Hello. Sorry about the delay, I had to go to Cleveland yesterday…
My computer is slower than ever now that Combo-Fix got involved. I did the following this time:
I downloaded combofix from link 1 and renamed it to Combo-Fix as instructed. I double clicked on "Combo-Fix.exe" and followed the prompts and when the status bar finished a blue MSDOS window popped up and just hung for a while, then a pop up appeared asking me if I wanted to update to a newer version, I clicked on ok to download newer version then Combo-Fix began to run by backing up registry, THEN created system restore point, THEN a pop up window appeared = This machine does not have microsoft windows recovery software, without it CF will not attempt to fix some serious infections. I Clicked YES, the MSDOS Window read connecting… Then I clicked YES on end user agreement and YES on license agreement. CF began running again = downloading MS recovery console = 100% downloaded (the ##### 100% message just hung and hung and hung…), THEN I received a congratulations message for MS recovery console. CF automatically rebooted and ran, I clicked YES to scan for Malware, then the Autoscan took about 15 minutes then generated the following report:
COMBO FIX LOG IS PASTED BELOW AND ATTACHED AS A FILE (word wrap unchecked):
ComboFix 09-06-16.05 - kelly 06/17/2009 11:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.613 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\
0609 Virus Files\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\NetworkService\Application Data\twain_32
c:\windows\system32\Cache
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\documents and settings\NetworkService\Application Data\twain_32\user.ds
c:\windows\IE4 Error Log.txt
c:\windows\system32\abbnp.dll
c:\windows\system32\bszip.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\Ijl11.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
Infected copy of c:\windows\system32\ws2_32.dll was found and disinfected
Restored copy from - c:\system volume information\_restore{F540920D-71F2-4546-893B-35755F67B56E}\RP828\A0403053.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_IPRIP
——-\Service_Iprip
((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))
.
2009-06-17 14:45 . 2009-06-17 14:46 ——– dc—-w- C:\32788R22FWJFW
2009-06-17 14:01 . 2009-06-14 13:21 89104 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\NAVENG.SYS
2009-06-17 14:01 . 2009-06-14 13:21 876144 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\NAVEX15.SYS
2009-06-17 14:01 . 2009-06-14 13:21 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\NAVENG32.DLL
2009-06-17 14:01 . 2009-06-14 13:21 1181040 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\NAVEX32A.DLL
2009-06-17 14:00 . 2009-06-14 13:21 101936 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\ERASER.SYS
2009-06-17 14:00 . 2009-06-14 13:21 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\EECTRL.SYS
2009-06-17 14:00 . 2009-06-14 13:20 259368 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\ECMSVR32.DLL
2009-06-17 14:00 . 2009-06-14 13:20 2414128 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090616.052\CCERASER.DLL
2009-06-15 18:54 . 2009-06-15 18:54 ——– dc—-w- C:\_OTS
2009-06-15 13:26 . 2009-06-15 13:26 ——– dc—-w- C:\N360_BACKUP
2009-06-14 18:20 . 2009-06-14 13:21 276344 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys
2009-06-14 18:20 . 2009-06-14 13:20 447864 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSxpx86.dll
2009-06-14 18:20 . 2009-03-16 20:03 533880 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\Scxpx86.dll
2009-06-14 18:20 . 2009-06-14 13:21 396848 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSviA64.sys
2009-06-14 18:20 . 2009-06-14 13:21 292912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSvix86.sys
2009-06-14 15:46 . 2009-06-14 15:46 ——– d—–w- c:\documents and settings\kelly\Local Settings\Application Data\Symantec
2009-06-14 13:22 . 2009-01-15 16:19 23848 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-14 13:22 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-14 13:22 . 2009-06-14 13:22 ——– d—–w- c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-14 13:20 . 2009-06-14 13:20 447864 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\idsxpx86.dll
2009-06-14 13:20 . 2009-06-14 13:20 259368 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090226.034\ECMSVR32.DLL
2009-06-14 13:20 . 2009-06-14 13:20 796016 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-06-14 13:20 . 2009-06-14 13:20 2414128 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090226.034\CCERASER.DLL
2009-06-14 11:44 . 2009-06-14 11:44 ——– d—–w- c:\documents and settings\kelly\Local Settings\Application Data\Apple Computer
2009-06-14 03:51 . 2009-06-14 03:51 ——– d—–w- c:\windows\system32\drivers\N360
2009-06-14 03:51 . 2009-06-14 16:01 ——– d—–w- c:\program files\Norton 360
2009-06-14 03:51 . 2009-06-14 03:51 ——– d—–w- c:\program files\Windows Sidebar
2009-06-14 02:27 . 2009-06-14 02:27 ——– d—–w- c:\documents and settings\kelly\Application Data\Malwarebytes
2009-06-14 02:27 . 2009-05-26 17:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 02:27 . 2009-06-15 21:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-14 02:27 . 2009-06-14 02:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-14 02:27 . 2009-05-26 17:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-14 02:12 . 2009-06-15 21:50 ——– d—–w- c:\program files\ERUNT
2009-06-14 02:05 . 2009-06-14 02:05 ——– d—–w- c:\program files\Trend Micro
2009-06-13 19:47 . 2009-06-13 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\PCSettings
2009-06-13 19:47 . 2009-06-13 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-06-13 19:46 . 2009-06-14 13:19 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-06-13 19:46 . 2009-06-13 19:46 ——– d—–w- c:\program files\NortonInstaller
2009-06-13 19:08 . 2009-06-13 19:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-12 23:57 . 2009-06-12 23:57 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-06-12 23:41 . 2009-06-12 23:41 ——– d—–w- c:\documents and settings\kelly\Application Data\Windows Desktop Search
2009-06-12 22:47 . 2009-06-12 22:50 ——– dc—-w- C:\433f51f4670db33e128b49cb
2009-06-12 21:18 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-12 21:18 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-12 21:13 . 2009-06-12 21:16 ——– dc-h–w- c:\windows\ie8
2009-06-10 22:54 . 2009-06-10 22:54 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-05-31 18:56 . 2009-05-31 18:56 ——– d—–w- c:\program files\Dopewars
2009-05-30 21:43 . 2009-05-30 21:43 ——– d—–w- c:\documents and settings\kelly\Local Settings\Application Data\Apple
2009-05-25 19:33 . 2009-05-25 19:37 ——– d—–w- c:\documents and settings\kelly\Application Data\Windows Live Writer
2009-05-25 19:33 . 2009-05-25 19:33 ——– d—–w- c:\documents and settings\kelly\Local Settings\Application Data\Windows Live Writer
2009-05-25 18:06 . 2009-06-14 15:30 ——– d—–w- c:\documents and settings\kelly\Tracing
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-17 15:21 . 2003-12-10 21:54 22 —-a-w- C:\qpmd8376.bin
2009-06-17 15:19 . 2007-05-26 01:24 24 —-a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000007-00001102-00000002-80221102}.dat
2009-06-17 15:19 . 2007-05-26 01:24 24 —-a-w- c:\windows\system32\DVCState-{00000002-00000000-00000007-00001102-00000002-80221102}.dat
2009-06-15 01:10 . 2003-05-31 16:10 ——– d—–w- c:\program files\Trillian
2009-06-14 03:51 . 2003-05-30 02:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-13 20:12 . 2008-07-24 03:32 ——– d—–w- c:\program files\Windows Desktop Search
2009-06-13 19:47 . 2003-05-30 02:56 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-13 19:08 . 2004-08-26 23:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-13 01:07 . 2008-07-27 01:23 ——– d—–w- c:\program files\Microsoft SQL Server
2009-06-12 23:47 . 2006-04-22 00:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-02 21:00 . 2009-06-02 21:00 44173 —-a-w- c:\documents and settings\All Users\Application Data\tmp20.tmp
2009-05-30 21:46 . 2003-06-01 08:27 ——– d—–w- c:\program files\QuickTime
2009-05-30 21:45 . 2007-06-15 05:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-24 17:25 . 2007-06-25 07:25 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-05-17 23:33 . 2004-12-19 02:42 ——– d—–w- c:\program files\Google
2009-05-13 09:21 . 2008-02-17 23:49 ——– d—–w- c:\program files\WinMX
2009-05-13 05:15 . 2004-02-06 22:05 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-11 03:12 . 2009-05-10 05:45 ——– d—–w- c:\program files\Digital Foci PhotoViewer 2.0
2009-05-11 03:12 . 2003-08-23 02:36 ——– d—–w- c:\program files\FinePixViewer
2009-05-11 03:12 . 2007-10-20 02:28 ——– d—–w- c:\program files\Windows Media Connect 2
2009-05-11 03:12 . 2003-06-15 20:25 ——– d—–w- c:\program files\Veo Digital Studio
2009-05-11 03:12 . 2009-04-05 12:11 ——– d—–w- c:\program files\PHP
2009-05-11 03:12 . 2003-05-31 22:32 ——– d—–w- c:\program files\Microsoft Image Composer
2009-05-10 08:53 . 2003-06-15 20:27 ——– d—–w- c:\program files\Common Files\Real
2009-05-07 15:32 . 2001-08-18 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-03 19:40 . 2007-07-10 13:42 78592 -c–a-w- c:\documents and settings\kelly\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-03 19:34 . 2009-05-03 19:28 ——– d—–w- c:\program files\Windows Live
2009-05-03 19:34 . 2009-05-03 19:34 ——– d—–w- c:\program files\Microsoft Sync Framework
2009-05-03 19:32 . 2008-08-05 00:14 ——– d—–w- c:\program files\Microsoft SQL Server Compact Edition
2009-05-03 19:29 . 2009-03-14 04:26 ——– d—–w- c:\program files\Microsoft
2009-05-03 19:29 . 2009-05-03 19:29 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-05-03 03:18 . 2007-07-19 06:21 ——– d—–w- c:\program files\Qualcomm
2009-05-03 03:18 . 2003-05-30 01:34 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-03 00:16 . 2008-06-30 18:41 ——– d—–w- c:\program files\Opera
2009-05-02 22:31 . 2006-05-08 00:06 ——– d—–w- c:\program files\Citrix
2009-05-02 00:08 . 2007-06-09 04:20 ——– d—–w- c:\program files\Common Files\HP
2009-04-29 04:55 . 2009-04-29 04:55 78336 ——w- c:\windows\system32\ieencode.dll
2009-04-24 14:59 . 2009-04-24 14:59 58702 -c–a-w- c:\documents and settings\All Users\Application Data\tmpA1.tmp
2009-04-22 21:21 . 2009-04-22 21:21 ——– d—–w- c:\program files\Common Files\SupportSoft
2009-04-17 15:26 . 2009-04-17 15:25 42014 -c–a-w- c:\documents and settings\All Users\Application Data\tmp25C.tmp
2009-04-17 12:26 . 2001-08-18 12:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-04-21 03:35 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-07 11:01 . 2005-12-12 17:39 95093 —-a-w- c:\program files\Common Files\Engines.lnl
2009-04-07 10:59 . 2009-04-07 10:59 1078 -c–a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{A84D0BEE-2422-4F50-9CC8-83B495A6370E}\_60322c3b.exe
2009-04-07 10:59 . 2009-04-07 10:59 1078 -c–a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{A84D0BEE-2422-4F50-9CC8-83B495A6370E}\_42307eb7.exe
2009-04-07 10:59 . 2009-04-07 10:59 1078 -c–a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{A84D0BEE-2422-4F50-9CC8-83B495A6370E}\_366b66c4.exe
2009-04-06 22:09 . 2009-04-06 22:09 212 —-a-w- c:\windows\ildasmfnt.bin
2001-08-18 12:00 . 2001-08-18 12:00 94784 -csh–w- c:\windows\twain.dll
2008-04-14 00:12 . 2001-08-18 12:00 50688 -csh–w- c:\windows\twain_32.dll
2008-12-24 09:11 . 2008-12-24 09:08 109 -csha-w- c:\windows\system32\14913480.dat
2008-04-14 00:12 . 2001-08-18 12:00 57344 -csha-w- c:\windows\system32\msvcirt.dll
2008-04-14 00:12 . 2003-05-30 03:38 413696 –sha-w- c:\windows\system32\msvcp60.dll
2008-04-14 00:12 . 2001-08-18 12:00 551936 –sh–w- c:\windows\system32\oleaut32.dll
2008-04-14 00:12 . 2001-08-18 12:00 84992 -csha-w- c:\windows\system32\olepro32.dll
2008-04-14 00:12 . 2001-08-18 12:00 11776 -csha-w- c:\windows\system32\regsvr32.exe
.
——- Sigcheck ——-
[-] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2006-01-13 17:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB893066$\tcpip.sys
[-] 2005-05-25 19:04 359808 88763A98A4C26C409741B4AA162720C9 c:\windows\$NtUninstallKB913446$\tcpip.sys
[-] 2006-01-13 02:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows\$NtUninstallKB917953$\tcpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Live Menu 3.3.lnk]
backup=c:\windows\pss\eFax Live Menu 3.3.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 3.3.lnk]
backup=c:\windows\pss\eFax Tray Menu 3.3.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax.com Tray Menu.lnk]
backup=c:\windows\pss\eFax.com Tray Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
backup=c:\windows\pss\Exif Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=c:\windows\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HPAiODevice(hp psc 700 series) - 1.lnk]
backup=c:\windows\pss\HPAiODevice(hp psc 700 series) - 1.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Instant Wireless Configuration Utility.lnk]
backup=c:\windows\pss\Instant Wireless Configuration Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Live Menu.lnk]
backup=c:\windows\pss\Live Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk.disabled
backup=c:\windows\pss\Microsoft Office.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^kelly^Start Menu^Programs^Startup^HotSync Manager.LNK]
path=c:\documents and settings\kelly\Start Menu\Programs\Startup\HotSync Manager.LNK
backup=c:\windows\pss\HotSync Manager.LNKStartup
[HKLM\~\startupfolder\C:^Documents and Settings^kelly^Start Menu^Programs^Startup^Palm Registration.lnk]
path=c:\documents and settings\kelly\Start Menu\Programs\Startup\Palm Registration.lnk
backup=c:\windows\pss\Palm Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^kelly^Start Menu^Programs^Startup^SpywareGuard.lnk]
path=c:\documents and settings\kelly\Start Menu\Programs\Startup\SpywareGuard.lnk
backup=c:\windows\pss\SpywareGuard.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^kelly^Start Menu^Programs^Startup^Starter.lnk]
path=c:\documents and settings\kelly\Start Menu\Programs\Startup\Starter.lnk
backup=c:\windows\pss\Starter.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Admanager Controller
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BullsEye Network
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Optimizer
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbb
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Si Meter
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebRebates0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Win Comm
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows AdTools
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE"
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinPatrol"=c:\program files\BillP Studios\WinPatrol\winpatrol.exe
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\
0300000.087\BHDrvx86.sys [6/14/2009 9:21 AM 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\
0300000.087\cchpx86.sys [6/14/2009 9:21 AM 482352]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090610.006\IDSXpx86.sys [6/14/2009 2:20 PM 276344]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [5/3/2009 3:34 PM 55152]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/14/2009 9:45 AM 101936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-17 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-23 04:43]
2009-06-16 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - kelly.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-04-25 03:19]
2009-06-17 c:\windows\Tasks\User_Feed_Synchronization-{7AC137BD-8B93-4F53-B158-681DD966BBF5}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NAV Agent - c:\progra~1\NORTON~1\navapw32.exe
ShellExecuteHooks-{56F9679E-7826-4C84-81F3-532071A8BCC5} - c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page =
https://secure-ausomxana.crmondemand.com/On…mp;reason=logon
uInternet Settings,ProxyOverride = 127.0.0.1
Trusted Zone: crmondemand.com\sso
DPF: cpcScanner - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {C77FB8C0-8B6D-440E-AC26-2BD39E97E8F2} - hxxp://speedtest.adelphia.net/customerdiag/speedtest/SPEEDTESTACTIVEX.CAB
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-17 11:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MsDepSvc]
"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"
–
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.0.0.135\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(4948)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
c:\cfusionmx\runtime\bin\jrunsvc.exe
c:\cfusionmx\db\slserver52\bin\swagent.exe
c:\cfusionmx\runtime\bin\jrun.exe
c:\cfusionmx\db\slserver52\bin\swstrtr.exe
c:\cfusionmx\db\slserver52\bin\swsoc.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Mail Enable\Bin\MELSC.exe
c:\program files\Mail Enable\Bin\MEMTA.exe
c:\program files\Mail Enable\Bin\MEPOC.exe
c:\program files\Mail Enable\Bin\MEPOPS.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\program files\Mail Enable\Bin\MESMTPC.exe
c:\windows\system32\msdtc.exe
c:\program files\Microsoft SQL Server\MSSQL.5\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\locator.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\snmp.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\mqsvc.exe
c:\program files\Norton 360\Engine\3.0.0.135\ccSvcHst.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-17 11:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-17 15:36
Pre-Run: 11,729,731,584 bytes free
Post-Run: 12,174,315,520 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
371