Yes, I did run ComboFix very recently, after the infection took hold.
Here's the log:
ComboFix 09-09-11.01 - William 12/09/2009 15:43.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1605 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\William\Desktop\CFScript.txt
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.
((((((((((((((((((((((((( Files Created from 2009-08-12 to 2009-09-12 )))))))))))))))))))))))))))))))
.
2009-09-12 07:04 . 2009-09-12 07:04 ——– d—–w- c:\documents and settings\William\Application Data\Malwarebytes
2009-09-12 07:03 . 2009-09-10 06:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-12 07:03 . 2009-09-12 07:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-12 07:03 . 2009-09-12 07:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-12 07:03 . 2009-09-10 06:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-12 05:42 . 2009-09-12 05:42 ——– d—–w- c:\documents and settings\Felicity\Local Settings\Application Data\Sophos
2009-09-11 10:19 . 2009-09-11 10:36 ——– d—–w- c:\program files\Savage 2 - A Tortured Soul
2009-09-09 10:24 . 2009-06-21 21:44 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-09-07 09:51 . 2009-09-07 09:51 ——– d—–w- c:\program files\7-Zip
2009-09-07 08:12 . 2009-09-07 09:01 ——– d—–w- c:\documents and settings\William\Application Data\BitTorrent
2009-09-05 08:17 . 2009-09-07 10:24 ——– d—–w- c:\documents and settings\William\Local Settings\Application Data\Gas Powered Games
2009-09-05 07:26 . 2009-09-05 08:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Media Center Programs
2009-09-05 05:42 . 2009-09-05 05:42 ——– d—–w- C:\found.000
2009-09-03 18:07 . 2009-09-03 18:07 41872 —-a-w- c:\windows\system32\xfcodec.dll
2009-08-22 15:14 . 2009-08-22 15:14 ——– d—–w- c:\program files\NCSoft
2009-08-22 15:12 . 2009-08-22 15:12 ——– d—–w- c:\documents and settings\William\Application Data\InstallShield
2009-08-22 04:37 . 2009-08-22 04:37 ——– d—–w- c:\program files\bman654
2009-08-21 11:44 . 2009-08-29 10:04 ——– d—–w- c:\program files\TQ Defiler.NET
2009-08-18 09:42 . 2009-08-18 09:42 19 —-a-w- c:\windows\popcinfo.dat
2009-08-17 14:18 . 2009-08-17 14:18 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-17 14:18 . 2009-08-17 14:18 ——– d—–w- c:\program files\MSBuild
2009-08-17 14:18 . 2009-08-17 14:18 ——– d—–w- c:\program files\Reference Assemblies
2009-08-17 14:17 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-17 14:17 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-17 14:17 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-17 14:17 . 2009-08-17 14:17 ——– d—–w- C:\083e85c5d1d6c2d67c
2009-08-17 14:17 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-17 14:17 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-17 14:17 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-17 14:17 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-15 09:46 . 2009-08-15 09:46 ——– d—–w- c:\documents and settings\William\Local Settings\Application Data\Iteral_Group_Ltd
2009-08-15 09:36 . 2009-08-15 09:36 ——– d—–w- c:\program files\Iteral
2009-08-15 03:31 . 2008-04-13 21:41 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2009-08-15 03:31 . 2008-04-13 21:41 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-08-15 03:31 . 2008-04-13 16:15 60032 -c–a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-08-15 03:31 . 2008-04-13 16:15 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-12 05:37 . 2009-06-21 05:36 ——– d—–w- c:\documents and settings\William\Application Data\Skype
2009-09-12 05:19 . 2009-06-13 09:30 ——– d—–w- c:\documents and settings\William\Application Data\Xfire
2009-09-12 04:57 . 2009-06-21 05:37 ——– d—–w- c:\documents and settings\William\Application Data\skypePM
2009-09-11 09:25 . 2009-06-20 07:47 ——– d—–w- c:\documents and settings\William\Application Data\Hamachi
2009-09-10 07:45 . 2009-06-13 09:30 ——– d—–w- c:\program files\Xfire
2009-09-09 14:40 . 2009-08-03 12:11 138520 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-09 14:40 . 2009-08-03 12:11 189640 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-09-05 07:47 . 2009-06-11 13:01 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-09-05 07:14 . 2009-06-14 07:56 ——– d—–w- c:\program files\THQ
2009-09-02 11:16 . 2009-06-13 08:02 ——– d—–w- c:\documents and settings\William\Application Data\Apple Computer
2009-08-24 01:20 . 2009-08-10 12:34 70032 —-a-w- c:\documents and settings\James\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-22 15:12 . 2009-06-17 14:52 ——– d—–w- c:\documents and settings\William\Application Data\GetRightToGo
2009-08-22 04:37 . 2009-06-13 09:18 70032 —-a-w- c:\documents and settings\William\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-16 10:37 . 2009-06-13 09:23 ——– d—–w- c:\program files\Windows Live
2009-08-11 10:51 . 2009-08-11 10:50 ——– d—–w- c:\program files\NCH Software
2009-08-11 10:50 . 2009-08-11 10:50 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Software
2009-08-09 09:54 . 2009-06-11 13:51 68840 —-a-w- c:\documents and settings\Graham\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 09:48 . 2009-08-09 09:48 ——– d—–w- c:\program files\iTunes
2009-08-09 09:48 . 2009-08-09 09:48 ——– d—–w- c:\program files\iPod
2009-08-09 09:48 . 2009-06-11 15:29 ——– d—–w- c:\program files\Common Files\Apple
2009-08-09 09:22 . 2009-08-09 09:22 ——– d—–w- c:\documents and settings\James\Application Data\Apple Computer
2009-08-05 09:01 . 2004-08-04 12:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 12:11 . 2009-08-03 12:11 139152 —-a-w- c:\documents and settings\William\Application Data\PnkBstrK.sys
2009-08-03 12:11 . 2009-08-03 12:11 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-08-03 12:11 . 2009-08-03 12:11 794408 —-a-w- c:\windows\system32\pbsvc.exe
2009-08-03 10:56 . 2009-06-14 05:15 ——– d—–w- c:\program files\EA GAMES
2009-08-02 05:37 . 2009-06-13 10:39 ——– d—–w- c:\documents and settings\William\Application Data\SPORE
2009-07-29 09:58 . 2009-07-29 09:58 ——– d—–w- c:\program files\Google
2009-07-17 19:01 . 2004-08-04 12:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-12 04:21 . 2004-08-04 12:00 233472 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 12:31 . 2009-06-11 13:53 130104 —-a-w- c:\windows\system32\sdccoinstaller.dll
2009-07-03 17:09 . 2004-08-04 12:00 915456 ——w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-04 12:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 12:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 12:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 12:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 12:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 12:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 12:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-21 05:37 . 2009-06-21 05:37 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-06-20 07:47 . 2009-06-20 07:47 25280 —-a-w- c:\windows\system32\drivers\hamachi.sys
2009-06-16 14:36 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-09-19 455968]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GBB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-07-12 356352]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-30 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]
"TWCU"="c:\program files\TP-LINK\TWCU\TWCU.exe" [2006-03-29 364544]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-29 196608]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-04-30 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\William\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2009-9-4 3111824]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2009-6-11 245760]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Documents and Settings\\William\\My Documents\\Game Stuff From Desktop\\Defcon\\defcon.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"c:\\Documents and Settings\\William\\My Documents\\Game Stuff From Desktop\\BF2\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Documents and Settings\\William\\My Documents\\Game Stuff From Desktop\\BF2\\BATTLEFIELD 2 64 PLAYER\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Documents and Settings\\William\\My Documents\\Game Stuff From Desktop\\Halo\\halo.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander - Forged Alliance\\bin\\ForgedAlliance.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"c:\\Program Files\\Savage 2 - A Tortured Soul\\savage2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [11/06/2009 9:52 PM 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [11/06/2009 9:52 PM 38528]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [7/05/2009 4:12 PM 80936]
S2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [21/08/2008 1:04 PM 98304]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [11/06/2009 9:52 PM 14976]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-07-16 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 09:04]
2009-09-12 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 09:04]
2009-09-11 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 04:25]
2009-08-29 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 04:25]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.troner.net/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.23.0.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-12 15:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-746137067-1214440339-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c4,38,fb,64,7e,ff,9b,e8,08,6c,08,76,69,10,5b,ce,b9,79,1e,f3,83,27,0f,
73,ae,d5,d9,5a,67,4a,f5,33,dd,60,73,45,70,7f,b6,90,da,0e,b8,a0,15,7c,ab,2b,\
"??"=hex:5e,cb,36,11,96,79,6b,f1,be,ea,9a,20,42,6f,20,95
[HKEY_USERS\S-1-5-21-746137067-1214440339-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:17,77,ff,4d,de,24,f3,90,f4,40,3a,cb,28,84,79,e8,02,47,ee,22,15,
06,d9,c1,2f,dd,9f,58,fa,da,a6,08,ac,e6,66,22,ea,f8,8a,e5,b7,b7,80,89,8f,98,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3112)
c:\windows\system32\WININET.dll
c:\program files\Xfire\xfire_toucan_39110.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-09-12 15:49
ComboFix-quarantined-files.txt 2009-09-12 07:49
ComboFix2.txt 2009-09-12 07:27
Pre-Run: 792,313,356,288 bytes free
Post-Run: 792,283,553,792 bytes free
226 — E O F — 2009-09-09 15:42
Here's the C:\Qoobox\ComboFix-quarantined-files.txt:
2009-09-12 07:43:04 . 2009-09-12 07:43:05 228 —-a-w- C:\Qoobox\Quarantine\catchme.txt
2009-09-12 07:26:52 . 2009-09-12 07:26:52 102 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-PlayNC Launcher.reg.dat
2009-09-12 07:20:41 . 2009-09-12 07:20:41 1,398 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}.reg.dat
2009-09-12 07:20:35 . 2009-09-12 07:46:01 8,622 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-09-12 07:18:28 . 2009-09-12 07:18:28 61,952 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir
2009-09-12 07:12:01 . 2009-09-12 07:42:03 289 —-a-w- C:\Qoobox\Quarantine\catchme.log
2007-11-07 00:03:18 . 2007-11-07 00:03:18 562,688 —-a-w- C:\Qoobox\Quarantine\C\install.exe.vir
And I'm afraid the ESET scanner isn't downloading correctly. I'll keep trying; perhaps this is to do with the virus.
No changes with how the computer is running. Thanks.