Here's the Combofix data -
c:\windows\system32\Thumbs.db
.
.
\\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ITLPERF
-------\Service_itlperf
.
.
((((((((((((((((((((((((( Files Created from 2011-02-15 to 2011-03-15 )))))))))))))))))))))))))))))))
.
.
2011-03-15 18:27 . 2004-08-04 07:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2011-03-14 12:49 . 2011-03-14 12:49 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-03-14 12:48 . 2011-03-14 12:49 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-03-13 11:13 . 2011-03-13 11:13 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-03-13 11:04 . 2011-03-13 11:04 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-03-13 10:50 . 2011-03-13 10:50 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2011-03-13 10:40 . 2009-01-08 02:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2011-03-13 10:39 . 2011-03-13 10:48 -------- dc-h--w- c:\windows\ie8
2011-03-13 10:34 . 2004-08-17 11:21 87168 ----a-w- c:\windows\system32\drivers\drvmcdb.sys
2011-03-13 10:34 . 2004-07-14 10:56 40448 ----a-w- c:\windows\system32\drivers\drvnddm.sys
2011-03-13 10:34 . 2011-03-14 05:20 -------- d-----w- c:\windows\system32\dla
2011-03-13 10:34 . 2004-08-03 09:05 98358 ----a-w- c:\windows\dla.exe
2011-03-13 10:34 . 2004-08-03 09:05 61498 ----a-w- c:\windows\system32\tfswapi.dll
2011-03-13 10:34 . 2004-07-14 19:29 5627 ----a-w- c:\windows\system32\drivers\sscdbhk5.sys
2011-03-13 10:34 . 2004-07-14 19:28 23545 ----a-w- c:\windows\system32\drivers\ssrtln.sys
2011-03-13 10:34 . 2004-02-26 18:34 110592 ----a-w- c:\windows\system32\ArcSpl.ax
2011-03-13 10:34 . 2004-02-23 02:01 48128 ----a-w- c:\windows\system32\mpgvideo.ax
2011-03-13 10:34 . 2004-02-23 02:01 192512 ----a-w- c:\windows\system32\AdavVideoDec.dll
2011-03-13 10:34 . 2003-12-18 17:03 47616 ----a-w- c:\windows\system32\mpgaudio.ax
2011-03-13 10:34 . 2003-12-18 17:03 126976 ----a-w- c:\windows\system32\AdavAudioDec.dll
2011-03-13 10:30 . 1995-08-01 12:44 212480 ----a-w- c:\windows\PCDLIB32.DLL
2011-03-13 10:30 . 2002-09-29 18:56 139264 ----a-w- c:\windows\system32\PhotoBase Screen Saver.scr
2011-03-13 10:30 . 2011-03-13 10:30 -------- d-----w- c:\program files\ArcSoft
2011-03-13 10:12 . 2011-03-15 18:36 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2011-03-13 10:11 . 2011-03-13 10:11 -------- d-----w- c:\program files\AVG
2011-03-13 09:58 . 2011-03-13 10:11 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2011-03-13 09:34 . 2011-03-13 09:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-03-13 09:34 . 2010-12-21 02:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-13 09:34 . 2011-03-13 09:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-13 09:34 . 2010-12-21 02:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-13 09:31 . 2011-03-13 09:31 -------- d-----w- c:\program files\SymNetDrv
2011-03-13 08:19 . 2011-03-15 18:35 -------- d-----w- c:\documents and settings\uentin
2011-03-13 08:18 . 2004-11-16 06:07 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\InterVideo
2011-03-13 08:18 . 2004-11-16 05:44 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\AOL
2011-03-13 08:18 . 2004-11-16 05:30 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2011-03-13 08:18 . 2004-11-16 05:22 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\InterTrust
2011-03-13 08:18 . 2004-11-16 05:07 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Symantec
2011-03-13 08:18 . 2004-11-16 04:32 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Intuit
2011-03-13 08:18 . 2004-11-16 03:57 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2011-03-13 08:18 . 2001-04-04 09:31 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\toshiba
2011-03-13 08:18 . 2011-03-13 08:18 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Intel
2011-03-13 08:17 . 2011-03-13 08:17 17119 ----a-w- c:\windows\system32\drivers\AegisP.sys
2011-03-13 08:17 . 2011-03-13 08:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2011-03-13 08:16 . 2004-12-08 15:44 458752 ----a-w- c:\windows\system32\w29NCPA.dll
2011-03-13 08:16 . 2004-12-08 15:44 3222784 ----a-w- c:\windows\system32\drivers\w29n51.sys
2011-03-13 08:15 . 2004-12-08 15:44 1654784 ----a-w- c:\windows\system32\W29MLRES.DLL
2011-03-13 08:15 . 2004-11-16 03:57 -------- d-----w- c:\documents and settings\Default User\WINDOWS
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2003-08-27 22:19 . 2004-11-16 04:31 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-02-18 2423752]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-08 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-08 126976]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2004-12-15 368640]
"NDSTray.exe"="NDSTray.exe" [BU]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-09-06 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 88363]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-09-15 135168]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2004-11-13 73728]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-03 122939]
"TFncKy"="TFncKy.exe" [BU]
"TPSMain"="TPSMain.exe" [2004-08-27 278528]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 1077301]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2004-11-03 147456]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 356352]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-11-16 98304]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2004-12-7 155648]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 19:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
itlsvc REG_MULTI_SZ itlperf
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
uInternet Connection Wizard,ShellNext = hxxp://toolbar.google.com/done
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\uentin\Application Data\Mozilla\Firefox\Profiles\7vd88vbh.default\
FF - prefs.js: network.proxy.type - 1
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Notify-itlntfy - itlnfw32.dll
AddRemove-whitesmoketoolbar - c:\program files\whitesmoketoolbar\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2011-03-15 10:58
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(988)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
- - - - - - - > 'explorer.exe'(2724)
c:\windows\system32\SynTPFcs.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\ZcfgSvc.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\TPSMain.exe
c:\windows\system32\TPSBattM.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Intel\Wireless\Bin\OProtSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-03-15 11:00:45 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-15 19:00
.
Pre-Run: 92,824,227,840 bytes free
Post-Run: 92,877,041,664 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - B9730990EA2B3E511737B5A64F2FDADD