ComboFix 10-12-15.04 - lilhutch 12/15/2010 17:39:13.1.2 - x86 NETWORK Microsoft� Windows Vista� Home Premium 6.0.6001.1.1252.1.1033.18.2046.1546 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *Enabled/Updated* {0C939084-9E57-CBDB-EA61-0B0C7F62AF82} SP: AVG Anti-Virus Free *Enabled/Updated* {B7F27160-B86D-C455-D0D1-307E04E5E53F} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\lsprst7.dll c:\windows\winhelp.ini . ((((((((((((((((((((((((( Files Created from 2010-11-15 to 2010-12-15 ))))))))))))))))))))))))))))))) . 2010-12-15 22:45 . 2010-12-15 22:45 -------- d-----w- c:\users\lilhutch\AppData\Local\temp 2010-12-15 22:45 . 2010-12-15 22:45 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-12-15 09:27 . 2010-12-15 09:27 -------- d-----w- c:\programdata\Norton 2010-12-15 09:27 . 2010-12-15 09:34 -------- d-----w- c:\users\lilhutch\AppData\Local\NPE 2010-12-15 03:06 . 2010-12-15 03:06 -------- d-----w- c:\program files\CCleaner 2010-12-15 01:45 . 2010-12-15 01:45 -------- d-----w- c:\program files\Marcos Velasco Security 2010-12-14 23:16 . 2010-12-14 23:20 -------- d-----w- c:\windows\system32\catroot2 2010-12-14 19:26 . 2010-12-14 19:26 -------- d-----w- c:\users\lilhutch\AppData\Roaming\Malwarebytes 2010-12-14 19:26 . 2010-11-29 22:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-12-14 19:26 . 2010-12-14 19:26 -------- d-----w- c:\programdata\Malwarebytes 2010-12-14 19:26 . 2010-12-14 19:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-12-14 19:26 . 2010-11-29 22:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-12-14 13:54 . 2010-12-14 13:54 -------- d-----w- c:\users\lilhutch\AppData\Local\{DC3C2172-3BF7-4068-8C45-E3AED85BECA4}(25) 2010-12-10 06:08 . 2010-12-10 06:08 644360 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2010-12-05 12:05 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C36DCF44-DD3E-448D-BECD-B22118B58E40}\mpengine.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-12-14 13:54 . 2010-07-30 21:07 0 ----a-w- c:\users\lilhutch\AppData\Local\Spodazu.bin 2010-10-19 15:41 . 2009-11-21 01:49 222080 ------w- c:\windows\system32\MpSigStub.exe 2010-10-08 08:38 . 2010-10-19 18:11 57960 ----a-w- c:\windows\system32\OpenCL.dll 2010-10-08 08:38 . 2010-10-19 18:11 5399656 ----a-w- c:\windows\system32\nvwgf2um.dll 2010-10-08 08:38 . 2010-10-19 18:11 888424 ----a-w- c:\windows\system32\nvdispco322050.dll 2010-10-08 08:38 . 2010-10-19 18:11 813672 ----a-w- c:\windows\system32\nvgenco322030.dll 2010-10-08 08:38 . 2010-10-19 18:11 14899816 ----a-w- c:\windows\system32\nvoglv32.dll 2010-10-08 08:38 . 2010-10-19 18:11 10055304 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys 2010-10-08 08:38 . 2010-10-19 18:11 4836456 ----a-w- c:\windows\system32\nvcuda.dll 2010-10-08 08:38 . 2010-10-19 18:11 2911848 ----a-w- c:\windows\system32\nvcuvid.dll 2010-10-08 08:38 . 2010-10-19 18:11 2666088 ----a-w- c:\windows\system32\nvcuvenc.dll 2010-10-08 08:38 . 2010-10-19 18:11 13019752 ----a-w- c:\windows\system32\nvcompiler.dll 2010-10-08 08:38 . 2010-10-19 18:11 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd 2010-10-08 08:38 . 2010-01-12 17:03 10021992 ----a-w- c:\windows\system32\nvd3dum.dll 2010-10-08 08:38 . 2008-09-18 03:55 1718376 ----a-w- c:\windows\system32\nvapi.dll 2010-10-08 05:57 . 2010-10-08 05:57 600680 ----a-w- c:\windows\system32\nvvsvc.exe 2010-10-08 05:57 . 2010-10-08 05:57 110696 ----a-w- c:\windows\system32\nvmctray.dll 2010-10-08 05:57 . 2010-10-08 05:57 3416680 ----a-w- c:\windows\system32\nvcpl.dll 2010-10-08 05:57 . 2010-10-08 05:57 2079336 ----a-w- c:\windows\system32\nvsvc.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "GrpConv"="grpconv -o" [X] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-3-13 813584] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "AntiVirusOverride"=dword:00000001 R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-01 1029456] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-10-08 369256] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-07-03 64160] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder 2010-12-13 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 16:03] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://search.myheritage.com IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 Trusted Zone: intuit.com\ttlc FF - ProfilePath - c:\users\lilhutch\AppData\Roaming\Mozilla\Firefox\Profiles\vif5zxat.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Zotero: [removed] - %profile%\extensions\[removed] . - - - - ORPHANS REMOVED - - - - HKLM-RunOnce- - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-12-15 17:45 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Windows 6.0.6001 Disk: Hitachi_ rev.V54O -> Harddisk0\DR0 -> device: opened successfully user: MBR read successfully Disk trace: called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x857E0555]<< _asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x857e67b0]; MOV EAX, [0x857e682c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; } 1 ntkrnlpa!IofCallDriver[0x81D0E05F] -> \Device\Harddisk0\DR0[0x857BF2A8] 3 CLASSPNP[0x827A4745] -> ntkrnlpa!IofCallDriver[0x81D0E05F] -> [0x8447BA78] 5 acpi[0x806996A0] -> ntkrnlpa!IofCallDriver[0x81D0E05F] -> [0x8447DC90] \Driver\nvstor32[0x857C6D18] -> IRP_MJ_CREATE -> 0x857E0555 kernel: MBR read successfully _asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; } detected disk devices: \Device\0000004f -> \??\SCSI#Disk&Ven_Hitachi&Prod_HDT725032VLA#4&358dcf36&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found detected hooks: user & kernel MBR OK Warning: possible TDL3 rootkit infection ! ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . Completion time: 2010-12-15 17:47:47 ComboFix-quarantined-files.txt 2010-12-15 22:47 Pre-Run: 169,313,955,840 bytes free Post-Run: 169,196,765,184 bytes free - - End Of File - - 4B06B4B721D930B3DFA137259EAE96BB