ComboFix 11-04-01.01 - Nicki 04/02/2011 1:14.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2724 [GMT 1:00]
Running from: c:\documents and settings\Nicki\My Documents\Combo-Fix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\muzapp.exe
.
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-04-01 14:01 . 2011-04-01 14:01 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2011-03-30 16:21 . 2011-03-30 16:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-03-30 16:21 . 2011-03-30 16:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-30 00:43 . 2011-03-30 00:43 -------- d-----w- c:\documents and settings\Nicki\Application Data\DDMSettings
2011-03-29 23:49 . 2011-03-29 23:49 -------- d-----w- c:\documents and settings\Nicki\Local Settings\Application Data\Unity
2011-03-29 18:18 . 2011-03-29 18:18 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2011-03-29 18:18 . 2011-03-29 18:18 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-03-29 02:41 . 2011-03-29 02:41 -------- d-----w- c:\documents and settings\Nicki\Local Settings\Application Data\Identities
2011-03-28 23:58 . 2011-03-28 23:58 388096 ----a-r- c:\documents and settings\Nicki\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-28 23:58 . 2011-03-28 23:58 -------- d-----w- c:\program files\Trend Micro
2011-03-28 17:17 . 2011-03-28 17:17 -------- d-----w- c:\documents and settings\Administrator
2011-03-28 16:01 . 2011-03-28 16:01 -------- d-----w- c:\documents and settings\Nicki\Application Data\Malwarebytes
2011-03-28 16:01 . 2011-03-28 16:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-03-28 16:01 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-28 16:01 . 2011-03-29 18:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-28 16:01 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-28 10:40 . 2011-03-28 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-03-14 14:24 . 2011-03-14 14:24 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-03-13 17:02 . 2011-03-13 17:02 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-03-13 17:02 . 2011-03-13 17:11 -------- d-----w- c:\program files\Google
2011-03-13 17:02 . 2011-03-13 17:07 -------- d-----w- c:\documents and settings\Nicki\Local Settings\Application Data\Google
2011-03-08 16:14 . 2011-03-08 16:14 -------- d-----w- c:\documents and settings\Nicki\Local Settings\Application Data\Electronic Arts
2011-03-06 18:54 . 2011-03-08 10:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2011-03-06 18:54 . 2011-03-06 18:54 -------- d-----w- C:\ProgramData
2011-03-06 18:53 . 2008-09-04 18:17 447752 ----a-r- c:\windows\system32\vp6vfw.dll
2011-03-06 18:53 . 2011-03-06 18:53 -------- d-----w- c:\program files\Microsoft WSE
2011-03-06 18:36 . 2011-03-16 18:58 -------- d-----w- c:\program files\Electronic Arts
2011-03-05 18:28 . 2011-03-05 18:28 -------- d-----w- c:\windows\Sun
2011-03-04 18:52 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2011-03-04 18:52 . 2011-03-04 18:52 -------- d-----w- c:\program files\Windows Media Connect 2
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-20 19:25 . 2011-02-20 19:25 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-20 19:25 . 2011-02-20 19:25 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-09 13:53 . 2006-02-28 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2006-02-28 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2011-01-27 00:28 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-29 23:16 . 2011-01-29 23:16 30056 ----a-w- c:\windows\system32\MASetupCleaner.exe
2011-01-29 17:00 . 2011-02-20 19:11 4659712 ----a-w- c:\windows\system32\Redemption.dll
2011-01-29 17:00 . 2011-01-29 17:00 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2011-01-29 17:00 . 2011-01-29 17:00 325552 ----a-w- c:\windows\MASetupCaller.dll
2011-01-29 17:00 . 2011-01-29 17:00 30568 ----a-w- c:\windows\MusiccityDownload.exe
2011-01-29 17:00 . 2011-01-29 17:00 974848 ----a-w- c:\windows\system32\cis-2.4.dll
2011-01-29 17:00 . 2011-01-29 17:00 81920 ----a-w- c:\windows\system32\issacapi_bs-2.3.dll
2011-01-29 17:00 . 2011-01-29 17:00 65536 ----a-w- c:\windows\system32\issacapi_pe-2.3.dll
2011-01-29 17:00 . 2011-01-29 17:00 57344 ----a-w- c:\windows\system32\MTXSYNCICON.dll
2011-01-29 17:00 . 2011-01-29 17:00 57344 ----a-w- c:\windows\system32\MK_Lyric.dll
2011-01-29 17:00 . 2011-01-29 17:00 57344 ----a-w- c:\windows\system32\issacapi_se-2.3.dll
2011-01-29 17:00 . 2011-01-29 17:00 569344 ----a-w- c:\windows\system32\muzdecode.ax
2011-01-29 17:00 . 2011-01-29 17:00 491520 ----a-w- c:\windows\system32\muzapp.dll
2011-01-29 17:00 . 2011-01-29 17:00 49152 ----a-w- c:\windows\system32\MaJGUILib.dll
2011-01-29 17:00 . 2011-01-29 17:00 45056 ----a-w- c:\windows\system32\MaXMLProto.dll
2011-01-29 17:00 . 2011-01-29 17:00 45056 ----a-w- c:\windows\system32\MACXMLProto.dll
2011-01-29 17:00 . 2011-01-29 17:00 40960 ----a-w- c:\windows\system32\MTTELECHIP.dll
2011-01-29 17:00 . 2011-01-29 17:00 40960 ----a-w- c:\windows\system32\MAMACExtract.dll
2011-01-29 17:00 . 2011-01-29 17:00 352256 ----a-w- c:\windows\system32\MSLUR71.dll
2011-01-29 17:00 . 2011-01-29 17:00 258048 ----a-w- c:\windows\system32\muzoggsp.ax
2011-01-29 17:00 . 2011-01-29 17:00 245760 ----a-w- c:\windows\system32\MSCLib.dll
2011-01-29 17:00 . 2011-01-29 17:00 200704 ----a-w- c:\windows\system32\muzwmts.dll
2011-01-29 17:00 . 2011-01-29 17:00 155648 ----a-w- c:\windows\system32\MSFLib.dll
2011-01-29 17:00 . 2011-01-29 17:00 143360 ----a-w- c:\windows\system32\3DAudio.ax
2011-01-29 17:00 . 2011-01-29 17:00 135168 ----a-w- c:\windows\system32\muzaf1.dll
2011-01-29 17:00 . 2011-01-29 17:00 131072 ----a-w- c:\windows\system32\muzmpgsp.ax
2011-01-29 17:00 . 2011-01-29 17:00 122880 ----a-w- c:\windows\system32\muzeffect.ax
2011-01-29 17:00 . 2011-01-29 17:00 118784 ----a-w- c:\windows\system32\MaDRM.dll
2011-01-29 17:00 . 2011-01-29 17:00 110592 ----a-w- c:\windows\system32\muzmp4sp.ax
2011-01-29 17:00 . 2011-02-20 19:11 821824 ----a-w- c:\windows\system32\dgderapi.dll
2011-01-29 17:00 . 2011-02-20 19:11 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
2011-01-29 17:00 . 2011-02-20 19:11 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
2011-01-27 11:57 . 2011-01-27 00:28 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-26 17:40 . 2011-01-26 17:40 15256 ----a-w- c:\documents and settings\Nicki\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
2011-01-21 14:44 . 2006-02-28 12:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-13 08:47 . 2011-01-26 17:29 38848 ----a-w- c:\windows\avastSS.scr
2011-01-13 08:47 . 2011-01-26 17:29 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-01-13 08:41 . 2011-01-26 17:29 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-01-13 08:40 . 2011-01-26 17:29 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-01-13 08:40 . 2011-01-26 17:29 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-01-13 08:39 . 2011-01-26 17:29 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-01-13 08:37 . 2011-01-26 17:29 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-01-13 08:37 . 2011-01-26 17:29 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-01-13 08:37 . 2011-01-26 17:29 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-01-07 14:09 . 2006-02-28 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2011-01-03 08:38 . 2011-02-20 19:11 136680 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2011-01-03 08:38 . 2011-02-20 19:11 12776 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2011-01-03 08:38 . 2011-02-20 19:11 10472 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
2011-01-03 08:38 . 2011-02-20 19:11 10472 ----a-w- c:\windows\system32\drivers\ssadcm.sys
2011-01-03 08:38 . 2011-02-20 19:11 121192 ----a-w- c:\windows\system32\drivers\ssadbus.sys
2011-01-03 08:38 . 2011-02-20 19:11 10344 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
2011-01-03 08:38 . 2011-02-20 19:11 10344 ----a-w- c:\windows\system32\drivers\ssadwh.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-24 13574144]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-02-15 1230704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast5]
2011-01-13 08:47 3396624 ----a-w- c:\program files\Alwil Software\Avast5\AvastUI.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\football manager 2011\\fm.exe"=
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [1/26/2011 6:29 PM 294608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/26/2011 6:29 PM 17744]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/13/2011 6:02 PM 136176]
S3 FXDrv32;FXDrv32;\??\d:\fxdrv32.sys --> d:\FXDrv32.sys [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2/20/2011 8:11 PM 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2/20/2011 8:11 PM 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2/20/2011 8:11 PM 136680]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-01 c:\windows\Tasks\doxillionShakeIcon.job
- c:\program files\NCH Software\Doxillion\doxillion.exe [2011-04-01 14:01]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-13 17:02]
.
2011-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-13 17:02]
.
2011-02-09 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2011-02-02 23:58]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\Nicki\Application Data\Mozilla\Firefox\Profiles\4lish9d5.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Conduit Engine :
engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: DivX Plus Web Player HTML5 <video>: {23fcfd51-4958-4f00-80a3-ae97e717ed8b} - c:\program files\DivX\DivX Plus Web Player\firefox\html5video
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-04-02 01:21
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-04-02 01:22:48
ComboFix-quarantined-files.txt 2011-04-02 00:22
.
Pre-Run: 454,294,437,888 bytes free
Post-Run: 454,706,286,592 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 5851A5FB027B71FFD6A96BD48BA45156