Combofix
ComboFix 09-06-12.04 - David 13/06/2009 18:07.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1023.544 [GMT 1:00]
Running from: c:\documents and settings\David\Desktop\ComboFix1.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\MSIVXbakndowpdwkmrmktitexcprrvqymtnvi.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\MSIVXmvltpwfdgdkonqrdlqrmupfhpteymfkd.dll
c:\windows\system32\MSIVXqpvihsrsmkjntyxvaqlxopyhuuagntsc.dll
c:\windows\system32\drivers\MSIVXbakndowpdwkmrmktitexcprrvqymtnvi.sys
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXmvltpwfdgdkonqrdlqrmupfhpteymfkd.dll
c:\windows\system32\MSIVXqpvihsrsmkjntyxvaqlxopyhuuagntsc.dll
c:\windows\system32\msxml71.dll
c:\windows\system32\packet.dll
c:\windows\system32\wpcap.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MSIVXserv.sys
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-05-13 to 2009-06-13 )))))))))))))))))))))))))))))))
.
2009-06-11 21:29 . 2009-06-11 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Winferno
2009-06-11 18:42 . 2009-06-11 18:42 -------- d-----w- c:\program files\Trend Micro
2009-06-04 21:35 . 2009-06-04 21:35 -------- d--h--r- c:\documents and settings\David\Application Data\SecuROM
2009-06-02 14:32 . 2009-06-02 14:32 -------- d-----w- c:\program files\OpenAL
2009-06-02 14:18 . 2009-06-09 17:41 -------- d-----w- C:\Quake2
2009-06-01 07:45 . 2009-06-01 07:57 116839 ----a-w- c:\windows\hpqins00.dat
2009-05-27 02:29 . 2009-05-27 02:29 -------- d-----w- c:\program files\FLAC
2009-05-26 07:05 . 2009-05-26 07:08 -------- d-----w- c:\program files\NDSROM Player
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-13 17:17 . 2008-01-25 23:54 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-13 16:54 . 2006-12-25 05:45 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-13 16:27 . 2008-11-12 00:10 -------- d-----w- c:\documents and settings\David\Application Data\HPAppData
2009-06-13 12:00 . 2006-12-25 09:10 -------- d-----w- c:\program files\BitComet
2009-06-13 07:16 . 2008-01-25 23:54 -------- d-----w- c:\program files\Spyware Doctor
2009-06-11 21:08 . 2006-12-25 05:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-11 13:39 . 2007-12-08 23:17 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-11 13:39 . 2007-12-08 23:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-11 03:45 . 2007-12-01 20:03 -------- d-----w- c:\documents and settings\David\Application Data\mIRC
2009-06-11 03:37 . 2007-12-01 20:03 -------- d-----w- c:\program files\mIRC
2009-06-02 14:32 . 2009-04-15 01:27 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-06-02 14:32 . 2009-04-15 01:27 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-05-07 09:02 . 2009-05-07 09:02 -------- d-----w- c:\program files\Coupon Printer
2009-05-07 09:02 . 2009-05-07 09:02 31 ---ha-w- c:\windows\UKCpInfo.sys
2009-05-07 05:53 . 2009-05-07 05:53 360580 ----a-w- c:\windows\eSellerateEngine.dll
2009-05-06 06:10 . 2006-12-26 16:51 -------- d-----w- c:\program files\DivX
2009-05-06 06:09 . 2009-05-06 06:09 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-04-23 16:32 . 2006-12-24 21:57 126304 ----a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-21 05:59 . 2009-04-21 05:59 -------- d-----w- c:\documents and settings\David\Application Data\SpinTop
2009-04-15 01:29 . 2009-02-09 22:16 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-04-15 01:23 . 2009-04-15 01:22 -------- d-----w- c:\program files\AGEIA Technologies
2009-04-15 01:22 . 2009-01-27 22:34 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-04-14 00:12 . 2004-08-10 15:37 1159168 --sh--r- c:\windows\system32\pvdhost.exe
.
------- Sigcheck -------
[-] 2005-03-14 01:17 359936 6129E70F3D2F1E60860C930EBEAF92C2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-09-06 04:30 360320 3C966F647BAB332093CB0F92692B5CB8 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 13:00 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB893066$\tcpip.sys
[-] 2005-03-14 00:55 359808 0E66B538096A6529D1AC66E78EB0D5C8 c:\windows\$NtUninstallKB917953$\tcpip.sys
[-] 2007-12-03 17:04 359808 DE891AD282E856ACFD40990094A63B6F c:\windows\$NtUninstallKB941644$\tcpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\tcpip.sys
[-] 2009-01-25 12:22 361600 D24EA301E2B36C4E975FD216CA85D8E7 c:\windows\system32\dllcache\tcpip.sys
[-] 2009-01-25 12:22 361600 D24EA301E2B36C4E975FD216CA85D8E7 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2005-04-20 894464]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-03 136600]
"PCMService"="c:\apps\Powercinema\PCMService.exe" [2005-01-28 110740]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-28 107112]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2006-09-06 26248]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-12-26 185896]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 583048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-08 515416]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2007-10-03 53248]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-03 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2008-2-14 262144]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2bexx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3bfxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3gjxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"21227:TCP"= 21227:TCP:BitComet 21227 TCP
"21227:UDP"= 21227:UDP:BitComet 21227 UDP
"22152:TCP"= 22152:TCP:BitComet 22152 TCP
"22152:UDP"= 22152:UDP:BitComet 22152 UDP
"14634:TCP"= 14634:TCP:BitComet 14634 TCP
"14634:UDP"= 14634:UDP:BitComet 14634 UDP
"16635:TCP"= 16635:TCP:BitComet 16635 TCP
"16635:UDP"= 16635:UDP:BitComet 16635 UDP
"13570:TCP"= 13570:TCP:BitComet 13570 TCP
"13570:UDP"= 13570:UDP:BitComet 13570 UDP
"11529:TCP"= 11529:TCP:BitComet 11529 TCP
"11529:UDP"= 11529:UDP:BitComet 11529 UDP
"14510:TCP"= 14510:TCP:BitComet 14510 TCP
"14510:UDP"= 14510:UDP:BitComet 14510 UDP
"9012:TCP"= 9012:TCP:BitComet 9012 TCP
"9012:UDP"= 9012:UDP:BitComet 9012 UDP
"12616:TCP"= 12616:TCP:BitComet 12616 TCP
"12616:UDP"= 12616:UDP:BitComet 12616 UDP
"12249:TCP"= 12249:TCP:BitComet 12249 TCP
"12249:UDP"= 12249:UDP:BitComet 12249 UDP
"12543:TCP"= 12543:TCP:BitComet 12543 TCP
"12543:UDP"= 12543:UDP:BitComet 12543 UDP
"8989:TCP"= 8989:TCP:BitComet 8989 TCP
"8989:UDP"= 8989:UDP:BitComet 8989 UDP
"11422:TCP"= 11422:TCP:BitComet 11422 TCP
"11422:UDP"= 11422:UDP:BitComet 11422 UDP
"24134:TCP"= 24134:TCP:BitComet 24134 TCP
"24134:UDP"= 24134:UDP:BitComet 24134 UDP
"21600:TCP"= 21600:TCP:BitComet 21600 TCP
"21600:UDP"= 21600:UDP:BitComet 21600 UDP
"9253:TCP"= 9253:TCP:BitComet 9253 TCP
"9253:UDP"= 9253:UDP:BitComet 9253 UDP
"11476:TCP"= 11476:TCP:BitComet 11476 TCP
"11476:UDP"= 11476:UDP:BitComet 11476 UDP
"15079:TCP"= 15079:TCP:BitComet 15079 TCP
"15079:UDP"= 15079:UDP:BitComet 15079 UDP
"25616:TCP"= 25616:TCP:BitComet 25616 TCP
"25616:UDP"= 25616:UDP:BitComet 25616 UDP
"16222:TCP"= 16222:TCP:BitComet 16222 TCP
"16222:UDP"= 16222:UDP:BitComet 16222 UDP
"12741:TCP"= 12741:TCP:BitComet 12741 TCP
"12741:UDP"= 12741:UDP:BitComet 12741 UDP
"8222:TCP"= 8222:TCP:BitComet 8222 TCP
"8222:UDP"= 8222:UDP:BitComet 8222 UDP
"14173:TCP"= 14173:TCP:BitComet 14173 TCP
"14173:UDP"= 14173:UDP:BitComet 14173 UDP
"16856:TCP"= 16856:TCP:BitComet 16856 TCP
"16856:UDP"= 16856:UDP:BitComet 16856 UDP
"26395:TCP"= 26395:TCP:BitComet 26395 TCP
"26395:UDP"= 26395:UDP:BitComet 26395 UDP
"21016:TCP"= 21016:TCP:BitComet 21016 TCP
"21016:UDP"= 21016:UDP:BitComet 21016 UDP
"9643:TCP"= 9643:TCP:BitComet 9643 TCP
"9643:UDP"= 9643:UDP:BitComet 9643 UDP
"20033:TCP"= 20033:TCP:BitComet 20033 TCP
"20033:UDP"= 20033:UDP:BitComet 20033 UDP
"27750:TCP"= 27750:TCP:BitComet 27750 TCP
"27750:UDP"= 27750:UDP:BitComet 27750 UDP
"8198:TCP"= 8198:TCP:BitComet 8198 TCP
"8198:UDP"= 8198:UDP:BitComet 8198 UDP
"20163:TCP"= 20163:TCP:BitComet 20163 TCP
"20163:UDP"= 20163:UDP:BitComet 20163 UDP
"12946:TCP"= 12946:TCP:BitComet 12946 TCP
"12946:UDP"= 12946:UDP:BitComet 12946 UDP
"27595:TCP"= 27595:TCP:BitComet 27595 TCP
"27595:UDP"= 27595:UDP:BitComet 27595 UDP
"13578:TCP"= 13578:TCP:BitComet 13578 TCP
"13578:UDP"= 13578:UDP:BitComet 13578 UDP
"7535:TCP"= 7535:TCP:BitComet 7535 TCP
"7535:UDP"= 7535:UDP:BitComet 7535 UDP
"9481:TCP"= 9481:TCP:BitComet 9481 TCP
"9481:UDP"= 9481:UDP:BitComet 9481 UDP
"19225:TCP"= 19225:TCP:BitComet 19225 TCP
"19225:UDP"= 19225:UDP:BitComet 19225 UDP
"17795:TCP"= 17795:TCP:BitComet 17795 TCP
"17795:UDP"= 17795:UDP:BitComet 17795 UDP
"25445:TCP"= 25445:TCP:BitComet 25445 TCP
"25445:UDP"= 25445:UDP:BitComet 25445 UDP
"26632:TCP"= 26632:TCP:BitComet 26632 TCP
"26632:UDP"= 26632:UDP:BitComet 26632 UDP
"10195:TCP"= 10195:TCP:BitComet 10195 TCP
"10195:UDP"= 10195:UDP:BitComet 10195 UDP
"12761:TCP"= 12761:TCP:BitComet 12761 TCP
"12761:UDP"= 12761:UDP:BitComet 12761 UDP
"20680:TCP"= 20680:TCP:BitComet 20680 TCP
"20680:UDP"= 20680:UDP:BitComet 20680 UDP
"20187:TCP"= 20187:TCP:BitComet 20187 TCP
"20187:UDP"= 20187:UDP:BitComet 20187 UDP
"9246:TCP"= 9246:TCP:BitComet 9246 TCP
"9246:UDP"= 9246:UDP:BitComet 9246 UDP
"12216:TCP"= 12216:TCP:BitComet 12216 TCP
"12216:UDP"= 12216:UDP:BitComet 12216 UDP
"17012:TCP"= 17012:TCP:BitComet 17012 TCP
"17012:UDP"= 17012:UDP:BitComet 17012 UDP
"26564:TCP"= 26564:TCP:BitComet 26564 TCP
"26564:UDP"= 26564:UDP:BitComet 26564 UDP
"20300:TCP"= 20300:TCP:BitComet 20300 TCP
"20300:UDP"= 20300:UDP:BitComet 20300 UDP
"8797:TCP"= 8797:TCP:BitComet 8797 TCP
"8797:UDP"= 8797:UDP:BitComet 8797 UDP
"13387:TCP"= 13387:TCP:BitComet 13387 TCP
"13387:UDP"= 13387:UDP:BitComet 13387 UDP
"14079:TCP"= 14079:TCP:BitComet 14079 TCP
"14079:UDP"= 14079:UDP:BitComet 14079 UDP
"15116:TCP"= 15116:TCP:BitComet 15116 TCP
"15116:UDP"= 15116:UDP:BitComet 15116 UDP
"15424:TCP"= 15424:TCP:BitComet 15424 TCP
"15424:UDP"= 15424:UDP:BitComet 15424 UDP
"7462:TCP"= 7462:TCP:BitComet 7462 TCP
"7462:UDP"= 7462:UDP:BitComet 7462 UDP
"9746:TCP"= 9746:TCP:BitComet 9746 TCP
"9746:UDP"= 9746:UDP:BitComet 9746 UDP
"21658:TCP"= 21658:TCP:BitComet 21658 TCP
"21658:UDP"= 21658:UDP:BitComet 21658 UDP
"12487:TCP"= 12487:TCP:BitComet 12487 TCP
"12487:UDP"= 12487:UDP:BitComet 12487 UDP
"23016:TCP"= 23016:TCP:BitComet 23016 TCP
"23016:UDP"= 23016:UDP:BitComet 23016 UDP
"27693:TCP"= 27693:TCP:BitComet 27693 TCP
"27693:UDP"= 27693:UDP:BitComet 27693 UDP
"12989:TCP"= 12989:TCP:BitComet 12989 TCP
"12989:UDP"= 12989:UDP:BitComet 12989 UDP
"7536:TCP"= 7536:TCP:BitComet 7536 TCP
"7536:UDP"= 7536:UDP:BitComet 7536 UDP
"19687:TCP"= 19687:TCP:BitComet 19687 TCP
"19687:UDP"= 19687:UDP:BitComet 19687 UDP
"9791:TCP"= 9791:TCP:BitComet 9791 TCP
"9791:UDP"= 9791:UDP:BitComet 9791 UDP
"17021:TCP"= 17021:TCP:BitComet 17021 TCP
"17021:UDP"= 17021:UDP:BitComet 17021 UDP
"13735:TCP"= 13735:TCP:BitComet 13735 TCP
"13735:UDP"= 13735:UDP:BitComet 13735 UDP
"15354:TCP"= 15354:TCP:BitComet 15354 TCP
"15354:UDP"= 15354:UDP:BitComet 15354 UDP
"8584:TCP"= 8584:TCP:BitComet 8584 TCP
"8584:UDP"= 8584:UDP:BitComet 8584 UDP
"12358:TCP"= 12358:TCP:BitComet 12358 TCP
"12358:UDP"= 12358:UDP:BitComet 12358 UDP
"19702:TCP"= 19702:TCP:BitComet 19702 TCP
"19702:UDP"= 19702:UDP:BitComet 19702 UDP
"9020:TCP"= 9020:TCP:BitComet 9020 TCP
"9020:UDP"= 9020:UDP:BitComet 9020 UDP
"12392:TCP"= 12392:TCP:BitComet 12392 TCP
"12392:UDP"= 12392:UDP:BitComet 12392 UDP
"20436:TCP"= 20436:TCP:BitComet 20436 TCP
"20436:UDP"= 20436:UDP:BitComet 20436 UDP
"9309:TCP"= 9309:TCP:BitComet 9309 TCP
"9309:UDP"= 9309:UDP:BitComet 9309 UDP
"8740:TCP"= 8740:TCP:BitComet 8740 TCP
"8740:UDP"= 8740:UDP:BitComet 8740 UDP
"12625:TCP"= 12625:TCP:BitComet 12625 TCP
"12625:UDP"= 12625:UDP:BitComet 12625 UDP
"16825:TCP"= 16825:TCP:BitComet 16825 TCP
"16825:UDP"= 16825:UDP:BitComet 16825 UDP
"17348:TCP"= 17348:TCP:BitComet 17348 TCP
"17348:UDP"= 17348:UDP:BitComet 17348 UDP
"9436:TCP"= 9436:TCP:BitComet 9436 TCP
"9436:UDP"= 9436:UDP:BitComet 9436 UDP
"24773:TCP"= 24773:TCP:BitComet 24773 TCP
"24773:UDP"= 24773:UDP:BitComet 24773 UDP
"7597:TCP"= 7597:TCP:BitComet 7597 TCP
"7597:UDP"= 7597:UDP:BitComet 7597 UDP
"25564:TCP"= 25564:TCP:BitComet 25564 TCP
"25564:UDP"= 25564:UDP:BitComet 25564 UDP
"7239:TCP"= 7239:TCP:BitComet 7239 TCP
"7239:UDP"= 7239:UDP:BitComet 7239 UDP
"7795:TCP"= 7795:TCP:BitComet 7795 TCP
"7795:UDP"= 7795:UDP:BitComet 7795 UDP
"13244:TCP"= 13244:TCP:BitComet 13244 TCP
"13244:UDP"= 13244:UDP:BitComet 13244 UDP
"15255:TCP"= 15255:TCP:BitComet 15255 TCP
"15255:UDP"= 15255:UDP:BitComet 15255 UDP
"19736:TCP"= 19736:TCP:BitComet 19736 TCP
"19736:UDP"= 19736:UDP:BitComet 19736 UDP
"19824:TCP"= 19824:TCP:BitComet 19824 TCP
"19824:UDP"= 19824:UDP:BitComet 19824 UDP
"21331:TCP"= 21331:TCP:BitComet 21331 TCP
"21331:UDP"= 21331:UDP:BitComet 21331 UDP
"21226:TCP"= 21226:TCP:BitComet 21226 TCP
"21226:UDP"= 21226:UDP:BitComet 21226 UDP
"24798:TCP"= 24798:TCP:BitComet 24798 TCP
"24798:UDP"= 24798:UDP:BitComet 24798 UDP
"17125:TCP"= 17125:TCP:BitComet 17125 TCP
"17125:UDP"= 17125:UDP:BitComet 17125 UDP
"7722:TCP"= 7722:TCP:BitComet 7722 TCP
"7722:UDP"= 7722:UDP:BitComet 7722 UDP
"22628:TCP"= 22628:TCP:BitComet 22628 TCP
"22628:UDP"= 22628:UDP:BitComet 22628 UDP
"10803:TCP"= 10803:TCP:BitComet 10803 TCP
"10803:UDP"= 10803:UDP:BitComet 10803 UDP
"11296:TCP"= 11296:TCP:BitComet 11296 TCP
"11296:UDP"= 11296:UDP:BitComet 11296 UDP
"27049:TCP"= 27049:TCP:BitComet 27049 TCP
"27049:UDP"= 27049:UDP:BitComet 27049 UDP
"17662:TCP"= 17662:TCP:BitComet 17662 TCP
"17662:UDP"= 17662:UDP:BitComet 17662 UDP
"27091:TCP"= 27091:TCP:BitComet 27091 TCP
"27091:UDP"= 27091:UDP:BitComet 27091 UDP
"12760:TCP"= 12760:TCP:BitComet 12760 TCP
"12760:UDP"= 12760:UDP:BitComet 12760 UDP
"7835:TCP"= 7835:TCP:BitComet 7835 TCP
"7835:UDP"= 7835:UDP:BitComet 7835 UDP
"24836:TCP"= 24836:TCP:BitComet 24836 TCP
"24836:UDP"= 24836:UDP:BitComet 24836 UDP
"26439:TCP"= 26439:TCP:BitComet 26439 TCP
"26439:UDP"= 26439:UDP:BitComet 26439 UDP
"20042:TCP"= 20042:TCP:BitComet 20042 TCP
"20042:UDP"= 20042:UDP:BitComet 20042 UDP
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [25/01/2009 16:22 64160]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15/01/2009 17:17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15/01/2009 17:17 55024]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [26/01/2008 00:54 747912]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [16/11/2008 04:36 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [19/04/2009 17:08 101936]
S0 ati2bexx;ati2bexx;c:\windows\system32\Drivers\ati2bexx.sys --> c:\windows\system32\Drivers\ati2bexx.sys [?]
S0 ati3bfxx;ati3bfxx;c:\windows\system32\Drivers\ati3bfxx.sys --> c:\windows\system32\Drivers\ati3bfxx.sys [?]
S0 ati3gjxx;ati3gjxx;c:\windows\system32\Drivers\ati3gjxx.sys --> c:\windows\system32\Drivers\ati3gjxx.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 22:34 951632]
S3 jswmidin;jswmidin;\??\c:\docume~1\David\LOCALS~1\Temp\jswmidin.sys --> c:\docume~1\David\LOCALS~1\Temp\jswmidin.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15/01/2009 17:17 7408]
S3 WebSTARNdis;WebSTAR DPX USB Cable Modem Adapter;c:\windows\system32\drivers\WebSTAR.sys [16/01/2008 10:01 15417]
S3 WebSTARXP;Scientific Atlanta WebSTAR 100 & 200 series Cable Modem;c:\windows\system32\drivers\SACMXP1.sys [20/11/2003 16:01 14848]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-06-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 15:22]
2009-06-12 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - David.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2006-09-07 05:38]
.
- - - - ORPHANS REMOVED - - - -
BHO-{500BCA15-57A7-4eaf-8143-8C619470B13D} - c:\windows\system32\msxml71.dll
HKLM-Run-ISTray - c:\program files\Spyware Doctor\pctsTray.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.animenewsnetwork.com/
uInternet Settings,ProxyOverride = 127.0.0.1;<local>
IE: &Search - ?p=ZUman000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-13 18:19
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-496444892-2130754668-317057550-1006\Software\SecuROM\License information*]
"datasecu"=hex:7d,bc,a3,74,30,ba,20,9e,7f,8c,f6,d8,f4,39,90,15,bb,c4,5b,5d,b5,
80,c5,5b,56,0a,7c,38,72,b7,ec,2f,4c,a0,00,43,ef,57,08,14,e1,4a,d9,ec,87,e0,\
"rkeysecu"=hex:38,51,e7,b4,0f,6b,fc,8e,7a,7e,08,de,6b,46,23,6e
[HKEY_LOCAL_MACHINE\software\Microsoft\DirectPlay\Applications]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\DirectPlay\Applications\FTM]
@DACL=(02 0000)
"CurrentDirectory"="c:\\Ross\\Fallout Tactics"
"Path"="c:\\Ross\\Fallout Tactics"
"File"="BOS.exe"
"Guid"="{BC3A2ACD-FB46-4c6b-8B5C-CD193C9805CF}"
[HKEY_LOCAL_MACHINE\software\Microsoft\DirectPlay8\Applications]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(572)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(2092)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE
c:\program files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe
c:\apps\Powercinema\Kernel\TV\CLSched.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\apps\HIDSERVICE\HidService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\program files\Java\jre6\bin\jucheck.exe
c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe
.
**************************************************************************
.
Completion time: 2009-06-13 18:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-13 17:29
Pre-Run: 41,826,381,824 bytes free
Post-Run: 41,830,490,112 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
479 --- E O F --- 2009-01-15 03:12