ComboFix 11-04-26.02 - Dominic 26/04/2011 21:40:57.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.429 [GMT -4:00]
Running from: c:\documents and settings\Dominic\Desktop\ComboFix.exe
AV: Ad-Aware Total Security *Disabled/Updated* {71310606-6F3B-49F2-9A81-8315AA75FBB3}
FW: Ad-Aware Personal Firewall *Disabled* {6E6F4BA6-C07D-443F-A130-0A57DA59A082}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Dominic\Application Data\Adobe\plugs
c:\documents and settings\Dominic\Application Data\Adobe\shed
c:\windows\Fonts\HandelGotDOT-Bol.otf
c:\windows\system32\system
c:\windows\system32\Thumbs.db
c:\windows\system32\tmp.reg
.
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((( Files Created from 2011-03-27 to 2011-04-27 )))))))))))))))))))))))))))))))
.
.
2011-04-15 18:16 . 2011-04-16 08:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-04-13 17:17 . 2011-04-13 17:17 -------- d-----w- c:\documents and settings\Dominic\Application Data\Intuit Canada
2011-04-13 17:17 . 2011-04-13 17:17 -------- d-----w- c:\program files\Common Files\Intuit
2011-04-13 17:17 . 2011-04-13 17:35 -------- d-----w- c:\program files\TurboTax 2010
2011-04-13 17:16 . 2011-04-13 17:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit Canada
2011-04-13 13:52 . 2011-04-13 13:52 -------- d-----w- c:\documents and settings\Dominic\Local Settings\Application Data\G DATA
2011-04-12 03:36 . 2011-04-12 03:36 68976 ----a-w- c:\windows\system32\drivers\GRD.sys
2011-04-12 02:26 . 2011-04-12 02:21 15880 ----a-w- c:\windows\system32\lsdelete.exe
2011-04-12 02:26 . 2010-05-11 08:19 137288 ----a-w- c:\program files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}\Components\AvkWebFilterFF.dll
2011-04-12 02:26 . 2011-04-12 02:26 51400 ----a-w- c:\windows\system32\drivers\GDTdiIcpt.sys
2011-04-12 02:26 . 2011-04-12 02:26 29640 ----a-w- c:\windows\system32\drivers\GDNdisIc.sys
2011-04-12 02:26 . 2011-04-12 02:26 62024 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys
2011-04-12 02:26 . 2011-04-12 02:26 38600 ----a-w- c:\windows\system32\drivers\HookCentre.sys
2011-04-12 02:26 . 2011-04-12 02:26 33480 ----a-w- c:\windows\system32\drivers\GDBehave.sys
2011-04-12 02:24 . 2011-04-12 02:50 -------- d-----w- c:\documents and settings\All Users\Application Data\G DATA
2011-04-12 02:24 . 2011-04-12 02:24 -------- d-----w- c:\program files\Common Files\G Data
2011-04-12 02:24 . 2011-04-12 02:24 -------- d-----w- c:\program files\Lavasoft
2011-04-11 20:14 . 2011-04-11 20:14 -------- d--h--w- c:\windows\PIF
2011-04-11 19:45 . 2011-04-11 19:45 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-04-09 00:04 . 2011-04-09 00:04 -------- d-----w- c:\program files\RegTweaker
2011-04-06 01:12 . 2011-04-06 01:12 -------- d-----w- c:\documents and settings\Dominic\Local Settings\Application Data\PCHealth
2011-04-04 20:00 . 2011-04-04 20:00 -------- d-----w- c:\documents and settings\Dominic\Application Data\Malwarebytes
2011-04-04 17:55 . 2011-04-04 17:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-04-04 17:55 . 2010-12-20 22:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-04 17:55 . 2011-04-04 17:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-04-04 17:55 . 2011-04-08 13:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-04 17:55 . 2010-12-20 22:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-04 16:51 . 2011-04-08 17:35 0 ----a-w- c:\windows\Edutik.bin
2011-04-04 16:51 . 2011-04-04 16:51 -------- d-----w- c:\documents and settings\Dominic\Local Settings\Application Data\{6D791525-EE5B-43F0-A819-ECD8A4C2FE84}
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-09 13:53 . 2009-05-20 19:07 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2009-05-20 19:07 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58 . 2009-05-20 19:16 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2009-05-20 19:16 677888 ----a-w- c:\windows\system32\mstsc.exe
2010-04-25 08:06 . 2001-10-31 04:07 249856 ----a-w- c:\program files\SOUNDPAD.EXE
2011-02-09 15:50 . 2011-02-09 15:50 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA5CA8B6-9B9C-4994-A7A1-947B6C631BE7}]
2011-03-29 14:01 243200 ----a-w- c:\program files\RegTweaker\key.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayIconExtension1]
@="{fe25455d-b4c2-4e32-97d2-92632ec1c224}"
[HKEY_CLASSES_ROOT\CLSID\{fe25455d-b4c2-4e32-97d2-92632ec1c224}]
2009-11-07 05:07 297808 ----a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayIconExtension2]
@="{1fae2d88-a78e-4f03-909f-be818a3c1ce6}"
[HKEY_CLASSES_ROOT\CLSID\{1fae2d88-a78e-4f03-909f-be818a3c1ce6}]
2009-11-07 05:07 297808 ----a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-17 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-17 118784]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-06 1434920]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-03-06 79144]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2009-07-08 3054136]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-27 17567744]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-6-22 376832]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 16:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Dominic^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Dominic\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Dominic^Start Menu^Programs^Startup^SolidWorks Task Scheduler Engine.lnk]
path=c:\documents and settings\Dominic\Start Menu\Programs\Startup\SolidWorks Task Scheduler Engine.lnk
backup=c:\windows\pss\SolidWorks Task Scheduler Engine.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-22 05:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eyobekawepazuc]
2008-04-14 12:00 372736 ----a-w- c:\windows\azomutivolubu.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\G Data AntiVirus Tray Application]
2010-06-29 21:20 981504 ----a-w- c:\program files\Lavasoft\Ad-Aware Total Security\AVKTray\AVKTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GDFirewallTray]
2010-06-29 21:22 1550576 ----a-w- c:\program files\Lavasoft\Ad-Aware Total Security\Firewall\GDFirewallTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2011-02-09 15:49 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-04-30 10:46 136176 ----atw- c:\documents and settings\Dominic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 09:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2009-06-17 16:55 55824 ----a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveUpdate]
2010-01-29 15:18 751592 ----a-w- c:\program files\ASUS\LiveUpdate\LiveUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-12-20 22:08 443728 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 12:42 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-07 01:51 3885408 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2008-04-14 12:00 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 09:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 15:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Xmarks]
2010-09-28 05:38 1048576 ----a-w- c:\program files\Xmarks\IE Extension\xmarkssync.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Dominic\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12455:UDP"= 12455:UDP:iTap
"443:TCP"= 443:TCP:Foxtel Downloader 2
.
R0 GDBehave;GDBehave;c:\windows\system32\drivers\GDBehave.sys [11/04/2011 10:26 PM 33480]
R0 GDNdisIc;GDNdisIc;c:\windows\system32\drivers\GDNdisIc.sys [11/04/2011 10:26 PM 29640]
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [23/06/2010 10:26 AM 11448]
R1 GDMnIcpt;GDMnIcpt;c:\windows\system32\drivers\MiniIcpt.sys [11/04/2011 10:26 PM 62024]
R1 GRD;G Data Rootkit Detector Driver;c:\windows\system32\drivers\GRD.sys [11/04/2011 11:36 PM 68976]
R1 HookCentre;HookCentre;c:\windows\system32\drivers\HookCentre.sys [11/04/2011 10:26 PM 38600]
R2 AVKProxy;Ad-Aware Total Security Proxy;c:\program files\Common Files\G Data\AVKProxy\AVKProxy.exe [29/06/2010 5:22 PM 1081384]
R2 AVKService;Ad-Aware Scheduler;c:\program files\Lavasoft\Ad-Aware Total Security\AVK\AVKService.exe [29/06/2010 5:22 PM 412944]
R2 AVKWCtl;Ad-Aware Filesystem Monitor;c:\program files\Lavasoft\Ad-Aware Total Security\AVK\AVKWCtl.exe [23/06/2010 12:35 PM 1635672]
R2 GDTdiInterceptor;GDTdiInterceptor;c:\windows\system32\drivers\GDTdiIcpt.sys [11/04/2011 10:26 PM 51400]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [22/09/2010 9:47 PM 10384]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [04/04/2011 1:55 PM 363344]
R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [04/05/2010 1:07 PM 503080]
R3 GDFwSvc;Ad-Aware Personal Firewall;c:\program files\Lavasoft\Ad-Aware Total Security\Firewall\GDFwSvc.exe [15/06/2010 11:14 AM 1834432]
R3 GDScan;Ad-Aware Scanner;c:\program files\Common Files\G Data\GDScan\GDScan.exe [29/06/2010 5:16 PM 624064]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [01/06/2009 3:26 AM 38912]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [04/04/2011 1:55 PM 20952]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30/04/2010 6:46 AM 136176]
S2 HidCom;USB-HID -> COM Driver Service;c:\windows\system32\drivers\HidCom.sys [09/11/2005 1:01 PM 21016]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [22/06/2009 11:49 PM 1684736]
S3 GDBackupSvc;Ad-Aware Backup Service;c:\program files\Lavasoft\Ad-Aware Total Security\AVKBackup\AVKBackupService.exe [29/06/2010 5:15 PM 911976]
S3 GDTunerSvc;Ad-Aware Tuner Service;c:\program files\Lavasoft\Ad-Aware Total Security\AVKTuner\AVKTunerService.exe [29/06/2010 5:15 PM 1234896]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [09/02/2011 11:49 AM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [30/04/2010 6:46 AM 136176]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [31/10/2009 4:55 PM 18432]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [01/06/2009 3:26 AM 39040]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys --> c:\windows\system32\DRIVERS\wdcsam.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-30 10:46]
.
2011-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-30 10:46]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-68344126-3362229131-3438012487-1005Core.job
- c:\documents and settings\Dominic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-07 10:46]
.
2011-04-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-68344126-3362229131-3438012487-1005UA.job
- c:\documents and settings\Dominic\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-07 10:46]
.
2011-02-10 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
- c:\program files\Microsoft IntelliType Pro\itype.exe [2006-11-21 10:08]
.
2011-02-20 c:\windows\Tasks\mixpadShakeIcon.job
- c:\program files\NCH Swift Sound\MixPad\mixpad.exe [2010-04-25 08:09]
.
2011-03-28 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-04-25 08:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://www.msn.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Dominic\Application Data\Mozilla\Firefox\Profiles\xqcl2m4i.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Ad-Aware WebFilter: {9AA46F4F-4DC7-4c06-97AF-5035170633FE} - c:\program files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}
FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: YouTube mp3: info@youtube-mp3.org - %profile%\extensions\info@youtube-mp3.org
FF - Ext: Gmail Notifier: {44d0a1b4-9c90-4f86-ac92-8680b5d6549e} - %profile%\extensions\{44d0a1b4-9c90-4f86-ac92-8680b5d6549e}
FF - Ext: Zoom toolbar: {FBFB7597-9E32-46b4-A500-8B6B0412777F} - %profile%\extensions\{FBFB7597-9E32-46b4-A500-8B6B0412777F}
FF - Ext: PageZoom Buttons: 54c7d9671b9eccd9e5686a73df34ab60@button.codefisher.org - %profile%\extensions\54c7d9671b9eccd9e5686a73df34ab60@button.codefisher.org
FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: ALMANSOORI WIRELINE SERVICES Community Toolbar: {1105fc58-3295-4308-bace-00e344be1cc7} - %profile%\extensions\{1105fc58-3295-4308-bace-00e344be1cc7}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: XULRunner: {6D791525-EE5B-43F0-A819-ECD8A4C2FE84} - c:\documents and settings\Dominic\Local Settings\Application Data\{6D791525-EE5B-43F0-A819-ECD8A4C2FE84}
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-BrMfcWnd - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
MSConfigStartUp-ControlCenter3 - c:\program files\Brother\ControlCenter3\brctrcen.exe
MSConfigStartUp-k70ccreloc - c:\documents and settings\Dominic\Application Data\2CB5FE0CD8ED5B773626E38628914F23\k70ccreloc.exe
MSConfigStartUp-SetDefPrt - c:\program files\Brother\Brmfl06a\BrStDvPt.exe
MSConfigStartUp-tvncontrol - c:\program files\TightVNC\tvnserver.exe
AddRemove-Power Tools_is1 - c:\documents and settings\Dominic\My Documents\Downloads\Setup_PowerTools_V1.05\Setup_Power Tools_V1.05\Power Tools_V1.05\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-04-26 22:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: ST916031 rev.0002 -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x867B4439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x867ba7d0]; MOV EAX, [0x867ba84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x87174030]
3 CLASSPNP[0xF7505FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000070[0x8717AB58]
5 ACPI[0xF739C620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x87145028]
\Driver\iaStor[0x87171500] -> IRP_MJ_CREATE -> 0x867B4439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x147; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskST9160314AS_____________________________0002SDM1#4&44f0d94&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-68344126-3362229131-3438012487-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FBA0D318-D97B-974B-96FB-2388840E3407}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oamedmmllbgppmlfmmnkenkpiabafl"=hex:6a,61,69,6c,65,67,69,6d,65,6d,6d,6d,6e,64,
6f,68,67,6e,6e,67,00,54
"nagejkfjngkhagbgeocagbohpfdg"=hex:6a,61,69,6c,65,67,69,6d,65,6d,6d,6d,6e,64,
6f,68,67,6e,6e,67,00,54
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\WININET.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
- - - - - - - > 'lsass.exe'(856)
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(10948)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\ASUS\Eee Storage\XPClient.dll
c:\program files\ASUS\Eee Storage\LogicNP.EZShellExtensions.dll
c:\program files\ASUS\Eee Storage\EcaremeDLL.dll
c:\windows\assembly\GAC_MSIL\SqliteShared\1.0.3390.31024__0d0f4b69e50e559b\SqliteShared.dll
c:\windows\assembly\GAC_32\System.Data.SQLite\1.0.60.0__db937bc2d44ff139\System.Data.SQLite.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
.
**************************************************************************
.
Completion time: 2011-04-26 22:17:06 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-27 02:16
.
Pre-Run: 18,298,912,768 bytes free
Post-Run: 18,544,009,216 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 65DA68D10CE8A3445BFC6864A42E08CB
*****************************************************************************
*****************************************************************************
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Dominic at 22:23:01.23 on 26/04/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.476 [GMT -4:00]
.
AV: Ad-Aware Total Security *Enabled/Updated* {71310606-6F3B-49F2-9A81-8315AA75FBB3}
FW: Ad-Aware Personal Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\Program Files\Common Files\G Data\GDScan\GDScan.exe
C:\Program Files\Lavasoft\Ad-Aware Total Security\AVK\AVKWCtl.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Common Files\G Data\AVKProxy\AVKProxy.exe
C:\Program Files\Lavasoft\Ad-Aware Total Security\AVK\AVKService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Nero\Update\NASvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Lavasoft\Ad-Aware Total Security\Firewall\GDFwSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
C:\WINDOWS\AsScrPro.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Dominic\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://www.msn.com
BHO: Ad-Aware WebFilter: {0124123d-61b4-456f-af86-78c53a0790c5} - c:\program files\lavasoft\ad-aware total security\webfilter\AvkWebIE.dll
BHO: QuickNet BHO: {ea5ca8b6-9b9c-4994-a7a1-947b6c631be7} - c:\program files\regtweaker\key.dll
TB: Ad-Aware WebFilter: {0124123d-61b4-456f-af86-78c53a0790c5} - c:\program files\lavasoft\ad-aware total security\webfilter\AvkWebIE.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SynAsusAcpi] c:\program files\synaptics\syntp\SynAsusAcpi.exe
mRun: [ASUS Screen Saver Protector] c:\windows\AsScrPro.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Handler: intu-tt2010 - {97A0575E-2309-4e75-8509-B1F9390C4DE7} - c:\program files\turbotax 2010\ic2010pp.dll
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\dominic\applic~1\mozilla\firefox\profiles\xqcl2m4i.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\documents and settings\dominic\application data\mozilla\firefox\profiles\xqcl2m4i.default\extensions\{1105fc58-3295-4308-bace-00e344be1cc7}\components\RadioWMPCoreGecko19.dll
FF - component: c:\documents and settings\dominic\application data\mozilla\firefox\profiles\xqcl2m4i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\dominic\application data\mozilla\firefox\profiles\xqcl2m4i.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll
FF - component: c:\documents and settings\dominic\application data\mozilla\firefox\profiles\xqcl2m4i.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
FF - component: c:\program files\mozilla firefox\extensions\{9aa46f4f-4dc7-4c06-97af-5035170633fe}\components\AvkWebFilterFF.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Ad-Aware WebFilter: {9AA46F4F-4DC7-4c06-97AF-5035170633FE} - c:\program files\mozilla firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}
FF - Ext: Xmarks: foxmarks@kei.com - %profile%\extensions\foxmarks@kei.com
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: YouTube mp3: info@youtube-mp3.org - %profile%\extensions\info@youtube-mp3.org
FF - Ext: Gmail Notifier: {44d0a1b4-9c90-4f86-ac92-8680b5d6549e} - %profile%\extensions\{44d0a1b4-9c90-4f86-ac92-8680b5d6549e}
FF - Ext: Zoom toolbar: {FBFB7597-9E32-46b4-A500-8B6B0412777F} - %profile%\extensions\{FBFB7597-9E32-46b4-A500-8B6B0412777F}
FF - Ext: PageZoom Buttons: 54c7d9671b9eccd9e5686a73df34ab60@button.codefisher.org - %profile%\extensions\54c7d9671b9eccd9e5686a73df34ab60@button.codefisher.org
FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - Ext: ALMANSOORI WIRELINE SERVICES Community Toolbar: {1105fc58-3295-4308-bace-00e344be1cc7} - %profile%\extensions\{1105fc58-3295-4308-bace-00e344be1cc7}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: XULRunner: {6D791525-EE5B-43F0-A819-ECD8A4C2FE84} - c:\documents and settings\dominic\local settings\application data\{6D791525-EE5B-43F0-A819-ECD8A4C2FE84}
.
============= SERVICES / DRIVERS ===============
.
R0 GDBehave;GDBehave;c:\windows\system32\drivers\GDBehave.sys [2011-4-11 33480]
R0 GDNdisIc;GDNdisIc;c:\windows\system32\drivers\GDNdisIc.sys [2011-4-11 29640]
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-6-23 11448]
R1 GDMnIcpt;GDMnIcpt;c:\windows\system32\drivers\MiniIcpt.sys [2011-4-11 62024]
R1 GRD;G Data Rootkit Detector Driver;c:\windows\system32\drivers\GRD.sys [2011-4-11 68976]
R1 HookCentre;HookCentre;c:\windows\system32\drivers\HookCentre.sys [2011-4-11 38600]
R2 AVKProxy;Ad-Aware Total Security Proxy;c:\program files\common files\g data\avkproxy\AVKProxy.exe [2010-6-29 1081384]
R2 AVKService;Ad-Aware Scheduler;c:\program files\lavasoft\ad-aware total security\avk\AVKService.exe [2010-6-29 412944]
R2 AVKWCtl;Ad-Aware Filesystem Monitor;c:\program files\lavasoft\ad-aware total security\avk\AVKWCtl.exe [2010-6-23 1635672]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-6-23 55152]
R2 GDTdiInterceptor;GDTdiInterceptor;c:\windows\system32\drivers\GDTdiIcpt.sys [2011-4-11 51400]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2010-9-22 10384]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-4-4 363344]
R2 NAUpdate;@c:\program files\nero\update\nasvc.exe,-200;c:\program files\nero\update\NASvc.exe [2010-5-4 503080]
R3 GDFwSvc;Ad-Aware Personal Firewall;c:\program files\lavasoft\ad-aware total security\firewall\GDFwSvc.exe [2010-6-15 1834432]
R3 GDScan;Ad-Aware Scanner;c:\program files\common files\g data\gdscan\GDScan.exe [2010-6-29 624064]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2009-6-1 38912]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-4-4 20952]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-30 136176]
S2 HidCom;USB-HID -> COM Driver Service;c:\windows\system32\drivers\HidCom.sys [2005-11-9 21016]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-6-22 1684736]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
S3 GDBackupSvc;Ad-Aware Backup Service;c:\program files\lavasoft\ad-aware total security\avkbackup\AVKBackupService.exe [2010-6-29 911976]
S3 GDTunerSvc;Ad-Aware Tuner Service;c:\program files\lavasoft\ad-aware total security\avktuner\AVKTunerService.exe [2010-6-29 1234896]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2011-2-9 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-4-30 136176]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2009-10-31 18432]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [2009-6-1 39040]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys --> c:\windows\system32\drivers\wdcsam.sys [?]
.
=============== Created Last 30 ================
.
2011-04-27 01:24:09 -------- d-sha-r- C:\cmdcons
2011-04-27 01:15:27 98816 ----a-w- c:\windows\sed.exe
2011-04-27 01:15:27 89088 ----a-w- c:\windows\MBR.exe
2011-04-27 01:15:27 256512 ----a-w- c:\windows\PEV.exe
2011-04-27 01:15:27 161792 ----a-w- c:\windows\SWREG.exe
2011-04-13 17:17:28 -------- d-----w- c:\docume~1\dominic\applic~1\Intuit Canada
2011-04-13 17:17:08 -------- d-----w- c:\program files\common files\Intuit
2011-04-13 17:17:01 -------- d-----w- c:\program files\TurboTax 2010
2011-04-13 17:16:47 -------- d-----w- c:\docume~1\alluse~1\applic~1\Intuit Canada
2011-04-13 13:52:48 -------- d-----w- c:\docume~1\dominic\locals~1\applic~1\G DATA
2011-04-12 03:36:51 68976 ----a-w- c:\windows\system32\drivers\GRD.sys
2011-04-12 02:26:51 15880 ----a-w- c:\windows\system32\lsdelete.exe
2011-04-12 02:26:41 137288 ----a-w- c:\program files\mozilla firefox\extensions\{9aa46f4f-4dc7-4c06-97af-5035170633fe}\components\AvkWebFilterFF.dll
2011-04-12 02:26:19 51400 ----a-w- c:\windows\system32\drivers\GDTdiIcpt.sys
2011-04-12 02:26:19 29640 ----a-w- c:\windows\system32\drivers\GDNdisIc.sys
2011-04-12 02:26:14 62024 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys
2011-04-12 02:26:14 38600 ----a-w- c:\windows\system32\drivers\HookCentre.sys
2011-04-12 02:26:14 33480 ----a-w- c:\windows\system32\drivers\GDBehave.sys
2011-04-12 02:24:50 -------- d-----w- c:\program files\Lavasoft
2011-04-12 02:24:50 -------- d-----w- c:\program files\common files\G Data
2011-04-12 02:24:50 -------- d-----w- c:\docume~1\alluse~1\applic~1\G DATA
2011-04-11 20:14:41 -------- d--h--w- c:\windows\PIF
2011-04-09 00:04:58 -------- d-----w- c:\program files\RegTweaker
2011-04-06 01:12:38 -------- d-----w- c:\docume~1\dominic\locals~1\applic~1\PCHealth
2011-04-04 20:00:12 -------- d-----w- c:\docume~1\dominic\applic~1\Malwarebytes
2011-04-04 17:55:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-04 17:55:37 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-04-04 17:55:34 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-04 17:55:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-04 16:51:07 0 ----a-w- c:\windows\Edutik.bin
2011-04-04 16:51:05 -------- d-----w- c:\docume~1\dominic\locals~1\applic~1\{6D791525-EE5B-43F0-A819-ECD8A4C2FE84}
.
==================== Find3M ====================
.
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2010-04-25 08:06:43 249856 ----a-w- c:\program files\SOUNDPAD.EXE
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: ST916031 rev.0002 -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x867B4439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x867ba7d0]; MOV EAX, [0x867ba84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x87174030]
3 CLASSPNP[0xF7505FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000070[0x8717AB58]
5 ACPI[0xF739C620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x87145028]
\Driver\iaStor[0x87171500] -> IRP_MJ_CREATE -> 0x867B4439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x147; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskST9160314AS_____________________________0002SDM1#4&44f0d94&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 22:25:33.04 ===============
Attach.txt (16.26K)
Number of downloads: 1