Hello, scan spyware isn't in the add/remove programs list.
i deleted the vghd.scr, i've never used Xobni.
Here's the combofix2 log:
ComboFix 09-11-27.07 - Spike 11/28/2009 15:14.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.125 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Spike.com.exe
Command switches used :: c:\documents and settings\Spike\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
file zipped: c:\windows\system32\winsysdriver.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\plugin.dat
c:\windows\system32\winsysdriver.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-28 )))))))))))))))))))))))))))))))
.
2009-11-27 19:09 . 2009-11-27 19:09 ——– dc—-w- c:\documents and settings\Spike\Application Data\Malwarebytes
2009-11-27 19:09 . 2009-09-10 19:54 38224 -c–a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-27 19:09 . 2009-11-27 19:09 ——– dc—-w- c:\program files\Malwarebytes' Anti-Malware
2009-11-27 19:09 . 2009-11-27 19:09 ——– dc—-w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-27 19:09 . 2009-09-10 19:53 19160 -c–a-w- c:\windows\system32\drivers\mbam.sys
2009-11-27 16:41 . 2009-09-18 16:28 1115392 -c–a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-11-27 14:14 . 2009-11-27 14:14 ——– dc-h–w- c:\windows\PIF
2009-11-27 11:02 . 2009-11-27 11:02 ——– dc—-w- c:\program files\ERUNT
2009-11-27 10:29 . 2009-11-27 10:29 1110 -c–a-w- c:\documents and settings\Spike\cc_20091127_052940.reg
2009-11-27 10:26 . 2009-11-27 10:28 ——– dc—-w- c:\documents and settings\Spike\Application Data\ScanSpyware
2009-11-24 05:03 . 2009-11-24 05:03 842 -c–a-w- c:\documents and settings\Spike\cc_20091124_000322.reg
2009-11-24 04:19 . 2009-11-24 04:19 ——– dc—-w- C:\stdtsa
2009-11-24 03:57 . 2009-11-24 03:57 ——– dc—-w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-11-23 08:00 . 2009-11-23 08:00 164 -c–a-w- c:\documents and settings\Spike\cc_20091123_030031.reg
2009-11-22 11:32 . 2009-11-22 11:32 ——– dc—-w- c:\documents and settings\Spike\Local Settings\Application Data\WMTools Downloaded Files
2009-11-21 03:16 . 2009-11-21 03:16 ——– dc—-w- c:\documents and settings\All Users\Application Data\AIM
2009-11-21 03:16 . 2009-11-21 03:16 ——– dc—-w- c:\program files\AIM
2009-11-21 03:14 . 2009-11-21 03:14 ——– dc—-w- c:\program files\Common Files\Software Update Utility
2009-11-18 20:27 . 2009-11-18 20:27 19764 -c–a-w- c:\documents and settings\Spike\cc_20091118_152651.reg
2009-11-18 20:11 . 2009-11-18 20:11 ——– dc—-w- c:\program files\7-Zip
2009-11-18 08:41 . 2009-11-18 08:41 2328832 -c–a-w- c:\windows\system32\TUKernel.exe
2009-11-18 07:55 . 2009-11-18 07:55 152576 -c–a-w- c:\documents and settings\Spike\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-18 07:54 . 2009-11-18 07:54 79488 -c–a-w- c:\documents and settings\Spike\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-18 03:55 . 2009-11-18 06:56 ——– dc—-w- c:\program files\Common Files\Adobe
2009-11-18 02:07 . 2009-11-18 02:07 ——– dc—-w- c:\windows\Sun
2009-11-18 02:04 . 2009-10-11 09:17 411368 -c–a-w- c:\windows\system32\deploytk.dll
2009-11-18 02:03 . 2009-11-18 07:57 ——– dc—-w- c:\program files\Java
2009-11-18 02:02 . 2009-11-18 02:02 152576 -c–a-w- c:\documents and settings\Spike\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-11-17 14:46 . 2009-07-15 09:48 29000 -c–a-w- c:\windows\system32\uxtuneup.dll
2009-11-17 14:46 . 2009-11-17 14:46 361288 -c–a-w- c:\windows\system32\TuneUpDefragService.exe
2009-11-12 05:41 . 2009-11-28 09:42 ——– dc—-w- c:\documents and settings\Spike\Application Data\vlc
2009-11-12 04:11 . 2009-11-12 04:11 ——– dc—-w- c:\program files\VideoLAN
2009-11-12 03:54 . 2009-05-27 00:50 607472 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-11-12 03:53 . 2009-11-12 03:54 ——– dc—-w- c:\program files\Yahoo!
2009-11-12 03:29 . 2009-11-17 14:46 604488 -c–a-w- c:\windows\system32\TUProgSt.exe
2009-11-12 03:23 . 2009-11-12 03:23 5370 -c–a-w- c:\documents and settings\Spike\cc_20091111_222255.reg
2009-11-11 10:10 . 2009-11-11 10:10 ——– dc—-w- c:\documents and settings\Spike\Local Settings\Application Data\Identities
2009-11-10 05:57 . 2009-11-10 05:57 1144 -c–a-w- c:\documents and settings\Spike\cc_20091110_005659.reg
2009-11-10 05:56 . 2009-11-10 05:56 82 -c–a-w- c:\documents and settings\Spike\cc_20091110_005654.reg
2009-11-10 05:28 . 2009-11-10 05:28 28196 -c–a-w- c:\documents and settings\Spike\cc_20091110_002846.reg
2009-11-10 05:08 . 2009-11-10 05:08 844 -c–a-w- c:\documents and settings\Spike\cc_20091110_000823.reg
2009-11-09 19:41 . 2009-11-09 19:41 4960 -c–a-w- c:\documents and settings\Spike\cc_20091109_144141.reg
2009-11-09 19:32 . 2009-11-09 19:32 4180 -c–a-w- c:\documents and settings\Spike\cc_20091109_143207.reg
2009-11-09 09:21 . 2009-11-10 07:48 ——– dc—-w- c:\program files\Common Files\Blizzard Entertainment
2009-11-09 07:29 . 2009-11-09 07:32 ——– dc—-w- c:\documents and settings\Spike\Application Data\acccore
2009-11-09 07:28 . 2009-11-21 03:36 ——– dc—-w- c:\documents and settings\Spike\Local Settings\Application Data\AIM
2009-11-09 07:28 . 2009-11-09 07:28 ——– dc—-w- c:\documents and settings\Spike\Local Settings\Application Data\AOL
2009-11-09 07:27 . 2009-11-21 03:14 ——– dc—-w- c:\program files\Common Files\AOL
2009-11-09 06:58 . 2009-11-09 06:58 1278 -c–a-w- c:\documents and settings\Spike\cc_20091109_015801.reg
2009-11-08 07:52 . 2009-11-08 07:53 ——– dc—-w- C:\Inetpub
2009-11-06 00:22 . 2008-04-14 00:12 26624 -c–a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-11-05 22:17 . 2009-11-05 22:17 ——– dc—-w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-11-05 21:06 . 2009-11-05 21:06 23546 -c–a-w- c:\documents and settings\Spike\cc_20091105_160558.reg
2009-11-05 20:57 . 2005-08-02 21:35 176128 -c–a-w- c:\windows\system32\nvudisp.exe
2009-11-05 20:55 . 2009-11-05 20:55 ——– dc—-w- C:\NVIDIA
2009-11-05 19:20 . 2009-11-05 19:20 86016 -c–a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-05 19:19 . 2009-11-06 19:03 ——– dc—-w- c:\documents and settings\All Users\Application Data\NOS
2009-11-04 17:32 . 2009-11-04 17:33 616 -c–a-w- c:\documents and settings\Spike\cc_20091104_123255.reg
2009-11-03 22:05 . 2009-11-03 22:05 4574 -c–a-w- c:\documents and settings\Spike\cc_20091103_170519.reg
2009-11-01 00:12 . 2009-11-01 00:13 ——– dc—-w- c:\program files\Windows Media Connect 2
2009-11-01 00:02 . 2009-11-08 07:56 ——– dc—-w- c:\windows\system32\drivers\UMDF
2009-11-01 00:02 . 2009-11-01 00:02 ——– dc—-w- c:\windows\system32\LogFiles
2009-10-30 19:31 . 2009-10-30 19:31 6512 -c–a-w- c:\documents and settings\Spike\cc_20091030_153127.reg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-28 11:19 . 2009-10-16 18:57 0 -c–a-w- c:\documents and settings\Spike\Local Settings\Application Data\prvlcl.dat
2009-11-27 16:41 . 2009-10-16 18:52 ——– dc—-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-26 04:33 . 2009-10-16 04:52 ——– dc—-w- c:\documents and settings\Spike\Application Data\uTorrent
2009-11-20 14:41 . 2009-10-16 04:37 13104 -c–a-w- c:\documents and settings\Spike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-17 14:46 . 2009-10-22 22:25 ——– dc—-w- c:\program files\TuneUp Utilities 2009
2009-11-12 03:24 . 2009-10-22 22:20 ——– dcsh–w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-11-10 14:27 . 2009-10-16 18:53 360584 -c–a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-10 05:15 . 2009-10-16 18:56 ——– dc—-w- c:\documents and settings\Spike\Application Data\DMCache
2009-11-09 19:35 . 2009-10-23 18:30 ——– dc—-w- c:\documents and settings\Spike\Application Data\Yahoo!
2009-11-09 19:35 . 2009-10-23 18:26 ——– dc—-w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-09 19:29 . 2009-10-26 23:13 ——– dc—-w- c:\program files\Common Files\InstallShield
2009-11-04 05:22 . 2009-10-22 06:23 1956 -c–a-w- c:\windows\system32\d3d8caps.dat
2009-10-29 16:45 . 2009-10-29 16:45 ——– dc—-w- c:\program files\MSBuild
2009-10-29 16:44 . 2009-10-29 16:44 ——– dc—-w- c:\program files\Reference Assemblies
2009-10-28 03:31 . 2009-10-28 03:31 1278 -c–a-w- c:\documents and settings\Spike\cc_20091027_233058.reg
2009-10-26 23:39 . 2009-10-26 23:39 6696 -c–a-w- c:\documents and settings\Spike\cc_20091026_193933.reg
2009-10-26 22:55 . 2009-10-26 22:55 ——– dc—-w- c:\documents and settings\All Users\Application Data\UAB
2009-10-26 22:55 . 2009-10-26 22:55 ——– dc—-w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-10-22 22:28 . 2009-10-22 22:28 ——– dc—-w- c:\documents and settings\Spike\Application Data\TuneUp Software
2009-10-22 22:25 . 2009-10-22 22:25 ——– dc—-w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-10-22 19:14 . 2009-10-16 18:53 28424 -c–a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-22 19:14 . 2009-10-16 18:52 25608 -c–a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2009-10-22 19:13 . 2009-10-16 18:51 30104 -c–a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-10-22 19:13 . 2009-10-16 18:51 50968 -c–a-w- c:\windows\system32\avgfwdx.dll
2009-10-22 19:11 . 2009-10-16 18:52 161800 -c–a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-10-22 06:52 . 2009-10-15 06:46 86327 -c–a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-21 05:37 . 2009-10-16 20:48 7 -c–a-w- c:\windows\sbacknt.bin
2009-10-20 07:08 . 2009-10-20 07:06 ——– dc–a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-16 20:46 . 2009-10-16 20:46 152904 -c–a-w- c:\windows\system32\vghd.scr
2009-10-16 19:09 . 2009-10-16 19:09 3460 -c–a-w- c:\documents and settings\Spike\cc_20091016_150911.reg
2009-10-16 18:53 . 2009-10-16 18:53 12464 -c–a-w- c:\windows\system32\avgrsstx.dll
2009-10-16 18:53 . 2009-10-16 18:53 333192 -c–a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-16 18:51 . 2009-10-16 18:51 ——– dc—-w- c:\program files\AVG
2009-10-16 18:51 . 2009-10-16 18:51 ——– dc—-w- c:\documents and settings\All Users\Application Data\avg9
2009-10-16 18:06 . 2009-10-16 18:06 ——– dc—-w- c:\program files\CCleaner
2009-10-15 07:23 . 2009-10-15 07:23 0 -c–a-w- c:\windows\nsreg.dat
2009-10-15 06:50 . 2009-10-15 06:50 ——– dc—-w- c:\program files\microsoft frontpage
2009-10-15 06:35 . 2009-10-15 06:35 21640 -c–a-w- c:\windows\system32\emptyregdb.dat
2009-09-25 05:37 . 2004-08-04 12:00 667136 -c—-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-04 12:00 81920 -c–a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:18 . 2004-08-04 12:00 136192 -c–a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 -c–a-w- c:\windows\system32\msasn1.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\Inetpub —-
2007-04-02 13:10 . 2007-04-02 13:10 85813 -c–a-w- c:\inetpub\AdminScripts\adsutil.vbs
((((((((((((((((((((((((((((( SnapShot@2009-11-27_14.02.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-28 10:01 . 2009-11-28 10:01 16384 c:\windows\Temp\Perflib_Perfdata_6bc.dat
+ 2006-02-24 05:06 . 2006-02-24 05:06 1031233 c:\windows\system32\WindowsErrorTemp.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1115392]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-18 16:28 1115392 -c–a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1115392]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1115392]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-16 18:53 12464 -c–a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Spike^Start Menu^Programs^Startup^DesktopVideoPlayer.LNK]
path=c:\documents and settings\Spike\Start Menu\Programs\Startup\DesktopVideoPlayer.LNK
backup=c:\windows\pss\DesktopVideoPlayer.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Documents and Settings\\Spike\\My Documents\\Downloads\\Programs\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [10/16/2009 1:52 PM 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [10/16/2009 1:52 PM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/16/2009 1:53 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/16/2009 1:53 PM 360584]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [10/16/2009 1:52 PM 906520]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/16/2009 1:52 PM 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [10/22/2009 2:12 PM 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [10/22/2009 2:13 PM 5832712]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [11/11/2009 10:29 PM 604488]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [10/16/2009 1:51 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [10/16/2009 1:52 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [10/16/2009 1:52 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [10/16/2009 1:52 PM 25736]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [10/16/2009 1:51 PM 30104]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-11-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 08:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
FF - ProfilePath - c:\documents and settings\Spike\Application Data\Mozilla\Firefox\Profiles\wvl2fd3k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-28 15:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{33e7086a-f19c-4631-98cd-fc669e6b59dd}]
@Denied: (Full) (Everyone)
"Model"=dword:00000138
"Therad"=dword:00000019
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e9,96,28,6f,90,d5,43,9b,2d,3b,3e,2f,d7,92,dc,eb,db,29,dc,2a,6e,
18,a3,13,aa,54,af,84,80,4d,7c,5e,3f,7a,85,b6,3f,e3,48,b5,00,00,00,00,00,00,\
.
Completion time: 2009-11-28 15:45
ComboFix-quarantined-files.txt 2009-11-28 20:45
ComboFix2.txt 2009-11-27 19:03
Pre-Run: 2,624,909,312 bytes free
Post-Run: 2,674,937,856 bytes free
- - End Of File - - B78BA26CAF2C91EF54A17376FFDCB1F5
Upload was successful
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
and here's the systemlook log:
SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 01:27 on 29/11/2009 by Spike (Administrator - Elevation successful)
========== dir ==========
C:\stdtsa - Parameters: "/s"
—Files—
instmsiW.exe –a–c 1822520 bytes [04:19 24/11/2009] [17:25 07/05/2004]
readesavxpsa.txt –a–c 3189 bytes [04:19 24/11/2009] [00:06 23/10/2007]
readsavxp_76_eng.html –a–c 49978 bytes [04:19 24/11/2009] [19:47 29/10/2009]
SavResChs.dll –a–c 249856 bytes [04:19 24/11/2009] [18:16 27/11/2008]
SavResCht.dll –a–c 327680 bytes [04:19 24/11/2009] [18:16 27/11/2008]
SavResDeu.dll –a–c 204800 bytes [04:19 24/11/2009] [04:19 24/11/2009]
Setup.exe –a–c 252984 bytes [04:19 24/11/2009] [18:17 27/11/2008]
C:\stdtsa\sau d—-c [04:19 24/11/2009]
C:\stdtsa\sau\program files d—-c [04:19 24/11/2009]
C:\stdtsa\sau\program files\Sophos d—-c [04:19 24/11/2009]
C:\stdtsa\sau\program files\Sophos\AutoUpdate d—-c [04:19 24/11/2009]
ALMon.exe –a–c 245760 bytes [04:19 24/11/2009] [17:18 21/06/2007]
ALsvc.exe –a–c 172032 bytes [04:19 24/11/2009] [22:00 26/06/2008]
ALUpdate.exe –a–c 655360 bytes [04:19 24/11/2009] [22:33 21/11/2008]
AUAdapter.dll –a–c 499712 bytes [04:19 24/11/2009] [17:56 09/07/2008]
boost_date_time-vc71-mt-1_32.dll –a–c 45056 bytes [04:19 24/11/2009] [16:07 02/04/2007]
ChannelUpdater.dll –a–c 172032 bytes [04:19 24/11/2009] [22:32 21/11/2008]
cidsync.dll –a–c 176128 bytes [04:19 24/11/2009] [22:33 21/11/2008]
config.dll –a–c 102400 bytes [04:19 24/11/2009] [14:30 03/04/2007]
crypto.dll –a–c 20480 bytes [04:19 24/11/2009] [14:17 03/04/2007]
EECustomActions.dll –a–c 180224 bytes [04:19 24/11/2009] [21:50 13/02/2008]
inetconn.dll –a–c 135168 bytes [04:19 24/11/2009] [14:30 03/04/2007]
InstlMgr.dll –a–c 90112 bytes [04:19 24/11/2009] [22:33 21/11/2008]
ispsheet.dll –a–c 69632 bytes [04:19 24/11/2009] [14:30 03/04/2007]
libcurl.dll –a–c 159744 bytes [04:19 24/11/2009] [22:13 30/03/2007]
libeay32.dll –a–c 745472 bytes [04:19 24/11/2009] [22:12 30/03/2007]
license_agreements.txt –a–c 8894 bytes [04:19 24/11/2009] [21:30 30/03/2007]
Logger.dll –a–c 278528 bytes [04:19 24/11/2009] [16:02 05/07/2007]
MFC71.dll –a–c 1060864 bytes [04:19 24/11/2009] [17:25 07/05/2004]
msvcp71.dll –a–c 499712 bytes [04:19 24/11/2009] [00:06 18/03/2004]
msvcr71.dll –a–c 348160 bytes [04:19 24/11/2009] [00:06 18/03/2004]
retailer.dll –a–c 208896 bytes [04:19 24/11/2009] [22:32 21/11/2008]
SAUConfigDLL.dll –a–c 253952 bytes [04:19 24/11/2009] [22:00 26/06/2008]
C:\stdtsa\sau\program files\Sophos\AutoUpdate\de d—-c [04:19 24/11/2009]
almonres.dll –a–c 45056 bytes [04:19 24/11/2009] [15:13 27/04/2007]
iconfres.dll –a–c 6656 bytes [04:19 24/11/2009] [14:28 03/04/2007]
ilogres.dll –a–c 5120 bytes [04:19 24/11/2009] [14:29 03/04/2007]
ischdres.dll –a–c 3072 bytes [04:19 24/11/2009] [14:30 03/04/2007]
C:\stdtsa\sau\program files\Sophos\AutoUpdate\en d—-c [04:19 24/11/2009]
almonres.dll –a–c 45056 bytes [04:19 24/11/2009] [15:13 27/04/2007]
iconfres.dll –a–c 6144 bytes [04:19 24/11/2009] [14:28 03/04/2007]
ilogres.dll –a–c 4608 bytes [04:19 24/11/2009] [14:29 03/04/2007]
ischdres.dll –a–c 3072 bytes [04:19 24/11/2009] [14:30 03/04/2007]
C:\stdtsa\sau\program files\Sophos\AutoUpdate\es d—-c [04:19 24/11/2009]
almonres.dll –a–c 45056 bytes [04:19 24/11/2009] [15:13 27/04/2007]
iconfres.dll –a–c 6144 bytes [04:19 24/11/2009] [14:28 03/04/2007]
ilogres.dll –a–c 4608 bytes [04:19 24/11/2009] [14:29 03/04/2007]
ischdres.dll –a–c 3072 bytes [04:19 24/11/2009] [14:30 03/04/2007]
C:\stdtsa\sau\program files\Sophos\AutoUpdate\fr d—-c [04:19 24/11/2009]
almonres.dll –a–c 45056 bytes [04:19 24/11/2009] [15:13 27/04/2007]
iconfres.dll –a–c 6656 bytes [04:19 24/11/2009] [14:28 03/04/2007]
ilogres.dll –a–c 5120 bytes [04:19 24/11/2009] [14:29 03/04/2007]
ischdres.dll –a–c 3072 bytes [04:19 24/11/2009] [14:30 03/04/2007]
C:\stdtsa\sau\program files\Sophos\AutoUpdate\it d—-c [04:19 24/11/2009]
ALMonres.dll –a–c 45056 bytes [04:19 24/11/2009] [15:13 27/04/2007]
iconfres.dll –a–c 6144 bytes [04:19 24/11/2009] [14:25 03/04/2007]
ilogres.dll –a–c 5120 bytes [04:19 24/11/2009] [14:29 03/04/2007]
ischdres.dll –a–c 3072 bytes [04:19 24/11/2009] [14:30 03/04/2007]
C:\stdtsa\sau\program files\Sophos\AutoUpdate\ja d—-c [04:19 24/11/2009]
almonres.dll –a–c 40960 bytes [04:19 24/11/2009] [15:13 27/04/2007]
iconfres.dll –a–c 5632 bytes [04:19 24/11/2009] [14:26 03/04/2007]
ilogres.dll –a–c 4608 bytes [04:19 24/11/2009] [14:29 03/04/2007]
ischdres.dll –a–c 3072 bytes [04:19 24/11/2009] [14:30 03/04/2007]
C:\stdtsa\sau\program files\Sophos\AutoUpdate\zh_cn d—-c [04:19 24/11/2009]
ALMonres.dll –a–c 40960 bytes [04:19 24/11/2009] [15:13 27/04/2007]
iconfres.dll –a–c 5632 bytes [04:19 24/11/2009] [14:26 03/04/2007]
ilogres.dll –a–c 4096 bytes [04:19 24/11/2009] [14:29 03/04/2007]
ischdres.dll –a–c 3072 bytes [04:19 24/11/2009] [14:30 03/04/2007]
C:\stdtsa\sau\program files\Sophos\AutoUpdate\zh_tw d—-c [04:19 24/11/2009]
ALMonres.dll –a–c 40960 bytes [04:19 24/11/2009] [15:13 27/04/2007]
iconfres.dll –a–c 5632 bytes [04:19 24/11/2009] [14:30 03/04/2007]
ilogres.dll –a–c 4096 bytes [04:19 24/11/2009] [14:29 03/04/2007]
ischdres.dll –a–c 3072 bytes [04:19 24/11/2009] [14:30 03/04/2007]
C:\stdtsa\savxp d—-c [04:19 24/11/2009]
ConfigureSAV.exe –a–c 94208 bytes [04:19 24/11/2009] [22:06 09/12/2008]
osdp.dll –a–c 118849 bytes [04:19 24/11/2009] [19:26 14/10/2009]
rkdisk.dll –a–c 94208 bytes [04:19 24/11/2009] [17:15 11/01/2008]
savi.dll –a–c 490608 bytes [04:19 24/11/2009] [19:26 14/10/2009]
SDCDevCon.exe –a–c 49152 bytes [04:19 24/11/2009] [22:16 09/12/2008]
SDCDevConIA64.exe –a–c 104448 bytes [04:19 24/11/2009] [22:16 09/12/2008]
SDCDevConx64.exe –a–c 51712 bytes [04:19 24/11/2009] [22:16 09/12/2008]
SDCService.exe –a–c 393216 bytes [04:19 24/11/2009] [22:17 09/12/2008]
C:\stdtsa\savxp\Common d—-c [04:19 24/11/2009]
C:\stdtsa\savxp\Common\Cisco Systems d—-c [04:19 24/11/2009]
C:\stdtsa\savxp\Common\Cisco Systems\CiscoTrustAgent d—-c [04:19 24/11/2009]
C:\stdtsa\savxp\Common\Cisco Systems\CiscoTrustAgent\Plugins d—-c [04:19 24/11/2009]
C:\stdtsa\savxp\Common\Cisco Systems\CiscoTrustAgent\Plugins\Install d—-c [04:19 24/11/2009]
SAVPosturePlugin.dll –a–c 102400 bytes [04:19 24/11/2009] [21:50 09/12/2008]
SAVPosturePlugin.inf –a–c 597 bytes [04:19 24/11/2009] [21:14 09/12/2008]
C:\stdtsa\savxp\program files d—-c [04:19 24/11/2009]
C:\stdtsa\savxp\program files\Sophos d—-c [04:19 24/11/2009]
C:\stdtsa\savxp\program files\Sophos\Sophos Anti-Virus d—-c [04:19 24/11/2009]
Categories.dll –a–c 7168 bytes [04:19 24/11/2009] [22:09 09/12/2008]
msvcp71.dll –a–c 499712 bytes [04:19 24/11/2009] [13:25 30/08/2007]
msvcr71.dll –a–c 348160 bytes [04:19 24/11/2009] [13:25 30/08/2007]
sav32cli.exe –a–c 224312 bytes [04:19 24/11/2009] [18:20 14/11/2008]
SAVAdminService.exe –a–c 69632 bytes [04:19 24/11/2009] [21:46 09/12/2008]
SAVCleanupService.exe –a–c 90112 bytes [04:19 24/11/2009] [21:45 09/12/2008]
SAVMSCM.DLL –a–c 131072 bytes [04:19 24/11/2009] [16:20 14/11/2008]
SavNeutralRes.dll –a–c 651264 bytes [04:19 24/11/2009] [22:05 09/12/2008]
SavRes.dll –a–c 524288 bytes [04:19 24/11/2009] [22:12 09/12/2008]
SavResChs.dll –a–c 151552 bytes [04:19 24/11/2009] [22:13 09/12/2008]
SavResCht.dll –a–c 151552 bytes [04:19 24/11/2009] [22:13 09/12/2008]
SavResDeu.dll –a–c 163840 bytes [04:19 24/11/2009] [22:13 09/12/2008]
SavService.exe –a–c 98304 bytes [04:19 24/11/2009] [21:44 09/12/2008]
C:\stdtsa\savxp\program files\Sophos\Sophos Anti-Virus\Module Retargetable Folder d—-c [04:19 24/11/2009]
AuthorisedLists.dll –a–c 147456 bytes [04:19 24/11/2009] [21:44 09/12/2008]
BackgroundScanClient.exe –a–c 45608 bytes [04:19 24/11/2009] [22:03 09/12/2008]
BackgroundScanning.dll –a–c 77824 bytes [04:19 24/11/2009] [21:59 09/12/2008]
BHOManagement.dll –a–c 180224 bytes [04:19 24/11/2009] [21:43 09/12/2008]
ComponentManager.dll –a–c 90112 bytes [04:19 24/11/2009] [21:45 09/12/2008]
Configuration.dll –a–c 286720 bytes [04:19 24/11/2009] [21:49 09/12/2008]
DCManagement.dll –a–c 94208 bytes [04:19 24/11/2009] [21:46 09/12/2008]
DesktopMessaging.dll –a–c 331776 bytes [04:19 24/11/2009] [21:49 09/12/2008]
DriveProcessor.dll –a–c 147456 bytes [04:19 24/11/2009] [21:43 09/12/2008]
EEConsumer.dll –a–c 110592 bytes [04:19 24/11/2009] [21:49 09/12/2008]
FilterProcessors.dll –a–c 233472 bytes [04:19 24/11/2009] [21:58 09/12/2008]
FSDecomposer.dll –a–c 98304 bytes [04:19 24/11/2009] [21:59 09/12/2008]
ICAdapter.dll –a–c 102400 bytes [04:19 24/11/2009] [21:46 09/12/2008]
ICManagement.dll –a–c 282624 bytes [04:19 24/11/2009] [21:46 09/12/2008]
ICProcessors.dll –a–c 258048 bytes [04:19 24/11/2009] [21:47 09/12/2008]
LegacyConsumers.dll –a–c 139264 bytes [04:19 24/11/2009] [21:47 09/12/2008]
Localisation.dll –a–c 126976 bytes [04:19 24/11/2009] [21:47 09/12/2008]
Logging.dll –a–c 462848 bytes [04:19 24/11/2009] [21:49 09/12/2008]
Persistance.dll –a–c 98304 bytes [04:19 24/11/2009] [21:55 09/12/2008]
SavAdapter.dll –a–c 675840 bytes [04:19 24/11/2009] [21:48 09/12/2008]
SavMain.exe –a–c 2014248 bytes [04:19 24/11/2009] [22:03 09/12/2008]
SavProgress.exe –a–c 556072 bytes [04:19 24/11/2009] [22:03 09/12/2008]
C:\stdtsa\savxp\SXS d—-c [04:19 24/11/2009]
msxml4.dll –a–c 1233920 bytes [04:19 24/11/2009] [22:46 18/04/2003]
msxml4r.dll –a–c 82432 bytes [04:19 24/11/2009] [22:29 18/04/2003]
C:\stdtsa\savxp\System d—-c [04:19 24/11/2009]
msxml4.dll –a–c 1233920 bytes [04:19 24/11/2009] [22:46 18/04/2003]
msxml4a.dll –a–c 44544 bytes [04:19 24/11/2009] [22:29 18/04/2003]
msxml4r.dll –a–c 82432 bytes [04:19 24/11/2009] [22:29 18/04/2003]
C:\stdtsa\savxp\Win2K d—-c [04:19 24/11/2009]
savonaccessdriv.inf –a–c 2270 bytes [04:19 24/11/2009] [16:43 18/07/2008]
SophosBootDriver.inf –a–c 2020 bytes [04:19 24/11/2009] [13:29 23/05/2008]
SophosBootTasks.exe –a–c 23552 bytes [04:19 24/11/2009] [22:10 09/12/2008]
C:\stdtsa\savxp\WinLH_AMD64 d—-c [04:19 24/11/2009]
native.exe –a–c 42496 bytes [04:19 24/11/2009] [22:13 09/12/2008]
savonaccessdriv.inf –a–c 3078 bytes [04:19 24/11/2009] [16:43 18/07/2008]
SophosBootDriver.inf –a–c 2020 bytes [04:19 24/11/2009] [13:29 23/05/2008]
SophosBootTasks.exe –a–c 30208 bytes [04:19 24/11/2009] [22:09 09/12/2008]
C:\stdtsa\savxp\WinLH_i386 d—-c [04:19 24/11/2009]
savonaccessdriv.inf –a–c 3078 bytes [04:19 24/11/2009] [16:43 18/07/2008]
SophosBootDriver.inf –a–c 2020 bytes [04:19 24/11/2009] [13:29 23/05/2008]
SophosBootTasks.exe –a–c 23552 bytes [04:19 24/11/2009] [22:10 09/12/2008]
C:\stdtsa\savxp\WinLH_IA64 d—-c [04:19 24/11/2009]
native.exe –a–c 80896 bytes [04:19 24/11/2009] [22:13 09/12/2008]
savonaccessdriv.inf –a–c 3078 bytes [04:19 24/11/2009] [16:43 18/07/2008]
SophosBootTasks.exe –a–c 59392 bytes [04:19 24/11/2009] [22:10 09/12/2008]
C:\stdtsa\savxp\WinXP_AMD64 d—-c [04:19 24/11/2009]
native.exe –a–c 42496 bytes [04:19 24/11/2009] [22:13 09/12/2008]
savonaccessdriv.inf –a–c 2270 bytes [04:19 24/11/2009] [16:43 18/07/2008]
SophosBootDriver.inf –a–c 2020 bytes [04:19 24/11/2009] [13:29 23/05/2008]
SophosBootTasks.exe –a–c 30208 bytes [04:19 24/11/2009] [22:09 09/12/2008]
C:\stdtsa\savxp\WinXP_i386 d—-c [04:19 24/11/2009]
savonaccessdriv.inf –a–c 2270 bytes [04:19 24/11/2009] [16:43 18/07/2008]
SophosBootDriver.inf –a–c 2020 bytes [04:19 24/11/2009] [13:29 23/05/2008]
SophosBootTasks.exe –a–c 23552 bytes [04:19 24/11/2009] [22:10 09/12/2008]
C:\stdtsa\savxp\WinXP_IA64 d—-c [04:19 24/11/2009]
native.exe –a–c 80896 bytes [04:19 24/11/2009] [22:13 09/12/2008]
savonaccessdriv.inf –a–c 2270 bytes [04:19 24/11/2009] [16:43 18/07/2008]
SophosBootDriver.inf –a–c 2020 bytes [04:19 24/11/2009] [13:29 23/05/2008]
SophosBootTasks.exe –a–c 59392 bytes [04:19 24/11/2009] [22:10 09/12/2008]
-=End Of File=-