Iwall
Lately, Firefox has been running slower than usual. Here's the newest ComboFix log:
ComboFix 09-02-06.04 - Ian 2009-02-07 21:15:16.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2046.946 [GMT -5:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Ian\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\LHTC12F.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\LHTC12F.tmp
c:\program files\Bonjour
c:\program files\Bonjour\About Bonjour.rtf
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.html
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\programdata\Symantec
c:\programdata\Symantec\Definitions\SymcData\idsdefs\lulock.dat
c:\programdata\Symantec\Definitions\VirusDefs\lulock.dat
c:\programdata\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
c:\programdata\Symantec\LiveUpdate\Settings.LiveUpdate
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}.qbi
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{9081E184-3805-41A7-9CA0-0FFB247C388E}.qbd
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{9081E184-3805-41A7-9CA0-0FFB247C388E}.qbi
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{CE3798B1-4EDE-4366-930F-16845DF9901E}.qbd
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{CE3798B1-4EDE-4366-930F-16845DF9901E}.qbi
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{E8694A6E-42F4-4607-9573-0A5E68F10A6C}.qbd
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{E8694A6E-42F4-4607-9573-0A5E68F10A6C}.qbi
c:\programdata\Symantec\wcid0.log
c:\windows\system32\acovcnt.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-08 to 2009-02-08 )))))))))))))))))))))))))))))))
.
2009-02-07 12:47 . 2009-02-07 21:13 d–h—– C:\$AVG8.VAULT$
2009-02-06 23:46 . 2009-02-07 14:29 d——– c:\windows\System32\drivers\Avg
2009-02-06 23:46 . 2009-02-06 23:46 d——– c:\programdata\avg8
2009-02-06 23:46 . 2009-02-06 23:46 325,128 –a—— c:\windows\System32\drivers\avgldx86.sys
2009-02-06 23:46 . 2009-02-06 23:46 107,272 –a—— c:\windows\System32\drivers\avgtdix.sys
2009-02-06 23:46 . 2009-02-06 23:46 10,520 –a—— c:\windows\System32\avgrsstx.dll
2009-02-05 22:09 . 2009-02-05 22:09 d——– c:\users\Ian\AppData\Roaming\Malwarebytes
2009-02-05 22:09 . 2009-02-05 22:09 d——– c:\programdata\Malwarebytes
2009-02-05 22:09 . 2009-02-05 22:09 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-05 22:09 . 2009-01-14 16:11 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-05 22:09 . 2009-01-14 16:11 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-02-04 11:29 . 2009-02-04 11:28 410,984 –a—— c:\windows\System32\deploytk.dll
2009-02-01 12:39 . 2009-02-01 12:40 d——– c:\program files\ERUNT
2009-02-01 12:35 . 2009-02-01 12:35 d——– c:\program files\Trend Micro
2009-02-01 11:19 . 2009-02-01 11:19 d——– c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-01 11:19 . 2009-02-01 11:19 d——– c:\program files\iTunes
2009-02-01 11:19 . 2009-02-01 11:19 d——– c:\program files\iPod
2009-02-01 11:15 . 2009-02-01 11:16 d——– c:\program files\QuickTime
2009-01-13 13:31 . 2008-12-15 21:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-12 18:24 . 2009-01-12 18:24 d——– c:\users\Ian\AppData\Roaming\Final Draft
2009-01-12 18:23 . 2009-01-12 18:24 d——– c:\programdata\Final Draft
2009-01-12 18:23 . 2009-01-12 18:23 d——– c:\program files\Final Draft Tagger
2009-01-12 18:23 . 2009-01-12 18:23 d——– c:\program files\Final Draft 7
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 16:28 ——— d—–w c:\program files\Java
2009-02-01 20:03 27,145 —-a-w c:\users\Ian\AppData\Roaming\nvModes.dat
2009-02-01 16:19 ——— d—–w c:\program files\Common Files\Apple
2009-01-27 03:43 ——— d—–w c:\users\Ian\AppData\Roaming\U3
2009-01-14 08:04 ——— d—–w c:\program files\Windows Mail
2009-01-12 23:22 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-01-08 00:05 ——— d—–w c:\program files\AVG
2008-06-06 16:11 174 –sha-w c:\program files\desktop.ini
2008-02-01 21:31 22,328 —-a-w c:\users\Ian\AppData\Roaming\PnkBstrK.sys
2007-09-28 16:23 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-28 16:23 32,768 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-28 16:23 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2006-09-18 21:43 10 –sha-w c:\windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6000.16386_none_fbd6b71e75a2c6c8\config.sys
2006-09-18 21:43 10 –sha-w c:\windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\config.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-02-07_ 9.33.22.55 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-07 04:47:00 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-08 02:23:12 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-02-07 14:32:32 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-08 02:23:12 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-08 02:23:12 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2007-01-23 11:12:57 516,832 —-a-w c:\windows\System32\capicom.dll
+ 2007-09-12 23:27:24 511,328 —-a-w c:\windows\System32\capicom.dll
- 2009-02-07 14:27:12 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-02-08 02:14:39 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2009-02-07 01:00:33 13,186 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-704585500-2511578236-835495662-1000_UserData.bin
+ 2009-02-08 02:24:38 13,484 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-704585500-2511578236-835495662-1000_UserData.bin
- 2009-02-07 01:00:33 129,814 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-08 02:24:36 129,920 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-02-07 01:00:30 53,358 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-08 02:24:29 53,660 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [2007-09-07 43008]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-09-18 171464]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-02-25 677408]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2007-05-14 33136]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2007-05-14 37232]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-04 136600]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-10-03 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-03 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-03 81920]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-06 1601304]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 c:\windows\RtHDVCpl.exe]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2C7286D0-A849-43E0-A2AF-540FB910B976}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{DBAB0557-1B0E-4808-B869-8483890DCD18}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{40373EE2-652C-45F2-A812-4E27A0E1BE2C}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{436224B1-B386-48A3-8CC5-775B646F572F}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{236B5FD7-C053-4349-A47C-3C51BE3FC324}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{850DAC95-E51A-4796-AA20-1885A6517BD0}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{51045A2F-325F-45EB-AA5F-4E7C9E142324}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{0E69635A-D23A-4C29-A302-CA76FF8E6979}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{40B6FE4A-9C6E-445F-80F1-FED491819088}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{DC31E839-517C-4CF6-A5EC-3B2E0197634F}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{06C0E4F7-1CE9-42CE-947F-5546C3503FB9}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{01E42116-132C-4C3B-8210-01E61C629BD4}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{85BBDF9B-03ED-4F2A-A1E6-6651B4F01A2E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D54B81C7-B73C-4425-B897-625D75A1696B}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{4519EA19-3C0C-4935-A77D-5A56689520F2}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{7930A450-897F-4F80-9677-2D5BF20F1442}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{897AEA56-EDA8-4FB8-BAE4-07C7F50727D5}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{05C723D8-2FF6-4737-AB15-19B2B973C02E}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{1D153665-0FF6-4459-A02A-FB606EF9E6D3}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{E32E67A2-F747-47B4-8055-1877B0E373E1}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{E708E0CC-648E-4F64-94B5-BB08E8EB9233}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{2B77894B-6D04-4A8F-BD73-AAB61CED106F}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{213DDDBF-2BAB-44BA-946A-0026D2B32703}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B8D2A98F-E12B-4350-8744-7F28E7F53046}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E39FB138-1EA5-4D17-AF65-F7390EF7D256}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6DEA027A-52AD-4575-8E9A-767ED94E1298}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{149131E6-4693-4F6D-922E-48EDB9758A9C}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{70BC65DB-670E-4C4D-A2F6-F35A6F273B26}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"{D8FF01AF-0B95-43BE-9035-18ABA71E2D4B}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{13B2B98E-6A10-4019-97CB-19D09A2B9B19}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2009-02-06 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2009-02-06 107272]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\System32\drivers\psd.sys [2007-01-23 39080]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\atl01v32.sys [2007-03-15 48128]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\System32\drivers\StkCMini.sys [2007-02-12 1245056]
S3 MusCDriverV32;MusCDriverV32;c:\windows\System32\drivers\MusCDriverV32.sys [2007-07-25 22528]
— Other Services/Drivers In Memory —
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6af3fcb-fff3-11dc-9d1f-001bfc3faa23}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-02-07 c:\windows\Tasks\Security Platform Backup Schedule.job
- c:\program files\Infineon\Security Platform Software\SpBackupWz.exe [2007-02-22 09:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.daemonsearch.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Ian\AppData\Roaming\Mozilla\Firefox\Profiles\ph7i4ta3.default\
FF - prefs.js: browser.startup.homepage - www.emerson.edu
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-07 21:23:17
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(800)
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\windows\System32\wlanext.exe
c:\program files\ATK Hotkey\HControl.exe
c:\program files\ATKOSD2\ATKOSD2.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\program files\P4G\BatteryLife.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\windows\System32\IFXTCS.exe
c:\windows\System32\IfxPsdSv.exe
c:\windows\System32\PnkBstrA.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\System32\StkCSrv.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\windows\System32\IfxUAGUI.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Infineon\Security Platform Software\PSDrt.exe
c:\program files\Infineon\Security Platform Software\SpTNA.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-02-07 21:30:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-08 02:29:54
ComboFix2.txt 2009-02-07 14:35:11
Pre-Run: 5,609,750,528 bytes free
Post-Run: 5,895,184,384 bytes free
258 — E O F — 2009-02-06 01:33:37
And the new HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:39:03 PM, on 02/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
C:\Program Files\Infineon\Security Platform Software\SpTna.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\ifxspmgt.exe /NotifyLogon
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O13 - Gopher Prefix:
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
–
End of file - 8199 bytes
ComboFix 09-02-06.04 - Ian 2009-02-07 21:15:16.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2046.946 [GMT -5:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
Command switches used :: c:\users\Ian\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\LHTC12F.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\LHTC12F.tmp
c:\program files\Bonjour
c:\program files\Bonjour\About Bonjour.rtf
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\ez_log.html
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\programdata\Symantec
c:\programdata\Symantec\Definitions\SymcData\idsdefs\lulock.dat
c:\programdata\Symantec\Definitions\VirusDefs\lulock.dat
c:\programdata\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
c:\programdata\Symantec\LiveUpdate\Settings.LiveUpdate
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}.qbi
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{9081E184-3805-41A7-9CA0-0FFB247C388E}.qbd
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{9081E184-3805-41A7-9CA0-0FFB247C388E}.qbi
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{CE3798B1-4EDE-4366-930F-16845DF9901E}.qbd
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{CE3798B1-4EDE-4366-930F-16845DF9901E}.qbi
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{E8694A6E-42F4-4607-9573-0A5E68F10A6C}.qbd
c:\programdata\Symantec\Shared\QBackup\{2C167C99-9833-464C-9F6D-A27DC970535F}\{E8694A6E-42F4-4607-9573-0A5E68F10A6C}.qbi
c:\programdata\Symantec\wcid0.log
c:\windows\system32\acovcnt.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-08 to 2009-02-08 )))))))))))))))))))))))))))))))
.
2009-02-07 12:47 . 2009-02-07 21:13 d–h—– C:\$AVG8.VAULT$
2009-02-06 23:46 . 2009-02-07 14:29 d——– c:\windows\System32\drivers\Avg
2009-02-06 23:46 . 2009-02-06 23:46 d——– c:\programdata\avg8
2009-02-06 23:46 . 2009-02-06 23:46 325,128 –a—— c:\windows\System32\drivers\avgldx86.sys
2009-02-06 23:46 . 2009-02-06 23:46 107,272 –a—— c:\windows\System32\drivers\avgtdix.sys
2009-02-06 23:46 . 2009-02-06 23:46 10,520 –a—— c:\windows\System32\avgrsstx.dll
2009-02-05 22:09 . 2009-02-05 22:09 d——– c:\users\Ian\AppData\Roaming\Malwarebytes
2009-02-05 22:09 . 2009-02-05 22:09 d——– c:\programdata\Malwarebytes
2009-02-05 22:09 . 2009-02-05 22:09 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-05 22:09 . 2009-01-14 16:11 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-05 22:09 . 2009-01-14 16:11 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-02-04 11:29 . 2009-02-04 11:28 410,984 –a—— c:\windows\System32\deploytk.dll
2009-02-01 12:39 . 2009-02-01 12:40 d——– c:\program files\ERUNT
2009-02-01 12:35 . 2009-02-01 12:35 d——– c:\program files\Trend Micro
2009-02-01 11:19 . 2009-02-01 11:19 d——– c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-01 11:19 . 2009-02-01 11:19 d——– c:\program files\iTunes
2009-02-01 11:19 . 2009-02-01 11:19 d——– c:\program files\iPod
2009-02-01 11:15 . 2009-02-01 11:16 d——– c:\program files\QuickTime
2009-01-13 13:31 . 2008-12-15 21:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-12 18:24 . 2009-01-12 18:24 d——– c:\users\Ian\AppData\Roaming\Final Draft
2009-01-12 18:23 . 2009-01-12 18:24 d——– c:\programdata\Final Draft
2009-01-12 18:23 . 2009-01-12 18:23 d——– c:\program files\Final Draft Tagger
2009-01-12 18:23 . 2009-01-12 18:23 d——– c:\program files\Final Draft 7
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 16:28 ——— d—–w c:\program files\Java
2009-02-01 20:03 27,145 —-a-w c:\users\Ian\AppData\Roaming\nvModes.dat
2009-02-01 16:19 ——— d—–w c:\program files\Common Files\Apple
2009-01-27 03:43 ——— d—–w c:\users\Ian\AppData\Roaming\U3
2009-01-14 08:04 ——— d—–w c:\program files\Windows Mail
2009-01-12 23:22 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-01-08 00:05 ——— d—–w c:\program files\AVG
2008-06-06 16:11 174 –sha-w c:\program files\desktop.ini
2008-02-01 21:31 22,328 —-a-w c:\users\Ian\AppData\Roaming\PnkBstrK.sys
2007-09-28 16:23 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-28 16:23 32,768 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-28 16:23 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2006-09-18 21:43 10 –sha-w c:\windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6000.16386_none_fbd6b71e75a2c6c8\config.sys
2006-09-18 21:43 10 –sha-w c:\windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\config.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-02-07_ 9.33.22.55 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-07 04:47:00 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-02-08 02:23:12 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-02-07 14:32:32 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-08 02:23:12 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-02-08 02:23:12 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2007-01-23 11:12:57 516,832 —-a-w c:\windows\System32\capicom.dll
+ 2007-09-12 23:27:24 511,328 —-a-w c:\windows\System32\capicom.dll
- 2009-02-07 14:27:12 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-02-08 02:14:39 262,144 —-a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2009-02-07 01:00:33 13,186 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-704585500-2511578236-835495662-1000_UserData.bin
+ 2009-02-08 02:24:38 13,484 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-704585500-2511578236-835495662-1000_UserData.bin
- 2009-02-07 01:00:33 129,814 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-08 02:24:36 129,920 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-02-07 01:00:30 53,358 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-08 02:24:29 53,660 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [2007-09-07 43008]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-09-18 171464]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648]
"IFXSPMGT"="c:\windows\system32\ifxspmgt.exe" [2007-02-25 677408]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2007-05-14 33136]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2007-05-14 37232]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-04 136600]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-10-03 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-03 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-03 81920]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-06 1601304]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 c:\windows\RtHDVCpl.exe]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2C7286D0-A849-43E0-A2AF-540FB910B976}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{DBAB0557-1B0E-4808-B869-8483890DCD18}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{40373EE2-652C-45F2-A812-4E27A0E1BE2C}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{436224B1-B386-48A3-8CC5-775B646F572F}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{236B5FD7-C053-4349-A47C-3C51BE3FC324}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{850DAC95-E51A-4796-AA20-1885A6517BD0}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{51045A2F-325F-45EB-AA5F-4E7C9E142324}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{0E69635A-D23A-4C29-A302-CA76FF8E6979}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{40B6FE4A-9C6E-445F-80F1-FED491819088}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{DC31E839-517C-4CF6-A5EC-3B2E0197634F}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{06C0E4F7-1CE9-42CE-947F-5546C3503FB9}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{01E42116-132C-4C3B-8210-01E61C629BD4}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{85BBDF9B-03ED-4F2A-A1E6-6651B4F01A2E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D54B81C7-B73C-4425-B897-625D75A1696B}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{4519EA19-3C0C-4935-A77D-5A56689520F2}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{7930A450-897F-4F80-9677-2D5BF20F1442}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{897AEA56-EDA8-4FB8-BAE4-07C7F50727D5}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{05C723D8-2FF6-4737-AB15-19B2B973C02E}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{1D153665-0FF6-4459-A02A-FB606EF9E6D3}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{E32E67A2-F747-47B4-8055-1877B0E373E1}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{E708E0CC-648E-4F64-94B5-BB08E8EB9233}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{2B77894B-6D04-4A8F-BD73-AAB61CED106F}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{213DDDBF-2BAB-44BA-946A-0026D2B32703}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B8D2A98F-E12B-4350-8744-7F28E7F53046}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E39FB138-1EA5-4D17-AF65-F7390EF7D256}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6DEA027A-52AD-4575-8E9A-767ED94E1298}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{149131E6-4693-4F6D-922E-48EDB9758A9C}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{70BC65DB-670E-4C4D-A2F6-F35A6F273B26}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"{D8FF01AF-0B95-43BE-9035-18ABA71E2D4B}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{13B2B98E-6A10-4019-97CB-19D09A2B9B19}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2009-02-06 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2009-02-06 107272]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\System32\drivers\psd.sys [2007-01-23 39080]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\atl01v32.sys [2007-03-15 48128]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:\windows\System32\drivers\StkCMini.sys [2007-02-12 1245056]
S3 MusCDriverV32;MusCDriverV32;c:\windows\System32\drivers\MusCDriverV32.sys [2007-07-25 22528]
— Other Services/Drivers In Memory —
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6af3fcb-fff3-11dc-9d1f-001bfc3faa23}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-02-07 c:\windows\Tasks\Security Platform Backup Schedule.job
- c:\program files\Infineon\Security Platform Software\SpBackupWz.exe [2007-02-22 09:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.daemonsearch.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Ian\AppData\Roaming\Mozilla\Firefox\Profiles\ph7i4ta3.default\
FF - prefs.js: browser.startup.homepage - www.emerson.edu
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-07 21:23:17
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(800)
c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\program files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
c:\program files\ATK Hotkey\ASLDRSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\windows\System32\wlanext.exe
c:\program files\ATK Hotkey\HControl.exe
c:\program files\ATKOSD2\ATKOSD2.exe
c:\program files\Wireless Console 2\wcourier.exe
c:\program files\ASUS\Splendid\ACMON.exe
c:\program files\P4G\BatteryLife.exe
c:\windows\System32\ACEngSvr.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\windows\System32\IFXTCS.exe
c:\windows\System32\IfxPsdSv.exe
c:\windows\System32\PnkBstrA.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\System32\StkCSrv.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\windows\System32\IfxUAGUI.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Infineon\Security Platform Software\PSDrt.exe
c:\program files\Infineon\Security Platform Software\SpTNA.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-02-07 21:30:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-08 02:29:54
ComboFix2.txt 2009-02-07 14:35:11
Pre-Run: 5,609,750,528 bytes free
Post-Run: 5,895,184,384 bytes free
258 — E O F — 2009-02-06 01:33:37
And the new HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:39:03 PM, on 02/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Infineon\Security Platform Software\PSDrt.exe
C:\Program Files\Infineon\Security Platform Software\SpTna.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\ifxspmgt.exe /NotifyLogon
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O13 - Gopher Prefix:
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\ifxspmgt.exe
O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\ifxtcs.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: Personal Secure Drive Service (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
–
End of file - 8199 bytes