tommytommy
New member
Combofix log
ComboFix 10-06-10.06 - Ashish 06/11/2010 12:38:21.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.191 [GMT -5:00]
Running from: c:\documents and settings\Ashish\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ashish\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-05-11 to 2010-06-11 )))))))))))))))))))))))))))))))
.
2010-06-10 02:30 . 2010-05-06 10:41 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-10 01:58 . 2010-05-06 20:39 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-10 01:58 . 2010-05-06 20:39 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-10 01:58 . 2010-05-06 20:34 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-10 01:58 . 2010-05-06 20:33 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-10 01:58 . 2010-05-06 20:33 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-10 01:58 . 2010-05-06 20:33 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-10 01:58 . 2010-05-06 20:33 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-10 01:58 . 2010-05-06 20:59 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-06-10 01:58 . 2010-05-06 20:59 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-10 01:58 . 2010-06-10 01:58 -------- dc----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-06-10 01:58 . 2010-06-10 01:58 -------- d-----w- c:\program files\Alwil Software
2010-06-06 22:00 . 2010-06-06 22:00 -------- d-----w- c:\documents and settings\Ashish\Local Settings\Application Data\Western_Digital
2010-06-06 21:21 . 2010-06-06 21:21 -------- dc----w- c:\documents and settings\All Users\Application Data\WD_SmartWareCommon
2010-06-06 21:16 . 2010-06-06 21:16 -------- d-----w- c:\documents and settings\Ashish\Application Data\Western Digital
2010-06-06 21:16 . 2010-06-06 21:16 -------- dc----w- c:\documents and settings\All Users\Application Data\Western Digital
2010-06-06 21:15 . 2010-06-06 21:15 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ServiceTest
2010-06-06 21:15 . 2009-02-13 16:02 11520 ----a-w- c:\windows\system32\drivers\wdcsam.sys
2010-06-06 21:14 . 2010-06-06 21:14 -------- d-----w- c:\program files\Western Digital
2010-06-06 21:13 . 2010-06-06 21:13 -------- d-----w- c:\documents and settings\Ashish\Local Settings\Application Data\Western Digital
2010-05-28 23:20 . 2010-05-28 23:20 -------- d-sh--w- c:\documents and settings\Ashish\IECompatCache
2010-05-28 21:03 . 2010-05-28 21:02 411368 ----a-w- c:\windows\system32\deployJava1.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-09 03:26 . 2009-01-03 20:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-09 03:23 . 2009-01-03 20:20 -------- dc----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-09 03:20 . 2009-10-30 22:16 -------- d-----w- c:\program files\QuickTime
2010-06-09 03:20 . 2009-10-30 22:16 -------- dc----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-06-08 15:34 . 2009-09-15 04:41 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-06 18:15 . 2009-03-17 23:42 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee
2010-06-06 17:55 . 2006-08-06 03:21 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-06-06 17:55 . 2006-08-06 03:21 -------- d-----w- c:\program files\Symantec
2010-06-06 17:55 . 2006-08-06 03:21 -------- dc----w- c:\documents and settings\All Users\Application Data\Symantec
2010-06-06 17:28 . 2007-08-04 19:05 -------- d-----w- c:\program files\DivX
2010-06-06 05:00 . 2006-08-06 03:30 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS
2010-06-06 04:50 . 2009-08-29 17:07 -------- d-----w- c:\program files\Veoh Networks
2010-06-06 04:46 . 2007-09-02 15:07 -------- d-----w- c:\program files\Winamp
2010-06-06 04:45 . 2007-11-11 04:54 -------- d-----w- c:\program files\SopCast
2010-06-06 04:44 . 2007-04-04 03:30 -------- d-----r- c:\program files\Skype
2010-06-06 04:44 . 2007-04-04 03:30 -------- dc----w- c:\documents and settings\All Users\Application Data\Skype
2010-06-06 04:41 . 2009-10-30 22:13 -------- d-----w- c:\program files\Common Files\Apple
2010-05-28 22:15 . 2006-08-06 03:31 -------- d-----w- c:\program files\Google
2010-05-28 21:16 . 2006-10-18 05:30 -------- d-----w- c:\program files\Common Files\Real
2010-05-28 21:04 . 2007-12-14 07:12 -------- d-----w- c:\program files\Common Files\Java
2010-05-28 21:02 . 2007-12-14 07:12 -------- d-----w- c:\program files\Java
2010-05-28 20:48 . 2009-01-20 00:37 -------- d-----w- c:\program files\uTorrent
2010-05-28 20:48 . 2009-01-20 00:37 -------- d-----w- c:\documents and settings\Ashish\Application Data\uTorrent
2010-05-27 23:25 . 2006-08-20 04:55 -------- d-----w- c:\program files\Yahoo!
2010-05-25 00:44 . 2009-03-19 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-24 19:03 . 2008-05-13 00:12 -------- d-----w- c:\documents and settings\Ashish\Application Data\ZoomBrowser EX
2010-05-24 03:12 . 2008-05-13 00:11 -------- d-----w- c:\documents and settings\Ashish\Application Data\CameraWindowDC
2010-05-06 10:41 . 1980-01-01 07:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 1980-01-01 07:00 1851264 ------w- c:\windows\system32\win32k.sys
2010-04-29 20:39 . 2009-03-19 21:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39 . 2009-03-19 21:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 16:34 . 2010-04-23 16:34 -------- d-----w- c:\program files\Safer Networking
2010-04-20 05:30 . 1980-01-01 07:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-11 16:54 . 2006-08-15 16:13 25296 ----a-w- c:\documents and settings\Ashish\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-28 22:58 . 2010-03-28 22:58 56 ---ha-w- c:\windows\system32\ezsidmv.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Ashish\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-17 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 512000]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2005-10-29 864256]
"TpShocks"="TpShocks.exe" [2005-11-07 106496]
"TP4EX"="tp4ex.exe" [2005-10-17 65536]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 237568]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-03-09 94208]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-12-15 925696]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"suScheduler"="c:\program files\ThinkVantage\SystemUpdate\UCLauncher.exe" [2005-08-02 40960]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2006-01-25 106496]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-08-01 122940]
"cssauth"="c:\program files\IBM ThinkVantage\Client Security Solution\cssauth.exe" [2005-12-22 1996336]
"PDService.exe"="c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe" [2005-11-15 49152]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-12-07 151552]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-12-07 208896]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-04-17 98304]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2006-04-17 409600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2005-11-1 581693]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-5 24576]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-12-08 21:59 39936 ------w- c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ------w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 03:16 24576 ------w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ psqlpwd scecli
[HKLM\~\startupfolder\C:^Documents and Settings^Ashish^Start Menu^Programs^Startup^Monitor My eRooms (V7).lnk]
path=c:\documents and settings\Ashish\Start Menu\Programs\Startup\Monitor My eRooms (V7).lnk
backup=c:\windows\pss\Monitor My eRooms (V7).lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-09-25 06:11 132496 ------w- c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IBM ThinkVantage\\SafeGuard PrivateDisk\\pdservice.exe"=
"c:\\WINDOWS\\system32\\TpShocks.exe"=
"c:\\Program Files\\IBM ThinkVantage\\Client Security Solution\\pwmgr.exe"=
"c:\\Documents and Settings\\Ashish\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Ashish\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6/9/2010 8:58 PM 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/9/2010 8:58 PM 19024]
R2 PrivateDisk;PrivateDisk;c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\privatediskm.sys [11/15/2005 3:11 PM 46142]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [12/21/2005 6:45 PM 3968]
R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [12/8/2005 4:44 PM 3328]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [11/13/2009 11:28 AM 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [6/16/2009 8:58 AM 20480]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Ashish\Desktop\SysProt\SysProtDrv.sys [6/5/2010 2:58 PM 44288]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [6/6/2010 4:15 PM 11520]
.
Contents of the 'Scheduled Tasks' folder
2010-06-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2831233549-764648575-2230604533-1005Core.job
- c:\documents and settings\Ashish\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-17 16:51]
2010-06-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2831233549-764648575-2230604533-1005UA.job
- c:\documents and settings\Ashish\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-17 16:51]
2010-06-11 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2006-08-06 08:12]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: att.net
Trusted Zone: sbcglobal.net
Trusted Zone: yahoo.com\clientapps
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Ashish\Application Data\Mozilla\Firefox\Profiles\0rqw79jb.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US
fficial
FF - plugin: c:\documents and settings\Ashish\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Ashish\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-11 12:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(924)
c:\windows\system32\vrlogon.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\windows\system32\biologon.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\windows\system32\tphklock.dll
- - - - - - - > 'lsass.exe'(980)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
- - - - - - - > 'explorer.exe'(1048)
c:\windows\system32\WININET.dll
c:\windows\system32\PROCHLP.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\System32\TPHDEXLG.EXE
c:\windows\system32\TpKmpSVC.exe
c:\program files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
c:\program files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
c:\program files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
c:\program files\ThinkVantage\SystemUpdate\UCLauncherService.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\IBM ThinkVantage\Common\Logger\logmon.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\TpShocks.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\windows\system32\rundll32.exe
c:\program files\IBM ThinkVantage\Client Security Solution\pwmgr.exe
.
**************************************************************************
.
Completion time: 2010-06-11 13:07:35 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-11 18:07
ComboFix2.txt 2010-06-10 21:54
ComboFix3.txt 2010-06-09 04:34
Pre-Run: 15,432,163,328 bytes free
Post-Run: 15,458,590,720 bytes free
- - End Of File - - 396368FEC1FE88F6CC763215AB1703EF
ComboFix 10-06-10.06 - Ashish 06/11/2010 12:38:21.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.191 [GMT -5:00]
Running from: c:\documents and settings\Ashish\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ashish\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-05-11 to 2010-06-11 )))))))))))))))))))))))))))))))
.
2010-06-10 02:30 . 2010-05-06 10:41 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-10 01:58 . 2010-05-06 20:39 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-10 01:58 . 2010-05-06 20:39 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-10 01:58 . 2010-05-06 20:34 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-10 01:58 . 2010-05-06 20:33 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-10 01:58 . 2010-05-06 20:33 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-10 01:58 . 2010-05-06 20:33 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-10 01:58 . 2010-05-06 20:33 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-10 01:58 . 2010-05-06 20:59 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-06-10 01:58 . 2010-05-06 20:59 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-10 01:58 . 2010-06-10 01:58 -------- dc----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-06-10 01:58 . 2010-06-10 01:58 -------- d-----w- c:\program files\Alwil Software
2010-06-06 22:00 . 2010-06-06 22:00 -------- d-----w- c:\documents and settings\Ashish\Local Settings\Application Data\Western_Digital
2010-06-06 21:21 . 2010-06-06 21:21 -------- dc----w- c:\documents and settings\All Users\Application Data\WD_SmartWareCommon
2010-06-06 21:16 . 2010-06-06 21:16 -------- d-----w- c:\documents and settings\Ashish\Application Data\Western Digital
2010-06-06 21:16 . 2010-06-06 21:16 -------- dc----w- c:\documents and settings\All Users\Application Data\Western Digital
2010-06-06 21:15 . 2010-06-06 21:15 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ServiceTest
2010-06-06 21:15 . 2009-02-13 16:02 11520 ----a-w- c:\windows\system32\drivers\wdcsam.sys
2010-06-06 21:14 . 2010-06-06 21:14 -------- d-----w- c:\program files\Western Digital
2010-06-06 21:13 . 2010-06-06 21:13 -------- d-----w- c:\documents and settings\Ashish\Local Settings\Application Data\Western Digital
2010-05-28 23:20 . 2010-05-28 23:20 -------- d-sh--w- c:\documents and settings\Ashish\IECompatCache
2010-05-28 21:03 . 2010-05-28 21:02 411368 ----a-w- c:\windows\system32\deployJava1.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-09 03:26 . 2009-01-03 20:20 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-09 03:23 . 2009-01-03 20:20 -------- dc----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-09 03:20 . 2009-10-30 22:16 -------- d-----w- c:\program files\QuickTime
2010-06-09 03:20 . 2009-10-30 22:16 -------- dc----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-06-08 15:34 . 2009-09-15 04:41 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-06 18:15 . 2009-03-17 23:42 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee
2010-06-06 17:55 . 2006-08-06 03:21 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-06-06 17:55 . 2006-08-06 03:21 -------- d-----w- c:\program files\Symantec
2010-06-06 17:55 . 2006-08-06 03:21 -------- dc----w- c:\documents and settings\All Users\Application Data\Symantec
2010-06-06 17:28 . 2007-08-04 19:05 -------- d-----w- c:\program files\DivX
2010-06-06 05:00 . 2006-08-06 03:30 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS
2010-06-06 04:50 . 2009-08-29 17:07 -------- d-----w- c:\program files\Veoh Networks
2010-06-06 04:46 . 2007-09-02 15:07 -------- d-----w- c:\program files\Winamp
2010-06-06 04:45 . 2007-11-11 04:54 -------- d-----w- c:\program files\SopCast
2010-06-06 04:44 . 2007-04-04 03:30 -------- d-----r- c:\program files\Skype
2010-06-06 04:44 . 2007-04-04 03:30 -------- dc----w- c:\documents and settings\All Users\Application Data\Skype
2010-06-06 04:41 . 2009-10-30 22:13 -------- d-----w- c:\program files\Common Files\Apple
2010-05-28 22:15 . 2006-08-06 03:31 -------- d-----w- c:\program files\Google
2010-05-28 21:16 . 2006-10-18 05:30 -------- d-----w- c:\program files\Common Files\Real
2010-05-28 21:04 . 2007-12-14 07:12 -------- d-----w- c:\program files\Common Files\Java
2010-05-28 21:02 . 2007-12-14 07:12 -------- d-----w- c:\program files\Java
2010-05-28 20:48 . 2009-01-20 00:37 -------- d-----w- c:\program files\uTorrent
2010-05-28 20:48 . 2009-01-20 00:37 -------- d-----w- c:\documents and settings\Ashish\Application Data\uTorrent
2010-05-27 23:25 . 2006-08-20 04:55 -------- d-----w- c:\program files\Yahoo!
2010-05-25 00:44 . 2009-03-19 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-24 19:03 . 2008-05-13 00:12 -------- d-----w- c:\documents and settings\Ashish\Application Data\ZoomBrowser EX
2010-05-24 03:12 . 2008-05-13 00:11 -------- d-----w- c:\documents and settings\Ashish\Application Data\CameraWindowDC
2010-05-06 10:41 . 1980-01-01 07:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 1980-01-01 07:00 1851264 ------w- c:\windows\system32\win32k.sys
2010-04-29 20:39 . 2009-03-19 21:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39 . 2009-03-19 21:30 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 16:34 . 2010-04-23 16:34 -------- d-----w- c:\program files\Safer Networking
2010-04-20 05:30 . 1980-01-01 07:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-11 16:54 . 2006-08-15 16:13 25296 ----a-w- c:\documents and settings\Ashish\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-28 22:58 . 2010-03-28 22:58 56 ---ha-w- c:\windows\system32\ezsidmv.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Ashish\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-17 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 512000]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2005-10-29 864256]
"TpShocks"="TpShocks.exe" [2005-11-07 106496]
"TP4EX"="tp4ex.exe" [2005-10-17 65536]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 237568]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-03-09 94208]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-12-15 925696]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"suScheduler"="c:\program files\ThinkVantage\SystemUpdate\UCLauncher.exe" [2005-08-02 40960]
"LPManager"="c:\progra~1\THINKV~2\PrdCtr\LPMGR.exe" [2006-01-25 106496]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-08-01 122940]
"cssauth"="c:\program files\IBM ThinkVantage\Client Security Solution\cssauth.exe" [2005-12-22 1996336]
"PDService.exe"="c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\pdservice.exe" [2005-11-15 49152]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-12-07 151552]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-12-07 208896]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-04-17 98304]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2006-04-17 409600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2005-11-1 581693]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-5 24576]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-11-13 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-11-13 9117504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-12-08 21:59 39936 ------w- c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ------w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 03:16 24576 ------w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ psqlpwd scecli
[HKLM\~\startupfolder\C:^Documents and Settings^Ashish^Start Menu^Programs^Startup^Monitor My eRooms (V7).lnk]
path=c:\documents and settings\Ashish\Start Menu\Programs\Startup\Monitor My eRooms (V7).lnk
backup=c:\windows\pss\Monitor My eRooms (V7).lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-09-25 06:11 132496 ------w- c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IBM ThinkVantage\\SafeGuard PrivateDisk\\pdservice.exe"=
"c:\\WINDOWS\\system32\\TpShocks.exe"=
"c:\\Program Files\\IBM ThinkVantage\\Client Security Solution\\pwmgr.exe"=
"c:\\Documents and Settings\\Ashish\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Ashish\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [6/9/2010 8:58 PM 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/9/2010 8:58 PM 19024]
R2 PrivateDisk;PrivateDisk;c:\program files\IBM ThinkVantage\SafeGuard PrivateDisk\privatediskm.sys [11/15/2005 3:11 PM 46142]
R2 smi2;smi2;c:\program files\SMI2\smi2.sys [12/21/2005 6:45 PM 3968]
R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [12/8/2005 4:44 PM 3328]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [11/13/2009 11:28 AM 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [6/16/2009 8:58 AM 20480]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Ashish\Desktop\SysProt\SysProtDrv.sys [6/5/2010 2:58 PM 44288]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [6/6/2010 4:15 PM 11520]
.
Contents of the 'Scheduled Tasks' folder
2010-06-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2831233549-764648575-2230604533-1005Core.job
- c:\documents and settings\Ashish\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-17 16:51]
2010-06-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2831233549-764648575-2230604533-1005UA.job
- c:\documents and settings\Ashish\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-17 16:51]
2010-06-11 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2006-08-06 08:12]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: att.net
Trusted Zone: sbcglobal.net
Trusted Zone: yahoo.com\clientapps
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Ashish\Application Data\Mozilla\Firefox\Profiles\0rqw79jb.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

FF - plugin: c:\documents and settings\Ashish\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Ashish\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-11 12:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(924)
c:\windows\system32\vrlogon.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\windows\system32\biologon.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\windows\system32\tphklock.dll
- - - - - - - > 'lsass.exe'(980)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
- - - - - - - > 'explorer.exe'(1048)
c:\windows\system32\WININET.dll
c:\windows\system32\PROCHLP.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\System32\TPHDEXLG.EXE
c:\windows\system32\TpKmpSVC.exe
c:\program files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
c:\program files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
c:\program files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
c:\program files\ThinkVantage\SystemUpdate\UCLauncherService.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\IBM ThinkVantage\Common\Logger\logmon.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\system32\TpShocks.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\windows\system32\rundll32.exe
c:\program files\IBM ThinkVantage\Client Security Solution\pwmgr.exe
.
**************************************************************************
.
Completion time: 2010-06-11 13:07:35 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-11 18:07
ComboFix2.txt 2010-06-10 21:54
ComboFix3.txt 2010-06-09 04:34
Pre-Run: 15,432,163,328 bytes free
Post-Run: 15,458,590,720 bytes free
- - End Of File - - 396368FEC1FE88F6CC763215AB1703EF