The first time I ran combofix I accidentally denied internet access, without realizing that that was combofix. Combofix just kept running, so I've run it twice: once before installing the recovery console and once after. I am including both logs.
Without Recovery console:
ComboFix 10-08-15.01 - Thomas 08/15/2010 23:41:27.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.1184 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Thomas\Local Settings\Temporary Internet Files\sipip.sys
c:\documents and settings\Thomas\Local Settings\Temporary Internet Files\ubifix.vbs
C:\Install.exe
c:\windows\henasilyd.exe
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\ubadiququ.scr
c:\windows\yjosivygu.dll
.
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
((((((((((((((((((((((((( Files Created from 2010-07-16 to 2010-08-16 )))))))))))))))))))))))))))))))
.
2010-08-03 18:35 . 2010-08-03 18:35 ——– d—–w- c:\documents and settings\Thomas\Local Settings\Application Data\Symantec
2010-08-02 23:52 . 2010-08-02 23:52 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-29 22:53 . 2010-07-30 02:59 ——– d—–w- C:\4d5b36bb62f8f8ae7a6f361c383e
2010-07-29 00:11 . 2010-07-29 00:13 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 04:57 . 2010-06-13 14:26 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-08-16 04:57 . 2010-06-13 14:25 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-08-02 15:18 . 2004-01-03 01:33 65808 -c–a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-29 06:57 . 2009-12-01 18:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-29 06:28 . 2004-05-18 03:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-29 03:41 . 2010-04-26 22:42 ——– d—–w- c:\program files\megamek-0.35.13-windows
2010-07-28 21:47 . 2010-02-25 04:10 ——– d—–w- c:\program files\megamek-dev-svn-20091208
2010-07-26 17:17 . 2009-01-31 20:40 ——– d—–w- c:\program files\Steam
2010-07-08 13:34 . 2004-01-18 23:21 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-06-23 18:51 . 2009-02-02 23:41 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2010-06-23 18:51 . 2004-11-09 02:00 103936 —-a-w- c:\windows\system32\zlcommdb.dll
2010-06-23 18:51 . 2004-11-09 02:00 69120 —-a-w- c:\windows\system32\zlcomm.dll
2008-11-06 02:50 . 2008-11-06 02:50 15233 -c–a-w- c:\program files\Common Files\nycowek.ban
2008-11-06 02:50 . 2008-11-06 02:50 10961 -c–a-w- c:\program files\Common Files\ivybujyk.bat
2008-11-06 02:50 . 2008-11-06 02:50 19869 -c–a-w- c:\program files\Common Files\vimexanyb.dl
2008-11-06 02:50 . 2008-11-06 02:50 18223 -c–a-w- c:\program files\Common Files\tacyliwi._dl
2008-11-06 02:50 . 2008-11-06 02:50 16390 -c–a-w- c:\program files\Common Files\lopoq.db
2008-11-06 02:50 . 2008-11-06 02:50 13137 -c–a-w- c:\program files\Common Files\zokif.sys
2008-11-06 02:50 . 2008-11-06 02:50 10079 -c–a-w- c:\program files\Common Files\nalehuma.lib
2007-06-20 01:44 . 2007-06-20 01:43 10007784 -c–a-w- c:\program files\Azureus_2.5.0.4a_Win32.setup.exe
2001-10-06 00:21 . 2004-10-02 20:51 5331244 -c–a-w- c:\program files\icq2000b.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-11 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-08-04 180269]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"BCMSMMSG"="c:\windows\BCMSMMSG.exe" [2003-06-02 122880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-26 8523776]
"nwiz"="nwiz.exe" [2007-12-26 1626112]
"NvMediaCenter"="NvMCTray.dll" [2007-12-26 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-10-29 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-8-8 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Documents and Settings\\Thomas\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\SymEFA.sys [2/2/2010 11:55 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\BHDrvx86.sys [2/2/2010 11:54 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\cchpx86.sys [2/2/2010 11:54 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100809.001\IDSXpx86.sys [8/12/2010 11:11 PM 331640]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 11:54 PM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/12/2010 2:05 PM 102448]
S2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [10/29/2009 5:48 PM 3712]
S2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" –> c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [?]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys –> c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007Core.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]
2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007UA.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL =
mStart Page = hxxp://www.google.com
mSearch Bar =
uCustomizeSearch =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
HKCU-Run-Microsoft Works Update Detection - c:\program files\Microsoft Works\WkDetect.exe
Notify-AtiExtEvent - (no file)
AddRemove-Survival Map - c:\program files\THQ\Dawn of War - Dark Crusade\DXP2\Data\uninst.exe
AddRemove-Survival Map Packs - c:\program files\THQ\Dawn of War - Dark Crusade\DXP2\Data\scenarios\mp\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-16 00:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(964)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(3872)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\browselc.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\wdfmgr.exe
c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-08-16 00:18:06 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-16 05:17
Pre-Run: 3,048,099,840 bytes free
Post-Run: 5,674,676,224 bytes free
- - End Of File - - D89939278FD5A41D4B2FEE6971389709
With Recovery Console:
ComboFix 10-08-15.01 - Thomas 08/16/2010 0:30.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.895 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
((((((((((((((((((((((((( Files Created from 2010-07-16 to 2010-08-16 )))))))))))))))))))))))))))))))
.
2010-08-03 18:35 . 2010-08-03 18:35 ——– d—–w- c:\documents and settings\Thomas\Local Settings\Application Data\Symantec
2010-08-02 23:52 . 2010-08-02 23:52 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-29 22:53 . 2010-07-30 02:59 ——– d—–w- C:\4d5b36bb62f8f8ae7a6f361c383e
2010-07-29 00:11 . 2010-07-29 00:13 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 05:04 . 2005-03-15 19:30 5387014 —-a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-08-16 04:57 . 2010-06-13 14:26 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-08-16 04:57 . 2010-06-13 14:25 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-08-02 15:18 . 2004-01-03 01:33 65808 -c–a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-29 06:57 . 2009-12-01 18:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-29 06:28 . 2004-05-18 03:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-29 03:41 . 2010-04-26 22:42 ——– d—–w- c:\program files\megamek-0.35.13-windows
2010-07-28 21:47 . 2010-02-25 04:10 ——– d—–w- c:\program files\megamek-dev-svn-20091208
2010-07-26 17:17 . 2009-01-31 20:40 ——– d—–w- c:\program files\Steam
2010-07-08 20:29 . 2010-07-08 20:29 503808 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\msvcp71.dll
2010-07-08 20:29 . 2010-07-08 20:29 499712 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\jmc.dll
2010-07-08 20:29 . 2010-07-08 20:29 348160 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\msvcr71.dll
2010-07-08 13:34 . 2004-01-18 23:21 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-07-08 13:33 . 2010-07-08 13:33 7423488 —-a-w- c:\windows\Internet Logs\xDB2C.tmp
2010-07-08 13:32 . 2010-07-08 13:33 7423488 —-a-w- c:\windows\Internet Logs\xDB2B.tmp
2010-06-23 18:51 . 2009-02-02 23:41 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2010-06-23 18:51 . 2004-11-09 02:00 103936 —-a-w- c:\windows\system32\zlcommdb.dll
2010-06-23 18:51 . 2004-11-09 02:00 69120 —-a-w- c:\windows\system32\zlcomm.dll
2010-06-11 21:51 . 2010-06-11 21:51 3055600 —-a-w- c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 21:36 . 2010-06-11 21:36 275952 —-a-w- c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgoogletalk.dll
2008-11-06 02:50 . 2008-11-06 02:50 15233 -c–a-w- c:\program files\Common Files\nycowek.ban
2008-11-06 02:50 . 2008-11-06 02:50 10961 -c–a-w- c:\program files\Common Files\ivybujyk.bat
2008-11-06 02:50 . 2008-11-06 02:50 19869 -c–a-w- c:\program files\Common Files\vimexanyb.dl
2008-11-06 02:50 . 2008-11-06 02:50 18223 -c–a-w- c:\program files\Common Files\tacyliwi._dl
2008-11-06 02:50 . 2008-11-06 02:50 16390 -c–a-w- c:\program files\Common Files\lopoq.db
2008-11-06 02:50 . 2008-11-06 02:50 13137 -c–a-w- c:\program files\Common Files\zokif.sys
2008-11-06 02:50 . 2008-11-06 02:50 10079 -c–a-w- c:\program files\Common Files\nalehuma.lib
2007-06-20 01:44 . 2007-06-20 01:43 10007784 -c–a-w- c:\program files\Azureus_2.5.0.4a_Win32.setup.exe
2001-10-06 00:21 . 2004-10-02 20:51 5331244 -c–a-w- c:\program files\icq2000b.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-11 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-08-04 180269]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"BCMSMMSG"="c:\windows\BCMSMMSG.exe" [2003-06-02 122880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-26 8523776]
"nwiz"="nwiz.exe" [2007-12-26 1626112]
"NvMediaCenter"="NvMCTray.dll" [2007-12-26 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-10-29 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-8-8 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Documents and Settings\\Thomas\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\SymEFA.sys [2/2/2010 11:55 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\BHDrvx86.sys [2/2/2010 11:54 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\cchpx86.sys [2/2/2010 11:54 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100809.001\IDSXpx86.sys [8/12/2010 11:11 PM 331640]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 11:54 PM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/12/2010 2:05 PM 102448]
S2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [10/29/2009 5:48 PM 3712]
S2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" –> c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [?]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys –> c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007Core.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]
2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007UA.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL =
mStart Page = hxxp://www.google.com
mSearch Bar =
uCustomizeSearch =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-16 00:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(964)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(876)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2010-08-16 00:40:45
ComboFix-quarantined-files.txt 2010-08-16 05:40
ComboFix2.txt 2010-08-16 05:18
Pre-Run: 5,664,669,696 bytes free
Post-Run: 5,627,691,008 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - B53ED070033AF192C638E969F0F15B44