ComboFix 11-06-22.02 - Athena_6 06/22/2011 19:20:00.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2045.1103 [GMT -4:00]
Running from: c:\users\Athena_6\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-22 to 2011-06-22 )))))))))))))))))))))))))))))))
.
.
2011-06-22 23:18 . 2011-06-22 23:19 -------- d-----w- C:\32788R22FWJFW
2011-06-22 01:23 . 2011-06-22 01:23 -------- d-----w- c:\windows\system32\log
2011-06-21 05:56 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0C255BCB-9A1E-43F5-842C-E7D3D133B293}\mpengine.dll
2011-06-21 02:21 . 2008-06-20 01:18 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2011-06-21 02:21 . 2008-06-20 01:17 97800 ----a-w- c:\windows\system32\infocardapi.dll
2011-06-21 02:21 . 2008-06-20 01:17 622080 ----a-w- c:\windows\system32\icardagt.exe
2011-06-21 02:21 . 2008-06-20 01:17 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2011-06-21 02:21 . 2008-06-20 01:18 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-06-21 02:21 . 2008-06-20 01:17 11264 ----a-w- c:\windows\system32\icardres.dll
2011-06-21 02:21 . 2008-06-20 01:18 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2011-06-21 02:21 . 2008-06-20 01:18 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2011-06-21 02:13 . 2008-07-27 18:00 96760 ----a-w- c:\windows\system32\dfshim.dll
2011-06-21 02:13 . 2008-07-27 18:00 282112 ----a-w- c:\windows\system32\mscoree.dll
2011-06-21 02:13 . 2008-07-27 18:00 41984 ----a-w- c:\windows\system32\netfxperf.dll
2011-06-21 02:13 . 2008-07-27 18:00 158720 ----a-w- c:\windows\system32\mscorier.dll
2011-06-21 02:13 . 2008-07-27 18:00 83968 ----a-w- c:\windows\system32\mscories.dll
2011-06-21 00:59 . 2007-08-31 02:16 8704 ----a-w- c:\windows\system32\hcrstco.dll
2011-06-21 00:59 . 2007-08-31 01:20 192000 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-06-21 00:59 . 2007-08-31 01:20 224768 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-06-21 00:59 . 2007-08-31 01:19 38400 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-06-21 00:59 . 2007-08-31 01:19 23040 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-06-21 00:59 . 2007-08-31 01:19 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-06-21 00:40 . 2011-06-21 00:41 -------- d-----w- c:\program files\Common Files\Adobe
2011-06-20 01:16 . 2011-06-20 03:11 -------- d-----w- c:\program files\Wise Registry Cleaner
2011-06-17 13:09 . 2011-06-17 13:09 378368 ----a-w- c:\windows\system32\winhttp.dll
2011-06-17 13:09 . 2011-06-17 13:09 268800 ----a-w- c:\windows\system32\es.dll
2011-06-17 04:32 . 2011-06-17 04:32 156672 ----a-w- c:\windows\system32\t2embed.dll
2011-06-17 04:32 . 2011-06-17 04:32 72704 ----a-w- c:\windows\system32\fontsub.dll
2011-06-17 04:32 . 2011-06-17 04:32 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-06-17 04:32 . 2011-06-17 04:32 289792 ----a-w- c:\windows\system32\atmfd.dll
2011-06-17 04:32 . 2011-06-17 04:32 24064 ----a-w- c:\windows\system32\lpk.dll
2011-06-17 04:32 . 2011-06-17 04:32 10240 ----a-w- c:\windows\system32\dciman32.dll
2011-06-17 04:29 . 2011-06-17 04:29 61440 ----a-w- c:\windows\system32\winipsec.dll
2011-06-17 04:29 . 2011-06-17 04:29 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2011-06-17 04:29 . 2011-06-17 04:29 28672 ----a-w- c:\windows\system32\FwRemoteSvr.dll
2011-06-17 04:29 . 2011-06-17 04:29 272896 ----a-w- c:\windows\system32\polstore.dll
2011-06-17 04:28 . 2011-06-17 04:28 84992 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-17 04:28 . 2011-06-17 04:28 306688 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-17 04:28 . 2011-06-17 04:28 95232 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2011-06-17 04:28 . 2011-06-17 04:28 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2011-06-17 04:28 . 2011-06-17 04:28 160768 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2011-06-17 04:26 . 2011-06-17 04:26 704000 ----a-w- c:\windows\system32\PhotoScreensaver.scr
2011-06-17 04:26 . 2011-06-17 04:26 356352 ----a-w- c:\windows\system32\wbem\wbemcomn.dll
2011-06-17 04:26 . 2011-06-17 04:26 24064 ----a-w- c:\windows\system32\wtsapi32.dll
2011-06-17 04:26 . 2011-06-17 04:26 258232 ----a-w- c:\windows\system32\drivers\acpi.sys
2011-06-17 04:26 . 2011-06-17 04:26 542720 ----a-w- c:\windows\system32\sysmain.dll
2011-06-17 04:25 . 2011-06-17 04:25 194560 ----a-w- c:\windows\system32\WebClnt.dll
2011-06-17 04:25 . 2011-06-17 04:25 110080 ----a-w- c:\windows\system32\drivers\mrxdav.sys
2011-06-17 04:25 . 2011-06-17 04:25 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2011-06-17 04:25 . 2011-06-17 04:25 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2011-06-17 04:25 . 2011-06-17 04:25 502272 ----a-w- c:\windows\system32\wlansvc.dll
2011-06-17 04:25 . 2011-06-17 04:25 47104 ----a-w- c:\windows\system32\wlanapi.dll
2011-06-17 04:25 . 2011-06-17 04:25 297984 ----a-w- c:\windows\system32\wlansec.dll
2011-06-17 04:25 . 2011-06-17 04:25 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2011-06-17 04:24 . 2011-06-17 04:24 2048 ----a-w- c:\windows\system32\msxml3r.dll
2011-06-17 04:24 . 2011-06-17 04:24 1260032 ----a-w- c:\windows\system32\msxml3.dll
2011-06-17 04:24 . 2011-06-17 04:24 2048 ----a-w- c:\windows\system32\msxml6r.dll
2011-06-17 04:24 . 2011-06-17 04:24 1406464 ----a-w- c:\windows\system32\msxml6.dll
2011-06-17 04:24 . 2011-06-17 04:24 216576 ----a-w- c:\windows\system32\msv1_0.dll
2011-06-17 04:23 . 2011-06-17 04:23 58368 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-17 04:23 . 2011-06-17 04:23 211968 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-17 04:23 . 2011-06-17 04:23 102400 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-17 04:23 . 2011-06-17 04:23 49664 ----a-w- c:\windows\system32\csrsrv.dll
2011-06-17 04:23 . 2011-06-17 04:23 376320 ----a-w- c:\windows\system32\winsrv.dll
2011-06-17 04:22 . 2011-06-17 04:22 98816 ----a-w- c:\windows\system32\mfps.dll
2011-06-17 04:22 . 2011-06-17 04:22 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2011-06-17 04:22 . 2011-06-17 04:22 2855424 ----a-w- c:\windows\system32\mf.dll
2011-06-17 04:22 . 2011-06-17 04:22 2048 ----a-w- c:\windows\system32\mferror.dll
2011-06-17 04:22 . 2011-06-17 04:22 24576 ----a-w- c:\windows\system32\mfpmp.exe
2011-06-17 04:22 . 2011-06-17 04:22 3502480 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-17 04:22 . 2011-06-17 04:22 3468168 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-06-17 04:20 . 2011-06-17 04:20 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-06-17 04:19 . 2011-06-17 04:19 71680 ----a-w- c:\windows\system32\atl.dll
2011-06-17 04:18 . 2011-06-17 04:18 297472 ----a-w- c:\windows\system32\gdi32.dll
2011-06-17 04:18 . 2011-06-17 04:18 41984 ----a-w- c:\windows\system32\drivers\monitor.sys
2011-06-17 04:18 . 2011-06-17 04:18 1060920 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-06-17 04:17 . 2011-06-17 04:17 374456 ----a-w- c:\windows\system32\mcupdate_GenuineIntel.dll
2011-06-17 04:16 . 2011-06-17 04:16 500736 ----a-w- c:\windows\system32\msdtcprx.dll
2011-06-17 04:16 . 2011-06-17 04:16 30208 ----a-w- c:\windows\system32\xolehlp.dll
2011-06-17 04:16 . 2011-06-17 04:16 156160 ----a-w- c:\windows\system32\wkssvc.dll
2011-06-17 04:16 . 2011-06-17 04:16 36352 ----a-w- c:\windows\system32\tsgqec.dll
2011-06-17 04:16 . 2011-06-17 04:16 116736 ----a-w- c:\windows\system32\aaclient.dll
2011-06-17 04:16 . 2011-06-17 04:16 1871872 ----a-w- c:\windows\system32\mstscax.dll
2011-06-17 04:15 . 2011-06-17 04:15 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2011-06-17 04:14 . 2011-06-17 04:14 414208 ----a-w- c:\windows\system32\msscp.dll
2011-06-17 04:14 . 2011-06-17 04:14 713728 ----a-w- c:\windows\system32\timedate.cpl
2011-06-17 04:13 . 2011-06-17 04:13 356864 ----a-w- c:\windows\system32\MediaMetadataHandler.dll
2011-06-17 04:13 . 2011-06-17 04:13 86016 ----a-w- c:\windows\system32\icfupgd.dll
2011-06-17 04:13 . 2011-06-17 04:13 63488 ----a-w- c:\windows\system32\drivers\mpsdrv.sys
2011-06-17 04:13 . 2011-06-17 04:13 396800 ----a-w- c:\windows\system32\MPSSVC.dll
2011-06-17 04:13 . 2011-06-17 04:13 392192 ----a-w- c:\windows\system32\FirewallAPI.dll
2011-06-17 04:13 . 2011-06-17 04:13 61952 ----a-w- c:\windows\system32\cmifw.dll
2011-06-17 04:13 . 2011-06-17 04:13 16896 ----a-w- c:\windows\system32\wfapigp.dll
2011-06-17 04:12 . 2011-06-17 04:12 150016 ----a-w- c:\program files\Movie Maker\MOVIEMK.exe
2011-06-17 04:12 . 2011-06-17 04:12 10922496 ----a-w- c:\program files\Movie Maker\MOVIEMK.dll
2011-06-17 04:12 . 2011-06-17 04:12 23040 ----a-w- c:\program files\Movie Maker\WMM2EXT.dll
2011-06-17 04:12 . 2011-06-17 04:12 195072 ----a-w- c:\program files\Movie Maker\WMM2AE.dll
2011-06-17 04:11 . 2011-06-17 04:11 80896 ----a-w- c:\windows\system32\MSNP.ax
2011-06-17 04:11 . 2011-06-17 04:11 68608 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-06-17 04:11 . 2011-06-17 04:11 428032 ----a-w- c:\windows\system32\EncDec.dll
2011-06-17 04:11 . 2011-06-17 04:11 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-06-17 04:11 . 2011-06-17 04:11 177152 ----a-w- c:\windows\system32\mpg2splt.ax
2011-06-17 04:11 . 2011-06-17 04:11 1244672 ----a-w- c:\windows\system32\mcmde.dll
2011-06-17 04:11 . 2011-06-17 04:11 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-06-17 04:11 . 2011-06-17 04:11 292352 ----a-w- c:\windows\system32\psisdecd.dll
2011-06-17 04:09 . 2011-06-17 04:09 2048 ----a-w- c:\windows\system32\tzres.dll
2011-06-17 04:09 . 2011-06-17 04:09 696832 ----a-w- c:\windows\system32\localspl.dll
2011-06-17 04:09 . 2011-06-17 04:09 211000 ----a-w- c:\windows\system32\drivers\volsnap.sys
2011-06-17 04:09 . 2011-06-17 04:09 154624 ----a-w- c:\windows\system32\drivers\nwifi.sys
2011-06-17 04:08 . 2011-06-17 04:08 104448 ----a-w- c:\windows\system32\DWWIN.EXE
2011-06-17 04:08 . 2011-06-17 04:08 2923520 ----a-w- c:\windows\explorer.exe
2011-06-17 04:07 . 2011-06-17 04:07 7680 ----a-w- c:\windows\system32\lsass.exe
2011-06-17 04:07 . 2011-06-17 04:07 72704 ----a-w- c:\windows\system32\secur32.dll
2011-06-17 04:07 . 2011-06-17 04:07 494592 ----a-w- c:\windows\system32\kerberos.dll
2011-06-17 04:07 . 2011-06-17 04:07 408136 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2011-06-17 04:07 . 2011-06-17 04:07 175104 ----a-w- c:\windows\system32\wdigest.dll
2011-06-17 04:07 . 2011-06-17 04:07 1233920 ----a-w- c:\windows\system32\lsasrv.dll
2011-06-17 04:07 . 2011-06-17 04:07 272384 ----a-w- c:\windows\system32\schannel.dll
2011-06-17 04:07 . 2011-06-17 04:07 24064 ----a-w- c:\windows\system32\netcfg.exe
2011-06-17 04:05 . 2011-06-17 04:05 549888 ----a-w- c:\windows\system32\rpcss.dll
2011-06-17 04:04 . 2011-06-17 04:04 454656 ----a-w- c:\program files\Common Files\System\msadc\msadce.dll
2011-06-17 04:04 . 2011-06-17 04:04 9728 ----a-w- c:\windows\system32\LAPRXY.DLL
2011-06-17 04:04 . 2011-06-17 04:04 2048 ----a-w- c:\windows\system32\asferror.dll
2011-06-17 04:04 . 2011-06-17 04:04 223232 ----a-w- c:\windows\system32\WMASF.DLL
2011-06-17 04:04 . 2011-06-17 04:04 25600 ----a-w- c:\windows\system32\amxread.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-17 13:08 . 2011-06-17 13:08 36864 ----a-w- c:\windows\system32\drivers\en-US\http.sys.mui
2011-06-17 04:30 . 2011-06-17 04:30 52736 ----a-w- c:\windows\apppatch\iebrshim.dll
2011-06-17 04:06 . 2011-06-17 04:06 5632 ----a-w- c:\windows\system32\drivers\en-US\sermouse.sys.mui
2011-06-17 04:06 . 2011-06-17 04:06 4608 ----a-w- c:\windows\system32\drivers\en-US\mouclass.sys.mui
2011-06-17 04:06 . 2011-06-17 04:06 4608 ----a-w- c:\windows\system32\drivers\en-US\kbdclass.sys.mui
2011-06-17 04:06 . 2011-06-17 04:06 3072 ----a-w- c:\windows\system32\drivers\en-US\mouhid.sys.mui
2011-06-17 04:06 . 2011-06-17 04:06 3072 ----a-w- c:\windows\system32\drivers\en-US\kbdhid.sys.mui
2011-06-17 04:06 . 2011-06-17 04:06 10752 ----a-w- c:\windows\system32\drivers\en-US\i8042prt.sys.mui
2011-06-17 04:04 . 2011-06-17 04:04 40960 ----a-w- c:\windows\apppatch\apihex86.dll
2011-06-17 04:00 . 2011-06-17 04:00 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2011-06-17 04:00 . 2011-06-17 04:00 2143744 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-06-17 04:00 . 2011-06-17 04:00 537600 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-06-17 04:00 . 2011-06-17 04:00 449024 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-06-17 04:00 . 2011-06-17 04:00 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-04-14 16:26 . 2011-06-15 14:03 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2011-06-17 1232896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-14 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-14 92704]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
c:\users\Athena_6\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2011-04-24 225856]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - TMCOMM
*Deregistered* - avipbb
*Deregistered* - ssmdrv
*Deregistered* - tmcomm
.
.
------- Supplementary Scan -------
.
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\Athena_6\AppData\Roaming\Mozilla\Firefox\Profiles\xgrdxh0j.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-06-22 19:24
Windows 6.0.6000 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-06-22 19:26:05
ComboFix-quarantined-files.txt 2011-06-22 23:26
.
Pre-Run: 188,401,422,336 bytes free
Post-Run: 186,772,643,840 bytes free
.
[
b]- - End Of File - - 160BBC6677139E026BD5058C12937C8C[/b]aswMBR version 0.9.7.675 Copyright© 2011 AVAST Software
Run date: 2011-06-22 20:13:06
-----------------------------
20:13:06.639 OS Version: Windows 6.0.6000
20:13:06.639 Number of processors: 2 586 0xF02
20:13:06.639 ComputerName: ATHENA_6-PC UserName: Athena_6
20:13:07.466 Initialize success
20:13:14.610 AVAST engine defs: 11062201
20:13:18.822 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
20:13:18.822 Disk 0 Vendor: WDC_WD25 10.0 Size: 238418MB BusType: 3
20:13:18.854 Disk 0 MBR read successfully
20:13:18.854 Disk 0 MBR scan
20:13:18.854 Disk 0 unknown MBR code
20:13:18.854 Disk 0 scanning sectors +488278016
20:13:18.916 Disk 0 scanning C:\Windows\system32\drivers
20:13:38.541 Service scanning
20:13:39.524 Disk 0 trace - called modules:
20:13:39.539 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastorv.sys hal.dll
20:13:39.555 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x843d9030]
20:13:39.555 3 ntkrnlpa.exe[81cb07e2] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x843da030]
20:13:40.382 AVAST engine scan C:\Windows
22:28:56.625 AVAST engine scan C:\Users\Athena_6
22:43:22.596 AVAST engine scan C:\ProgramData
22:43:56.230 Scan finished successfully
22:44:54.434 Disk 0 MBR has been saved successfully to "C:\Users\Athena_6\Desktop\MBR.dat"
22:44:54.434 The log file has been saved successfully to "C:\Users\Athena_6\Desktop\aswMBR.txt
PS: Only Fix MBR displayed at end of scan.