About the replacement files, i have a half installed windows (installed it by accident) on another drive, so that might work, if those arent infected lol.
COMBOLOG:
ComboFix 09-11-15.01 - Administrator 11/15/2009 14:33.4.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3326.2842 [GMT 11:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
FILE ::
"c:\windows\Irediriqurejada.bin"
file zipped: c:\windows\Rmatanonu.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\9bee7c1
c:\windows\Irediriqurejada.bin
c:\windows\msacm32.drv
c:\windows\rasqervy.dll
c:\windows\Rmatanonu.dat
c:\windows\sdfinacs.dll
c:\windows\sdfixwcs.dll
c:\windows\wuasirvy.dll
c:\windows\system32\calc.exe . . . is infected!!
c:\windows\system32\mstsc.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2009-10-15 to 2009-11-15 )))))))))))))))))))))))))))))))
.
2009-11-14 16:23 . 2009-11-15 03:38 18432 —-a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Common\d3ca203219.exe
2009-11-14 16:23 . 2009-11-14 16:23 104960 —-a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Common\d3ca20321.dll
2009-11-14 15:57 . 2009-11-14 15:57 ——– d—–w- c:\windows\Sun
2009-11-14 15:56 . 2009-11-14 15:56 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-14 15:56 . 2009-11-14 15:56 ——– d—–w- c:\program files\Java
2009-11-14 15:55 . 2009-11-14 15:55 152576 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-14 10:21 . 2009-11-14 10:21 ——– d—–w- c:\program files\Microsoft
2009-11-14 10:21 . 2009-11-14 10:21 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-11-10 08:05 . 2009-09-10 03:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-10 08:05 . 2009-09-10 03:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-10 07:17 . 2009-11-10 07:22 ——– d—–w- c:\documents and settings\Administrator\DoctorWeb
2009-11-10 06:51 . 2009-11-14 03:20 ——– d—–w- c:\program files\trend micro
2009-11-10 06:51 . 2009-11-10 06:51 ——– d—–w- C:\rsit
2009-11-10 06:44 . 2009-11-10 06:44 160272 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-10 06:40 . 2009-11-10 06:40 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-11-09 13:43 . 2009-11-10 09:01 ——– d—–w- c:\program files\Steam
2009-11-06 01:57 . 2009-11-06 01:57 ——– d—–w- c:\documents and settings\Administrator\Application Data\MessengerDiscovery 2
2009-11-06 01:38 . 2009-11-14 16:42 ——– d—–w- c:\documents and settings\Administrator\Tracing
2009-11-06 01:35 . 2009-11-06 01:35 ——– d—–w- c:\program files\Common Files\Windows Live
2009-10-29 07:49 . 2009-10-29 11:32 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-10-29 07:48 . 2009-10-29 07:48 1961720 —-a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-10-26 06:15 . 2009-11-14 13:31 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2009-10-26 06:14 . 2009-10-26 06:14 ——– d—–w- c:\program files\VideoLAN
2009-10-26 01:35 . 2009-10-26 01:35 ——– d-sh–w- c:\documents and settings\Administrator\IECompatCache
2009-10-23 16:39 . 2009-10-23 16:39 ——– d—–w- c:\documents and settings\Administrator\Application Data\Megaupload
2009-10-23 14:46 . 2009-11-10 08:02 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-10-23 14:46 . 2009-11-10 08:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-23 14:21 . 2009-10-23 14:21 ——– d—–w- c:\program files\Combined Community Codec Pack
2009-10-23 14:08 . 2009-10-23 14:09 ——– dc-h–w- c:\windows\ie8
2009-10-23 11:18 . 2009-11-12 03:28 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2009-10-23 11:18 . 2009-10-23 11:18 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2009-10-23 11:16 . 2009-10-25 11:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-10-23 10:59 . 2009-10-23 10:59 ——– d—–w- c:\program files\Megaupload
2009-10-23 10:57 . 2009-10-23 10:57 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-23 10:57 . 2009-11-10 08:05 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-10-23 10:57 . 2009-10-23 10:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-23 10:53 . 2009-10-23 10:53 ——– d—–w- c:\program files\uTorrent
2009-10-23 10:52 . 2009-11-14 16:39 ——– d—–w- c:\documents and settings\Administrator\Application Data\uTorrent
2009-10-23 10:50 . 2009-10-23 10:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Adobe Systems
2009-10-23 10:50 . 2009-10-23 10:50 ——– d—–w- c:\program files\Common Files\Adobe Systems Shared
2009-10-23 10:44 . 2009-10-26 07:58 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-10-23 10:40 . 2006-10-26 09:56 32592 —-a-w- c:\windows\system32\msonpmon.dll
2009-10-23 10:39 . 2009-10-23 10:39 ——– d—–w- c:\program files\Microsoft Works
2009-10-23 10:39 . 2009-10-23 10:39 ——– d—–w- c:\program files\MSBuild
2009-10-23 10:38 . 2009-10-23 10:38 ——– d—–w- c:\program files\Microsoft.NET
2009-10-23 10:37 . 2009-10-23 10:37 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2009-10-23 10:36 . 2009-10-23 10:39 ——– d—–w- c:\windows\SHELLNEW
2009-10-23 10:36 . 2009-10-23 10:36 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Help
2009-10-23 10:36 . 2009-10-23 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-23 10:35 . 2009-10-23 10:35 ——– d—–r- C:\MSOCache
2009-10-23 08:32 . 2009-10-23 08:32 ——– d—–w- c:\program files\Messenger Plus! Live
2009-10-23 07:50 . 2002-12-31 12:00 25600 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-10-23 06:29 . 2009-10-23 07:49 ——– d—–w- c:\windows\system32\drivers\umdf
2009-10-23 06:21 . 2004-08-03 14:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-10-23 06:21 . 2004-08-03 13:07 59264 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-10-23 06:21 . 2004-08-03 13:08 31616 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2009-10-23 06:19 . 2009-10-23 07:49 ——– d—–w- c:\windows\system32\LogFiles
2009-10-23 05:45 . 2009-10-23 05:45 ——– d—–w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-10-23 05:17 . 2009-11-01 09:08 ——– d—–w- c:\documents and settings\Administrator\Application Data\Ventrilo
2009-10-23 05:17 . 2009-10-23 05:17 ——– d—–w- c:\program files\Ventrilo
2009-10-23 05:15 . 2009-10-23 05:17 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-10-23 05:03 . 2004-08-03 22:59 57472 —-a-w- c:\windows\system32\drivers\redbook.sys
2009-10-23 05:03 . 2001-08-17 13:46 6400 —-a-w- c:\windows\system32\drivers\enum1394.sys
2009-10-23 05:02 . 2004-08-03 14:56 74240 —-a-w- c:\windows\system32\usbui.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-15 03:37 . 2009-10-22 19:24 16608 —-a-w- c:\windows\gdrv.sys
2009-11-14 16:01 . 2009-10-22 20:03 75808 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-14 10:21 . 2009-10-23 04:23 ——– d—–w- c:\program files\Windows Live
2009-11-14 10:19 . 2009-10-23 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-11-14 03:31 . 2009-10-22 19:48 ——– d—–w- c:\program files\Heroes of Newerth
2009-11-06 02:17 . 2009-10-22 19:07 ——– d—–w- c:\program files\Unlocker
2009-10-24 10:01 . 2009-10-22 19:10 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-23 14:22 . 2009-10-22 19:19 ——– d—–w- c:\program files\Symantec
2009-10-23 14:22 . 2009-10-22 19:19 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-10-23 14:22 . 2009-10-22 19:19 ——– d—–w- c:\program files\Symantec Client Security
2009-10-23 14:22 . 2009-10-22 19:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-10-23 14:21 . 2009-10-22 19:20 40 —-a-w- c:\windows\system32\profile.dat
2009-10-23 10:59 . 2009-10-22 19:25 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-10-23 10:52 . 2009-10-22 19:18 ——– d—–w- c:\program files\Common Files\Adobe
2009-10-23 05:17 . 2009-10-22 20:10 ——– d—–w- c:\documents and settings\Administrator\Application Data\Winamp
2009-10-23 05:01 . 2009-10-22 19:08 ——– d—–w- c:\program files\Windows Media Connect 2
2009-10-23 04:49 . 2009-10-22 20:10 ——– d—–w- c:\program files\Winamp
2009-10-23 04:25 . 2009-10-23 04:23 ——– dcsh–w- c:\program files\Common Files\WindowsLiveInstaller
2009-10-22 20:23 . 2009-10-22 20:23 ——– d—–w- c:\documents and settings\Administrator\Application Data\Apple Computer
2009-10-22 20:23 . 2009-10-22 20:23 ——– d—–w- c:\program files\iTunes
2009-10-22 20:23 . 2009-10-22 20:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-10-22 20:23 . 2009-10-22 20:23 ——– d—–w- c:\program files\iPod
2009-10-22 20:23 . 2009-10-22 19:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-22 20:23 . 2009-10-22 20:23 ——– d—–w- c:\program files\Bonjour
2009-10-22 20:23 . 2009-10-22 19:17 ——– d—–w- c:\program files\QuickTime Alternative
2009-10-22 20:22 . 2009-10-22 20:22 ——– d—–w- c:\program files\Apple Software Update
2009-10-22 20:22 . 2009-10-22 20:22 ——– d—–w- c:\program files\Common Files\Apple
2009-10-22 20:22 . 2009-10-22 20:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-10-22 20:02 . 2009-10-22 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI
2009-10-22 20:02 . 2009-10-22 20:02 ——– d—–w- c:\documents and settings\Administrator\Application Data\ATI
2009-10-22 20:02 . 2009-10-22 20:02 0 —-a-w- c:\windows\ativpsrm.bin
2009-10-22 19:58 . 2009-10-22 19:52 ——– d—–w- c:\program files\ATI Technologies
2009-10-22 19:56 . 2009-10-22 19:56 9158 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
2009-10-22 19:55 . 2009-10-22 19:55 ——– d—–w- c:\program files\Common Files\ATI Technologies
2009-10-22 19:52 . 2009-10-22 19:52 0 —-a-w- c:\windows\nsreg.dat
2009-10-22 19:49 . 2009-10-22 19:49 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-10-22 19:44 . 2009-10-22 19:37 ——– d—–w- c:\program files\Creative
2009-10-22 19:42 . 2009-10-22 19:42 20747 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-10-22 19:42 . 2009-10-22 19:42 ——– d—–w- c:\program files\Linksys Wireless-G PCI Wireless Network Monitor
2009-10-22 19:38 . 2009-10-22 19:25 ——– d—–w- c:\program files\Common Files\InstallShield
2009-10-22 19:31 . 2009-10-22 19:29 ——– d—–w- c:\program files\Realtek
2009-10-22 19:31 . 2009-10-22 19:31 ——– d—–w- c:\documents and settings\Administrator\Application Data\InstallShield
2009-10-22 19:29 . 2009-10-22 19:29 315392 —-a-w- c:\windows\HideWin.exe
2009-10-22 19:26 . 2009-10-22 19:26 ——– d—–w- c:\program files\Intel
2009-10-22 19:25 . 2009-10-22 19:25 ——– d—–w- c:\program files\GIGABYTE
2009-10-22 19:18 . 2009-10-22 19:18 ——– d—–w- c:\program files\Nero
2009-10-22 19:18 . 2009-10-22 19:18 ——– d—–w- c:\program files\Common Files\Ahead
2009-10-22 19:18 . 2009-10-22 19:18 ——– d—–w- c:\program files\7-Zip
2009-10-22 19:18 . 2009-10-22 19:18 ——– d—–w- c:\program files\Real Alternative
2009-10-22 19:17 . 2009-10-22 19:17 ——– d—–w- c:\program files\Media Player Classic
2009-10-22 19:17 . 2009-10-22 19:17 ——– d—–w- c:\program files\K-Lite Codec Pack
2009-10-22 19:17 . 2009-10-22 19:17 2232 —-a-w- c:\windows\java\Packages\Data\XFXJZL3H.DAT
2009-10-22 19:17 . 2009-10-22 19:17 155995 —-a-w- c:\windows\java\Packages\JXZHJVNN.ZIP
2009-10-22 19:17 . 2009-10-22 19:17 2678 —-a-w- c:\windows\java\Packages\Data\IYRBJXV5.DAT
2009-10-22 19:17 . 2009-10-22 19:17 2678 —-a-w- c:\windows\java\Packages\Data\ZXN7XJTF.DAT
2009-10-22 19:17 . 2009-10-22 19:17 2678 —-a-w- c:\windows\java\Packages\Data\ZFRHB9J3.DAT
2009-10-22 19:17 . 2009-10-22 19:17 2678 —-a-w- c:\windows\java\Packages\Data\EV7HBBZ5.DAT
2009-10-22 19:17 . 2009-10-22 19:17 2678 —-a-w- c:\windows\java\Packages\Data\3Z9BJX71.DAT
2009-10-22 19:08 . 2009-10-22 19:08 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-10-22 19:07 . 2009-10-22 19:07 ——– d—–w- c:\program files\Desktop
2009-10-22 19:07 . 2009-10-22 19:07 ——– d—–w- c:\program files\Microsoft PowerToys
2009-10-22 19:07 . 2009-10-22 19:07 ——– d—–w- c:\program files\HashTab Shell Extension
.
(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
((((((((((((((((((((((((((((( SnapShot@2009-11-10_07.53.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-15 03:37 . 2009-11-15 03:37 16384 c:\windows\Temp\Perflib_Perfdata_654.dat
+ 2009-11-10 06:40 . 2009-11-14 03:11 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-11-10 06:40 . 2009-11-10 07:32 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-11-10 06:40 . 2009-11-10 07:32 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2009-11-10 06:40 . 2009-11-14 03:11 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2009-11-14 10:21 . 2009-11-14 10:21 27136 c:\windows\Installer\2fe68.msi
+ 2009-11-14 10:21 . 2009-11-14 10:21 83456 c:\windows\Installer\2fe4c.msi
+ 2009-11-14 10:21 . 2009-11-14 10:21 58880 c:\windows\Installer\2fe45.msi
- 2009-11-06 01:37 . 2009-11-06 01:37 62304 c:\windows\Installer\{F6BD194C-4190-4D73-B1B1-C48C99921BFE}\IconWlc.exe
+ 2009-11-14 10:21 . 2009-11-14 10:21 62304 c:\windows\Installer\{F6BD194C-4190-4D73-B1B1-C48C99921BFE}\IconWlc.exe
+ 2009-11-14 10:21 . 2009-11-14 10:21 80395 c:\windows\Installer\{A85FD55B-891B-4314-97A5-EA96C0BD80B5}\MsblIco.Exe
- 2009-11-06 01:37 . 2009-11-06 01:37 80395 c:\windows\Installer\{A85FD55B-891B-4314-97A5-EA96C0BD80B5}\MsblIco.Exe
- 2006-12-01 12:54 . 2006-12-01 12:54 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-01 11:54 . 2006-12-01 11:54 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
- 2006-12-01 12:54 . 2006-12-01 12:54 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 11:54 . 2006-12-01 11:54 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
- 2006-12-01 12:54 . 2006-12-01 12:54 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 11:54 . 2006-12-01 11:54 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2005-09-22 11:48 . 2005-09-22 11:48 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
- 2005-09-22 21:29 . 2005-09-22 21:29 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
- 2005-09-22 21:29 . 2005-09-22 21:29 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-22 11:48 . 2005-09-22 11:48 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
- 2005-09-22 21:29 . 2005-09-22 21:29 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2005-09-22 11:48 . 2005-09-22 11:48 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2009-11-14 15:56 . 2009-11-14 15:56 149280 c:\windows\system32\javaws.exe
+ 2009-11-14 15:56 . 2009-11-14 15:56 145184 c:\windows\system32\javaw.exe
+ 2009-11-14 15:56 . 2009-11-14 15:56 145184 c:\windows\system32\java.exe
+ 2009-10-23 04:55 . 2009-11-15 03:24 272576 c:\windows\system32\FNTCACHE.DAT
+ 2009-11-14 10:21 . 2009-11-14 10:21 430080 c:\windows\Installer\2fe77.msi
+ 2009-11-14 10:21 . 2009-11-14 10:21 155648 c:\windows\Installer\2fe6f.msi
+ 2009-11-14 10:21 . 2009-11-14 10:21 140288 c:\windows\Installer\2fe61.msi
+ 2009-11-14 10:21 . 2009-11-14 10:21 202752 c:\windows\Installer\2fe5a.msi
+ 2009-11-14 10:21 . 2009-11-14 10:21 152576 c:\windows\Installer\2fe53.msi
+ 2009-11-14 10:20 . 2009-11-14 10:20 107008 c:\windows\Installer\2fe3e.msi
+ 2009-11-14 10:12 . 2009-11-14 10:12 301056 c:\windows\Installer\19dc3.msi
+ 2009-11-14 15:56 . 2009-11-14 15:56 537600 c:\windows\Installer\1390c27.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WAB"="c:\documents and settings\Administrator\Application Data\Macromedia\Common\d3ca203219.exe" [2009-11-15 18432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-14 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-07 16862208]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2005-05-03 64512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\d3ca20321.dll
"mixer1"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\d3ca20321.dll
"wave1"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\d3ca20321.dll
"aux1"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\d3ca20321.dll
"midi2"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\d3ca20321.dll
"mixer2"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\d3ca20321.dll
"wave2"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\d3ca20321.dll
"aux2"=c:\docume~1\ADMINI~1\APPLIC~1\MACROM~1\Common\d3ca20321.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^lyesys32.exe]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\lyesys32.exe
backup=c:\windows\pss\lyesys32.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Heroes of Newerth\\hon.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\[removed]\\counter-strike\\hl.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [10/23/2009 6:25 AM 80392]
— Other Services/Drivers In Memory —
*NewlyCreated* - GTNDIS5
*Deregistered* - mbr
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\97mip8de.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/|http://www.allkpop.com/|http://seoulbeats.com/
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-rundll32.exe - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-15 14:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-436374069-179605362-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,47,f0,3e,7f,57,39,04,40,b0,a8,ff,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,47,f0,3e,7f,57,39,04,40,b0,a8,ff,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
@DACL=(02 0000)
"DLLName"="Ati2evxx.dll"
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000001
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"Shutdown"="AtiShutdownEvent"
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3684)
c:\program files\Unlocker\UnlockerHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\windows\system32\Rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2009-11-15 14:39 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-15 03:39
ComboFix2.txt 2009-11-14 15:44
ComboFix3.txt 2009-11-14 09:40
ComboFix4.txt 2009-11-10 07:56
Pre-Run: 38,643,593,216 bytes free
Post-Run: 38,705,823,744 bytes free
- - End Of File - - 9BE65D4BBE449AD883454086867EF420
KASPERSKY LOG:
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, November 15, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, November 14, 2009 16:15:57
Records in database: 3208640
——————————————————————————–
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
Scan statistics:
Objects scanned: 66265
Threats found: 2
Infected objects found: 2
Suspicious objects found: 0
Scan duration: 00:42:34
File name / Threat / Threats count
C:\Documents and Settings\Administrator\Local Settings\temp\jar_cache2137662534849341714.tmp Infected: Trojan-Downloader.Java.OpenStream.ad 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.TDSS.y 1
Selected area has been scanned.