Hi _Rip_Chain_,
I ran ComboFix, the log is below.
A question about the Kaspersky Online scan. I started it and let it go for 14 hours, but it had only done 13 files. I restarted thinking it may have locked up. It's now at 8.5 hours and at 13 files again:
Now scanning: ABP480N5.SY_/abp480n5.sys
Location: C:\cmdcons
Is this normal? How long should I let it go for? Thanks!
`````````````````
ComboFix 09-03-14.01 - Katy & Steven 2009-03-15 2:51:59.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1055 [GMT -5:00]
Running from: c:\documents and settings\Katy & Steven\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Katy & Steven\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *enabled*
* Created a new restore point
FILE ::
c:\docume~1\KATY&S~1\LOCALS~1\Temp\ewdmaudn.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EWDMAUDN
-------\Service_ewdmaudn
((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 )))))))))))))))))))))))))))))))
.
2009-03-04 00:44 . 2009-03-04 00:44 <DIR> d-------- c:\documents and settings\Katy & Steven\Application Data\Malwarebytes
2009-03-04 00:43 . 2009-03-04 00:43 <DIR> d-------- C:\VundoFix Backups
2009-03-04 00:43 . 2009-03-04 00:43 <DIR> d-------- c:\documents and settings\Steven Admin\Application Data\Yahoo!
2009-03-04 00:37 . 2009-03-04 00:37 <DIR> d-------- c:\windows\system32\IOSUBSYS
2009-02-25 21:30 . 2009-02-25 21:31 <DIR> d-------- c:\windows\ERUNT
2009-02-25 21:19 . 2009-03-04 00:49 <DIR> d-------- C:\SDFix
2009-02-20 00:44 . 2009-02-20 00:45 <DIR> d-------- C:\rsit
2009-02-18 16:44 . 2009-02-18 16:44 <DIR> d-------- c:\documents and settings\Steven Admin\Application Data\Malwarebytes
2009-02-16 17:44 . 2009-03-04 00:44 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-16 17:44 . 2009-02-16 17:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-16 17:44 . 2009-02-11 11:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-16 17:44 . 2009-02-11 11:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-16 14:09 . 2009-02-16 14:09 <DIR> d-------- c:\program files\Trend Micro
2009-02-16 14:07 . 2009-03-04 00:43 <DIR> d-------- c:\program files\ERUNT
2009-02-16 01:21 . 2009-03-04 00:45 <DIR> d-------- c:\documents and settings\Steven Admin\Application Data\AVGTOOLBAR
2009-02-15 17:19 . 2009-03-12 18:52 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-02-15 17:19 . 2009-03-04 00:43 <DIR> d-------- c:\program files\AVG
2009-02-15 17:19 . 2009-02-15 17:19 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-02-15 17:19 . 2009-02-15 17:19 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-02-15 17:19 . 2009-02-15 17:19 12,552 --a------ c:\windows\system32\drivers\avgrkx86.sys
2009-02-15 17:19 . 2009-02-15 17:19 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-02-15 17:04 . 2009-03-04 00:45 <DIR> d-------- c:\documents and settings\Katy & Steven\Application Data\AVGTOOLBAR
2009-02-15 17:03 . 2009-03-04 00:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-02-15 02:37 . 2009-02-15 02:14 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-15 02:14 . 2009-02-15 02:14 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-15 02:11 . 2009-03-04 00:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-15 02:11 . 2009-03-04 00:38 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 08:01 21,235,744 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-15 07:59 251,900 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-04 05:45 --------- d-----w c:\program files\Google
2009-03-04 05:38 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-04 05:38 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-15 07:11 --------- d-----w c:\program files\Lavasoft
2009-02-14 05:16 --------- d-----w c:\documents and settings\Katy & Steven\Application Data\Skype
2009-02-14 05:15 --------- d-----w c:\documents and settings\Katy & Steven\Application Data\skypePM
2009-02-11 22:12 --------- d-----w c:\documents and settings\Katy & Steven\Application Data\CoreFTP
2009-02-11 22:10 --------- d-----w c:\program files\CoreFTP
2009-02-07 19:40 --------- d-----w c:\documents and settings\Steven Admin\Application Data\HotSync
2009-02-07 06:20 --------- d-----w c:\program files\epic
2009-02-07 06:16 --------- d-----w c:\program files\EPSON
2009-02-07 06:16 --------- d-----w c:\program files\Common Files\EPSON
2009-01-19 19:48 --------- d-----w c:\program files\activePDF
2009-01-17 21:13 --------- d-----w c:\program files\Quicken
2008-09-13 19:53 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2004-07-08 00:30 21 ----a-w c:\program files\AVPersonalAVWIN.INI
2000-07-08 17:39 219,646 ----a-w c:\documents and settings\Katy & Steven\digital_photo.zip
1998-05-12 01:01 229,680 ----a-w c:\documents and settings\Katy & Steven\SUBACK.BIN
1998-05-12 01:01 168,160 ----a-w c:\documents and settings\Katy & Steven\W98SETUP.BIN
1998-02-06 17:35 0 ------w c:\program files\Common Files\MSCREATE.DIR
2008-08-06 04:44 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080520080806\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ResChanger 2005"="c:\program files\ResChanger 2005\ResChanger2005.exe" [2005-05-26 885248]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"WebCamRT.exe"="" [BU]
"Steam"="" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IntelliType"="c:\program files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-21 94208]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"LogitechGalleryRepair"="c:\program files\Logitech\ImageStudio\ISStart.exe" [2002-09-11 155648]
"D-Link Wireless G WUA-1340"="c:\program files\D-Link\Wireless G WUA-1340\AirGCFG.exe" [2007-08-27 1662976]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"Ink Monitor"="c:\program files\EPSON\Ink Monitor\InkMonitor.exe" [2001-10-16 258118]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-15 509784]
"POINTER"="point32.exe" [BU]
"nwiz"="nwiz.exe" [2006-03-09 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2009-02-07 127488]
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2004-06-09 471040]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2007-07-16 49220]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-15 17:19 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=tbbick.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-09-03 20:12 111936 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-12-24 23:25 342848 c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-09-10 17:40 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
--a------ 2007-09-06 14:53 169264 c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Stuff\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Stuff\\Sierra\\FEAR\\FEAR.exe"=
"c:\\Program Files\\Stuff\\Sierra\\FEAR\\FEARMP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Stuff\\Sierra\\FEAR\\FEARXP\\FEARXP.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Stuff\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"c:\\Program Files\\Stuff\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-02-15 12552]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-15 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-15 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-15 107272]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-15 298264]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2004-11-26 2368]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v3.8.205\ATI Tray Tools\atitray.sys --> c:\program files\Radeon Omega Drivers\v3.8.205\ATI Tray Tools\atitray.sys [?]
S2 mrtRate;mrtRate; [x]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S3 VisorUsb;Handspring USB;c:\windows\system32\DRIVERS\VisorUsb.sys --> c:\windows\system32\DRIVERS\VisorUsb.sys [?]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2004-04-02 15576]
.
Contents of the 'Scheduled Tasks' folder
2009-02-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-15 02:14]
2009-02-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.statesman.com/
uInternet Settings,ProxyServer = http=localhost:8000;https=localhost:8000
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{9239E4EC-C9A6-11D2-A844-00C04F68D538}
FF - ProfilePath - c:\documents and settings\Katy & Steven\Application Data\Mozilla\Firefox\Profiles\hf8thdlc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-US
fficial
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJPI142_05.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava11.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava12.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJPI141_02.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 03:00:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3942243025-2935130677-2106517767-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:bf,86,64,e1,a6,55,9c,ec,5d,cd,7e,db,36,28,17,9d,87,89,e4,f4,03,3f,16,
29,98,6a,87,ec,76,14,40,84,22,7c,9c,71,e1,83,44,8e,b5,a9,8c,dd,71,24,c3,99,\
"??"=hex:c8,31,c6,07,f4,10,40,93,a4,43,1d,e0,57,a1,e4,26
[HKEY_USERS\S-1-5-21-3942243025-2935130677-2106517767-1005\& *]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-3942243025-2935130677-2106517767-1005\& *\Preferences]
"UITransitions"=dword:00000001
"SizeDots"=dword:00000000
"ResampleFilter2"=dword:00000006
DUMPHIVE0.003 (REGF)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\program files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Microsoft Hardware\Mouse\point32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\spool\drivers\w32x86\3\E_S10IC2.EXE
c:\progra~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Completion time: 2009-03-15 3:07:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-15 08:07:12
ComboFix2.txt 2009-03-09 05:29:03
ComboFix3.txt 2009-02-24 22:39:51
Pre-Run: 130,263,998,464 bytes free
Post-Run: 130,244,333,568 bytes free
249
I ran ComboFix, the log is below.
A question about the Kaspersky Online scan. I started it and let it go for 14 hours, but it had only done 13 files. I restarted thinking it may have locked up. It's now at 8.5 hours and at 13 files again:
Now scanning: ABP480N5.SY_/abp480n5.sys
Location: C:\cmdcons
Is this normal? How long should I let it go for? Thanks!
`````````````````
ComboFix 09-03-14.01 - Katy & Steven 2009-03-15 2:51:59.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1055 [GMT -5:00]
Running from: c:\documents and settings\Katy & Steven\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Katy & Steven\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *enabled*
* Created a new restore point
FILE ::
c:\docume~1\KATY&S~1\LOCALS~1\Temp\ewdmaudn.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EWDMAUDN
-------\Service_ewdmaudn
((((((((((((((((((((((((( Files Created from 2009-02-15 to 2009-03-15 )))))))))))))))))))))))))))))))
.
2009-03-04 00:44 . 2009-03-04 00:44 <DIR> d-------- c:\documents and settings\Katy & Steven\Application Data\Malwarebytes
2009-03-04 00:43 . 2009-03-04 00:43 <DIR> d-------- C:\VundoFix Backups
2009-03-04 00:43 . 2009-03-04 00:43 <DIR> d-------- c:\documents and settings\Steven Admin\Application Data\Yahoo!
2009-03-04 00:37 . 2009-03-04 00:37 <DIR> d-------- c:\windows\system32\IOSUBSYS
2009-02-25 21:30 . 2009-02-25 21:31 <DIR> d-------- c:\windows\ERUNT
2009-02-25 21:19 . 2009-03-04 00:49 <DIR> d-------- C:\SDFix
2009-02-20 00:44 . 2009-02-20 00:45 <DIR> d-------- C:\rsit
2009-02-18 16:44 . 2009-02-18 16:44 <DIR> d-------- c:\documents and settings\Steven Admin\Application Data\Malwarebytes
2009-02-16 17:44 . 2009-03-04 00:44 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-16 17:44 . 2009-02-16 17:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-16 17:44 . 2009-02-11 11:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-16 17:44 . 2009-02-11 11:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-16 14:09 . 2009-02-16 14:09 <DIR> d-------- c:\program files\Trend Micro
2009-02-16 14:07 . 2009-03-04 00:43 <DIR> d-------- c:\program files\ERUNT
2009-02-16 01:21 . 2009-03-04 00:45 <DIR> d-------- c:\documents and settings\Steven Admin\Application Data\AVGTOOLBAR
2009-02-15 17:19 . 2009-03-12 18:52 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-02-15 17:19 . 2009-03-04 00:43 <DIR> d-------- c:\program files\AVG
2009-02-15 17:19 . 2009-02-15 17:19 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-02-15 17:19 . 2009-02-15 17:19 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-02-15 17:19 . 2009-02-15 17:19 12,552 --a------ c:\windows\system32\drivers\avgrkx86.sys
2009-02-15 17:19 . 2009-02-15 17:19 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-02-15 17:04 . 2009-03-04 00:45 <DIR> d-------- c:\documents and settings\Katy & Steven\Application Data\AVGTOOLBAR
2009-02-15 17:03 . 2009-03-04 00:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-02-15 02:37 . 2009-02-15 02:14 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-15 02:14 . 2009-02-15 02:14 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-15 02:11 . 2009-03-04 00:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-15 02:11 . 2009-03-04 00:38 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 08:01 21,235,744 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-15 07:59 251,900 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-04 05:45 --------- d-----w c:\program files\Google
2009-03-04 05:38 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-04 05:38 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-15 07:11 --------- d-----w c:\program files\Lavasoft
2009-02-14 05:16 --------- d-----w c:\documents and settings\Katy & Steven\Application Data\Skype
2009-02-14 05:15 --------- d-----w c:\documents and settings\Katy & Steven\Application Data\skypePM
2009-02-11 22:12 --------- d-----w c:\documents and settings\Katy & Steven\Application Data\CoreFTP
2009-02-11 22:10 --------- d-----w c:\program files\CoreFTP
2009-02-07 19:40 --------- d-----w c:\documents and settings\Steven Admin\Application Data\HotSync
2009-02-07 06:20 --------- d-----w c:\program files\epic
2009-02-07 06:16 --------- d-----w c:\program files\EPSON
2009-02-07 06:16 --------- d-----w c:\program files\Common Files\EPSON
2009-01-19 19:48 --------- d-----w c:\program files\activePDF
2009-01-17 21:13 --------- d-----w c:\program files\Quicken
2008-09-13 19:53 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2004-07-08 00:30 21 ----a-w c:\program files\AVPersonalAVWIN.INI
2000-07-08 17:39 219,646 ----a-w c:\documents and settings\Katy & Steven\digital_photo.zip
1998-05-12 01:01 229,680 ----a-w c:\documents and settings\Katy & Steven\SUBACK.BIN
1998-05-12 01:01 168,160 ----a-w c:\documents and settings\Katy & Steven\W98SETUP.BIN
1998-02-06 17:35 0 ------w c:\program files\Common Files\MSCREATE.DIR
2008-08-06 04:44 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080520080806\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ResChanger 2005"="c:\program files\ResChanger 2005\ResChanger2005.exe" [2005-05-26 885248]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"WebCamRT.exe"="" [BU]
"Steam"="" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IntelliType"="c:\program files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-21 94208]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"LogitechGalleryRepair"="c:\program files\Logitech\ImageStudio\ISStart.exe" [2002-09-11 155648]
"D-Link Wireless G WUA-1340"="c:\program files\D-Link\Wireless G WUA-1340\AirGCFG.exe" [2007-08-27 1662976]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"Ink Monitor"="c:\program files\EPSON\Ink Monitor\InkMonitor.exe" [2001-10-16 258118]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-15 509784]
"POINTER"="point32.exe" [BU]
"nwiz"="nwiz.exe" [2006-03-09 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2009-02-07 127488]
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2004-06-09 471040]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2007-07-16 49220]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-15 17:19 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=tbbick.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-09-03 20:12 111936 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-12-24 23:25 342848 c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-09-10 17:40 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
--a------ 2007-09-06 14:53 169264 c:\program files\Maxtor\OneTouch Status\MaxMenuMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Stuff\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Stuff\\Sierra\\FEAR\\FEAR.exe"=
"c:\\Program Files\\Stuff\\Sierra\\FEAR\\FEARMP.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Stuff\\Sierra\\FEAR\\FEARXP\\FEARXP.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Stuff\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"c:\\Program Files\\Stuff\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"c:\\Program Files\\SmartFTP\\SmartFTP.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-02-15 12552]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-15 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-15 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-15 107272]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-15 298264]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2004-11-26 2368]
S1 atitray;atitray;\??\c:\program files\Radeon Omega Drivers\v3.8.205\ATI Tray Tools\atitray.sys --> c:\program files\Radeon Omega Drivers\v3.8.205\ATI Tray Tools\atitray.sys [?]
S2 mrtRate;mrtRate; [x]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S3 VisorUsb;Handspring USB;c:\windows\system32\DRIVERS\VisorUsb.sys --> c:\windows\system32\DRIVERS\VisorUsb.sys [?]
S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2004-04-02 15576]
.
Contents of the 'Scheduled Tasks' folder
2009-02-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-15 02:14]
2009-02-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.statesman.com/
uInternet Settings,ProxyServer = http=localhost:8000;https=localhost:8000
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {{9239E4EC-C9A6-11D2-A844-00C04F68D538}
FF - ProfilePath - c:\documents and settings\Katy & Steven\Application Data\Mozilla\Firefox\Profiles\hf8thdlc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-US

FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPJPI142_05.dll
FF - plugin: c:\program files\Java\j2re1.4.2_05\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava11.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava12.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJPI141_02.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 03:00:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3942243025-2935130677-2106517767-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:bf,86,64,e1,a6,55,9c,ec,5d,cd,7e,db,36,28,17,9d,87,89,e4,f4,03,3f,16,
29,98,6a,87,ec,76,14,40,84,22,7c,9c,71,e1,83,44,8e,b5,a9,8c,dd,71,24,c3,99,\
"??"=hex:c8,31,c6,07,f4,10,40,93,a4,43,1d,e0,57,a1,e4,26
[HKEY_USERS\S-1-5-21-3942243025-2935130677-2106517767-1005\& *]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-3942243025-2935130677-2106517767-1005\& *\Preferences]
"UITransitions"=dword:00000001
"SizeDots"=dword:00000000
"ResampleFilter2"=dword:00000006
DUMPHIVE0.003 (REGF)
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\program files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Microsoft Hardware\Mouse\point32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\spool\drivers\w32x86\3\E_S10IC2.EXE
c:\progra~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Completion time: 2009-03-15 3:07:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-15 08:07:12
ComboFix2.txt 2009-03-09 05:29:03
ComboFix3.txt 2009-02-24 22:39:51
Pre-Run: 130,263,998,464 bytes free
Post-Run: 130,244,333,568 bytes free
249