Thank u Mr Evilfantasy
Instructions followed verbatim (I assume they are in order and specific for a reason)
Combofix stopped and rebooted in middle siting the presence of root activity and resumed. I didn't expect it to log off and reboot just b4 "Preparing Log Report" but maybe that is normal.
AVG was removed from tray and other things moved around through this ordeal
Combofix log:
ComboFix 10-05-04.04 - SUSAN TORK 05/04/2010 21:36:56.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.601 [GMT -5:00]
Running from: c:\documents and settings\SUSAN TORK\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\WindowsUpdate
c:\recycler\S-1-5-21-522090433-925392414-3357670280-1003
c:\windows\system32\avgrsstx.dll
c:\windows\system32\ctfmon .exe
c:\windows\system32\drivers\xakcj.sys
c:\windows\system32\pragmabbr.dll
c:\windows\system32\PRAGMAsrcr.dat
c:\windows\system32\sqlite3.dll
----- BITS: Possible infected sites -----
hxxp://dibs.ddni.net
Infected copy of c:\windows\system32\drivers\rasacd.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ocskb
-------\Service_ocskb
((((((((((((((((((((((((( Files Created from 2010-04-05 to 2010-05-05 )))))))))))))))))))))))))))))))
.
2010-05-04 20:46 . 2010-05-04 20:46 -------- d-----w- c:\program files\Trend Micro
2010-05-04 20:43 . 2010-05-04 20:43 -------- d-----w- c:\program files\Common Files\Java
2010-05-04 20:42 . 2010-05-04 20:42 503808 ----a-w- c:\documents and settings\SUSAN TORK\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5e3fe64e-n\msvcp71.dll
2010-05-04 20:42 . 2010-05-04 20:42 499712 ----a-w- c:\documents and settings\SUSAN TORK\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5e3fe64e-n\jmc.dll
2010-05-04 20:42 . 2010-05-04 20:42 348160 ----a-w- c:\documents and settings\SUSAN TORK\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5e3fe64e-n\msvcr71.dll
2010-05-04 20:42 . 2010-05-04 20:42 12800 ----a-w- c:\documents and settings\SUSAN TORK\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-529f682a-n\decora-d3d.dll
2010-05-04 20:42 . 2010-05-04 20:42 61440 ----a-w- c:\documents and settings\SUSAN TORK\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-529f682a-n\decora-sse.dll
2010-05-04 20:42 . 2010-04-12 22:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-04 17:25 . 2010-05-04 17:25 63488 ----a-w- c:\documents and settings\SUSAN TORK\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-05-04 17:25 . 2010-05-04 17:25 52224 ----a-w- c:\documents and settings\SUSAN TORK\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-05-04 17:25 . 2010-05-04 17:25 117760 ----a-w- c:\documents and settings\SUSAN TORK\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-05-04 17:24 . 2010-05-04 17:24 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-05-04 17:24 . 2010-05-04 17:24 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-05-04 17:24 . 2010-05-04 17:24 -------- d-----w- c:\documents and settings\SUSAN TORK\Application Data\SUPERAntiSpyware.com
2010-05-04 17:22 . 2010-05-04 17:22 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-05-04 03:45 . 2010-05-04 03:45 -------- d-----w- c:\documents and settings\SUSAN TORK\Application Data\Malwarebytes
2010-05-04 03:45 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-04 03:45 . 2010-05-04 03:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-04 03:45 . 2010-05-04 03:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-04 03:45 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-03 17:46 . 2010-05-04 16:08 -------- d-----w- c:\documents and settings\SUSAN TORK\Local Settings\Application Data\vvxhxatin
2010-05-03 17:45 . 2010-05-03 17:46 -------- d-----w- c:\documents and settings\SUSAN TORK\Application Data\0E6F04692F7986568160CFC22A3747AF
2010-05-03 17:45 . 2010-05-03 17:45 107008 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\b00001b44.dll
2010-04-24 15:49 . 2010-04-24 15:49 -------- d-----w- c:\documents and settings\SUSAN TORK\Application Data\MSNInstaller
2010-04-24 03:50 . 2010-04-24 03:50 360584 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-04-24 03:50 . 2010-04-24 03:50 333192 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-04-24 03:50 . 2010-04-24 03:50 28424 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-04-21 23:29 . 2010-04-21 23:29 -------- d-----w- c:\documents and settings\SUSAN TORK\Application Data\DivX
2010-04-21 23:17 . 2010-04-21 23:17 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-04-21 23:14 . 2010-04-21 23:10 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-04-21 23:14 . 2010-04-21 23:09 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-21 23:10 . 2010-04-21 23:10 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-04-21 23:10 . 2010-04-21 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-04-15 00:07 . 2010-04-15 00:07 -------- d-----w- c:\documents and settings\SUSAN TORK\Local Settings\Application Data\WMTools Downloaded Files
2010-04-10 15:35 . 2010-04-10 15:35 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonBJ
2010-04-10 15:18 . 2007-04-02 10:00 69632 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8U.DLL
2010-04-10 15:18 . 2007-04-02 10:00 27136 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8U.DLL
2010-04-10 15:18 . 2008-02-06 10:00 216064 ----a-w- c:\windows\system32\CNMLM8U.DLL
2010-04-10 15:18 . 2010-04-10 15:18 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
2010-04-10 15:18 . 2007-03-15 19:12 188416 ----a-w- c:\windows\system32\CNC470O.DLL
2010-04-10 15:18 . 2007-03-23 21:30 1400832 ----a-w- c:\windows\system32\CNC470C.DLL
2010-04-10 15:18 . 2007-03-23 21:29 98304 ----a-w- c:\windows\system32\CNC470I.DLL
2010-04-10 15:18 . 2007-03-19 15:21 200704 ----a-w- c:\windows\system32\CNC470L.DLL
2010-04-10 15:17 . 2010-04-10 15:17 -------- d--h--w- c:\program files\CanonBJ
2010-04-09 16:40 . 2010-05-04 20:14 -------- d-----w- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-04 22:50 . 2010-03-13 05:50 0 ----a-w- c:\documents and settings\SUSAN TORK\Local Settings\Application Data\prvlcl.dat
2010-05-04 20:41 . 2009-08-27 00:07 -------- d-----w- c:\program files\Java
2010-05-04 20:14 . 2010-03-12 07:02 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-05-04 20:14 . 2010-02-07 19:00 -------- d-----w- c:\program files\iTunes
2010-05-04 20:14 . 2009-09-26 05:34 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-05-04 05:56 . 2009-06-18 20:32 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-04 02:21 . 2009-12-08 04:44 -------- d-----w- c:\program files\CCleaner
2010-04-24 03:50 . 2010-03-06 23:11 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-24 03:50 . 2009-09-01 14:57 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-24 03:48 . 2009-09-01 14:57 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-24 03:02 . 2010-04-24 03:23 244142 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1033.dat
2010-04-21 23:14 . 2010-04-21 23:14 56766 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-04-21 23:14 . 2010-04-21 23:14 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-04-21 23:14 . 2010-04-21 23:14 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-04-21 23:14 . 2010-04-21 23:12 -------- d-----w- c:\program files\DivX
2010-04-21 23:14 . 2010-04-21 23:14 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-04-21 23:14 . 2010-04-21 23:14 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-04-21 23:14 . 2010-04-21 23:14 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-04-21 23:14 . 2010-04-21 23:14 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-04-21 23:14 . 2010-04-21 23:14 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-04-21 23:14 . 2010-04-21 23:14 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-04-21 23:13 . 2010-04-21 23:13 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-04-21 23:13 . 2010-04-21 23:13 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-04-21 23:13 . 2010-04-21 23:13 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-04-21 23:00 . 2010-02-07 19:01 -------- d-----w- c:\documents and settings\SUSAN TORK\Application Data\Apple Computer
2010-04-17 20:29 . 2009-08-10 23:36 -------- d-----w- c:\program files\Google
2010-04-15 00:45 . 2009-05-04 11:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-10 05:13 . 2010-04-03 00:13 165312 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-04-02 23:09 . 2009-06-18 20:31 72040 ----a-w- c:\documents and settings\SUSAN TORK\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-11 12:38 . 2004-08-04 20:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 20:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2004-08-04 20:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2004-08-04 20:00 430080 ------w- c:\windows\system32\vbscript.dll
2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-03-06 23:11 . 2010-03-06 23:11 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-03-06 23:11 . 2009-09-01 14:57 -------- d-----w- c:\program files\AVG
2010-02-24 13:11 . 2004-08-04 20:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 19:27 . 2010-02-19 19:27 720384 ----a-w- c:\windows\system32\DivX.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2010-02-19 19:27 . 2010-02-19 19:27 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2010-02-19 19:27 . 2010-02-19 19:27 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2010-02-19 19:27 . 2010-02-19 19:27 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2010-02-16 14:08 . 2004-08-04 20:00 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-04 06:59 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2004-08-04 20:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 20:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
<pre>
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\DivX\DivX Update\divxupdate .exe
c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\program files\Hewlett-Packard\HP Software Update\hpwuschd .exe
c:\program files\HP\hpcoretech\hpcmpmgr .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Lenovo\Energy Management\energy management .exe
c:\program files\Lenovo\Energy Management\utility .exe
c:\program files\Microsoft ActiveSync\wcescomm .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Spybot - Search & Destroy\teatimer .exe
c:\windows\BisonC07\bisonm07 .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09 .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2009-06-06 14:52 241752 ----a-w- c:\windows\system32\IcnOvrly.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\SUSAN TORK\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-18 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ID Vault.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ID Vault.lnk
backup=c:\windows\pss\ID Vault.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-12-02 18:34 35184 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-28 07:00 166424 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IdeaNotesUser]
2009-08-24 14:15 221872 ----a-w- c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGUser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-02-28 07:00 141848 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
c:\program files\Messenger\msmsgs.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-02-28 07:00 137752 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-03-24 11:10 17567744 ----a-w- c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2009-04-09 13:13 1512744 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
2009-06-06 14:52 323584 ----a-w- c:\program files\Lenovo\VeriFaceIII\PManage.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\spoolsv.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/1/2009 9:57 AM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/6/2010 6:11 PM 242896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [4/27/2010 5:30 PM 61440]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [4/23/2010 10:50 PM 308064]
R2 DDNIMSGService;DDNIMSGService;c:\program files\DDNI\Lenovo Idea Notes\DDNIMSGService.exe [1/17/2009 1:59 AM 172720]
R2 DDNIService;DDNIService;c:\program files\DDNI\DIBS\DDNIService.exe [5/4/2009 6:52 AM 160432]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\qstart.sys\config\DVMExportService.exe [3/25/2009 9:20 PM 315392]
R2 System_Repair_UpdateMonitor;System Repair Windows Update Monitor;c:\program files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe [5/4/2009 6:17 AM 430080]
R2 tvtumon;tvtumon;c:\windows\system32\drivers\tvtumon.sys [5/4/2009 6:17 AM 48192]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [6/6/2009 9:56 AM 9472]
S2 gupdate1ca1a13d4570dfa;Google Update Service (gupdate1ca1a13d4570dfa);c:\program files\Google\Update\GoogleUpdate.exe [8/10/2009 6:39 PM 133104]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [5/4/2009 6:10 AM 1684736]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys --> c:\windows\system32\Drivers\RtsUStor.sys [?]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [5/4/2009 6:17 AM 81192]
.
Contents of the 'Scheduled Tasks' folder
2010-05-05 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 07:54]
2010-05-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-10 23:36]
2010-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]
2010-05-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]
2010-05-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-409764278-1039016446-177758585-1008Core.job
- c:\documents and settings\SUSAN TORK\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-04 15:08]
2010-05-05 c:\windows\Tasks\User_Feed_Synchronization-{E0937533-BB98-490D-955D-A0280C0E943C}.job
- c:\windows\system32\msfeedssync.exe [2009-05-04 10:36]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://lenovo.live.com/
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\SUSAN TORK\Application Data\Mozilla\Firefox\Profiles\s3wyq629.default\
FF - prefs.js: browser.search.selectedEngine - Google (Language: EN)
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\SUSAN TORK\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\SUSAN TORK\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.
enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_
everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a
s_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugi
n", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
Notify-AutorunsDisabled - avgrsstx.dll
Notify-avgrsstarter - avgrsstx.dll
AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-04 21:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\AutorunsDisabled]
@DACL=(02 0000)
"AVG8_TRAY"="c:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(688)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3324)
c:\windows\system32\WININET.dll
c:\windows\system32\IcnOvrly.dll
c:\windows\system32\IEFRAME.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\documents and settings\SUSAN TORK\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
.
**************************************************************************
.
Completion time: 2010-05-04 21:51:07 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-05 02:51
Pre-Run: 78,300,327,936 bytes free
Post-Run: 78,216,916,992 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 285D74C3179E177ACF42BB9D282EADC5