giambino
Here is the combofix.txt that was done on 7/21: ( Also in that folder was Combofix-quarantined-files.txt ( I copied that file at the end ))
ComboFix 12-07-21.01 - Kevin 07/22/2012 7:12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.538 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
c:\program files\FunWebProducts
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000019_.tmp.dll
c:\windows\system32\_000020_.tmp.dll
c:\windows\system32\_000021_.tmp.dll
c:\windows\system32\_000022_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
.
.
2012-07-22 05:38 . 2012-07-22 05:38 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\offreg.dll
2012-07-22 05:38 . 2012-07-22 05:38 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys
2012-07-22 05:37 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\mpengine.dll
2012-07-22 02:26 . 2012-07-22 02:26 ——– d—–w- C:\_OTL
2012-07-22 02:23 . 2012-07-22 02:23 ——– d—–w- c:\program files\ERUNT
2012-07-21 19:49 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-08 22:07 . 2012-07-08 22:08 ——– d—–w- c:\program files\Microsoft Security Client
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-11 22:53 . 2012-04-17 10:20 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 22:53 . 2011-05-16 11:34 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:19 . 2005-08-16 10:18 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2010-10-01 22:16 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2005-08-16 10:18 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2005-08-16 10:18 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2009-08-07 00:24 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2005-08-16 10:40 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2005-08-16 10:40 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2005-08-16 10:40 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2009-08-07 00:24 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2005-08-16 10:40 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2005-08-16 10:40 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2005-08-16 10:18 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2009-08-07 00:24 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2005-08-16 10:40 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2005-08-16 10:40 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2010-10-02 02:57 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2010-10-02 02:57 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2010-10-02 02:57 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2005-08-16 10:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2005-08-16 10:18 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2005-08-16 10:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2005-08-16 10:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2005-08-16 10:18 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2005-08-16 10:18 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-04 04:59 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2005-08-16 10:37 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2010-03-11 04:01 . 2010-03-11 04:01 124272 —-a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-03-11 04:40 . 2010-03-11 04:40 13168 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-03-11 04:02 . 2010-03-11 04:02 70512 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-03-11 04:01 . 2010-03-11 04:01 91504 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-03-11 04:01 . 2010-03-11 04:01 22384 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-03-11 04:00 . 2010-03-11 04:00 255344 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-03-11 04:01 . 2010-03-11 04:01 31088 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-03-11 04:01 . 2010-03-11 04:01 40304 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2009-10-05 17:49 . 2009-10-05 17:49 652640 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-03-11 04:02 . 2010-03-11 04:02 23920 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-07-20 10:44 . 2011-05-02 21:54 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-12-19 26112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-13 1117184]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-03-11 300400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
c:\documents and settings\Kevin\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Content Manager Assistant for PlayStation®.lnk - c:\program files\Sony\Content Manager Assistant\CMA.exe [2012-1-26 2520504]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-12-19 24576]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [10/5/2009 10:08 AM 65584]
R1 MpKsladdc328d;MpKsladdc328d;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys [7/22/2012 1:38 AM 29904]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/17/2012 6:20 AM 250056]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4/25/2012 7:46 AM 113120]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2/13/2009 3:02 PM 11520]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLADDC328D
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 22:53]
.
2012-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-07-22 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell4me.com/myway
Trusted Zone: musicmatch.com\online
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yankees.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Apple - c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
HKU-Default-Run-Apple - c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-22 07:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-22 07:19:29
ComboFix-quarantined-files.txt 2012-07-22 11:19
.
Pre-Run: 42,415,812,608 bytes free
Post-Run: 42,381,115,392 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 38382EB380F25AFCAD75D503E831D4B4
2012-07-22 11:18:35 . 2012-07-22 11:18:35 230 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKU-Default-Run-Apple.reg.dat
2012-07-22 11:18:33 . 2012-07-22 11:18:33 228 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Apple.reg.dat
2012-07-22 11:15:19 . 2012-07-22 11:15:19 6,241 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2012-07-22 11:08:04 . 2012-07-22 11:08:05 51 —-a-w- C:\Qoobox\Quarantine\catchme.log
2012-07-15 04:39:29 . 2012-07-15 04:39:30 566,784 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll.vir
2005-08-16 10:18:45 . 2008-04-14 09:42:10 132,096 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000008_.tmp.dll.vir
2005-08-16 10:18:43 . 2008-04-14 05:00:12 1,845,632 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000010_.tmp.dll.vir
2005-08-16 10:18:36 . 2008-04-14 09:42:36 108,544 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000019_.tmp.dll.vir
2005-08-16 10:18:29 . 2008-04-14 09:41:26 706,048 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000020_.tmp.dll.vir
2005-08-16 10:18:22 . 2008-04-14 09:41:58 728,064 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000021_.tmp.dll.vir
2005-08-16 10:18:22 . 2008-04-14 09:41:58 343,040 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000006_.tmp.dll.vir
2005-08-16 10:18:21 . 2008-04-14 09:41:58 989,696 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000007_.tmp.dll.vir
2005-08-16 10:18:07 . 2008-04-14 09:41:52 32,256 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000009_.tmp.dll.vir
2005-08-16 10:18:03 . 2008-04-14 09:41:50 617,472 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000022_.tmp.dll.vir
ComboFix 12-07-21.01 - Kevin 07/22/2012 7:12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.538 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
c:\program files\FunWebProducts
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000019_.tmp.dll
c:\windows\system32\_000020_.tmp.dll
c:\windows\system32\_000021_.tmp.dll
c:\windows\system32\_000022_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
.
.
2012-07-22 05:38 . 2012-07-22 05:38 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\offreg.dll
2012-07-22 05:38 . 2012-07-22 05:38 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys
2012-07-22 05:37 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\mpengine.dll
2012-07-22 02:26 . 2012-07-22 02:26 ——– d—–w- C:\_OTL
2012-07-22 02:23 . 2012-07-22 02:23 ——– d—–w- c:\program files\ERUNT
2012-07-21 19:49 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-08 22:07 . 2012-07-08 22:08 ——– d—–w- c:\program files\Microsoft Security Client
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-11 22:53 . 2012-04-17 10:20 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 22:53 . 2011-05-16 11:34 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:19 . 2005-08-16 10:18 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2010-10-01 22:16 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2005-08-16 10:18 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2005-08-16 10:18 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2009-08-07 00:24 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2005-08-16 10:40 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2005-08-16 10:40 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2005-08-16 10:40 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2009-08-07 00:24 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2005-08-16 10:40 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2005-08-16 10:40 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2005-08-16 10:18 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2009-08-07 00:24 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2005-08-16 10:40 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2005-08-16 10:40 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2010-10-02 02:57 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2010-10-02 02:57 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2010-10-02 02:57 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2005-08-16 10:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2005-08-16 10:18 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2005-08-16 10:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2005-08-16 10:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2005-08-16 10:18 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2005-08-16 10:18 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-04 04:59 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2005-08-16 10:37 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2010-03-11 04:01 . 2010-03-11 04:01 124272 —-a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-03-11 04:40 . 2010-03-11 04:40 13168 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-03-11 04:02 . 2010-03-11 04:02 70512 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-03-11 04:01 . 2010-03-11 04:01 91504 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-03-11 04:01 . 2010-03-11 04:01 22384 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-03-11 04:00 . 2010-03-11 04:00 255344 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-03-11 04:01 . 2010-03-11 04:01 31088 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-03-11 04:01 . 2010-03-11 04:01 40304 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2009-10-05 17:49 . 2009-10-05 17:49 652640 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-03-11 04:02 . 2010-03-11 04:02 23920 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-07-20 10:44 . 2011-05-02 21:54 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-12-19 26112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-13 1117184]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-03-11 300400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
c:\documents and settings\Kevin\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Content Manager Assistant for PlayStation®.lnk - c:\program files\Sony\Content Manager Assistant\CMA.exe [2012-1-26 2520504]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-12-19 24576]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [10/5/2009 10:08 AM 65584]
R1 MpKsladdc328d;MpKsladdc328d;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys [7/22/2012 1:38 AM 29904]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/17/2012 6:20 AM 250056]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4/25/2012 7:46 AM 113120]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2/13/2009 3:02 PM 11520]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLADDC328D
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 22:53]
.
2012-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-07-22 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell4me.com/myway
Trusted Zone: musicmatch.com\online
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yankees.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Apple - c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
HKU-Default-Run-Apple - c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-22 07:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-22 07:19:29
ComboFix-quarantined-files.txt 2012-07-22 11:19
.
Pre-Run: 42,415,812,608 bytes free
Post-Run: 42,381,115,392 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 38382EB380F25AFCAD75D503E831D4B4
2012-07-22 11:18:35 . 2012-07-22 11:18:35 230 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKU-Default-Run-Apple.reg.dat
2012-07-22 11:18:33 . 2012-07-22 11:18:33 228 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-Apple.reg.dat
2012-07-22 11:15:19 . 2012-07-22 11:15:19 6,241 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2012-07-22 11:08:04 . 2012-07-22 11:08:05 51 —-a-w- C:\Qoobox\Quarantine\catchme.log
2012-07-15 04:39:29 . 2012-07-15 04:39:30 566,784 —-a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll.vir
2005-08-16 10:18:45 . 2008-04-14 09:42:10 132,096 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000008_.tmp.dll.vir
2005-08-16 10:18:43 . 2008-04-14 05:00:12 1,845,632 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000010_.tmp.dll.vir
2005-08-16 10:18:36 . 2008-04-14 09:42:36 108,544 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000019_.tmp.dll.vir
2005-08-16 10:18:29 . 2008-04-14 09:41:26 706,048 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000020_.tmp.dll.vir
2005-08-16 10:18:22 . 2008-04-14 09:41:58 728,064 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000021_.tmp.dll.vir
2005-08-16 10:18:22 . 2008-04-14 09:41:58 343,040 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000006_.tmp.dll.vir
2005-08-16 10:18:21 . 2008-04-14 09:41:58 989,696 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000007_.tmp.dll.vir
2005-08-16 10:18:07 . 2008-04-14 09:41:52 32,256 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000009_.tmp.dll.vir
2005-08-16 10:18:03 . 2008-04-14 09:41:50 617,472 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_000022_.tmp.dll.vir