ComboFix 09-05-20.09 - user 05/20/2009 21:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.714 [GMT -4:00]
Running from: E:\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\N1
c:\documents and settings\NetworkService\protect.dll
c:\documents and settings\user\Application Data\pidle
c:\documents and settings\user\protect.dll
c:\documents and settings\user\Start Menu\Programs\Startup\ChkDisk.lnk
c:\windows\system32\autochk.dll
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\drivers\ovfsthxdukkjgjt.sys
c:\windows\system32\iguwudil.ini
c:\windows\system32\lds.exe
c:\windows\system32\lmn_setup.exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\ovfsthxbovmgafn.dll
c:\windows\system32\ovfsthxcyqypbev.dat
c:\windows\system32\ovfsthxinforiuj.dat
c:\windows\system32\ovfsthxoaplrnow.dll
c:\windows\system32\ovfsthxsfqroyym.dll
c:\windows\system32\royalogo.exe
c:\windows\system32\sdra64.exe
c:\windows\t55ft2692f44.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ovfsthxedfeaacc
((((((((((((((((((((((((( Files Created from 2009-04-21 to 2009-05-21 )))))))))))))))))))))))))))))))
.
2009-05-07 13:49 . 2009-05-07 13:49 -------- d-----w c:\windows\system32\config\systemprofile\Application Data\AVGTOOLBAR
2009-05-07 13:33 . 2009-05-07 14:20 -------- d-----w c:\windows\system32\796525
2009-05-06 22:57 . 2009-05-06 22:57 -------- d-sh--w c:\documents and settings\user\IECompatCache
2009-05-06 21:19 . 2009-05-06 21:19 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-05-06 21:19 . 2009-05-06 21:19 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\ESET
2009-05-06 21:17 . 2009-05-06 21:17 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-05-06 02:23 . 2009-05-06 02:23 -------- d-----w c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-05-05 03:23 . 2009-05-05 03:23 -------- d-sh--w c:\documents and settings\user\PrivacIE
2009-05-05 03:17 . 2009-05-05 03:17 -------- d-sh--w c:\windows\system32\config\systemprofile\IETldCache
2009-05-05 03:16 . 2009-05-05 03:16 -------- d-sh--w c:\documents and settings\user\IETldCache
2009-05-05 02:43 . 2009-05-05 02:43 -------- d-----w c:\windows\ie8updates
2009-05-05 02:43 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-05-05 02:40 . 2009-05-05 02:43 -------- dc-h--w c:\windows\ie8
2009-05-05 01:51 . 2009-05-05 01:51 -------- d-----w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-05 01:51 . 2009-05-05 01:51 -------- d-----w c:\program files\SUPERAntiSpyware
2009-05-05 01:51 . 2009-05-05 01:51 -------- d-----w c:\documents and settings\user\Application Data\SUPERAntiSpyware.com
2009-05-05 01:44 . 2009-05-05 01:44 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-05-05 01:33 . 2009-05-05 01:33 -------- d-----w c:\documents and settings\user\Application Data\DriverCure
2009-05-05 01:33 . 2009-05-05 02:26 -------- d-----w c:\documents and settings\All Users\Application Data\DriverCure
2009-05-05 01:33 . 2009-05-05 01:33 -------- d-----w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-05-05 01:21 . 2009-05-05 20:47 -------- d-----w c:\documents and settings\user\Application Data\Desktopicon
2009-05-05 01:21 . 2009-05-09 15:05 -------- d-----w c:\program files\Unlocker
2009-05-04 21:40 . 2009-05-04 21:40 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\Symantec
2009-05-04 21:30 . 2008-04-17 16:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-05-04 21:30 . 2009-01-15 16:19 23848 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-04 21:30 . 2009-05-04 21:30 -------- d-----w c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-04 21:30 . 2009-05-06 02:22 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\Downloaded Installations
2009-05-04 21:29 . 2009-05-04 23:22 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-05-04 21:29 . 2009-05-04 23:21 -------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-05-04 21:29 . 2009-05-04 23:21 -------- d-----w c:\documents and settings\All Users\Application Data\Norton
2009-05-04 21:23 . 2009-05-04 21:23 -------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-05-04 21:09 . 2009-05-04 21:24 -------- d-----w c:\documents and settings\user\Application Data\GetRightToGo
2009-05-03 12:33 . 2009-05-03 12:33 -------- d-----w c:\documents and settings\user\Local Settings\Application Data\PCHealth
2009-05-01 14:30 . 2007-08-02 02:47 102664 ----a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-30 23:42 . 2009-04-30 23:42 -------- d-----w c:\windows\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 13:12 . 2009-02-25 21:37 -------- d-----w c:\program files\Windows Live Safety Center
2009-05-06 21:49 . 2008-06-02 01:21 -------- d-----w c:\program files\MSN Messenger
2009-05-06 02:26 . 2006-09-13 16:24 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-04 18:49 . 2009-02-24 21:27 108552 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-05-04 18:49 . 2009-02-24 21:27 325896 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-04 18:49 . 2009-02-24 21:27 11952 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-30 23:53 . 2006-09-13 18:41 -------- d-----w c:\program files\Java
2009-04-27 16:46 . 2008-06-02 02:02 -------- d-----w c:\program files\Common Files\Adobe
2009-04-05 05:25 . 2009-04-05 05:24 -------- d-----w c:\program files\Yahoo!
2009-03-29 12:57 . 2006-12-20 20:01 19424 ----a-w c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-09 09:19 . 2009-02-24 21:37 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 08:34 . 2006-06-23 16:33 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2003-07-16 16:26 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2003-07-16 16:20 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2003-07-16 16:43 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2003-07-16 16:17 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2003-07-16 16:24 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2003-07-16 16:24 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2003-07-16 16:30 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2003-07-16 16:30 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2003-07-16 16:30 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2003-07-16 16:34 284160 ----a-w c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-28 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2006-05-25 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2006-05-25 126976]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-04 1947928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
c:\documents and settings\user\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - e:\limewire\LimeWire.exe [2009-1-29 139776]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-04 18:49 11952 ----a-w c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgtray.exe"=
"e:\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/24/2009 5:27 PM 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/24/2009 5:27 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [4/28/2009 11:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/28/2009 11:33 AM 72944]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2/24/2009 5:27 PM 908568]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/24/2009 5:27 PM 298776]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [4/28/2009 11:33 AM 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-20 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 21:39]
.
- - - - ORPHANS REMOVED - - - -
BHO-{2ed15f84-b61a-4836-8e59-a58a80fa79ee} - (no file)
BHO-{E7F15AC4-E0A9-43F0-921B-70DFEA621220} - c:\windows\system32\796525\796525.dll
HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe
HKU-Default-Run-autochk - c:\windows\system32\config\SYSTEM~1\protect.dll
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.htmluSearchURL,(Default) =
hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.comIE: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm082RZUSIE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxDPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} -
hxxp://utilities.pcpitstop.com/DiskMD3/DiskMD3Ctrl.dll.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-20 21:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(676)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(3636)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-21 21:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-21 01:12
Pre-Run: 30,594,224,128 bytes free
Post-Run: 30,933,680,128 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
227 --- E O F --- 2009-03-25 07:00