SuperDave !
I installed Avast! (Is it ok to run Avast! along side an anti malware program like SuperAntiSpyware ?)
The AVG removal tool worked, AVG is gone.
Combofix was able to run and produced this log :
ComboFix 10-11-12.06 - Rob 11/14/2010 2:12.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1024.429 [GMT 1:00]
Running from: c:\documents and settings\Rob\Desktop\war on spyware\commy.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Rob\Application Data\install
c:\program files\Search Settings
c:\program files\Search Settings\FF\chrome.manifest
c:\program files\Search Settings\FF\chrome\content\plugin.js
c:\program files\Search Settings\FF\chrome\content\plugin.xul
c:\program files\Search Settings\FF\chrome\content\protection.js
c:\program files\Search Settings\FF\chrome\content\utils.js
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.dtd
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.properties
c:\program files\Search Settings\FF\components\IFBHOSearch.xpt
c:\program files\Search Settings\FF\components\IFBHOSearchHelperEngine.xpt
c:\program files\Search Settings\FF\components\IFHelperPreferences.xpt
c:\program files\Search Settings\FF\components\SearchSettingsFF.dll
c:\program files\Search Settings\FF\install.rdf
c:\program files\Search Settings\SearchSettings.exe
c:\program files\Search Settings\SearchSettings_AVG_RESTORED.exe
c:\program files\Search Settings\SearchSettingsRes409.dll
c:\windows\system\Pncrt.dll
c:\windows\system32\driVERs\ndhchq.sys
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ndhchq
-------\Service_ndhchq
((((((((((((((((((((((((( Files Created from 2010-10-14 to 2010-11-14 )))))))))))))))))))))))))))))))
.
2010-11-13 14:40 . 2010-11-13 14:40 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Google
2010-11-13 14:18 . 2010-09-07 15:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-11-13 14:18 . 2010-09-07 15:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-11-13 14:18 . 2010-09-07 15:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-11-13 14:18 . 2010-09-07 15:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-11-13 14:18 . 2010-09-07 15:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-11-13 14:18 . 2010-09-07 15:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-11-13 14:18 . 2010-09-07 15:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-11-13 14:17 . 2010-09-07 16:12 38848 ----a-w- c:\windows\avastSS.scr
2010-11-13 14:17 . 2010-09-07 16:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
2010-11-13 14:17 . 2010-11-13 14:17 -------- d-----w- c:\program files\Alwil Software
2010-11-13 14:17 . 2010-11-13 14:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-11-13 13:17 . 2010-11-13 13:27 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2010-11-10 22:43 . 2010-11-10 23:50 -------- d-----w- c:\documents and settings\Rob\Application Data\Celemony Software GmbH
2010-11-10 22:42 . 2010-11-10 22:42 -------- d-----w- c:\program files\Common Files\VST3
2010-11-10 22:41 . 2010-11-10 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Celemony Software GmbH
2010-11-10 22:41 . 2010-11-10 22:41 -------- d-----w- c:\program files\Common Files\Celemony
2010-11-08 04:09 . 2010-11-08 04:09 388096 ----a-r- c:\documents and settings\Rob\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-08 04:09 . 2010-11-13 01:32 -------- d-----w- c:\program files\Trend Micro
2010-11-03 19:23 . 2010-11-03 19:23 -------- d-----w- C:\VritualRoot
2010-11-03 11:39 . 2010-11-03 11:39 -------- d-----w- c:\documents and settings\Rob\Application Data\Malwarebytes
2010-11-03 11:39 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-03 11:39 . 2010-11-03 11:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-03 11:39 . 2010-11-03 11:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-11-03 11:39 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-03 11:29 . 2010-11-03 11:29 -------- d-----w- c:\documents and settings\Administrator
2010-11-03 02:22 . 2010-11-03 02:22 -------- d-----w- c:\documents and settings\Rob\Application Data\SUPERAntiSpyware.com
2010-11-03 02:22 . 2010-11-03 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-11-03 02:22 . 2010-11-08 15:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-11-03 01:59 . 2010-11-03 01:59 -------- d-----w- c:\program files\CCleaner
2010-11-03 01:45 . 2010-11-03 01:45 -------- d-----w- c:\program files\COMODO
2010-11-03 01:42 . 2010-11-03 11:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2010-11-02 19:41 . 2010-11-02 19:41 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-11-02 18:02 . 2010-11-02 18:02 -------- d-sh--w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
2010-11-02 08:52 . 2006-03-30 16:39 368640 ----a-w- c:\windows\system32\ReWire.dll
2010-11-02 08:07 . 2003-11-18 05:27 2402025 ----a-w- c:\windows\system32\dongle.dll
2010-10-31 00:26 . 2010-10-31 00:26 -------- d-----w- c:\windows\system32\wbem\Repository
2010-10-30 23:44 . 2010-10-30 23:44 -------- d-----w- c:\documents and settings\Rob\Application Data\DriverCure
2010-10-28 23:34 . 2010-10-28 23:34 -------- d-----w- c:\program files\u-he
2010-10-28 23:34 . 2010-11-10 22:41 -------- d-----w- c:\program files\Celemony
2010-10-27 21:40 . 2010-10-27 21:40 -------- d-----w- c:\documents and settings\Rob\Application Data\Antares
2010-10-27 21:18 . 2010-11-02 10:28 -------- d-----w- c:\program files\Antares Audio Technologies
2010-10-27 12:15 . 2010-11-13 13:45 -------- d-----w- C:\found.001
2010-10-26 17:12 . 2010-11-13 13:10 -------- d-----w- c:\documents and settings\Rob\Application Data\uTorrent
2010-10-26 12:49 . 2010-11-02 07:57 -------- d-----w- c:\program files\Syncrosoft
2010-10-26 12:49 . 2002-11-25 05:36 45056 ----a-w- c:\windows\system32\Synsopos.exe
2010-10-26 12:47 . 2000-06-27 21:40 487936 ----a-w- c:\windows\system32\Rmbe3260.dll
2010-10-26 12:47 . 1999-02-26 16:08 87040 ----a-w- c:\windows\system32\Ra32sipr.dll
2010-10-26 12:47 . 1999-02-26 16:08 72704 ----a-w- c:\windows\system32\Ra3228_8.dll
2010-10-26 12:47 . 1999-02-26 16:08 21504 ----a-w- c:\windows\system32\Ra32dnet.dll
2010-10-26 12:47 . 2000-06-27 21:40 352768 ----a-w- c:\windows\system32\pngu3263.dll
2010-10-26 12:47 . 1999-02-26 16:08 81920 ----a-w- c:\windows\system32\Ra3214_4.dll
2010-10-26 12:47 . 1999-02-26 16:08 131072 ----a-w- c:\windows\system32\Pneng50.dll
2010-10-26 12:47 . 1999-02-26 16:08 85504 ----a-w- c:\windows\system32\Encdnet.dll
2010-10-26 12:47 . 1999-02-26 16:08 61952 ----a-w- c:\windows\system32\Decdnet.dll
2010-10-26 12:47 . 1999-02-26 16:08 130560 ----a-w- c:\windows\system32\Pnc3250.dll
2010-10-25 22:24 . 2010-10-25 22:36 -------- d-----w- c:\documents and settings\Rob\Application Data\Easy Duplicate Finder
2010-10-23 22:32 . 2007-11-06 11:22 36224 ----a-w- c:\windows\system32\drivers\ArcCD.sys
2010-10-23 22:32 . 2007-04-25 06:55 134912 ----a-w- c:\windows\system32\drivers\ArcUdfs.sys
2010-10-23 22:32 . 2007-04-24 09:33 7680 ----a-w- c:\windows\system32\drivers\ArcRec.sys
2010-10-21 13:47 . 2010-10-23 22:32 -------- d-----w- c:\program files\Kodak
2010-10-20 20:16 . 2010-10-20 20:16 -------- d-----w- c:\documents and settings\Rob\Application Data\AnvSoft
2010-10-20 20:16 . 2010-10-20 20:17 -------- d-----w- c:\program files\Any Video Converter
2010-10-20 19:29 . 2010-10-20 19:32 -------- d-----w- c:\documents and settings\Rob\Local Settings\Application Data\Video Converter
2010-10-20 19:28 . 2010-10-26 12:28 -------- d-----w- c:\program files\Free Video Converter
2010-10-20 19:27 . 2010-10-20 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\VideoConverter
2010-10-19 15:46 . 2010-10-19 15:46 -------- d-----w- c:\documents and settings\Rob\Local Settings\Application Data\ArcSoft
2010-10-19 15:42 . 2010-10-21 13:51 -------- d--h--w- c:\documents and settings\All Users\Application Data\ArcSoft
2010-10-19 15:40 . 2006-11-10 13:05 18688 ----a-w- c:\windows\system32\drivers\afc.sys
2010-10-19 15:40 . 2010-10-23 22:34 -------- d-----w- c:\program files\Common Files\ArcSoft
2010-10-19 15:39 . 2010-10-19 16:15 -------- d-----w- c:\documents and settings\Rob\Application Data\ArcSoft
2010-10-19 11:12 . 2010-10-19 11:12 -------- d-----w- c:\documents and settings\Guest\Application Data\Apple Computer
2010-10-19 11:12 . 2010-10-19 11:12 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-03 15:14 . 2010-10-03 15:14 76 ----a-w- c:\documents and settings\Rob\Local Settings\Application Data\GLF458.tmp
2010-09-19 20:32 . 2010-09-18 17:44 184976 ----a-w- C:\CEPxReverb3.tmp
2010-09-19 19:25 . 2009-12-25 18:38 2762080 ----a-w- C:\CEPxReverb2.tmp
2010-09-19 17:13 . 2009-10-24 18:32 5058192 ----a-w- C:\CEPxReverb1.tmp
2010-09-19 17:05 . 2009-10-23 23:22 3890576 ----a-w- C:\CEPxReverb0.tmp
2010-09-19 16:59 . 2009-10-23 20:08 2882976 ----a-w- C:\CEPxReverb9.tmp
2010-09-19 16:58 . 2009-10-23 19:56 2561744 ----a-w- C:\CEPxReverb8.tmp
2010-09-19 15:53 . 2009-10-23 19:55 2440800 ----a-w- C:\CEPxReverb7.tmp
2010-09-19 14:11 . 2009-10-13 23:12 698256 ----a-w- C:\CEPxReverb6.tmp
2010-09-19 14:11 . 2009-10-13 23:11 3366624 ----a-w- C:\CEPxReverb5.tmp
2010-09-18 17:45 . 2010-09-18 17:45 2142080 ----a-w- C:\CEPxReverb4.tmp
2010-09-10 22:41 . 2010-09-10 22:41 285480 ----a-w- c:\windows\system32\guard32.dll
2010-09-10 22:40 . 2010-09-10 22:40 91560 ----a-w- c:\windows\system32\drivers\inspect.sys
2010-09-10 22:40 . 2010-09-10 22:40 25240 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-09-10 22:40 . 2010-09-10 22:40 239240 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-09-10 22:40 . 2010-09-10 22:40 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys
2010-09-08 09:17 . 2010-09-08 09:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 09:17 . 2010-09-08 09:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
.
------- Sigcheck -------
[-] 2008-04-14 . 355EDBB4D412B01F1740C17E3F50FA00 . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll
[7] 2004-08-03 . 98EC447E00229AFD88D5161A25D065DA . 343040 . . [7.0.2600.2180] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\msvcrt.dll
[7] 2004-08-03 . B0FEFA816D61EC66AA765DDF534EAB5E . 343040 . . [7.0.2600.2180] . . c:\windows\system32\dllcache\msvcrt.dll
[7] 2002-08-29 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"DeltTray"="DeltTray.exe" [2003-12-10 56320]
"B2C_AGENT"="c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe" [2010-03-16 300992]
"tsnp2std"="c:\windows\tsnp2std.exe" [2005-11-14 110592]
"snp2std"="c:\windows\vsnp2std.exe" [2005-11-16 344064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-09-10 2500552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"ArcSoft MediaImpression Monitor"="c:\program files\Kodak\MediaImpression\ArcMonitor.exe" [2010-07-20 80384]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-9-8 113664]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1035:TCP"= 1035:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
R0 inic1620;inic1620;c:\windows\system32\drivers\inic1620.sys [9/3/2009 4:41 PM 20224]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10/24/2009 1:43 PM 64288]
R0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [9/4/2009 5:10 PM 84529]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11/13/2010 3:18 PM 165584]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [9/10/2010 11:40 PM 239240]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/10/2010 11:40 PM 25240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 7:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 7:41 PM 67656]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [12/16/2009 5:38 PM 375296]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/13/2010 3:18 PM 17744]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 12:17 PM 1181328]
R3 ArcCD;ArcCD Filter Driver Service;c:\windows\system32\drivers\ArcCD.sys [10/23/2010 11:32 PM 36224]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/13/2010 3:18 PM 136176]
S4 ArcUdfs;ArcUdfs FileSystem Driver Service;c:\windows\system32\drivers\ArcUdfs.sys [10/23/2010 11:32 PM 134912]
--- Other Services/Drivers In Memory ---
*Deregistered* - ArcRec
.
Contents of the 'Scheduled Tasks' folder
2010-11-14 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 19:44]
2010-11-14 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 19:44]
2010-11-14 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 19:44]
2010-11-14 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 19:44]
2010-11-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 19:44]
2010-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-13 14:18]
2010-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-11-13 14:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {F40B8187-044C-4BFC-8FC8-B9C24ED5BE98} = 156.154.70.22,156.154.71.22
FF - ProfilePath - c:\documents and settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/403
FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=403&q=
FF - component: c:\documents and settings\Rob\Application Data\Mozilla\Firefox\Profiles\33uo4by5.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npornap.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-RevHDD - c:\windows\SYSTEM\RevHDD.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
Notify-avgrsstarter - avgrsstx.dll
AddRemove-VB:FFX-4 Rack - c:\program files\VB\FFX4\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-11-14 02:33
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5
977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,eb,9f,f0,f1,a6,9c,30,46,b7,40,12,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839
E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,eb,9f,f0,f1,a6,9c,30,46,b7,40,12,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\WININET.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'lsass.exe'(796)
c:\windows\system32\guard32.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2324)
c:\windows\system32\WININET.dll
c:\windows\system32\guard32.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\DeltTray.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\program files\iPod\bin\iPodService.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-11-14 02:40:05 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-14 01:39
Pre-Run: 14,949,916,672 bytes free
Post-Run: 16,544,411,648 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 5EFB47407E3E9A14136BF9EC820B082A