ComboFix 11-12-13.03 - Phil 12/14/2011 14:27:46.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3039.2209 [GMT -5:00]
Running from: e:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
e:\docume~1\Phil\LOCALS~1\Temp\AdskCleanup.0001.dir.0001\~de87df.tmp
e:\docume~1\Phil\LOCALS~1\Temp\AdskCleanup.0001.dir.0001\~df394b.tmp
e:\documents and settings\Phil\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
e:\documents and settings\Phil\Local Settings\Temp\AdskCleanup.0001.dir.0001\~de87df.tmp
e:\documents and settings\Phil\Local Settings\Temp\AdskCleanup.0001.dir.0001\~df394b.tmp
e:\documents and settings\Phil\Start Menu\Programs\System Fix
e:\documents and settings\Phil\Start Menu\Programs\System Fix\System Fix.lnk
e:\documents and settings\Phil\Start Menu\Programs\System Fix\Uninstall System Fix.lnk
G:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-11-14 to 2011-12-14 )))))))))))))))))))))))))))))))
.
.
2011-12-14 20:01 . 2011-12-14 20:01 29904 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4F678CED-A1DD-4F4F-871B-9C0AC760CDC8}\MpKsl2513e80b.sys
2011-12-14 20:01 . 2011-12-14 20:01 56200 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4F678CED-A1DD-4F4F-871B-9C0AC760CDC8}\offreg.dll
2011-12-14 12:43 . 2011-11-21 10:47 6823496 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4F678CED-A1DD-4F4F-871B-9C0AC760CDC8}\mpengine.dll
2011-12-14 12:31 . 2011-12-14 12:31 ——– d—–w- e:\windows\system32\wbem\Repository
2011-12-14 12:31 . 2011-12-14 12:31 ——– d—–w- e:\documents and settings\All Users\Application Data\AVG10
2011-12-14 12:30 . 2011-12-14 12:30 ——– d—–w- e:\documents and settings\Phil\Application Data\AVG Secure Search
2011-12-14 12:30 . 2011-12-14 12:30 ——– d—–w- E:\$AVG
2011-12-14 12:30 . 2011-12-14 12:31 ——– d—–w- e:\program files\AVG Secure Search
2011-12-14 12:30 . 2011-12-14 12:30 ——– d–h–w- e:\program files\Common Files\AVG Secure Search
2011-12-07 02:55 . 2011-12-07 02:55 ——– d–h–w- e:\windows\PIF
2011-12-07 02:52 . 2011-12-13 19:48 ——– d—–w- e:\documents and settings\Administrator
2011-11-22 12:59 . 2011-11-22 12:59 ——– d—–w- e:\documents and settings\Phil\Local Settings\Application Data\VS Revo Group
2011-11-22 12:59 . 2009-12-30 16:20 27064 —-a-w- e:\windows\system32\drivers\revoflt.sys
2011-11-22 12:59 . 2011-11-22 12:59 ——– d–h–w- e:\program files\VS Revo Group
2011-11-22 11:48 . 2011-08-31 22:00 22216 —ha-w- e:\windows\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-08-15 23:56 6823496 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-17 14:00 . 2011-05-18 12:05 414368 —-a-w- e:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 12:42 . 2011-10-24 12:42 20909356 —-a-w- E:\GEDC0052.zip
2011-10-10 14:22 . 2010-12-09 01:05 692736 —h–w- e:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 12:00 599040 —-a-w- e:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2007-10-09 17:03 611328 —-a-w- e:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 12:00 220160 —ha-w- e:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 12:00 20480 —-a-w- e:\windows\system32\oleaccrc.dll
1997-06-23 08:00 123664 –sha-w- e:\windows\system32\Msjint35.dll
1997-06-23 17:06 24848 –sha-w- e:\windows\system32\Msjter35.dll
1997-06-23 17:06 252176 –sha-w- e:\windows\system32\Msrd2x35.dll
1997-06-23 17:06 287504 –sha-w- e:\windows\system32\Msxbse35.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "e:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-05-30 15:33 2495816 —-a-w- e:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="e:\documents and settings\Phil\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
"RCUI"="e:\progra~1\RINGCE~1\RINGCE~1\RCUI.exe" [2010-11-23 500992]
"RCHotKey"="e:\progra~1\RINGCE~1\RINGCE~1\RCHotKey.exe" [2010-11-23 38144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="e:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"nwiz"="nwiz.exe" [2006-10-31 1622016]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-08-24 18702336]
"LXBXCATS"="e:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-11-02 69632]
"lxbxmon.exe"="e:\program files\Lexmark 7100 Series\lxbxmon.exe" [2005-01-18 196608]
"FaxCenterServer4_in_1"="e:\program files\Lexmark 7100 Series\fm3032.exe" [2004-12-06 286720]
"EzPrint"="e:\program files\Lexmark 7100 Series\ezprint.exe" [2004-09-17 61440]
"Microsoft Default Manager"="e:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"boincmgr"="e:\program files\BOINC\boincmgr.exe" [2010-09-23 4543232]
"boinctray"="e:\program files\BOINC\boinctray.exe" [2010-09-23 58112]
"HPWQTOOLBOX"="e:\program files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe" [2005-06-03 335872]
"MpsOnn"="e:\windows\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe" [2007-05-27 28232]
"Adobe ARM"="e:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"MSC"="e:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
e:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - e:\program files\Common Files\Autodesk Shared\acstart16.exe [2004-2-24 10872]
subst.lnk - e:\windows\system32\subst.exe [2004-8-4 9216]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0e:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0e:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- e:\program files\Messenger\msmsgs.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\WINDOWS\\system32\\lxbxcoms.exe"=
"e:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxbxPSWX.EXE"=
"e:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"e:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"e:\\Program Files\\RingCentral\\RingCentral Call Controller\\RCUI.exe"=
"e:\\Documents and Settings\\Phil\\Application Data\\mjusbsp\\magicJack.exe"=
"e:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"e:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
.
R0 AVGIDSEH;AVGIDSEH;e:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 22992]
R1 Avgtdix;AVG TDI Driver;e:\windows\system32\drivers\avgtdix.sys [11/9/2010 10:20 PM 297168]
R1 BIOS;BIOS;e:\windows\system32\drivers\BIOS.sys [12/8/2010 1:53 PM 13696]
R1 MpKsl2513e80b;MpKsl2513e80b;e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4F678CED-A1DD-4F4F-871B-9C0AC760CDC8}\MpKsl2513e80b.sys [12/14/2011 3:01 PM 29904]
R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;e:\windows\system32\drivers\lne100v5.sys [12/8/2010 8:51 AM 36224]
S0 Avgrkx86;AVG Anti-Rootkit Driver;e:\windows\system32\DRIVERS\avgrkx86.sys –> e:\windows\system32\DRIVERS\avgrkx86.sys [?]
S1 Avgldx86;AVG AVI Loader Driver;e:\windows\system32\DRIVERS\avgldx86.sys –> e:\windows\system32\DRIVERS\avgldx86.sys [?]
S1 MpKsl78bf1b8c;MpKsl78bf1b8c;\??\e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7FDE7CDA-1824-4018-96CA-88626BF90FC5}\MpKsl78bf1b8c.sys –> e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7FDE7CDA-1824-4018-96CA-88626BF90FC5}\MpKsl78bf1b8c.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;"e:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe" –> e:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [?]
S2 avgwd;AVG WatchDog;e:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 4:33 AM 269520]
S2 gupdate;Google Update Service (gupdate);e:\program files\Google\Update\GoogleUpdate.exe [12/13/2010 9:35 AM 136176]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [12/8/2010 1:56 PM 1684736]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;e:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [5/12/2011 8:38 AM 1025352]
S3 AVGIDSDriver;AVGIDSDriver;e:\windows\system32\DRIVERS\AVGIDSDriver.Sys –> e:\windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
S3 AVGIDSFilter;AVGIDSFilter;e:\windows\system32\DRIVERS\AVGIDSFilter.Sys –> e:\windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
S3 AVGIDSShim;AVGIDSShim;e:\windows\system32\DRIVERS\AVGIDSShim.Sys –> e:\windows\system32\DRIVERS\AVGIDSShim.Sys [?]
S3 gupdatem;Google Update Service (gupdatem);e:\program files\Google\Update\GoogleUpdate.exe [12/13/2010 9:35 AM 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"e:\program files\McAfee Security Scan\2.1.121\McCHSvc.exe" –> e:\program files\McAfee Security Scan\2.1.121\McCHSvc.exe [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL2513E80B
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-14 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-12-13 14:35]
.
2011-12-14 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-12-13 14:35]
.
2011-12-14 e:\windows\Tasks\MP Scheduled Scan.job
- e:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride =
IE: Google Sidewiki… - e:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.2.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - e:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Adobe Flash Player ActiveX - e:\windows\system32\Macromed\Flash\FlashUtil10w_ActiveX.exe
AddRemove-Google Chrome - e:\program files\Google\Chrome\Application\14.0.835.186\Installer\setup.exe
AddRemove-McAfee Security Scan - e:\program files\McAfee Security Scan\uninstall.exe
AddRemove-{2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\Google\Google Toolbar\Component\GoogleToolbarManager_4E7D715D860E20E1.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-14 15:02
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBXCATS = rundll32 e:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE255"): The system cannot find the file specified.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3248)
e:\windows\system32\WININET.dll
e:\progra~1\RINGCE~1\RINGCE~1\RCHotKeyHook.dll
e:\windows\system32\ieframe.dll
e:\windows\system32\mshtml.dll
e:\windows\system32\msls31.dll
e:\windows\system32\jscript.dll
e:\windows\system32\webcheck.dll
e:\windows\system32\WPDShServiceObj.dll
e:\windows\system32\PortableDeviceTypes.dll
e:\windows\system32\PortableDeviceApi.dll
e:\windows\system32\ImgUtil.dll
e:\windows\system32\pngfilt.dll
e:\windows\system32\Dxtrans.dll
e:\windows\system32\Dxtmsft.dll
.
———————— Other Running Processes ————————
.
e:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\windows\system32\nvsvc32.exe
e:\windows\System32\snmp.exe
e:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
e:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
e:\windows\RTHDCPL.EXE
e:\windows\system32\lxbxcoms.exe
e:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
e:\program files\BOINC\boinc.exe
e:\documents and settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_c4cw_lmps_6.40_windows_intelx86
e:\documents and settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_c4cw_lmps_6.40_windows_intelx86
e:\documents and settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_c4cw_lmps_6.40_windows_intelx86
e:\documents and settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_c4cw_lmps_6.40_windows_intelx86
e:\program files\Common Files\Java\Java Update\jucheck.exe
e:\program files\AutoCAD 2005\acad.exe
e:\docume~1\Phil\LOCALS~1\Temp\AdskCleanup.0001
e:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
e:\program files\Common Files\Autodesk Shared\WSCommCntr1.exe
e:\program files\Adobe\Reader 10.0\Reader\AcroRd32.exe
e:\program files\Adobe\Reader 10.0\Reader\AcroRd32.exe
.
**************************************************************************
.
Completion time: 2011-12-14 15:19:03 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-14 20:18
ComboFix2.txt 2011-12-12 11:39
.
Pre-Run: 466,974,113,792 bytes free
Post-Run: 467,246,444,544 bytes free
.
- - End Of File - - F2D9C9872D794DB1B28D9466DE367536