ComboFix 10-03-05.03 - kimberly 03/06/2010 5:21.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.316 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-0179193959-3470405625-231077376-6026
c:\recycler\S-1-5-21-0712768270-0004971720-049930737-7674
c:\recycler\S-1-5-21-3250031104-0249178269-825233449-4003
c:\recycler\S-1-5-21-7379268727-7688960969-933157425-4138
c:\recycler\S-1-5-21-9940903873-4017106262-411153334-6619
c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\system32\drivers\cdrom.sys . . . is missing!!
.
((((((((((((((((((((((((( Files Created from 2010-02-06 to 2010-03-06 )))))))))))))))))))))))))))))))
.
2010-03-06 12:47 . 2010-03-06 12:47 ——– d—–w- c:\documents and settings\kimberly\Local Settings\Application Data\VS Revo Group
2010-03-06 12:47 . 2009-12-30 19:20 27064 —-a-w- c:\windows\system32\drivers\revoflt.sys
2010-03-06 12:47 . 2010-03-06 12:47 ——– d—–w- c:\program files\VS Revo Group
2010-03-06 01:42 . 2010-03-06 01:42 ——– d—–w- c:\documents and settings\kimberly\Application Data\AVG9
2010-03-05 16:37 . 2010-03-05 16:37 74760 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\UniversalDD.sys
2010-03-05 16:37 . 2010-03-05 16:37 360584 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-03-05 16:37 . 2010-03-05 16:37 28424 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-03-05 16:37 . 2010-03-05 16:37 25608 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSxx.sys
2010-03-05 16:37 . 2010-03-05 16:37 333192 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-03-05 16:37 . 2010-03-05 16:37 30216 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSFilter.sys
2010-03-05 16:37 . 2010-03-05 16:37 25736 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSShim.sys
2010-03-05 16:37 . 2010-03-05 16:37 122376 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSDriver.sys
2010-03-05 16:37 . 2010-03-05 16:37 161800 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrkx86.sys
2010-03-05 16:36 . 2010-03-05 16:36 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-05 16:33 . 2010-03-03 22:06 800536 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-03-05 16:33 . 2010-03-03 22:06 613656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-03-05 16:33 . 2010-03-03 22:06 1658136 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-03-05 16:33 . 2010-03-03 22:06 1007896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-03-04 14:28 . 2010-03-04 14:28 ——– d—–w- c:\program files\Trend Micro
2010-03-03 22:07 . 2010-03-03 22:07 ——– d—–w- C:\$AVG
2010-03-03 22:06 . 2010-03-05 16:36 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-03 22:06 . 2010-03-05 16:35 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-03 22:06 . 2010-03-06 01:52 ——– d—–w- c:\windows\system32\drivers\Avg
2010-03-03 22:06 . 2010-03-05 16:36 25096 —-a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-03-03 22:06 . 2010-03-05 16:35 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-03-03 22:06 . 2010-03-05 16:36 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-03 22:06 . 2010-03-03 22:06 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2010-03-03 22:06 . 2010-03-03 22:06 30104 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-03-03 22:06 . 2010-03-03 22:06 ——– d—–w- c:\program files\AVG
2010-03-03 22:05 . 2010-03-03 22:05 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-03-03 15:07 . 2010-03-03 15:07 ——– d—–w- c:\program files\GiPo@Utilities
2010-03-03 15:07 . 2010-03-03 15:07 ——– d—–w- c:\program files\Common Files\Gibinsoft Shared
2010-03-03 11:01 . 2010-03-03 11:01 ——– d—–w- c:\windows\ServicePackFiles
2010-03-03 10:24 . 2009-06-30 17:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2010-03-03 10:22 . 2010-03-03 10:22 ——– d—–w- c:\program files\Panda Security
2010-03-03 08:36 . 2010-03-03 08:36 52224 —-a-w- c:\documents and settings\Administrator.KIMBERLY-7044FA.000\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-03 08:36 . 2010-03-03 08:36 117760 —-a-w- c:\documents and settings\Administrator.KIMBERLY-7044FA.000\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-03 08:35 . 2010-03-03 08:35 ——– d—–w- c:\documents and settings\Administrator.KIMBERLY-7044FA.000\Application Data\SUPERAntiSpyware.com
2010-03-03 08:23 . 2010-03-03 08:23 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-03 08:22 . 2010-03-06 12:40 ——– d—–w- c:\documents and settings\kimberly\Application Data\SUPERAntiSpyware.com
2010-03-03 08:22 . 2010-03-06 12:40 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-03-03 08:21 . 2010-03-03 12:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-03 08:21 . 2010-03-03 08:21 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-03 07:59 . 2010-03-03 08:12 ——– d—–w- c:\windows\system32\CatRoot_bak
2010-03-03 07:57 . 2008-06-13 13:10 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2010-03-03 07:57 . 2008-06-13 13:10 272128 ——w- c:\windows\system32\drivers\bthport.sys
2010-03-03 07:51 . 2009-12-04 14:41 453760 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-03 07:48 . 2009-08-04 12:49 2142720 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-03-03 07:48 . 2009-08-04 12:51 2185984 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-03-03 07:48 . 2009-08-04 12:02 2062976 -c—-w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-03-03 07:48 . 2009-08-04 12:02 2020864 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-03-03 00:59 . 2008-07-09 07:38 26488 —-a-w- c:\windows\system32\spupdsvc.exe
2010-03-02 20:16 . 2010-03-02 20:16 12328 —-a-w- c:\documents and settings\kimberly\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-02 18:37 . 2010-03-02 18:37 ——– d—–w- c:\documents and settings\Administrator.KIMBERLY-7044FA.000\Application Data\Malwarebytes
2010-03-02 12:15 . 2010-03-02 12:15 0 —-a-w- c:\windows\nsreg.dat
2010-03-02 12:15 . 2010-03-02 12:15 ——– d—–w- c:\documents and settings\kimberly\Local Settings\Application Data\WMTools Downloaded Files
2010-03-02 12:14 . 2010-03-02 12:14 ——– d—–w- c:\documents and settings\kimberly\Local Settings\Application Data\Mozilla
2010-03-02 12:12 . 2006-12-07 18:45 110592 —-a-w- c:\documents and settings\kimberly\Application Data\U3\temp\cleanup.exe
2010-03-02 12:10 . 2004-08-04 06:58 5376 -c–a-w- c:\windows\system32\dllcache\mspclock.sys
2010-03-02 12:10 . 2004-08-04 06:58 5376 —-a-w- c:\windows\system32\drivers\MSPCLOCK.sys
2010-03-02 12:10 . 2004-08-04 08:56 4096 -c–a-w- c:\windows\system32\dllcache\ksuser.dll
2010-03-02 12:10 . 2004-08-04 08:56 4096 —-a-w- c:\windows\system32\ksuser.dll
2010-03-02 12:10 . 2004-08-04 07:08 60288 -c–a-w- c:\windows\system32\dllcache\drmk.sys
2010-03-02 12:10 . 2004-08-04 07:08 60288 —-a-w- c:\windows\system32\drivers\drmk.sys
2010-03-02 12:08 . 2010-03-02 12:08 ——– d—–w- c:\program files\Intel
2010-03-02 12:07 . 2010-03-02 12:07 ——– d—–w- c:\program files\Broadcom
2010-03-02 12:06 . 2010-03-02 12:06 ——– d—–w- c:\documents and settings\kimberly\Application Data\Malwarebytes
2010-03-02 12:06 . 2010-01-08 00:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 12:06 . 2010-03-02 12:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-02 12:06 . 2010-03-02 12:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-02 12:06 . 2010-01-08 00:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-02 20:36 . 2010-03-02 11:52 77423 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-02 12:09 . 2010-03-02 12:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-02 12:09 . 2010-03-02 12:09 ——– d—–w- c:\program files\SigmaTel
2010-03-02 12:09 . 2010-03-02 12:08 ——– d—–w- c:\program files\Common Files\InstallShield
2010-03-02 12:09 . 2010-03-02 12:09 ——– d—–w- c:\program files\Dell
2010-03-02 11:59 . 2010-03-02 11:59 ——– d—–w- c:\documents and settings\kimberly\Application Data\U3
2010-03-02 11:54 . 2010-03-02 11:54 ——– d—–w- c:\program files\microsoft frontpage
2010-03-02 11:50 . 2010-03-02 11:50 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-12-31 16:14 . 2004-08-04 10:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:42 . 2006-03-04 03:33 662016 —-a-w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-12-16 12:58 . 2010-03-02 11:48 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2004-08-04 10:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-05 16:36 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [3/3/2010 2:06 PM 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [3/3/2010 2:06 PM 52872]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [3/3/2010 2:24 AM 28552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/3/2010 2:06 PM 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/3/2010 2:06 PM 242696]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [3/5/2010 8:35 AM 916760]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/5/2010 8:36 AM 308064]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [3/5/2010 8:35 AM 2325816]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [3/3/2010 2:06 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [3/3/2010 2:06 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [3/3/2010 2:06 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [3/3/2010 2:06 PM 26120]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [3/5/2010 8:36 AM 5888008]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [3/3/2010 2:06 PM 30104]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [3/6/2010 4:47 AM 27064]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com
FF - ProfilePath - c:\documents and settings\kimberly\Application Data\Mozilla\Firefox\Profiles\j5dqlign.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SyncMan - c:\documents and settings\kimberly\SyncMan.exe
HKCU-Run-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Notify-!SASWinLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-06 05:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1172)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2010-03-06 05:26:04
ComboFix-quarantined-files.txt 2010-03-06 13:26
Pre-Run: 35,177,103,360 bytes free
Post-Run: 35,514,847,232 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - EC5E0EB5A22FE8F91596C6E557FDC9E9