Here is the log as requested………..
ComboFix 08-11-12.02 - EBox 2008-11-15 15:08:51.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.787 [GMT 0:00]
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\update.exe
c:\windows\brastk.exe
c:\windows\karna.dat
c:\windows\system32\brastk.exe
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\svchost.exe
c:\windows\system32\drivers\TDSSpqlt.sys
c:\windows\system32\karna.dat
c:\windows\system32\MSINET.oca
c:\windows\system32\TDSSbrsr.dll
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\wini10894.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2008-10-15 to 2008-11-15 )))))))))))))))))))))))))))))))
.
2008-11-11 23:03 . 2008-11-11 23:03 d——– c:\program files\FileASSASSIN
2008-11-11 19:54 . 2008-11-11 19:54 d–h—– c:\windows\PIF
2008-11-11 18:06 . 2008-10-24 11:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 18:05 . 2008-09-04 17:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-02 12:55 . 2008-10-15 16:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2008-10-16 21:02 . 2008-10-16 21:02 d——– c:\program files\Microsoft CAPICOM 2.1.0.2
2008-10-16 15:58 . 2008-09-08 10:41 333,824 —–c— c:\windows\system32\dllcache\srv.sys
2008-10-16 15:57 . 2008-08-14 10:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-16 15:57 . 2008-08-14 10:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-16 15:57 . 2008-08-14 09:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-16 15:57 . 2008-08-14 09:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-16 15:57 . 2008-09-15 12:12 1,846,400 —–c— c:\windows\system32\dllcache\win32k.sys
2008-10-15 20:18 . 2008-10-15 20:18 d——– c:\program files\MestRe-C
2008-10-15 20:12 . 2008-10-15 20:12 d——– c:\documents and settings\All Users\Application Data\CambridgeSoft
2008-10-15 19:52 . 2008-10-15 19:53 d——– C:\CSTEMP
2008-10-15 19:12 . 2008-10-15 19:12 d——– c:\program files\Common Files\Deterministic Networks
2008-10-15 19:08 . 2008-10-15 19:08 1,594 –a—— c:\windows\VPNUnInstall.MIF
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-15 19:53 ——— d—–w c:\program files\CambridgeSoft
2008-10-11 12:10 ——— d—–w c:\program files\iTunes
2008-10-11 12:10 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-11 12:09 ——— d—–w c:\program files\iPod
2008-09-29 21:03 96,384 —-a-w c:\windows\system32\drivers\sptd7917.sys
2008-09-23 15:28 ——— d—–w c:\program files\Apple Software Update
2008-09-23 15:25 ——— d—–w c:\program files\QuickTime
2008-09-23 15:25 ——— d—–w c:\program files\Bonjour
2008-09-23 10:00 ——— d—–w c:\program files\LimeWire
2006-05-06 12:22 20,872 —-a-w c:\documents and settings\EBox\Application Data\GDIPFONTCACHEV1.DAT
2004-03-01 13:25 114,688 —-a-w c:\program files\internet explorer\plugins\ChimeShim.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-08-18 94208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Network Associates Error Reporting Service"="c:\program files\Common Files\Network Associates\TalkBack\tbmon.exe" [2003-10-07 147514]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"nwiz"="nwiz.exe" [2006-03-09 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
VPN Client.lnk - c:\windows\Installer\{51FB15F4-AD27-43BC-AD4B-DD0354FB6BBD}\Icon3E5562ED7.ico [2008-10-15 6144]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoSecCPL"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 1 (0x1)
"NoStrCmpLogical"= 1 (0x1)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"DisableMyPicturesDirChange"= 0 (0x0)
"DisableMyMusicDirChange"= 0 (0x0)
"DisableFavoritesDirChange"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoStrCmpLogical"= 1 (0x1)
"NoFavoritesMenu"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\progra~1\DVD Region+CSS Free\DVDShell.dll" [2004-10-09 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MFZ0"= MyFlashZip0.ax
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BT Broadband Help.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BT Broadband Help.lnk
backup=c:\windows\pss\BT Broadband Help.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Gizmoz Talking Headz.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Gizmoz Talking Headz.lnk
backup=c:\windows\pss\Gizmoz Talking Headz.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^EBox^Start Menu^Programs^Startup^Registration Brothers In Arms EiB.LNK]
path=c:\documents and settings\EBox\Start Menu\Programs\Startup\Registration Brothers In Arms EiB.LNK
backup=c:\windows\pss\Registration Brothers In Arms EiB.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
–a—— 2003-06-26 03:02 184320 c:\program files\Creative\Shared Files\CamTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a—— 2002-11-03 20:02 188416 c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-10-01 17:57 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfeeUpdaterUI]
–a—— 2004-08-06 02:50 139320 c:\program files\Network Associates\Common Framework\UpdaterUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2005-05-31 00:04 1415824 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2006-12-15 03:23 75520 c:\program files\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2006-11-30 21:49 4662776 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"NVSvc"=2 (0x2)
"McTaskManager"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"CVPND"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Java\\j2re1.4.2_05\\bin\\javaw.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\CambridgeSoft\\ChemOffice2008\\ChemDraw\\ChemDraw.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:Shareaza
"6346:UDP"= 6346:UDP:Shareaza
S3 usbprint;Microsoft USB PRINTER Class;c:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 vim;vim;c:\windows\system32\drivers\vim.sys [2004-10-17 5248]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1792c260-c5a2-11da-9777-0040f4da804c}]
\Shell\AutoRun\command - G:\autorun.exe
*Newly Created Service* - ENTDRV51
.
Contents of the 'Scheduled Tasks' folder
2008-10-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-brastk - c:\windows\system32\brastk.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-DAEMON Tools-1033 - c:\program files\D-Tools\daemon.exe
MSConfigStartUp-PCPerf - c:\program files\PC Accelerator 2005 Trial Demo\pcperf.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\EBox\Application Data\Mozilla\Firefox\Profiles\2wiaxj4b.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF -: plugin - c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - c:\program files\CambridgeSoft\ChemOffice2008\Chem3D\npChem3DPlugin.dll
FF -: plugin - c:\program files\CambridgeSoft\ChemOffice2008\ChemDraw\NPCDP32.DLL
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\VideoEgg\Loader\2663\npvideoegg-loader.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
.
——- File Associations ——-
.
VBSFile=blank
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-15 15:17:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
c:\program files\Network Associates\VirusScan\mcshield.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-11-15 15:22:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-15 15:22:38
Pre-Run: 28,820,996,096 bytes free
Post-Run: 30,883,385,344 bytes free
244 — E O F — 2008-11-12 12:43:29