ComboFix 11-11-29.04 - Owner 11/29/2011 19:24:43.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2012.1500 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{40BF1E83-20EB-11D8-97C5-0009C5020658}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\plgwrrbw.default\extensions\{c348ed13-eeb8-40f1-a387-32843d9947dc}
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\plgwrrbw.default\extensions\{c348ed13-eeb8-40f1-a387-32843d9947dc}\chrome\xulcache.jar
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\plgwrrbw.default\extensions\{c348ed13-eeb8-40f1-a387-32843d9947dc}\defaults\preferences\xulcache.js
c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\plgwrrbw.default\extensions\{c348ed13-eeb8-40f1-a387-32843d9947dc}\install.rdf
c:\windows\$NtUninstallKB17967$\1314785393\@
c:\windows\$NtUninstallKB17967$\1314785393\bckfg.tmp
c:\windows\$NtUninstallKB17967$\1314785393\cfg.ini
c:\windows\$NtUninstallKB17967$\1314785393\Desktop.ini
c:\windows\$NtUninstallKB17967$\1314785393\keywords
c:\windows\$NtUninstallKB17967$\1314785393\kwrd.dll
c:\windows\$NtUninstallKB17967$\1314785393\L\oiegfygl
c:\windows\$NtUninstallKB17967$\1314785393\lsflt7.ver
c:\windows\$NtUninstallKB17967$\1314785393\U\00000001.@
c:\windows\$NtUninstallKB17967$\1314785393\U\00000002.@
c:\windows\$NtUninstallKB17967$\1314785393\U\00000004.@
c:\windows\$NtUninstallKB17967$\1314785393\U\80000000.@
c:\windows\$NtUninstallKB17967$\1314785393\U\80000004.@
c:\windows\$NtUninstallKB17967$\1314785393\U\80000032.@
c:\windows\$NtUninstallKB17967$\2890381209
c:\windows\system32\sysprep.exe
c:\windows\$NtUninstallKB17967$ . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-30 )))))))))))))))))))))))))))))))
.
.
2011-11-30 00:03 . 2011-11-30 00:03 ——– d—–w- c:\program files\WinASO
2011-11-29 23:57 . 2011-11-29 23:57 ——– d—–w- C:\ubuntu
2011-11-29 23:53 . 2011-11-29 23:53 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\FUJIFILM
2011-11-29 23:35 . 2011-11-29 23:35 ——– d—–w- c:\windows\system32\wbem\Repository
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2010-04-23 22:48 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2008-04-14 10:41 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 17:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 17:41 . 2004-08-04 07:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 17:41 . 2004-08-04 07:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 18:47 . 2010-04-24 19:07 29712 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2011-09-06 13:20 . 2008-04-14 06:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-10-24 23:44 . 2011-03-23 23:32 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-03-18 2471240]
.
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-03-18 13:11 2471240 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-03-18 2471240]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2011-03-18 2471240]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2009-09-29 210216]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-05-31 323976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"RTHDCPL"="RTHDCPL.EXE" [2010-07-28 19557480]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2009-04-16 91432]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-23 144920]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2009-04-16 50472]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-23 174104]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2009-06-04 103720]
"AVG9_TRAY"="c:\program files\AVG\AVG9\avgtray.exe" [2011-10-24 2078048]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
D-Link AirPlus G Configuration Utility.lnk - c:\program files\D-Link AirPlus G\AirPlus.exe [2010-4-26 294912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-15 15:41 12536 —-a-w- c:\windows\system32\avgrsstx.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\TurboTax\\Deluxe 2010\\Installer\\TurboTax 2010 Installer.exe"=
"c:\\Program Files\\TurboTax\\Deluxe 2010\\32bit\\TurboTax.exe"=
.
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/24/2010 12:07 PM 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/24/2010 12:07 PM 243152]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [7/15/2010 8:41 AM 921952]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [7/15/2010 8:41 AM 308136]
R2 REFILERW;REFILERW;c:\windows\system32\drivers\REFILERW.SYS [2/12/2011 1:34 PM 4224]
R2 RtNdPt5x;Realtek NDIS Protocol Driver;c:\windows\system32\drivers\RtNdPt5x.sys [1/2/2011 10:52 AM 22016]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [4/23/2010 4:16 PM 116224]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/23/2010 4:14 PM 1691480]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [10/26/2010 7:37 AM 947528]
S3 RTLTEAMING;Realtek Intermediate Driver for Ethernet Extended Features;c:\windows\system32\drivers\RTLTEAMING.SYS [1/2/2011 10:52 AM 29440]
S3 RTLVLAN;Realtek VLAN Intermediate Driver;c:\windows\system32\drivers\RTLVLAN.SYS [1/2/2011 10:52 AM 17536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
2009-03-08 10:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 192.168.0.1 [removed]
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\plgwrrbw.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 61192
FF - prefs.js: network.proxy.type - 4
.
.
——- File Associations ——-
.
vbefile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
vbsfile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
jsefile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Live 8.0.1 - i:\progra~1\ABLETON\LIVE80~1.1\INSTALL\UNWISE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-29 19:33
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2796)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\RTHDCPL.EXE
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-11-29 19:36:05 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-30 02:36
.
Pre-Run: 301,148,610,560 bytes free
Post-Run: 302,765,936,640 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 40B528F24685E6D32BFE49A6A173DADD