Hey!,
uTorrent is now uninstalled!
Here is the ComboFix followed by the Kaspersky report:
ComboFix 08-10-23.01 - Jim 2008-10-23 21:42:01.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2518 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jim\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\Alcmtr.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Alcmtr.exe
C:\WINDOWS\system32\acpiz.dll
C:\WINDOWS\system32\acup.sys
C:\WINDOWS\system32\adr95.bin
.
((((((((((((((((((((((((( Files Created from 2008-09-23 to 2008-10-23 )))))))))))))))))))))))))))))))
.
2008-12-20 01:36 . 2008-12-20 01:36 d——– C:\Program Files\Lavasoft
2008-12-20 01:36 . 2008-12-20 01:36 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-10-23 21:45 . 2008-10-23 21:45 0 –a—— C:\WINDOWS\system32\k86.bin
2008-10-23 17:52 . 2008-10-23 17:52 d——– C:\_OTMoveIt
2008-10-22 23:26 . 2008-10-22 23:26 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-22 23:26 . 2008-10-22 23:26 d——– C:\Documents and Settings\Jim\Application Data\Malwarebytes
2008-10-22 23:26 . 2008-10-22 23:26 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-22 23:26 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-22 23:26 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-22 13:57 . 2008-10-22 13:57 67 –a—— C:\WINDOWS\wininit.ini
2008-10-16 00:46 . 2008-10-16 00:46 d——– C:\Program Files\Anvil Studio
2008-10-16 00:46 . 2008-10-16 00:47 d——– C:\Documents and Settings\Jim\Application Data\Anvil Studio
2008-10-13 16:15 . 2008-10-13 16:15 118 –a—— C:\WINDOWS\system32\MRT.INI
2008-10-09 01:25 . 2008-10-09 01:25 d——– C:\Program Files\GameTap
2008-10-09 01:25 . 2008-10-09 01:25 d——– C:\Documents and Settings\Jim\Application Data\InstallShield
2008-10-09 01:25 . 2008-10-09 01:27 d——– C:\Documents and Settings\All Users\Application Data\GameTap
2008-10-05 00:39 . 2008-10-05 00:39 d——– C:\Program Files\DivXLand
2008-10-05 00:39 . 1999-12-17 10:13 86,016 –a—— C:\WINDOWS\unvise32.exe
2008-10-05 00:25 . 2008-10-05 00:25 d——– C:\Program Files\Common Files\Download Manager
2008-10-05 00:20 . 2008-10-05 00:20 d——– C:\Documents and Settings\Jim\AUDIO_TS
2008-10-05 00:12 . 2008-10-05 00:14 d——– C:\Program Files\MV2Player
2008-10-04 17:36 . 2008-10-04 23:59 d——– C:\WINDOWS\SxsCaPendDel
2008-10-04 02:16 . 2008-10-04 02:16 d——– C:\Program Files\SubtitleCreator
2008-10-04 02:06 . 2008-10-04 02:08 d——– C:\VideoToDVD
2008-10-04 02:06 . 2008-10-04 02:09 d——– C:\Program Files\AVI DivX MPEG to DVD Converter & Burner
2008-10-04 02:06 . 2005-01-05 16:17 655,360 –a—— C:\WINDOWS\system32\dvdlib.dll
2008-10-04 02:06 . 2004-02-10 19:15 344,064 –a—— C:\WINDOWS\system32\xvid.dll
2008-10-04 02:06 . 2001-08-18 20:00 262,144 –a—— C:\WINDOWS\system32\mpg4ds32.axu
2008-10-04 02:06 . 2005-01-09 12:41 245,760 –a—— C:\WINDOWS\system32\writelib.dll
2008-10-04 02:06 . 2003-08-19 15:20 180,224 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-10-04 02:06 . 2000-06-30 17:40 139,264 –a—— C:\WINDOWS\system32\Mpeg2Decoder.ax
2008-10-04 02:06 . 2000-06-26 13:13 94,208 –a—— C:\WINDOWS\system32\Mpeg2Parser.ax
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-20 00:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-23 19:21 ——— d—–w C:\Documents and Settings\Jim\Application Data\BullGuard
2008-10-22 12:57 ——— d—–w C:\Program Files\DivX
2008-10-22 12:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-10-19 23:23 196,608 —-a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-10-09 00:25 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-10-04 16:36 ——— d—–w C:\Program Files\Microsoft Works
2008-10-04 16:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-04 16:33 ——— d—–w C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
2008-09-16 00:14 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-09-16 00:12 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-09-16 00:12 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2008-09-16 00:12 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2008-09-16 00:12 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2008-09-16 00:12 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2008-09-16 00:12 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-09-16 00:12 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2008-09-16 00:12 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-09-16 00:11 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-09-16 00:11 815,104 —-a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-09-16 00:11 683,520 —-a-w C:\WINDOWS\system32\DivX.dll
2008-09-16 00:11 161,096 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-09-15 11:57 1,846,016 —-a-w C:\WINDOWS\system32\win32k.sys
2008-08-28 10:04 333,056 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-28 08:00 74,752 —-a-w C:\WINDOWS\system32\msw3prt.dll
2008-08-28 08:00 104,448 —-a-w C:\WINDOWS\system32\win32spl.dll
2008-08-26 07:24 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 09:58 2,136,064 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:22 2,015,744 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-02-01 16:18 0 —-a-w C:\Documents and Settings\Guest\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-10-23_19.30.17.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-03-15 12:00:00 175,616 —-a-w C:\WINDOWS\system32\adsldp.dll
- 2008-10-23 18:26:32 222,831 —-a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
+ 2008-10-23 20:47:44 222,826 —-a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-15 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-15 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless USB Utility.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Belkin Wireless USB Utility.lnk
backup=C:\WINDOWS\pss\Belkin Wireless USB Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Remote Control.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Remote Control.lnk
backup=C:\WINDOWS\pss\Remote Control.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSGamerOSD]
–a—— 2007-07-12 11:03 380928 C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BullGuard]
–a—— 2008-02-03 20:52 308552 C:\Program Files\BullGuard Software\BullGuard\BullGuard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
–a—— 2006-03-15 13:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
——— 2006-06-12 15:32 700416 C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2005-08-05 14:56 64512 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
–a—— 2006-12-05 22:55 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-06-28 17:43 8466432 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-06-28 17:43 81920 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
–a—— 2006-03-15 13:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2006-11-23 15:10 56928 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2007-08-31 17:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 04:43 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2006-03-30 17:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
——— 2006-10-18 21:05 204288 C:\Program Files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-06-28 17:43 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ptipbmf]
–a—— 2003-06-20 15:06 118784 C:\WINDOWS\system32\ptipbmf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2007-05-10 19:08 16342528 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)
"RichVideo"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NVSvc"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"Bonjour Service"=2 (0x2)
"BGLiveSvc"=2 (0x2)
"ATKKeyboardService"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"aawservice"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R1 HTTPFILT.DLL;BullGuard Firewall HTTP Plugin;C:\Program Files\BullGuard Software\BullGuard\FwEngine\HttpFilt.dll [2008-10-20 8576]
R2 BdFileSpy;BullGuard File Monitor Driver;C:\WINDOWS\system32\drivers\BdFileSpy.sys [2007-11-23 50896]
R2 BsFileScan;BullGuard File Scan Service;C:\WINDOWS\System32\svchost.exe [2006-03-15 14336]
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-02-15 656896]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 12416]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-07-12 10752]
S1 ADBLOCK.DLL;BullGuard Firewall Adware Plugin;C:\Program Files\BullGuard Software\BullGuard\FwEngine\AdBlock.dll [2008-10-20 8576]
S1 HTMLFILT.DLL;BullGuard Firewall HTML Plugin;C:\Program Files\BullGuard Software\BullGuard\FwEngine\HtmlFilt.dll [2008-10-20 8576]
S2 BsFwall;BullGuard Firewall Service;C:\WINDOWS\System32\svchost.exe [2006-03-15 14336]
S3 PROTECT.DLL;BullGuard Firewall Protection Plugin;C:\Program Files\BullGuard Software\BullGuard\FwEngine\Protect.dll [2006-11-02 16960]
S3 Reconn;BullGuard Email Monitor;C:\Program Files\BullGuard Software\BullGuard\reconn.sys [2007-11-23 16984]
S4 iteraid;ITERAID_Service_Install;C:\WINDOWS\system32\DRIVERS\iteraid.sys [2004-07-16 24971]
S4 m5287;m5287;C:\WINDOWS\system32\DRIVERS\m5287.sys [2005-09-23 103680]
S4 m5288;m5288;C:\WINDOWS\system32\DRIVERS\m5288.sys [2005-12-23 210304]
S4 m5289;m5289;C:\WINDOWS\system32\DRIVERS\m5289.sys [2005-07-04 52480]
S4 SI3112r;Silicon Image SiI 3512 SATARaid Controller;C:\WINDOWS\system32\DRIVERS\SI3112r.sys [2003-05-09 89749]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard REG_MULTI_SZ BgMainSvc BsFileScan BsMailProxy
BullGuardFw REG_MULTI_SZ BsFwall
.
Contents of the 'Scheduled Tasks' folder
2008-10-16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
Notify-acpiz - acpiz.dll
MSConfigStartUp-uTorrent - C:\Program Files\uTorrent\uTorrent.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-23 21:47:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-10-23 21:54:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-23 20:54:27
ComboFix2.txt 2008-10-23 18:30:36
ComboFix3.txt 2008-01-21 22:27:08
Pre-Run: 292,995,354,624 bytes free
Post-Run: 293,012,901,888 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
244 — E O F — 2008-10-23 16:19:18
=========================================================
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, October 23, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, October 23, 2008 21:11:09
Records in database: 1340820
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan statistics:
Files scanned: 93714
Threat name: 4
Infected objects: 8
Suspicious objects: 0
Duration of the scan: 00:46:40
File name / Threat name / Threats count
C:\Program Files\BullGuard Software\BullGuard\fwengine\AdBlock.dll Infected: Trojan-Spy.Win32.Goldun.bcu 1
C:\Program Files\BullGuard Software\BullGuard\fwengine\HtmlFilt.dll Infected: Trojan-Spy.Win32.Goldun.bcu 1
C:\Program Files\BullGuard Software\BullGuard\fwengine\HttpFilt.dll Infected: Trojan-Spy.Win32.Goldun.bcu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\figaro.sys.vir Infected: Backdoor.Win32.UltimateDefender.a 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\_figaro_.sys.zip Infected: Backdoor.Win32.UltimateDefender.a 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\_acpiz_.dll.zip Infected: Trojan-Spy.Win32.Goldun.bct 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\_acup_.sys.zip Infected: Trojan-Spy.Win32.Goldun.bcu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\~.exe.vir Infected: Trojan.Win32.Pakes.lbo 1
The selected area was scanned.