So..
My computer has been acting really quarky as of late--and I decided to do a complete system virus scan to make sure nothing was wrong--and behold, my instincs were indeed correct--my computer had become infected with a Win32 Aleuron Rootkit. Avast so kindly detected this for me--and I kept trying to remove it to the bin where it could no longer infect my pc, but this did not work---and so then, being the person I am, I tried to delete this from the system files, but it still appeared---which was when I seeked the help of a friend of mine who is technical and knowledgable with this stuff. He suggested I do a Combo Fix, and it seemed to have fixed/deleted those files that were infected---though, I'm not sure, so he advised me to post it here...
can some one please tell me if my Combo Fix has indeed fixed my problem? I have no clue what this stuff in Combo fix means...
Combo Fix Log is as follows:
ComboFix 10-01-16.04 - Administrator 01/17/2010 12:39:47.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.171 [GMT -5:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100117-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\Microsoft\1eaadjc.dll
c:\documents and settings\Administrator\Application Data\Microsoft\bass.dll
c:\documents and settings\Administrator\Application Data\Microsoft\engine_vx.dll
c:\documents and settings\Administrator\Application Data\Microsoft\kfgresk.dll
c:\documents and settings\Administrator\Application Data\Microsoft\mjcriu.dll
c:\documents and settings\Administrator\Application Data\Microsoft\peaadje.dll
c:\documents and settings\Administrator\Application Data\Microsoft\qwadjb.dll
c:\documents and settings\Administrator\Application Data\Microsoft\rsaadjd.dll
C:\LOG.TXT
c:\windows\93bfe3ca-1bf1-4ae8-b812-1f3bc95e7619.ocx
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system\oeminfo.ini
c:\windows\system32\2a700b3e-848e-485e-b458-90433d601fe5.dll
c:\windows\system32\Cache
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\msblcd32.dll
c:\windows\system32\twain_32.dll
c:\windows\system32\zip32.dll
c:\windows\unins000.dat
c:\windows\unins000.exe
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-12-17 to 2010-01-17 )))))))))))))))))))))))))))))))
.
2010-01-17 16:45 . 2010-01-17 16:59 95360 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2010-01-17 16:45 . 2010-01-17 16:59 95360 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-01-17 07:42 . 2010-01-17 07:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-17 02:59 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-17 02:59 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-17 02:59 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-17 02:59 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-01-17 02:59 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-17 02:59 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-17 02:59 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-17 02:59 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-17 02:58 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-17 02:58 . 2010-01-17 02:58 -------- d-----w- c:\program files\Alwil Software
2010-01-16 19:42 . 2010-01-16 19:42 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-01-16 19:41 . 2010-01-16 19:41 -------- d-----w- c:\program files\Microsoft.NET
2010-01-16 19:41 . 2010-01-16 19:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-01-16 19:41 . 2010-01-16 19:41 -------- d-----w- c:\documents and settings\All Users\Microsoft
2010-01-16 19:27 . 2010-01-16 19:27 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-01-14 05:45 . 2010-01-14 05:45 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AIM Toolbar
2010-01-14 05:36 . 2010-01-14 05:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\acccore
2010-01-14 05:36 . 2010-01-14 05:36 -------- d-----w- c:\program files\AIM Toolbar
2010-01-14 05:36 . 2010-01-14 05:36 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM Toolbar
2010-01-14 05:36 . 2010-01-14 05:37 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AIM
2010-01-14 05:35 . 2010-01-14 05:35 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-01-14 05:35 . 2010-01-14 05:35 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM
2010-01-14 05:34 . 2010-01-14 05:34 -------- d-----w- c:\program files\AIM
2010-01-14 02:00 . 2010-01-14 02:00 -------- d-----w- c:\documents and settings\All Users\Application Data\{BFCD9266-8B97-4A73-8FDF-E2743DE8939E}
2010-01-13 20:46 . 2001-08-18 03:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-01-13 20:46 . 2001-08-18 03:36 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2010-01-13 20:46 . 2001-08-18 03:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-01-13 20:46 . 2001-08-18 03:36 8192 ----a-w- c:\windows\system32\kbdkor.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 ----a-w- c:\windows\system32\kbd106.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2010-01-13 20:46 . 2001-08-17 19:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2010-01-13 20:46 . 2001-08-17 19:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2010-01-11 22:45 . 2010-01-11 22:47 -------- d-----w- c:\windows\system32\NtmsData
2010-01-11 05:45 . 2010-01-11 05:45 -------- d-----w- c:\program files\Ventrilo
2010-01-11 05:44 . 2010-01-11 05:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-11 05:09 . 2003-01-08 16:23 49152 ----a-w- c:\windows\system32\DSndUp.exe
2010-01-11 05:09 . 2002-04-17 21:05 45056 ----a-w- c:\windows\system32\CleanUp.exe
2010-01-11 04:45 . 2010-01-11 04:45 -------- d-----w- c:\program files\Family Toolbar
2010-01-10 21:59 . 2010-01-10 21:59 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-01-10 21:35 . 2010-01-10 21:35 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-10 21:34 . 2010-01-10 21:34 -------- d-----w- c:\program files\CSS Tab Designer 2
2010-01-09 10:45 . 2010-01-09 10:45 -------- d-----w- c:\documents and settings\Administrator\ErrorLogs
2010-01-09 10:40 . 2010-01-10 20:13 258568 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-09 10:32 . 2010-01-09 10:32 -------- d-----w- C:\Dell
2010-01-09 10:19 . 2010-01-09 10:24 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2010-01-09 10:16 . 2010-01-10 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2010-01-09 09:58 . 2010-01-09 10:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\uniblue
2010-01-09 09:57 . 2010-01-10 21:34 -------- d-----w- c:\program files\Uniblue
2010-01-09 09:57 . 2010-01-10 21:34 -------- dc----w- c:\documents and settings\All Users\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2010-01-09 05:23 . 2008-09-24 15:40 4122368 ----a-r- c:\windows\system32\drivers\ALCXWDM.SYS
2010-01-09 05:21 . 2006-10-18 07:53 147456 ----a-w- c:\windows\system32\RTLCPAPI.dll
2010-01-09 05:21 . 2006-07-31 16:27 217088 ----a-w- c:\windows\Alcrmv.exe
2010-01-09 04:21 . 2010-01-11 05:07 -------- d-----w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-01-09 04:21 . 2010-01-11 04:51 -------- d-----w- c:\program files\PCPitstop
2010-01-07 05:15 . 2010-01-07 05:27 -------- d-----w- c:\program files\PHP
2010-01-07 05:09 . 2010-01-07 05:09 -------- d-----w- c:\program files\Apache Group
2010-01-06 19:47 . 2010-01-06 19:47 -------- d-----w- c:\documents and settings\All Users\Application Data\MySQL
2010-01-06 14:42 . 2010-01-14 02:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Stamps.com Internet Postage
2010-01-06 05:18 . 2010-01-06 05:49 -------- d-----w- c:\program files\PMIC EBOOKS
2010-01-05 16:11 . 2010-01-05 16:11 -------- d-----w- c:\documents and settings\LocalService\Application Data\Juniper Networks
2010-01-05 16:10 . 2010-01-05 16:11 -------- d-----w- c:\program files\Juniper Networks
2010-01-05 15:18 . 2010-01-05 15:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\Avaya
2010-01-05 15:17 . 2010-01-05 15:17 -------- d-----w- c:\program files\Avaya
2010-01-05 14:56 . 2010-01-05 14:56 -------- d-----w- c:\windows\IP Agent
2009-12-31 16:53 . 2009-12-31 16:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1
2009-12-31 01:43 . 2009-12-31 01:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ABBYY
2009-12-19 22:49 . 2009-12-19 22:49 -------- d-----w- c:\program files\Common Files\Java
2009-12-19 22:48 . 2009-12-19 22:48 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150010}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 17:49 . 2009-10-08 02:21 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-01-17 17:49 . 2009-10-08 02:16 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-01-17 16:21 . 2009-11-04 20:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\Juniper Networks
2010-01-17 07:43 . 2009-05-01 15:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-17 03:01 . 2008-08-21 23:55 121152 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-17 02:27 . 2009-11-06 16:42 0 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\prvlcl.dat
2010-01-17 01:29 . 2010-01-17 01:29 5080 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2010-01-16 21:05 . 2008-10-05 23:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-16 20:20 . 2009-06-08 23:18 -------- d-----w- c:\program files\TeamViewer
2010-01-16 17:41 . 2009-11-04 20:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Juniper Networks
2010-01-16 01:07 . 2008-10-05 23:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\GetRightToGo
2010-01-14 02:15 . 2009-12-11 18:16 -------- d-----w- c:\program files\Stamps.com Internet Postage
2010-01-14 02:05 . 2009-12-11 18:16 36 ---ha-w- c:\windows\system32\f9t.dat
2010-01-11 05:09 . 2008-12-13 23:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-11 04:47 . 2008-09-05 00:15 -------- d-----w- c:\program files\MyHeritage
2010-01-10 21:59 . 2010-01-10 21:59 3584 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-01-10 21:59 . 2009-03-07 15:09 -------- d-----w- c:\program files\MSECACHE
2010-01-06 20:22 . 2009-05-01 02:55 -------- d-----w- c:\program files\SpeedFan
2010-01-06 19:47 . 2008-10-30 15:44 -------- d-----w- c:\program files\MySQL
2010-01-06 12:42 . 2009-10-04 19:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\5600-6600 Series
2010-01-05 15:13 . 2009-11-02 12:43 86016 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\meetingconvertor.dll
2010-01-05 15:13 . 2009-11-02 12:43 81920 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connecthook.dll
2010-01-05 15:13 . 2009-11-02 12:43 303104 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectsprd.dll
2010-01-01 19:04 . 2009-06-12 17:43 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-01 19:02 . 2009-06-12 17:43 38784 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-26 04:50 . 2008-09-17 00:09 -------- d-----w- c:\program files\Yahoo!
2009-12-20 00:13 . 2009-11-21 20:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nova Development
2009-12-20 00:09 . 2009-11-06 22:44 -------- d-----w- c:\program files\NetZero
2009-12-20 00:06 . 2008-08-26 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-12-19 22:50 . 2008-08-21 21:59 -------- d-----w- c:\program files\Java
2009-12-19 21:16 . 2009-05-01 15:02 -------- d-----w- c:\program files\Citrix
2009-12-19 06:17 . 2009-12-19 06:17 2158652 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\1.1.6.1\setup.exe
2009-12-19 06:17 . 2009-12-19 06:17 42960 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\1.1.6.1\noneCodesignFilesBundle.exe
2009-12-19 06:17 . 2008-09-12 23:45 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-12-17 21:26 . 2010-01-14 02:00 5121427 ----a-w- c:\documents and settings\All Users\Application Data\{BFCD9266-8B97-4A73-8FDF-E2743DE8939E}\stamps.exe
2009-12-17 21:26 . 2010-01-14 02:00 321108 ----a-w- c:\documents and settings\All Users\Application Data\{BFCD9266-8B97-4A73-8FDF-E2743DE8939E}\mia.dll
2009-12-17 18:00 . 2008-09-23 01:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\mjusbsp
2009-12-17 02:10 . 2009-12-17 02:10 -------- d--h--r- c:\documents and settings\All Users\Application Data\Atheros
2009-12-17 02:05 . 2009-12-17 02:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NETGEAR
2009-12-12 01:12 . 2009-12-12 01:10 1088 ----a-w- c:\windows\checkip.dat
2009-12-12 01:05 . 2009-12-12 01:05 1235 ----a-w- c:\windows\ipconfig.dat
2009-12-11 18:40 . 2009-12-11 18:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit
2009-12-11 18:28 . 2009-12-11 18:28 -------- d-----w- c:\program files\Common Files\Intuit
2009-12-08 19:29 . 2008-08-24 04:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\TeamViewer
2009-12-02 02:52 . 2008-08-26 16:20 -------- d--h--w- c:\documents and settings\Administrator\Application Data\yahoo!
2009-12-01 23:25 . 2009-10-16 07:31 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-25 08:01 . 2009-11-25 08:01 -------- d-----w- c:\program files\MSXML 6.0
2009-11-22 23:16 . 2009-11-22 18:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\ComfortSoftware
2009-11-21 20:27 . 2008-10-21 03:28 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-11-21 20:26 . 2009-11-21 18:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\GetRight
2009-11-21 16:24 . 2007-07-05 19:50 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 19:25 . 2009-11-16 19:25 134 ----a-w- c:\documents and settings\Administrator\neoteris_write_15235194.reg
2009-11-10 21:34 . 2009-10-15 16:35 81920 -c--a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connecthook.dll
2009-11-10 21:34 . 2009-10-15 16:35 158720 -c--a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectsprd.dll
2009-11-10 19:39 . 2009-12-02 02:48 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-11-10 00:14 . 2009-11-10 00:14 134 ------w- c:\documents and settings\Administrator\neoteris_write_2566497.reg
2009-11-09 21:10 . 2009-11-09 21:10 134 ------w- c:\documents and settings\Administrator\neoteris_write_21450309.reg
2009-11-06 19:46 . 2009-06-01 17:33 61224 -c--a-w- c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe
2009-11-04 20:51 . 2009-11-04 20:51 33220 -c--a-w- c:\documents and settings\Administrator\Application Data\Juniper Networks\Setup\uninstall.exe
2009-10-29 07:45 . 2007-07-05 20:07 841216 ----a-w- c:\windows\system32\wininet.dll
2009-10-29 07:45 . 2009-05-25 17:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:45 . 2007-07-05 20:06 17408 ----a-w- c:\windows\system32\corpol.dll
2009-10-25 10:21 . 2009-10-25 10:21 10802163 -c--a-w- c:\documents and settings\All Users\SPLC0C.tmp
2009-10-21 17:03 . 2009-10-21 17:03 4736992 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe
2009-10-21 05:50 . 2004-08-04 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:50 . 2004-08-04 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:41 . 2008-09-03 04:12 265728 ----a-w- c:\windows\system32\drivers\http.sys
.
------- Sigcheck -------
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\sfcfiles.dll
[-] 2007-07-05 . 0F57A1C9E6D48DE4D12B86FB482FA495 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\program files\Family Toolbar\tbhelper.dll" [2009-05-07 355840]
[HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-04 02:12 556432 ----a-w- c:\progra~1\MICROS~3\Office14\URLREDIR.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim"="c:\program files\AIM\aim.exe" [2009-12-01 3951976]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="mqrt.dll" [2009-06-25 177152]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2009-09-27 83312]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2009-11-3 225680]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"noshutdown"= 0 (0x0)
"nosimplestartmenu"= 0 (0x0)
"norecentdochistory"= 0 (0x0)
"maxrecentdocs"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^4t Tray Minimizer.lnk]
backup=c:\windows\pss\4t Tray Minimizer.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 16:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2009-08-01 16:11 50520 ----a-w- c:\documents and settings\Administrator\Application Data\mjusbsp\cdloader2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
2009-01-14 13:49 113680 ----a-w- c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-01-29 23:13 118784 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-01-29 23:13 155648 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 5600-6600 Series Fax Server]
2009-05-11 17:02 311976 ----a-w- c:\program files\Lexmark 5600-6600 Series\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-12-20 11:50 2656528 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxduamon]
2009-05-11 17:02 16040 ----a-w- c:\program files\Lexmark 5600-6600 Series\lxduamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdumon.exe]
2009-05-11 17:02 684712 ----a-w- c:\program files\Lexmark 5600-6600 Series\lxdumon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nitro PDF Printer Monitor]
2009-03-04 20:27 209216 ----a-w- c:\program files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
2006-10-13 21:04 707376 ----a-w- c:\windows\vVX3000.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1232223850\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\lxducoms.exe"=
"c:\\Program Files\\Lexmark 5600-6600 Series\\lxduamon.exe"=
"c:\\Program Files\\Lexmark 5600-6600 Series\\FRun.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\scan\\scanman6.exe"=
"c:\\Program Files\\Lexmark 5600-6600 Series\\lxdufax.exe"=
"c:\\Documents and Settings\\Administrator\\taw\\winvnc.exe"=
"c:\\Documents and Settings\\Administrator\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Documents and Settings\\Administrator\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"83:TCP"= 83:TCP:Web Dictate Web Server
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [1/16/2010 9:59 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/16/2010 9:59 PM 20560]
R2 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe -service --> c:\windows\system32\lxducoms.exe -service [?]
R2 lxduCATSCustConnectService;lxduCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxduserv.exe [10/4/2009 2:43 PM 98984]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/12/2008 6:44 PM 24652]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [11/25/2005 4:43 PM 31896]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [7/24/2003 12:10 PM 17149]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/26/2009 4:28 AM 4639136]
S3 WNA1000;NETGEAR WNA1000 USB2.0 Wireless Card Service;c:\windows\system32\DRIVERS\WNA1000.sys --> c:\windows\system32\DRIVERS\WNA1000.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-17 c:\windows\Tasks\User_Feed_Synchronization-{5D785F0C-06E5-4195-A669-3EAFD23F73EB}.job
- c:\windows\system32\msfeedssync.exe [2008-08-21 23:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://search.myheritage.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - /105
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: {2AB1C516-D654-4D3A-B3D6-2185BBCEB409} - hxxps://vpn02.nucomm.net/+CSCOL+/relayp.cab
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
DPF: {B5F31C7D-D161-46FF-B06C-AE133F284477} - hxxp://www2.ubroadcast.com/Share/ubweb.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\lhujuiu8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\Plugins\npybrowserplus_2.4.21.dll
FF - plugin: c:\progra~1\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJPI150_01.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPOJI610.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-dimsntfy - (no file)
Notify-WgaLogon - (no file)
MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
MSConfigStartUp-Meebo Notifier - c:\documents and settings\Administrator\Local Settings\Application Data\Meebo\Meebo Notifier\MeeboNotifier.exe
MSConfigStartUp-pwreset - c:\program files\Avaya\Avaya IP Agent\Service Provider\pwreset.exe
ActiveSetup-Nitro PDF Professional - (no file)
AddRemove-Barnes & Noble_is1 - c:\windows\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-17 12:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9a,65,5d,a9,2f,e5,3f,4e,8c,6d,cb,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9a,65,5d,a9,2f,e5,3f,4e,8c,6d,cb,\
[HKEY_USERS\S-1-5-21-527237240-1343024091-682003330-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2C870AA1-E68C-1665-B27B-BB68A03453D3}*]
"hadamppdegdjfpoh"=hex:6b,61,62,70,63,6a,69,70,69,70,63,62,6f,68,67,70,6b,6a,
61,6f,6c,63,00,00
"iabbcdegcmaibgknfb"=hex:63,61,6c,6f,67,6d,00,7c
"iafpcdhhijmkiadnka"=hex:6a,61,62,70,6d,69,67,70,68,70,66,6b,70,6c,6c,64,63,69,
6e,6d,00,ff
[HKEY_USERS\S-1-5-21-527237240-1343024091-682003330-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{930712F4-CD50-EE73-AD19-CB80E42CDADF}*]
"naedjpgmcggpneiaehbgodffaopm"=hex:6b,61,69,65,6d,6d,6e,6c,68,64,67,62,6e,6d,
67,6a,68,6d,66,66,6a,6e,00,00
"maoclcdheaocgcknmalmepkhed"=hex:6b,61,69,65,6e,6d,6b,6c,67,61,62,69,6c,70,66,
6e,6d,61,64,6a,64,67,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(6360)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\acs.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\lxducoms.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2010-01-17 13:00:51 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-17 18:00
Pre-Run: 62,039,445,504 bytes free
Post-Run: 62,032,863,232 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 6DE8EBE2B2822B2CDCD1CE05877D4779
My computer has been acting really quarky as of late--and I decided to do a complete system virus scan to make sure nothing was wrong--and behold, my instincs were indeed correct--my computer had become infected with a Win32 Aleuron Rootkit. Avast so kindly detected this for me--and I kept trying to remove it to the bin where it could no longer infect my pc, but this did not work---and so then, being the person I am, I tried to delete this from the system files, but it still appeared---which was when I seeked the help of a friend of mine who is technical and knowledgable with this stuff. He suggested I do a Combo Fix, and it seemed to have fixed/deleted those files that were infected---though, I'm not sure, so he advised me to post it here...
can some one please tell me if my Combo Fix has indeed fixed my problem? I have no clue what this stuff in Combo fix means...
Combo Fix Log is as follows:
ComboFix 10-01-16.04 - Administrator 01/17/2010 12:39:47.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.171 [GMT -5:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100117-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\Microsoft\1eaadjc.dll
c:\documents and settings\Administrator\Application Data\Microsoft\bass.dll
c:\documents and settings\Administrator\Application Data\Microsoft\engine_vx.dll
c:\documents and settings\Administrator\Application Data\Microsoft\kfgresk.dll
c:\documents and settings\Administrator\Application Data\Microsoft\mjcriu.dll
c:\documents and settings\Administrator\Application Data\Microsoft\peaadje.dll
c:\documents and settings\Administrator\Application Data\Microsoft\qwadjb.dll
c:\documents and settings\Administrator\Application Data\Microsoft\rsaadjd.dll
C:\LOG.TXT
c:\windows\93bfe3ca-1bf1-4ae8-b812-1f3bc95e7619.ocx
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system\oeminfo.ini
c:\windows\system32\2a700b3e-848e-485e-b458-90433d601fe5.dll
c:\windows\system32\Cache
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\msblcd32.dll
c:\windows\system32\twain_32.dll
c:\windows\system32\zip32.dll
c:\windows\unins000.dat
c:\windows\unins000.exe
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-12-17 to 2010-01-17 )))))))))))))))))))))))))))))))
.
2010-01-17 16:45 . 2010-01-17 16:59 95360 -c--a-w- c:\windows\system32\dllcache\atapi.sys
2010-01-17 16:45 . 2010-01-17 16:59 95360 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-01-17 07:42 . 2010-01-17 07:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-17 02:59 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-17 02:59 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-17 02:59 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-17 02:59 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-01-17 02:59 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-17 02:59 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-17 02:59 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-17 02:59 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-17 02:58 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-17 02:58 . 2010-01-17 02:58 -------- d-----w- c:\program files\Alwil Software
2010-01-16 19:42 . 2010-01-16 19:42 -------- d-----w- c:\program files\Microsoft Synchronization Services
2010-01-16 19:41 . 2010-01-16 19:41 -------- d-----w- c:\program files\Microsoft.NET
2010-01-16 19:41 . 2010-01-16 19:41 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-01-16 19:41 . 2010-01-16 19:41 -------- d-----w- c:\documents and settings\All Users\Microsoft
2010-01-16 19:27 . 2010-01-16 19:27 -------- d-----w- c:\program files\Microsoft Analysis Services
2010-01-14 05:45 . 2010-01-14 05:45 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AIM Toolbar
2010-01-14 05:36 . 2010-01-14 05:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\acccore
2010-01-14 05:36 . 2010-01-14 05:36 -------- d-----w- c:\program files\AIM Toolbar
2010-01-14 05:36 . 2010-01-14 05:36 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM Toolbar
2010-01-14 05:36 . 2010-01-14 05:37 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AIM
2010-01-14 05:35 . 2010-01-14 05:35 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-01-14 05:35 . 2010-01-14 05:35 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM
2010-01-14 05:34 . 2010-01-14 05:34 -------- d-----w- c:\program files\AIM
2010-01-14 02:00 . 2010-01-14 02:00 -------- d-----w- c:\documents and settings\All Users\Application Data\{BFCD9266-8B97-4A73-8FDF-E2743DE8939E}
2010-01-13 20:46 . 2001-08-18 03:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-01-13 20:46 . 2001-08-18 03:36 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2010-01-13 20:46 . 2001-08-18 03:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-01-13 20:46 . 2001-08-18 03:36 8192 ----a-w- c:\windows\system32\kbdkor.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 ----a-w- c:\windows\system32\kbd106.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2010-01-13 20:46 . 2001-08-17 19:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2010-01-13 20:46 . 2001-08-17 19:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2010-01-13 20:46 . 2001-08-17 19:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2010-01-11 22:45 . 2010-01-11 22:47 -------- d-----w- c:\windows\system32\NtmsData
2010-01-11 05:45 . 2010-01-11 05:45 -------- d-----w- c:\program files\Ventrilo
2010-01-11 05:44 . 2010-01-11 05:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-11 05:09 . 2003-01-08 16:23 49152 ----a-w- c:\windows\system32\DSndUp.exe
2010-01-11 05:09 . 2002-04-17 21:05 45056 ----a-w- c:\windows\system32\CleanUp.exe
2010-01-11 04:45 . 2010-01-11 04:45 -------- d-----w- c:\program files\Family Toolbar
2010-01-10 21:59 . 2010-01-10 21:59 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-01-10 21:35 . 2010-01-10 21:35 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-10 21:34 . 2010-01-10 21:34 -------- d-----w- c:\program files\CSS Tab Designer 2
2010-01-09 10:45 . 2010-01-09 10:45 -------- d-----w- c:\documents and settings\Administrator\ErrorLogs
2010-01-09 10:40 . 2010-01-10 20:13 258568 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-09 10:32 . 2010-01-09 10:32 -------- d-----w- C:\Dell
2010-01-09 10:19 . 2010-01-09 10:24 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2010-01-09 10:16 . 2010-01-10 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2010-01-09 09:58 . 2010-01-09 10:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\uniblue
2010-01-09 09:57 . 2010-01-10 21:34 -------- d-----w- c:\program files\Uniblue
2010-01-09 09:57 . 2010-01-10 21:34 -------- dc----w- c:\documents and settings\All Users\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2010-01-09 05:23 . 2008-09-24 15:40 4122368 ----a-r- c:\windows\system32\drivers\ALCXWDM.SYS
2010-01-09 05:21 . 2006-10-18 07:53 147456 ----a-w- c:\windows\system32\RTLCPAPI.dll
2010-01-09 05:21 . 2006-07-31 16:27 217088 ----a-w- c:\windows\Alcrmv.exe
2010-01-09 04:21 . 2010-01-11 05:07 -------- d-----w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-01-09 04:21 . 2010-01-11 04:51 -------- d-----w- c:\program files\PCPitstop
2010-01-07 05:15 . 2010-01-07 05:27 -------- d-----w- c:\program files\PHP
2010-01-07 05:09 . 2010-01-07 05:09 -------- d-----w- c:\program files\Apache Group
2010-01-06 19:47 . 2010-01-06 19:47 -------- d-----w- c:\documents and settings\All Users\Application Data\MySQL
2010-01-06 14:42 . 2010-01-14 02:05 -------- d-----w- c:\documents and settings\Administrator\Application Data\Stamps.com Internet Postage
2010-01-06 05:18 . 2010-01-06 05:49 -------- d-----w- c:\program files\PMIC EBOOKS
2010-01-05 16:11 . 2010-01-05 16:11 -------- d-----w- c:\documents and settings\LocalService\Application Data\Juniper Networks
2010-01-05 16:10 . 2010-01-05 16:11 -------- d-----w- c:\program files\Juniper Networks
2010-01-05 15:18 . 2010-01-05 15:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\Avaya
2010-01-05 15:17 . 2010-01-05 15:17 -------- d-----w- c:\program files\Avaya
2010-01-05 14:56 . 2010-01-05 14:56 -------- d-----w- c:\windows\IP Agent
2009-12-31 16:53 . 2009-12-31 16:53 -------- d-----w- c:\documents and settings\Administrator\Application Data\com.pandora.desktop.FB9956FD96E03239939108614098AD95535EE674.1
2009-12-31 01:43 . 2009-12-31 01:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ABBYY
2009-12-19 22:49 . 2009-12-19 22:49 -------- d-----w- c:\program files\Common Files\Java
2009-12-19 22:48 . 2009-12-19 22:48 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150010}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 17:49 . 2009-10-08 02:21 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-01-17 17:49 . 2009-10-08 02:16 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-01-17 16:21 . 2009-11-04 20:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\Juniper Networks
2010-01-17 07:43 . 2009-05-01 15:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-17 03:01 . 2008-08-21 23:55 121152 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-17 02:27 . 2009-11-06 16:42 0 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\prvlcl.dat
2010-01-17 01:29 . 2010-01-17 01:29 5080 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2010-01-16 21:05 . 2008-10-05 23:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-16 20:20 . 2009-06-08 23:18 -------- d-----w- c:\program files\TeamViewer
2010-01-16 17:41 . 2009-11-04 20:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Juniper Networks
2010-01-16 01:07 . 2008-10-05 23:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\GetRightToGo
2010-01-14 02:15 . 2009-12-11 18:16 -------- d-----w- c:\program files\Stamps.com Internet Postage
2010-01-14 02:05 . 2009-12-11 18:16 36 ---ha-w- c:\windows\system32\f9t.dat
2010-01-11 05:09 . 2008-12-13 23:20 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-11 04:47 . 2008-09-05 00:15 -------- d-----w- c:\program files\MyHeritage
2010-01-10 21:59 . 2010-01-10 21:59 3584 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-01-10 21:59 . 2009-03-07 15:09 -------- d-----w- c:\program files\MSECACHE
2010-01-06 20:22 . 2009-05-01 02:55 -------- d-----w- c:\program files\SpeedFan
2010-01-06 19:47 . 2008-10-30 15:44 -------- d-----w- c:\program files\MySQL
2010-01-06 12:42 . 2009-10-04 19:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\5600-6600 Series
2010-01-05 15:13 . 2009-11-02 12:43 86016 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\meetingconvertor.dll
2010-01-05 15:13 . 2009-11-02 12:43 81920 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connecthook.dll
2010-01-05 15:13 . 2009-11-02 12:43 303104 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectsprd.dll
2010-01-01 19:04 . 2009-06-12 17:43 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-01 19:02 . 2009-06-12 17:43 38784 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-26 04:50 . 2008-09-17 00:09 -------- d-----w- c:\program files\Yahoo!
2009-12-20 00:13 . 2009-11-21 20:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nova Development
2009-12-20 00:09 . 2009-11-06 22:44 -------- d-----w- c:\program files\NetZero
2009-12-20 00:06 . 2008-08-26 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-12-19 22:50 . 2008-08-21 21:59 -------- d-----w- c:\program files\Java
2009-12-19 21:16 . 2009-05-01 15:02 -------- d-----w- c:\program files\Citrix
2009-12-19 06:17 . 2009-12-19 06:17 2158652 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\1.1.6.1\setup.exe
2009-12-19 06:17 . 2009-12-19 06:17 42960 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\1.1.6.1\noneCodesignFilesBundle.exe
2009-12-19 06:17 . 2008-09-12 23:45 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-12-17 21:26 . 2010-01-14 02:00 5121427 ----a-w- c:\documents and settings\All Users\Application Data\{BFCD9266-8B97-4A73-8FDF-E2743DE8939E}\stamps.exe
2009-12-17 21:26 . 2010-01-14 02:00 321108 ----a-w- c:\documents and settings\All Users\Application Data\{BFCD9266-8B97-4A73-8FDF-E2743DE8939E}\mia.dll
2009-12-17 18:00 . 2008-09-23 01:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\mjusbsp
2009-12-17 02:10 . 2009-12-17 02:10 -------- d--h--r- c:\documents and settings\All Users\Application Data\Atheros
2009-12-17 02:05 . 2009-12-17 02:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NETGEAR
2009-12-12 01:12 . 2009-12-12 01:10 1088 ----a-w- c:\windows\checkip.dat
2009-12-12 01:05 . 2009-12-12 01:05 1235 ----a-w- c:\windows\ipconfig.dat
2009-12-11 18:40 . 2009-12-11 18:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit
2009-12-11 18:28 . 2009-12-11 18:28 -------- d-----w- c:\program files\Common Files\Intuit
2009-12-08 19:29 . 2008-08-24 04:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\TeamViewer
2009-12-02 02:52 . 2008-08-26 16:20 -------- d--h--w- c:\documents and settings\Administrator\Application Data\yahoo!
2009-12-01 23:25 . 2009-10-16 07:31 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-25 08:01 . 2009-11-25 08:01 -------- d-----w- c:\program files\MSXML 6.0
2009-11-22 23:16 . 2009-11-22 18:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\ComfortSoftware
2009-11-21 20:27 . 2008-10-21 03:28 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-11-21 20:26 . 2009-11-21 18:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\GetRight
2009-11-21 16:24 . 2007-07-05 19:50 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 19:25 . 2009-11-16 19:25 134 ----a-w- c:\documents and settings\Administrator\neoteris_write_15235194.reg
2009-11-10 21:34 . 2009-10-15 16:35 81920 -c--a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connecthook.dll
2009-11-10 21:34 . 2009-10-15 16:35 158720 -c--a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin6x5\connectsprd.dll
2009-11-10 19:39 . 2009-12-02 02:48 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-11-10 00:14 . 2009-11-10 00:14 134 ------w- c:\documents and settings\Administrator\neoteris_write_2566497.reg
2009-11-09 21:10 . 2009-11-09 21:10 134 ------w- c:\documents and settings\Administrator\neoteris_write_21450309.reg
2009-11-06 19:46 . 2009-06-01 17:33 61224 -c--a-w- c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe
2009-11-04 20:51 . 2009-11-04 20:51 33220 -c--a-w- c:\documents and settings\Administrator\Application Data\Juniper Networks\Setup\uninstall.exe
2009-10-29 07:45 . 2007-07-05 20:07 841216 ----a-w- c:\windows\system32\wininet.dll
2009-10-29 07:45 . 2009-05-25 17:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:45 . 2007-07-05 20:06 17408 ----a-w- c:\windows\system32\corpol.dll
2009-10-25 10:21 . 2009-10-25 10:21 10802163 -c--a-w- c:\documents and settings\All Users\SPLC0C.tmp
2009-10-21 17:03 . 2009-10-21 17:03 4736992 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\connectaddin\connectaddin.exe
2009-10-21 05:50 . 2004-08-04 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:50 . 2004-08-04 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:41 . 2008-09-03 04:12 265728 ----a-w- c:\windows\system32\drivers\http.sys
.
------- Sigcheck -------
[-] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\79123dd72d0f61d4ed8c7a816ed338d7\sfcfiles.dll
[-] 2007-07-05 . 0F57A1C9E6D48DE4D12B86FB482FA495 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\program files\Family Toolbar\tbhelper.dll" [2009-05-07 355840]
[HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-11-04 02:12 556432 ----a-w- c:\progra~1\MICROS~3\Office14\URLREDIR.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim"="c:\program files\AIM\aim.exe" [2009-12-01 3951976]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="mqrt.dll" [2009-06-25 177152]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2009-09-27 83312]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2009-11-3 225680]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"noshutdown"= 0 (0x0)
"nosimplestartmenu"= 0 (0x0)
"norecentdochistory"= 0 (0x0)
"maxrecentdocs"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^4t Tray Minimizer.lnk]
backup=c:\windows\pss\4t Tray Minimizer.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 16:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
2009-08-01 16:11 50520 ----a-w- c:\documents and settings\Administrator\Application Data\mjusbsp\cdloader2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
2009-01-14 13:49 113680 ----a-w- c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-01-29 23:13 118784 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-01-29 23:13 155648 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 5600-6600 Series Fax Server]
2009-05-11 17:02 311976 ----a-w- c:\program files\Lexmark 5600-6600 Series\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2008-12-20 11:50 2656528 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxduamon]
2009-05-11 17:02 16040 ----a-w- c:\program files\Lexmark 5600-6600 Series\lxduamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdumon.exe]
2009-05-11 17:02 684712 ----a-w- c:\program files\Lexmark 5600-6600 Series\lxdumon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nitro PDF Printer Monitor]
2009-03-04 20:27 209216 ----a-w- c:\program files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
2006-10-13 21:04 707376 ----a-w- c:\windows\vVX3000.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1232223850\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\lxducoms.exe"=
"c:\\Program Files\\Lexmark 5600-6600 Series\\lxduamon.exe"=
"c:\\Program Files\\Lexmark 5600-6600 Series\\FRun.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\scan\\scanman6.exe"=
"c:\\Program Files\\Lexmark 5600-6600 Series\\lxdufax.exe"=
"c:\\Documents and Settings\\Administrator\\taw\\winvnc.exe"=
"c:\\Documents and Settings\\Administrator\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Documents and Settings\\Administrator\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"83:TCP"= 83:TCP:Web Dictate Web Server
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [1/16/2010 9:59 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/16/2010 9:59 PM 20560]
R2 lxdu_device;lxdu_device;c:\windows\system32\lxducoms.exe -service --> c:\windows\system32\lxducoms.exe -service [?]
R2 lxduCATSCustConnectService;lxduCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxduserv.exe [10/4/2009 2:43 PM 98984]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/12/2008 6:44 PM 24652]
R3 dfmirage;dfmirage;c:\windows\system32\drivers\dfmirage.sys [11/25/2005 4:43 PM 31896]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [7/24/2003 12:10 PM 17149]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; [x]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [9/26/2009 4:28 AM 4639136]
S3 WNA1000;NETGEAR WNA1000 USB2.0 Wireless Card Service;c:\windows\system32\DRIVERS\WNA1000.sys --> c:\windows\system32\DRIVERS\WNA1000.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-17 c:\windows\Tasks\User_Feed_Synchronization-{5D785F0C-06E5-4195-A669-3EAFD23F73EB}.job
- c:\windows\system32\msfeedssync.exe [2008-08-21 23:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://search.myheritage.com
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - /105
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: {2AB1C516-D654-4D3A-B3D6-2185BBCEB409} - hxxps://vpn02.nucomm.net/+CSCOL+/relayp.cab
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A084A130-28AE-4B32-B51A-1C8CE164BC88} - hxxp://www.convergysworkathome.com/AppHardT.CAB
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
DPF: {B5F31C7D-D161-46FF-B06C-AE133F284477} - hxxp://www2.ubroadcast.com/Share/ubweb.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\lhujuiu8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\Plugins\npybrowserplus_2.4.21.dll
FF - plugin: c:\progra~1\MICROS~3\Office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\MICROS~3\Office14\NPSPWRAP.DLL
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPJPI150_01.dll
FF - plugin: c:\program files\Java\jre1.5.0_01\bin\NPOJI610.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-dimsntfy - (no file)
Notify-WgaLogon - (no file)
MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
MSConfigStartUp-Meebo Notifier - c:\documents and settings\Administrator\Local Settings\Application Data\Meebo\Meebo Notifier\MeeboNotifier.exe
MSConfigStartUp-pwreset - c:\program files\Avaya\Avaya IP Agent\Service Provider\pwreset.exe
ActiveSetup-Nitro PDF Professional - (no file)
AddRemove-Barnes & Noble_is1 - c:\windows\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-17 12:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9a,65,5d,a9,2f,e5,3f,4e,8c,6d,cb,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9a,65,5d,a9,2f,e5,3f,4e,8c,6d,cb,\
[HKEY_USERS\S-1-5-21-527237240-1343024091-682003330-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2C870AA1-E68C-1665-B27B-BB68A03453D3}*]
"hadamppdegdjfpoh"=hex:6b,61,62,70,63,6a,69,70,69,70,63,62,6f,68,67,70,6b,6a,
61,6f,6c,63,00,00
"iabbcdegcmaibgknfb"=hex:63,61,6c,6f,67,6d,00,7c
"iafpcdhhijmkiadnka"=hex:6a,61,62,70,6d,69,67,70,68,70,66,6b,70,6c,6c,64,63,69,
6e,6d,00,ff
[HKEY_USERS\S-1-5-21-527237240-1343024091-682003330-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{930712F4-CD50-EE73-AD19-CB80E42CDADF}*]
"naedjpgmcggpneiaehbgodffaopm"=hex:6b,61,69,65,6d,6d,6e,6c,68,64,67,62,6e,6d,
67,6a,68,6d,66,66,6a,6e,00,00
"maoclcdheaocgcknmalmepkhed"=hex:6b,61,69,65,6e,6d,6b,6c,67,61,62,69,6c,70,66,
6e,6d,61,64,6a,64,67,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(6360)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\acs.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\lxducoms.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2010-01-17 13:00:51 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-17 18:00
Pre-Run: 62,039,445,504 bytes free
Post-Run: 62,032,863,232 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 6DE8EBE2B2822B2CDCD1CE05877D4779

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top











