GrumpySasquatch
Topic Starter
I am having a bear of a time removing some nasties off of my box. Is there someone that might be inclined to help? Below are my logs:
AntiSpywareMaster scan report
Report generated at: 04/28/08 11:56:30
|Type |Run type |Name |Details
|Spyware |autorun |Spyware.KeySnitch |is a spyware program that monitors user activity, logs keystrokes, and captures screenshots.
|Spyware |C:\WINDOWS\system32\comaddin.dll |Spyware.KeySnitch |is a spyware program that monitors user activity, logs keystrokes, and captures screenshots.
|Spyware |C:\WINDOWS\system32\duser.dll |Spyware.KeySnitch |is a spyware program that monitors user activity, logs keystrokes, and captures screenshots.
|Backdoor |C:\WINDOWS\system32\ipsmsnap.dll |Backdoor.Hacarmy.G |is a Trojan horse that connects to a predetermined IRC server and opens a back door on the compromised computer.
|Adware |registry |Adware.Elodu |is an adware program that installs itself as a Browser Helper Object and displays pop up advertisements.
|Worm |C:\WINDOWS\system32\mag_hook.dll |Downloader.Almanahe |is a Trojan horse that attempts to download a variant from the W32.Alamanahe family of worms.
|Adware |C:\WINDOWS\system32\msjava.dll |Adware.Elodu |is an adware program that installs itself as a Browser Helper Object and displays pop up advertisements.
|Dialer |injection |Dialer.InstantAccess |is a dialer that gives a user access to the premium services of a third-party Web site, by dialing a high cost number using a modem.
|Adware |C:\WINDOWS\system32\pdh.dll |Adware.PPRich |is a program that displays Internet advertisements in Chinese on the compromised computer.
|Dialer |C:\WINDOWS\system32\sclgntfy.dll |Dialer.Cyberbill |is a dialer program that can be used to access pornography by dialing a high-cost number using a modem.
|Adware |C:\WINDOWS\system32\usrcoina.dll |Adware.Elodu |is an adware program that installs itself as a Browser Helper Object and displays pop up advertisements.
|Tracking Cookie|Web browser |193.227.121 |C:\Documents and Settings\Christian\Cookies\christian@193.227.121[1].txt
|Tracking Cookie|Web browser |82.98.235 |C:\Documents and Settings\Christian\Cookies\christian@82.98.235[1].txt
|Tracking Cookie|Web browser |adnetserver |C:\Documents and Settings\Christian\Cookies\christian@adnetserver[1].txt
|Tracking Cookie|Web browser |google |C:\Documents and Settings\Christian\Cookies\christian@google[1].txt
|Tracking Cookie|Web browser |messenger.msn |C:\Documents and Settings\Christian\Cookies\[removed][1].txt
|Tracking Cookie|Web browser |msn |C:\Documents and Settings\Christian\Cookies\christian@msn[1].txt
ComboFix 08-05-01.3 - Christian 2008-05-06 11:50:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1295 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\ehkmp.ini
C:\WINDOWS\system32\ehkmp.ini2
C:\WINDOWS\system32\gjjlm.ini2
C:\WINDOWS\system32\grouppolicy\machine\scripts\scripts.ini
C:\WINDOWS\system32\ihygxien.ini
C:\WINDOWS\system32\ijllm.ini2
C:\WINDOWS\system32\rttss.ini2
C:\WINDOWS\system32\wfbasklp.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-06 to 2008-05-06 )))))))))))))))))))))))))))))))
.
2100-02-23 18:55 . 2001-05-17 16:06 1,096 –a–c— C:\WINDOWS\Lexmark_ICM.ini
2008-05-06 11:26 . 2008-05-06 11:26 d——– C:\Documents and Settings\Christian\Application Data\Malwarebytes
2008-05-06 11:25 . 2008-05-06 11:26 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-05-06 11:25 . 2008-05-06 11:25 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-06 11:25 . 2008-05-05 20:46 27,048 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-06 11:25 . 2008-05-05 20:46 15,864 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-05-01 15:10 . 2008-05-01 15:10 d——– C:\Program Files\Common Files\Agnitum Shared
2008-05-01 15:10 . 2008-05-01 15:10 d——– C:\Program Files\Agnitum
2008-05-01 15:10 . 2008-05-01 15:10 677,376 –a—— C:\WINDOWS\is-BDF5P.exe
2008-05-01 15:10 . 2008-05-01 15:10 10,883 –a—— C:\WINDOWS\is-BDF5P.msg
2008-05-01 15:10 . 2008-05-01 15:10 325 –a—— C:\WINDOWS\is-BDF5P.lst
2008-04-30 17:04 . 2008-05-01 00:19 d——– C:\Program Files\Protege_3.3.1
2008-04-30 15:20 . 2008-04-30 15:20 d——– C:\Program Files\Safer Networking
2008-04-30 13:26 . 2008-04-30 13:26 153 –a—— C:\WINDOWS\wininit.ini
2008-04-30 10:10 . 2008-04-30 10:10 d——– C:\Program Files\Spybot - Search & Destroy
2008-04-30 10:10 . 2008-04-30 10:44 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-30 09:28 . 2008-04-30 09:28 d——– C:\WINDOWS\system32\windows media
2008-04-30 09:28 . 2008-04-30 09:28 d–h—– C:\WINDOWS\msdownld.tmp
2008-04-30 09:28 . 2008-04-30 09:28 d——– C:\Program Files\Windows Media Components
2008-04-30 09:23 . 2008-04-30 09:23 d——– C:\Program Files\ResChanger 2005
2008-04-30 09:23 . 2008-04-30 09:23 720,896 –a—— C:\WINDOWS\iun6002.exe
2008-04-29 18:05 . 2008-04-29 18:05 118,784 –a—— C:\WINDOWS\SeaMonkeyUninstall.exe
2008-04-29 11:12 . 2008-04-29 11:12 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-04-29 11:02 . 2008-04-29 11:02 d——– C:\Program Files\Qwest
2008-04-29 11:02 . 2008-04-29 11:02 d——– C:\Program Files\Common Files\SupportSoft
2008-04-28 15:34 . 2008-04-28 15:34 d——– C:\Program Files\Uniblue
2008-04-28 14:16 . 2008-04-28 14:16 d–h—– C:\WINDOWS\system32\GroupPolicy
2008-04-28 12:46 . 2008-04-28 12:46 250 –a—— C:\WINDOWS\gmer.ini
2008-04-28 10:35 . 2008-04-28 10:35 d——– C:\Program Files\Trend Micro
2008-04-27 07:24 . 2008-04-27 07:24 0 –a—— C:\WINDOWS\BM0f2d042d.xml
2008-04-26 22:07 . 2008-05-06 12:03 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-26 22:07 . 2007-12-10 13:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-26 22:07 . 2007-12-10 13:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-26 22:07 . 2008-02-01 11:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-26 22:07 . 2007-12-10 13:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-04-26 22:06 . 2008-05-05 07:50 d——– C:\Program Files\Spyware Doctor
2008-04-26 22:06 . 2008-04-26 22:06 d——– C:\Documents and Settings\Christian\Application Data\PC Tools
2008-04-21 22:36 . 2004-08-22 23:49 121,472 -ra—— C:\WINDOWS\system32\drivers\b57xp32.sys
2008-04-21 22:36 . 2004-08-22 23:49 121,472 –a–c— C:\WINDOWS\system32\dllcache\b57xp32.sys
2008-04-21 11:48 . 2008-04-26 20:53 129,536 –a—-t- C:\WINDOWS\system32\DarkSpyKernel.sys
2008-04-17 20:31 . 2008-04-26 15:12 d——– C:\boilsoft_tmp
2008-04-17 20:29 . 2008-04-26 15:11 67 –a—— C:\WINDOWS\AVIConverter.INI
2008-04-17 15:44 . 2008-04-30 13:38 dr——- C:\UDC Output Files
2008-04-16 17:01 . 2008-04-16 17:02 d——– C:\Documents and Settings\Christian\Application Data\DivX
2008-04-16 16:55 . 2008-03-21 13:30 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-04-16 16:55 . 2008-03-21 13:30 120,056 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-04-16 16:55 . 2008-03-21 13:30 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-04-16 16:54 . 2008-04-26 22:18 d——– C:\Program Files\DivX
2008-04-14 10:06 . 2008-04-14 10:06 71,152 –ah—– C:\WINDOWS\system32\mlfcache.dat
2008-04-10 11:42 . 2008-04-10 11:42 d——– C:\Documents and Settings\Christian\Application Data\SystemRequirementsLab
2008-04-09 14:14 . 2008-04-09 14:15 d——– C:\ruby
2008-04-08 14:47 . 2008-04-08 14:47 1,409 –a—— C:\WINDOWS\QTFont.for
2008-04-08 14:44 . 2008-04-08 14:45 d——– C:\Program Files\QuickTime
2008-04-07 22:07 . 2008-04-21 12:04 d——– C:\Program Files\UnHackMe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 19:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\VMware
2008-05-06 18:53 ——— d—–w C:\Program Files\PeerGuardian2
2008-05-06 15:21 ——— d—–w C:\Documents and Settings\LocalService\Application Data\VMware
2008-05-05 14:27 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-04 03:35 ——— d—–w C:\Program Files\Soulseek
2008-04-30 01:05 118,784 —-a-w C:\WINDOWS\GREUninstall.exe
2008-04-30 01:05 ——— d—–w C:\Program Files\mozilla.org
2008-04-30 00:16 ——— d—–w C:\Program Files\RegScrubXP
2008-04-29 23:21 ——— d—–w C:\Documents and Settings\Christian\Application Data\Azureus
2008-04-29 16:20 ——— d—–w C:\Documents and Settings\Christian\Application Data\VMware
2008-04-28 22:34 ——— d—–w C:\Documents and Settings\Christian\Application Data\Uniblue
2008-04-28 19:47 ——— d—–w C:\Program Files\Bonjour
2008-04-28 19:17 ——— d—–w C:\Program Files\eclipse
2008-04-22 15:10 ——— d—–w C:\Program Files\WinHTTrack
2008-04-18 19:31 ——— d—–w C:\Program Files\Azureus
2008-04-18 16:51 ——— d—–w C:\Program Files\EndNote X
2008-04-18 16:51 ——— d—–w C:\Documents and Settings\Christian\Application Data\EndNote
2008-04-17 20:02 ——— d—–w C:\Program Files\Safari
2008-04-17 10:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-15 20:38 ——— d—–w C:\Program Files\Apple Software Update
2008-04-09 06:22 ——— d—–w C:\Program Files\BibleWorks 7
2008-04-08 21:46 ——— d—–w C:\Program Files\iTunes
2008-04-08 21:46 ——— d—–w C:\Program Files\iPod
2008-04-02 17:05 ——— d—–w C:\Program Files\MATLAB
2008-03-27 19:24 ——— d—–w C:\Program Files\Common Files\Macrovision Shared
2008-03-27 19:17 ——— d—–w C:\Program Files\Common Files\Adobe
2008-03-24 21:59 ——— d—–w C:\Program Files\Java
2008-03-23 03:43 ——— d—–w C:\Program Files\Opera
2008-03-22 22:22 ——— d—–w C:\Program Files\BibleWorks 6
2008-03-21 20:30 43,528 -c—-w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-03-18 21:47 ——— d—–w C:\Program Files\VMware
2008-03-18 21:47 ——— d—–w C:\Program Files\Common Files\VMware
2008-03-18 20:46 ——— d—–w C:\Documents and Settings\Christian\Application Data\Apple Computer
2008-03-10 20:27 ——— d—–w C:\Program Files\AviSynth 2.5
2008-03-10 20:27 ——— d—–w C:\Program Files\AviDvdBurner
2008-03-10 20:26 ——— d—–w C:\Program Files\AC3Filter
2008-02-19 20:08 4,679 —-a-w C:\deftask.dat
2008-02-11 19:44 64,512 —ha-w C:\Documents and Settings\Christian\Application Data\rbap450.dll
2008-02-11 19:44 1,360,384 —ha-w C:\Documents and Settings\Christian\Application Data\V4RB.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"UnHackMe Monitor"="C:\Program Files\UnHackMe\hackmon.exe" [2005-10-04 14:42 228864]
"ResChanger 2005"="C:\Program Files\ResChanger 2005\ResChanger2005.exe" [2005-05-26 16:30 885248]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-10-07 17:53 131072]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-28 15:47 7573504]
"nwiz"="nwiz.exe" [2006-04-28 15:47 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-28 15:47 86016]
"lxamsp32.exe"="lxamsp32.exe" [2001-10-21 19:12 45056 C:\WINDOWS\system32\LXAMSP32.EXE]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-21 16:54 36864]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-31 05:55 185896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-07-24 21:09 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-06 17:05 200704]
"VMware hqtray"="C:\Program Files\VMware\VMware Player\hqtray.exe" [2008-03-03 20:05 55856]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 11:55 1103240]
"QUICKCARE"="C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe" [2006-11-07 21:07 192512]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Outpost Firewall"="C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" [2007-04-05 16:56 94720]
"OutpostFeedBack"="C:\Program Files\Agnitum\Outpost Firewall\feedback.exe" [2007-06-28 13:18 335872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxvtuv]
cbxvtuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
——— 2005-09-20 08:06 1397760 C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mozilla Quick Launch]
–a—— 2006-04-14 23:05 98192 C:\Program Files\mozilla.org\Mozilla\Mozilla.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-12-22 02:09 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Qwest\\QuickCare\\agentui\\quickcare.exe"=
"C:\\Program Files\\Qwest\\QuickCare\\bin\\sprtcmd.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
R1 SandBox;Outpost Firewall Sandbox Driver;C:\Program Files\Agnitum\Outpost Firewall\kernel\Sandbox.SYS [2007-06-26 19:01]
R1 VFILT;Outpost Firewall Kernel Driver;C:\Program Files\Agnitum\Outpost Firewall\kernel\FILTNT.SYS [2007-04-05 16:56]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
R2 vnccom;vnccom;C:\WINDOWS\system32\Drivers\vnccom.SYS [2004-06-26 13:22]
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL [2007-04-05 16:57]
R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\ARP.DLL [2007-04-05 16:57]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\CONTENT.DLL [2007-04-05 16:57]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL [2007-04-05 16:57]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL [2007-04-05 16:57]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL [2007-04-05 16:57]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL [2007-04-05 16:57]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL [2007-04-05 16:57]
R3 KeyScrambler;KeyScrambler;C:\WINDOWS\system32\drivers\keyscrambler.sys [2007-12-29 07:35]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL [2007-04-05 16:57]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL [2007-04-05 16:57]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL [2007-04-05 16:57]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\PROTECT.DLL [2007-04-05 16:57]
R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\SECRET.DLL [2007-04-05 16:57]
S2 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE []
S2 OracleXETNSListener;OracleXETNSListener;C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe [2006-02-02 01:49]
S3 DarkSpy;DarkSpy;C:\WINDOWS\system32\DarkSpyKernel.sys [2008-04-26 20:53]
S3 ORIUGSAIJOD;ORIUGSAIJOD;C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\ORIUGSAIJOD.exe []
S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{64fd9011-3969-11db-b0e5-806d6172696f}]
\Shell\AutoRun\command - D:\Bin\assetup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-01 19:57:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-06 11:59:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2008-05-06 12:21:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-06 19:20:57
Pre-Run: 249,672,032,256 bytes free
Post-Run: 249,747,857,408 bytes free
251 — E O F — 2008-04-29 16:41:28
AntiSpywareMaster scan report
Report generated at: 04/28/08 11:56:30
|Type |Run type |Name |Details
|Spyware |autorun |Spyware.KeySnitch |is a spyware program that monitors user activity, logs keystrokes, and captures screenshots.
|Spyware |C:\WINDOWS\system32\comaddin.dll |Spyware.KeySnitch |is a spyware program that monitors user activity, logs keystrokes, and captures screenshots.
|Spyware |C:\WINDOWS\system32\duser.dll |Spyware.KeySnitch |is a spyware program that monitors user activity, logs keystrokes, and captures screenshots.
|Backdoor |C:\WINDOWS\system32\ipsmsnap.dll |Backdoor.Hacarmy.G |is a Trojan horse that connects to a predetermined IRC server and opens a back door on the compromised computer.
|Adware |registry |Adware.Elodu |is an adware program that installs itself as a Browser Helper Object and displays pop up advertisements.
|Worm |C:\WINDOWS\system32\mag_hook.dll |Downloader.Almanahe |is a Trojan horse that attempts to download a variant from the W32.Alamanahe family of worms.
|Adware |C:\WINDOWS\system32\msjava.dll |Adware.Elodu |is an adware program that installs itself as a Browser Helper Object and displays pop up advertisements.
|Dialer |injection |Dialer.InstantAccess |is a dialer that gives a user access to the premium services of a third-party Web site, by dialing a high cost number using a modem.
|Adware |C:\WINDOWS\system32\pdh.dll |Adware.PPRich |is a program that displays Internet advertisements in Chinese on the compromised computer.
|Dialer |C:\WINDOWS\system32\sclgntfy.dll |Dialer.Cyberbill |is a dialer program that can be used to access pornography by dialing a high-cost number using a modem.
|Adware |C:\WINDOWS\system32\usrcoina.dll |Adware.Elodu |is an adware program that installs itself as a Browser Helper Object and displays pop up advertisements.
|Tracking Cookie|Web browser |193.227.121 |C:\Documents and Settings\Christian\Cookies\christian@193.227.121[1].txt
|Tracking Cookie|Web browser |82.98.235 |C:\Documents and Settings\Christian\Cookies\christian@82.98.235[1].txt
|Tracking Cookie|Web browser |adnetserver |C:\Documents and Settings\Christian\Cookies\christian@adnetserver[1].txt
|Tracking Cookie|Web browser |google |C:\Documents and Settings\Christian\Cookies\christian@google[1].txt
|Tracking Cookie|Web browser |messenger.msn |C:\Documents and Settings\Christian\Cookies\[removed][1].txt
|Tracking Cookie|Web browser |msn |C:\Documents and Settings\Christian\Cookies\christian@msn[1].txt
ComboFix 08-05-01.3 - Christian 2008-05-06 11:50:15.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1295 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\ehkmp.ini
C:\WINDOWS\system32\ehkmp.ini2
C:\WINDOWS\system32\gjjlm.ini2
C:\WINDOWS\system32\grouppolicy\machine\scripts\scripts.ini
C:\WINDOWS\system32\ihygxien.ini
C:\WINDOWS\system32\ijllm.ini2
C:\WINDOWS\system32\rttss.ini2
C:\WINDOWS\system32\wfbasklp.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-06 to 2008-05-06 )))))))))))))))))))))))))))))))
.
2100-02-23 18:55 . 2001-05-17 16:06 1,096 –a–c— C:\WINDOWS\Lexmark_ICM.ini
2008-05-06 11:26 . 2008-05-06 11:26 d——– C:\Documents and Settings\Christian\Application Data\Malwarebytes
2008-05-06 11:25 . 2008-05-06 11:26 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-05-06 11:25 . 2008-05-06 11:25 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-06 11:25 . 2008-05-05 20:46 27,048 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-06 11:25 . 2008-05-05 20:46 15,864 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-05-01 15:10 . 2008-05-01 15:10 d——– C:\Program Files\Common Files\Agnitum Shared
2008-05-01 15:10 . 2008-05-01 15:10 d——– C:\Program Files\Agnitum
2008-05-01 15:10 . 2008-05-01 15:10 677,376 –a—— C:\WINDOWS\is-BDF5P.exe
2008-05-01 15:10 . 2008-05-01 15:10 10,883 –a—— C:\WINDOWS\is-BDF5P.msg
2008-05-01 15:10 . 2008-05-01 15:10 325 –a—— C:\WINDOWS\is-BDF5P.lst
2008-04-30 17:04 . 2008-05-01 00:19 d——– C:\Program Files\Protege_3.3.1
2008-04-30 15:20 . 2008-04-30 15:20 d——– C:\Program Files\Safer Networking
2008-04-30 13:26 . 2008-04-30 13:26 153 –a—— C:\WINDOWS\wininit.ini
2008-04-30 10:10 . 2008-04-30 10:10 d——– C:\Program Files\Spybot - Search & Destroy
2008-04-30 10:10 . 2008-04-30 10:44 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-30 09:28 . 2008-04-30 09:28 d——– C:\WINDOWS\system32\windows media
2008-04-30 09:28 . 2008-04-30 09:28 d–h—– C:\WINDOWS\msdownld.tmp
2008-04-30 09:28 . 2008-04-30 09:28 d——– C:\Program Files\Windows Media Components
2008-04-30 09:23 . 2008-04-30 09:23 d——– C:\Program Files\ResChanger 2005
2008-04-30 09:23 . 2008-04-30 09:23 720,896 –a—— C:\WINDOWS\iun6002.exe
2008-04-29 18:05 . 2008-04-29 18:05 118,784 –a—— C:\WINDOWS\SeaMonkeyUninstall.exe
2008-04-29 11:12 . 2008-04-29 11:12 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-04-29 11:02 . 2008-04-29 11:02 d——– C:\Program Files\Qwest
2008-04-29 11:02 . 2008-04-29 11:02 d——– C:\Program Files\Common Files\SupportSoft
2008-04-28 15:34 . 2008-04-28 15:34 d——– C:\Program Files\Uniblue
2008-04-28 14:16 . 2008-04-28 14:16 d–h—– C:\WINDOWS\system32\GroupPolicy
2008-04-28 12:46 . 2008-04-28 12:46 250 –a—— C:\WINDOWS\gmer.ini
2008-04-28 10:35 . 2008-04-28 10:35 d——– C:\Program Files\Trend Micro
2008-04-27 07:24 . 2008-04-27 07:24 0 –a—— C:\WINDOWS\BM0f2d042d.xml
2008-04-26 22:07 . 2008-05-06 12:03 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-26 22:07 . 2007-12-10 13:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-26 22:07 . 2007-12-10 13:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-26 22:07 . 2008-02-01 11:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-26 22:07 . 2007-12-10 13:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-04-26 22:06 . 2008-05-05 07:50 d——– C:\Program Files\Spyware Doctor
2008-04-26 22:06 . 2008-04-26 22:06 d——– C:\Documents and Settings\Christian\Application Data\PC Tools
2008-04-21 22:36 . 2004-08-22 23:49 121,472 -ra—— C:\WINDOWS\system32\drivers\b57xp32.sys
2008-04-21 22:36 . 2004-08-22 23:49 121,472 –a–c— C:\WINDOWS\system32\dllcache\b57xp32.sys
2008-04-21 11:48 . 2008-04-26 20:53 129,536 –a—-t- C:\WINDOWS\system32\DarkSpyKernel.sys
2008-04-17 20:31 . 2008-04-26 15:12 d——– C:\boilsoft_tmp
2008-04-17 20:29 . 2008-04-26 15:11 67 –a—— C:\WINDOWS\AVIConverter.INI
2008-04-17 15:44 . 2008-04-30 13:38 dr——- C:\UDC Output Files
2008-04-16 17:01 . 2008-04-16 17:02 d——– C:\Documents and Settings\Christian\Application Data\DivX
2008-04-16 16:55 . 2008-03-21 13:30 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-04-16 16:55 . 2008-03-21 13:30 120,056 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-04-16 16:55 . 2008-03-21 13:30 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-04-16 16:54 . 2008-04-26 22:18 d——– C:\Program Files\DivX
2008-04-14 10:06 . 2008-04-14 10:06 71,152 –ah—– C:\WINDOWS\system32\mlfcache.dat
2008-04-10 11:42 . 2008-04-10 11:42 d——– C:\Documents and Settings\Christian\Application Data\SystemRequirementsLab
2008-04-09 14:14 . 2008-04-09 14:15 d——– C:\ruby
2008-04-08 14:47 . 2008-04-08 14:47 1,409 –a—— C:\WINDOWS\QTFont.for
2008-04-08 14:44 . 2008-04-08 14:45 d——– C:\Program Files\QuickTime
2008-04-07 22:07 . 2008-04-21 12:04 d——– C:\Program Files\UnHackMe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 19:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\VMware
2008-05-06 18:53 ——— d—–w C:\Program Files\PeerGuardian2
2008-05-06 15:21 ——— d—–w C:\Documents and Settings\LocalService\Application Data\VMware
2008-05-05 14:27 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-04 03:35 ——— d—–w C:\Program Files\Soulseek
2008-04-30 01:05 118,784 —-a-w C:\WINDOWS\GREUninstall.exe
2008-04-30 01:05 ——— d—–w C:\Program Files\mozilla.org
2008-04-30 00:16 ——— d—–w C:\Program Files\RegScrubXP
2008-04-29 23:21 ——— d—–w C:\Documents and Settings\Christian\Application Data\Azureus
2008-04-29 16:20 ——— d—–w C:\Documents and Settings\Christian\Application Data\VMware
2008-04-28 22:34 ——— d—–w C:\Documents and Settings\Christian\Application Data\Uniblue
2008-04-28 19:47 ——— d—–w C:\Program Files\Bonjour
2008-04-28 19:17 ——— d—–w C:\Program Files\eclipse
2008-04-22 15:10 ——— d—–w C:\Program Files\WinHTTrack
2008-04-18 19:31 ——— d—–w C:\Program Files\Azureus
2008-04-18 16:51 ——— d—–w C:\Program Files\EndNote X
2008-04-18 16:51 ——— d—–w C:\Documents and Settings\Christian\Application Data\EndNote
2008-04-17 20:02 ——— d—–w C:\Program Files\Safari
2008-04-17 10:01 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-15 20:38 ——— d—–w C:\Program Files\Apple Software Update
2008-04-09 06:22 ——— d—–w C:\Program Files\BibleWorks 7
2008-04-08 21:46 ——— d—–w C:\Program Files\iTunes
2008-04-08 21:46 ——— d—–w C:\Program Files\iPod
2008-04-02 17:05 ——— d—–w C:\Program Files\MATLAB
2008-03-27 19:24 ——— d—–w C:\Program Files\Common Files\Macrovision Shared
2008-03-27 19:17 ——— d—–w C:\Program Files\Common Files\Adobe
2008-03-24 21:59 ——— d—–w C:\Program Files\Java
2008-03-23 03:43 ——— d—–w C:\Program Files\Opera
2008-03-22 22:22 ——— d—–w C:\Program Files\BibleWorks 6
2008-03-21 20:30 43,528 -c—-w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-03-18 21:47 ——— d—–w C:\Program Files\VMware
2008-03-18 21:47 ——— d—–w C:\Program Files\Common Files\VMware
2008-03-18 20:46 ——— d—–w C:\Documents and Settings\Christian\Application Data\Apple Computer
2008-03-10 20:27 ——— d—–w C:\Program Files\AviSynth 2.5
2008-03-10 20:27 ——— d—–w C:\Program Files\AviDvdBurner
2008-03-10 20:26 ——— d—–w C:\Program Files\AC3Filter
2008-02-19 20:08 4,679 —-a-w C:\deftask.dat
2008-02-11 19:44 64,512 —ha-w C:\Documents and Settings\Christian\Application Data\rbap450.dll
2008-02-11 19:44 1,360,384 —ha-w C:\Documents and Settings\Christian\Application Data\V4RB.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"UnHackMe Monitor"="C:\Program Files\UnHackMe\hackmon.exe" [2005-10-04 14:42 228864]
"ResChanger 2005"="C:\Program Files\ResChanger 2005\ResChanger2005.exe" [2005-05-26 16:30 885248]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-10-07 17:53 131072]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-28 15:47 7573504]
"nwiz"="nwiz.exe" [2006-04-28 15:47 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-28 15:47 86016]
"lxamsp32.exe"="lxamsp32.exe" [2001-10-21 19:12 45056 C:\WINDOWS\system32\LXAMSP32.EXE]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-21 16:54 36864]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-31 05:55 185896]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-07-24 21:09 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-06 17:05 200704]
"VMware hqtray"="C:\Program Files\VMware\VMware Player\hqtray.exe" [2008-03-03 20:05 55856]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 11:55 1103240]
"QUICKCARE"="C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe" [2006-11-07 21:07 192512]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Outpost Firewall"="C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" [2007-04-05 16:56 94720]
"OutpostFeedBack"="C:\Program Files\Agnitum\Outpost Firewall\feedback.exe" [2007-06-28 13:18 335872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxvtuv]
cbxvtuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
——— 2005-09-20 08:06 1397760 C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mozilla Quick Launch]
–a—— 2006-04-14 23:05 98192 C:\Program Files\mozilla.org\Mozilla\Mozilla.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-12-22 02:09 77824 C:\WINDOWS\SOUNDMAN.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Qwest\\QuickCare\\agentui\\quickcare.exe"=
"C:\\Program Files\\Qwest\\QuickCare\\bin\\sprtcmd.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
R1 SandBox;Outpost Firewall Sandbox Driver;C:\Program Files\Agnitum\Outpost Firewall\kernel\Sandbox.SYS [2007-06-26 19:01]
R1 VFILT;Outpost Firewall Kernel Driver;C:\Program Files\Agnitum\Outpost Firewall\kernel\FILTNT.SYS [2007-04-05 16:56]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
R2 vnccom;vnccom;C:\WINDOWS\system32\Drivers\vnccom.SYS [2004-06-26 13:22]
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL [2007-04-05 16:57]
R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\ARP.DLL [2007-04-05 16:57]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\CONTENT.DLL [2007-04-05 16:57]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL [2007-04-05 16:57]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL [2007-04-05 16:57]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL [2007-04-05 16:57]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL [2007-04-05 16:57]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL [2007-04-05 16:57]
R3 KeyScrambler;KeyScrambler;C:\WINDOWS\system32\drivers\keyscrambler.sys [2007-12-29 07:35]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL [2007-04-05 16:57]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL [2007-04-05 16:57]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL [2007-04-05 16:57]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\PROTECT.DLL [2007-04-05 16:57]
R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);C:\Program Files\Agnitum\Outpost Firewall\kernel\SECRET.DLL [2007-04-05 16:57]
S2 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE []
S2 OracleXETNSListener;OracleXETNSListener;C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe [2006-02-02 01:49]
S3 DarkSpy;DarkSpy;C:\WINDOWS\system32\DarkSpyKernel.sys [2008-04-26 20:53]
S3 ORIUGSAIJOD;ORIUGSAIJOD;C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\ORIUGSAIJOD.exe []
S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{64fd9011-3969-11db-b0e5-806d6172696f}]
\Shell\AutoRun\command - D:\Bin\assetup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-01 19:57:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-06 11:59:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2008-05-06 12:21:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-06 19:20:57
Pre-Run: 249,672,032,256 bytes free
Post-Run: 249,747,857,408 bytes free
251 — E O F — 2008-04-29 16:41:28