I dont have the application errors anymore but i havent tried running XP out of safemode yet. So far so good. =]
ComboFix 09-09-16.02 - kayialess 09/16/2009 23:09.1.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1634 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Worknow.com.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
ADS - system32: deleted 12 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
c:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
c:\recycler\S-1-5-21-1284193018-2690920046-2573575750-500
c:\recycler\S-1-5-21-1417001333-1409082233-682003330-1005
c:\recycler\S-1-5-21-1417001333-1409082233-682003330-500
c:\recycler\S-1-5-21-1717359693-725540966-1392451680-1005
c:\recycler\S-1-5-21-1717359693-725540966-1392451680-500
c:\recycler\S-1-5-21-2097178511-3723882698-4260316654-500
c:\recycler\S-1-5-21-2323265706-4101010762-3771514121-500
c:\recycler\S-1-5-21-3434858073-770328501-1186697724-500
c:\recycler\S-1-5-21-3981961388-1238095360-2153429229-1005
c:\recycler\S-1-5-21-3981961388-1238095360-2153429229-500
c:\recycler\S-1-5-21-4264208443-1597490366-951982877-1005
c:\recycler\S-1-5-21-4264208443-1597490366-951982877-500
c:\recycler\S-1-5-21-975613499-1138187149-3970294880-500
c:\windows\Installer\69d82.msp
c:\windows\run.log
c:\windows\system32\AutoRun.inf
c:\windows\system32\images
c:\windows\system32\images\toolbar\calendar.gif
c:\windows\system32\images\toolbar\crlogo.gif
c:\windows\system32\images\toolbar\export.gif
c:\windows\system32\images\toolbar\export_over.gif
c:\windows\system32\images\toolbar\exportd.gif
c:\windows\system32\images\toolbar\First.gif
c:\windows\system32\images\toolbar\first_over.gif
c:\windows\system32\images\toolbar\Firstd.gif
c:\windows\system32\images\toolbar\gotopage.gif
c:\windows\system32\images\toolbar\gotopage_over.gif
c:\windows\system32\images\toolbar\gotopaged.gif
c:\windows\system32\images\toolbar\grouptree.gif
c:\windows\system32\images\toolbar\grouptree_over.gif
c:\windows\system32\images\toolbar\grouptreed.gif
c:\windows\system32\images\toolbar\grouptreepressed.gif
c:\windows\system32\images\toolbar\Last.gif
c:\windows\system32\images\toolbar\last_over.gif
c:\windows\system32\images\toolbar\Lastd.gif
c:\windows\system32\images\toolbar\Next.gif
c:\windows\system32\images\toolbar\next_over.gif
c:\windows\system32\images\toolbar\Nextd.gif
c:\windows\system32\images\toolbar\Prev.gif
c:\windows\system32\images\toolbar\prev_over.gif
c:\windows\system32\images\toolbar\Prevd.gif
c:\windows\system32\images\toolbar\print.gif
c:\windows\system32\images\toolbar\print_over.gif
c:\windows\system32\images\toolbar\printd.gif
c:\windows\system32\images\toolbar\Refresh.gif
c:\windows\system32\images\toolbar\refresh_over.gif
c:\windows\system32\images\toolbar\refreshd.gif
c:\windows\system32\images\toolbar\Search.gif
c:\windows\system32\images\toolbar\search_over.gif
c:\windows\system32\images\toolbar\searchd.gif
c:\windows\system32\images\toolbar\up.gif
c:\windows\system32\images\toolbar\up_over.gif
c:\windows\system32\images\toolbar\upd.gif
c:\windows\system32\images\tree\begindots.gif
c:\windows\system32\images\tree\beginminus.gif
c:\windows\system32\images\tree\beginplus.gif
c:\windows\system32\images\tree\blank.gif
c:\windows\system32\images\tree\blankdots.gif
c:\windows\system32\images\tree\dots.gif
c:\windows\system32\images\tree\lastdots.gif
c:\windows\system32\images\tree\lastminus.gif
c:\windows\system32\images\tree\lastplus.gif
c:\windows\system32\images\tree\Magnify.gif
c:\windows\system32\images\tree\minus.gif
c:\windows\system32\images\tree\minusbox.gif
c:\windows\system32\images\tree\plus.gif
c:\windows\system32\images\tree\plusbox.gif
c:\windows\system32\images\tree\singleminus.gif
c:\windows\system32\images\tree\singleplus.gif
c:\windows\system32\UAs
c:\windows\system32\UAs\aim6_UAs001.dat
c:\windows\system32\UAs\aolsoftware_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs001.dat
c:\windows\system32\UAs\firefox_UAs001.dat
c:\windows\system32\UAs\firefox_UAs002.dat
c:\windows\system32\UAs\hprbupdate_UAs001.dat
c:\windows\system32\UAs\hpwucli_UAs001.dat
c:\windows\system32\UAs\hpwucli_UAs002.dat
c:\windows\system32\UAs\hpwucli_UAs003.dat
c:\windows\system32\UAs\hpwucli_UAs004.dat
c:\windows\system32\UAs\LUCOMS~1_UAs001.dat
c:\windows\system32\UAs\LUCOMS~1_UAs002.dat
c:\windows\system32\UAs\LUCOMS~1_UAs003.dat
c:\windows\system32\UAs\LUCOMS~1_UAs004.dat
c:\windows\system32\UAs\LUCOMS~1_UAs005.dat
c:\windows\system32\UAs\LUCOMS~1_UAs006.dat
c:\windows\system32\UAs\LUCOMS~1_UAs007.dat
c:\windows\system32\UAs\LUCOMS~1_UAs008.dat
c:\windows\system32\UAs\LUCOMS~1_UAs009.dat
c:\windows\system32\UAs\LUCOMS~1_UAs010.dat
c:\windows\system32\UAs\LUCOMS~1_UAs011.dat
c:\windows\system32\UAs\LUCOMS~1_UAs012.dat
c:\windows\system32\UAs\LUCOMS~1_UAs013.dat
c:\windows\system32\UAs\LUCOMS~1_UAs014.dat
c:\windows\system32\UAs\LUCOMS~1_UAs015.dat
c:\windows\system32\UAs\LUCOMS~1_UAs016.dat
c:\windows\system32\UAs\LUCOMS~1_UAs017.dat
c:\windows\system32\UAs\LUCOMS~1_UAs018.dat
c:\windows\system32\UAs\LUCOMS~1_UAs019.dat
c:\windows\system32\UAs\LUCOMS~1_UAs020.dat
c:\windows\system32\UAs\LUCOMS~1_UAs021.dat
c:\windows\system32\UAs\LUCOMS~1_UAs022.dat
c:\windows\system32\UAs\LUCOMS~1_UAs023.dat
c:\windows\system32\UAs\LUCOMS~1_UAs024.dat
c:\windows\system32\UAs\LUCOMS~1_UAs025.dat
c:\windows\system32\UAs\mbam_UAs001.dat
c:\windows\system32\UAs\mbam_UAs002.dat
c:\windows\system32\UAs\mbam_UAs003.dat
c:\windows\system32\UAs\mbam_UAs004.dat
c:\windows\system32\UAs\McciBrowser_UAs001.dat
c:\windows\system32\UAs\McciBrowser_UAs002.dat
c:\windows\system32\UAs\McciBrowser_UAs003.dat
c:\windows\system32\UAs\Smc_UAs001.dat
c:\windows\system32\UAs\smupdate_UAs001.dat
c:\windows\system32\UAs\SUPERAntiSpyware_UAs001.dat
c:\windows\system32\UAs\wgatray_UAs001.dat
—– BITS: Possible infected sites —–
hxxp://witwsus.wit.private
Infected copy of c:\windows\system32\powrprof.dll was found and disinfected
Restored copy from - c:\system volume information\_restore{C7A74BFA-C672-4486-A207-C0D9A9138B5A}\RP53\A0028911.dll
Infected copy of c:\windows\system32\wininet.dll was found and disinfected
Restored copy from - c:\system volume information\_restore{C7A74BFA-C672-4486-A207-C0D9A9138B5A}\RP53\A0028912.dll
.
((((((((((((((((((((((((( Files Created from 2009-08-17 to 2009-09-17 )))))))))))))))))))))))))))))))
.
2009-09-17 02:53 . 2009-09-17 02:53 ——– d—–w- C:\_OTM
2009-09-16 16:02 . 2009-09-16 16:02 ——– d—–w- c:\program files\Trend Micro
2009-09-15 20:34 . 2009-09-15 20:34 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-15 20:34 . 2009-09-15 20:34 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-09-15 20:34 . 2009-09-15 20:34 ——– d—–w- c:\documents and settings\kayialess\Application Data\SUPERAntiSpyware.com
2009-09-15 20:34 . 2009-09-15 20:34 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-09-15 19:55 . 2009-09-15 20:08 ——– d—–w- c:\program files\SpywareBlaster
2009-09-10 15:33 . 2009-09-11 16:09 ——– d—–w- c:\windows\system32\cock
2009-09-03 18:25 . 2009-09-16 16:02 ——– d—–w- c:\windows\system32\xmldm
2009-08-18 20:11 . 2009-09-03 18:24 46640 —-a-w- c:\windows\system32\msln.exe
2009-08-18 20:11 . 2009-09-03 18:24 46640 —-a-w- c:\windows\system32\msln(2).exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-16 21:37 . 2009-05-02 04:43 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-09-16 19:17 . 2009-04-22 14:57 ——– d—–w- c:\documents and settings\NetworkService\Application Data\VMware
2009-09-16 19:17 . 2009-04-22 14:48 ——– d—–w- c:\documents and settings\All Users\Application Data\VMware
2009-09-16 16:02 . 2009-04-21 23:38 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-15 20:01 . 2009-04-21 23:41 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-13 02:40 . 2009-04-28 05:01 ——– d—–w- c:\documents and settings\kayialess\Application Data\uTorrent
2009-09-10 18:54 . 2009-04-21 23:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-04-21 23:38 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-25 02:10 . 2009-07-25 01:55 ——– d—–w- c:\program files\dvrfxe
2009-07-20 22:23 . 2009-07-20 22:23 ——– d—–w- c:\documents and settings\kayialess\Application Data\Smith Micro
2009-07-20 22:20 . 2009-07-20 22:20 ——– d—–w- c:\program files\Verizon Wireless
2009-07-20 22:19 . 2009-07-20 22:19 ——– d—–w- c:\program files\LG Electronics
2009-07-20 22:19 . 2008-06-10 14:31 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-29 20:29 . 2008-06-10 18:43 71752 —-a-w- c:\documents and settings\Default User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-01 21:02 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
——- Sigcheck ——-
[-] 2009-09-11 . FF9650BE501D152437001D21DD24727C . 993792 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2009-09-11 . FF9650BE501D152437001D21DD24727C . 993792 . . [5.1.2600.5781] . . c:\windows\$NtUninstallKB959426$\kernel32.dll
[-] 2009-09-11 . FF9650BE501D152437001D21DD24727C . 993792 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll
[-] 2009-09-11 . FF9650BE501D152437001D21DD24727C . 993792 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll
[-] 2008-05-28 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
"AdobeUpdater"="c:\program files\common files\adobe\updater5\adobeupdater.exe" [2009-04-22 2356088]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-04 1994480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-07-04 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-04 1323008]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 66928]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-01-11 294912]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2008-01-11 208896]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-03-26 59680]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-04-27 243248]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2008-01-11 144728]
"LPMailChecker"="c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.exe" [2008-01-11 124248]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-03-14 425984]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-03-14 126976]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"PSQLLauncher"="c:\program files\ThinkVantage Fingerprint Software\launcher.exe" [2007-08-14 48904]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-04-21 115560]
"QuickTime Task"="c:\program files\quicktime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2009-03-10 1553920]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2007-11-22 181536]
c:\documents and settings\Admin\Start Menu\Programs\Startup\
Shortcut to bg.lnk - c:\documents and settings\Admin\BGinfo\bg.bat [2008-6-11 34]
c:\documents and settings\kayialess\Start Menu\Programs\Startup\
VZAccess Manager.lnk - c:\program files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [2009-7-20 1738032]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 19:13 49152 —-a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-08-14 19:54 89600 —-a-w- c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 20:37 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2007-12-14 20:36 28672 —-a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2008-03-14 22:54 32768 —-a-w- c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ACGina psqlpwd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2746289630-3061505222-2800193894-17083\Scripts\Logon\0\0]
"Script"=\\wit.private\SysVol\wit.private\scripts\students.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2746289630-3061505222-2800193894-61192\Scripts\Logon\0\0]
"Script"=\\wit.private\SysVol\wit.private\scripts\students.bat
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre1.6.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\QK SMTP Server 3\\QKSmtpServer3.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [10/16/2007 6:33 PM 103472]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [10/16/2007 6:32 PM 19504]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [6/10/2008 11:37 AM 57344]
S0 fxef;fxef;c:\windows\system32\drivers\rxhol.sys –> c:\windows\system32\drivers\rxhol.sys [?]
S1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [6/10/2008 11:45 AM 4442]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/21/2009 7:38 PM 269648]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [8/14/2007 3:46 PM 10896]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [10/28/2008 11:08 PM 54960]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [11/18/2008 6:56 PM 23888]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/10/2009 11:58 AM 102448]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [4/21/2009 7:38 PM 19160]
S3 Smcinst;Symantec Auto-upgrade Agent;c:\program files\Symantec AntiVirus\SmcLU\Setup\smcinst.exe –> c:\program files\Symantec AntiVirus\SmcLU\Setup\smcinst.exe [?]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [5/22/2007 2:59 PM 30336]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [4/21/2009 9:07 PM 79888]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-09-15 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-06-10 05:30]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.symantec.com/enterprise/security_response/index.jsp
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
FF - ProfilePath - c:\documents and settings\kayialess\Application Data\Mozilla\Firefox\Profiles\czvyun4n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\kayialess\Application Data\Mozilla\Firefox\Profiles\czvyun4n.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071302000002.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
Notify-NavLogon - (no file)
SafeBoot-Symantec Antvirus
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-16 23:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1076)
c:\windows\system32\vrlogon.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\kayialess\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\Ati2evxx.dll
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\program files\ThinkVantage Fingerprint Software\crypto.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
- - - - - - - > 'lsass.exe'(1132)
c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACON.dll
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
c:\program files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
c:\program files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
c:\program files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
.
———————— Other Running Processes ————————
.
c:\program files\Symantec AntiVirus\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\progra~1\COMMON~1\stardock\SDMCP.exe
c:\program files\Symantec AntiVirus\SmcGui.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
.
**************************************************************************
.
Completion time: 2009-09-17 23:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-17 03:27
Pre-Run: 114,007,310,336 bytes free
Post-Run: 113,956,319,232 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=10 Default=10 Failed=9 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11
381 — E O F — 2009-05-01 17:39
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
c:\windows\system32\osysk.dat moved successfully.
c:\windows\system32\osysw.dat moved successfully.
c:\windows\system32\wincode.dat moved successfully.
c:\windows\system32\osysp.dat moved successfully.
c:\windows\system32\krncode.dat moved successfully.
c:\windows\system32\pwrcode.dat moved successfully.
c:\windows\system32\nsysp.ini moved successfully.
c:\windows\system32\shifld2.old moved successfully.
c:\windows\system32\nsysw.ini moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
User: jstudent
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
User: kayialess
->Temp folder emptied: 737280 bytes
->Temporary Internet Files folder emptied: 6856253 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 40067971 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 49152 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Setup
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 112 bytes
Windows Temp folder emptied: 53369 bytes
RecycleBin emptied: 4103671 bytes
Total Files Cleaned = 49.53 mb
OTM by OldTimer - Version 3.0.0.6 log created on 09162009_225328
Files moved on Reboot…
Registry entries deleted on Reboot…