Here is the log from combofix
ComboFix 10-03-29.02 - Amit 03/29/2010 18:55:34.9.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1519 [GMT -5:00]
Running from: c:\documents and settings\Amit\My Documents\ComboFx.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-30 )))))))))))))))))))))))))))))))
.
2010-03-28 23:27 . 2010-03-28 23:27 -------- d-sh--w- c:\documents and settings\Darshana\IETldCache
2010-03-28 23:20 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-28 23:20 . 2010-03-28 23:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-28 23:20 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-28 22:58 . 2010-03-28 23:13 -------- d-----w- C:\ComboFx
2010-03-28 22:42 . 2010-03-28 22:42 -------- d-----w- c:\documents and settings\Amit\Application Data\AVG8
2010-03-27 14:14 . 2010-03-27 14:16 20846064 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\rp\RealPlayerSPGold.exe
2010-03-20 22:04 . 2010-03-20 22:04 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-03-20 21:38 . 2010-03-20 21:38 -------- d-----w- c:\program files\Western Digital Corporation
2010-03-17 00:15 . 2010-03-17 00:15 8405312 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-03-17 00:14 . 2010-03-17 00:14 149000 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\chr_helper\LaunchHelper.exe
2010-03-17 00:13 . 2010-03-17 00:14 10309448 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-17 00:12 . 2010-03-17 00:12 283280 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\carb\CarboniteSetupLiteRealPreinstaller.exe
2010-03-17 00:12 . 2010-03-17 00:12 181768 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\carb\LaunchHelper.exe
2010-03-17 00:12 . 2010-03-17 00:12 79368 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\RUP\vista.exe
2010-03-17 00:12 . 2010-03-17 00:12 52288 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-17 00:12 . 2010-03-17 00:12 64000 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-17 00:12 . 2010-03-17 00:12 50688 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-17 00:12 . 2010-03-17 00:12 49152 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-17 00:12 . 2010-03-17 00:12 118784 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-16 00:23 . 2010-03-27 14:17 439816 ----a-w- c:\documents and settings\Amit\Application Data\Real\Update\setup3.10\setup.exe
2010-03-11 02:33 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-05 19:21 . 2010-03-05 19:21 -------- d-----w- c:\program files\Seagate
2010-03-05 19:20 . 2010-03-05 19:20 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-28 02:36 . 2010-02-28 02:41 -------- d-----w- c:\documents and settings\Amit\Application Data\ImgBurn
2010-02-28 02:34 . 2010-02-28 02:34 -------- d-----w- c:\program files\ImgBurn
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-29 08:01 . 2008-10-03 04:25 -------- d-----w- c:\program files\IDrive
2010-03-29 00:45 . 2006-04-08 21:19 -------- d-----w- c:\documents and settings\Amit\Application Data\Azureus
2010-03-24 00:20 . 2005-03-04 17:06 -------- d-----w- c:\program files\Dell AIO Printer A920
2010-03-21 03:01 . 2010-01-30 21:23 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat
2010-03-21 01:15 . 2009-11-28 16:33 -------- d-----w- c:\documents and settings\Amit\Application Data\Skype
2010-03-21 00:28 . 2009-11-28 16:38 -------- d-----w- c:\documents and settings\Amit\Application Data\skypePM
2010-03-20 22:18 . 2009-07-28 14:33 -------- d-----w- c:\program files\iTunes
2010-03-20 22:17 . 2006-08-18 19:05 -------- d-----w- c:\program files\iPod
2010-03-20 22:17 . 2007-11-02 22:43 -------- d-----w- c:\program files\Common Files\Apple
2010-03-20 18:16 . 2007-09-12 17:34 -------- d-----w- c:\program files\PaRav
2010-03-14 20:29 . 2006-12-25 04:28 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-19 20:45 . 2009-05-23 01:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-02-15 04:18 . 2010-02-15 02:55 -------- d-----w- c:\program files\ffdshow
2010-02-15 04:18 . 2010-02-15 02:55 -------- d-----w- c:\program files\AviSynth 2.5
2010-02-15 04:17 . 2010-02-15 04:17 -------- d-----w- c:\program files\Common Files\SourceTec
2010-02-15 04:17 . 2010-02-15 04:17 -------- d-----w- c:\program files\SourceTec
2010-02-15 03:48 . 2007-06-19 02:05 -------- d-----w- c:\documents and settings\Amit\Application Data\Vso
2010-02-15 03:47 . 2007-06-19 02:05 47360 -c--a-w- c:\documents and settings\Amit\Application Data\pcouffin.sys
2010-02-15 03:47 . 2007-06-19 02:05 47360 -c--a-w- c:\documents and settings\Amit\Application Data\pcouffin.sys
2010-02-15 03:47 . 2006-04-05 02:25 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-02-15 03:47 . 2010-02-15 03:47 -------- d-----w- c:\program files\DVDFab 6
2010-02-15 03:01 . 2005-08-28 03:28 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-02-15 02:55 . 2010-02-15 02:55 -------- d-----w- c:\program files\Haali
2010-02-11 18:53 . 2010-01-29 22:34 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-11 18:53 . 2010-01-29 22:34 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-11 18:42 . 2010-01-29 22:35 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-11 18:42 . 2010-01-29 22:35 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-11 18:39 . 2010-01-29 22:35 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-11 18:38 . 2010-01-29 22:35 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-11 18:38 . 2010-01-29 22:35 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-11 18:38 . 2010-01-29 22:35 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-11 18:38 . 2010-01-29 22:35 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-10 02:40 . 2010-02-07 21:04 -------- d-----w- c:\documents and settings\Amit\Application Data\Malwarebytes
2010-02-10 02:40 . 2010-02-07 21:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-30 22:01 . 2010-01-30 22:01 55192 ----a-w- c:\documents and settings\Amit\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-29 22:57 . 2004-12-09 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\QuickTime
2010-01-29 22:34 . 2010-01-29 22:34 -------- d-----w- c:\program files\Alwil Software
2010-01-29 22:34 . 2010-01-29 22:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-01-29 21:01 . 2010-01-29 21:01 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100129.006\CCERASER.DLL
2010-01-29 21:01 . 2010-01-29 21:01 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100129.006\ECMSVR32.DLL
2010-01-29 20:25 . 2010-01-29 20:25 -------- d-----w- c:\program files\Windows Sidebar
2009-12-31 16:50 . 2004-08-04 11:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2008-10-29 23:25 . 2008-10-29 23:25 13706 -c--a-w- c:\program files\Common Files\vasosicuv.scr
2007-03-09 14:37 . 2007-03-09 14:37 57792 -c--a-w- c:\program files\MC
2006-07-01 12:46 . 2006-07-01 12:46 73 -c--a-w- c:\program files\cdboot.phx
2006-07-01 12:46 . 2006-07-01 12:46 389 -c--a-w- c:\program files\proginfo.txt
2006-07-01 12:46 . 2006-07-01 12:46 167936 -c--a-w- c:\program files\diskinst.exe
2006-07-01 12:46 . 2006-07-01 12:46 113 -c--a-w- c:\program files\instruct.ini
1601-01-01 00:03 . 1601-01-01 00:03 71168 --sha-w- c:\windows\SYSTEM32\nunupofa.dll
1601-01-01 00:03 . 1601-01-01 00:03 71168 --sha-w- c:\windows\SYSTEM32\zasulege.dll
2009-11-01 16:54 . 2009-10-31 16:22 45223968 --sha-w- c:\windows\SYSTEM32\DRIVERS\fidbox.dat
.
((((((((((((((((((((((((((((( SnapShot_2010-02-12_17.11.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-30 00:03 . 2010-03-30 00:03 40960 c:\windows\temp\rtdrvmon.exe
+ 2010-03-30 00:03 . 2010-03-30 00:03 16384 c:\windows\temp\Perflib_Perfdata_308.dat
- 2007-01-29 08:58 . 2009-10-28 15:07 46080 c:\windows\SYSTEM32\tzchange.exe
+ 2007-01-29 08:58 . 2010-01-23 08:11 46080 c:\windows\SYSTEM32\tzchange.exe
- 2009-12-09 02:50 . 2009-05-26 11:40 17272 c:\windows\SYSTEM32\spmsg.dll
+ 2009-12-09 02:50 . 2008-07-08 13:02 17272 c:\windows\SYSTEM32\spmsg.dll
+ 2010-02-15 02:55 . 2008-06-09 04:58 60273 c:\windows\SYSTEM32\pthreadGC2.dll
+ 2004-12-09 06:24 . 2010-03-14 17:02 75726 c:\windows\SYSTEM32\PERFC009.DAT
- 2004-12-09 06:24 . 2009-12-10 01:31 75726 c:\windows\SYSTEM32\PERFC009.DAT
- 2008-08-22 12:33 . 2009-12-20 02:57 84507 c:\windows\SYSTEM32\Macromed\Flash\uninstall_activeX.exe
+ 2008-08-22 12:33 . 2010-03-17 00:17 84507 c:\windows\SYSTEM32\Macromed\Flash\uninstall_activeX.exe
+ 2010-02-15 02:55 . 2008-12-08 18:53 57344 c:\windows\SYSTEM32\ff_vfw.dll
+ 2007-04-25 11:20 . 2007-04-25 11:20 62592 c:\windows\SYSTEM32\DLLCACHE\cdrom.sys
+ 2004-12-17 11:33 . 2010-03-28 13:31 98304 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-12-17 11:33 . 2009-12-10 01:27 98304 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-12-17 11:33 . 2009-12-10 01:27 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-12-17 11:33 . 2010-03-28 13:31 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-03-05 19:22 . 2010-03-05 19:22 11264 c:\windows\Installer\{98613C99-1399-416C-A07C-1EE1C585D872}\Icon98613C992.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 90112 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 90112 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 45056 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 45056 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 22528 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 22528 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 30720 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 30720 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 16384 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 16384 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 34304 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 34304 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 81920 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 81920 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
+ 2010-02-26 18:54 . 2009-10-28 15:07 46080 c:\windows\$NtUninstallKB979306$\tzchange.exe
+ 2010-02-26 18:54 . 2010-01-23 10:40 16896 c:\windows\$NtUninstallKB979306$\spuninst\tzchange.dll
+ 2010-02-26 18:59 . 2008-07-08 13:02 26488 c:\windows\$hf_mig$\KB976662-IE8\update\spcustom.dll
+ 2010-02-26 18:59 . 2008-07-08 13:02 17272 c:\windows\$hf_mig$\KB976662-IE8\spmsg.dll
+ 2005-06-15 22:04 . 2010-03-11 03:21 3584 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 3584 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 8192 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 8192 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 2560 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 2560 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2004-12-09 06:24 . 2010-03-14 17:02 451968 c:\windows\SYSTEM32\PERFH009.DAT
- 2004-12-09 06:24 . 2009-12-10 01:31 451968 c:\windows\SYSTEM32\PERFH009.DAT
+ 2010-01-27 00:58 . 2010-01-27 00:58 256280 c:\windows\SYSTEM32\Macromed\Flash\FlashUtil10e.exe
+ 2004-08-04 11:00 . 2009-12-09 05:53 726528 c:\windows\SYSTEM32\jscript.dll
- 2004-08-04 11:00 . 2009-06-22 06:44 726528 c:\windows\SYSTEM32\jscript.dll
+ 2008-10-30 22:37 . 2008-10-30 22:37 922112 c:\windows\SYSTEM32\imapi2fs.dll
+ 2008-10-30 22:37 . 2008-10-30 22:37 426496 c:\windows\SYSTEM32\imapi2.dll
+ 2008-05-09 10:53 . 2009-12-09 05:53 726528 c:\windows\SYSTEM32\DLLCACHE\jscript.dll
- 2008-05-09 10:53 . 2009-06-22 06:44 726528 c:\windows\SYSTEM32\DLLCACHE\jscript.dll
+ 2008-10-30 22:37 . 2008-10-30 22:37 922112 c:\windows\SYSTEM32\DLLCACHE\imapi2fs.dll
+ 2008-10-30 22:37 . 2008-10-30 22:37 426496 c:\windows\SYSTEM32\DLLCACHE\imapi2.dll
+ 2004-05-26 12:37 . 2004-05-26 12:37 719872 c:\windows\SYSTEM32\devil.dll
+ 2008-12-21 21:46 . 2008-12-21 21:46 351744 c:\windows\SYSTEM32\avisynth.dll
+ 2010-03-05 19:22 . 2010-03-05 19:22 584704 c:\windows\Installer\d9fcc6.msi
+ 2010-03-20 21:38 . 2010-03-20 21:38 200192 c:\windows\Installer\1636526.msi
- 2005-06-15 22:04 . 2010-02-10 03:55 114688 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 114688 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2005-06-15 22:04 . 2010-02-10 03:55 167936 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2005-06-15 22:04 . 2010-03-11 03:21 167936 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2010-03-20 22:19 . 2010-03-20 22:19 102400 c:\windows\Installer\{81063354-9060-42B2-A000-1EBE96778AA9}\iTunesIco.exe
+ 2010-02-26 18:59 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll
+ 2010-02-26 18:59 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe
+ 2010-02-26 18:59 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll
+ 2010-02-26 18:54 . 2009-05-26 11:40 382840 c:\windows\$NtUninstallKB979306$\spuninst\updspapi.dll
+ 2010-02-26 18:54 . 2009-05-26 11:40 231288 c:\windows\$NtUninstallKB979306$\spuninst\spuninst.exe
+ 2010-02-15 02:57 . 2008-07-09 17:32 379184 c:\windows\$NtUninstallKB952011$\spuninst\updspapi.dll
+ 2010-02-15 02:57 . 2008-07-09 17:32 221488 c:\windows\$NtUninstallKB952011$\spuninst\spuninst.exe
+ 2010-02-26 18:59 . 2008-07-08 13:02 382840 c:\windows\$hf_mig$\KB976662-IE8\update\updspapi.dll
+ 2010-02-26 18:59 . 2008-07-08 13:02 755576 c:\windows\$hf_mig$\KB976662-IE8\update\update.exe
+ 2010-02-26 18:59 . 2008-07-08 13:02 231288 c:\windows\$hf_mig$\KB976662-IE8\spuninst.exe
+ 2010-02-26 16:09 . 2009-12-09 05:51 726528 c:\windows\$hf_mig$\KB976662-IE8\SP3QFE\jscript.dll
+ 2010-02-15 04:17 . 2009-08-17 15:54 1184984 c:\windows\SYSTEM32\wvc1dmod.dll
+ 2005-06-09 20:50 . 2010-03-28 22:42 5148540 c:\windows\SYSTEM32\Restore\rstrlog.dat
+ 2010-03-20 22:19 . 2010-03-20 22:19 4449280 c:\windows\Installer\180a61a.msi
+ 2010-01-28 12:17 . 2010-01-28 12:17 17510400 c:\windows\Installer\dda47d.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9c79fc4a-256b-424a-9362-2bcb36b93b7b}]
1601-01-01 00:03 71168 --sha-w- c:\windows\SYSTEM32\zasulege.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 86016]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-05-26 185896]
"VX3000"="c:\windows\vVX3000.exe" [2009-07-24 762208]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"penekelasu"="hatutiza.dll" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\Amit\Start Menu\Programs\Startup\
avast.lnk - c:\program files\Alwil Software\Avast5\AvastUI.exe [2010-1-29 2756488]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2004-12-9 24576]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
path=
backup=
backupExtension=Common Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^802.11b+g USB Wireless LAN Utility.lnk]
backup=c:\windows\pss\802.11b+g USB Wireless LAN Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
backupExtension=Common Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
backupExtension=Common Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Amit^Start Menu^Programs^Startup^IDrive Tray.lnk]
backup=c:\windows\pss\IDrive Tray.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2008-04-23 07:08 483328 ----a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
2009-02-03 13:22 1004544 ----a-w- c:\program files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
2004-04-15 08:32 270336 ----a-w- c:\program files\Dell AIO Printer A920\dlbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-15 23:07 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2009-07-24 21:05 118640 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 16:50 155648 ----a-w- c:\windows\SYSTEM32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 05:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Samsung PanelMgr]
2008-08-08 05:03 524288 ----a-w- c:\windows\Samsung\PanelMgr\SSMMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-10-09 19:11 25623336 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
2009-07-24 21:05 762208 ----a-w- c:\windows\vVX3000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\kdx\\KHost.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IDrive\\IDriveEClassic.exe"=
"c:\\Program Files\\IDrive\\IDriveETray.exe"=
"c:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"c:\\Program Files\\WLAN\\802.11b+g USB WLAN\\ZDWlan.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\SYSTEM32\\hkcmd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"14238:TCP"= 14238:TCP:darshmeet
"1755:TCP"= 1755:TCP:windows media player
R1 aswSP;aswSP;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [1/29/2010 5:35 PM 162512]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [11/13/2009 9:12 PM 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [11/13/2009 9:13 PM 234888]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [1/29/2010 5:35 PM 19024]
R2 IDriveE Service;IDriveE Service;c:\program files\IDrive\IDriveE Service.exe [10/2/2008 11:25 PM 136656]
R2 IDrivePlugin;IDrivePlugin;c:\program files\IDrive\IDriveWebM.exe [10/2/2008 11:25 PM 58832]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys --> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys --> c:\windows\system32\drivers\TfSysMon.sys [?]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys --> c:\windows\system32\drivers\TfNetMon.sys [?]
S3 WLAN(WLAN);802.11b+g USB Wireless LAN Adapter Driver(WLAN);c:\windows\SYSTEM32\DRIVERS\ZD1211U.sys [6/5/2005 6:18 PM 258560]
S3 ZD1201U;ZyDAS ZD1201 IEEE 802.11b Wireless LAN Driver (USB);c:\windows\system32\DRIVERS\zd1201u.sys --> c:\windows\system32\DRIVERS\zd1201u.sys [?]
S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;c:\windows\SYSTEM32\ZDBRGSYS.sys [6/5/2005 6:18 PM 19200]
S3 ZDNDIS5;ZDNDIS5 NDIS Protocol Driver;\??\c:\windows\system32\ZDNDIS5.SYS --> c:\windows\system32\ZDNDIS5.SYS [?]
.
Contents of the 'Scheduled Tasks' folder
2009-08-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-02-15 c:\windows\Tasks\McDefragTask.job
- c:\windows\system32\DEFRAG.EXE [2004-08-04 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.comuSearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7mStart Page =
hxxp://www.google.commSearch Bar =
uInternet Connection Wizard,ShellNext =
hxxp://start.earthlink.net/uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
TCP: {6876C54C-08AF-4D30-8DB2-CA7CBADD2463} = 192.168.1.254,192.168.2.254
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/mygarmin/m/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-29 19:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3018035710-715601661-13499995-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2452)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-03-29 19:44:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-30 00:43
ComboFix2.txt 2010-03-28 23:13
Pre-Run: 133,024,346,112 bytes free
Post-Run: 133,304,475,648 bytes free
- - End Of File - - 51EB7D30B5C4B9D6D136938477903390