brian_723
it did not create log first time ,don't reckon it even did everything correct but now after rerunning i have a log file .
ComboFix 10-06-28.01 - Administrator 29/06/2010 16:49:22.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1048 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ADMINI~1\LOCALS~1\Temp\install_flash_player.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Packet.dll
c:\windows\system32\Process.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))))
.
2010-06-23 14:26 . 2010-06-23 14:26 ——– d—–w- C:\_OTL
2010-06-20 09:03 . 2010-06-20 09:03 ——– d—–w- c:\program files\Common Files\HP
2010-06-20 09:01 . 2009-02-11 11:03 589824 —-a-w- c:\windows\system32\hpost_d02c.dll
2010-06-20 09:01 . 2009-02-11 11:03 712704 —-a-w- c:\windows\system32\hposwia_d02c.dll
2010-06-20 09:01 . 2009-02-11 11:03 315392 —-a-w- c:\windows\system32\hposc_d02a.dll
2010-06-20 08:57 . 2010-06-20 09:05 137724 —-a-w- c:\windows\hpoins44.dat
2010-06-20 08:57 . 2010-01-30 13:02 512 ——w- c:\windows\hpomdl44.dat
2010-06-20 08:51 . 2008-10-28 10:27 372736 —-a-r- c:\windows\system32\hppldcoi.dll
2010-06-20 08:51 . 2008-10-28 10:27 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-06-18 17:27 . 2010-06-18 17:27 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2010-06-18 17:27 . 2010-06-18 17:27 30104 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-06-18 17:24 . 2010-06-18 17:30 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-06-16 18:39 . 2010-06-16 18:39 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-15 16:00 . 2010-06-15 16:00 133648 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-15 16:00 . 2010-06-15 16:00 133720 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-14 18:59 . 2010-06-14 18:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\Google Chrome Backup
2010-06-13 11:11 . 2010-06-13 11:11 ——– d—–w- c:\program files\Trend Micro
2010-06-09 15:31 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-30 21:28 . 2010-05-30 21:28 ——– d—–w- c:\windows\XSxS
2010-05-30 21:28 . 2010-05-30 21:28 ——– d—–w- c:\program files\Xenocode
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-29 16:14 . 2010-01-12 20:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-06-29 15:39 . 2009-06-15 07:38 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-27 21:57 . 2009-06-27 01:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\uTorrent
2010-06-27 21:18 . 2010-01-17 00:08 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2010-06-27 20:29 . 2009-06-17 23:47 ——– d—–w- c:\program files\Opera
2010-06-20 09:00 . 2009-01-25 11:55 ——– d—–w- c:\program files\HP
2010-06-18 17:25 . 2009-08-16 22:18 ——– d—–w- c:\program files\AVG
2010-06-14 18:58 . 2009-06-15 07:18 70400 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-12 22:55 . 2010-01-21 21:24 ——– d—–w- c:\program files\UltraISO
2010-06-12 22:33 . 2009-01-25 11:57 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-06-12 12:20 . 2009-06-18 01:16 ——– d—–w- c:\program files\Aspell
2010-06-12 12:19 . 2009-12-31 18:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-12 12:18 . 2009-06-27 01:51 ——– d—–w- c:\program files\LimeWire
2010-06-12 12:15 . 2009-06-13 00:33 ——– d—–w- c:\program files\GemMaster
2010-06-09 22:12 . 2010-02-27 23:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-05 12:55 . 2009-06-20 14:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-01 15:31 . 2009-06-27 01:34 ——– d—–w- c:\program files\uTorrent
2010-05-24 21:39 . 2009-10-01 18:26 ——– d—–w- c:\program files\CCleaner
2010-05-24 19:18 . 2009-01-25 23:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\HPAppData
2010-05-23 12:40 . 2009-12-01 23:14 ——– d—–w- c:\program files\QuickTime
2010-05-23 12:38 . 2010-05-23 12:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-05-23 12:33 . 2010-05-23 11:03 ——– d—–w- c:\program files\CodeStuff
2010-05-16 10:40 . 2010-05-01 11:31 57344 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-16 10:40 . 2010-05-01 11:18 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-05-16 10:39 . 2010-05-01 11:25 ——– d—–w- c:\program files\DivX
2010-05-16 10:37 . 2010-05-16 10:37 144696 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-08 21:52 . 2010-01-17 16:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-06 10:41 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-05 19:36 . 2010-01-12 20:32 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-05-05 19:36 . 2010-01-12 20:32 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-05-03 14:59 . 2010-05-03 14:59 ——– d—–w- c:\program files\Common Files\AOLSHARE
2010-05-03 14:59 . 2010-05-03 14:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\AOL
2010-05-02 05:22 . 2004-08-10 11:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-05-01 11:29 . 2010-05-01 11:29 ——– d—–w- c:\documents and settings\Administrator\Application Data\DivX
2010-05-01 11:18 . 2010-05-01 11:31 1180952 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-29 14:39 . 2010-01-17 16:49 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2010-01-17 16:49 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:30 . 2004-08-10 11:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-07 21:31 . 2010-04-07 21:31 5607 —-a-w- c:\windows\~GLH0001.TMP
2010-04-07 21:31 . 2010-04-07 21:31 27136 —-a-w- c:\windows\~GLH0000.TMP
2010-04-07 21:31 . 2010-04-07 21:31 140288 —-a-w- c:\windows\~GLC0000.TMP
2010-03-31 16:33 . 2009-06-20 00:38 335 —-a-w- c:\windows\nsreg.dat
.
——- Sigcheck ——-
[-] 2009-12-30 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2009-12-30 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
c:\windows\System32\ctfmon.exe … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-20 340456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^WWU.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\WWU.lnk
backup=c:\windows\pss\WWU.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Launchy.lnk
backup=c:\windows\pss\Launchy.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-06-16 11:55 133104 —-atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ThreatFire"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\Charon.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1270674119\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1270674119\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24884:TCP"= 24884:TCP:BitComet 24884 TCP
"24884:UDP"= 24884:UDP:BitComet 24884 UDP
"20482:TCP"= 20482:TCP:BitComet 20482 TCP
"20482:UDP"= 20482:UDP:BitComet 20482 UDP
"9067:TCP"= 9067:TCP:BitComet 9067 TCP(ED2K)
"9067:UDP"= 9067:UDP:BitComet 9067 UDP(ED2K)
"9751:TCP"= 9751:TCP:BitComet 9751 TCP(ED2K)
"9751:UDP"= 9751:UDP:BitComet 9751 UDP(ED2K)
"7043:TCP"= 7043:TCP:BitComet 7043 TCP
"7043:UDP"= 7043:UDP:BitComet 7043 UDP
"10255:TCP"= 10255:TCP:BitComet 10255 TCP
"10255:UDP"= 10255:UDP:BitComet 10255 UDP
"8343:TCP"= 8343:TCP:BitComet 8343 TCP
"8343:UDP"= 8343:UDP:BitComet 8343 UDP
"7175:TCP"= 7175:TCP:BitComet 7175 TCP
"7175:UDP"= 7175:UDP:BitComet 7175 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [14/10/2009 21:18 36880]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [14/01/2010 23:45 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [14/01/2010 23:46 59664]
R1 wbsecdrv;wbsecdrv Protocol Driver;c:\windows\system32\drivers\wbsecdrv.sys [08/04/2010 17:15 17952]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R2 wbsecsvc;wbsecsvc;c:\windows\system32\wbsecsvc.exe [08/04/2010 17:15 274432]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/10/2009 19:39 19472]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [14/01/2010 23:46 33552]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [18/06/2010 18:27 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [18/06/2010 18:27 30104]
S3 W35UND;IS89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\drivers\W35UND.SYS [08/04/2010 17:15 117632]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [24/10/2009 16:55 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 16:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1326574676-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 11:55]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1326574676-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 11:55]
2010-06-29 c:\windows\Tasks\User_Feed_Synchronization-{FFFA57F7-E474-4C3A-9B66-7535F0F662CF}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.co.uk/aolbroadband
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.myaolbroadband.co.uk
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
IE: &D&ownload &with BitComet
IE: &D&ownload all video with BitComet
IE: &D&ownload all with BitComet
IE: &Download by Orbit
IE: &Grab video by Orbit
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Do&wnload selected by Orbit
IE: Down&load all by Orbit
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}\platform\WINNT_x86-msvc\components\enbar3.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\NPMetaStream3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
user_pref('capability.policy.policynames', 'localfilelinks');user_pref('capability.policy.localfilelinks.sites', 'hxxp://www.webmynd.com http://www.google.com');user_pref('…ri.enabled', 'allAccess');.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-avgrsstarter - (no file)
MSConfigStartUp-Advanced SystemCare 3 - c:\program files\IObit\Advanced SystemCare 3\AWC.exe
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-DU Meter - c:\program files\DU Meter\DUMeter.exe
MSConfigStartUp-ISW - c:\program files\CheckPoint\ZAForceField\ForceField.exe
MSConfigStartUp-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
MSConfigStartUp-ZoneAlarm Client - c:\program files\Zone Labs\ZoneAlarm\zlclient.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-29 17:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ThreatFire]
"AlternateImagePath"=""
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-789336058-1326574676-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,43,8e,9a,c0,2d,a6,4c,43,85,76,45,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,da,72,39,5d,4b,78,90,4a,99,93,8e,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,43,8e,9a,c0,2d,a6,4c,43,85,76,45,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1372)
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\program files\ThreatFire\TFWAH.dll
- - - - - - - > 'lsass.exe'(1428)
c:\program files\ThreatFire\TFWAH.dll
- - - - - - - > 'explorer.exe'(1128)
c:\windows\system32\WININET.dll
c:\program files\ThreatFire\TfWah.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\program files\ThreatFire\TFNI.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\ThreatFire\TFService.exe
c:\windows\wanmpsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2010-06-29 17:28:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-29 16:28
Pre-Run: 56,320,016,384 bytes free
Post-Run: 56,529,436,672 bytes free
- - End Of File - - 1E6E78B3ECEC92B98A729DD24D824CFD
ComboFix 10-06-28.01 - Administrator 29/06/2010 16:49:22.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1048 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ADMINI~1\LOCALS~1\Temp\install_flash_player.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Packet.dll
c:\windows\system32\Process.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
——-\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))))
.
2010-06-23 14:26 . 2010-06-23 14:26 ——– d—–w- C:\_OTL
2010-06-20 09:03 . 2010-06-20 09:03 ——– d—–w- c:\program files\Common Files\HP
2010-06-20 09:01 . 2009-02-11 11:03 589824 —-a-w- c:\windows\system32\hpost_d02c.dll
2010-06-20 09:01 . 2009-02-11 11:03 712704 —-a-w- c:\windows\system32\hposwia_d02c.dll
2010-06-20 09:01 . 2009-02-11 11:03 315392 —-a-w- c:\windows\system32\hposc_d02a.dll
2010-06-20 08:57 . 2010-06-20 09:05 137724 —-a-w- c:\windows\hpoins44.dat
2010-06-20 08:57 . 2010-01-30 13:02 512 ——w- c:\windows\hpomdl44.dat
2010-06-20 08:51 . 2008-10-28 10:27 372736 —-a-r- c:\windows\system32\hppldcoi.dll
2010-06-20 08:51 . 2008-10-28 10:27 309760 —-a-r- c:\windows\system32\difxapi.dll
2010-06-18 17:27 . 2010-06-18 17:27 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2010-06-18 17:27 . 2010-06-18 17:27 30104 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-06-18 17:24 . 2010-06-18 17:30 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-06-16 18:39 . 2010-06-16 18:39 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-15 16:00 . 2010-06-15 16:00 133648 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\rollback\patch\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-15 16:00 . 2010-06-15 16:00 133720 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav9exec\9.0.0.736\mmpprtc.dll
2010-06-14 18:59 . 2010-06-14 18:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\Google Chrome Backup
2010-06-13 11:11 . 2010-06-13 11:11 ——– d—–w- c:\program files\Trend Micro
2010-06-09 15:31 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-30 21:28 . 2010-05-30 21:28 ——– d—–w- c:\windows\XSxS
2010-05-30 21:28 . 2010-05-30 21:28 ——– d—–w- c:\program files\Xenocode
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-29 16:14 . 2010-01-12 20:30 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2010-06-29 15:39 . 2009-06-15 07:38 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-27 21:57 . 2009-06-27 01:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\uTorrent
2010-06-27 21:18 . 2010-01-17 00:08 ——– d—–w- c:\documents and settings\Administrator\Application Data\vlc
2010-06-27 20:29 . 2009-06-17 23:47 ——– d—–w- c:\program files\Opera
2010-06-20 09:00 . 2009-01-25 11:55 ——– d—–w- c:\program files\HP
2010-06-18 17:25 . 2009-08-16 22:18 ——– d—–w- c:\program files\AVG
2010-06-14 18:58 . 2009-06-15 07:18 70400 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-12 22:55 . 2010-01-21 21:24 ——– d—–w- c:\program files\UltraISO
2010-06-12 22:33 . 2009-01-25 11:57 ——– d—–w- c:\documents and settings\All Users\Application Data\HP
2010-06-12 12:20 . 2009-06-18 01:16 ——– d—–w- c:\program files\Aspell
2010-06-12 12:19 . 2009-12-31 18:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-12 12:18 . 2009-06-27 01:51 ——– d—–w- c:\program files\LimeWire
2010-06-12 12:15 . 2009-06-13 00:33 ——– d—–w- c:\program files\GemMaster
2010-06-09 22:12 . 2010-02-27 23:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-05 12:55 . 2009-06-20 14:29 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-01 15:31 . 2009-06-27 01:34 ——– d—–w- c:\program files\uTorrent
2010-05-24 21:39 . 2009-10-01 18:26 ——– d—–w- c:\program files\CCleaner
2010-05-24 19:18 . 2009-01-25 23:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\HPAppData
2010-05-23 12:40 . 2009-12-01 23:14 ——– d—–w- c:\program files\QuickTime
2010-05-23 12:38 . 2010-05-23 12:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-05-23 12:33 . 2010-05-23 11:03 ——– d—–w- c:\program files\CodeStuff
2010-05-16 10:40 . 2010-05-01 11:31 57344 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-16 10:40 . 2010-05-01 11:18 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-05-16 10:39 . 2010-05-01 11:25 ——– d—–w- c:\program files\DivX
2010-05-16 10:37 . 2010-05-16 10:37 144696 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-08 21:52 . 2010-01-17 16:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-06 10:41 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-05 19:36 . 2010-01-12 20:32 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-05-05 19:36 . 2010-01-12 20:32 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-05-03 14:59 . 2010-05-03 14:59 ——– d—–w- c:\program files\Common Files\AOLSHARE
2010-05-03 14:59 . 2010-05-03 14:59 ——– d—–w- c:\documents and settings\Administrator\Application Data\AOL
2010-05-02 05:22 . 2004-08-10 11:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-05-01 11:29 . 2010-05-01 11:29 ——– d—–w- c:\documents and settings\Administrator\Application Data\DivX
2010-05-01 11:18 . 2010-05-01 11:31 1180952 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-29 14:39 . 2010-01-17 16:49 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39 . 2010-01-17 16:49 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-20 05:30 . 2004-08-10 11:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-07 21:31 . 2010-04-07 21:31 5607 —-a-w- c:\windows\~GLH0001.TMP
2010-04-07 21:31 . 2010-04-07 21:31 27136 —-a-w- c:\windows\~GLH0000.TMP
2010-04-07 21:31 . 2010-04-07 21:31 140288 —-a-w- c:\windows\~GLC0000.TMP
2010-03-31 16:33 . 2009-06-20 00:38 335 —-a-w- c:\windows\nsreg.dat
.
——- Sigcheck ——-
[-] 2009-12-30 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2009-12-30 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
c:\windows\System32\ctfmon.exe … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-20 340456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^WWU.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\WWU.lnk
backup=c:\windows\pss\WWU.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Launchy.lnk
backup=c:\windows\pss\Launchy.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-06-16 11:55 133104 —-atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ThreatFire"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\Charon.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1270674119\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1270674119\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24884:TCP"= 24884:TCP:BitComet 24884 TCP
"24884:UDP"= 24884:UDP:BitComet 24884 UDP
"20482:TCP"= 20482:TCP:BitComet 20482 TCP
"20482:UDP"= 20482:UDP:BitComet 20482 UDP
"9067:TCP"= 9067:TCP:BitComet 9067 TCP(ED2K)
"9067:UDP"= 9067:UDP:BitComet 9067 UDP(ED2K)
"9751:TCP"= 9751:TCP:BitComet 9751 TCP(ED2K)
"9751:UDP"= 9751:UDP:BitComet 9751 UDP(ED2K)
"7043:TCP"= 7043:TCP:BitComet 7043 TCP
"7043:UDP"= 7043:UDP:BitComet 7043 UDP
"10255:TCP"= 10255:TCP:BitComet 10255 TCP
"10255:UDP"= 10255:UDP:BitComet 10255 UDP
"8343:TCP"= 8343:TCP:BitComet 8343 TCP
"8343:UDP"= 8343:UDP:BitComet 8343 UDP
"7175:TCP"= 7175:TCP:BitComet 7175 TCP
"7175:UDP"= 7175:UDP:BitComet 7175 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [14/10/2009 21:18 36880]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [14/01/2010 23:45 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [14/01/2010 23:46 59664]
R1 wbsecdrv;wbsecdrv Protocol Driver;c:\windows\system32\drivers\wbsecdrv.sys [08/04/2010 17:15 17952]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service –> c:\program files\ThreatFire\TFService.exe service [?]
R2 wbsecsvc;wbsecsvc;c:\windows\system32\wbsecsvc.exe [08/04/2010 17:15 274432]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/10/2009 19:39 19472]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [14/01/2010 23:46 33552]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [18/06/2010 18:27 30104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [18/06/2010 18:27 30104]
S3 W35UND;IS89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\drivers\W35UND.SYS [08/04/2010 17:15 117632]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [24/10/2009 16:55 717296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 16:34 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1326574676-839522115-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 11:55]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-1326574676-839522115-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-16 11:55]
2010-06-29 c:\windows\Tasks\User_Feed_Synchronization-{FFFA57F7-E474-4C3A-9B66-7535F0F662CF}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.co.uk/aolbroadband
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://www.myaolbroadband.co.uk
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
IE: &D&ownload &with BitComet
IE: &D&ownload all video with BitComet
IE: &D&ownload all with BitComet
IE: &Download by Orbit
IE: &Grab video by Orbit
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Do&wnload selected by Orbit
IE: Down&load all by Orbit
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0a6g1p7l.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}\platform\WINNT_x86-msvc\components\enbar3.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\KavLinkFilter.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Opera\program\plugins\NPMetaStream3.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
user_pref('capability.policy.policynames', 'localfilelinks');user_pref('capability.policy.localfilelinks.sites', 'hxxp://www.webmynd.com http://www.google.com');user_pref('…ri.enabled', 'allAccess');.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Notify-avgrsstarter - (no file)
MSConfigStartUp-Advanced SystemCare 3 - c:\program files\IObit\Advanced SystemCare 3\AWC.exe
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-DU Meter - c:\program files\DU Meter\DUMeter.exe
MSConfigStartUp-ISW - c:\program files\CheckPoint\ZAForceField\ForceField.exe
MSConfigStartUp-MSSE - c:\program files\Microsoft Security Essentials\msseces.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
MSConfigStartUp-ZoneAlarm Client - c:\program files\Zone Labs\ZoneAlarm\zlclient.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-29 17:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ThreatFire]
"AlternateImagePath"=""
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-789336058-1326574676-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,43,8e,9a,c0,2d,a6,4c,43,85,76,45,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,da,72,39,5d,4b,78,90,4a,99,93,8e,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,43,8e,9a,c0,2d,a6,4c,43,85,76,45,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1372)
c:\program files\ThreatFire\TFNI.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\program files\ThreatFire\TFWAH.dll
- - - - - - - > 'lsass.exe'(1428)
c:\program files\ThreatFire\TFWAH.dll
- - - - - - - > 'explorer.exe'(1128)
c:\windows\system32\WININET.dll
c:\program files\ThreatFire\TfWah.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\program files\ThreatFire\TFNI.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\ThreatFire\TFMon.dll
c:\program files\ThreatFire\TFRK.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\ThreatFire\TFService.exe
c:\windows\wanmpsvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2010-06-29 17:28:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-29 16:28
Pre-Run: 56,320,016,384 bytes free
Post-Run: 56,529,436,672 bytes free
- - End Of File - - 1E6E78B3ECEC92B98A729DD24D824CFD