I will have to post in two sections.
ComboFix 09-06-11.05 - david 06/11/2009 15:39.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.593 [GMT -4:00]
Running from: G:\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\amanda\Application Data\twain_32
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\amanda\Application Data\twain_32\user.ds
c:\documents and settings\david\Application Data\wiaserva.log
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\windows\kb913800.exe
c:\windows\system32\_000000_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\Temp\19534943.exe
D:\Desktop.ini
c:\windows\system32\grpconv.exe was missing
Restored copy from - c:\system volume information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP423\A0026221.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AVAST!ANTIVIRUS
-------\Legacy_WIN32X
((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 )))))))))))))))))))))))))))))))
.
2009-06-11 19:42 . 2004-08-10 15:00 39424 ----a-w- c:\windows\system32\grpconv.exe
2009-06-11 19:42 . 2004-08-10 15:00 39424 ----a-w- c:\windows\system32\dllcache\grpconv.exe
2009-06-10 16:25 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-10 16:25 . 2009-03-24 20:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-10 16:25 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-10 16:25 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-10 16:25 . 2009-06-10 16:25 -------- d-----w- c:\program files\Avira
2009-06-10 16:25 . 2009-06-10 16:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-09 17:19 . 2009-06-09 17:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-06-09 17:19 . 2009-06-09 17:19 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-06-09 17:19 . 2009-06-09 17:19 -------- d-----w- c:\documents and settings\david\Application Data\Sonic
2009-06-09 17:19 . 2009-06-09 17:19 -------- d-----w- c:\documents and settings\david\Application Data\PC Tools
2009-06-09 17:18 . 2009-06-09 17:18 -------- d-----w- c:\program files\Common Files\BitDefender
2009-06-09 17:18 . 2009-06-09 17:18 -------- d-----w- C:\4304f949750ce894fde4cc20
2009-06-09 11:57 . 2009-06-09 17:19 -------- d-s---w- C:\ComboFix1
2009-06-08 17:11 . 2004-08-10 15:00 4096 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
2009-06-08 13:46 . 2009-06-08 13:46 -------- d-----w- c:\documents and settings\david\Application Data\Malwarebytes
2009-06-08 13:46 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-08 13:46 . 2009-06-08 13:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-08 13:46 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-08 13:46 . 2009-06-09 17:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-08 12:53 . 2009-06-11 19:45 117760 ----a-w- c:\documents and settings\david\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-08 12:52 . 2009-06-09 17:14 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-06-08 12:52 . 2009-06-08 12:52 -------- d-----w- c:\documents and settings\david\Application Data\SUPERAntiSpyware.com
2009-06-08 12:51 . 2009-06-08 12:51 -------- d-----w- c:\program files\Microsoft Windows OneCare Live
2009-06-05 13:43 . 2009-06-05 13:43 -------- d-----w- c:\documents and settings\david\Application Data\MSNInstaller
2009-06-05 00:21 . 2009-06-05 00:21 -------- d-----w- c:\documents and settings\david\Application Data\Leadertech
2009-06-04 23:31 . 2008-06-11 01:22 81288 ----a-w- c:\windows\system32\drivers\iksyssec.sys
2009-06-04 23:31 . 2008-06-02 19:19 29576 ----a-w- c:\windows\system32\drivers\kcom.sys
2009-06-04 23:31 . 2008-06-02 19:19 42376 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
2009-06-04 23:31 . 2008-06-02 19:19 66952 ----a-w- c:\windows\system32\drivers\iksysflt.sys
2009-06-04 23:30 . 2009-06-09 17:19 -------- d-----w- c:\program files\Spyware Doctor
2009-06-04 14:01 . 2004-05-11 13:56 423784 ----a-w- c:\windows\system32\XceedBkp.dll
2009-06-04 14:01 . 2003-11-19 17:59 512688 ----a-w- c:\windows\system32\XceedCry.dll
2009-06-04 14:01 . 2000-07-15 09:00 101888 ----a-w- c:\windows\system32\VB6STKIT.DLL
2009-06-03 14:03 . 2009-06-09 17:18 -------- d-----w- C:\AV-CLS
2009-06-03 13:45 . 2009-06-11 19:45 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-03 13:22 . 2009-06-03 13:22 -------- d-----w- c:\program files\Enigma Software Group
2009-06-02 22:27 . 2004-08-10 15:00 82944 ----a-w- c:\windows\system32\dllcache\ws2_32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-11 19:37 . 2006-08-29 08:20 -------- d-----w- c:\documents and settings\david\Application Data\U3
2009-06-10 15:56 . 2006-04-13 13:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-10 03:27 . 2006-09-20 02:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-06-10 03:27 . 2006-09-20 02:38 -------- d-----w- c:\program files\Viewpoint
2009-06-09 17:18 . 2006-09-23 02:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-06-09 17:18 . 2006-09-23 02:08 -------- d-----w- c:\program files\NVIDIA Corporation
2009-06-09 17:18 . 2006-09-20 02:40 -------- d-----w- c:\documents and settings\david\Application Data\Aim
2009-06-09 17:18 . 2006-09-20 02:38 -------- d-----w- c:\program files\AIM
2009-06-09 17:18 . 2006-10-28 02:45 -------- d-----w- c:\program files\DivX
2009-06-09 17:18 . 2007-08-15 03:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-04 18:53 . 2006-04-13 13:56 110416 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-04 15:35 . 2006-04-13 13:44 -------- d-----w- c:\program files\Quickensetup
2009-06-04 15:35 . 2006-04-13 13:17 -------- d-----w- c:\program files\Microsoft Works
2009-06-04 14:29 . 2008-11-04 16:19 -------- d-----w- c:\documents and settings\david\Application Data\GetRightToGo
2009-06-04 13:48 . 2006-04-13 12:47 -------- d-----w- c:\program files\HPQ
2009-06-04 13:47 . 2007-08-06 02:19 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-04 11:58 . 2008-12-01 22:18 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-04 11:42 . 2007-08-15 03:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-02 21:52 . 2006-10-27 02:30 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-05-31 01:41 . 2008-09-29 01:16 -------- d-----w- c:\documents and settings\amanda\Application Data\U3
2006-10-28 03:10 . 2006-10-28 03:10 56 --sh--r- c:\windows\system32\260588ACD5.sys
2006-10-28 03:10 . 2006-10-28 03:10 1890 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
------- Sigcheck -------
[-] 2008-04-14 00:12 82432 2CCC474EB85CEAA3E1FA1726580A3E5A c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ws2_32.dll
[-] 2004-08-10 15:00 82944 BCFD249150061F29941893CD0F8FE620 c:\windows\system32\ws2_32.dll
[-] 2004-08-10 15:00 82944 BCFD249150061F29941893CD0F8FE620 c:\windows\system32\dllcache\ws2_32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-04 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-14 257088]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-07-16 1166216]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-04 68856]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 10:05 AM 9968]
R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 72944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/10/2009 12:25 PM 108289]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2/10/2007 6:29 AM 29178224]
R2 sdauxservice;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [6/4/2009 7:30 PM 356920]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/22/2005 5:06 AM 231424]
R3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 7408]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
.
------- Supplementary Scan -------
.
uStart Page = yahoo.com/
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-11 15:45
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0