ComboFix 09-09-25.01 - Tez 09/27/2009 13:03.1.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2559.2144 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1351 [VPS 090926-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Mimi\My Documents\ZbThumbnail.info c:\recycler\NPROTECT c:\windows\Installer\67f43.msi c:\windows\system32\drivers\fad.sys . ((((((((((((((((((((((((( Files Created from 2009-08-27 to 2009-09-27 ))))))))))))))))))))))))))))))) . 2009-09-27 15:02 . 2009-09-27 15:02 -------- d-----w- c:\program files\iPod 2009-09-27 15:02 . 2009-09-27 15:03 -------- d-----w- c:\program files\iTunes 2009-09-22 19:41 . 2009-09-22 19:46 -------- d-----w- C:\rsit 2009-09-22 19:01 . 2009-09-22 19:01 -------- d-----w- C:\_OTM 2009-09-20 00:40 . 2009-09-20 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-09-08 17:45 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-09-27 15:36 . 2008-12-17 02:03 -------- d-----w- c:\program files\Windows Live Safety Center 2009-09-27 15:33 . 2004-08-12 20:17 -------- d-----w- c:\program files\Java 2009-09-27 15:24 . 2004-09-08 16:43 -------- d-----w- c:\program files\Common Files\Adobe 2009-09-27 15:12 . 2004-08-12 20:25 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-09-27 15:02 . 2008-01-08 15:24 -------- d-----w- c:\program files\Common Files\Apple 2009-09-26 17:45 . 2007-07-09 17:32 -------- d-----w- c:\program files\Star Defender 4 2009-09-25 19:58 . 2007-04-18 20:55 -------- d-----w- c:\program files\Star Defender 3 2009-09-22 19:08 . 2006-01-01 22:14 -------- d-----w- c:\documents and settings\Tez\Application Data\Apple Computer 2009-09-20 00:38 . 2008-12-27 19:44 -------- d-----w- c:\program files\QuickTime 2009-09-16 01:13 . 2009-08-09 01:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-09-15 22:05 . 2009-06-28 01:58 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-09-10 18:54 . 2009-08-09 01:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 18:53 . 2009-08-09 01:10 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-08-31 12:24 . 2004-08-12 20:32 93200 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-08-24 17:59 . 2009-08-24 17:59 -------- d-----w- c:\program files\MSBuild 2009-08-24 17:59 . 2009-08-24 17:59 -------- d-----w- c:\program files\Reference Assemblies 2009-08-17 16:10 . 2009-06-27 22:07 1279456 ----a-w- c:\windows\system32\aswBoot.exe 2009-08-17 16:06 . 2009-06-27 22:07 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys 2009-08-17 16:06 . 2009-06-27 22:07 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2009-08-17 16:05 . 2009-06-27 22:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys 2009-08-17 16:05 . 2009-06-27 22:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2009-08-17 16:04 . 2009-06-27 22:07 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2009-08-17 16:04 . 2009-06-27 22:07 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2009-08-17 16:03 . 2009-06-27 22:07 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2009-08-17 16:02 . 2009-06-27 22:07 97480 ----a-w- c:\windows\system32\AvastSS.scr 2009-08-11 17:10 . 2009-06-28 01:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-08-11 00:37 . 2008-03-16 16:02 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-08-09 01:11 . 2009-08-09 01:11 -------- d-----w- c:\documents and settings\Tez\Application Data\Malwarebytes 2009-08-09 01:10 . 2009-08-09 01:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-08-05 09:01 . 2002-12-12 05:14 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-07-17 19:01 . 2004-03-19 22:33 58880 ----a-w- c:\windows\system32\atl.dll 2009-07-14 03:43 . 2005-08-11 20:02 286208 ----a-w- c:\windows\system32\wmpdxm.dll 2009-07-03 17:09 . 2004-12-07 21:37 915456 ----a-w- c:\windows\system32\wininet.dll 2009-06-30 12:08 . 2009-06-30 12:08 106 ----a-w- c:\documents and settings\Mimi\Application Data\netstat.bat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "Nero PhotoShow Media Manager"="c:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-05-10 249856] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-30 139264] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-11-03 4800512] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248] "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933] "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-06-15 366400] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2004-9-8 82026] HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048] HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248] Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "123:UDP"= 123:UDP:internet time server R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [6/27/2009 6:07 PM 114768] R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [6/27/2009 6:07 PM 20560] S1 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?] S2 gupdate1c986402a70f1e6;Google Update Service (gupdate1c986402a70f1e6);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2009 4:44 PM 133104] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-09-26 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2009-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 20:44] 2009-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 20:44] 2009-09-27 c:\windows\Tasks\User_Feed_Synchronization-{4502CF49-98B6-4E80-9F21-66A63EFE8936}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31] . . ------- Supplementary Scan ------- . uStart Page = about:blank uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz uSearchURL,(Default) = hxxp://www.google.com/search?q=%s Trusted Zone: internet Trusted Zone: mcafee.com DPF: {27F3D5C7-9440-410F-AEDA-E37456121070} - hxxp://x.longandfoster.com/Xcelerate/ActiveXcomponent/eXcelerate.CAB DPF: {475E5A2B-6EAC-4EA3-880A-55207CB012B5} - hxxp://wucma.wyldfyre.com/xbin/CMAX.dll FF - ProfilePath - c:\documents and settings\Tez\Application Data\Mozilla\Firefox\Profiles\8lbzxcqn.default\ FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - Toolbar-Locked - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-09-27 13:10 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-09-27 13:12 ComboFix-quarantined-files.txt 2009-09-27 17:12 Pre-Run: 38,865,666,048 bytes free Post-Run: 39,855,263,744 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn 166 --- E O F --- 2009-09-25 03:37