How bad is the infection?
When I ran ComboFix, it asked me to install some kind of Recovery Console. I didn't know what this was so I didn't do it. I don't know if that's a bad thing. I can re-run the scan and download the Recovery Console if that's what I'm supposed to do.
It also asked me to disable my antivirus when I ran it, so I did, but now Windows Firewall seems to be disabled also.
--------------------
ComboFix 09-07-19.02 - Mikey Chrobok 19/07/2009 15:32.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.524 [GMT -4:00]
Running from: c:\documents and settings\Mikey Chrobok\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1335 [VPS 090718-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\56e64.msi
c:\windows\Installer\eed021.msi
c:\windows\patch.exe
c:\windows\system32\Data
c:\windows\system32\Data\CTP0243W.DAT
c:\windows\system32\E95THK16.EXE
c:\windows\system32\encapi32.dll
c:\windows\system32\netzy.dll
.
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.
2009-07-19 02:27 . 2009-07-19 02:27 180690 ----a-w- c:\windows\system32\wisdstr.exe
2009-07-19 00:57 . 2009-07-19 00:57 -------- d-----w- c:\documents and settings\Mikey Chrobok\Local Settings\Application Data\Codemasters
2009-07-19 00:39 . 2009-07-19 00:39 -------- d-----w- c:\program files\Codemasters
2009-07-15 15:22 . 2009-07-15 15:22 -------- d-----w- c:\documents and settings\Mikey Chrobok\.jagex_cache_32
2009-07-15 15:21 . 2009-07-15 15:21 -------- d-----w- C:\.jagex_cache_32
2009-07-02 11:46 . 2008-02-20 21:49 495104 ----a-w- c:\windows\Michael_Walltrip.exe
2009-07-02 11:46 . 2009-07-02 11:46 -------- d-----w- c:\windows\Michael_Walltrip Uninstaller
2009-07-02 11:46 . 2008-02-20 21:50 903680 ----a-w- c:\windows\Michael_Walltrip.scr
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 19:13 . 2006-01-07 14:21 -------- d-----w- c:\program files\Hijack This
2009-07-19 15:48 . 2008-07-23 23:04 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-07-19 04:51 . 2008-11-06 12:39 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-07-19 02:26 . 2004-07-30 02:36 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-07-19 02:26 . 2004-07-30 02:36 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-07-19 00:50 . 2004-10-05 00:49 31256 ----a-w- c:\documents and settings\Mikey Chrobok\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-19 00:40 . 2004-07-30 01:05 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-18 23:54 . 2008-07-04 19:10 34 ----a-w- c:\documents and settings\Mikey Chrobok\jagex_runescape_preferences.dat
2009-07-10 01:06 . 2007-07-06 14:06 -------- d-----w- c:\documents and settings\Mikey Chrobok\Application Data\ZoomBrowser EX
2009-07-10 01:06 . 2007-07-06 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-07-03 00:50 . 2007-09-01 19:11 138016 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-03 00:50 . 2007-09-01 19:10 189448 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-06-13 01:25 . 2009-01-19 01:39 -------- d-----w- c:\program files\ARCA Download Client
2009-06-13 01:23 . 2009-01-19 02:30 -------- d-----w- c:\program files\ARCA 08
2009-06-13 01:15 . 2009-03-01 01:22 20480 ----a-w- c:\documents and settings\All Users\Application Data\ARCA Download Client\dcds\patches\SelfUpdateFull.exe
2009-05-31 18:55 . 2007-09-01 19:10 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-04-28 18:21 . 2009-04-28 18:21 34063 ----a-w- c:\documents and settings\Mikey Chrobok\Application Data\Move Networks\ie_bin\Uninst.exe
2009-04-28 18:21 . 2009-04-28 18:20 1046584 ----a-w- c:\documents and settings\Mikey Chrobok\Application Data\Move Networks\MoveMediaPlayer_071301000019.exe
2005-10-22 23:44 . 2005-10-06 02:31 0 ---h--w- c:\program files\viewpoint
2009-04-03 20:03 . 2004-08-12 13:04 10022 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SB Audigy 2 Startup Menu"="/L:ENG" [X]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 1415824]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-23 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2004-10-08 131072]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-06-25 294998]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-10-31 180269]
"AceGain LiveUpdate"="c:\program files\AceGain\LiveUpdate\LiveUpdate.exe" [2004-01-01 417792]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2004-10-08 53248]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-06-15 366400]
"Itiva Media Accelerator"="c:\program files\Itiva\Itiva Media Accelerator\ItivaMediaAccelerator.exe" [2008-06-04 4994288]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CTHELPER.EXE [2003-02-20 28672]
"AsioReg"="CTASIO.DLL" - c:\windows\system32\CTASIO.DLL [2003-02-20 110592]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-03 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2004-8-2 106560]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\Shell ExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-02-27 15:39 282624 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-04-08 15:09 10536 ----a-w- c:\program files\Citrix\GoToAssist\508\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawser vice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDef end]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Papyrus\\NASCAR Racing 2003 Season\\NR2003.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Soldier of Fortune II - Double Helix GOLD\\SoF2MP.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"c:\\Program Files\\ARCA Remax\\ARCA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Itiva\\Itiva Media Accelerator\\ItivaMediaAccelerator.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\ARCA Download Client\\ARCALeverageClient.exe"=
"c:\\Program Files\\ARCA 08\\ARCA.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [31/03/2009 8:44 PM 114768]
R1 atitray;atitray;c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [22/05/2007 5:04 AM 18088]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 12:53 PM 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [27/02/2007 11:39 AM 32256]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [31/03/2009 8:44 PM 20560]
R2 IniPciCheck;IniPciCheck;c:\windows\system32\drivers\IPciChk.sys [12/09/2004 11:59 AM 5120]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [23/07/2008 7:03 PM 206096]
R2 sensorsview;sensorsview;c:\windows\system32\drivers\sensorsview.sys [17/08/2007 12:00 PM 4224]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 6:19 PM 13592]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [16/02/2006 4:51 PM 4096]
S3 tupdate;tupdate;\??\c:\docume~1\MIKEYC~1\LOCALS~1\Temp\tupdate.sys --> c:\docume~1\MIKEYC~1\LOCALS~1\Temp\tupdate.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-07-19 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 22:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Sonic RecordNow! - (no file)
HKCU-Run-Start WingMan Profiler - (no file)
Notify-AtiExtEvent - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://nascar.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = about
:blank
mSearch Bar = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Search &Dictionary - c:\program files\Lexico\Toolbar\dictionary.htm
IE: Search &Thesaurus - c:\program files\Lexico\Toolbar\thesaurus.htm
DPF: {6BA77042-FC93-4AED-B0E8-824979156BA4} - hxxp://chevy.a.content.maven.net/mvms/vfs/chevy/chevylive/live/install/installerAX.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-19 15:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D8B5B5E3-2F8F-3000-6CB8-D2D6FBAF5C53}\InProcServer32*]
"oalijnfmmidclifhmdehadbjnmcdia"=hex:6a,61,63,63,69,67,70,61,64,67,70,65,62 ,68,
6c,69,68,70,70,6a,00,00
"nalidpalmhnhbficmckhgaigmieg"=hex:6b,61,6a,6e,6f,67,6c,67,64,6d,61,6a,65,6 5,
61,66,66,68,67,64,68,62,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(552)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\program files\Citrix\GoToAssist\508\G2AWinLogon.dll
.
Completion time: 2009-07-19 15:45
ComboFix-quarantined-files.txt 2009-07-19 19:45
ComboFix2.txt 2007-05-05 17:48
Pre-Run: 2,745,925,632 bytes free
Post-Run: 5,885,231,104 bytes free
179