Hi,
Thanks for your reply.
Below is my log but i just need to say something regarding this log…
As you will see, there was a keylogger (ReFog or something like that) I installed that along with the Vistamizer which you will also see on the log under the (((((((((((((((((OTHER DELETIONS)))))))))))))))))))))) bit.
ComboFix Log
ComboFix 10-04-26.05 - Me 28/04/2010 0:19.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1919.963 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\All Users\Application Data\MPK
c:\documents and settings\All Users\Application Data\MPK\1\D0000
c:\documents and settings\All Users\Application Data\MPK\1\S0000
c:\documents and settings\All Users\Application Data\MPK\2\D0000
c:\documents and settings\All Users\Application Data\MPK\2\S0000
c:\documents and settings\All Users\Application Data\MPK\3\D0000
c:\documents and settings\All Users\Application Data\MPK\3\S0000
c:\documents and settings\All Users\Application Data\MPK\CPDM\cpfm.bin
c:\documents and settings\All Users\Application Data\MPK\M0000
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\Get discount!.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\Order now!.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\REFOG Free Keylogger on the Web.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\REFOG Free Keylogger.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Free Keylogger\Uninstall REFOG Free Keylogger.lnk
c:\documents and settings\All Users\Application Data\MPK\S0000
c:\windows\system32\drivers\etc\lmhosts
Infected copy of c:\windows\system32\midimap.dll was found and disinfected
Restored copy from - c:\windows\VistaMizer\old\midimap.dll
.
((((((((((((((((((((((((( Files Created from 2010-03-27 to 2010-04-27 )))))))))))))))))))))))))))))))
.
2010-04-27 05:13 . 2010-04-27 05:13 ——– d—–w- c:\documents and settings\LocalService\Application Data\PeerNetworking
2010-04-25 01:14 . 2010-04-25 02:46 ——– d-sh–w- c:\windows\system32\MPK
2010-04-25 00:11 . 2010-04-25 00:11 ——– d—–w- c:\documents and settings\Admin Account\Application Data\MyPhoneExplorer
2010-04-25 00:08 . 2010-04-25 00:08 ——– d—–w- c:\documents and settings\Admin Account\Local Settings\Application Data\Microsoft
2010-04-21 13:02 . 2010-04-21 13:02 ——– d-sh–w- c:\documents and settings\Me\IECompatCache
2010-04-21 13:00 . 2010-04-21 13:00 ——– d-sh–w- c:\documents and settings\Me\PrivacIE
2010-04-21 11:31 . 2010-04-21 11:31 ——– d-sh–w- c:\documents and settings\Me\IETldCache
2010-04-21 02:18 . 2010-04-21 02:18 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-04-21 02:07 . 2010-02-25 06:24 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-04-21 02:07 . 2010-02-25 06:24 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-21 02:07 . 2010-04-21 02:07 ——– d—–w- c:\windows\ie8updates
2010-04-21 02:06 . 2010-02-16 04:50 64000 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-04-21 02:05 . 2010-04-21 02:06 ——– dc-h–w- c:\windows\ie8
2010-04-21 01:50 . 2010-04-27 02:30 ——– d—–w- c:\program files\Windows Desktop Search
2010-04-13 02:39 . 2010-04-13 02:39 ——– d—–w- c:\windows\system32\Adobe
2010-04-09 01:09 . 2010-04-19 01:40 ——– d—–w- c:\documents and settings\Me\Local Settings\Application Data\Axialis
2010-04-08 19:15 . 2001-08-17 21:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-04-08 19:15 . 2008-04-14 04:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-04-08 19:15 . 2008-04-13 23:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-08 19:15 . 2008-04-13 23:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-04-06 03:09 . 2010-04-06 03:09 ——– d—–w- c:\program files\iPod
2010-04-06 03:09 . 2010-04-06 03:10 ——– d—–w- c:\program files\iTunes
2010-04-06 03:09 . 2010-04-06 03:10 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-06 03:06 . 2010-04-06 03:06 ——– d—–w- c:\program files\QuickTime
2010-04-06 03:02 . 2010-04-06 03:02 ——– d—–w- c:\program files\Bonjour
2010-04-06 02:57 . 2010-04-06 02:57 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-01 11:53 . 2010-04-01 11:53 348160 —-a-w- c:\windows\system32\msvcr71.dll
2010-04-01 11:53 . 2010-04-01 11:53 499712 —-a-w- c:\windows\system32\msvcp71.dll
2010-03-30 01:29 . 2010-03-30 01:29 ——– d—–w- C:\rsit
2010-03-30 00:57 . 2010-03-30 00:57 5918720 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-03-29 03:55 . 2010-03-29 03:55 29184 —-a-r- c:\documents and settings\Me\Application Data\Microsoft\Installer\{52C8FAA0-68CA-4AF9-8A7A-92CF3174CC77}\IconTmpl5.26D6FF13_F77C_402E_8E96_9E49DFBBAF31.exe
2010-03-29 03:55 . 2010-03-29 03:55 ——– d—–w- c:\program files\Windows XP Fun Pack
2010-03-29 03:53 . 2010-02-23 14:04 1664256 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-27 17:11 . 2010-03-25 03:05 0 —-a-w- c:\documents and settings\Me\Local Settings\Application Data\prvlcl.dat
2010-04-26 22:42 . 2010-02-04 01:40 ——– d—–w- c:\program files\CCleaner
2010-04-25 00:09 . 2010-04-25 00:09 ——– d—–w- c:\documents and settings\Admin Account\Application Data\Windows Desktop Search
2010-04-25 00:09 . 2010-04-25 00:09 ——– d—–w- c:\documents and settings\Admin Account\Application Data\Apple Computer
2010-04-25 00:09 . 2010-04-25 00:09 45024 —-a-w- c:\documents and settings\Admin Account\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-24 03:02 . 2010-02-05 01:05 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-22 07:44 . 2010-03-24 14:38 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-21 13:00 . 2010-03-24 14:38 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-04-14 21:49 . 2010-02-07 03:37 ——– d—–w- c:\documents and settings\Me\Application Data\dvdcss
2010-04-12 03:15 . 2010-02-06 02:52 ——– d—–w- c:\documents and settings\Me\Application Data\Marine Aquarium 3
2010-04-08 11:56 . 2010-03-24 14:26 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-04-08 04:25 . 2010-02-05 01:04 ——– d—–w- c:\program files\SpywareBlaster
2010-04-06 03:09 . 2010-02-04 21:36 ——– d—–w- c:\program files\Common Files\Apple
2010-03-31 17:00 . 2010-02-13 01:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-29 14:24 . 2010-02-13 01:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 14:24 . 2010-02-13 01:55 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-29 10:54 . 2010-02-04 21:38 ——– d—–w- c:\documents and settings\Me\Application Data\Apple Computer
2010-03-29 10:53 . 2010-02-04 21:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-03-27 02:37 . 2010-03-24 22:52 ——– d—–w- c:\documents and settings\Me\Application Data\Rokario
2010-03-26 16:50 . 2010-02-04 02:56 ——– d—–w- c:\documents and settings\Me\Application Data\NT Registry Analyzer
2010-03-26 02:20 . 2010-03-26 02:20 ——– d—–w- c:\documents and settings\Me\Application Data\AVG9
2010-03-24 22:52 . 2010-03-24 22:52 ——– d—–w- c:\program files\Rokario
2010-03-24 14:38 . 2010-03-24 14:38 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-24 14:38 . 2010-03-24 14:38 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-24 14:38 . 2010-03-24 14:38 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-24 14:29 . 2010-03-24 00:56 ——– d—–w- c:\program files\CheckPoint
2010-03-24 14:27 . 2010-03-24 14:27 ——– d—–w- c:\program files\AVG
2010-03-24 14:05 . 2010-02-05 00:54 ——– d—–w- c:\program files\COMODO
2010-03-24 00:57 . 2010-03-24 00:57 ——– d—–w- c:\documents and settings\Me\Application Data\CheckPoint
2010-03-24 00:56 . 2010-03-24 00:56 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-03-20 01:43 . 2010-03-19 01:42 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-03-19 10:12 . 2010-02-05 01:15 1474832 —-a-w- c:\windows\system32\drivers\sfi.dat
2010-03-11 00:33 . 2010-02-15 01:42 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2010-03-11 00:29 . 2010-02-18 02:11 ——– d—–w- c:\program files\Java
2010-03-11 00:24 . 2010-02-06 17:15 ——– d—–w- c:\program files\VS Revo Group
2010-03-10 06:15 . 2004-08-04 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 20:20 . 2010-03-09 20:20 ——– d—–r- c:\documents and settings\Me\Application Data\Brother
2010-03-01 02:59 . 2010-03-01 02:59 38428 —ha-w- c:\windows\system32\mlfcache.dat
2010-02-28 16:28 . 2010-02-04 01:53 45024 —-a-w- c:\documents and settings\Me\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-25 06:24 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-25 02:40 . 2010-02-24 22:43 598400 —-a-w- c:\windows\system32\drivers\RTL8192su.sys
2010-02-24 13:11 . 2004-08-04 12:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-24 10:16 . 2010-02-18 00:21 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-24 02:17 . 2004-12-16 04:43 218624 —-a-w- c:\windows\system32\uxtheme.dll
2010-02-18 02:12 . 2010-02-18 02:12 503808 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7fd050e2-n\msvcp71.dll
2010-02-18 02:12 . 2010-02-18 02:12 499712 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7fd050e2-n\jmc.dll
2010-02-18 02:12 . 2010-02-18 02:12 348160 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7fd050e2-n\msvcr71.dll
2010-02-18 02:12 . 2010-02-18 02:12 61440 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4699ef4f-n\decora-sse.dll
2010-02-18 02:12 . 2010-02-18 02:12 12800 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4699ef4f-n\decora-d3d.dll
2010-02-18 02:11 . 2010-02-18 02:12 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-18 02:11 . 2010-02-18 02:11 79488 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\jre1.6.0_18\gtapi.dll
2010-02-18 02:10 . 2010-02-18 02:10 152576 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\jre1.6.0_18\lzma.dll
2010-02-16 14:08 . 2004-08-04 12:00 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-03 22:59 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-15 01:58 . 2010-02-15 01:58 193824 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\VBExpress\9.0\1033\ResourceCache.dll
2010-02-15 01:57 . 2010-02-15 01:57 416 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-02-14 03:09 . 2010-02-04 01:05 16384 —-a-w- c:\windows\system32\wbem\mofcomp.exe
2010-02-13 19:30 . 2010-02-04 01:10 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-02-12 10:46 . 2010-02-12 10:46 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 10:46 . 2010-02-12 10:46 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-12 10:03 . 2010-02-24 18:14 293376 ——w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33 . 2004-08-04 12:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 12:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-08 19:45 . 2010-02-08 19:45 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-02-04 01:41 . 2010-02-04 01:41 0 —-a-w- c:\windows\nsreg.dat
2010-02-04 01:34 . 2010-02-04 01:34 21035 —-a-w- c:\windows\system32\drivers\AegisP.sys
2010-02-04 01:07 . 2010-02-04 01:07 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2008-04-14 05:42 . 2010-02-04 21:56 60416 –sha-w- c:\windows\VistaMizer\old\msimn.exe
.
——- Sigcheck ——-
[-] 2008-04-14 . A55B8899D2EA2E800061BCFD456E34DC . 547328 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 . A55B8899D2EA2E800061BCFD456E34DC . 547328 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe
[-] 2004-08-04 . 55ACA85EB80E2155E20211AAADDD711A . 541696 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-04-14 . C280F24E855FBC107E8B95C42DC0EB3C . 724992 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-14 . C280F24E855FBC107E8B95C42DC0EB3C . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
[7] 2008-04-14 . 06F247492BC786CE5C24A23E178C711A . 617472 . . [5.82] . . c:\windows\VistaMizer\old\comctl32.dll
[-] 2004-08-04 . 5F25281C9DC595E269735EABC9F64485 . 718848 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll
[-] 2008-04-14 . 1F796B640B01A277B463E51CF0D79E10 . 587264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
[-] 2008-04-14 . 1F796B640B01A277B463E51CF0D79E10 . 587264 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[7] 2008-04-14 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\user32.dll
[7] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\user32.dll
[7] 2004-08-04 . C72661F8552ACE7C5C85E16A3CF505C4 . 577024 . . [5.1.2600.2180] . . c:\windows\ERDNT\cache\user32.dll
[-] 2008-04-14 . DCDEAA7B5698587F82C0F6CD7FB71967 . 1551872 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . DCDEAA7B5698587F82C0F6CD7FB71967 . 1551872 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe
[-] 2004-08-04 . 49290030CE8BB6A2C5AF4339B122261F . 1550336 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe
[-] 2008-04-14 . B5E8782D4AF1B3756F38E11E7C157BBE . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . B5E8782D4AF1B3756F38E11E7C157BBE . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe
[-] 2004-08-04 . 5F1724D0E11EB88C95A3B73A6DD72779 . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 14:04 1664256 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-01 16208384]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"nwiz"="nwiz.exe" [2006-04-27 1519616]
"Breakaway"="c:\program files\Breakaway\breakaway.exe" [2008-12-14 8994816]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-03-10 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-03-10 688218]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-27 7561216]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 25088]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-24 14:38 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless Networking Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Belkin Wireless Networking Utility.lnk
backup=c:\windows\pss\Belkin Wireless Networking Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ZDWLan Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ZDWLan Utility.lnk
backup=c:\windows\pss\ZDWLan Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bandmon]
2008-06-01 17:05 1529856 —-a-w- c:\program files\Rokario\Bandwidth Monitor\bandmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-03-26 00:10 142120 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
2008-04-17 03:31 169256 —-a-w- c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [24/03/2010 15:38 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [24/03/2010 15:38 242896]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [24/03/2010 15:36 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [24/03/2010 15:36 308064]
R3 EuMusDesignVirtualAudioCableWdm_lcs;Breakaway Pipeline (WDM);c:\windows\system32\drivers\vaclcskd.sys [27/08/2008 04:01 48872]
R3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [19/04/2004 16:01 6656]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [24/02/2010 23:43 598400]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 20:19 13592]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [24/03/2010 15:38 369920]
S3 cpuz131;cpuz131;\??\c:\docume~1\Me\LOCALS~1\Temp\cpuz131\cpuz_x32.sys –> c:\docume~1\Me\LOCALS~1\Temp\cpuz131\cpuz_x32.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2010-04-27 c:\windows\Tasks\Auslogics Console Defragmentation.job
- c:\program files\Auslogics\AusLogics Disk Defrag\cdefrag.exe [2010-02-04 00:42]
2010-04-27 c:\windows\Tasks\User_Feed_Synchronization-{AC472B14-94B8-4C03-BFA0-802CE98B3952}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.belkin.com/support/networkingsupport.asp
uInternet Settings,ProxyOverride = *.local
IE: Download with Faster Downloader - c:\program files\PsykonikCorp\Faster Downloader\dl.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: {5952FBA8-3A7E-4D84-AD2A-86D1E9102708} = 156.154.70.22,156.154.71.22
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\documents and settings\Me\Application Data\Mozilla\Firefox\Profiles\c1qwdl02.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Me\Application Data\Mozilla\Firefox\Profiles\c1qwdl02.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-boincmgr - c:\program files\BOINC\boincmgr.exe
MSConfigStartUp-boinctray - c:\program files\BOINC\boinctray.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-28 00:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1144)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(1200)
c:\windows\system32\setupapi.dll
c:\windows\system32\psbase.dll
- - - - - - - > 'explorer.exe'(1112)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSENG.DLL
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\mqsvc.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\mqtgsvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\OSK.exe
c:\windows\system32\MSSWCHX.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-04-28 00:34:20 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-27 23:34
ComboFix2.txt 2010-02-13 01:41
ComboFix3.txt 2010-02-08 02:03
Pre-Run: 85,320,896,512 bytes free
Post-Run: 85,313,699,840 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 1409057E823B01621A833CD14BD78DA3