Here are the logs
ComboFix 09-02-15.01 - Chris 2009-02-19 12:32:44.4 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1758 [GMT -8:00]
Running from: c:\documents and settings\Chris\Desktop\ComboFix.exe
AV: Trend Micro PC-cillin Internet Security 2006 *On-access scanning disabled* (Outdated)
FW: Trend Micro PC-cillin Internet Security (Firewall) *disabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Chris\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\Install.txt
c:\windows\system32\config\systemprofile\reader_s.exe
c:\windows\system32\drivers\ntndis.sys
c:\windows\system32\drivers\str.sys
c:\windows\system32\inf\rundll33.exe
c:\windows\system32\Install.txt
c:\windows\system32\w.exe
c:\windows\system32\xcchit32.ini
c:\windows\xccwinsys.ini
c:\windows\system32\userinit.exe . . . is infected!!
c:\windows\system32\svchost.exe . . . is infected!!
c:\windows\system32\spoolsv.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AFISICX
-------\Legacy_DEFAULTLIB
-------\Legacy_MABIDWE
-------\Legacy_NOYTCYR
-------\Legacy_ROYTCTM
-------\Legacy_SOXPECA
-------\Legacy_TDYDOWKC
-------\Legacy_WSLDOEKD
-------\Service_defaultlib
-------\Service_Passthru
((((((((((((((((((((((((( Files Created from 2009-01-19 to 2009-02-19 )))))))))))))))))))))))))))))))
.
2009-02-18 12:56 . 2009-02-18 12:56 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-18 12:56 . 2009-02-18 12:56 <DIR> d-------- c:\documents and settings\Chris\Application Data\Malwarebytes
2009-02-18 12:56 . 2009-02-18 12:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-18 12:56 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-18 12:56 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-18 12:55 . 2009-02-18 12:55 163,268 --a------ c:\windows\system32\19.tmp
2009-02-18 12:55 . 2009-02-18 12:55 2,048 --a------ c:\windows\system32\16.tmp
2009-02-18 12:55 . 2009-02-18 12:55 168 --a------ c:\windows\system32\10.tmp
2009-02-18 12:43 . 2009-02-18 12:45 163,268 --a------ c:\windows\system32\17.tmp
2009-02-18 12:43 . 2009-02-18 12:43 2,048 --a------ c:\windows\system32\14.tmp
2009-02-17 14:31 . 2009-02-17 14:38 <DIR> d-------- C:\CombFxx
2009-02-17 14:29 . 2009-02-17 14:31 159,613 --a------ c:\windows\system32\13.tmp
2009-02-17 14:29 . 2009-02-17 14:29 31,744 --ah----- c:\documents and settings\Chris\kfurfg.exe
2009-02-17 14:16 . 2009-02-17 14:16 244 --ah----- C:\sqmnoopt19.sqm
2009-02-17 14:16 . 2009-02-17 14:16 232 --ah----- C:\sqmdata19.sqm
2009-02-17 14:14 . 2009-02-17 14:14 25,601 --a------ c:\windows\system32\12.tmp
2009-02-17 14:06 . 2009-02-17 14:06 244 --ah----- C:\sqmnoopt18.sqm
2009-02-17 14:06 . 2009-02-17 14:06 232 --ah----- C:\sqmdata18.sqm
2009-02-17 14:05 . 2009-02-17 14:05 244 --ah----- C:\sqmnoopt17.sqm
2009-02-17 14:05 . 2009-02-17 14:05 232 --ah----- C:\sqmdata17.sqm
2009-02-17 14:04 . 2009-02-17 14:04 31,744 --ah----- c:\documents and settings\Chris\hbxha.exe
2009-02-17 12:17 . 2009-02-17 12:17 206 --a------ c:\windows\system32\MRT.INI
2009-02-17 10:41 . 2009-02-17 10:41 24,577 --a------ c:\windows\system32\86.tmp
2009-02-17 10:41 . 2009-02-17 10:41 244 --ah----- C:\sqmnoopt16.sqm
2009-02-17 10:41 . 2009-02-17 10:41 232 --ah----- C:\sqmdata16.sqm
2009-02-17 10:40 . 2009-02-17 10:40 244 --ah----- C:\sqmnoopt15.sqm
2009-02-17 10:40 . 2009-02-17 10:40 244 --ah----- C:\sqmnoopt14.sqm
2009-02-17 10:40 . 2009-02-17 10:40 232 --ah----- C:\sqmdata15.sqm
2009-02-17 10:40 . 2009-02-17 10:40 232 --ah----- C:\sqmdata14.sqm
2009-02-17 10:39 . 2009-02-17 10:39 244 --ah----- C:\sqmnoopt13.sqm
2009-02-17 10:39 . 2009-02-17 10:39 232 --ah----- C:\sqmdata13.sqm
2009-02-17 10:38 . 2009-02-17 10:41 163,748 --a------ c:\windows\system32\11.tmp
2009-02-17 10:38 . 2009-02-17 10:38 77,824 --a------ c:\windows\system32\u101795332.dll
2009-02-17 10:38 . 2009-02-17 10:38 31,744 --ah----- c:\documents and settings\Chris\tka.exe
2009-02-17 01:44 . 2009-02-17 10:34 130 --a------ c:\windows\adobe.bat
2009-02-17 01:44 . 2009-02-17 01:44 6 --a------ c:\windows\_id.dat
2009-02-17 01:41 . 2009-02-17 01:41 31,744 --ah----- c:\documents and settings\Chris\ccumuu.exe
2009-02-16 23:04 . 2009-02-16 23:04 33,920 --a------ c:\windows\system32\drivers\uoeiupgf.sys
2009-02-16 22:56 . 2009-02-18 12:45 137,408 --a------ c:\windows\system32\drivers\ethpllbq.sys
2009-02-16 22:55 . 2009-02-16 22:55 <DIR> d-------- c:\windows\$ntunistalls
2009-02-16 22:55 . 2009-02-16 22:55 52 --a------ c:\windows\system32\xcchit32.ini.ssyq
2009-02-16 22:54 . 2002-02-15 14:02 676,352 --a------ c:\windows\system32\rtl60.bpl
2009-02-16 22:54 . 2009-02-16 22:54 62,464 --a------ c:\windows\Eyexipadaxu.dll
2009-02-16 22:54 . 2009-02-16 22:54 44,032 --a------ c:\windows\system32\grcrt2.exe
2009-02-16 22:53 . 2009-02-17 14:29 67,072 ---h----- c:\windows\system32\secupdat.dat
2009-02-16 22:53 . 2009-02-17 14:29 53,248 --a------ c:\windows\system32\drivers\ndisio.sys
2009-02-16 22:53 . 2009-02-16 22:53 31,744 --ah----- c:\documents and settings\Chris\nldhj.exe
2009-02-14 10:34 . 2009-02-14 10:34 182,656 --a--c--- c:\windows\system32\dllcache\ndis.sys
2009-02-14 02:10 . 2009-02-14 02:10 <DIR> d-------- C:\rsit
2009-02-09 00:22 . 2009-02-19 12:34 <DIR> d-------- c:\windows\system32\inf
2009-01-28 22:36 . 2009-01-28 22:36 <DIR> d-------- C:\gnuplot
2009-01-24 15:17 . 2009-01-24 15:17 244 --ah----- C:\sqmnoopt12.sqm
2009-01-24 15:17 . 2009-01-24 15:17 232 --ah----- C:\sqmdata12.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-17 22:14 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-17 22:13 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-16 19:53 --------- d-----w c:\program files\SnapStream Media
2009-02-16 19:53 --------- d-----w c:\documents and settings\All Users\Application Data\SnapStream
2009-02-16 18:29 --------- d-----w c:\program files\Common Files\Adobe
2009-02-15 20:19 --------- d-----w c:\program files\QSuite
2009-02-14 18:48 --------- d-----w c:\program files\Java
2009-02-14 18:34 182,656 ----a-w c:\windows\system32\drivers\ndis.sys
2009-01-14 20:58 --------- d-----w c:\program files\MixMeister Fusion + Video
2009-01-11 05:32 --------- d-----w c:\documents and settings\Chris\Application Data\MixMeister Technology
2008-12-31 01:37 --------- d-----w c:\documents and settings\All Users\Application Data\Minnetonka Audio Software
2008-12-28 23:25 --------- d-----w c:\documents and settings\Chris\Application Data\Apple Computer
2004-09-10 21:40 92,160 ----a-w c:\program files\DECCHECK.exe
2004-09-10 21:40 5,970 ----a-w c:\program files\eula.txt
2008-10-06 16:57 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-10-06 16:57 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-10-06 16:57 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-10-06 16:57 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-10-06 16:57 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
------- Sigcheck -------
2004-08-04 04:00 31232 67569ebfaf170f559143d4434e2056ee c:\windows\$NtServicePackUninstall$\svchost.exe
2008-04-13 16:12 31744 e7062f33567f821d9e7ef6ff75e12694 c:\windows\ServicePackFiles\i386\svchost.exe
2009-01-22 22:56 31232 eb015b8f368f08ea457000a19175bee4 c:\windows\system32\svchost.exe
2009-01-22 22:56 31232 c7a2f067e4455df518241a532a56c16d c:\windows\system32\dllcache\svchost.exe
2004-08-04 04:00 182912 1df7f42665c94b825322fae71721130d c:\windows\$NtServicePackUninstall$\ndis.sys
2008-04-13 11:20 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2009-02-14 10:34 212608 1df7f42665c94b825322fae71721130d c:\windows\system32\dllcache\ndis.sys
2009-02-14 10:34 212608 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys
2008-04-13 16:12 1050624 a70fd46df39fc22b3db23e55b4fb520c c:\windows\explorer.exe
2007-06-13 03:26 1050112 62088503ce726540fd2b65eef9261b23 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 02:23 1050112 575ab078a76fc433e6b1f79269b09190 c:\windows\$NtServicePackUninstall$\explorer.exe
2004-08-04 04:00 1049088 c6affd4a895a674719ddd3fb2bc40da7 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-13 16:12 1050624 8c08a5235fc41026da77fa8bc60d2907 c:\windows\ServicePackFiles\i386\explorer.exe
2004-08-04 04:00 32256 b9d5ef452ce5b5ca09fdaa782c2ad5bc c:\windows\$NtServicePackUninstall$\ctfmon.exe
2008-04-13 16:12 32256 11cde4a9c00d81d9390caeafe0193f89 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-13 16:12 32256 ba567d2aad8ed2aae7183702d96650b6 c:\windows\system32\ctfmon.exe
2005-06-10 16:17 74752 bb33ba137547b468c1f6e253b8cff829 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 15:53 74752 346c592ebdb24f1dfe45987c110b20f3 c:\windows\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 04:00 74752 aead5cc82bacdd5af8838dcdaea7811c c:\windows\$NtUninstallKB896423$\spoolsv.exe
2008-04-13 16:12 74752 53b1c475dbb1dfd3157355607cfd42e6 c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-13 16:12 74752 05c5ed1c4f67a4df9fbac916bea9f26c c:\windows\system32\spoolsv.exe
2004-08-04 04:00 41472 712f66b287319fb3d0f9dc76cc5a793c c:\windows\$NtServicePackUninstall$\userinit.exe
2008-04-13 16:12 43008 7da09362dc61d725ed47002994d9a291 c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-13 16:12 43008 9834e0cdeb23ae248fd546c8ac4782e7 c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-02-15_12.27.06.64 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-05-10 23:51:10 75,776 ----a-w c:\windows\$hf_mig$\KB896428\SP2QFE\telnet.exe
+ 2005-05-10 23:51:10 92,672 ----a-w c:\windows\$hf_mig$\KB896428\SP2QFE\telnet.exe
- 2007-12-06 08:34:45 625,664 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
+ 2007-12-06 08:34:45 643,072 ----a-w c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
- 2008-10-16 12:46:08 70,656 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ie4uinit.exe
+ 2008-10-16 12:46:08 87,552 ----a-w c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\ie4uinit.exe
- 2004-08-04 12:00:00 19,968 -c----w c:\windows\$NtServicePackUninstall$\ssbezier.scr
+ 2004-08-04 12:00:00 36,864 -c----w c:\windows\$NtServicePackUninstall$\ssbezier.scr
- 2004-08-04 12:00:00 214,528 -c----w c:\windows\$NtServicePackUninstall$\wordpad.exe
+ 2004-08-04 12:00:00 231,936 -c----w c:\windows\$NtServicePackUninstall$\wordpad.exe
- 2007-06-05 19:41:16 573,503 ----a-w c:\windows\gmer.dll
+ 2009-02-19 05:18:14 884,736 ----a-w c:\windows\gmer.dll
- 2008-08-25 08:38:00 13,824 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-25 08:38:00 30,720 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2007-12-12 23:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
- 2008-04-14 00:12:12 14,336 ------w c:\windows\ServicePackFiles\i386\auditusr.exe
+ 2008-04-14 00:12:12 31,232 ------w c:\windows\ServicePackFiles\i386\auditusr.exe
- 2008-04-14 00:12:15 39,936 ------w c:\windows\ServicePackFiles\i386\cmmon32.exe
+ 2008-04-14 00:12:15 56,832 ------w c:\windows\ServicePackFiles\i386\cmmon32.exe
- 2008-04-13 18:43:32 9,728 ------w c:\windows\ServicePackFiles\i386\comsdupd.exe
+ 2008-04-13 18:43:32 26,624 ------w c:\windows\ServicePackFiles\i386\comsdupd.exe
- 2008-04-14 00:12:34 18,944 ------w c:\windows\ServicePackFiles\i386\secedit.exe
+ 2008-04-14 00:12:34 35,840 ------w c:\windows\ServicePackFiles\i386\secedit.exe
- 2008-04-14 00:12:40 196,608 ------w c:\windows\ServicePackFiles\i386\wmiadap.exe
+ 2008-04-14 00:12:40 214,016 ------w c:\windows\ServicePackFiles\i386\wmiadap.exe
- 2000-08-31 16:00:00 179,200 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 16:00:00 179,712 ----a-w c:\windows\SWREG.exe
- 2008-04-14 00:12:14 56,832 ----a-w c:\windows\system32\cipher.exe
+ 2008-04-14 00:12:14 73,728 ----a-w c:\windows\system32\cipher.exe
+ 2009-02-18 20:54:56 32,768 --sha-w c:\windows\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\UserData\index.dat
- 2009-02-15 20:08:58 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-19 20:45:58 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-15 20:08:58 49,152 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-19 20:45:58 98,304 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-19 05:38:27 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009021820090219\index.dat
- 2009-02-15 20:08:58 49,152 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-19 20:45:58 278,528 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-08-04 12:00:00 262,200 -c--a-w c:\windows\system32\dllcache\imjputy.exe
+ 2004-08-04 12:00:00 282,680 -c--a-w c:\windows\system32\dllcache\imjputy.exe
- 2004-09-23 02:45:46 991,232 -c--a-w c:\windows\system32\dllcache\migrate.exe
+ 2004-09-23 02:45:46 1,011,712 -c--a-w c:\windows\system32\dllcache\migrate.exe
- 2004-08-04 12:00:00 35,328 -c--a-w c:\windows\system32\dllcache\notiflag.exe
+ 2004-08-04 12:00:00 52,224 -c--a-w c:\windows\system32\dllcache\notiflag.exe
- 2007-06-05 19:41:16 69,905 ----a-w c:\windows\system32\drivers\gmer.sys
+ 2009-02-19 05:18:14 85,969 ----a-w c:\windows\system32\drivers\gmer.sys
- 2008-04-14 00:12:24 59,392 ----a-w c:\windows\system32\logman.exe
+ 2008-04-14 00:12:24 76,288 ----a-w c:\windows\system32\logman.exe
- 2009-01-10 01:35:28 20,853,704 ----a-w c:\windows\system32\MRT.exe
+ 2009-02-12 04:56:17 21,244,872 ----a-w c:\windows\system32\MRT.exe
- 2008-11-14 09:40:23 71,512 ----a-w c:\windows\system32\perfc009.dat
+ 2009-02-17 05:17:37 71,512 ----a-w c:\windows\system32\perfc009.dat
- 2008-11-14 09:40:23 441,954 ----a-w c:\windows\system32\perfh009.dat
+ 2009-02-17 05:17:37 441,954 ----a-w c:\windows\system32\perfh009.dat
+ 2004-01-23 00:31:54 10,761 ----a-w c:\windows\system32\ReinstallBackups\
0022\DriverFiles\x10uif.sys
- 2007-11-30 12:39:22 17,272 ----a-w c:\windows\system32\spmsg.dll
+ 2008-07-09 07:38:24 17,272 ------w c:\windows\system32\spmsg.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 32256]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2008-01-22 152872]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 221696]
"FireflyMini"="c:\program files\SnapStream Media\Firefly Mini\FireflyMini.exe" [2007-01-12 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2005-12-04 437008]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 2006\pccguide.exe" [2005-09-28 917566]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 151552]
"pdfFactory Pro Dispatcher v2"="c:\windows\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [2006-01-12 516096]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 434176]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2008-05-28 570664]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-04 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"FireflyMini"="c:\program files\SnapStream Media\Firefly Mini\FireflyMini.exe" [2007-01-12 155648]
"Firefly"="c:\program files\SnapStream Media\Firefly\Firefly.exe" [2006-06-05 200704]
"SoundMan"="SOUNDMAN.EXE" [2005-06-20 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"reader_s"="c:\documents and settings\Chris\reader_s.exe" [BU]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\a.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\matrix31290.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpa.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpb.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\~tmpc.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uoeiupgf.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRegistrationService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVNetworkService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVNotifierService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRecordingEngine.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVD3DShell.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\SetupWizard.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 AmdAcpi;AmdAcpi Bus Filter Driver;c:\windows\system32\drivers\amdacpi.sys [2006-01-13 13824]
R0 uoeiupgf;uoeiupgf;c:\windows\system32\drivers\uoeiupgf.sys [2009-02-16 33920]
R1 amdtools;AMD Special Tools Driver;c:\windows\system32\drivers\amdtools.sys [2006-01-13 21120]
S0 scybpr;scybpr;c:\windows\system32\drivers\trbg.sys --> c:\windows\system32\drivers\trbg.sys [?]
S1 ethpllbq;ethpllbq;c:\windows\system32\drivers\ethpllbq.sys [2009-02-16 137408]
S1 ewido security suite driver;ewido security suite driver;c:\program files\ewido anti-malware\guard.sys [2005-12-30 3072]
S2 acnkm;acnkm;\??\c:\windows\system32\drivers\dcqkplt.sys --> c:\windows\system32\drivers\dcqkplt.sys [?]
S2 RTWTKRNL;Real-Time Windows Target;c:\windows\system32\drivers\RTWTKRNL.sys [2008-02-11 27200]
S2 Tmfilter;Tmfilter;c:\windows\system32\drivers\tmxpflt.sys [2005-09-26 205328]
S2 Tmntsrv;Trend Micro Real-time Service;c:\progra~1\TRENDM~1\INTERN~1\Tmntsrv.exe [2005-09-28 360517]
S2 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2005-09-12 651325]
S2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2005-09-26 36368]
S2 tmproxy;Trend Micro Proxy Service;c:\progra~1\TRENDM~1\INTERN~1\tmproxy.exe [2005-09-12 307268]
S3 atirage;atirage;c:\windows\system32\drivers\atiragem.sys [2006-01-12 70528]
S3 MPCSYS;MPCSYS; [x]
S3 WLAN(WLAN);XPC 802.11b/g Wireless Kit Driver(WLAN);c:\windows\system32\drivers\ZD1211U.sys [2006-01-12 278016]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{V2FR455T-5K8M-BRW1-NFF4-I3DY73S22YA5}]
"c:\program files\Internet Explorer\iexplore.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-02-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DeskTopSrv - c:\windows\system32\grcrt.exe
HKU-Default-Run-cogad - c:\documents and settings\Chris\Application Data\cogad\cogad.exe
HKLM-Explorer_Run-xccinit - c:\windows\system32\inf\rundll33.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\z2fqqhdr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-19 12:46:49
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:83,70,db,6f,f3,01,18,bc,8a,2c,26,51,2d,77,68,01,45,df,69,a2,32,
04,4f,4d,2e,7b,c9,65,6b,2f,a9,6c,42,48,23,e3,82,6e,4e,c2,89,10,ea,8f,ec,03,\
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:83,70,db,6f,f3,01,18,bc,8a,2c,26,51,2d,77,68,01,45,df,69,a2,32,
04,4f,4d,2e,7b,c9,65,6b,2f,a9,6c,42,48,23,e3,82,6e,4e,c2,89,10,ea,8f,ec,03,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(232)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-02-19 12:52:33 - machine was rebooted [Chris]
ComboFix-quarantined-files.txt 2009-02-19 20:52:31
ComboFix2.txt 2009-02-16 18:51:52
ComboFix3.txt 2009-02-15 20:27:49
Pre-Run: 32,262,320,128 bytes free
Post-Run: 32,266,375,168 bytes free
Current=1 Default=1 Failed=2 LastKnownGood=3 Sets=1,2,3,4
334 --- E O F --- 2009-02-17 20:17:16
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:34 PM, on 2/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Chris\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\explorer.exe,
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FireflyMini] "C:\Program Files\SnapStream Media\Firefly Mini\FireflyMini.exe"
O4 - HKLM\..\Run: [Firefly] C:\Program Files\SnapStream Media\Firefly\Firefly.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [FireflyMini] "C:\Program Files\SnapStream Media\Firefly Mini\FireflyMini.exe"
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Chris\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [reader_s] C:\Documents and Settings\Chris\reader_s.exe (User 'Default user')
O4 - Global Startup: BDARemote.lnk = ?
O4 - Global Startup: Beyond TV.lnk = C:\Program Files\SnapStream Media\Beyond TV\BTVAgent2.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) -
http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137127858093
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} -
http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB701\webserver\bin\win32\matlabserver.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\SNAPST~1\Common\x10nets.exe
--
End of file - 7951 bytes