wozzle
Topic Starter
So I've gotten some sort of problem. I don't know when really but now THIS (use caution maybe when checking the link. It's the same as the title. duh?) website is popping up. I scanned it's credentials in Opera and something is amiss with it. I've since gone back to Firefox (my favorite) as it's been following me through IE and Opera anyway. I've been searching for it in google and this is the only place it seems that has any info.
What is it, and how do I get rid of it short of somehow just blocking it in Firefox?
I'll be grateful as tech if you can help we with this one. Thanks for your time
I checked out the other threads and just went along to use combofix… hope that's appropriate.
——————————-
ComboFix 09-12-01.01 - Julian 12/01/2009 13:11.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1917.888 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-11-01 to 2009-12-01 )))))))))))))))))))))))))))))))
.
2009-12-01 21:19 . 2009-12-01 21:19 ——– d—–w- c:\users\Julian\AppData\Local\temp
2009-12-01 21:19 . 2009-12-01 21:19 ——– d—–w- c:\users\Public\AppData\Local\temp
2009-12-01 21:19 . 2009-12-01 21:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-11-25 04:42 . 2009-11-25 04:42 ——– d—–w- c:\users\Julian\AppData\Local\Opera
2009-11-25 00:13 . 2009-11-25 00:17 4096 d—–w- c:\program files\DeusEx
2009-11-24 22:54 . 2009-10-29 09:17 2048 —-a-w- c:\windows\system32\tzres.dll
2009-11-24 20:17 . 2009-08-11 16:44 1401856 —-a-w- c:\windows\system32\msxml6.dll
2009-11-24 20:17 . 2009-08-11 16:44 1248768 —-a-w- c:\windows\system32\msxml3.dll
2009-11-24 10:27 . 2009-11-24 10:27 ——– d—–w- c:\program files\directx
2009-11-23 03:09 . 2009-11-09 02:50 877848 —-a-w- c:\programdata\avg9\update\backup\avgupd.exe
2009-11-13 03:44 . 2009-11-10 01:17 4026136 —-a-w- c:\programdata\avg9\update\backup\avgui.exe
2009-11-13 03:44 . 2009-11-10 01:17 2016536 —-a-w- c:\programdata\avg9\update\backup\avgtray.exe
2009-11-13 03:44 . 2009-11-10 01:17 1257240 —-a-w- c:\programdata\avg9\update\backup\avgfrw.exe
2009-11-13 03:44 . 2009-11-09 02:50 600344 —-a-w- c:\programdata\avg9\update\backup\avgnsx.exe
2009-11-13 03:44 . 2009-11-13 03:44 3963648 —-a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2009-11-13 03:44 . 2009-11-13 03:44 497944 —-a-w- c:\programdata\avg9\update\backup\avgchjwx.dll
2009-11-10 22:46 . 2009-08-14 13:27 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-10 22:46 . 2009-08-10 12:35 355328 —-a-w- c:\windows\system32\WSDApi.dll
2009-11-10 01:20 . 2009-11-09 02:50 360584 —-a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2009-11-10 01:14 . 2009-11-10 01:13 1657112 —-a-w- c:\programdata\avg9\update\backup\avgupd.dll
2009-11-10 01:14 . 2009-11-09 02:50 610072 —-a-w- c:\programdata\avg9\update\backup\avgiproxy.exe
2009-11-09 02:51 . 2009-11-09 04:01 ——– d—–w- C:\$AVG
2009-11-09 02:50 . 2009-11-09 02:50 4096 d—–w- c:\programdata\avg9
2009-11-04 08:07 . 2009-11-04 08:07 ——– d—–w- c:\program files\iPod
2009-11-04 08:07 . 2009-11-04 08:08 4096 d—–w- c:\program files\iTunes
2009-11-04 08:01 . 2009-11-04 08:01 79144 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-30 09:46 . 2009-09-29 08:37 4096 d—–w- c:\users\Julian\AppData\Roaming\vlc
2009-11-30 06:19 . 2009-03-24 22:46 12288 d—–w- c:\program files\Steam
2009-11-30 05:05 . 2009-03-24 22:46 ——– d—–w- c:\program files\Common Files\Steam
2009-11-25 06:22 . 2009-03-24 06:00 196608 d—–w- c:\users\Julian\AppData\Roaming\uTorrent
2009-11-11 11:20 . 2006-11-02 11:18 4096 d—–w- c:\program files\Windows Mail
2009-11-10 01:17 . 2009-03-24 05:52 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-09 02:50 . 2009-03-24 05:52 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-09 02:50 . 2009-03-24 05:52 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-09 02:50 . 2009-03-24 05:52 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-09 02:50 . 2009-03-24 05:52 ——– d—–w- c:\program files\AVG
2009-11-04 08:07 . 2009-04-23 01:51 ——– d—–w- c:\program files\Common Files\Apple
2009-11-03 04:42 . 2009-10-03 04:54 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 02:42 . 2009-10-29 02:42 ——– d—–w- c:\program files\Windows Portable Devices
2009-10-29 02:41 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-10-29 02:41 . 2009-10-29 02:41 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-29 01:51 . 2009-03-25 21:31 ——– d—–w- c:\programdata\FLEXnet
2009-10-29 01:32 . 2009-10-29 01:31 4096 d—–w- c:\users\Julian\AppData\Roaming\Windows System Defender
2009-10-27 20:38 . 2009-05-04 08:48 4096 d—–w- c:\users\Julian\AppData\Roaming\dvdcss
2009-10-08 21:08 . 2009-10-29 02:31 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-10-29 02:31 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-10-29 02:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-10-01 01:02 . 2009-10-29 02:33 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-29 02:33 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-10-29 02:33 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-29 02:33 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-29 02:33 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-29 02:33 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-29 02:33 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-29 02:33 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-29 02:33 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-29 02:33 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-29 02:33 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-29 02:33 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-09-25 02:10 . 2009-10-29 02:33 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-10-29 02:33 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-10-29 02:33 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-10-29 02:33 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-10-29 02:33 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-10-29 02:33 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-10-29 02:33 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-10-29 02:33 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-10-29 02:33 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-10-29 02:33 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-10-29 02:33 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-10-29 02:33 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-10-29 02:33 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-10-29 02:33 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-10-29 02:33 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-10-29 02:33 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-10-29 02:33 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-10-29 02:33 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-10-29 02:33 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-10-29 02:33 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-10-29 02:33 634880 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-10-29 02:33 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-10-29 02:33 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-10-29 02:33 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-10-29 02:33 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-10-29 02:33 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-10-29 02:33 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-14 09:29 . 2009-10-15 05:11 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-15 05:13 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-10 14:59 . 2009-10-29 02:15 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-09-10 14:58 . 2009-10-29 02:15 310784 —-a-w- c:\windows\system32\unregmp2.exe
2009-09-10 02:01 . 2009-10-29 02:34 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2009-09-10 02:00 . 2009-10-29 02:34 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2009-09-10 02:00 . 2009-10-29 02:34 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2009-09-04 11:41 . 2009-10-15 05:11 60928 —-a-w- c:\windows\system32\msasn1.dll
2009-03-23 23:17 . 2009-03-23 23:17 16 –sh–r- c:\windows\System32\drivers\fbd.sys
2009-03-23 23:18 . 2009-03-23 23:18 4 –sh–r- c:\windows\System32\drivers\taishop.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-01-30 430080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="\HWSetup.exe hwSetUP" [X]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-13 2020120]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-30 4911104]
"NDSTray.exe"="NDSTray.exe" [BU]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-11-21 1826816]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
:cc,2b,83,7f,66,20,ca,01
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [3/23/2009 9:52 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [3/23/2009 9:52 PM 360584]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [3/23/2009 2:59 PM 20352]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [11/8/2009 6:50 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/8/2009 6:50 PM 285392]
R2 ConfigFree Service;ConfigFree Service;c:\program files\Toshiba\ConfigFree\CFSvcs.exe [12/25/2007 1:07 PM 40960]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 6:23 PM 21504]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [3/23/2009 2:59 PM 937984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://pitchfork.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\2b6g4kdd.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-01 13:19
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i??????c??]???h?????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-12-01 13:21
ComboFix-quarantined-files.txt 2009-12-01 21:21
ComboFix2.txt 2009-12-01 20:55
Pre-Run: 76,884,213,760 bytes free
Post-Run: 76,851,187,712 bytes free
- - End Of File - - C50A3805F4D8A8D34C9A22E41FDFD771
What is it, and how do I get rid of it short of somehow just blocking it in Firefox?
I'll be grateful as tech if you can help we with this one. Thanks for your time
I checked out the other threads and just went along to use combofix… hope that's appropriate.
——————————-
ComboFix 09-12-01.01 - Julian 12/01/2009 13:11.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1917.888 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-11-01 to 2009-12-01 )))))))))))))))))))))))))))))))
.
2009-12-01 21:19 . 2009-12-01 21:19 ——– d—–w- c:\users\Julian\AppData\Local\temp
2009-12-01 21:19 . 2009-12-01 21:19 ——– d—–w- c:\users\Public\AppData\Local\temp
2009-12-01 21:19 . 2009-12-01 21:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-11-25 04:42 . 2009-11-25 04:42 ——– d—–w- c:\users\Julian\AppData\Local\Opera
2009-11-25 00:13 . 2009-11-25 00:17 4096 d—–w- c:\program files\DeusEx
2009-11-24 22:54 . 2009-10-29 09:17 2048 —-a-w- c:\windows\system32\tzres.dll
2009-11-24 20:17 . 2009-08-11 16:44 1401856 —-a-w- c:\windows\system32\msxml6.dll
2009-11-24 20:17 . 2009-08-11 16:44 1248768 —-a-w- c:\windows\system32\msxml3.dll
2009-11-24 10:27 . 2009-11-24 10:27 ——– d—–w- c:\program files\directx
2009-11-23 03:09 . 2009-11-09 02:50 877848 —-a-w- c:\programdata\avg9\update\backup\avgupd.exe
2009-11-13 03:44 . 2009-11-10 01:17 4026136 —-a-w- c:\programdata\avg9\update\backup\avgui.exe
2009-11-13 03:44 . 2009-11-10 01:17 2016536 —-a-w- c:\programdata\avg9\update\backup\avgtray.exe
2009-11-13 03:44 . 2009-11-10 01:17 1257240 —-a-w- c:\programdata\avg9\update\backup\avgfrw.exe
2009-11-13 03:44 . 2009-11-09 02:50 600344 —-a-w- c:\programdata\avg9\update\backup\avgnsx.exe
2009-11-13 03:44 . 2009-11-13 03:44 3963648 —-a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2009-11-13 03:44 . 2009-11-13 03:44 497944 —-a-w- c:\programdata\avg9\update\backup\avgchjwx.dll
2009-11-10 22:46 . 2009-08-14 13:27 2036736 —-a-w- c:\windows\system32\win32k.sys
2009-11-10 22:46 . 2009-08-10 12:35 355328 —-a-w- c:\windows\system32\WSDApi.dll
2009-11-10 01:20 . 2009-11-09 02:50 360584 —-a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2009-11-10 01:14 . 2009-11-10 01:13 1657112 —-a-w- c:\programdata\avg9\update\backup\avgupd.dll
2009-11-10 01:14 . 2009-11-09 02:50 610072 —-a-w- c:\programdata\avg9\update\backup\avgiproxy.exe
2009-11-09 02:51 . 2009-11-09 04:01 ——– d—–w- C:\$AVG
2009-11-09 02:50 . 2009-11-09 02:50 4096 d—–w- c:\programdata\avg9
2009-11-04 08:07 . 2009-11-04 08:07 ——– d—–w- c:\program files\iPod
2009-11-04 08:07 . 2009-11-04 08:08 4096 d—–w- c:\program files\iTunes
2009-11-04 08:01 . 2009-11-04 08:01 79144 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-30 09:46 . 2009-09-29 08:37 4096 d—–w- c:\users\Julian\AppData\Roaming\vlc
2009-11-30 06:19 . 2009-03-24 22:46 12288 d—–w- c:\program files\Steam
2009-11-30 05:05 . 2009-03-24 22:46 ——– d—–w- c:\program files\Common Files\Steam
2009-11-25 06:22 . 2009-03-24 06:00 196608 d—–w- c:\users\Julian\AppData\Roaming\uTorrent
2009-11-11 11:20 . 2006-11-02 11:18 4096 d—–w- c:\program files\Windows Mail
2009-11-10 01:17 . 2009-03-24 05:52 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-09 02:50 . 2009-03-24 05:52 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-09 02:50 . 2009-03-24 05:52 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-09 02:50 . 2009-03-24 05:52 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-09 02:50 . 2009-03-24 05:52 ——– d—–w- c:\program files\AVG
2009-11-04 08:07 . 2009-04-23 01:51 ——– d—–w- c:\program files\Common Files\Apple
2009-11-03 04:42 . 2009-10-03 04:54 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 02:42 . 2009-10-29 02:42 ——– d—–w- c:\program files\Windows Portable Devices
2009-10-29 02:41 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-10-29 02:41 . 2009-10-29 02:41 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-29 01:51 . 2009-03-25 21:31 ——– d—–w- c:\programdata\FLEXnet
2009-10-29 01:32 . 2009-10-29 01:31 4096 d—–w- c:\users\Julian\AppData\Roaming\Windows System Defender
2009-10-27 20:38 . 2009-05-04 08:48 4096 d—–w- c:\users\Julian\AppData\Roaming\dvdcss
2009-10-08 21:08 . 2009-10-29 02:31 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-10-29 02:31 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-10-29 02:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-10-01 01:02 . 2009-10-29 02:33 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-29 02:33 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-10-29 02:33 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-29 02:33 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-29 02:33 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-29 02:33 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-29 02:33 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-29 02:33 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-29 02:33 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-29 02:33 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-29 02:33 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-29 02:33 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-09-25 02:10 . 2009-10-29 02:33 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-10-29 02:33 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-10-29 02:33 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-10-29 02:33 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-10-29 02:33 351232 —-a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-10-29 02:33 847360 —-a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-10-29 02:33 280064 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-10-29 02:33 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-10-29 02:33 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-10-29 02:33 829440 —-a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-10-29 02:33 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-10-29 02:33 252928 —-a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-10-29 02:33 519680 —-a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-10-29 02:33 486912 —-a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-10-29 02:33 161280 —-a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-10-29 02:33 218112 —-a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-10-29 02:33 1030144 —-a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-10-29 02:33 828928 —-a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-10-29 02:33 481792 —-a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-10-29 02:33 190464 —-a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-10-29 02:33 634880 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-10-29 02:33 37888 —-a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-10-29 02:33 793088 —-a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-10-29 02:33 1064448 —-a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-10-29 02:33 258048 —-a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-10-29 02:33 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-10-29 02:33 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-14 09:29 . 2009-10-15 05:11 144896 —-a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 16:48 . 2009-10-15 05:13 218624 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-10 14:59 . 2009-10-29 02:15 8147456 —-a-w- c:\windows\system32\wmploc.DLL
2009-09-10 14:58 . 2009-10-29 02:15 310784 —-a-w- c:\windows\system32\unregmp2.exe
2009-09-10 02:01 . 2009-10-29 02:34 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2009-09-10 02:00 . 2009-10-29 02:34 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2009-09-10 02:00 . 2009-10-29 02:34 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2009-09-04 11:41 . 2009-10-15 05:11 60928 —-a-w- c:\windows\system32\msasn1.dll
2009-03-23 23:17 . 2009-03-23 23:17 16 –sh–r- c:\windows\System32\drivers\fbd.sys
2009-03-23 23:18 . 2009-03-23 23:18 4 –sh–r- c:\windows\System32\drivers\taishop.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-01-30 430080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HWSetup"="\HWSetup.exe hwSetUP" [X]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-13 2020120]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-30 4911104]
"NDSTray.exe"="NDSTray.exe" [BU]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-11-21 1826816]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [3/23/2009 9:52 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [3/23/2009 9:52 PM 360584]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [3/23/2009 2:59 PM 20352]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [11/8/2009 6:50 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/8/2009 6:50 PM 285392]
R2 ConfigFree Service;ConfigFree Service;c:\program files\Toshiba\ConfigFree\CFSvcs.exe [12/25/2007 1:07 PM 40960]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 6:23 PM 21504]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [3/23/2009 2:59 PM 937984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://pitchfork.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\Julian\AppData\Roaming\Mozilla\Firefox\Profiles\2b6g4kdd.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-01 13:19
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i??????c??]???h?????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-12-01 13:21
ComboFix-quarantined-files.txt 2009-12-01 21:21
ComboFix2.txt 2009-12-01 20:55
Pre-Run: 76,884,213,760 bytes free
Post-Run: 76,851,187,712 bytes free
- - End Of File - - C50A3805F4D8A8D34C9A22E41FDFD771