I'm trying to fix my mother's computer and she has Windows XP. I followed the instructions with Combofix and I think it scanned the system correctly. I had to run it in safe mode because it kept on freezing in windows mode. The AVG antivirus alert is now telling me there is a Trojan Horse Generic14.BMQW in my mother's user settings. This is where Total Security is running and I can't get onto her user settings(due to freezing, very slow start-up) so I'm doing everything from my username. Very worried about this
C:\Documents and Settings\Blossom\restorer32_a.exe
This the logfile of Combofix
ComboFix 09-09-30.06 - LeLe 01/10/2009 13:25.1.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.263 [GMT 1:00]
Running from: c:\documents and settings\LeLe\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AVEngn.dll
c:\program files\AntivirusPro_2010\data\daily.cvd
c:\program files\AntivirusPro_2010\htmlayout.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\AntivirusPro_2010\pthreadVC2.dll
c:\program files\Common Files\ycogeciv._dl
c:\program files\Common Files\ydanupe.scr
c:\program files\screensavers.com
c:\program files\screensavers.com\ActiveDesktop\bin\ActiveDesktopExe.exe
c:\program files\screensavers.com\SSSUninst.exe
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\ahisafuza.dll
c:\windows\doxuwivyt.dll
c:\windows\hnphz32.dll
c:\windows\Installer\105323.msp
c:\windows\Installer\106ef18.msp
c:\windows\Installer\10a03f9.msp
c:\windows\Installer\10db7e9.msp
c:\windows\Installer\10ddf09.msp
c:\windows\Installer\1176729.msp
c:\windows\Installer\117809c.msp
c:\windows\Installer\117e07.msp
c:\windows\Installer\11b7ef3.msp
c:\windows\Installer\1230680.msp
c:\windows\Installer\12d440.msp
c:\windows\Installer\12db110.msp
c:\windows\Installer\130c906.msp
c:\windows\Installer\1313b29.msp
c:\windows\Installer\13dbf23.msp
c:\windows\Installer\13f4779.msp
c:\windows\Installer\14924b.msp
c:\windows\Installer\14cf108.msp
c:\windows\Installer\14d7451.msp
c:\windows\Installer\14e143b.msp
c:\windows\Installer\14f67c5.msp
c:\windows\Installer\15171cd.msp
c:\windows\Installer\154456.msp
c:\windows\Installer\15489db.msp
c:\windows\Installer\155889.msp
c:\windows\Installer\1572055.msp
c:\windows\Installer\15f19d.msp
c:\windows\Installer\16096b.msp
c:\windows\Installer\160f56.msp
c:\windows\Installer\1622b3c.msp
c:\windows\Installer\1631b2a.msp
c:\windows\Installer\163c33.msp
c:\windows\Installer\1645d3f.msp
c:\windows\Installer\166074.msp
c:\windows\Installer\167a20a.msp
c:\windows\Installer\167f08.msp
c:\windows\Installer\17145a1.msp
c:\windows\Installer\17485b9.msp
c:\windows\Installer\177038a.msp
c:\windows\Installer\17d2ec3.msp
c:\windows\Installer\181c3d.msp
c:\windows\Installer\183aa3.msp
c:\windows\Installer\18ab0f4.msp
c:\windows\Installer\190cf0e.msp
c:\windows\Installer\19d713f.msp
c:\windows\Installer\19d893.msp
c:\windows\Installer\19fdb2a.msp
c:\windows\Installer\1a247e5.msp
c:\windows\Installer\1a6626e.msp
c:\windows\Installer\1a667fc.msp
c:\windows\Installer\1b0aca.msp
c:\windows\Installer\1b5ac30.msp
c:\windows\Installer\1b8bd1.msp
c:\windows\Installer\1bd3da0.msp
c:\windows\Installer\1c21abe.msp
c:\windows\Installer\1c41a76.msp
c:\windows\Installer\1c72ce7.msp
c:\windows\Installer\1cdc8c.msp
c:\windows\Installer\1d2d6dd.msp
c:\windows\Installer\1d372f.msp
c:\windows\Installer\1d6b596.msp
c:\windows\Installer\1deea1c.msp
c:\windows\Installer\1e15b8.msp
c:\windows\Installer\1e379.msp
c:\windows\Installer\1e576a0.msp
c:\windows\Installer\1e8746f.msp
c:\windows\Installer\1e8b56f.msp
c:\windows\Installer\1f1707b.msp
c:\windows\Installer\208774.msp
c:\windows\Installer\20e983a.msp
c:\windows\Installer\221bb46.msp
c:\windows\Installer\221c1d.msp
c:\windows\Installer\224418.msp
c:\windows\Installer\228b99e.msp
c:\windows\Installer\228d37f.msp
c:\windows\Installer\22c59c.msp
c:\windows\Installer\252f0b.msp
c:\windows\Installer\271bd.msp
c:\windows\Installer\2806a0b.msp
c:\windows\Installer\2820452.msp
c:\windows\Installer\286c57c.msp
c:\windows\Installer\2994ed9.msp
c:\windows\Installer\29f94b1.msp
c:\windows\Installer\2b8fd81.msp
c:\windows\Installer\2c1f382.msp
c:\windows\Installer\2dfcc4.msp
c:\windows\Installer\2e6e5a.msp
c:\windows\Installer\2e91e.msp
c:\windows\Installer\2ea22b.msp
c:\windows\Installer\2fba931.msp
c:\windows\Installer\30736d5.msp
c:\windows\Installer\32915.msp
c:\windows\Installer\332d9.msp
c:\windows\Installer\33346.msp
c:\windows\Installer\33ca3d.msp
c:\windows\Installer\33e22a.msp
c:\windows\Installer\33f6fa.msp
c:\windows\Installer\340991b.msp
c:\windows\Installer\35416a4.msp
c:\windows\Installer\35c580.msp
c:\windows\Installer\35e7c.msp
c:\windows\Installer\35e82.msp
c:\windows\Installer\36e8a.msp
c:\windows\Installer\382799.msp
c:\windows\Installer\39029a.msp
c:\windows\Installer\390684b.msp
c:\windows\Installer\392b9e.msp
c:\windows\Installer\39ca30.msp
c:\windows\Installer\3a6e81e.msp
c:\windows\Installer\3ab0b72.msp
c:\windows\Installer\3abb56.msp
c:\windows\Installer\3ac71e.msp
c:\windows\Installer\3af7c3.msp
c:\windows\Installer\3c0d5a2.msp
c:\windows\Installer\3c29d04.msp
c:\windows\Installer\3c38b2c.msp
c:\windows\Installer\3f8de5.msp
c:\windows\Installer\403198.msp
c:\windows\Installer\40bc24.msp
c:\windows\Installer\40c9f.msp
c:\windows\Installer\415613.msp
c:\windows\Installer\41ac8f.msp
c:\windows\Installer\41bc3f.msp
c:\windows\Installer\42a42e.msp
c:\windows\Installer\4344b4.msp
c:\windows\Installer\4553a38.msp
c:\windows\Installer\458ab.msp
c:\windows\Installer\48fe8.msp
c:\windows\Installer\4a7007.msp
c:\windows\Installer\4be55e.msp
c:\windows\Installer\4c03f.msp
c:\windows\Installer\4c0c33.msp
c:\windows\Installer\4cfef0.msp
c:\windows\Installer\4d10b2.msp
c:\windows\Installer\4d3dcd.msp
c:\windows\Installer\4e23e.msp
c:\windows\Installer\4ff106.msp
c:\windows\Installer\517341.msp
c:\windows\Installer\52ee8a8.msp
c:\windows\Installer\53606b.msp
c:\windows\Installer\54cd98.msp
c:\windows\Installer\566aae.msp
c:\windows\Installer\5a4669.msp
c:\windows\Installer\5ae057.msp
c:\windows\Installer\5b993.msp
c:\windows\Installer\5bf8e.msp
c:\windows\Installer\5c90e6.msp
c:\windows\Installer\61d99f.msp
c:\windows\Installer\629108.msp
c:\windows\Installer\636b89.msp
c:\windows\Installer\63c68a.msp
c:\windows\Installer\679e3e.msp
c:\windows\Installer\6818dd.msp
c:\windows\Installer\6857e.msp
c:\windows\Installer\68d547.msp
c:\windows\Installer\6ab20f6.msp
c:\windows\Installer\6aff8a.msp
c:\windows\Installer\6c594e.msp
c:\windows\Installer\6ed6b1.msp
c:\windows\Installer\6fb99.msp
c:\windows\Installer\701888.msp
c:\windows\Installer\723f1.msp
c:\windows\Installer\7413d.msp
c:\windows\Installer\76dfa.msp
c:\windows\Installer\78fd53.msp
c:\windows\Installer\7c1978.msp
c:\windows\Installer\7cb7b.msp
c:\windows\Installer\7f57f9.msp
c:\windows\Installer\800c55.msp
c:\windows\Installer\803951.msp
c:\windows\Installer\81e5c8.msp
c:\windows\Installer\82553c.msp
c:\windows\Installer\82c413.msp
c:\windows\Installer\82dcf.msp
c:\windows\Installer\82edb3.msp
c:\windows\Installer\8431db.msp
c:\windows\Installer\8b0a0e.msp
c:\windows\Installer\8d059.msp
c:\windows\Installer\8d4817.msp
c:\windows\Installer\9248f9.msp
c:\windows\Installer\93ce51.msp
c:\windows\Installer\94e530.msp
c:\windows\Installer\950d97.msp
c:\windows\Installer\9bfb07.msp
c:\windows\Installer\9c2beb.msp
c:\windows\Installer\9e1da9.msp
c:\windows\Installer\a1ef04.msp
c:\windows\Installer\a46b7d.msp
c:\windows\Installer\a7181f.msp
c:\windows\Installer\aa4626.msp
c:\windows\Installer\ab4b9.msp
c:\windows\Installer\ade073.msp
c:\windows\Installer\b18168.msp
c:\windows\Installer\b4aa0.msp
c:\windows\Installer\b5d7c.msp
c:\windows\Installer\b76bdf.msp
c:\windows\Installer\b9a85.msp
c:\windows\Installer\bb3f2e.msp
c:\windows\Installer\bccd7f.msp
c:\windows\Installer\bcf308.msp
c:\windows\Installer\bd7bfe.msp
c:\windows\Installer\befc9.msp
c:\windows\Installer\c56a25.msp
c:\windows\Installer\c7a281.msp
c:\windows\Installer\c9e0f8.msp
c:\windows\Installer\cb4b94.msp
c:\windows\Installer\ccd272.msp
c:\windows\Installer\d6e147.msp
c:\windows\Installer\d71007.msp
c:\windows\Installer\d8cb8.msi
c:\windows\Installer\db95b2.msp
c:\windows\Installer\dbeedb.msp
c:\windows\Installer\dd9c0e.msp
c:\windows\Installer\e02f4b.msp
c:\windows\Installer\e34778.msp
c:\windows\Installer\e3853d.msp
c:\windows\Installer\e5f7f2.msp
c:\windows\Installer\e8dcf9.msp
c:\windows\Installer\ed5080.msp
c:\windows\Installer\eeeff.msp
c:\windows\Installer\efa945.msp
c:\windows\Installer\f3db2f.msp
c:\windows\Installer\f4ba54.msp
c:\windows\Installer\fc2bd8.msp
c:\windows\system32\drivers\npf.sys
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\usacylyviw.reg
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\zofyleh.bat
Infected copy of c:\windows\system32\drivers\AGP440.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\agp440.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-09-01 to 2009-10-01 )))))))))))))))))))))))))))))))
.
2009-10-01 11:05 . 2009-10-01 11:08 -------- d-----w- c:\documents and settings\LeLe\Application Data\U3
2009-09-30 20:15 . 2009-09-30 20:15 -------- d-----w- c:\documents and settings\LeLe\Local Settings\Application Data\{1CE97981-E0CD-4400-87EB-57BAA15DE8AE}
2009-09-29 16:27 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-29 16:27 . 2009-09-29 16:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-29 16:27 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-29 16:27 . 2009-09-29 16:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-29 14:56 . 2009-09-29 16:09 -------- d-----w- c:\program files\Common Files\PC Tools
2009-09-29 07:59 . 2009-09-29 07:59 10889 ----a-w- c:\windows\alikital.com
2009-09-29 07:48 . 2009-10-01 11:03 0 ----a-w- c:\windows\Dpomeza.bin
2009-09-29 07:48 . 2009-09-30 21:59 120 ----a-w- c:\windows\Vtatigizo.dat
2009-09-29 07:43 . 2009-10-01 11:01 -------- d-----w- c:\documents and settings\All Users\Application Data\15203754
2009-09-26 12:19 . 2009-09-26 12:19 -------- d-----w- C:\b4ba555c974b0ebb886f1b2494
2009-09-26 12:15 . 2009-09-26 12:16 -------- d-----w- C:\a767d66792f486a3b62ab97853e15820
2009-09-25 20:20 . 2009-09-25 20:20 -------- d-----w- C:\b61eba71b554de70bd1e018603c5fa
2009-09-25 20:20 . 2009-09-25 20:20 -------- d-----w- C:\ddc5c8a9088569a869ec79c6c1f3
2009-09-15 17:03 . 2009-09-15 17:03 -------- d-----w- c:\program files\iPod
2009-09-15 17:03 . 2009-09-15 17:04 -------- d-----w- c:\program files\iTunes
2009-09-15 17:03 . 2009-09-15 17:04 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-11 17:16 . 2009-09-11 17:17 -------- d-----w- c:\program files\Bamboo Scribe 2.6
2009-09-11 17:15 . 2009-09-11 17:15 -------- d-----w- c:\program files\Wacom
2009-09-11 17:10 . 2009-09-11 17:10 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-09-11 17:09 . 2009-09-11 17:09 -------- d-----w- c:\program files\PenLauncher
2009-09-10 16:32 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-01 11:55 . 2008-09-19 13:13 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-01 11:29 . 2007-11-23 14:34 -------- d-----w- c:\program files\Microsoft SQL Server
2009-09-30 20:17 . 2008-06-25 11:23 71032 ----a-w- c:\documents and settings\LeLe\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-29 16:07 . 2009-07-07 17:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-29 15:33 . 2007-09-15 23:33 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-23 17:22 . 2007-07-12 22:09 5852 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-09-23 17:22 . 2007-07-12 22:09 168 --sh--r- c:\windows\system32\6343D7904E.sys
2009-09-16 09:01 . 2009-06-17 18:36 -------- d-----w- c:\program files\QuickTime
2009-09-15 17:03 . 2007-10-04 17:37 -------- d-----w- c:\program files\Common Files\Apple
2009-09-11 17:15 . 2007-07-09 19:13 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-10 21:24 . 2008-02-10 23:23 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-10 18:41 . 2007-11-23 13:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-28 21:18 . 2007-07-14 09:54 -------- d-----w- c:\program files\Google
2009-08-28 18:42 . 2009-03-16 19:40 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 18:42 . 2007-10-04 17:38 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-24 18:30 . 2009-08-24 18:19 116841 ----a-w- c:\windows\hpqins00.dat
2009-08-22 02:11 . 2008-10-27 12:32 -------- d-----w- c:\program files\MSBuild
2009-08-22 02:11 . 2009-08-22 02:11 -------- d-----w- c:\program files\Reference Assemblies
2009-08-21 09:00 . 2008-09-19 13:14 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-21 09:00 . 2008-09-19 13:14 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-21 09:00 . 2008-09-19 13:14 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-20 10:43 . 2007-09-02 13:25 135150 -c--a-w- c:\windows\hpwins10.dat
2009-08-19 13:51 . 2009-08-17 13:46 -------- d-----w- c:\program files\Burger Shop 2
2009-08-17 13:52 . 2009-08-17 13:52 -------- d-----w- c:\documents and settings\All Users\Application Data\GoBit Games
2009-08-17 13:46 . 2009-08-17 13:46 -------- d-----w- c:\program files\ReflexiveArcade
2009-08-05 17:41 . 2007-08-14 00:52 -------- d-----w- c:\program files\Java
2009-08-05 09:01 . 2004-08-04 10:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 04:23 . 2008-12-05 13:51 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2004-08-04 10:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" [2006-11-27 255528]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-21 2007832]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2009-01-29 2303216]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
c:\documents and settings\LeLe\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Device Detector 3.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2009-1-9 118784]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-21 09:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager 1.0\\MediaManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/09/2008 14:14 335240]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [27/03/2009 21:37 55152]
S3 SUSCOM;Susteen Serial port driver;c:\windows\system32\drivers\SUSCOM.SYS [22/10/2002 13:58 40448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-09-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 18:05]
2009-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 18:05]
2009-10-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} -
hxxp://game03.zylom.com/activex/zylomgamesplayer.cabDPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} -
hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Ogahi - c:\windows\ahisafuza.dll
HKLM-Run-TkBellExe - realsched.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-01 13:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2624)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\PSIService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\searchprotocolhost.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2009-10-01 13:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-01 12:53
Pre-Run: 24,672,264,192 bytes free
Post-Run: 24,734,064,640 bytes free
490 --- E O F --- 2009-10-01 11:30