Thank-you.
ComboFix 09-10-27.07 - HP 28/10/2009 23:25.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.1015.651 [GMT 10.5:30]
Running from: c:\documents and settings\HP\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP\Application Data\AntispywareBot
c:\documents and settings\HP\goimes.exe
c:\program files\AskSearch\bin\DefaultSearch.dll
c:\windows\system32\MSVolume.dll
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 )))))))))))))))))))))))))))))))
.
2009-10-28 12:44 . 2009-10-28 12:45 -------- d-----w- C:\32788R22FWJFW
2009-10-21 16:12 . 2009-10-21 16:12 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet
2009-10-21 14:36 . 2009-10-21 14:36 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-10-21 14:36 . 2009-10-21 14:36 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-10-21 14:35 . 2009-10-21 14:35 -------- d-----w- c:\program files\Prevx
2009-10-21 14:35 . 1980-01-03 14:01 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-10-18 08:22 . 2009-10-18 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\pI3demoLicense
2009-10-18 08:22 . 2009-10-18 13:29 -------- d-----w- c:\program files\particleIllusion 3.0 demo
2009-10-07 01:45 . 1980-01-03 13:47 -------- d-----w- C:\$AVG8.VAULT$
2009-10-01 00:30 . 2009-10-01 00:36 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-01 00:30 . 2009-10-01 00:36 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-01 00:30 . 2009-10-01 00:36 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-01 00:30 . 2009-10-01 00:36 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-01 00:30 . 2009-10-28 12:41 -------- d-----w- c:\windows\system32\drivers\Avg
2009-10-01 00:30 . 2009-10-01 00:30 -------- d-----w- c:\program files\AVG
2009-10-01 00:30 . 2009-10-01 00:30 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-01 00:20 . 2009-10-01 00:20 -------- d-----w- c:\documents and settings\HP\Application Data\AVG8
2009-09-29 13:44 . 2009-09-29 13:44 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-29 13:43 . 2009-09-29 13:43 -------- d-----w- c:\documents and settings\HP\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-28 12:52 . 2008-10-08 14:38 -------- d-----w- c:\documents and settings\HP\Application Data\WTablet
2009-10-14 13:44 . 2008-09-17 13:06 31001 ----a-w- c:\windows\nsreg.dat
2009-10-01 02:18 . 2008-05-08 02:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-25 05:37 . 2004-08-04 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 14:46 . 2009-08-30 14:46 -------- d-----w- c:\documents and settings\HP\Application Data\Smith Micro
2009-08-30 14:46 . 2009-08-30 14:46 -------- d-----w- c:\program files\Smith Micro
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 09:54 . 2008-05-08 02:15 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 09:54 . 2008-05-08 02:15 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 09:54 . 2008-05-08 02:15 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 09:54 . 2007-07-30 09:19 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 09:54 . 2008-05-08 02:15 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 09:54 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 09:53 . 2008-05-08 02:15 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 09:53 . 2008-05-08 02:15 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 2004-08-04 12:00 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2006-05-03 09:06 . 2009-06-15 10:04 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2009-06-15 10:04 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-06-15 10:04 216064 --sh--r- c:\windows\system32\nbDX.dll
.
------- Sigcheck -------
[7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[7] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll
c:\windows\system32\eventlog.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-06 04:20 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-06 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-21 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-10 40048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-06 136600]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-04 143360]
"DrvLsnr"="c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe" [2003-05-08 69632]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-13 61440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-04-13 155648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-17 2025752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-6-2 180224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-01 00:36 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [22/01/2009 3:39 PM 64160]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [22/10/2009 1:06 AM 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [22/10/2009 1:06 AM 27656]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/10/2009 11:00 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/10/2009 11:00 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [1/10/2009 11:06 AM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/10/2009 11:06 AM 297752]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [22/10/2009 1:05 AM 4368952]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [9/10/2008 1:07 AM 1373480]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13157&gct=&gc=1&q=%s
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\HP\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\documents and settings\HP\Application Data\Mozilla\Firefox\Profiles\wx7m5t7c.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13157&gct=&gc=1&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\HP\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npaudio.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npavi32.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npdrmv2.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npdsplay.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\nphcd32.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npnul32.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin6.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npqtplugin7.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npswf32.dll
FF - plugin: c:\program files\Netscape\Communicator\Program\Plugins\npwmsdrm.dll
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
URLSearchHooks-EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
URLSearchHooks-C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-AdwareProMFCT - c:\program files\AdwarePro\StartApp.exe
HKCU-Run-goimes - c:\documents and settings\HP\goimes.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-28 23:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-10-28 23:32
ComboFix-quarantined-files.txt 2009-10-28 13:02
Pre-Run: 23,407,521,792 bytes free
Post-Run: 23,401,959,424 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - FFD6F1E17D5D12E3CB1F80A472633B23