ComboFix 10-01-04.01 - amman 08/01/2010 17:49:24.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.2.1033.18.1006.564 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\documents and settings\amman\Application Data\bcrypt.html
C:\LOG.TXT
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exesys_
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\recycler\S-1-5-21-0378130778-6474429877-631939249-5744
c:\recycler\S-1-5-21-2681464031-0444599439-339737916-0741
c:\recycler\S-1-5-21-3600527180-9977222190-737987849-0021
c:\recycler\S-1-5-21-3929573709-454856174-1111101461-1006
c:\recycler\S-1-5-21-6045477170-2786513263-068547380-3334
c:\recycler\S-1-5-21-6141979347-8995037954-190775191-7397
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\sdra64.exe
C:\xcrashdump.dat
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_SSHNAS
((((((((((((((((((((((((( Files Created from 2009-12-09 to 2010-01-09 )))))))))))))))))))))))))))))))
.
2010-01-08 15:51 . 2010-01-08 15:51 ——– d—–w- c:\documents and settings\amman\Application Data\Malwarebytes
2010-01-07 08:35 . 2010-01-07 08:35 ——– d—–w- c:\documents and settings\Administrator.DELL-LAPTOP\Application Data\Malwarebytes
2010-01-07 08:35 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 08:35 . 2010-01-07 08:35 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-01-07 08:35 . 2010-01-07 09:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-07 08:35 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 04:25 . 2010-01-07 04:25 ——– d—–w- c:\documents and settings\Administrator.DELL-LAPTOP\Local Settings\Application Data\Mozilla
2010-01-06 21:58 . 2010-01-06 22:09 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\RegCure
2010-01-06 21:58 . 2010-01-06 22:09 ——– d—–w- c:\program files\RegCure
2010-01-06 03:57 . 2010-01-06 03:57 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-24 21:03 . 2009-12-24 21:03 ——– d—–w- c:\program files\ffdshow
2009-12-24 21:03 . 2009-12-24 21:03 ——– d—–w- c:\program files\TVersity Codec Pack
2009-12-24 21:02 . 2009-12-24 21:02 ——– d—–w- c:\program files\TVersity
2009-12-24 20:56 . 2009-12-24 20:56 ——– d—–w- c:\program files\DirectVobSub
2009-12-24 20:50 . 2009-12-24 20:50 ——– d—–w- c:\program files\AviSynth 2.5
2009-12-18 21:18 . 2009-12-18 21:22 35902 —-a-w- c:\windows\scunin.dat
2009-12-18 21:18 . 2009-12-18 21:22 967 —-a-w- c:\windows\ScUnin.pif
2009-12-18 21:18 . 2009-12-18 21:22 94208 —-a-w- c:\windows\ScUnin.exe
2009-12-18 21:16 . 2009-12-20 07:27 ——– d—–w- c:\program files\Starcraft
2009-12-12 09:26 . 2009-12-12 09:26 63252 —ha-w- c:\windows\system32\mlfcache.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-06 22:12 . 2008-08-28 18:00 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-06 06:14 . 2009-05-19 19:59 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-01-06 03:54 . 2009-05-04 06:27 ——– d—–w- c:\documents and settings\amman\Application Data\uTorrent
2010-01-05 21:57 . 2009-09-01 05:15 ——– d—–w- c:\documents and settings\amman\Application Data\vlc
2010-01-02 07:10 . 2009-07-21 16:13 ——– d—–w- c:\program files\Safari
2010-01-02 07:04 . 2010-01-02 07:04 79144 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-24 20:40 . 2009-07-06 04:34 ——– d—–w- c:\program files\PS3 Media Server
2009-12-21 22:07 . 2009-06-03 04:07 ——– d—–w- c:\documents and settings\amman\Application Data\Apple Computer
2009-12-19 10:01 . 2009-07-03 02:18 ——– d—–w- c:\documents and settings\amman\Application Data\Skype
2009-12-19 10:00 . 2009-07-05 00:39 ——– d—–w- c:\documents and settings\amman\Application Data\skypePM
2009-12-18 21:20 . 2009-04-30 23:35 ——– d—–w- c:\program files\Acoustica Mixcraft
2009-12-10 08:08 . 2009-10-02 14:57 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-12-08 07:23 . 2009-08-19 15:25 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-26 03:43 . 2009-10-30 05:43 768 —-a-w- c:\windows\system32\d3d8caps.dat
2009-11-17 07:17 . 2009-09-25 01:05 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\myitlab
2009-11-11 01:45 . 2009-04-27 05:09 76224 —-a-w- c:\documents and settings\amman\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-11 01:42 . 2008-10-25 20:38 ——– d—–w- c:\program files\iTunes
2009-11-11 01:22 . 2005-11-27 22:39 ——– d—–w- c:\program files\iPod
2009-11-07 10:23 . 2009-06-08 15:19 256 —-a-w- c:\windows\system32\pool.bin
2009-11-03 19:08 . 2009-04-27 00:52 360320 —-a-w- c:\windows\system32\drivers\TCPIP.SYS
2009-11-03 14:51 . 2009-11-10 05:58 421888 —-a-w- c:\documents and settings\amman\Application Data\Mozilla\Firefox\Profiles\0poab2bg.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
2009-10-29 07:45 . 2009-04-27 00:52 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 01:58 . 2009-10-29 01:58 79144 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-21 06:00 . 2009-04-27 00:52 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2009-04-27 00:51 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2004-08-03 23:00 263552 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:53 . 2009-04-27 00:51 266752 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2009-04-27 00:52 69632 —-a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2009-04-27 00:52 112128 —-a-w- c:\windows\system32\rastls.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
——- Sigcheck ——-
[-] 2009-11-03 . 3ADCE4790F591BF160A94F6F08039577 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\drivers\TCPIP.SYS
[-] 2009-11-03 . 3ADCE4790F591BF160A94F6F08039577 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\TCPIP.SYS
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\tcpip.sys
[7] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"FlashMute"="c:\program files\FlashMute\FlashMute.exe" [2006-03-11 221184]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"CARPService"="carpserv.exe" [2002-10-17 4608]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-20 114688]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"f:\\Programs\\SimpleCenter\\SimpleCenter.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\VNC4\\winvnc4.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Starcraft\\StarCraft.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24116:TCP"= 24116:TCP:BitComet 24116 TCP
"24116:UDP"= 24116:UDP:BitComet 24116 UDP
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [19/08/2009 10:25 AM 108289]
R2 DisplayLinkService;DisplayLink Service;c:\program files\DisplayLink Core Software\DisplayLinkService.exe [18/12/2008 11:27 AM 447848]
R3 DisplayLinkGA;DisplayLinkGA;c:\windows\system32\drivers\DisplayLinkGAport.sys [18/12/2008 11:27 AM 20736]
R3 DisplayLinkmirror;DisplayLinkmirror;c:\windows\system32\drivers\DisplayLinkmirrorport.sys [18/12/2008 11:27 AM 18944]
R3 DisplayLinkUsbPort;DisplayLink USB Device;c:\windows\system32\drivers\DisplayLinkUsbPort.sys [18/12/2008 7:30 PM 20992]
S2 SessionLauncher;SessionLauncher;c:\docume~1\amman\LOCALS~1\Temp\DX9\SessionLauncher.exe –> c:\docume~1\amman\LOCALS~1\Temp\DX9\SessionLauncher.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [30/04/2009 6:38 PM 721904]
.
Contents of the 'Scheduled Tasks' folder
2010-01-08 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]
2010-01-09 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]
2010-01-06 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]
.
.
——- Supplementary Scan ——-
.
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\amman\Application Data\Mozilla\Firefox\Profiles\0poab2bg.default\
FF - component: c:\documents and settings\amman\Application Data\Mozilla\Firefox\Profiles\0poab2bg.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\documents and settings\amman\Application Data\Mozilla\Firefox\Profiles\0poab2bg.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-08 19:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2800)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\FlashMute\mutelib.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\WMASF.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\program files\DisplayLink Core Software\DisplayLinkManager.exe
c:\program files\DisplayLink Core Software\DisplayLinkUI.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\carpserv.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2010-01-08 19:17:59 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-09 00:17
Pre-Run: 5,994,729,472 bytes free
Post-Run: 9,277,747,200 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 080ECF3D936197B5445A22BBB4D6BF90