Alright…
CF Log:
ComboFix 08-12-21.01 - zarbuchan 2008-12-21 13:23:11.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2045.1519 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\zarbuchan\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\CombuttFix
c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
c:\windows\NV54325456.TMP
.
/wow section - STAGE 32A
The process cannot access the file because it is being used by another process.
((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 )))))))))))))))))))))))))))))))
.
2008-12-17 13:25 . 2008-12-17 13:25 0 –a—— C:\backup.reg
2008-12-14 23:26 . 2008-12-14 23:26 d——– c:\program files\COMODO
2008-12-14 23:26 . 2008-12-15 00:08 d——– c:\documents and settings\All Users\Application Data\comodo
2008-12-14 23:26 . 2008-12-14 23:26 147,192 –a—— c:\windows\system32\guard32.dll
2008-12-14 23:26 . 2008-12-14 23:26 101,776 –a—— c:\windows\system32\drivers\cmdguard.sys
2008-12-14 23:26 . 2008-12-14 23:26 31,504 –a—— c:\windows\system32\drivers\cmdhlp.sys
2008-12-14 23:23 . 2008-12-14 23:25 d——– c:\program files\SpywareGuard
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\program files\SUPERAntiSpyware
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\documents and settings\zarbuchan\Application Data\SUPERAntiSpyware.com
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-14 23:04 . 2008-12-14 23:05 d——– c:\program files\SpywareBlaster
2008-12-14 23:04 . 2008-12-17 13:30 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-14 00:56 . 2008-12-14 22:49 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-13 22:53 . 2008-12-13 22:53 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2008-12-13 22:07 . 2008-12-13 23:18 d——– c:\program files\Malwarebytes' Anti-Malwareddd
2008-12-13 22:07 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-13 22:07 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-13 20:38 . 2008-12-18 20:02 18,944 –ahs—- c:\windows\system32\Thumbs.db
2008-12-12 10:22 . 2008-12-12 10:22 d——– C:\rsit
2008-12-11 16:34 . 2008-12-11 16:35 d——– c:\program files\iTunes
2008-12-11 16:34 . 2008-12-11 16:34 d——– c:\program files\iPod
2008-12-11 16:34 . 2008-12-11 16:34 d——– c:\program files\Bonjour
2008-12-11 16:34 . 2008-12-11 16:35 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-11 16:33 . 2008-12-11 16:33 d——– c:\program files\QuickTime
2008-12-10 21:24 . 2007-12-08 14:48 d——– C:\msinst
2008-12-07 22:05 . 2008-12-07 22:35 d——– c:\windows\system32\Adobe
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\documents and settings\zarbuchan\Application Data\Malwarebytes
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-07 02:00 . 2008-12-07 02:00 d——– c:\program files\ERUNT
2008-12-07 01:55 . 2008-12-07 01:55 d——– c:\program files\Trend Micro
2008-12-07 00:34 . 2008-12-11 18:36 d——– c:\program files\Spybot - Search & Destroy
2008-12-07 00:34 . 2008-12-11 18:36 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-07 00:06 . 2004-08-10 04:00 169,984 –a—— c:\windows\system32\dllcache\iisui.dll
2008-12-07 00:06 . 2004-08-10 04:00 94,720 –a—— c:\windows\system32\dllcache\certmap.ocx
2008-12-07 00:06 . 2001-08-17 14:56 66,048 –a—— c:\windows\system32\dllcache\s3legacy.dll
2008-12-07 00:06 . 2004-08-10 04:00 19,968 –a—— c:\windows\system32\dllcache\inetsloc.dll
2008-12-07 00:06 . 2004-08-10 04:00 14,336 –a—— c:\windows\system32\dllcache\iisreset.exe
2008-12-07 00:06 . 2004-08-10 04:00 7,680 –a—— c:\windows\system32\dllcache\inetmgr.exe
2008-12-07 00:06 . 2004-08-10 04:00 7,168 –a—— c:\windows\system32\dllcache\wamregps.dll
2008-12-07 00:06 . 2004-08-10 04:00 6,144 –a—— c:\windows\system32\dllcache\ftpsapi2.dll
2008-12-07 00:06 . 2004-08-10 04:00 5,632 –a—— c:\windows\system32\dllcache\iisrstap.dll
2008-12-06 22:58 . 2008-12-06 22:58 d——– c:\program files\Alwil Software
2008-12-06 20:32 . 2008-12-06 20:32 d——– c:\program files\Lavasoft
2008-12-06 20:32 . 2008-12-11 18:51 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-29 00:57 . 2008-11-29 00:57 d——– c:\windows\system32\AGEIA
2008-11-29 00:56 . 2008-11-29 00:56 d——– c:\windows\nview
2008-11-29 00:56 . 2008-11-13 16:20 203,540 –a—— c:\windows\system32\nvapps.nvb
2008-11-29 00:55 . 2008-11-12 13:45 453,152 –a—— c:\windows\system32\NVUNINST.EXE
2008-11-29 00:51 . 2008-11-12 14:54 453,152 –a—— c:\windows\system32\nvudisp.exe
2008-11-29 00:51 . 2008-12-21 13:26 194,311 –a—— c:\windows\system32\nvapps.xml
2008-11-29 00:51 . 2008-11-12 14:54 18,537 –a—— c:\windows\system32\nvdisp.nvu
2008-11-29 00:49 . 2008-11-29 00:49 664 –a—— c:\windows\system32\d3d9caps.dat
2008-11-28 17:41 . 2008-11-28 17:45 d——– c:\windows\NV54325456.TMP
2008-11-28 17:04 . 2008-11-29 00:57 d——– c:\program files\AGEIA Technologies
2008-11-21 11:29 . 2008-11-21 11:29 d——– c:\program files\Chromium
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 19:19 ——— d—–w c:\program files\mIRC
2008-12-21 19:19 ——— d—–w c:\documents and settings\zarbuchan\Application Data\Skype
2008-12-21 19:14 ——— d—–w c:\documents and settings\zarbuchan\Application Data\skypePM
2008-12-16 21:14 ——— d—–w c:\program files\World of Warcraft
2008-12-15 17:59 ——— d—–w c:\program files\City of Heroes
2008-12-15 05:06 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-11 22:34 ——— d—–w c:\program files\Common Files\Apple
2008-12-07 07:12 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2008-12-07 06:03 ——— d—–w c:\documents and settings\LocalService\Application Data\SACore
2008-12-05 05:57 36,928 —-a-w c:\windows\system32\drivers\pssdk41.sys
2008-11-23 23:22 ——— d—–w c:\program files\XLink Kai
2008-11-15 04:47 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-13 06:28 ——— d—–w c:\program files\AIM
2008-11-12 20:54 6,188,320 —-a-w c:\windows\system32\drivers\nv4_mini.sys
2008-11-12 01:32 ——— d—–w c:\program files\Activision
2008-11-11 21:40 ——— d—–w c:\documents and settings\zarbuchan\Application Data\uTorrent
2008-11-11 17:48 ——— d—–w c:\program files\FLV Player
2008-11-07 22:36 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2008-11-07 17:05 ——— d—–w c:\program files\Common Files\Blizzard Entertainment
2008-10-31 02:28 22,328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-31 02:28 22,328 —-a-w c:\documents and settings\zarbuchan\Application Data\PnkBstrK.sys
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 14:25 ——— d—–w c:\program files\Apple Software Update
2004-03-15 22:51 114,688 —-a-w c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 15:32 131,072 —-a-w c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 15:48 133,920 —-a-w c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
2007-07-24 23:03 118,784 —-a-w c:\program files\internet explorer\plugins\LV85ActiveXControl.dll
2008-06-26 03:51 118,784 —-a-w c:\program files\internet explorer\plugins\LV86ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 122880]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2008-12-14 1797880]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
c:\documents and settings\zarbuchan\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\National Instruments\\Shared\\mDNS Responder\\nimdnsResponder.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\system32\drivers\nipbcfk.sys [2007-07-10 15448]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-14 111184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-12-14 101776]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-12-14 31504]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-14 20560]
R2 ni488enumsvc;NI-488.2 Enumeration Service;c:\windows\system32\nipalsm.exe [2007-02-16 12696]
R2 nidevldu;NI Device Loader;c:\windows\system32\nipalsm.exe [2007-02-16 12696]
R2 niLXIDiscovery;National Instruments LXI Discovery Service;"c:\program files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe" [2008-06-20 129144]
R2 nimDNSResponder;National Instruments mDNS Responder Service;"c:\program files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe" [2008-06-18 192112]
R2 nipxirmk;nipxirmk;\??\c:\windows\system32\drivers\nipxirmkl.sys [2007-09-18 11552]
R2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2008-06-20 11360]
R3 nidimk;nidimk;\??\c:\windows\system32\drivers\nidimkl.sys [2008-06-13 11360]
R3 nimru2k;nimru2k;\??\c:\windows\system32\drivers\nimru2kl.sys [2008-06-13 11360]
R3 nimstsk;nimstsk;\??\c:\windows\system32\drivers\nimstskl.sys [2007-12-18 11360]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys []
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe []
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe []
S2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys []
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;"c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe" [2008-08-31 79360]
S3 lvalarmk;lvalarmk;\??\c:\windows\system32\drivers\lvalarmk.sys [2007-12-20 20056]
S3 ni1006k;NI PXI-1006 Chassis Pilot;\??\c:\windows\system32\drivers\ni1006k.sys [2007-10-08 25888]
S3 ni1045k;NI PXI-1045 Chassis Pilot;\??\c:\windows\system32\drivers\ni1045kl.sys [2007-10-08 11552]
S3 ni1065k;NI PXIe-1065 Chassis Pilot;\??\c:\windows\system32\drivers\ni1065k.sys [2007-10-08 22360]
S3 ni488lock;NI-488.2 Locking Service;\??\c:\windows\system32\drivers\ni488lock.sys [2007-02-26 16672]
S3 nicdrk;nicdrk;\??\c:\windows\system32\drivers\nicdrkl.sys [2007-12-26 11352]
S3 nicsrk;nicsrk;\??\c:\windows\system32\drivers\nicsrkl.sys [2008-02-22 11336]
S3 nidmxfk;nidmxfk;\??\c:\windows\system32\drivers\nidmxfkl.sys [2007-12-18 11336]
S3 nidsark;nidsark;\??\c:\windows\system32\drivers\nidsarkl.sys [2008-02-29 11344]
S3 niemrk;niemrk;\??\c:\windows\system32\drivers\niemrkl.sys [2008-02-22 11336]
S3 niesrk;niesrk;\??\c:\windows\system32\drivers\niesrkl.sys [2008-02-22 11336]
S3 nifslk;nifslk;\??\c:\windows\system32\drivers\nifslkl.sys [2007-12-26 11352]
S3 nimsdrk;nimsdrk;\??\c:\windows\system32\drivers\nimsdrkl.sys [2008-01-11 11392]
S3 nimslk;nimslk;\??\c:\windows\system32\drivers\nimslk.dll [2007-06-24 14464]
S3 nimsrlk;nimsrlk;\??\c:\windows\system32\drivers\nimsrlk.dll [2007-06-24 151683]
S3 nimxpk;nimxpk;\??\c:\windows\system32\drivers\nimxpkl.sys [2007-12-18 11368]
S3 ninshsdk;ninshsdk;\??\c:\windows\system32\drivers\ninshsdkl.sys [2007-12-27 11360]
S3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [2008-06-13 11904]
S3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [2008-06-13 11896]
S3 nipxigpk;NI PXI Generic Chassis Pilot;\??\c:\windows\system32\drivers\nipxigpk.sys [2007-11-26 20768]
S3 niscdk;niscdk;\??\c:\windows\system32\drivers\niscdkl.sys [2008-01-07 11376]
S3 nisdigk;nisdigk;\??\c:\windows\system32\drivers\nisdigkl.sys [2008-01-07 11352]
S3 nisftk;nisftk;\??\c:\windows\system32\drivers\nisftkl.sys [2007-12-20 11344]
S3 nispdk;nispdk;\??\c:\windows\system32\drivers\nispdkl.sys [2008-01-07 11376]
S3 nissrk;nissrk;\??\c:\windows\system32\drivers\nissrkl.sys [2008-02-22 11336]
S3 nistc2k;nistc2k;\??\c:\windows\system32\drivers\nistc2kl.sys [2008-01-07 11312]
S3 nistcrk;nistcrk;\??\c:\windows\system32\drivers\nistcrkl.sys [2008-02-14 11360]
S3 niswdk;niswdk;\??\c:\windows\system32\drivers\niswdkl.sys [2008-01-02 11336]
S3 nitiork;nitiork;\??\c:\windows\system32\drivers\nitiorkl.sys [2008-02-19 11360]
S3 niufurk;niufurk;\??\c:\windows\system32\drivers\niufurkl.sys [2008-02-22 11368]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2008-06-20 11384]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2008-06-20 11360]
S3 niwfrk;niwfrk;\??\c:\windows\system32\drivers\niwfrkl.sys [2008-02-22 11336]
S3 nixsrk;nixsrk;\??\c:\windows\system32\drivers\nixsrkl.sys [2008-02-22 11336]
S3 PsSdk41;PsSdk41;\??\c:\windows\system32\Drivers\pssdk41.sys [2008-09-11 36928]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys []
S3 usb6xxxk;usb6xxxk;\??\c:\windows\system32\drivers\usb6xxxkl.sys []
S3 ZD1211BU(SMC);802.11g Wireless USB2.0 Adapter Driver(SMC);c:\windows\system32\DRIVERS\zd1211Bu.sys [2006-08-24 477696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - d:\setup\rsrc\Autorun.exe
\Shell\dinstall\command - d:\directx\dxsetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {6637E906-5A9B-4FFF-900E-1254039BBAB8} = 68.113.206.10,66.196.221.10
FF - ProfilePath - c:\documents and settings\zarbuchan\Application Data\Mozilla\Firefox\Profiles\dpyo2cei.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplv85win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplv86win32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-21 13:26:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(748)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\windows\system32\CTxfispi.exe
c:\program files\National Instruments\MAX\nimxs.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\windows\system32\nisvcloc.exe
c:\program files\National Instruments\Shared\Tagger\tagsrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-12-21 13:29:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-21 19:29:29
ComboFix2.txt 2008-12-19 16:48:46
Pre-Run: 122,663,297,024 bytes free
Post-Run: 122,642,333,696 bytes free
278 — E O F — 2008-12-19 01:57:24
Kaspersky log:
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, December 22, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, December 22, 2008 14:17:26
Records in database: 1500464
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 99730
Threat name: 2
Infected objects: 3
Suspicious objects: 0
Duration of the scan: 01:55:28
File name / Threat name / Threats count
C:\Program Files\mIRC\mirc.exe/C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1
C:\Documents and Settings\zarbuchan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5286af48-2e92c776.zip Infected: Exploit.Java.Gimsh.a 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1
The selected area was scanned.
HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:04:31 PM, on 12/22/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4071012
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\national instruments\shared\mdns responder\nimdnsnsp.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1214061259171
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6637E906-5A9B-4FFF-900E-1254039BBAB8}: NameServer = 68.113.206.10,66.196.221.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: NI-488.2 Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: National Instruments LXI Discovery Service (niLXIDiscovery) - National Instruments Corporation - C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
O23 - Service: National Instruments mDNS Responder Service (nimDNSResponder) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
O23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corporation - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
–
End of file - 10133 bytes