ComboFix 11-01-19.04 - Stanchevi 01.2011 г. 23:24:26.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.1024.526 [GMT 2:00]
Running from: c:\documents and settings\Stanchevi\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Stanchevi\AppData\LocalLow\Microсoft\reDIr.dll
c:\documents and settings\Stanchevi\Application Data\inst.exe
c:\windows\system32\detoured.dll
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Created from 2010-12-20 to 2011-01-20 )))))))))))))))))))))))))))))))
.
2011-01-20 19:54 . 2011-01-20 19:54 -------- d-----w- C:\_OTL
2011-01-20 17:20 . 2010-12-20 16:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-20 17:20 . 2011-01-20 17:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-20 17:20 . 2010-12-20 16:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-20 15:48 . 2011-01-20 15:48 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2011-01-20 15:30 . 2011-01-20 15:31 -------- d-----w- c:\documents and settings\Stanchevi\Local Settings\Application Data\Temp
2011-01-17 20:02 . 2011-01-13 08:37 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-01-17 20:02 . 2011-01-13 08:41 357968 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-01-17 20:02 . 2011-01-13 08:41 294608 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-01-17 20:02 . 2011-01-13 08:42 99792 ----a-w- c:\windows\system32\drivers\aswFW.sys
2011-01-17 20:00 . 2011-01-13 08:41 189904 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2011-01-17 20:00 . 2011-01-13 08:37 23632 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-01-17 20:00 . 2011-01-13 08:40 47440 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-01-17 20:00 . 2011-01-13 08:40 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-01-17 20:00 . 2011-01-13 08:39 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-01-17 20:00 . 2011-01-13 08:37 29392 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-01-17 20:00 . 2010-09-07 15:24 12112 ----a-w- c:\windows\system32\drivers\aswNdis.sys
2011-01-17 20:00 . 2011-01-13 08:47 38848 ----a-w- c:\windows\avastSS.scr
2011-01-17 20:00 . 2011-01-13 08:47 188216 ----a-w- c:\windows\system32\aswBoot.exe
2011-01-17 18:18 . 2011-01-17 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2011-01-17 14:11 . 2011-01-17 14:11 -------- d-----w- C:\temp
2011-01-17 14:10 . 2011-01-17 14:10 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-01-17 14:10 . 2011-01-17 14:10 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2011-01-14 17:17 . 2011-01-14 17:17 -------- d-----w- c:\windows\system32\wbem\Repository
2011-01-09 14:18 . 2011-01-09 14:18 -------- d-----w- c:\program files\Wizard101(UK)
2010-12-25 12:28 . 2010-12-25 12:30 -------- d-----w- c:\program files\Clarus
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2004-03-17 11:23 . 2009-01-18 19:58 1811584 -c--a-w- c:\program files\NAVSetup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-01-13 08:47 120712 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 695808]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"Google Update"="c:\documents and settings\Stanchevi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2011-01-20 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"AudioDeck"="c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-08-09 528384]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2011-01-13 3396624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 1294336]
c:\documents and settings\Stanchevi\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-6-5 385024]
Samsung Auto Backup Guage.lnk - c:\program files\Clarus\Samsung Auto Backup\ISFGuage.exe [2010-12-25 823296]
Samsung Auto Backup Real-Time Daemon.lnk - c:\program files\Clarus\Samsung Auto Backup\ISFRealTimeD.exe [2010-12-25 65536]
Samsung Auto Backup Scheduler.lnk - c:\program files\Clarus\Samsung Auto Backup\ISFTimerD.exe [2010-12-25 102400]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-4 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Anno 1701\\Anno1701.exe"=
"c:\\Documents and Settings\\Stanchevi\\Desktop\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"40720:UDP"= 40720:UDP:GooglePatch SecurityL2S
"35654:TCP"= 35654:TCP:GooglePatch HelpUS
"26524:TCP"= 26524:TCP:GooglePatch VideoLive
"17499:UDP"= 17499:UDP:GooglePatch PublishOffline
"61680:UDP"= 61680:UDP:GooglePatch MailMaker
"42531:TCP"= 42531:TCP:GooglePatch JavaGames
"47567:TCP"= 47567:TCP:GooglePatch ComponentsPerformance
"10299:UDP"= 10299:UDP:GooglePatch VideoAgent
R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [17.1.2011 г. 22:00 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [17.1.2011 г. 22:00 189904]
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [18.1.2009 г. 14:09 26112]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [03.8.2008 г. 21:16 717296]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [17.1.2011 г. 22:02 99792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [17.1.2011 г. 22:02 357968]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [17.1.2011 г. 22:02 294608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17.1.2011 г. 22:02 17744]
S2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [17.1.2011 г. 22:00 119200]
S3 mdf15;mdf15;\??\c:\program files\Clarus\Samsung SecretZone\mdf15.sys --> c:\program files\Clarus\Samsung SecretZone\mdf15.sys [?]
S3 mvd21;mvd21;\??\c:\program files\Clarus\Samsung SecretZone\mvd21.sys --> c:\program files\Clarus\Samsung SecretZone\mvd21.sys [?]
S3 xpzruc;xpzruc;\??\c:\windows\system32\02.tmp --> c:\windows\system32\02.tmp [?]
.
Contents of the 'Scheduled Tasks' folder
2011-01-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-884357618-725345543-1003Core.job
- c:\documents and settings\Stanchevi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-01-20 15:30]
2011-01-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-884357618-725345543-1003UA.job
- c:\documents and settings\Stanchevi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-01-20 15:30]
.
.
------- Supplementary Scan -------
.
uStart Page =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Stanchevi\Application Data\Mozilla\Firefox\Profiles\atdm8z6v.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2524319&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Feboz Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.bg/firefox?client=firefox-a&rls=org.mozilla:bg:official
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Get Styles: {6236BA26-C117-4007-928C-DE0716C7FA80} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA80}
FF - Ext: Usage Stat: {6236BA26-C117-4007-928C-DE0716C7FA96} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA96}
FF - Ext: FBFan: {6236BA26-C117-4007-928C-DE0716C7FA99} - %profile%\extensions\{6236BA26-C117-4007-928C-DE0716C7FA99}
FF - Ext: QAssistant: {63414328-3ab4-2c84-6c41-5a473c4b2ff7} - %profile%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
FF - Ext: QAssistant: {63414328-3ab4-2c84-6c41-5a473c4b2ff7} - %profile%\extensions\{63414328-3ab4-2c84-6c41-5a473c4b2ff7}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Java Quick Starter:
[email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-20 23:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = c:\program files\VIA\VIAudioi\SBADeck\ADeck.exe 1????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xpzruc]
"ImagePath"="\??\c:\windows\system32\02.tmp"
.
Completion time: 2011-01-20 23:37:31
ComboFix-quarantined-files.txt 2011-01-20 21:37
Pre-Run: 2 887 974 912 bytes free
Post-Run: 2 784 960 512 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B7C8818300DE7B3CD2D286C05D798098