Redirect seems to be better now. Can't see any immediate issues still present. Will keep an eye on. ComboFix 11-05-29.01 - Chris 06/02/2011 14:16:12.6.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.638.380 [GMT -4:00] Running from: c:\documents and settings\Chris\Desktop\ComboFix.exe AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} FW: AVG Firewall *Enabled* {8decf618-9569-4340-b34a-d78d28969b66} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Chris\Application Data\Adobe\plugs c:\documents and settings\Chris\Application Data\Adobe\shed . ---- Previous Run ------- . c:\documents and settings\All Users\Application Data\defender.exe . Infected copy of c:\windows\system32\drivers\volsnap.sys was found and disinfected Restored copy from - Kitty had a snack . ((((((((((((((((((((((((( Files Created from 2011-05-02 to 2011-06-02 ))))))))))))))))))))))))))))))) . . 2011-05-31 00:11 . 2011-05-31 00:11 -------- d-----w- c:\documents and settings\Chris-User\Local Settings\Application Data\{1DD73503-B8BC-40CE-B614-EDFB14419C18} 2011-05-31 00:00 . 2011-05-31 00:00 -------- d-----w- c:\documents and settings\Chris\Local Settings\Application Data\{91B76EBD-4003-4885-A44C-721A9CD95550} 2011-05-30 17:14 . 2011-05-30 17:14 -------- d-----w- c:\windows\msdownld.tmp 2011-05-30 14:50 . 2011-05-30 14:50 -------- d-----w- c:\documents and settings\Chris\Application Data\tor 2011-05-30 14:48 . 2011-05-30 15:03 -------- d-----w- c:\documents and settings\Chris\Application Data\Vidalia 2011-05-30 13:54 . 2011-05-30 13:54 -------- d-----w- c:\documents and settings\Chris\Application Data\Avira 2011-05-30 13:10 . 2011-04-01 21:07 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2011-05-30 13:10 . 2011-04-01 21:07 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys 2011-05-30 13:10 . 2010-06-17 19:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys 2011-05-30 13:10 . 2010-06-17 19:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys 2011-05-30 13:10 . 2011-05-30 13:10 -------- d-----w- c:\program files\Avira 2011-05-30 13:10 . 2011-05-30 13:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira 2011-05-30 00:15 . 2011-05-31 01:32 -------- d-----w- c:\documents and settings\Guest 2011-05-30 00:14 . 2011-05-30 00:14 -------- d-----w- c:\windows\system32\wbem\Repository 2011-05-18 02:44 . 2011-05-18 02:45 -------- d-----w- c:\program files\7-Zip 2011-05-15 20:44 . 2011-05-15 20:44 -------- d-----w- c:\documents and settings\Chris\Local Settings\Application Data\Doubleclick_Industries 2011-05-15 20:43 . 2011-05-15 20:44 -------- d-----w- c:\documents and settings\Chris\Application Data\FileFactory Turbo 2011-05-15 20:43 . 2011-05-15 20:43 -------- d-----w- c:\program files\FileFactory Turbo . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-29 13:11 . 2011-02-20 01:44 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-03-07 05:33 . 2009-11-18 21:33 692736 ----a-w- c:\windows\system32\inetcomm.dll . . ((((((((((((((((((((((((((((( SnapShot_2011-05-30_01.18.17 ))))))))))))))))))))))))))))))))))))))))) . + 2011-06-02 18:14 . 2011-06-02 18:14 16384 c:\windows\temp\Perflib_Perfdata_6bc.dat + 2009-11-19 02:48 . 2009-01-07 22:21 26144 c:\windows\system32\spupdsvc.exe - 2009-11-19 02:48 . 2009-01-07 23:21 26144 c:\windows\system32\spupdsvc.exe + 2009-11-19 02:47 . 2009-01-07 22:20 16928 c:\windows\system32\spmsg.dll - 2009-11-19 02:47 . 2009-01-07 23:20 16928 c:\windows\system32\spmsg.dll + 2006-06-29 13:05 . 2009-01-07 22:20 23552 c:\windows\system32\normaliz.dll - 2006-06-29 13:05 . 2009-01-07 23:20 23552 c:\windows\system32\normaliz.dll + 2006-06-28 22:59 . 2009-01-07 22:20 24576 c:\windows\system32\nlsdl.dll - 2006-06-28 22:59 . 2009-01-07 23:20 24576 c:\windows\system32\nlsdl.dll + 2007-08-13 23:39 . 2009-03-08 08:32 36864 c:\windows\system32\ieudinit.exe - 2007-08-13 23:39 . 2009-03-08 09:32 36864 c:\windows\system32\ieudinit.exe - 2006-06-29 13:05 . 2009-01-07 23:20 26112 c:\windows\system32\idndl.dll + 2006-06-29 13:05 . 2009-01-07 22:20 26112 c:\windows\system32\idndl.dll + 2011-05-30 13:10 . 2010-06-17 19:27 28520 c:\windows\system32\drivers\ssmdrv.sys + 2004-08-04 12:00 . 2008-04-13 18:41 52352 c:\windows\system32\dllcache\volsnap.sys - 2010-08-17 13:17 . 2010-08-17 13:17 58880 c:\windows\system32\dllcache\spoolsv.exe + 2004-08-04 12:00 . 2010-08-17 13:17 58880 c:\windows\system32\dllcache\spoolsv.exe - 2011-04-23 21:20 . 2010-07-05 13:15 26488 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\update\spcustom.dll - 2011-04-23 21:20 . 2010-07-05 13:15 17272 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\spmsg.dll - 2011-04-23 21:20 . 2011-02-22 23:27 12800 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\xpshims.dll - 2011-04-23 21:20 . 2011-02-22 23:27 66560 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\mshtmled.dll - 2011-04-23 21:20 . 2011-02-22 23:27 55296 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\msfeedsbs.dll - 2011-04-23 21:20 . 2011-02-22 23:27 43520 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\licmgr10.dll - 2011-04-23 21:20 . 2011-02-22 23:27 25600 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\jsproxy.dll - 2011-04-23 21:20 . 2011-02-22 23:06 12800 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\xpshims.dll - 2011-04-23 21:20 . 2011-02-22 23:06 66560 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\mshtmled.dll - 2011-04-23 21:20 . 2011-02-22 23:06 55296 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\msfeedsbs.dll - 2011-04-23 21:20 . 2011-02-22 23:06 43520 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\licmgr10.dll - 2011-04-23 21:20 . 2011-02-22 23:06 25600 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\jsproxy.dll + 2011-05-30 17:14 . 2009-12-11 08:38 69120 c:\windows\ie8updates\KB2447568-IE8\iecompat.dll + 2010-02-06 16:35 . 2010-10-18 11:10 7680 c:\windows\system32\dllcache\iecompat.dll + 2009-11-19 02:47 . 2009-01-07 22:21 121856 c:\windows\system32\xmllite.dll - 2009-11-19 02:47 . 2008-04-14 00:12 121856 c:\windows\system32\xmllite.dll + 2009-01-07 23:20 . 2009-01-07 22:20 265720 c:\windows\system32\msdbg2.dll - 2009-01-07 23:20 . 2009-01-07 23:20 265720 c:\windows\system32\msdbg2.dll + 2011-05-29 05:56 . 2011-06-02 18:14 224226 c:\windows\system32\inetsrv\MetaBase.bin - 2011-04-23 21:20 . 2010-07-05 13:16 382840 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\update\updspapi.dll - 2011-04-23 21:20 . 2010-07-05 13:15 755576 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\update\update.exe - 2011-04-23 21:20 . 2010-07-05 13:15 231288 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\spuninst.exe - 2011-04-23 21:20 . 2011-02-22 23:27 919552 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\wininet.dll - 2011-04-23 21:20 . 2011-02-22 23:27 206848 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\occache.dll - 2011-04-23 21:20 . 2011-02-22 23:27 611840 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\mstime.dll - 2011-04-23 21:20 . 2011-02-22 23:27 602112 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\msfeeds.dll - 2011-04-23 21:20 . 2011-02-22 23:27 247808 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\ieproxy.dll - 2011-04-23 21:20 . 2011-02-22 23:27 184320 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\iepeers.dll - 2011-04-23 21:20 . 2011-02-22 23:27 743424 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\iedvtool.dll - 2011-04-23 21:20 . 2011-02-22 23:27 387584 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\iedkcs32.dll - 2011-04-23 21:20 . 2011-02-22 12:08 173568 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\ie4uinit.exe - 2011-04-23 21:20 . 2011-02-22 23:06 916480 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\wininet.dll - 2011-04-23 21:20 . 2011-02-22 23:06 206848 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\occache.dll - 2011-04-23 21:20 . 2011-02-22 23:06 611840 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\mstime.dll - 2011-04-23 21:20 . 2011-02-22 23:06 602112 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\msfeeds.dll - 2011-04-23 21:20 . 2011-02-22 23:06 247808 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\ieproxy.dll - 2011-04-23 21:20 . 2011-02-22 23:06 184320 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\iepeers.dll - 2011-04-23 21:20 . 2011-02-22 23:06 743424 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\iedvtool.dll - 2011-04-23 21:20 . 2011-02-22 23:06 387584 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\iedkcs32.dll - 2011-04-23 21:20 . 2011-02-18 11:49 173568 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\ie4uinit.exe + 2011-05-30 17:14 . 2010-02-22 14:23 382840 c:\windows\ie8updates\KB2447568-IE8\spuninst\updspapi.dll + 2011-05-30 17:14 . 2010-02-22 14:23 231288 c:\windows\ie8updates\KB2447568-IE8\spuninst\spuninst.exe + 2009-01-07 22:20 . 2009-01-07 22:20 1497088 c:\windows\system32\dllcache\shdocvw.dll + 2009-01-07 22:20 . 2009-01-07 22:20 1022976 c:\windows\system32\dllcache\browseui.dll - 2011-04-23 21:20 . 2011-02-22 23:27 1212928 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\urlmon.dll - 2011-04-23 21:20 . 2011-02-22 23:27 5964800 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\mshtml.dll - 2011-04-23 21:20 . 2011-02-22 23:27 1992192 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3QFE\iertutil.dll - 2011-04-23 21:20 . 2011-02-22 23:06 1210880 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\urlmon.dll - 2011-04-23 21:20 . 2011-02-22 23:06 5962240 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\mshtml.dll - 2011-04-23 21:20 . 2011-02-22 23:06 1991680 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\iertutil.dll + 2010-02-06 16:28 . 2011-04-29 15:29 42829768 c:\windows\system32\MRT.exe - 2011-04-23 21:20 . 2011-02-22 23:06 11080704 c:\windows\SoftwareDistribution\Download\4a68e5ecf881bfdf9f622e39f79b4af0\SP3GDR\ieframe.dll . -- Snapshot reset to current date -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2009-12-17 149224] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 . R1 6bd6aafb-ce29-4dbb-ad25-c59a3e0c7415;6bd6aafb-ce29-4dbb-ad25-c59a3e0c7415;c:\windows\iprot\6bd6aafb-ce29-4dbb-ad25-c59a3e0c7415\PhysMem.sys [11/21/2009 11:53 PM 3584] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/30/2011 9:10 AM 136360] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2/19/2011 9:44 PM 39984] . Contents of the 'Scheduled Tasks' folder . 2011-05-27 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50] . 2011-06-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-329068152-261903793-682003330-1003Core.job - c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-01-08 00:35] . 2011-06-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-329068152-261903793-682003330-1003UA.job - c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-01-08 00:35] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = <local> IE: Download with &FileFactory Turbo - c:\program files\FileFactory Turbo\Plugins\IE\FileFactoryIE.html TCP: DhcpNameServer = 192.168.15.1 FF - ProfilePath - c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\b7c30e1u.default\ FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-06-02 14:22 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . Completion time: 2011-06-02 14:24:58 ComboFix-quarantined-files.txt 2011-06-02 18:24 ComboFix2.txt 2011-04-23 19:01 . Pre-Run: 21,883,912,192 bytes free Post-Run: 21,955,731,456 bytes free . - - End Of File - - B96D1D8C2B5023AD7ABE0FC8E2CC23BE