Combofix log.
ComboFix 12-02-13.01 - Administrator 02/19/2012 20:21:33.1.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2800 [GMT -5:00]
Running from: c:\documents and settings\Administrator.ARTZDELUX\Desktop\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
- REDUCED FUNCTIONALITY MODE -
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\driver
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system32\AutoRun.inf
G:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-01-20 to 2012-02-20 )))))))))))))))))))))))))))))))
.
.
2012-02-19 22:22 . 2012-02-19 22:22 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2012-02-19 21:32 . 2012-02-19 21:32 -------- d-----w- c:\documents and settings\Administrator.ARTZDELUX\Application Data\SUPERAntiSpyware.com
2012-02-19 21:31 . 2012-02-19 21:32 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-02-19 21:31 . 2012-02-19 21:31 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-02-19 00:05 . 2012-02-19 00:05 -------- d-----w- c:\documents and settings\Administrator.ARTZDELUX\Local Settings\Application Data\Identities
2012-02-18 22:50 . 2012-02-18 22:50 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2012-02-18 22:02 . 2012-02-18 22:33 -------- d-----w- c:\documents and settings\Administrator.ARTZDELUX\Local Settings\Application Data\Adobe
2012-02-18 21:59 . 2012-02-18 21:59 -------- d-sh--w- c:\documents and settings\Administrator.ARTZDELUX\PrivacIE
2012-02-18 18:39 . 2012-02-20 01:07 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-01-22 00:54 . 2012-01-22 00:54 -------- d--h--w- c:\program files\VitalSource Bookshelf
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-19 21:23 . 2008-07-21 10:23 110592 ----a-w- c:\windows\DUMP5c49.tmp
2012-02-16 00:59 . 2011-11-15 01:26 137416 ---ha-w- c:\windows\system32\drivers\avipbb.sys
2012-01-07 18:32 . 2012-01-07 18:32 414368 ---ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-02 05:15 . 2012-01-02 05:15 0 ---ha-w- C:\LOG35.tmp
2011-12-25 18:04 . 2004-08-03 13:56 26112 ---ha-w- c:\windows\system32\userinit.exe
2011-12-18 18:40 . 2011-12-18 18:40 0 ---ha-w- C:\LOG16.tmp
2011-12-18 18:23 . 2011-12-18 18:23 0 ---ha-w- C:\LOGB.tmp
2011-12-10 20:24 . 2009-01-08 23:23 20464 ---ha-w- c:\windows\system32\drivers\mbam.sys
2011-11-23 00:12 . 2011-11-26 19:00 16432 ---ha-w- c:\windows\system32\lsdelete.exe
2011-11-23 00:12 . 2011-04-19 22:20 101720 ---ha-w- c:\windows\system32\drivers\SBREDrv.sys
2007-11-09 20:10 . 2007-11-09 20:10 30288 ---ha-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-11-09 20:10 . 2007-11-09 20:10 79440 ---ha-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-11-09 20:10 . 2007-11-09 20:10 75344 ---ha-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2007-11-09 20:10 . 2007-11-09 20:10 140880 ---ha-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-11-09 20:10 . 2007-11-09 20:10 42576 ---ha-w- c:\program files\mozilla firefox\plugins\icafile.dll
2007-11-09 20:10 . 2007-11-09 20:10 50768 ---ha-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2007-11-09 20:10 . 2007-11-09 20:10 34384 ---ha-w- c:\program files\mozilla firefox\plugins\logging.dll
2007-11-09 20:11 . 2007-11-09 20:11 685648 ---ha-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-11-09 20:11 . 2007-11-09 20:11 30288 ---ha-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2011-11-23 00:31 . 2011-06-12 15:36 134104 ---ha-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-01-20 4617600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-11 16342528]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-26 1983816]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-10-19 258512]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest wsauth
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Laura^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Laura\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\rundll32.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\VMware\\VMware View\\Client\\bin\\vmware-remotemks.exe"=
"c:\\Program Files\\VMware\\VMware View\\Client\\bin\\wswc.exe"=
.
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R3 vmwvusb;VMware View Generic USB Driver;c:\windows\system32\drivers\vmwvusb.sys [1/16/2012 7:26 PM 39984]
S1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [11/14/2011 8:26 PM 36000]
S1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [7/21/2008 1:05 PM 13696]
S1 BS_I2cIo;BS_I2cIo;c:\windows\system32\drivers\BS_I2cIo.sys [7/22/2008 11:27 PM 16768]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
S2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/14/2011 8:26 PM 86224]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [11/3/2011 12:06 PM 2152152]
S2 NetworkLog;NetworkLog;c:\windows\svcs.exe --> c:\windows\svcs.exe [?]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/8/2008 5:47 PM 24652]
S2 wsnm;VMware View Client;c:\program files\VMware\VMware View\Client\bin\wsnm.exe [2/18/2011 6:37 PM 494192]
S2 wsnm_usbctrl;VMware View USB Control;c:\program files\VMware\VMware View\Client\bin\wsnm_usbctrl.exe [2/18/2011 6:38 PM 793200]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [11/3/2011 12:06 PM 15232]
S3 MobileAdapter;Mobile Adapter USB Modem and USB Serial;c:\windows\system32\drivers\qscnusb.sys [2/21/2010 12:23 PM 103552]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
NVNET
de_serv
qbfcservice
btwrchid
sffdisk
hcwPVRP2
Hardlock
npkcsvc
oracleorahomedatagatherer
z800mdm
bdss
svcwmu
Amsmpu4p
pcidrv
se45mdfl
trackcam4
inort
p2pgasvc
cwafreportscheduler
msgsrvservice
rksample
axinstsv
iaimfp2
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-11-03 17:06]
.
2011-12-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
2012-02-18 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-03-24 02:18]
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Administrator.ARTZDELUX\Application Data\Mozilla\Firefox\Profiles\6ioqnxb3.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM-Run-c:\windows\system32\kdkjo.exe - c:\windows\system32\kdkjo.exe
HKLM-Run-dplaysvr - c:\documents and settings\Administrator.ARTZDELUX\Application Data\dplaysvr.exe
HKU-Default-Run-dplaysvr - c:\documents and settings\Administrator.ARTZDELUX\Application Data\dplaysvr.exe
MSConfigStartUp-Aim6 - c:\program files\AIM6\aim6.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-02-19 20:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\windows\$NtUninstallKB13067$:SummaryInformation 0 bytes hidden from API
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.netWindows 5.1.2600 Disk: Hitachi_HDS721616PLA380 rev.P22OABEA -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8ABA82C6
user & kernel MBR OK
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1177238915-1326574676-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,aa,3f,d4,c3,c3,a4,47,89,b6,99,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,aa,3f,d4,c3,c3,a4,47,89,b6,99,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(592)
c:\windows\system32\WININET.dll
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\wsauth.dll
.
- - - - - - - > 'lsass.exe'(652)
c:\windows\system32\WININET.dll
c:\windows\system32\wsauth.dll
.
Completion time: 2012-02-19 20:32:36
ComboFix-quarantined-files.txt 2012-02-20 01:32
.
Pre-Run: 24,791,179,264 bytes free
Post-Run: 26,222,485,504 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 6B7BCC9CCA08563455050FE4FAF01A13