joeyfor
Awesome! Combofix ran! What next?
ComboFix 11-06-22.02 - ClientB 06/22/2011 15:48:26.1.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1980.1699 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\explorer.com.exe
AV: McAfee VirusScan Enterprise *Enabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\ClientB\0.781263767129598.exe
c:\documents and settings\ClientB\Application Data\PriceGong
c:\documents and settings\ClientB\Application Data\PriceGong\Data\1.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\a.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\b.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\c.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\d.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\e.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\f.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\g.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\h.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\i.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\J.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\k.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\l.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\m.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\n.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\o.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\p.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\q.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\r.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\s.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\t.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\u.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\v.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\w.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\x.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\y.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\z.xml
c:\documents and settings\ClientB\GoToAssistDownloadHelper.exe
c:\documents and settings\ClientB\Local Settings\Application Data\lwu.exe
c:\documents and settings\ClientB\Local Settings\Application Data\o80ys.dll
c:\documents and settings\Pharmadmin\GoToAssistDownloadHelper.exe
C:\LOGC.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-05-22 to 2011-06-22 )))))))))))))))))))))))))))))))
.
.
2011-06-22 21:42 . 2011-06-22 21:42 ——– d—–w- C:\explorer.com
2011-06-22 20:12 . 2011-06-22 20:12 ——– d—–w- c:\documents and settings\Administrator\Application Data\Windows Search
2011-06-22 20:11 . 2011-06-22 20:11 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2011-06-20 14:09 . 2011-06-20 14:09 0 —ha-w- c:\documents and settings\ClientB\oxdcrkgbmw.tmp
2011-06-18 05:33 . 2011-06-18 05:33 169472 —-a-w- c:\windows\system32\moricons32.dll
2011-06-18 05:33 . 2011-06-18 05:33 349696 —-a-w- c:\windows\system32\AmRes_ro32.dll
2011-06-16 20:33 . 2011-04-21 13:37 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-06-16 17:04 . 2011-06-16 17:04 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2011-06-15 21:31 . 2011-06-15 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-06-15 21:31 . 2011-06-15 21:32 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-06-15 20:28 . 2011-06-15 20:28 102400 —-a-w- c:\windows\RegBootClean.exe
2011-06-15 20:16 . 2010-09-06 09:26 189520 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2011-06-15 20:07 . 2011-06-15 20:07 ——– d—–w- c:\documents and settings\ClientB\Application Data\Malwarebytes
2011-06-15 20:07 . 2011-06-15 20:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-15 20:07 . 2011-05-29 15:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-15 20:07 . 2011-06-15 20:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-15 13:55 . 2011-06-15 21:19 ——– d—–w- c:\documents and settings\ClientB\Application Data\Sammsoft
2011-06-15 13:55 . 2011-06-15 20:50 ——– d—–w- c:\documents and settings\ClientB\Local Settings\Application Data\AskToolbar
2011-06-15 13:55 . 2011-06-15 13:55 ——– d—–w- c:\program files\Ask.com
2011-06-15 13:55 . 2011-06-15 13:55 ——– d—–w- C:\Firefox
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-22 21:52 . 2010-11-14 19:31 0 —-a-w- c:\documents and settings\ClientB\Local Settings\Application Data\WavXMapDrive.bat
2011-05-02 15:31 . 2008-04-25 21:27 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2008-04-25 16:16 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11 . 2008-04-25 16:16 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2008-04-25 16:16 43520 ——w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2008-04-25 16:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2008-04-25 16:16 385024 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2008-04-25 16:16 105472 —-a-w- c:\windows\system32\drivers\mup.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-02 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{018D0349-18BA-40B5-A01C-BA1CD7A107Df}]
2011-06-18 05:33 349696 —-a-w- c:\windows\system32\AmRes_ro32.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-02-02 01:17 1487240 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E5EBBA2A-83C0-7D2F-0E9B-290F17849D62}]
2011-06-18 05:33 169472 —-a-w- c:\windows\system32\moricons32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-02 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-02 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2010-03-29 16:45 62832 —-a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-22 1044480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-28 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-28 142872]
"IAStorIcon"="c:\program files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2010-07-21 159616]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2010-06-22 34232]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-01-16 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-04-30 124240]
"MPSUpg"="c:\autotask\update.vbs" [2010-10-25 38294]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\moricons32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [8/25/2010 12:39 PM 24064]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [8/25/2010 9:03 AM 13336]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\engineserver.exe [4/29/2009 7:07 PM 21256]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [11/3/2010 7:35 AM 70216]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [8/25/2010 9:07 AM 2066968]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [8/25/2010 12:39 PM 168616]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/15/2011 2:07 PM 39984]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [11/3/2010 7:35 AM 65224]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 10:16 AM 14336]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-22 c:\windows\Tasks\Free File Viewer Update Checker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2010-12-09 17:25]
.
2011-06-22 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-02-02 01:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
TCP: Interfaces\{D179768E-A390-42E7-80C9-3A6B7DBB09FC}: NameServer = 10.100.192.2
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
BHO-{1631550F-191D-4826-B069-D9439253D926} - (no file)
ShellIconOverlayIdentifiers-{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A} - c:\documents and settings\ClientB\Local Settings\Application Data\o80ys.dll
HKCU-Run-Weather - c:\program files\AWS\WeatherBug\Weather.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-22 15:52
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3148)
c:\windows\system32\WININET.dll
c:\windows\system32\igfxdo.dll
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\AMT\LMS.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\McAfee\VirusScan Enterprise\mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\documents and settings\All Users\Application Data\WeCareReminder\ReminderHelper.exe
c:\pharmsuite\Businfo.exe
.
**************************************************************************
.
Completion time: 2011-06-22 15:55:07 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-22 21:55
.
Pre-Run: 148,482,469,888 bytes free
Post-Run: 148,421,582,848 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 6EAB5A2FA716E87D520B92381681E9E1
ComboFix 11-06-22.02 - ClientB 06/22/2011 15:48:26.1.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1980.1699 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\explorer.com.exe
AV: McAfee VirusScan Enterprise *Enabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\ClientB\0.781263767129598.exe
c:\documents and settings\ClientB\Application Data\PriceGong
c:\documents and settings\ClientB\Application Data\PriceGong\Data\1.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\a.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\b.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\c.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\d.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\e.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\f.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\g.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\h.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\i.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\J.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\k.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\l.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\m.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\n.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\o.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\p.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\q.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\r.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\s.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\t.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\u.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\v.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\w.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\x.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\y.xml
c:\documents and settings\ClientB\Application Data\PriceGong\Data\z.xml
c:\documents and settings\ClientB\GoToAssistDownloadHelper.exe
c:\documents and settings\ClientB\Local Settings\Application Data\lwu.exe
c:\documents and settings\ClientB\Local Settings\Application Data\o80ys.dll
c:\documents and settings\Pharmadmin\GoToAssistDownloadHelper.exe
C:\LOGC.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-05-22 to 2011-06-22 )))))))))))))))))))))))))))))))
.
.
2011-06-22 21:42 . 2011-06-22 21:42 ——– d—–w- C:\explorer.com
2011-06-22 20:12 . 2011-06-22 20:12 ——– d—–w- c:\documents and settings\Administrator\Application Data\Windows Search
2011-06-22 20:11 . 2011-06-22 20:11 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2011-06-20 14:09 . 2011-06-20 14:09 0 —ha-w- c:\documents and settings\ClientB\oxdcrkgbmw.tmp
2011-06-18 05:33 . 2011-06-18 05:33 169472 —-a-w- c:\windows\system32\moricons32.dll
2011-06-18 05:33 . 2011-06-18 05:33 349696 —-a-w- c:\windows\system32\AmRes_ro32.dll
2011-06-16 20:33 . 2011-04-21 13:37 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-06-16 17:04 . 2011-06-16 17:04 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2011-06-15 21:31 . 2011-06-15 21:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-06-15 21:31 . 2011-06-15 21:32 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-06-15 20:28 . 2011-06-15 20:28 102400 —-a-w- c:\windows\RegBootClean.exe
2011-06-15 20:16 . 2010-09-06 09:26 189520 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2011-06-15 20:07 . 2011-06-15 20:07 ——– d—–w- c:\documents and settings\ClientB\Application Data\Malwarebytes
2011-06-15 20:07 . 2011-06-15 20:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-15 20:07 . 2011-05-29 15:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-15 20:07 . 2011-06-15 20:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-15 13:55 . 2011-06-15 21:19 ——– d—–w- c:\documents and settings\ClientB\Application Data\Sammsoft
2011-06-15 13:55 . 2011-06-15 20:50 ——– d—–w- c:\documents and settings\ClientB\Local Settings\Application Data\AskToolbar
2011-06-15 13:55 . 2011-06-15 13:55 ——– d—–w- c:\program files\Ask.com
2011-06-15 13:55 . 2011-06-15 13:55 ——– d—–w- C:\Firefox
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-22 21:52 . 2010-11-14 19:31 0 —-a-w- c:\documents and settings\ClientB\Local Settings\Application Data\WavXMapDrive.bat
2011-05-02 15:31 . 2008-04-25 21:27 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2008-04-25 16:16 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11 . 2008-04-25 16:16 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2008-04-25 16:16 43520 ——w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2008-04-25 16:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2008-04-25 16:16 385024 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2008-04-25 16:16 105472 —-a-w- c:\windows\system32\drivers\mup.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-02 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{018D0349-18BA-40B5-A01C-BA1CD7A107Df}]
2011-06-18 05:33 349696 —-a-w- c:\windows\system32\AmRes_ro32.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-02-02 01:17 1487240 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E5EBBA2A-83C0-7D2F-0E9B-290F17849D62}]
2011-06-18 05:33 169472 —-a-w- c:\windows\system32\moricons32.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-02 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-02-02 1487240]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2010-03-29 16:45 62832 —-a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-06-22 1044480]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-28 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-28 142872]
"IAStorIcon"="c:\program files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2010-07-21 159616]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2010-06-22 34232]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2009-01-16 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2009-04-30 124240]
"MPSUpg"="c:\autotask\update.vbs" [2010-10-25 38294]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\moricons32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [8/25/2010 12:39 PM 24064]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [8/25/2010 9:03 AM 13336]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\engineserver.exe [4/29/2009 7:07 PM 21256]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [11/3/2010 7:35 AM 70216]
R2 UNS;Intel® Management and Security Application User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [8/25/2010 9:07 AM 2066968]
R3 e1kexpress;Intel® PRO/1000 PCI Express Network Connection Driver K;c:\windows\system32\drivers\e1k5132.sys [8/25/2010 12:39 PM 168616]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/15/2011 2:07 PM 39984]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [11/3/2010 7:35 AM 65224]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 10:16 AM 14336]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-22 c:\windows\Tasks\Free File Viewer Update Checker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2010-12-09 17:25]
.
2011-06-22 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-02-02 01:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
TCP: Interfaces\{D179768E-A390-42E7-80C9-3A6B7DBB09FC}: NameServer = 10.100.192.2
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
BHO-{1631550F-191D-4826-B069-D9439253D926} - (no file)
ShellIconOverlayIdentifiers-{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A} - c:\documents and settings\ClientB\Local Settings\Application Data\o80ys.dll
HKCU-Run-Weather - c:\program files\AWS\WeatherBug\Weather.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-22 15:52
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3148)
c:\windows\system32\WININET.dll
c:\windows\system32\igfxdo.dll
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\AMT\LMS.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\McAfee\VirusScan Enterprise\mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\documents and settings\All Users\Application Data\WeCareReminder\ReminderHelper.exe
c:\pharmsuite\Businfo.exe
.
**************************************************************************
.
Completion time: 2011-06-22 15:55:07 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-22 21:55
.
Pre-Run: 148,482,469,888 bytes free
Post-Run: 148,421,582,848 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 6EAB5A2FA716E87D520B92381681E9E1