tasks\Wise Registry Cleaner 4.job
- c:\program files\Wise Registry Cleaner\WiseRegistryCleaner.exe [2009-10-03 12:40]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.club-vaio.com/en/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
LSP: lpomf.dll
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\Helen Melon\Application Data\Mozilla\Firefox\Profiles\964kqff7.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npBBCPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-04 01:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,f3,9f,ef,fd,77,c2,4b,92,c1,80,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,f3,9f,ef,fd,77,c2,4b,92,c1,80,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(684)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\VESWinlogon.dll
- - - - - - - > 'lsass.exe'(740)
c:\windows\system32\lpomf.dll
- - - - - - - > 'explorer.exe'(1392)
c:\windows\system32\WININET.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\windows\system32\ieframe.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Kontiki\KService.exe
c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Apoint\ApntEx.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-10-04 1:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-04 00:17
Pre-Run: 11,674,963,968 bytes free
Post-Run: 11,817,783,296 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
361 — E O F — 2009-09-13 02:01