The reports:
ComboFix 09-12-04.02 - Chris 12/04/2009 20:14.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.867 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\kwshncuk.sys
c:\windows\system32\drivers\str.sys
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_UJWALLSJECAKE
((((((((((((((((((((((((( Files Created from 2009-11-05 to 2009-12-05 )))))))))))))))))))))))))))))))
.
2009-12-03 07:40 . 2009-08-07 03:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2009-12-03 07:40 . 2009-08-07 03:23 215920 —-a-w- c:\windows\system32\muweb.dll
2009-12-03 02:01 . 2009-09-10 22:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 02:01 . 2009-09-10 22:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-03 02:01 . 2009-12-03 02:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-02 23:29 . 2009-12-02 23:29 66560 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{E0ADC73E-98F5-4BF8-1B8B-1607FA5B32CF}-essledv.exe
2009-12-02 23:24 . 2009-12-02 23:24 78720 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{B6F879FC-691D-4DC1-AD50-EFA4B689C19C}-arqwfzeanaxbr.sys
2009-12-02 23:10 . 2009-12-02 23:10 66560 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{963A81C1-1470-5992-C90E-6E0FDCDD9FE8}-essledv.exe
2009-12-02 23:06 . 2009-11-03 04:42 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-12-02 23:02 . 2009-12-02 23:02 ——– d—–w- c:\program files\Microsoft Security Essentials
2009-11-30 14:43 . 2009-11-30 14:43 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-11-29 05:02 . 2009-12-02 18:25 ——– d—–w- c:\documents and settings\Chris\Application Data\dvdcss
2009-11-29 00:44 . 2009-11-29 00:44 ——– d—–w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-11-20 16:36 . 2009-11-28 16:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-20 05:25 . 2009-11-20 05:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2009-11-20 00:48 . 2009-12-03 23:02 ——– d—–w- c:\program files\World of Warcraft
2009-11-15 17:17 . 2009-11-15 17:17 ——– d—–w- c:\documents and settings\Chris\Application Data\Yahoo!
2009-11-15 17:17 . 2009-11-20 00:38 ——– d—–w- c:\program files\Yahoo!
2009-11-15 01:42 . 2009-11-15 01:42 1794456 —-a-w- c:\documents and settings\Chris\Application Data\Move Networks\MoveMediaPlayerWin_071701000002.exe
2009-11-14 00:11 . 2009-11-14 00:13 7 —-a-w- c:\windows\system32\nar.bin
2009-11-14 00:06 . 2009-11-20 00:42 ——– d—–w- c:\program files\Trend Micro
2009-11-13 23:05 . 2009-11-13 23:05 ——– d-sh–w- c:\documents and settings\Chris\PrivacIE
2009-11-12 19:04 . 2009-12-02 23:00 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-12 18:54 . 2009-11-12 19:00 ——– d—–w- c:\documents and settings\Chris\HOST
2009-11-12 18:40 . 2009-11-12 18:40 ——– d-sh–w- c:\documents and settings\Administrator.CHRIS.001\IETldCache
2009-11-12 18:12 . 2009-11-12 18:12 ——– d—–w- c:\windows\system32\wbem\Repository
2009-11-12 17:26 . 2009-11-12 17:26 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-11-12 17:14 . 2009-11-12 17:14 ——– d—–w- c:\documents and settings\Administrator.CHRIS.000\IETldCache
2009-11-12 17:14 . 2009-11-12 18:11 ——– d—–w- c:\documents and settings\Administrator.CHRIS.000\Local Settings\Application Data\Microsoft
2009-11-12 17:14 . 2009-11-12 18:11 ——– d-s—w- c:\documents and settings\Administrator.CHRIS.000
2009-11-12 17:04 . 2009-11-12 17:04 ——– d—–w- c:\documents and settings\Administrator.CHRIS\IETldCache
2009-11-12 17:04 . 2009-11-12 18:11 ——– d—–w- c:\documents and settings\Administrator.CHRIS\Local Settings\Application Data\Microsoft
2009-11-12 17:04 . 2009-11-12 18:11 ——– d-s—w- c:\documents and settings\Administrator.CHRIS
2009-11-12 16:24 . 2009-11-12 16:24 ——– d—–w- c:\documents and settings\Administrator\IETldCache
2009-11-12 16:23 . 2009-11-12 18:11 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
2009-11-12 16:23 . 2009-11-12 18:11 ——– d-s—w- c:\documents and settings\Administrator
2009-11-12 03:24 . 2009-11-12 18:11 ——– d—–w- c:\program files\Desktop Media
2009-11-12 00:46 . 2009-11-12 00:46 ——– d—–w- c:\documents and settings\LocalService\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-05 04:29 . 2009-06-15 05:39 117760 —-a-w- c:\documents and settings\Chris\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-05 04:27 . 2009-05-14 20:30 865 –sha-w- c:\windows\system32\mmf.sys
2009-12-02 23:00 . 2003-11-25 05:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-02 18:58 . 2009-08-02 17:20 ——– d—–w- c:\documents and settings\Chris\Application Data\vlc
2009-12-01 02:06 . 2009-02-20 04:27 ——– d—–w- c:\program files\Elaborate Bytes
2009-11-28 04:43 . 2009-06-15 05:37 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-11-28 03:41 . 2009-07-14 17:52 ——– d—–w- c:\program files\RocketDock
2009-11-28 03:41 . 2009-10-14 18:23 ——– d—–w- c:\program files\Windows Media Connect 2
2009-11-28 03:40 . 2009-08-05 20:45 ——– d—–w- c:\documents and settings\Chris\Application Data\rockbox.org
2009-11-28 03:40 . 2009-07-05 22:45 ——– d—–w- c:\documents and settings\Chris\Application Data\gtk-2.0
2009-11-28 03:40 . 2008-10-13 21:17 ——– d—–w- c:\documents and settings\Chris\Application Data\Astroburn
2009-11-28 03:40 . 2008-10-13 20:58 ——– d—–w- c:\documents and settings\Chris\Application Data\DAEMON Tools
2009-11-28 03:39 . 2009-04-02 03:12 ——– d—–w- c:\documents and settings\Chris\Application Data\AVS4YOU
2009-11-20 03:49 . 2009-10-01 07:48 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-11-15 01:42 . 2009-07-02 03:28 143976 —-a-w- c:\documents and settings\Chris\Application Data\Move Networks\uninstall.exe
2009-11-15 01:42 . 2009-03-03 03:35 ——– d—–w- c:\documents and settings\Chris\Application Data\Move Networks
2009-11-15 01:42 . 2009-10-15 00:50 5642688 —-a-w- c:\documents and settings\Chris\Application Data\Move Networks\plugins\npqmp071701000002.dll
2009-11-14 01:06 . 2009-11-04 22:42 ——– d—–w- c:\program files\Firaxis Games
2009-11-14 01:06 . 2002-10-03 07:26 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-11-12 22:38 . 2009-03-03 19:48 1 —-a-w- c:\documents and settings\Chris\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-02 23:54 . 2004-01-25 07:14 ——– d—–w- c:\program files\EPSON
2009-11-02 02:45 . 2009-06-13 15:28 ——– d—–w- c:\program files\iTunes
2009-10-31 16:47 . 2005-07-23 14:01 ——– d—–w- c:\program files\iPod
2009-10-31 16:47 . 2008-10-17 20:03 ——– d—–w- c:\program files\Common Files\Apple
2009-10-31 16:41 . 2009-10-31 16:41 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-16 03:30 . 2009-10-16 03:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Blizzard
2009-10-15 00:50 . 2009-10-15 00:50 97216 —-a-w- c:\documents and settings\Chris\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-10-14 21:24 . 2009-10-12 22:03 ——– d—–w- c:\program files\THQ
2009-10-13 19:05 . 2005-05-11 23:28 43520 -c–a-w- c:\windows\system32\CmdLineExt03.dll
2009-09-26 23:46 . 2009-09-24 21:15 156672 —-a-w- c:\windows\system32\rmc_fixasf.exe
2009-09-26 23:46 . 2009-09-24 21:15 237568 —-a-w- c:\windows\system32\rmc_rtspdl.dll
2009-09-26 05:38 . 2003-03-06 19:18 96936 -c–a-w- c:\documents and settings\Chris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-25 05:37 . 2003-03-06 20:00 667136 ——w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2009-11-01 19:44 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:18 . 2001-08-18 11:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2008-10-04 00:33 . 2008-10-04 00:33 67 -c–a-w- c:\program files\rem_cdk.bat
.
——- Sigcheck ——-
[-] 2009-08-13 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\SYSTEM32\DRIVERS\TCPIP.SYS
[-] 2009-08-13 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\SYSTEM32\DLLCACHE\TCPIP.SYS
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2qfe\tcpip.sys
[-] 2006-04-20 . 1DBF125862891817F374F407626967F4 . 359808 . . [5.1.2600.2892] . . c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
[-] 2006-04-20 . B8158E2A6112C0A5CA67BC158FC70218 . 340480 . . [5.1.2600.1831] . . c:\windows\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp1qfe\tcpip.sys
[-] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\tcpip.sys
[7] 2002-08-29 . 244A2F9816BC9B593957281EF577D976 . 332928 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-11-28_05.46.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 03:41 . 2009-07-12 03:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
- 2002-10-03 07:17 . 2009-11-01 19:53 71264 c:\windows\SYSTEM32\PERFC009.DAT
+ 2002-10-03 07:17 . 2009-12-01 02:06 71264 c:\windows\SYSTEM32\PERFC009.DAT
- 2001-08-18 11:00 . 2001-08-18 11:00 13894 c:\windows\SYSTEM32\DLLCACHE\zonelibm.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 13894 c:\windows\SYSTEM32\DLLCACHE\zonelibm.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 29760 c:\windows\SYSTEM32\DLLCACHE\znetm.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 29760 c:\windows\SYSTEM32\DLLCACHE\znetm.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 41029 c:\windows\SYSTEM32\DLLCACHE\zcorem.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 41029 c:\windows\SYSTEM32\DLLCACHE\zcorem.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 36937 c:\windows\SYSTEM32\DLLCACHE\zclientm.exe
+ 2009-12-01 02:05 . 2001-08-18 11:00 36937 c:\windows\SYSTEM32\DLLCACHE\zclientm.exe
+ 2009-12-01 02:05 . 2001-08-18 11:00 32339 c:\windows\SYSTEM32\DLLCACHE\uniansi.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 32339 c:\windows\SYSTEM32\DLLCACHE\uniansi.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 42573 c:\windows\SYSTEM32\DLLCACHE\shvlzm.exe
- 2001-08-18 11:00 . 2001-08-18 11:00 42573 c:\windows\SYSTEM32\DLLCACHE\shvlzm.exe
- 2001-08-18 11:00 . 2001-08-18 11:00 66113 c:\windows\SYSTEM32\DLLCACHE\shvl.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 66113 c:\windows\SYSTEM32\DLLCACHE\shvl.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 42574 c:\windows\SYSTEM32\DLLCACHE\rvsezm.exe
+ 2009-12-01 02:05 . 2001-08-18 11:00 42574 c:\windows\SYSTEM32\DLLCACHE\rvsezm.exe
- 2001-08-18 11:00 . 2001-08-18 11:00 48706 c:\windows\SYSTEM32\DLLCACHE\rvse.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 48706 c:\windows\SYSTEM32\DLLCACHE\rvse.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 42573 c:\windows\SYSTEM32\DLLCACHE\hrtzzm.exe
- 2001-08-18 11:00 . 2001-08-18 11:00 42573 c:\windows\SYSTEM32\DLLCACHE\hrtzzm.exe
+ 2009-12-01 02:05 . 2001-08-18 11:00 57409 c:\windows\SYSTEM32\DLLCACHE\hrtz.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 57409 c:\windows\SYSTEM32\DLLCACHE\hrtz.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 42575 c:\windows\SYSTEM32\DLLCACHE\chkrzm.exe
+ 2009-12-01 02:05 . 2001-08-18 11:00 42575 c:\windows\SYSTEM32\DLLCACHE\chkrzm.exe
- 2001-08-18 11:00 . 2001-08-18 11:00 40515 c:\windows\SYSTEM32\DLLCACHE\chkr.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 40515 c:\windows\SYSTEM32\DLLCACHE\chkr.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 42577 c:\windows\SYSTEM32\DLLCACHE\bckgzm.exe
+ 2009-12-01 02:05 . 2001-08-18 11:00 42577 c:\windows\SYSTEM32\DLLCACHE\bckgzm.exe
- 2001-08-18 11:00 . 2001-08-18 11:00 82501 c:\windows\SYSTEM32\DLLCACHE\bckg.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 82501 c:\windows\SYSTEM32\DLLCACHE\bckg.dll
+ 2002-10-03 07:16 . 2008-04-14 08:10 96512 c:\windows\SYSTEM32\DLLCACHE\atapi.sys
+ 2002-10-03 07:15 . 2009-12-05 04:12 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2002-10-03 07:15 . 2009-11-28 05:13 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2002-10-03 07:15 . 2009-11-28 05:13 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2002-10-03 07:15 . 2009-12-05 04:12 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2009-12-01 02:05 . 2001-08-18 11:00 4677 c:\windows\SYSTEM32\DLLCACHE\zeeverm.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 4677 c:\windows\SYSTEM32\DLLCACHE\zeeverm.dll
+ 2009-07-12 08:02 . 2009-07-12 08:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
- 2002-10-03 07:17 . 2009-11-01 19:53 441454 c:\windows\SYSTEM32\PERFH009.DAT
+ 2002-10-03 07:17 . 2009-12-01 02:06 441454 c:\windows\SYSTEM32\PERFH009.DAT
+ 2009-06-19 02:48 . 2009-06-19 02:48 142832 c:\windows\SYSTEM32\DRIVERS\MpFilter.sys
+ 2009-12-01 02:05 . 2001-08-18 11:00 113222 c:\windows\SYSTEM32\DLLCACHE\zoneclim.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 113222 c:\windows\SYSTEM32\DLLCACHE\zoneclim.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 753236 c:\windows\SYSTEM32\DLLCACHE\rvseres.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 753236 c:\windows\SYSTEM32\DLLCACHE\rvseres.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 217160 c:\windows\SYSTEM32\DLLCACHE\cmnclim.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 217160 c:\windows\SYSTEM32\DLLCACHE\cmnclim.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 780885 c:\windows\SYSTEM32\DLLCACHE\chkrres.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 780885 c:\windows\SYSTEM32\DLLCACHE\chkrres.dll
+ 2002-10-03 07:15 . 2009-12-05 04:12 196608 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
- 2002-10-03 07:15 . 2009-11-28 05:13 196608 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT
+ 2009-12-02 23:02 . 2009-12-02 23:02 259072 c:\windows\Installer\7087a00.msi
+ 2009-12-02 23:02 . 2009-12-02 23:02 211968 c:\windows\Installer\70879fb.msi
+ 2009-12-02 23:02 . 2009-12-02 23:02 301056 c:\windows\Installer\70879f6.msi
+ 2009-12-03 11:00 . 2009-12-03 11:00 195584 c:\windows\Installer\1e01b23.msi
+ 2009-12-03 11:00 . 2009-12-03 11:00 248832 c:\windows\Installer\1e01b1e.msi
+ 2009-11-29 00:44 . 2009-11-29 00:44 602624 c:\windows\Installer\1c6f8ca.msi
- 2001-08-18 11:00 . 2001-08-18 11:00 2178131 c:\windows\SYSTEM32\DLLCACHE\shvlres.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 2178131 c:\windows\SYSTEM32\DLLCACHE\shvlres.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 1175635 c:\windows\SYSTEM32\DLLCACHE\hrtzres.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 1175635 c:\windows\SYSTEM32\DLLCACHE\hrtzres.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 1039955 c:\windows\SYSTEM32\DLLCACHE\cmnresm.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 1039955 c:\windows\SYSTEM32\DLLCACHE\cmnresm.dll
- 2001-08-18 11:00 . 2001-08-18 11:00 1817687 c:\windows\SYSTEM32\DLLCACHE\bckgres.dll
+ 2009-12-01 02:05 . 2001-08-18 11:00 1817687 c:\windows\SYSTEM32\DLLCACHE\bckgres.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Google Update"="c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-07 133104]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\7f0ede25-e5ae-421a-a93a-1d5e55a8cdfb.exe" [2009-06-29 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-14 1048392]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2003-10-06 741376]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 01000000
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-11-13 23:47 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-09-17 15:05 210168 —-a-w- c:\program files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\saifx]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SYSTEM32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sorrd.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Background Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EPSON Background Monitor.lnk
backup=c:\windows\pss\EPSON Background Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Chris^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Chris\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NVSvc"=2 (0x2)
"NProtectService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"EpsonBidirectionalService"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.1.9835-to-3.1.2.9901-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 9:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 9:05 AM 74480]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\SYSTEM32\DRIVERS\VCdRom.sys [2/19/2009 8:19 PM 8576]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 9:05 AM 7408]
S2 khhrllgoaqbmdc;khhrllgoaqbmdc;\??\c:\windows\system32\drivers\arqwfzeanaxbr.sys –> c:\windows\system32\drivers\arqwfzeanaxbr.sys [?]
S2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [5/14/2009 12:30 PM 2560]
S2 ujwallsjecake;ujwallsjecake;\??\c:\windows\system32\drivers\kwshncuk.sys –> c:\windows\system32\drivers\kwshncuk.sys [?]
S3 CW200USB;SvcDesc=CW200 USB Driver Service;c:\windows\SYSTEM32\DRIVERS\CW200USB.sys [9/29/2003 11:29 PM 10638]
S4 NProtectService;Norton Unerase Protection;c:\program files\Norton AntiVirus\AdvTools\NPROTECT.EXE –> c:\program files\Norton AntiVirus\AdvTools\NPROTECT.EXE [?]
.
Contents of the 'Scheduled Tasks' folder
2009-11-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-12-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1244572991-2690133624-1694720459-1006Core.job
- c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-07 06:58]
2009-12-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1244572991-2690133624-1694720459-1006UA.job
- c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-07 06:58]
2009-12-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-03 01:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.msn.com
mSearch Bar =
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Web Savings - file://c:\program files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {00000075-0000-0010-8000-00AA00389B71}
DPF: {00000161-0000-0010-8000-00AA00389B71}
DPF: {31435657-9980-0010-8000-00AA00389B71}
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-04 20:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y;@^t! #^$ g9^$&pgb; SDB36o \F3F0046F119EFA4F]
"1"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,42,54,3b,7e,24,3e,19,f8
"2"=hex:f1,df,16,de,80,08,0e,2a,d1,38,b5,6f,94,ca,dc,d2,b3,e8,d2,40,6c,6f,61,
5e,d2,5e,7f,21,14,b5,b2,29
"3"=hex:97,5e,49,d3,7c,a0,18,18,10,c9,e3,e3,c1,ae,57,ed,c2,97,86,6a,a5,82,f8,
d5,f2,55,76,c8,bc,53,92,25,3f,d1,b6,bc,00,35,73,43,96,90,79,f6,5b,97,35,47,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \F3F0046F119EFA4F\BB6E5071F4E6B2769BD4E4FACC553A99]
"1"=hex:09,d8,ec,22,15,54,e7,37,3d,5b,59,2d,b7,79,05,2e,dc,0a,71,44,dc,37,80,
ce,24,ad,19,19,d6,bf,9e,2f
"2"=hex:69,46,da,08,bb,5c,f4,0f
"3"=hex:fc,fe,88,54,c9,6f,14,57,8b,36,f6,23,c5,0c,d9,d6,39,fa,6f,d6,22,4a,4e,
c1,97,03,e5,d4,15,ab,46,92,55,eb,4d,2d,bc,d7,30,a4,b0,70,66,00,4a,8a,61,02,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:85,bb,69,ad,52,49,47,61,50,80,55,ef,fa,b4,14,9a,04,b7,d6,59,f0,23,46,
cc,d3,ec,dd,49,40,98,41,b7,16,93,15,99,41,9a,8d,78,4a,2e,fb,89,b2,3d,70,79,\
"8"=hex:63,5a,d7,1b,b1,d4,18,46,f1,a8,be,52,77,05,97,0b,34,a0,71,a8,88,47,3c,
8d,75,16,d6,0c,2b,a7,16,a7,8a,ab,2c,39,23,dd,28,0f
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:70,56,26,33,e3,20,f8,ab
"10"=hex:ef,01,3f,48,b8,d3,ab,86
"11"=hex:7d,ba,74,77,fe,09,92,36
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(496)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
- - - - - - - > 'explorer.exe'(3576)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-12-04 20:34 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-05 04:34
ComboFix2.txt 2009-11-28 05:56
Pre-Run: 3,844,796,416 bytes free
Post-Run: 3,805,806,592 bytes free
- - End Of File - - 76971FEC2B1A809990347FEF4A661D5E
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:20:45 PM, on 12/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\7f0ede25-e5ae-421a-a93a-1d5e55a8cdfb.exe
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71} -
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} -
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_14) -
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} (Java Plug-in 1.6.0) -
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} (Java Plug-in 1.6.0_14) -
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_14) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
O20 - AppInit_DLLs: C:\WINDOWS\SYSTEM32\wbsys.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: saifx - C:\WINDOWS\
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
–
End of file - 4784 bytes