Combo Fix & DDS log
Combofix log
ComboFix 09-10-10.02 - Eli 11/10/2009 12:29.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1517 [GMT -4:00]
Running from: c:\documents and settings\Eli\Desktop\Combo-Fixx.exe
Command switches used :: c:\documents and settings\Eli\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Net Protector
c:\documents and settings\All Users\Application Data\Net Protector\Md5GUSgx.db
C:\zv
c:\zv\FastScan.log
c:\zv\fs1.log
c:\zv\huristic.log
c:\zv\Mem\1XConfig.exe.Mem
c:\zv\Mem\aawservice.exe.Mem
c:\zv\Mem\alg.exe.Mem
c:\zv\Mem\ati2evxx.exe.Mem
c:\zv\Mem\BlueSoleil.exe.Mem
c:\zv\Mem\BTNtService.exe.Mem
c:\zv\Mem\CHKVRTB.EXE.Mem
c:\zv\Mem\cmd.exe.Mem
c:\zv\Mem\csrss.exe.Mem
c:\zv\Mem\ctfmon.exe.Mem
c:\zv\Mem\Dmem.exe.Mem
c:\zv\Mem\EvtEng.exe.Mem
c:\zv\Mem\explorer.exe.Mem
c:\zv\Mem\GoogleToolbarNotifier.exe.Mem
c:\zv\Mem\GrooveMonitor.exe.Mem
c:\zv\Mem\iFrmewrk.exe.Mem
c:\zv\Mem\IoctlSvc.exe.Mem
c:\zv\Mem\jusched.exe.Mem
c:\zv\Mem\lsass.exe.Mem
c:\zv\Mem\mcagent.exe.Mem
c:\zv\Mem\mcmscsvc.exe.Mem
c:\zv\Mem\McNASvc.exe.Mem
c:\zv\Mem\McProxy.exe.Mem
c:\zv\Mem\Mcshield.exe.Mem
c:\zv\Mem\mcsysmon.exe.Mem
c:\zv\Mem\mdm.exe.Mem
c:\zv\Mem\mem.log
c:\zv\Mem\MpfSrv.exe.Mem
c:\zv\Mem\Notepad.exe.Mem
c:\zv\Mem\OneBtn.exe.Mem
c:\zv\Mem\pctsTray.exe.Mem
c:\zv\Mem\QBCFMonitorService.exe.Mem
c:\zv\Mem\quickset.exe.Mem
c:\zv\Mem\RegSrvc.exe.Mem
c:\zv\Mem\S24EvMon.exe.Mem
c:\zv\Mem\services.exe.Mem
c:\zv\Mem\smss.exe.Mem
c:\zv\Mem\snmp.exe.Mem
c:\zv\Mem\spoolsv.exe.Mem
c:\zv\Mem\sqlbrowser.exe.Mem
c:\zv\Mem\sqlwriter.exe.Mem
c:\zv\Mem\svchost.exe.Mem
c:\zv\Mem\TeaTimer.exe.Mem
c:\zv\Mem\tfswctrl.exe.Mem
c:\zv\Mem\virto2.exe.Mem
c:\zv\Mem\vsnpstd.exe.Mem
c:\zv\Mem\winlogon.exe.Mem
c:\zv\Mem\WLKEEPER.exe.Mem
c:\zv\Mem\wmiprvse.exe.Mem
c:\zv\Mem\wuauclt.exe.Mem
c:\zv\Mem\ZCfgSvc.exe.Mem
c:\zv\Mem\zzz.exe.Mem
c:\zv\ProcName.log
c:\zv\REMDRV.LOG
c:\zv\Virto2\AIIR.DLL
c:\zv\Virto2\all_ext.reg
c:\zv\Virto2\CHKVRTB.EXE
c:\zv\Virto2\DisAsm.dll
c:\zv\Virto2\Dmem.exe
c:\zv\Virto2\exe_only.reg
c:\zv\Virto2\Krnlobj.db
c:\zv\Virto2\NPEXLIST.LST
c:\zv\Virto2\OLLY.DLL
c:\zv\Virto2\PClean.dll
c:\zv\Virto2\Report\18-09-2009_10-04-09_ScanFolder.log
c:\zv\Virto2\Report\18-09-2009_10-04-33_ScanPC.log
c:\zv\Virto2\virsgx00.db
c:\zv\Virto2\virto.CMD
c:\zv\Virto2\zzz.exe
C:\ZVDefs
.
((((((((((((((((((((((((( Files Created from 2009-09-11 to 2009-10-11 )))))))))))))))))))))))))))))))
.
2009-10-11 15:56 . 2009-10-11 15:55 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-11 13:39 . 2009-10-11 13:39 -------- d-----w- c:\program files\ESET
2009-10-11 13:17 . 2009-10-11 13:17 -------- d-----w- C:\Sun
2009-10-10 15:07 . 2009-10-10 15:07 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-05 10:29 . 2009-10-05 10:33 -------- d-----w- C:\Registry Backup
2009-10-05 02:34 . 2009-10-09 19:20 -------- d--h--w- c:\windows\PIF
2009-10-05 01:36 . 2009-10-05 01:36 -------- d-----w- c:\program files\Trend Micro
2009-10-04 12:47 . 2009-10-04 12:47 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-10-04 11:48 . 2009-10-04 11:48 -------- d-----w- c:\program files\Alwil Software
2009-10-03 22:48 . 2009-10-01 14:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-25 11:40 . 2009-09-25 11:40 -------- d-----w- C:\$AVG8.VAULT$
2009-09-25 07:16 . 2009-10-03 22:49 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-25 07:16 . 2009-10-03 22:47 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-09-25 07:16 . 2009-10-03 22:49 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-25 07:16 . 2009-10-03 22:49 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-25 07:16 . 2009-10-03 22:49 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-25 07:15 . 2009-10-11 12:09 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-25 07:15 . 2009-09-25 07:15 -------- d-----w- c:\program files\AVG
2009-09-25 07:15 . 2009-10-10 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-23 06:06 . 2009-09-23 06:09 -------- d-----w- c:\windows\system32\NtmsData
2009-09-20 07:17 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-09-18 14:17 . 2009-09-18 14:17 -------- d-sh--w- c:\documents and settings\Guest\IETldCache
2009-09-17 11:12 . 2009-09-17 11:12 -------- d-----w- C:\Combo-Fix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-11 16:10 . 2007-12-24 17:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-11 16:07 . 2007-12-24 17:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-11 15:55 . 2005-03-31 07:14 -------- d-----w- c:\program files\Java
2009-10-11 15:00 . 2009-06-25 19:57 -------- d-----w- c:\documents and settings\Eli\Application Data\Skype
2009-10-11 12:37 . 2007-12-24 02:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-10-11 12:19 . 2005-04-10 15:12 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-10 15:08 . 2007-12-24 16:58 -------- d-----w- c:\program files\Lavasoft
2009-10-10 15:06 . 2007-12-24 16:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-10 13:04 . 2008-12-12 00:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-10 12:08 . 2007-05-03 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-05 01:54 . 2007-12-24 02:46 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-04 10:19 . 2008-04-09 02:09 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-04 01:03 . 2005-11-18 21:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-03 23:10 . 2007-12-25 04:12 -------- d-----w- c:\program files\Spyware Doctor
2009-09-18 14:17 . 2008-05-27 15:05 8224 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-10 18:54 . 2008-12-12 00:12 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2008-12-12 00:12 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 01:44 . 2005-04-10 14:18 97536 ----a-w- c:\documents and settings\Eli\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2004-08-04 11:00 204800 ------w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2004-08-04 11:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 11:00 286208 ------w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-10-10_12.31.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-11 16:12 . 2009-10-11 16:12 16384 c:\windows\Temp\Perflib_Perfdata_750.dat
+ 2009-10-11 13:14 . 2009-10-11 13:14 84661 c:\windows\SYSTEM32\Macromed\Flash\uninstall_plugin.exe
- 2009-03-16 02:16 . 2009-03-16 02:16 84661 c:\windows\SYSTEM32\Macromed\Flash\uninstall_plugin.exe
- 2007-04-13 19:19 . 2008-03-21 22:36 12632 c:\windows\SYSTEM32\lsdelete.exe
+ 2008-05-16 15:58 . 2008-05-16 15:58 12632 c:\windows\SYSTEM32\lsdelete.exe
+ 2008-04-29 15:20 . 2008-04-29 15:20 15648 c:\windows\SYSTEM32\DRIVERS\NSDriver.sys
+ 2008-04-29 15:19 . 2008-04-29 15:19 15648 c:\windows\SYSTEM32\DRIVERS\Awrtrd.sys
+ 2008-04-29 15:19 . 2008-04-29 15:19 12960 c:\windows\SYSTEM32\DRIVERS\Awrtpd.sys
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\SYSTEM32\Macromed\Flash\NPSWF32_FlashUtil.exe
- 2004-08-04 11:00 . 2009-03-08 08:33 726528 c:\windows\SYSTEM32\jscript.dll
+ 2004-08-04 11:00 . 2009-06-22 06:44 726528 c:\windows\SYSTEM32\jscript.dll
+ 2009-10-11 15:56 . 2009-10-11 15:55 149280 c:\windows\SYSTEM32\javaws.exe
+ 2009-10-11 15:56 . 2009-10-11 15:55 145184 c:\windows\SYSTEM32\javaw.exe
+ 2009-10-11 15:56 . 2009-10-11 15:55 145184 c:\windows\SYSTEM32\java.exe
- 2008-05-09 10:53 . 2009-03-08 08:33 726528 c:\windows\SYSTEM32\DLLCACHE\jscript.dll
+ 2008-05-09 10:53 . 2009-06-22 06:44 726528 c:\windows\SYSTEM32\DLLCACHE\jscript.dll
+ 2009-10-11 12:24 . 2009-10-11 12:24 691200 c:\windows\Installer\294e7.msi
+ 2009-10-11 12:24 . 2009-10-11 12:24 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-800000000003}\ARPPRODUCTICON.exe
+ 2009-10-11 12:20 . 2009-10-11 12:27 295606 c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A81300000003}\SC_Reader.exe
+ 2007-01-23 15:39 . 2007-01-23 15:39 443904 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\JP2KLib.dll
+ 2009-10-10 12:37 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2009-10-10 12:37 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2009-10-10 12:37 . 2009-03-08 08:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\SYSTEM32\Macromed\Flash\NPSWF32.dll
+ 2009-10-11 15:55 . 2009-10-11 15:55 1757696 c:\windows\Installer\6c73d.msi
+ 2009-10-11 12:26 . 2009-10-11 12:26 9680384 c:\windows\Installer\29513.msp
+ 2009-10-11 12:25 . 2009-10-11 12:25 1711616 c:\windows\Installer\294f7.msp
+ 2009-10-11 12:23 . 2009-10-11 12:23 4733440 c:\windows\Installer\294e2.msp
+ 2009-10-10 15:08 . 2009-10-10 15:08 1947648 c:\windows\Installer\261a5f.msi
+ 2009-10-11 12:19 . 2009-10-11 12:19 4192256 c:\windows\Installer\157402.msi
+ 2008-10-15 04:42 . 2008-10-15 04:42 13219184 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7448A3100000030\8.1.3\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"Prolific2571_OneButton"="c:\program files\Prolific\PL2571 One Button\OneBtn.exe" [2007-04-12 33280]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-03 2023704]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-11-04 155648]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-09-09 623880]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset.exe" [2005-02-07 606208]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2008-5-14 1183744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-03 22:49 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office\\FRONTPG.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP

xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP

xpsp2res.dll,-22016
"500:UDP"= 500:UDP

xpsp2res.dll,-22017
R0 AvgRkx86;avgrkx86.sys;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [25/09/2009 3:16 AM 12552]
R0 PCTCore;PCTools KDS;c:\windows\SYSTEM32\DRIVERS\PCTCore.sys [27/06/2009 8:45 PM 130936]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [25/09/2009 3:16 AM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [25/09/2009 3:16 AM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [03/10/2009 6:47 PM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [03/10/2009 6:47 PM 297752]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 8:19 PM 13592]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\SYSTEM32\DRIVERS\IcdUsb2.sys [17/10/2008 11:43 AM 39048]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [02/04/2008 7:30 PM 348752]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-24 00:49]
2009-09-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.ashtro.ca/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: calgary.ca\ctx
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Eli\Application Data\Mozilla\Firefox\Profiles\ugu21xif.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.ashtro.ca
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-11 12:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3156687593-2781840335-3711123584-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-3156687593-2781840335-3711123584-1006\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-3156687593-2781840335-3711123584-1006)
@Allowed: (Read) (S-1-5-21-3156687593-2781840335-3711123584-1006)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1044)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2009-10-11 12:42
ComboFix-quarantined-files.txt 2009-10-11 16:42
ComboFix2.txt 2009-10-11 13:07
ComboFix3.txt 2009-10-10 12:41
Pre-Run: 31,230,709,760 bytes free
Post-Run: 31,181,463,552 bytes free
Current=4 Default=4 Failed=1 LastKnownGood=3 Sets=1,2,3,4
304 --- E O F --- 2009-10-11 11:42
=====================================================
DDS log - After removing all Java except 1.
DDS (Ver_09-09-29.01) - NTFSx86
Run by Eli at 12:44:35.59 on 11/10/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1431 [GMT -4:00]
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\SYSTEM32\IoctlSvc.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\snmp.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Eli\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.ashtro.ca/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar4.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar4.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [snpstd] c:\windows\vsnpstd.exe
mRun: [Prolific2571_OneButton] c:\program files\prolific\pl2571 one button\OneBtn.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Dell QuickSet] c:\program files\dell\quickset\Quickset.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueso~1.lnk - c:\program files\ivt corporation\bluesoleil\BlueSoleil.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mic273~1\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: calgary.ca\ctx
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-latest.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\eli\applic~1\mozilla\firefox\profiles\ugu21xif.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.ashtro.ca
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
============= SERVICES / DRIVERS ===============
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-9-25 12552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-6-27 130936]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-9-25 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-9-25 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-9-25 108552]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-10-3 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-10-3 297752]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\drivers\IcdUsb2.sys [2008-10-17 39048]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2007-12-25 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-10-17 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2007-12-25 81288]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-4-2 348752]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-4-2 1095560]
=============== Created Last 30 ================
2009-10-11 11:56 411,368 a------- c:\windows\system32\deploytk.dll
2009-10-11 11:56 73,728 a------- c:\windows\system32\javacpl.cpl
2009-10-11 09:39 <DIR> --d----- c:\program files\ESET
2009-10-11 09:18 95 a------- c:\windows\system32\productregistry
2009-10-11 09:17 <DIR> --d----- C:\Sun
2009-10-10 11:07 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-10-05 06:29 <DIR> --d----- C:\Registry Backup
2009-10-04 23:35 229,888 a------- c:\windows\PEV.exe
2009-10-04 23:35 161,792 a------- c:\windows\SWREG.exe
2009-10-04 23:35 98,816 a------- c:\windows\sed.exe
2009-10-04 22:34 <DIR> --d-h--- c:\windows\PIF
2009-10-04 21:36 <DIR> --d----- c:\program files\Trend Micro
2009-10-04 08:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\F-Secure
2009-10-03 18:48 195,440 -------- c:\windows\system32\MpSigStub.exe
2009-09-25 07:40 <DIR> --d----- C:\$AVG8.VAULT$
2009-09-25 03:16 12,552 a------- c:\windows\system32\drivers\avgrkx86.sys
2009-09-25 03:16 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-09-25 03:16 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-09-25 03:16 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
2009-09-25 03:15 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-09-25 03:15 <DIR> --d----- c:\program files\AVG
2009-09-25 03:15 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2009-09-23 11:26 7,680 a--sh--- c:\windows\Thumbs.db
2009-09-23 02:06 <DIR> --d----- c:\windows\system32\NtmsData
2009-09-20 03:17 153,088 -------- c:\windows\system32\dllcache\triedit.dll
2009-09-17 07:15 <DIR> a-dshr-- C:\cmdcons
2009-09-17 07:12 <DIR> --d----- C:\Combo-Fix
==================== Find3M ====================
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-08-05 05:01 204,800 -------- c:\windows\system32\mswebdvd.dll
2009-08-05 05:01 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-19 18:48 11,067,392 -------- c:\windows\system32\dllcache\ieframe.dll
2009-07-19 09:18 5,937,152 -------- c:\windows\system32\dllcache\mshtml.dll
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-17 15:01 58,880 -------- c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 -------- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 -------- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 -------- c:\windows\system32\dllcache\wmpdxm.dll
2008-05-13 22:17 61,224 a------- c:\documents and settings\eli\GoToAssistDownloadHelper.exe
2008-08-06 09:34 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008080620080807\index.dat
============= FINISH: 12:45:06.90 ===============