jcwhip4
2008-12-04, 17:44
Blade81 was helpingme on this previously - I had a lag in communication due to a vacation.
Here is a link to the previous thread: http://forums.spybot.info/showthread.php?t=36321&highlight=serious
Below is the Log following a running of ComboFix.exe on my PC:
ComboFix 08-12-03.04 - jc 2008-12-04 9:47:57.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.116 [GMT -5:00]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\jc\Local Settings\Temporary Internet Files\ejeroxyxyn.scr
c:\documents and settings\jc\Local Settings\Temporary Internet Files\gafizoxyq.db
c:\documents and settings\jc\Local Settings\Temporary Internet Files\kewogoh.bat
c:\documents and settings\jc\Local Settings\Temporary Internet Files\lazymuhoc.inf
c:\documents and settings\jc\Local Settings\Temporary Internet Files\mimutydut.com
c:\documents and settings\jc\Local Settings\Temporary Internet Files\qery.lib
c:\documents and settings\jc\Local Settings\Temporary Internet Files\uropyxav.scr
c:\windows\system32\av.dat
c:\windows\system32\dllcache\figaro.sys
c:\windows\system32\drivers\TDSSmqlt.sys
c:\windows\system32\drivers\TDSSpqxt.sys
c:\windows\system32\TDSSbutv.log
c:\windows\system32\TDSScbqp.dll
c:\windows\system32\TDSSciou.dll
c:\windows\system32\TDSSfpmp.log
c:\windows\system32\TDSShrsr.dll
c:\windows\system32\TDSShrxx.dll
c:\windows\system32\TDSSkkbi.log
c:\windows\system32\TDSSlblj.dll
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSmqxt.log
c:\windows\system32\TDSSmtql.dll
c:\windows\system32\TDSSmtyh.dat
c:\windows\system32\TDSSnmxh.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrse.dll
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSoiqh.log
c:\windows\system32\TDSSoiqn.dll
c:\windows\system32\TDSSorvd.dat
c:\windows\system32\TDSSosvn.dll
c:\windows\system32\TDSSpqxt.dat
c:\windows\system32\TDSSrhyp.dll
c:\windows\system32\TDSSrtqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\TDSSxfum.dll
c:\windows\system32\TDSSxnsx.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSSERV.SYS)
-------\Legacy_TDSSSERV.SYS)
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.
2008-11-13 13:24 . 2008-11-13 13:24 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-13 13:24 . 2008-11-13 13:24 <DIR> d-------- c:\documents and settings\jc\Application Data\Malwarebytes
2008-11-13 13:24 . 2008-11-13 13:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-13 13:24 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-13 13:24 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-12 12:58 . 2008-11-12 12:58 <DIR> d-------- C:\rsit
2008-11-12 10:17 . 2008-11-12 10:17 <DIR> d-------- c:\program files\Trend Micro
2008-11-08 08:46 . 2008-11-08 09:07 1,080 --a------ c:\windows\system32\drivers\kgpfr2(6).cfg
2008-11-08 08:46 . 2008-11-08 09:07 1,080 --a------ c:\windows\system32\drivers\kgpfr2(5).cfg
2008-11-08 08:46 . 2008-11-08 09:07 1,080 --a------ c:\windows\system32\drivers\kgpfr2(3).cfg
2008-11-08 08:46 . 2008-11-08 09:07 1,080 --a------ c:\windows\system32\drivers\kgpfr2(2).cfg
2008-11-08 07:29 . 2008-11-08 07:31 1,488 --a------ c:\windows\system32\drivers\kgpcpy(6).cfg
2008-11-08 07:29 . 2008-11-08 07:31 1,488 --a------ c:\windows\system32\drivers\kgpcpy(5).cfg
2008-11-08 07:29 . 2008-11-08 07:31 1,488 --a------ c:\windows\system32\drivers\kgpcpy(3).cfg
2008-11-08 07:29 . 2008-11-08 07:31 1,488 --a------ c:\windows\system32\drivers\kgpcpy(2).cfg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 20:32 --------- d-----w c:\program files\Google
2008-11-08 13:47 --------- d-----w c:\documents and settings\All Users\Application Data\DIGStream
2008-11-06 13:44 2,456 ----a-w c:\windows\system32\drivers\kgpfr2(4).cfg
2008-11-02 13:28 328 ----a-w c:\windows\system32\drivers\kgpcpy(4).cfg
2008-10-25 16:42 --------- d-----w c:\program files\ESPNRunTime
2008-10-25 16:42 --------- d-----w c:\program files\DIGStream
2008-10-25 16:42 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-10-25 16:42 --------- d-----w c:\program files\Common Files\Apple
2008-10-25 16:42 --------- d-----w c:\program files\Common Files\Adobe
2008-10-25 16:42 --------- d-----w c:\program files\Bonjour
2008-10-25 16:19 19,502 ----a-w c:\windows\uxyd.bat
2008-10-25 16:19 17,120 ----a-w c:\windows\emydomaky.sys
2008-10-25 16:19 16,816 ----a-w c:\documents and settings\All Users\Application Data\ufigan.bat
2008-10-25 16:19 16,038 ----a-w c:\windows\levemegy.com
2008-10-25 16:19 15,912 ----a-w c:\windows\ehyrib.reg
2008-10-25 16:19 12,844 ----a-w c:\windows\yxem.bin
2008-10-25 16:19 12,638 ----a-w c:\windows\cirubehu.reg
2008-10-25 16:19 10,561 ----a-w c:\windows\dinycufyby.bin
2008-10-04 12:40 --------- d-----w c:\program files\iTunes
2008-10-04 12:40 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-04 12:39 --------- d-----w c:\program files\iPod
2008-02-01 03:39 60,424 ----a-w c:\documents and settings\jc\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-09-02 100056]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2003-10-06 49152]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 110592]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-10-31 278528]
"DIGServices"="c:\program files\ESPNRunTime\DIGServices.exe" [2005-10-31 101888]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-01-31 366400]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"nwiz"="nwiz.exe" [2003-10-06 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-04-05 82026]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
Contents of the 'Scheduled Tasks' folder
2008-11-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe []
2008-11-08 c:\windows\Tasks\Norton AntiVirus - Scan my computer - jc.job
- c:\progra~1\NORTON~1\Navw32.exe [2005-01-10 11:20]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
HKLM-Run-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FireFox -: Profile - c:\documents and settings\jc\Application Data\Mozilla\Firefox\Profiles\rpxuh5ty.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://news.google.com/
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 09:52:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Norton AntiVirus\NAVAPSVC.EXE
c:\program files\Norton AntiVirus\IWP\NPFMNTOR.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\devldr32.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\MUSICM~1\MUSICM~1\MMDiag.exe
c:\program files\Musicmatch\Musicmatch Jukebox\mim.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-04 9:55:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 14:55:23
Pre-Run: 37,412,126,720 bytes free
Post-Run: 38,075,858,944 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
208 --- E O F --- 2008-10-24 07:01:06
Here is a link to the previous thread: http://forums.spybot.info/showthread.php?t=36321&highlight=serious
Below is the Log following a running of ComboFix.exe on my PC:
ComboFix 08-12-03.04 - jc 2008-12-04 9:47:57.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.116 [GMT -5:00]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\jc\Local Settings\Temporary Internet Files\ejeroxyxyn.scr
c:\documents and settings\jc\Local Settings\Temporary Internet Files\gafizoxyq.db
c:\documents and settings\jc\Local Settings\Temporary Internet Files\kewogoh.bat
c:\documents and settings\jc\Local Settings\Temporary Internet Files\lazymuhoc.inf
c:\documents and settings\jc\Local Settings\Temporary Internet Files\mimutydut.com
c:\documents and settings\jc\Local Settings\Temporary Internet Files\qery.lib
c:\documents and settings\jc\Local Settings\Temporary Internet Files\uropyxav.scr
c:\windows\system32\av.dat
c:\windows\system32\dllcache\figaro.sys
c:\windows\system32\drivers\TDSSmqlt.sys
c:\windows\system32\drivers\TDSSpqxt.sys
c:\windows\system32\TDSSbutv.log
c:\windows\system32\TDSScbqp.dll
c:\windows\system32\TDSSciou.dll
c:\windows\system32\TDSSfpmp.log
c:\windows\system32\TDSShrsr.dll
c:\windows\system32\TDSShrxx.dll
c:\windows\system32\TDSSkkbi.log
c:\windows\system32\TDSSlblj.dll
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSmqxt.log
c:\windows\system32\TDSSmtql.dll
c:\windows\system32\TDSSmtyh.dat
c:\windows\system32\TDSSnmxh.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrse.dll
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSoiqh.log
c:\windows\system32\TDSSoiqn.dll
c:\windows\system32\TDSSorvd.dat
c:\windows\system32\TDSSosvn.dll
c:\windows\system32\TDSSpqxt.dat
c:\windows\system32\TDSSrhyp.dll
c:\windows\system32\TDSSrtqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\TDSSxfum.dll
c:\windows\system32\TDSSxnsx.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSSERV.SYS)
-------\Legacy_TDSSSERV.SYS)
((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.
2008-11-13 13:24 . 2008-11-13 13:24 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-13 13:24 . 2008-11-13 13:24 <DIR> d-------- c:\documents and settings\jc\Application Data\Malwarebytes
2008-11-13 13:24 . 2008-11-13 13:24 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-13 13:24 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-13 13:24 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-12 12:58 . 2008-11-12 12:58 <DIR> d-------- C:\rsit
2008-11-12 10:17 . 2008-11-12 10:17 <DIR> d-------- c:\program files\Trend Micro
2008-11-08 08:46 . 2008-11-08 09:07 1,080 --a------ c:\windows\system32\drivers\kgpfr2(6).cfg
2008-11-08 08:46 . 2008-11-08 09:07 1,080 --a------ c:\windows\system32\drivers\kgpfr2(5).cfg
2008-11-08 08:46 . 2008-11-08 09:07 1,080 --a------ c:\windows\system32\drivers\kgpfr2(3).cfg
2008-11-08 08:46 . 2008-11-08 09:07 1,080 --a------ c:\windows\system32\drivers\kgpfr2(2).cfg
2008-11-08 07:29 . 2008-11-08 07:31 1,488 --a------ c:\windows\system32\drivers\kgpcpy(6).cfg
2008-11-08 07:29 . 2008-11-08 07:31 1,488 --a------ c:\windows\system32\drivers\kgpcpy(5).cfg
2008-11-08 07:29 . 2008-11-08 07:31 1,488 --a------ c:\windows\system32\drivers\kgpcpy(3).cfg
2008-11-08 07:29 . 2008-11-08 07:31 1,488 --a------ c:\windows\system32\drivers\kgpcpy(2).cfg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 20:32 --------- d-----w c:\program files\Google
2008-11-08 13:47 --------- d-----w c:\documents and settings\All Users\Application Data\DIGStream
2008-11-06 13:44 2,456 ----a-w c:\windows\system32\drivers\kgpfr2(4).cfg
2008-11-02 13:28 328 ----a-w c:\windows\system32\drivers\kgpcpy(4).cfg
2008-10-25 16:42 --------- d-----w c:\program files\ESPNRunTime
2008-10-25 16:42 --------- d-----w c:\program files\DIGStream
2008-10-25 16:42 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-10-25 16:42 --------- d-----w c:\program files\Common Files\Apple
2008-10-25 16:42 --------- d-----w c:\program files\Common Files\Adobe
2008-10-25 16:42 --------- d-----w c:\program files\Bonjour
2008-10-25 16:19 19,502 ----a-w c:\windows\uxyd.bat
2008-10-25 16:19 17,120 ----a-w c:\windows\emydomaky.sys
2008-10-25 16:19 16,816 ----a-w c:\documents and settings\All Users\Application Data\ufigan.bat
2008-10-25 16:19 16,038 ----a-w c:\windows\levemegy.com
2008-10-25 16:19 15,912 ----a-w c:\windows\ehyrib.reg
2008-10-25 16:19 12,844 ----a-w c:\windows\yxem.bin
2008-10-25 16:19 12,638 ----a-w c:\windows\cirubehu.reg
2008-10-25 16:19 10,561 ----a-w c:\windows\dinycufyby.bin
2008-10-04 12:40 --------- d-----w c:\program files\iTunes
2008-10-04 12:40 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-04 12:39 --------- d-----w c:\program files\iPod
2008-02-01 03:39 60,424 ----a-w c:\documents and settings\jc\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-09-02 100056]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2003-10-06 49152]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11776]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 110592]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-10-31 278528]
"DIGServices"="c:\program files\ESPNRunTime\DIGServices.exe" [2005-10-31 101888]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-01-31 366400]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"nwiz"="nwiz.exe" [2003-10-06 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-04-05 82026]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
Contents of the 'Scheduled Tasks' folder
2008-11-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe []
2008-11-08 c:\windows\Tasks\Norton AntiVirus - Scan my computer - jc.job
- c:\progra~1\NORTON~1\Navw32.exe [2005-01-10 11:20]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
HKLM-Run-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FireFox -: Profile - c:\documents and settings\jc\Application Data\Mozilla\Firefox\Profiles\rpxuh5ty.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://news.google.com/
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF -: plugin - c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 09:52:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Norton AntiVirus\NAVAPSVC.EXE
c:\program files\Norton AntiVirus\IWP\NPFMNTOR.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\devldr32.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\MUSICM~1\MUSICM~1\MMDiag.exe
c:\program files\Musicmatch\Musicmatch Jukebox\mim.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-04 9:55:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 14:55:23
Pre-Run: 37,412,126,720 bytes free
Post-Run: 38,075,858,944 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
208 --- E O F --- 2008-10-24 07:01:06