ComboFix 11-04-17.03 - Parent 04/18/2011 12:08:35.3.1 - x86
Running from: c:\documents and settings\Parent\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Parent\My Documents\CFScript.txt
.
FILE ::
"c:\docume~1\Parent\LOCALS~1\Temp\ZULNDSHL.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system\oeminfo.ini
c:\windows\system32\AutoRun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ZULNDSHL
-------\Service_ZULNDSHL
.
.
((((((((((((((((((((((((( Files Created from 2011-03-18 to 2011-04-18 )))))))))))))))))))))))))))))))
.
.
2011-04-18 15:18 . 2011-04-18 15:18 8646 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2011-04-18 15:18 . 2011-04-18 15:18 6429 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-04-18 15:18 . 2011-04-18 15:18 63115 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-04-18 15:18 . 2011-04-18 15:18 4599 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-04-14 18:52 . 2011-04-14 19:02 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-04-14 16:51 . 2011-02-23 13:54 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-04-14 16:51 . 2011-02-23 13:56 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-14 16:51 . 2011-02-23 13:55 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-14 16:51 . 2011-02-23 13:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-14 16:51 . 2011-02-23 13:55 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-14 16:51 . 2011-02-23 13:55 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-04-14 16:51 . 2011-02-23 13:55 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-04-14 16:51 . 2011-02-23 13:54 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-04-14 16:50 . 2011-02-23 14:04 40648 ----a-w- c:\windows\avastSS.scr
2011-04-14 16:50 . 2011-02-23 14:04 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-14 16:50 . 2011-04-14 16:50 -------- d-----w- c:\program files\AVAST Software
2011-04-14 16:50 . 2011-04-14 16:50 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2011-04-12 21:15 . 2011-04-12 21:15 388096 ----a-r- c:\documents and settings\Parent\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-04 04:06 . 2011-04-04 04:06 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-04 04:00 . 2011-04-04 04:00 -------- d-----w- c:\documents and settings\Parent\Local Settings\Application Data\Sunbelt Software
2011-04-04 03:42 . 2011-04-18 02:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-04-04 03:42 . 2011-04-04 03:42 -------- d-----w- c:\program files\Lavasoft
2011-04-03 03:13 . 2010-12-20 22:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-03 03:13 . 2011-04-03 03:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-03 03:05 . 2011-04-03 03:05 -------- d-----w- c:\documents and settings\All Users\Uniblue
2011-04-02 22:03 . 2011-04-02 22:03 -------- d-----w- c:\documents and settings\Parent\Local Settings\Application Data\PackageAware
2011-04-01 16:37 . 2011-04-04 16:49 -------- d-----w- c:\program files\Windows Live Safety Center
2011-04-01 16:18 . 2002-12-31 12:00 4224 ----a-w- c:\windows\system32\beep.sys
2011-04-01 01:30 . 2011-04-01 01:31 -------- d-----w- C:\ca7a77c2a8b4afc14cc4c4
2011-04-01 01:19 . 2011-04-01 01:19 -------- d-----w- c:\windows\system32\GroupPolicy
2011-03-31 23:34 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-03-21 18:49 . 2011-03-21 18:49 -------- d-----w- c:\documents and settings\Parent\Application Data\Unity
2011-03-21 18:39 . 2011-03-21 18:39 -------- d-----w- c:\documents and settings\Parent\Local Settings\Application Data\Unity
2011-03-21 18:32 . 2011-03-21 18:32 1409 ----a-w- c:\windows\QTFont.for
2011-03-21 18:32 . 2011-03-21 18:32 -------- d-----w- c:\program files\Blaster
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-23 20:15 . 2008-08-30 15:09 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-01-23 20:15 . 2011-01-23 20:16 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 14:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-12 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-04-25 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0417.0\mswinext.exe" [2010-07-06 240480]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP
xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP
xpsp2res.dll,-22016
"500:UDP"= 500:UDP
xpsp2res.dll,-22017
.
R1 MpKsl0880951c;MpKsl0880951c;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DCF2D3AA-02E6-4C66-A278-535556FCAB15}\MpKsl0880951c.sys [x]
R1 MpKsl220bf6b1;MpKsl220bf6b1;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{12E0912F-7805-4375-9D63-66459C119050}\MpKsl220bf6b1.sys [x]
R1 MpKsl410b4a1e;MpKsl410b4a1e;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{12E0912F-7805-4375-9D63-66459C119050}\MpKsl410b4a1e.sys [x]
R1 MpKsl4ad2c2ce;MpKsl4ad2c2ce;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0B11DBB3-7A29-4226-9ACF-0AA015CCE8D3}\MpKsl4ad2c2ce.sys [x]
R1 MpKsl60c5c3e1;MpKsl60c5c3e1;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DCF2D3AA-02E6-4C66-A278-535556FCAB15}\MpKsl60c5c3e1.sys [x]
R1 MpKsl8efd0456;MpKsl8efd0456;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E652C3C9-B2F7-499E-853B-071F3CEAFE66}\MpKsl8efd0456.sys [x]
R1 MpKsla456af21;MpKsla456af21;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{807DAD6B-20F4-490D-8D24-D045AC1C9AC8}\MpKsla456af21.sys [x]
R1 MpKsld1cd1d70;MpKsld1cd1d70;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{12E0912F-7805-4375-9D63-66459C119050}\MpKsld1cd1d70.sys [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S3 WUSB12;Instant Wireless Compact USB Adapter Driver;c:\windows\system32\DRIVERS\LSWLUSB.sys [2002-06-07 54083]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 20:45]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 20:45]
.
2011-04-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2322712386-359561344-2389969595-1003Core.job
- c:\documents and settings\Parent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-19 20:45]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2322712386-359561344-2389969595-1003UA.job
- c:\documents and settings\Parent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-19 20:45]
.
2011-04-14 c:\windows\Tasks\Norton Security Scan for Parent.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\3.0.1.8\Nss.exe [2011-01-30 14:06]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-18 12:15
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(1644)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2011-04-18 12:23:07
ComboFix-quarantined-files.txt 2011-04-18 16:23
.
Pre-Run: 62,698,266,624 bytes free
Post-Run: 62,737,125,376 bytes free
.
- - End Of File - - 33DBFCC98081BCFFDFD7BFD7CD17CB04
Running from: c:\documents and settings\Parent\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Parent\My Documents\CFScript.txt
.
FILE ::
"c:\docume~1\Parent\LOCALS~1\Temp\ZULNDSHL.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\system\oeminfo.ini
c:\windows\system32\AutoRun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ZULNDSHL
-------\Service_ZULNDSHL
.
.
((((((((((((((((((((((((( Files Created from 2011-03-18 to 2011-04-18 )))))))))))))))))))))))))))))))
.
.
2011-04-18 15:18 . 2011-04-18 15:18 8646 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2011-04-18 15:18 . 2011-04-18 15:18 6429 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-04-18 15:18 . 2011-04-18 15:18 63115 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-04-18 15:18 . 2011-04-18 15:18 4599 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-04-14 18:52 . 2011-04-14 19:02 -------- d-----w- c:\program files\Common Files\Symantec Shared
2011-04-14 16:51 . 2011-02-23 13:54 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-04-14 16:51 . 2011-02-23 13:56 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-04-14 16:51 . 2011-02-23 13:55 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-04-14 16:51 . 2011-02-23 13:56 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-04-14 16:51 . 2011-02-23 13:55 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-04-14 16:51 . 2011-02-23 13:55 102232 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-04-14 16:51 . 2011-02-23 13:55 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-04-14 16:51 . 2011-02-23 13:54 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-04-14 16:50 . 2011-02-23 14:04 40648 ----a-w- c:\windows\avastSS.scr
2011-04-14 16:50 . 2011-02-23 14:04 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-04-14 16:50 . 2011-04-14 16:50 -------- d-----w- c:\program files\AVAST Software
2011-04-14 16:50 . 2011-04-14 16:50 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2011-04-12 21:15 . 2011-04-12 21:15 388096 ----a-r- c:\documents and settings\Parent\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-04 04:06 . 2011-04-04 04:06 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-04 04:00 . 2011-04-04 04:00 -------- d-----w- c:\documents and settings\Parent\Local Settings\Application Data\Sunbelt Software
2011-04-04 03:42 . 2011-04-18 02:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-04-04 03:42 . 2011-04-04 03:42 -------- d-----w- c:\program files\Lavasoft
2011-04-03 03:13 . 2010-12-20 22:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-03 03:13 . 2011-04-03 03:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-03 03:05 . 2011-04-03 03:05 -------- d-----w- c:\documents and settings\All Users\Uniblue
2011-04-02 22:03 . 2011-04-02 22:03 -------- d-----w- c:\documents and settings\Parent\Local Settings\Application Data\PackageAware
2011-04-01 16:37 . 2011-04-04 16:49 -------- d-----w- c:\program files\Windows Live Safety Center
2011-04-01 16:18 . 2002-12-31 12:00 4224 ----a-w- c:\windows\system32\beep.sys
2011-04-01 01:30 . 2011-04-01 01:31 -------- d-----w- C:\ca7a77c2a8b4afc14cc4c4
2011-04-01 01:19 . 2011-04-01 01:19 -------- d-----w- c:\windows\system32\GroupPolicy
2011-03-31 23:34 . 2010-10-19 20:51 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-03-21 18:49 . 2011-03-21 18:49 -------- d-----w- c:\documents and settings\Parent\Application Data\Unity
2011-03-21 18:39 . 2011-03-21 18:39 -------- d-----w- c:\documents and settings\Parent\Local Settings\Application Data\Unity
2011-03-21 18:32 . 2011-03-21 18:32 1409 ----a-w- c:\windows\QTFont.for
2011-03-21 18:32 . 2011-03-21 18:32 -------- d-----w- c:\program files\Blaster
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-23 20:15 . 2008-08-30 15:09 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-01-23 20:15 . 2011-01-23 20:16 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 14:04 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-12 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-04-25 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0417.0\mswinext.exe" [2010-07-06 240480]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP
"1701:UDP"= 1701:UDP
"500:UDP"= 500:UDP
.
R1 MpKsl0880951c;MpKsl0880951c;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DCF2D3AA-02E6-4C66-A278-535556FCAB15}\MpKsl0880951c.sys [x]
R1 MpKsl220bf6b1;MpKsl220bf6b1;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{12E0912F-7805-4375-9D63-66459C119050}\MpKsl220bf6b1.sys [x]
R1 MpKsl410b4a1e;MpKsl410b4a1e;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{12E0912F-7805-4375-9D63-66459C119050}\MpKsl410b4a1e.sys [x]
R1 MpKsl4ad2c2ce;MpKsl4ad2c2ce;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0B11DBB3-7A29-4226-9ACF-0AA015CCE8D3}\MpKsl4ad2c2ce.sys [x]
R1 MpKsl60c5c3e1;MpKsl60c5c3e1;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DCF2D3AA-02E6-4C66-A278-535556FCAB15}\MpKsl60c5c3e1.sys [x]
R1 MpKsl8efd0456;MpKsl8efd0456;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E652C3C9-B2F7-499E-853B-071F3CEAFE66}\MpKsl8efd0456.sys [x]
R1 MpKsla456af21;MpKsla456af21;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{807DAD6B-20F4-490D-8D24-D045AC1C9AC8}\MpKsla456af21.sys [x]
R1 MpKsld1cd1d70;MpKsld1cd1d70;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{12E0912F-7805-4375-9D63-66459C119050}\MpKsld1cd1d70.sys [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S3 WUSB12;Instant Wireless Compact USB Adapter Driver;c:\windows\system32\DRIVERS\LSWLUSB.sys [2002-06-07 54083]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 20:45]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 20:45]
.
2011-04-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2322712386-359561344-2389969595-1003Core.job
- c:\documents and settings\Parent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-19 20:45]
.
2011-04-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2322712386-359561344-2389969595-1003UA.job
- c:\documents and settings\Parent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-19 20:45]
.
2011-04-14 c:\windows\Tasks\Norton Security Scan for Parent.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\3.0.1.8\Nss.exe [2011-01-30 14:06]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-18 12:15
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(1644)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2011-04-18 12:23:07
ComboFix-quarantined-files.txt 2011-04-18 16:23
.
Pre-Run: 62,698,266,624 bytes free
Post-Run: 62,737,125,376 bytes free
.
- - End Of File - - 33DBFCC98081BCFFDFD7BFD7CD17CB04