Starwalker
ComboFix 10-05-31.03 - Starwalker 06/01/2010 11:20:34.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1558 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Run These\Advanced\ComboFix.exe
Command switches used :: c:\documents and settings\Starwalker\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-01 to 2010-06-01 )))))))))))))))))))))))))))))))
.
2010-05-29 03:29 . 2010-05-29 03:29 ——– d—–w- c:\program files\Secunia
2010-05-28 11:04 . 2010-05-28 11:04 14896 —-a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-25 19:25 . 2010-05-25 19:25 503808 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\msvcp71.dll
2010-05-25 19:25 . 2010-05-25 19:25 499712 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\jmc.dll
2010-05-25 19:25 . 2010-05-25 19:25 348160 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\msvcr71.dll
2010-05-25 19:25 . 2010-05-25 19:25 61440 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-494f992d-n\decora-sse.dll
2010-05-25 19:25 . 2010-05-25 19:25 12800 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-494f992d-n\decora-d3d.dll
2010-05-21 05:24 . 2010-03-24 15:42 57418 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashGetXPI.dll
2010-05-20 04:28 . 2010-05-20 04:28 2944904 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\chrome\temp\askToolbar.exe
2010-05-19 04:37 . 2008-05-19 17:13 57344 —-a-w- c:\windows\system32\ASTSRV.EXE
2010-05-19 04:21 . 2010-05-19 04:21 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Foxit Software
2010-05-19 03:38 . 2010-05-19 03:38 ——– d—–w- c:\documents and settings\Starwalker\Application Data\ThumbsPlus
2010-05-19 03:35 . 2010-05-19 06:05 ——– d—–w- c:\program files\Thumbs7
2010-05-19 03:29 . 2010-05-19 03:29 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Auto FX Software
2010-05-19 03:27 . 2010-05-19 03:27 ——– d—–w- c:\documents and settings\Starwalker\Application Data\ThePluginSite
2010-05-19 03:27 . 2010-05-19 03:27 ——– d—–w- c:\program files\FocalBlade2
2010-05-18 17:28 . 2010-05-18 17:28 ——– d—–w- c:\documents and settings\LocalService\Application Data\Foxit Software
2010-05-15 08:20 . 2010-05-15 08:20 63488 —-a-w- c:\documents and settings\Starwalker\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-05-14 08:43 . 2010-04-12 22:29 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-05-11 08:58 . 2010-05-11 08:58 50354 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\uninstall.exe
2010-05-11 08:57 . 2010-05-11 08:58 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Facebook
2010-05-11 04:57 . 2010-03-26 02:49 66048 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\platform\WINNT\components\nsTwitterFoxSign.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-01 10:55 . 2007-11-06 06:08 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-01 10:51 . 2008-11-14 07:03 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-06-01 10:28 . 2010-02-19 20:48 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Disk Cleaner
2010-06-01 06:15 . 2008-05-10 01:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-05-31 17:03 . 2007-07-06 05:47 ——– d—–w- c:\program files\CCleaner
2010-05-29 03:24 . 2009-01-31 21:54 ——– d—–w- c:\program files\Glary Utilities
2010-05-21 05:14 . 2010-03-26 22:54 891 —-a-w- c:\windows\system32\secushr.dat
2010-05-20 09:13 . 2010-02-05 02:46 1 —-a-w- c:\documents and settings\Starwalker\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-20 07:01 . 2010-03-25 22:38 ——– d—–w- c:\program files\Ask.com
2010-05-20 03:00 . 2009-10-13 22:03 ——– d—–w- c:\program files\Outspark
2010-05-20 02:55 . 2007-07-06 04:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-05-19 04:41 . 2008-04-14 07:59 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Alien Skin
2010-05-19 02:58 . 2008-03-04 17:22 ——– d—–w- c:\documents and settings\Starwalker\Application Data\XnView
2010-05-19 01:50 . 2010-02-11 17:49 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Foxit Software
2010-05-18 17:28 . 2007-07-06 05:47 ——– d—–w- c:\program files\Foxit Software
2010-05-16 18:45 . 2007-07-08 04:09 ——– d—–w- c:\program files\Lexmark X1100 Series
2010-05-15 23:21 . 2007-07-23 02:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-15 16:34 . 2007-07-06 05:48 ——– d—–w- c:\program files\SpywareBlaster
2010-05-15 08:59 . 2009-01-31 22:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-15 08:19 . 2010-02-03 17:38 117760 —-a-w- c:\documents and settings\Starwalker\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-05-14 08:43 . 2007-07-08 01:48 ——– d—–w- c:\program files\Java
2010-05-14 03:58 . 2010-02-20 02:01 ——– d—–w- c:\documents and settings\Starwalker\Application Data\vlc
2010-05-12 00:20 . 2007-09-10 23:27 ——– d—–w- c:\program files\Google
2010-05-06 20:59 . 2010-02-19 22:58 165032 —-a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-02-19 22:58 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-02-19 22:58 164048 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-02-19 22:58 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2010-02-19 22:58 100432 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2010-02-19 22:58 94800 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2010-02-19 22:58 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2010-02-19 22:58 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-05 08:41 . 2010-02-10 08:39 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Skype
2010-05-04 09:32 . 2010-02-19 20:43 ——– d—–w- c:\program files\CleanUp!
2010-04-30 11:08 . 2007-07-08 00:24 ——– d—–w- c:\program files\IncrediMail
2010-04-30 01:46 . 2010-04-30 01:46 ——– d—–w- c:\documents and settings\Starwalker\Application Data\WeatherBug
2010-04-30 01:46 . 2010-04-30 01:46 18944 —-a-r- c:\documents and settings\Starwalker\Application Data\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe
2010-04-30 01:46 . 2010-04-30 01:46 11264 —-a-r- c:\documents and settings\Starwalker\Application Data\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A1630.exe
2010-04-30 01:46 . 2010-04-30 01:46 ——– d—–w- c:\program files\AWS
2010-04-29 22:31 . 2010-04-25 04:13 ——– d—–w- c:\program files\a-squared Free
2010-04-29 20:39 . 2009-01-31 22:17 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39 . 2009-01-31 22:17 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-26 19:27 . 2007-08-04 09:50 83888 —-a-w- c:\documents and settings\Starwalker\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-26 18:41 . 2010-04-26 18:41 ——– d—–w- c:\documents and settings\Starwalker\Application Data\AMPSoft
2010-04-18 05:27 . 2010-04-18 05:27 ——– d—–w- c:\program files\dayam NFO Viewer
2010-04-14 16:47 . 2010-02-19 22:58 38848 —-a-w- c:\windows\system32\avastSS.scr
2010-04-14 15:16 . 2010-04-14 15:16 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\program files\Norton Security Scan
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-04-14 15:07 . 2010-04-14 15:07 ——– d—–w- c:\program files\NortonInstaller
2010-04-14 15:07 . 2010-04-14 15:07 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-04-09 14:47 . 2010-04-09 14:46 ——– d—–w- c:\program files\QuickTime
2010-04-09 14:45 . 2010-02-20 02:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-04-09 09:06 . 2007-07-08 01:48 ——– d—–w- c:\program files\Common Files\Java
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23C.tmp
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23B.tmp
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23A.tmp
2010-04-09 09:00 . 2010-04-09 09:00 ——– d—–r- c:\program files\Skype
2010-04-09 09:00 . 2009-03-25 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2010-03-10 06:15 . 2001-08-18 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-10 05:24 . 2010-03-10 05:23 53319 —-a-w- c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2010-03-06 05:30 . 2010-03-06 05:30 847040 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\axfbootloader.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\npfbplugin_1_0_3.dll
.
——- Sigcheck ——-
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\ERDNT\cache\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-05-31_17.28.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-01 10:45 . 2010-06-01 10:45 16384 c:\windows\Temp\Perflib_Perfdata_9c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-17 23:43 1385864 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-10 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\Starwalker\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete
[HKLM\~\startupfolder\C:^Documents and Settings^Starwalker^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
2003-08-19 10:43 57344 —-a-w- c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 18:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 18:22 86016 —-a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 18:22 1622016 —-a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-04-06 07:27 26105128 —-a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-06-01 10:51 2397424 —-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2009-10-20 19:59 111928 —-a-r- c:\program files\SweetIM\Messenger\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2009-12-29 15:08 1653248 ——w- c:\program files\AWS\WeatherBug\Weather.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImPackr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImSc.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\Pando.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59165:TCP"= 59165:TCP:Pando
"59165:UDP"= 59165:UDP:Pando
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/19/2010 5:58 PM 164048]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 8:56 AM 67656]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [4/24/2010 11:13 PM 1872320]
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [5/18/2010 11:37 PM 57344]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/19/2010 5:58 PM 19024]
R3 DLKRTS;D-Link DFE-530TX+ PCI Adapter;c:\windows\system32\drivers\DLKRTS.SYS [7/7/2007 3:28 PM 45568]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [1/5/2010 8:56 AM 12872]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/11/2010 7:18 PM 136176]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 6:04 AM 14896]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 8:56 AM 12872]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-06-01 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-01-31 15:01]
2010-06-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-10 20:55]
2010-06-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 00:18]
2010-06-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 00:18]
2010-06-01 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-17 23:43]
.
.
——- Supplementary Scan ——-
.
uStart Page = yahoo.com
mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
uInternet Settings,ProxyOverride = *.local
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
FF - ProfilePath - c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search;=
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashGetXPI.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{db9d7a78-a76c-4bf2-97c6-258925ee1542}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{db9d7a78-a76c-4bf2-97c6-258925ee1542}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\platform\WINNT\components\nsTwitterFoxSign.dll
FF - plugin: c:\documents and settings\Starwalker\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\plugins\npiaplayer.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrWB.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-01 11:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(564)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2412)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-01 11:28:16
ComboFix-quarantined-files.txt 2010-06-01 16:28
ComboFix2.txt 2010-06-01 11:10
ComboFix3.txt 2010-05-31 23:18
ComboFix4.txt 2010-05-31 17:31
ComboFix5.txt 2010-06-01 16:17
Pre-Run: 14,086,074,368 bytes free
Post-Run: 14,079,471,616 bytes free
- - End Of File - - 0ABC67A7FC7FCDC60914448DB0C499C2
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1558 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Run These\Advanced\ComboFix.exe
Command switches used :: c:\documents and settings\Starwalker\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2010-05-01 to 2010-06-01 )))))))))))))))))))))))))))))))
.
2010-05-29 03:29 . 2010-05-29 03:29 ——– d—–w- c:\program files\Secunia
2010-05-28 11:04 . 2010-05-28 11:04 14896 —-a-w- c:\windows\system32\drivers\psi_mf.sys
2010-05-25 19:25 . 2010-05-25 19:25 503808 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\msvcp71.dll
2010-05-25 19:25 . 2010-05-25 19:25 499712 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\jmc.dll
2010-05-25 19:25 . 2010-05-25 19:25 348160 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4ae50dec-n\msvcr71.dll
2010-05-25 19:25 . 2010-05-25 19:25 61440 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-494f992d-n\decora-sse.dll
2010-05-25 19:25 . 2010-05-25 19:25 12800 —-a-w- c:\documents and settings\Starwalker\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-494f992d-n\decora-d3d.dll
2010-05-21 05:24 . 2010-03-24 15:42 57418 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashGetXPI.dll
2010-05-20 04:28 . 2010-05-20 04:28 2944904 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\chrome\temp\askToolbar.exe
2010-05-19 04:37 . 2008-05-19 17:13 57344 —-a-w- c:\windows\system32\ASTSRV.EXE
2010-05-19 04:21 . 2010-05-19 04:21 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Foxit Software
2010-05-19 03:38 . 2010-05-19 03:38 ——– d—–w- c:\documents and settings\Starwalker\Application Data\ThumbsPlus
2010-05-19 03:35 . 2010-05-19 06:05 ——– d—–w- c:\program files\Thumbs7
2010-05-19 03:29 . 2010-05-19 03:29 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Auto FX Software
2010-05-19 03:27 . 2010-05-19 03:27 ——– d—–w- c:\documents and settings\Starwalker\Application Data\ThePluginSite
2010-05-19 03:27 . 2010-05-19 03:27 ——– d—–w- c:\program files\FocalBlade2
2010-05-18 17:28 . 2010-05-18 17:28 ——– d—–w- c:\documents and settings\LocalService\Application Data\Foxit Software
2010-05-15 08:20 . 2010-05-15 08:20 63488 —-a-w- c:\documents and settings\Starwalker\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-05-14 08:43 . 2010-04-12 22:29 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-05-11 08:58 . 2010-05-11 08:58 50354 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\uninstall.exe
2010-05-11 08:57 . 2010-05-11 08:58 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Facebook
2010-05-11 04:57 . 2010-03-26 02:49 66048 —-a-w- c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\platform\WINNT\components\nsTwitterFoxSign.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-01 10:55 . 2007-11-06 06:08 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-01 10:51 . 2008-11-14 07:03 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-06-01 10:28 . 2010-02-19 20:48 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Disk Cleaner
2010-06-01 06:15 . 2008-05-10 01:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-05-31 17:03 . 2007-07-06 05:47 ——– d—–w- c:\program files\CCleaner
2010-05-29 03:24 . 2009-01-31 21:54 ——– d—–w- c:\program files\Glary Utilities
2010-05-21 05:14 . 2010-03-26 22:54 891 —-a-w- c:\windows\system32\secushr.dat
2010-05-20 09:13 . 2010-02-05 02:46 1 —-a-w- c:\documents and settings\Starwalker\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-20 07:01 . 2010-03-25 22:38 ——– d—–w- c:\program files\Ask.com
2010-05-20 03:00 . 2009-10-13 22:03 ——– d—–w- c:\program files\Outspark
2010-05-20 02:55 . 2007-07-06 04:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-05-19 04:41 . 2008-04-14 07:59 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Alien Skin
2010-05-19 02:58 . 2008-03-04 17:22 ——– d—–w- c:\documents and settings\Starwalker\Application Data\XnView
2010-05-19 01:50 . 2010-02-11 17:49 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Foxit Software
2010-05-18 17:28 . 2007-07-06 05:47 ——– d—–w- c:\program files\Foxit Software
2010-05-16 18:45 . 2007-07-08 04:09 ——– d—–w- c:\program files\Lexmark X1100 Series
2010-05-15 23:21 . 2007-07-23 02:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-15 16:34 . 2007-07-06 05:48 ——– d—–w- c:\program files\SpywareBlaster
2010-05-15 08:59 . 2009-01-31 22:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-15 08:19 . 2010-02-03 17:38 117760 —-a-w- c:\documents and settings\Starwalker\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-05-14 08:43 . 2007-07-08 01:48 ——– d—–w- c:\program files\Java
2010-05-14 03:58 . 2010-02-20 02:01 ——– d—–w- c:\documents and settings\Starwalker\Application Data\vlc
2010-05-12 00:20 . 2007-09-10 23:27 ——– d—–w- c:\program files\Google
2010-05-06 20:59 . 2010-02-19 22:58 165032 —-a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-02-19 22:58 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-02-19 22:58 164048 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-02-19 22:58 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2010-02-19 22:58 100432 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2010-02-19 22:58 94800 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2010-02-19 22:58 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2010-02-19 22:58 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-05 08:41 . 2010-02-10 08:39 ——– d—–w- c:\documents and settings\Starwalker\Application Data\Skype
2010-05-04 09:32 . 2010-02-19 20:43 ——– d—–w- c:\program files\CleanUp!
2010-04-30 11:08 . 2007-07-08 00:24 ——– d—–w- c:\program files\IncrediMail
2010-04-30 01:46 . 2010-04-30 01:46 ——– d—–w- c:\documents and settings\Starwalker\Application Data\WeatherBug
2010-04-30 01:46 . 2010-04-30 01:46 18944 —-a-r- c:\documents and settings\Starwalker\Application Data\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A16301.exe
2010-04-30 01:46 . 2010-04-30 01:46 11264 —-a-r- c:\documents and settings\Starwalker\Application Data\Microsoft\Installer\{8F018A9E-56DE-4A79-A5EF-25F413F1D538}\IconBB6A1630.exe
2010-04-30 01:46 . 2010-04-30 01:46 ——– d—–w- c:\program files\AWS
2010-04-29 22:31 . 2010-04-25 04:13 ——– d—–w- c:\program files\a-squared Free
2010-04-29 20:39 . 2009-01-31 22:17 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39 . 2009-01-31 22:17 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-26 19:27 . 2007-08-04 09:50 83888 —-a-w- c:\documents and settings\Starwalker\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-26 18:41 . 2010-04-26 18:41 ——– d—–w- c:\documents and settings\Starwalker\Application Data\AMPSoft
2010-04-18 05:27 . 2010-04-18 05:27 ——– d—–w- c:\program files\dayam NFO Viewer
2010-04-14 16:47 . 2010-02-19 22:58 38848 —-a-w- c:\windows\system32\avastSS.scr
2010-04-14 15:16 . 2010-04-14 15:16 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\program files\Norton Security Scan
2010-04-14 15:08 . 2010-04-14 15:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-04-14 15:07 . 2010-04-14 15:07 ——– d—–w- c:\program files\NortonInstaller
2010-04-14 15:07 . 2010-04-14 15:07 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-04-09 14:47 . 2010-04-09 14:46 ——– d—–w- c:\program files\QuickTime
2010-04-09 14:45 . 2010-02-20 02:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-04-09 09:06 . 2007-07-08 01:48 ——– d—–w- c:\program files\Common Files\Java
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23C.tmp
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23B.tmp
2010-04-09 09:03 . 2010-04-09 09:03 0 —-a-w- c:\windows\system32\REN23A.tmp
2010-04-09 09:00 . 2010-04-09 09:00 ——– d—–r- c:\program files\Skype
2010-04-09 09:00 . 2009-03-25 17:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2010-03-10 06:15 . 2001-08-18 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-10 05:24 . 2010-03-10 05:23 53319 —-a-w- c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2010-03-06 05:30 . 2010-03-06 05:30 847040 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\axfbootloader.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- c:\documents and settings\Starwalker\Application Data\Facebook\npfbplugin_1_0_3.dll
.
——- Sigcheck ——-
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\ERDNT\cache\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-05-31_17.28.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-01 10:45 . 2010-06-01 10:45 16384 c:\windows\Temp\Perflib_Perfdata_9c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-17 23:43 1385864 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-17 1385864]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-10 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\Starwalker\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2010-5-28 911920]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete
[HKLM\~\startupfolder\C:^Documents and Settings^Starwalker^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
2003-08-19 10:43 57344 —-a-w- c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 18:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 18:22 86016 —-a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 18:22 1622016 —-a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-04-06 07:27 26105128 —-a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-06-01 10:51 2397424 —-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2009-10-20 19:59 111928 —-a-r- c:\program files\SweetIM\Messenger\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2009-12-29 15:08 1653248 ——w- c:\program files\AWS\WeatherBug\Weather.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImPackr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImSc.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\Pando.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59165:TCP"= 59165:TCP:Pando
"59165:UDP"= 59165:UDP:Pando
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/19/2010 5:58 PM 164048]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 8:56 AM 67656]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [4/24/2010 11:13 PM 1872320]
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [5/18/2010 11:37 PM 57344]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/19/2010 5:58 PM 19024]
R3 DLKRTS;D-Link DFE-530TX+ PCI Adapter;c:\windows\system32\drivers\DLKRTS.SYS [7/7/2007 3:28 PM 45568]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [1/5/2010 8:56 AM 12872]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/11/2010 7:18 PM 136176]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [5/28/2010 6:04 AM 14896]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 8:56 AM 12872]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 09:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-06-01 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-01-31 15:01]
2010-06-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-10 20:55]
2010-06-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 00:18]
2010-06-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 00:18]
2010-06-01 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-05-17 23:43]
.
.
——- Supplementary Scan ——-
.
uStart Page = yahoo.com
mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
uInternet Settings,ProxyOverride = *.local
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
FF - ProfilePath - c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr;=ytff-&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search;=
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{DB9127A2-3381-41ec-82B3-1B6ED4C6F29A}\components\FlashGetXPI.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{db9d7a78-a76c-4bf2-97c6-258925ee1542}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\{db9d7a78-a76c-4bf2-97c6-258925ee1542}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\platform\WINNT\components\nsTwitterFoxSign.dll
FF - plugin: c:\documents and settings\Starwalker\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Starwalker\Application Data\Mozilla\Firefox\Profiles\39k2355g.default\extensions\[removed]\plugins\npiaplayer.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrWB.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-01 11:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(564)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2412)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-06-01 11:28:16
ComboFix-quarantined-files.txt 2010-06-01 16:28
ComboFix2.txt 2010-06-01 11:10
ComboFix3.txt 2010-05-31 23:18
ComboFix4.txt 2010-05-31 17:31
ComboFix5.txt 2010-06-01 16:17
Pre-Run: 14,086,074,368 bytes free
Post-Run: 14,079,471,616 bytes free
- - End Of File - - 0ABC67A7FC7FCDC60914448DB0C499C2