ComboFix 09-10-24.01 - Hasufel 10/25/2009 9:08.1.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2046.1068 [GMT -4:00]
Running from: c:\users\Hasufel\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\$recycle.bin\S-1-5-21-613219775-4175824793-1485929129-1007
c:\users\Hasufel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.lnk
c:\windows\search_res.txt
c:\windows\system32\cpcp.cpo
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\wpcap.dll
Infected copy of c:\windows\system32\cngaudit.dll was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-09-25 to 2009-10-25 )))))))))))))))))))))))))))))))
.
2009-10-25 13:18 . 2009-10-25 13:22 -------- d-----w- c:\users\Hasufel\AppData\Local\temp
2009-10-25 13:18 . 2009-10-25 13:18 -------- d-----w- c:\users\Guest\AppData\Local\temp
2009-10-25 13:18 . 2009-10-25 13:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-25 12:51 . 2009-10-25 13:04 -------- d-----w- C:\32788R22FWJFW
2009-10-25 06:39 . 2009-10-25 06:39 -------- d-----w- c:\users\Hasufel\Office Genuine Advantage
2009-10-22 09:39 . 2009-10-22 09:39 -------- d-----w- c:\users\Hasufel\PA-IMAGiNE
2009-10-21 13:48 . 2009-10-21 13:48 -------- d-----w- c:\users\Hasufel\AppData\Roaming\Malwarebytes
2009-10-21 13:48 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-21 13:48 . 2009-10-21 13:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-21 13:48 . 2009-10-21 13:48 -------- d-----w- c:\programdata\Malwarebytes
2009-10-21 13:48 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-19 23:27 . 2009-10-19 23:27 -------- d-----w- C:\Poker
2009-10-19 20:57 . 2009-10-19 20:57 -------- d-----w- c:\program files\Trend Micro
2009-10-16 01:16 . 2009-10-16 01:16 534 ----a-w- c:\windows\eReg.dat
2009-10-16 01:16 . 2009-10-16 01:16 -------- d-----w- c:\program files\Maxis
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-25 12:59 . 2008-05-15 16:44 -------- d-----w- c:\programdata\avg8
2009-10-20 10:25 . 2009-01-23 14:02 1356 ----a-w- c:\users\Hasufel\AppData\Local\d3d9caps.dat
2009-10-19 22:00 . 2008-01-10 18:01 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-19 22:00 . 2009-09-19 11:38 -------- d-----w- c:\program files\Spybot
2009-10-17 23:21 . 2008-03-18 05:33 -------- d-----w- c:\users\Hasufel\AppData\Roaming\BitTorrent
2009-10-17 23:20 . 2008-01-11 00:20 -------- d-----w- c:\program files\BitLord
2009-10-16 23:46 . 2008-01-29 21:43 -------- d-----w- c:\users\Hasufel\AppData\Roaming\LimeWire
2009-09-19 12:09 . 2009-09-19 12:09 -------- d-----w- c:\program files\ERUNT
2009-09-19 11:32 . 2008-01-10 18:01 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-19 11:20 . 2008-01-05 23:50 135572 ----a-w- c:\windows\DUMP4611.tmp
2009-09-19 10:57 . 2009-09-19 10:51 -------- d-----w- c:\programdata\Lavasoft
2009-09-19 10:57 . 2009-03-20 10:29 -------- d-----w- c:\programdata\WildTangent
2009-09-19 10:51 . 2009-09-19 10:51 -------- d-----w- c:\program files\Lavasoft
2009-09-19 10:50 . 2008-01-10 18:18 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-18 06:24 . 2008-04-30 05:17 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-18 06:23 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-18 05:37 . 2008-01-17 18:04 -------- d-----w- c:\programdata\Microsoft Help
2009-09-18 05:09 . 2009-01-22 23:45 -------- d-----w- c:\programdata\DriverScanner
2009-09-18 04:58 . 2009-09-18 04:58 117744 ----a-w- c:\users\Hasufel\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-17 07:40 . 2008-01-10 05:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-28 12:39 . 2009-09-18 05:24 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-18 05:24 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-15 12:54 . 2008-05-15 16:44 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-15 12:54 . 2008-05-15 16:44 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-15 12:54 . 2008-05-15 16:44 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-14 17:07 . 2009-09-18 05:25 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-18 05:25 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-18 05:25 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-18 05:25 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-18 05:25 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-18 05:25 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-18 05:25 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-18 05:25 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-18 05:25 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-18 05:25 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-12 22:06 . 2009-02-26 06:43 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-08-12 22:06 . 2009-02-26 06:43 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-08-12 22:06 . 2009-02-26 06:43 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-08-07 23:51 . 2009-08-07 23:51 15308424 ----a-w- c:\windows\system32\xlive.dll
2009-08-07 23:51 . 2009-08-07 23:51 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-08-03 19:07 . 2009-08-03 19:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 19:07 . 2009-08-03 19:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 19:07 . 2009-08-03 19:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-03-02 19:31 . 2008-03-02 19:31 848 --sha-w- c:\windows\System32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2009-09-19 2468200]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-09-21 55824]
c:\users\Hasufel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
MagicDisc.lnk.disabled [2008-5-14 804]
Registration Assassin's Creed.LNK.disabled [2008-3-31 1053]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-1-10 784912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"WindowsWelcomeCenter"=rundll32.exe oobefldr.dll,ShowWelcomeCenter
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
"<NO NAME>"=
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
"Comrade.exe"=c:\program files\GameSpy\Comrade\Comrade.exe
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun
"PopRock"=c:\users\Hasufel\AppData\Local\Temp\b.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Windows Defender"=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
"D-Link RangeBooster G WDA-2320"=c:\program files\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe
"ANIWZCS2Service"=c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
"SoundMan"=SOUNDMAN.EXE
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"AVG7_CC"=c:\progra~1\Grisoft\AVG7\avgcc.exe /STARTUP
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"Computer Alarm Clock"=
"GameRailClient"=c:\program files\GameRail\Conductor\client\GameRailClient.exe
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"EzPrint"="c:\program files\Lexmark 2600 Series\ezprint.exe"
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-613219775-4175824793-1485929129-1000]
"EnableNotificationsRef"=dword:00000001
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [5/15/2008 12:44 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [4/5/2008 12:23 AM 108552]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot\SDWinSec.exe [9/19/2009 7:38 AM 1153368]
S0 amacpi;Microsoft Away Mode System;c:\windows\System32\drivers\null.sys [4/29/2008 9:39 PM 4608]
S2 AODService;AODService;c:\program files\AMD\OverDrive\AODAssist --> c:\program files\AMD\OverDrive\AODAssist [?]
S2 NinjaVideo Helper.exe;NinjaVideo Helper;"c:\program files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe" --> c:\program files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe [?]
S2 RPCM;Remote Procedure Manager(TPM);c:\program files\Common Files\Microsoft Shared\Speech\csvde.exe --> c:\program files\Common Files\Microsoft Shared\Speech\csvde.exe [?]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\System32\drivers\A3AB.sys [8/25/2005 4:00 PM 466880]
S3 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [4/5/2008 12:23 AM 908056]
S3 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [4/5/2008 12:22 AM 297752]
S3 Ser2rs;Radioshack USB to Serial Driver;c:\windows\System32\drivers\ser2rs.sys [6/25/2007 8:14 AM 76288]
S3 tapgamerail;GameRail Adapter;c:\windows\System32\drivers\tapgamerail.sys [1/10/2008 2:38 PM 32280]
S4 lxbl_device;lxbl_device;c:\windows\system32\lxblcoms.exe -service --> c:\windows\system32\lxblcoms.exe -service [?]
S4 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
S4 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxdnserv.exe [12/5/2007 5:18 AM 98984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
2009-10-25 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-01-10 19:31]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
FF - ProfilePath - c:\users\Hasufel\AppData\Roaming\Mozilla\Firefox\Profiles\i2e32uim.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ninjavideo.net/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\users\Hasufel\AppData\Roaming\Mozilla\Firefox\Profiles\i2e32uim.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-35588938 - c:\programdata\35588938\35588938.exe
HKLM-Run-00251513 - c:\progra~2\00251513\00251513.exe
HKLM-Run-99057131 - c:\programdata\99057131\99057131.exe
AddRemove-bet365poker - c:\poker\Poker at bet365\_SetupPoker_3f8b.exe
AddRemove-Cross Fire_is1 - d:\crossfire\unins000.exe
AddRemove-SystemRequirementsLab - c:\program files\SystemRequirementsLab\Uninstall.exe
AddRemove-Teamspeak 2 RC2_is1 - c:\program files\Teamspeak2_RC2\unins000.exe
AddRemove-WinPcapInst - c:\program files\WinPcap\uninstall.exe
AddRemove-{ECCA8FE7-767A-4C8A-9DAA-BAB60F877C41} - c:\users\Hasufel\AppData\Local\{0E8E33D8-193A-414A-A909-0F101A142D26}\setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-25 09:22
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AODService]
"ImagePath"="c:\program files\AMD\OverDrive\AODAssist"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-613219775-4175824793-1485929129-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:74,4d,ca,38,5c,d1,08,bd,76,b0,57,fd,78,0b,e7,81,c7,10,23,3a,2a,55,19,
92,4e,2a,76,c4,5a,cb,37,4e,69,7d,f9,8c,50,8e,ce,34,4a,f1,ec,d1,e0,7a,82,ca,\
"??"=hex:a9,a2,18,80,1a,48,7d,8c,85,97,1e,47,c1,dd,9d,17
[HKEY_USERS\S-1-5-21-613219775-4175824793-1485929129-1000\Software\SecuROM\License information*]
"datasecu"=hex:be,b8,09,d7,0d,3a,02,c7,98,65,ad,97,e9,27,89,01,6a,3e,f2,48,dc,
1f,47,2e,9a,2b,39,2f,db,3c,30,48,27,ef,2c,c7,ee,1b,a3,a4,90,02,f8,ec,5e,56,\
"rkeysecu"=hex:98,47,44,5b,5e,2d,27,34,8e,ab,c3,5f,53,cf,3f,77
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(2108)
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\Ati2evxx.exe
c:\combofix\CF23123.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-25 9:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-25 13:27
Pre-Run: 32,005,988,352 bytes free
Post-Run: 32,585,121,792 bytes free
- - End Of File - - 77CFD6CEA81E98E72FC95A6EBBE38078