1
Re: bds small on Tue Feb 23, 2010 11:15 pm
newmin

Member

Hi...I am another user. I also have the same infection and was alerted by Avira... I run combofix and here is what my combofix.txt says... Please help.. thanks
ComboFix 10-02-23.03 - The 02/24/2010 4:01.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.241 [GMT 0]
Running from: c:\documents and settings\The\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\docume~1\THE~1\LOCALS~1\Temp\cvasds0.dll
c:\documents and settings\The\Application Data\avdrn.dat
c:\documents and settings\The\Start Menu\Programs\Startup\siszyd32.exe
c:\windows\system32\drivers\saishci.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_saishci
-------\Service_saishci
((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.
2010-02-22 09:50 . 2010-02-22 09:50 -------- d-----w- c:\documents and settings\The\Local Settings\Application Data\Apple Computer
2010-02-20 15:24 . 2010-02-20 15:24 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2010-02-20 15:23 . 2010-02-20 15:23 -------- d-----w- c:\program files\NCH Swift Sound
2010-02-09 00:20 . 2010-02-09 00:20 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-02-09 00:15 . 2010-02-09 00:15 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-02-05 10:39 . 2010-02-05 10:39 251376 ----a-w- c:\documents and settings\The\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-02-01 09:00 . 2008-05-02 10:41 3493888 ---ha-w- c:\documents and settings\The\Application Data\U3\temp\Launchpad Removal.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 04:00 . 2009-12-24 10:37 79488 ----a-w- c:\documents and settings\The\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-21 17:25 . 2008-11-08 10:23 -------- d-----w- c:\documents and settings\The\Application Data\Skype
2010-02-21 16:41 . 2008-11-08 10:24 -------- d-----w- c:\documents and settings\The\Application Data\skypePM
2010-02-14 14:20 . 2008-11-06 12:48 18080 ----a-w- c:\documents and settings\The\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-09 00:15 . 2008-11-07 08:47 -------- d-----w- c:\program files\Google
2010-02-01 09:11 . 2008-11-08 18:25 -------- d-----w- c:\documents and settings\The\Application Data\U3
2010-01-12 12:55 . 2010-01-12 12:55 16 ----a-w- c:\documents and settings\NetworkService\Application Data\fvgqad.dat
2010-01-08 21:44 . 2010-01-08 21:44 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-01-05 10:05 . 2010-01-05 10:05 16 ----a-w- c:\documents and settings\Default User\Application Data\fvgqad.dat
2010-01-05 02:46 . 2010-01-05 02:46 -------- d-----w- c:\program files\MSXML 4.0
2010-01-05 01:42 . 2010-01-05 01:42 16 ----a-w- c:\documents and settings\The\Application Data\fvgqad.dat
2010-01-04 04:31 . 2009-12-27 18:16 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-02 23:29 . 2008-11-06 12:56 -------- d-----w- c:\program files\Avira
2009-12-31 15:06 . 2006-01-13 01:49 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-27 18:16 . 2009-12-27 18:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-12-27 18:05 . 2008-11-11 12:47 -------- d-----w- c:\documents and settings\All Users\Application Data\OrbNetworks
2009-12-27 18:05 . 2008-11-11 12:47 -------- d-----w- c:\program files\Winamp Remote
2009-12-27 18:03 . 2008-11-11 12:46 -------- d-----w- c:\program files\Winamp
2009-12-22 05:35 . 2006-01-13 01:26 668672 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:35 . 2006-01-13 01:55 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-16 12:58 . 2008-11-06 20:23 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2006-01-13 01:13 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 13:37 . 2006-01-13 01:47 456832 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:04 . 2006-01-13 01:36 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:04 . 2006-01-06 15:53 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:37 . 2006-01-13 01:47 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37 . 2006-01-13 01:39 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:37 . 2006-01-13 01:10 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37 . 2006-01-06 15:53 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37 . 2006-01-06 15:53 8704 ----a-w- c:\windows\system32\tsbyuv.dll
.
------- Sigcheck -------
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[-] 2006-01-13 . 2DEACA71A7FD77205F59D48D76B2F565 . 1075200 . . [6.00.2900.2649] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2005-12-14 7095344]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-10 68856]
"Google Update"="c:\documents and settings\The\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-12 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-07 136600]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnsc"="c:\windows\system32\msnsc.exe" [2006-01-13 62054]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-01-13 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Documents and Settings\\The\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\The\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/27/2009 6:16 PM 108289]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/9/2010 12:15 AM 135664]
.
Contents of the 'Scheduled Tasks' folder
2010-02-20 c:\windows\Tasks\expressburnSevenDays.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-02-20 16:15]
2010-02-20 c:\windows\Tasks\expressburnSevenDaysInit.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-02-20 16:15]
2010-02-23 c:\windows\Tasks\expressburnShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-02-20 16:15]
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 00:15]
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 00:15]
2010-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1547161642-725345543-1003Core.job
- c:\documents and settings\The\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-12 14:21]
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1547161642-725345543-1003UA.job
- c:\documents and settings\The\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-12 14:21]
2010-02-24 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-01-08 22:18]
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\The\Application Data\Mozilla\Firefox\Profiles\bkk79tx6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-flv&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-flv&p=
FF - component: c:\documents and settings\The\Application Data\Mozilla\Firefox\Profiles\bkk79tx6.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\documents and settings\The\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\The\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-24 04:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-02-24 04:07:53
ComboFix-quarantined-files.txt 2010-02-24 04:07
Pre-Run: 18,369,077,248 bytes free
Post-Run: 18,331,672,576 bytes free
- - End Of File - - EB1F876066CD2FBA5D80C032C2396D2A
ComboFix 10-02-23.03 - The 02/24/2010 4:01.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.503.241 [GMT 0]
Running from: c:\documents and settings\The\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\docume~1\THE~1\LOCALS~1\Temp\cvasds0.dll
c:\documents and settings\The\Application Data\avdrn.dat
c:\documents and settings\The\Start Menu\Programs\Startup\siszyd32.exe
c:\windows\system32\drivers\saishci.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_saishci
-------\Service_saishci
((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.
2010-02-22 09:50 . 2010-02-22 09:50 -------- d-----w- c:\documents and settings\The\Local Settings\Application Data\Apple Computer
2010-02-20 15:24 . 2010-02-20 15:24 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2010-02-20 15:23 . 2010-02-20 15:23 -------- d-----w- c:\program files\NCH Swift Sound
2010-02-09 00:20 . 2010-02-09 00:20 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-02-09 00:15 . 2010-02-09 00:15 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-02-05 10:39 . 2010-02-05 10:39 251376 ----a-w- c:\documents and settings\The\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-02-01 09:00 . 2008-05-02 10:41 3493888 ---ha-w- c:\documents and settings\The\Application Data\U3\temp\Launchpad Removal.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 04:00 . 2009-12-24 10:37 79488 ----a-w- c:\documents and settings\The\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-21 17:25 . 2008-11-08 10:23 -------- d-----w- c:\documents and settings\The\Application Data\Skype
2010-02-21 16:41 . 2008-11-08 10:24 -------- d-----w- c:\documents and settings\The\Application Data\skypePM
2010-02-14 14:20 . 2008-11-06 12:48 18080 ----a-w- c:\documents and settings\The\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-09 00:15 . 2008-11-07 08:47 -------- d-----w- c:\program files\Google
2010-02-01 09:11 . 2008-11-08 18:25 -------- d-----w- c:\documents and settings\The\Application Data\U3
2010-01-12 12:55 . 2010-01-12 12:55 16 ----a-w- c:\documents and settings\NetworkService\Application Data\fvgqad.dat
2010-01-08 21:44 . 2010-01-08 21:44 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-01-05 10:05 . 2010-01-05 10:05 16 ----a-w- c:\documents and settings\Default User\Application Data\fvgqad.dat
2010-01-05 02:46 . 2010-01-05 02:46 -------- d-----w- c:\program files\MSXML 4.0
2010-01-05 01:42 . 2010-01-05 01:42 16 ----a-w- c:\documents and settings\The\Application Data\fvgqad.dat
2010-01-04 04:31 . 2009-12-27 18:16 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-02 23:29 . 2008-11-06 12:56 -------- d-----w- c:\program files\Avira
2009-12-31 15:06 . 2006-01-13 01:49 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-27 18:16 . 2009-12-27 18:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-12-27 18:05 . 2008-11-11 12:47 -------- d-----w- c:\documents and settings\All Users\Application Data\OrbNetworks
2009-12-27 18:05 . 2008-11-11 12:47 -------- d-----w- c:\program files\Winamp Remote
2009-12-27 18:03 . 2008-11-11 12:46 -------- d-----w- c:\program files\Winamp
2009-12-22 05:35 . 2006-01-13 01:26 668672 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:35 . 2006-01-13 01:55 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-16 12:58 . 2008-11-06 20:23 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2006-01-13 01:13 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-04 13:37 . 2006-01-13 01:47 456832 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:04 . 2006-01-13 01:36 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:04 . 2006-01-06 15:53 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:37 . 2006-01-13 01:47 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37 . 2006-01-13 01:39 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:37 . 2006-01-13 01:10 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37 . 2006-01-06 15:53 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37 . 2006-01-06 15:53 8704 ----a-w- c:\windows\system32\tsbyuv.dll
.
------- Sigcheck -------
[-] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[-] 2006-01-13 . 2DEACA71A7FD77205F59D48D76B2F565 . 1075200 . . [6.00.2900.2649] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2005-12-14 7095344]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-10 68856]
"Google Update"="c:\documents and settings\The\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-12 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-07 136600]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnsc"="c:\windows\system32\msnsc.exe" [2006-01-13 62054]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-01-13 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Documents and Settings\\The\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\The\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/27/2009 6:16 PM 108289]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/9/2010 12:15 AM 135664]
.
Contents of the 'Scheduled Tasks' folder
2010-02-20 c:\windows\Tasks\expressburnSevenDays.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-02-20 16:15]
2010-02-20 c:\windows\Tasks\expressburnSevenDaysInit.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-02-20 16:15]
2010-02-23 c:\windows\Tasks\expressburnShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressBurn\expressburn.exe [2010-02-20 16:15]
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 00:15]
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-09 00:15]
2010-02-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1547161642-725345543-1003Core.job
- c:\documents and settings\The\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-12 14:21]
2010-02-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1078081533-1547161642-725345543-1003UA.job
- c:\documents and settings\The\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-12 14:21]
2010-02-24 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-01-08 22:18]
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\The\Application Data\Mozilla\Firefox\Profiles\bkk79tx6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-flv&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-flv&p=
FF - component: c:\documents and settings\The\Application Data\Mozilla\Firefox\Profiles\bkk79tx6.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\documents and settings\The\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\The\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-24 04:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-02-24 04:07:53
ComboFix-quarantined-files.txt 2010-02-24 04:07
Pre-Run: 18,369,077,248 bytes free
Post-Run: 18,331,672,576 bytes free
- - End Of File - - EB1F876066CD2FBA5D80C032C2396D2A













from BleepingComputer.com









