tobyjones
Panda anti virus protection now won't enable. Also had a pop up of not being able to find pavjobs
ComboFix 10-07-21.01 - adam 21/07/2010 23:45:17.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1358 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\adam\Desktop\CFScript.txt
AV: Panda Global Protection 2010 *On-access scanning disabled* (Updated) {8BF935E7-731F-4115-B7A5-789FF5087595}
FW: Panda Personal Firewall 2010 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
FILE ::
"c:\windows\system.tmp"
"c:\windows\win.tmp"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system.tmp
c:\windows\win.tmp
.
—- Previous Run ——-
.
c:\documents and settings\adam\Application Data\inst.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\favicon.ico
c:\windows\system32\mssfc.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Legacy_SFC
——-\Service_npf
——-\Service_sfc
((((((((((((((((((((((((( Files Created from 2010-06-21 to 2010-07-21 )))))))))))))))))))))))))))))))
.
2010-07-21 16:13 . 2010-07-21 16:30 ——– d-sh–r- c:\windows\PSICache
2010-07-21 15:59 . 2010-07-21 15:59 388096 —-a-r- c:\documents and settings\adam\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-21 15:11 . 2010-07-21 15:11 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-21 15:11 . 2010-07-21 15:11 ——– d—–w- c:\program files\Common Files\Panda Security
2010-07-20 23:10 . 2010-07-20 23:10 262 —-a-w- c:\windows\system32\PavCPL.dat
2010-07-14 06:56 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-09 11:05 . 2010-07-09 11:05 503808 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-246ea41e-n\msvcp71.dll
2010-07-09 11:05 . 2010-07-09 11:05 499712 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-246ea41e-n\jmc.dll
2010-07-09 11:05 . 2010-07-09 11:05 348160 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-246ea41e-n\msvcr71.dll
2010-07-09 11:05 . 2010-07-09 11:05 12800 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-55854d55-n\decora-d3d.dll
2010-07-09 11:05 . 2010-07-09 11:05 61440 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-55854d55-n\decora-sse.dll
2010-07-08 08:17 . 2010-07-08 08:19 ——– d—–w- c:\documents and settings\adam\Application Data\acccore
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\documents and settings\adam\Local Settings\Application Data\AIM
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\documents and settings\adam\Local Settings\Application Data\AOL
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\documents and settings\All Users\Application Data\AIM
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\program files\AIM
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\program files\Common Files\Software Update Utility
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\program files\Common Files\AOL
2010-07-01 11:07 . 2010-07-01 11:07 434176 —-a-w- c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\17053\RapportMS.dll
2010-07-01 07:18 . 2010-07-01 07:18 ——– d—–w- c:\windows\system32\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-21 22:38 . 2010-01-08 12:04 346280 —-a-w- c:\windows\system32\drivers\APPFCONT.DAT.bck
2010-07-21 22:38 . 2010-01-08 12:04 346280 —-a-w- c:\windows\system32\drivers\APPFCONT.DAT
2010-07-21 22:38 . 2010-01-08 12:04 1132 —-a-w- c:\windows\system32\drivers\APPFLTR.CFG.bck
2010-07-21 22:38 . 2010-01-08 12:04 1132 —-a-w- c:\windows\system32\drivers\APPFLTR.CFG
2010-07-21 21:53 . 2010-01-08 12:08 13880 —-a-w- c:\windows\system32\drivers\COMFiltr.sys
2010-07-21 21:25 . 2007-03-06 08:39 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-21 16:13 . 2010-01-08 12:03 ——– d—–w- c:\program files\Panda Security
2010-07-21 10:19 . 2010-06-10 12:27 ——– d—–w- c:\documents and settings\adam\Application Data\OpenOffice.org2
2010-07-19 14:00 . 2009-10-01 07:44 ——– d—–w- c:\documents and settings\adam\Application Data\Vso
2010-07-17 18:17 . 2010-06-10 13:03 1 —-a-w- c:\documents and settings\adam\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-06-25 07:32 . 2009-07-10 16:08 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-06-14 14:31 . 2008-03-31 18:33 744448 —-a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-01 07:20 . 2010-06-01 07:20 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-06-01 07:20 . 2010-06-01 07:20 ——– d—–w- c:\program files\DVDVideoSoft
2010-05-31 14:01 . 2010-05-31 13:59 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2010-05-31 14:00 . 2007-02-23 19:03 70152 —-a-w- c:\documents and settings\adam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-31 14:00 . 2010-05-31 13:59 ——– d—–w- c:\documents and settings\adam\Application Data\CyberLink
2010-05-31 13:58 . 2007-02-23 19:13 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-05-31 13:51 . 2010-05-31 13:47 ——– d—–w- c:\program files\CyberLink
2010-05-31 13:46 . 2010-05-31 13:46 36864 —-a-w- c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2010-05-31 11:49 . 2010-05-31 11:40 ——– d—–w- c:\program files\Nuclear Coffee
2010-05-06 10:41 . 2002-08-29 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2002-08-29 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2007-05-26 08:01 . 2007-05-26 08:00 594800 —-a-w- c:\program files\gkwv2_setup.exe
2007-05-25 14:42 . 2007-05-25 14:42 14659071 —-a-w- c:\program files\KE_setup13143.exe
2007-05-25 14:40 . 2007-05-25 14:40 1585247 —-a-w- c:\program files\SEOE_setup4081.exe
2007-05-24 20:07 . 2007-05-24 20:04 14279822 —-a-w- c:\program files\scvc6000.exe
2007-05-23 15:28 . 2007-05-23 15:27 9389672 —-a-w- c:\program files\winzip111.exe
2007-05-21 17:54 . 2007-05-21 17:54 64625683 —-a-w- c:\program files\xsiteprosetup.exe
2007-03-06 08:50 . 2007-03-06 08:50 2683984 —-a-w- c:\program files\ccsetup137.exe
2007-03-06 08:39 . 2007-03-06 08:39 11352928 —-a-w- c:\program files\spydocsetup.exe
2007-02-28 00:03 . 2007-02-28 00:03 199874112 —-a-w- c:\program files\Nero-7.7.5.1_eng_trial.exe
2007-02-24 19:25 . 2007-02-24 19:25 33170212 —-a-w- c:\program files\klmcodec165.exe
2007-02-24 18:21 . 2007-02-24 18:20 411509 —-a-w- c:\program files\GSpot270a.zip
2007-02-24 17:52 . 2007-02-24 17:52 6241753 —-a-w- c:\program files\XP-Codec-Pack-2.0.6.zip
2007-02-24 17:45 . 2007-02-24 17:41 5134848 —-a-w- c:\program files\SVCD2DVDv2.msi
2007-02-24 09:52 . 2007-02-24 09:52 1145896 —-a-w- c:\program files\GoogleToolbarInstaller.exe
2007-02-24 08:24 . 2007-02-24 08:24 60640 —-a-w- c:\program files\AC3ACM.zip
2007-02-24 08:23 . 2007-02-24 08:23 1045001 —-a-w- c:\program files\VirtualDub-MPEG2.zip
2007-02-24 08:07 . 2007-02-24 08:07 1094021 —-a-w- c:\program files\dvdshrink32setup1.zip
2007-02-24 07:55 . 2007-02-24 07:55 25755448 —-a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2007-02-23 20:44 . 2007-02-23 20:44 1201041 —-a-w- c:\program files\winrar.exe
2007-02-23 20:41 . 2007-02-23 20:40 24265736 —-a-w- c:\program files\dotnetfx.exe
2007-02-23 20:39 . 2007-02-23 20:38 5968384 —-a-w- c:\program files\SVCD2DVD.msi
2007-02-23 20:00 . 2007-02-23 20:00 21822168 —-a-w- c:\program files\AdbeRdr80_en_US.exe
2007-02-23 19:56 . 2007-02-23 19:56 36808256 —-a-w- c:\program files\iTunesSetup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-12-27 160592]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-23 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]
"nwiz"="nwiz.exe" [2005-10-10 1519616]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2005-01-17 84480]
"SoundMan"="SOUNDMAN.EXE" [2005-07-12 81920]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"APVXDWIN"="c:\program files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE" [2009-09-25 906496]
"SCANINICIO"="c:\program files\Panda Security\Panda Global Protection 2010\Inicio.exe" [2009-08-12 56064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2006-12-11 2115728]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-2-24 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 16:58 58672 —-a-w- c:\windows\system32\avldr.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^Google Goggles.lnk]
backup=c:\windows\pss\Google Goggles.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\adam\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AffiliateWindow Alerts]
2005-02-25 13:54 476672 —-a-w- c:\program files\AffiliateWindow Alerts\affiliatewindow.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2010-05-21 15:36 3824472 —-a-w- c:\program files\AIM\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BinatoneInternetPhone]
2007-06-29 04:23 413696 —-a-w- c:\program files\Binatone Internet Phone\BinatoneInternetPhone.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-03-30 09:36 267048 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-09 17:53 153136 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rundll32.exe]
2007-08-30 16:43 4670704 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartHide]
2008-07-07 14:43 1335296 —-a-w- c:\program files\SmartHide\smarthide.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2007-08-30 16:43 4670704 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"iPod Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\SmartHide\\SmartHide.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17/11/2009 15:09 64288]
R0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [08/01/2010 13:00 28552]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [08/01/2010 13:04 75016]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [08/01/2010 13:04 53128]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [08/01/2010 13:04 22072]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [08/01/2010 13:04 193800]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [08/01/2010 13:04 159112]
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [01/07/2010 12:07 59240]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [01/07/2010 12:07 166632]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [08/01/2010 13:04 46728]
R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda –> c:\windows\system32\svchost -k Panda [?]
R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Global Protection 2010\psksvc.exe [08/01/2010 13:04 28928]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [01/07/2010 12:07 840936]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys –> c:\windows\system32\drivers\av5flt.sys [?]
R3 ComFiltr;Panda Anti-Dialer;c:\windows\system32\drivers\COMFiltr.sys [08/01/2010 13:08 13880]
R3 NETIMFLT01060039;PANDA NDIS IM Filter Miniport v1.6.0.39;c:\windows\system32\drivers\neti1639.sys [08/01/2010 13:03 199432]
R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\PavTPK.sys –> c:\windows\system32\PavTPK.sys [?]
R3 tap0801;Smarthide TAP driver;c:\windows\system32\drivers\tap0801.sys [12/10/2007 14:07 55808]
S1 ShldDrv;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShlDrv51.sys –> c:\windows\system32\DRIVERS\ShlDrv51.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 12:17 1181328]
S2 PavProc;Panda Process Protection Driver;\??\c:\windows\system32\DRIVERS\PavProc.sys –> c:\windows\system32\DRIVERS\PavProc.sys [?]
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys –> c:\windows\system32\PavSRK.sys [?]
S3 RkPavproc1;RkPavproc1;\??\c:\windows\system32\drivers\RkPavproc1.sys –> c:\windows\system32\drivers\RkPavproc1.sys [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys –> d:\NTGLM7X.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 03:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-20 c:\windows\Tasks\Basic clean-up.job
- c:\program files\Panda Security\Panda Global Protection 2010\PlaTasks.exe [2010-01-08 13:46]
2010-07-21 c:\windows\Tasks\User_Feed_Synchronization-{CF5E3D8D-1EED-4D74-931D-56B0FEE9941C}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.co.uk/
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - component: c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
AddRemove-Good Keywords v2.01_is1 - c:\program files\Softnik Technologies\Good Keywords v2.01\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-21 23:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-823518204-1343024091-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1640)
c:\windows\system32\avldr.dll
.
Completion time: 2010-07-21 23:54:24
ComboFix-quarantined-files.txt 2010-07-21 22:54
Pre-Run: 114,855,575,552 bytes free
Post-Run: 114,854,100,992 bytes free
- - End Of File - - 35CE3CF24C9236482117B201901A2429
ComboFix 10-07-21.01 - adam 21/07/2010 23:45:17.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1358 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\adam\Desktop\CFScript.txt
AV: Panda Global Protection 2010 *On-access scanning disabled* (Updated) {8BF935E7-731F-4115-B7A5-789FF5087595}
FW: Panda Personal Firewall 2010 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
FILE ::
"c:\windows\system.tmp"
"c:\windows\win.tmp"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system.tmp
c:\windows\win.tmp
.
—- Previous Run ——-
.
c:\documents and settings\adam\Application Data\inst.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\favicon.ico
c:\windows\system32\mssfc.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Legacy_SFC
——-\Service_npf
——-\Service_sfc
((((((((((((((((((((((((( Files Created from 2010-06-21 to 2010-07-21 )))))))))))))))))))))))))))))))
.
2010-07-21 16:13 . 2010-07-21 16:30 ——– d-sh–r- c:\windows\PSICache
2010-07-21 15:59 . 2010-07-21 15:59 388096 —-a-r- c:\documents and settings\adam\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-21 15:11 . 2010-07-21 15:11 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-21 15:11 . 2010-07-21 15:11 ——– d—–w- c:\program files\Common Files\Panda Security
2010-07-20 23:10 . 2010-07-20 23:10 262 —-a-w- c:\windows\system32\PavCPL.dat
2010-07-14 06:56 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-09 11:05 . 2010-07-09 11:05 503808 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-246ea41e-n\msvcp71.dll
2010-07-09 11:05 . 2010-07-09 11:05 499712 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-246ea41e-n\jmc.dll
2010-07-09 11:05 . 2010-07-09 11:05 348160 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-246ea41e-n\msvcr71.dll
2010-07-09 11:05 . 2010-07-09 11:05 12800 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-55854d55-n\decora-d3d.dll
2010-07-09 11:05 . 2010-07-09 11:05 61440 —-a-w- c:\documents and settings\adam\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-55854d55-n\decora-sse.dll
2010-07-08 08:17 . 2010-07-08 08:19 ——– d—–w- c:\documents and settings\adam\Application Data\acccore
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\documents and settings\adam\Local Settings\Application Data\AIM
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\documents and settings\adam\Local Settings\Application Data\AOL
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\documents and settings\All Users\Application Data\AIM
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\program files\AIM
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\program files\Common Files\Software Update Utility
2010-07-08 08:17 . 2010-07-08 08:17 ——– d—–w- c:\program files\Common Files\AOL
2010-07-01 11:07 . 2010-07-01 11:07 434176 —-a-w- c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\17053\RapportMS.dll
2010-07-01 07:18 . 2010-07-01 07:18 ——– d—–w- c:\windows\system32\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-21 22:38 . 2010-01-08 12:04 346280 —-a-w- c:\windows\system32\drivers\APPFCONT.DAT.bck
2010-07-21 22:38 . 2010-01-08 12:04 346280 —-a-w- c:\windows\system32\drivers\APPFCONT.DAT
2010-07-21 22:38 . 2010-01-08 12:04 1132 —-a-w- c:\windows\system32\drivers\APPFLTR.CFG.bck
2010-07-21 22:38 . 2010-01-08 12:04 1132 —-a-w- c:\windows\system32\drivers\APPFLTR.CFG
2010-07-21 21:53 . 2010-01-08 12:08 13880 —-a-w- c:\windows\system32\drivers\COMFiltr.sys
2010-07-21 21:25 . 2007-03-06 08:39 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-21 16:13 . 2010-01-08 12:03 ——– d—–w- c:\program files\Panda Security
2010-07-21 10:19 . 2010-06-10 12:27 ——– d—–w- c:\documents and settings\adam\Application Data\OpenOffice.org2
2010-07-19 14:00 . 2009-10-01 07:44 ——– d—–w- c:\documents and settings\adam\Application Data\Vso
2010-07-17 18:17 . 2010-06-10 13:03 1 —-a-w- c:\documents and settings\adam\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-06-25 07:32 . 2009-07-10 16:08 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-06-14 14:31 . 2008-03-31 18:33 744448 —-a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-01 07:20 . 2010-06-01 07:20 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-06-01 07:20 . 2010-06-01 07:20 ——– d—–w- c:\program files\DVDVideoSoft
2010-05-31 14:01 . 2010-05-31 13:59 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2010-05-31 14:00 . 2007-02-23 19:03 70152 —-a-w- c:\documents and settings\adam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-31 14:00 . 2010-05-31 13:59 ——– d—–w- c:\documents and settings\adam\Application Data\CyberLink
2010-05-31 13:58 . 2007-02-23 19:13 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-05-31 13:51 . 2010-05-31 13:47 ——– d—–w- c:\program files\CyberLink
2010-05-31 13:46 . 2010-05-31 13:46 36864 —-a-w- c:\documents and settings\All Users\Application Data\TEMP\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\PostBuild.exe
2010-05-31 11:49 . 2010-05-31 11:40 ——– d—–w- c:\program files\Nuclear Coffee
2010-05-06 10:41 . 2002-08-29 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2002-08-29 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2007-05-26 08:01 . 2007-05-26 08:00 594800 —-a-w- c:\program files\gkwv2_setup.exe
2007-05-25 14:42 . 2007-05-25 14:42 14659071 —-a-w- c:\program files\KE_setup13143.exe
2007-05-25 14:40 . 2007-05-25 14:40 1585247 —-a-w- c:\program files\SEOE_setup4081.exe
2007-05-24 20:07 . 2007-05-24 20:04 14279822 —-a-w- c:\program files\scvc6000.exe
2007-05-23 15:28 . 2007-05-23 15:27 9389672 —-a-w- c:\program files\winzip111.exe
2007-05-21 17:54 . 2007-05-21 17:54 64625683 —-a-w- c:\program files\xsiteprosetup.exe
2007-03-06 08:50 . 2007-03-06 08:50 2683984 —-a-w- c:\program files\ccsetup137.exe
2007-03-06 08:39 . 2007-03-06 08:39 11352928 —-a-w- c:\program files\spydocsetup.exe
2007-02-28 00:03 . 2007-02-28 00:03 199874112 —-a-w- c:\program files\Nero-7.7.5.1_eng_trial.exe
2007-02-24 19:25 . 2007-02-24 19:25 33170212 —-a-w- c:\program files\klmcodec165.exe
2007-02-24 18:21 . 2007-02-24 18:20 411509 —-a-w- c:\program files\GSpot270a.zip
2007-02-24 17:52 . 2007-02-24 17:52 6241753 —-a-w- c:\program files\XP-Codec-Pack-2.0.6.zip
2007-02-24 17:45 . 2007-02-24 17:41 5134848 —-a-w- c:\program files\SVCD2DVDv2.msi
2007-02-24 09:52 . 2007-02-24 09:52 1145896 —-a-w- c:\program files\GoogleToolbarInstaller.exe
2007-02-24 08:24 . 2007-02-24 08:24 60640 —-a-w- c:\program files\AC3ACM.zip
2007-02-24 08:23 . 2007-02-24 08:23 1045001 —-a-w- c:\program files\VirtualDub-MPEG2.zip
2007-02-24 08:07 . 2007-02-24 08:07 1094021 —-a-w- c:\program files\dvdshrink32setup1.zip
2007-02-24 07:55 . 2007-02-24 07:55 25755448 —-a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2007-02-23 20:44 . 2007-02-23 20:44 1201041 —-a-w- c:\program files\winrar.exe
2007-02-23 20:41 . 2007-02-23 20:40 24265736 —-a-w- c:\program files\dotnetfx.exe
2007-02-23 20:39 . 2007-02-23 20:38 5968384 —-a-w- c:\program files\SVCD2DVD.msi
2007-02-23 20:00 . 2007-02-23 20:00 21822168 —-a-w- c:\program files\AdbeRdr80_en_US.exe
2007-02-23 19:56 . 2007-02-23 19:56 36808256 —-a-w- c:\program files\iTunesSetup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-12-27 160592]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-23 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-10 7286784]
"nwiz"="nwiz.exe" [2005-10-10 1519616]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2005-01-17 84480]
"SoundMan"="SOUNDMAN.EXE" [2005-07-12 81920]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-10 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"APVXDWIN"="c:\program files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE" [2009-09-25 906496]
"SCANINICIO"="c:\program files\Panda Security\Panda Global Protection 2010\Inicio.exe" [2009-08-12 56064]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2006-12-11 2115728]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-2-24 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 16:58 58672 —-a-w- c:\windows\system32\avldr.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^Google Goggles.lnk]
backup=c:\windows\pss\Google Goggles.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\adam\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AffiliateWindow Alerts]
2005-02-25 13:54 476672 —-a-w- c:\program files\AffiliateWindow Alerts\affiliatewindow.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim]
2010-05-21 15:36 3824472 —-a-w- c:\program files\AIM\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BinatoneInternetPhone]
2007-06-29 04:23 413696 —-a-w- c:\program files\Binatone Internet Phone\BinatoneInternetPhone.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-03-30 09:36 267048 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-09 17:53 153136 —-a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rundll32.exe]
2007-08-30 16:43 4670704 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartHide]
2008-07-07 14:43 1335296 —-a-w- c:\program files\SmartHide\smarthide.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2007-08-30 16:43 4670704 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"iPod Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\SmartHide\\SmartHide.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17/11/2009 15:09 64288]
R0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [08/01/2010 13:00 28552]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [08/01/2010 13:04 75016]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [08/01/2010 13:04 53128]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [08/01/2010 13:04 22072]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [08/01/2010 13:04 193800]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [08/01/2010 13:04 159112]
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [01/07/2010 12:07 59240]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [01/07/2010 12:07 166632]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [08/01/2010 13:04 46728]
R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda –> c:\windows\system32\svchost -k Panda [?]
R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Global Protection 2010\psksvc.exe [08/01/2010 13:04 28928]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [01/07/2010 12:07 840936]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys –> c:\windows\system32\drivers\av5flt.sys [?]
R3 ComFiltr;Panda Anti-Dialer;c:\windows\system32\drivers\COMFiltr.sys [08/01/2010 13:08 13880]
R3 NETIMFLT01060039;PANDA NDIS IM Filter Miniport v1.6.0.39;c:\windows\system32\drivers\neti1639.sys [08/01/2010 13:03 199432]
R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\PavTPK.sys –> c:\windows\system32\PavTPK.sys [?]
R3 tap0801;Smarthide TAP driver;c:\windows\system32\drivers\tap0801.sys [12/10/2007 14:07 55808]
S1 ShldDrv;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShlDrv51.sys –> c:\windows\system32\DRIVERS\ShlDrv51.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 12:17 1181328]
S2 PavProc;Panda Process Protection Driver;\??\c:\windows\system32\DRIVERS\PavProc.sys –> c:\windows\system32\DRIVERS\PavProc.sys [?]
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys –> c:\windows\system32\PavSRK.sys [?]
S3 RkPavproc1;RkPavproc1;\??\c:\windows\system32\drivers\RkPavproc1.sys –> c:\windows\system32\drivers\RkPavproc1.sys [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys –> d:\NTGLM7X.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 03:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:09]
2010-07-20 c:\windows\Tasks\Basic clean-up.job
- c:\program files\Panda Security\Panda Global Protection 2010\PlaTasks.exe [2010-01-08 13:46]
2010-07-21 c:\windows\Tasks\User_Feed_Synchronization-{CF5E3D8D-1EED-4D74-931D-56B0FEE9941C}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.co.uk/
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.skybroadband.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - component: c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\documents and settings\adam\Application Data\Mozilla\Firefox\Profiles\9sjjzdwq.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
AddRemove-Good Keywords v2.01_is1 - c:\program files\Softnik Technologies\Good Keywords v2.01\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-21 23:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-823518204-1343024091-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1640)
c:\windows\system32\avldr.dll
.
Completion time: 2010-07-21 23:54:24
ComboFix-quarantined-files.txt 2010-07-21 22:54
Pre-Run: 114,855,575,552 bytes free
Post-Run: 114,854,100,992 bytes free
- - End Of File - - 35CE3CF24C9236482117B201901A2429