littlechaoz
Topic Starter
it seems to attack when i am not at my computer, i ran through the same steps as before, and this is the point i'm not completely getting reading the combofix report, here it is
ComboFix 09-01-01.01 - Owner 2009-01-02 8:28:31.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2943.2500 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\downloads\1564315.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\test.ttt
c:\windows\system32\uniq.tll
c:\windows\system32\win32hlp.cnf
—– BITS: Possible infected sites —–
hxxp://auf-jeder.com
c:\windows\system32\userinit.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.
2009-01-02 08:27 . 2009-01-02 08:28 d——– C:\ComboFix
2009-01-01 08:20 . 2009-01-01 08:24 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-27 16:13 . 2006-09-06 17:43 22,752 –a—— c:\windows\system32\spupdsvc.exe
2008-12-27 14:11 . 2008-12-27 14:11 d——– C:\Nexon
2008-12-27 14:11 . 2008-12-27 16:22 d——– c:\documents and settings\All Users\Application Data\NexonUS
2008-12-27 13:48 . 2008-12-27 14:11 d——– c:\program files\Combat arms
2008-12-27 13:48 . 2008-12-27 13:48 d——– c:\documents and settings\All Users\Application Data\PMB Files
2008-12-27 13:47 . 2008-12-27 13:47 d——– c:\program files\Pando Networks
2008-12-26 11:14 . 2008-07-12 08:18 3,851,784 –a—— c:\windows\system32\D3DX9_39.dll
2008-12-26 11:14 . 2008-07-12 08:18 1,493,528 –a—— c:\windows\system32\D3DCompiler_39.dll
2008-12-26 11:14 . 2008-07-31 10:40 509,448 –a—— c:\windows\system32\XAudio2_2.dll
2008-12-26 11:14 . 2008-07-12 08:18 467,984 –a—— c:\windows\system32\d3dx10_39.dll
2008-12-26 11:14 . 2008-07-31 10:41 238,088 –a—— c:\windows\system32\xactengine3_2.dll
2008-12-26 11:14 . 2008-07-31 10:41 68,616 –a—— c:\windows\system32\XAPOFX1_1.dll
2008-12-26 10:59 . 2008-12-26 10:59 d——– c:\program files\Flying Lab Software
2008-12-26 10:43 . 2008-12-26 10:57 d——– C:\POTBS
2008-12-26 04:42 . 2008-12-26 04:43 d——– c:\program files\Spybot - Search & Destroy
2008-12-26 04:42 . 2008-12-26 05:58 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-26 04:41 . 2008-12-26 04:41 d——– c:\program files\System Security Suite 1.04
2008-12-25 17:47 . 2004-08-04 00:56 21,504 –a—— c:\windows\system32\hidserv.dll
2008-12-25 17:47 . 2004-08-04 00:56 21,504 –a–c— c:\windows\system32\dllcache\hidserv.dll
2008-12-25 17:40 . 2008-12-25 17:40 d——– c:\program files\Logitech
2008-12-25 17:40 . 2008-12-25 17:40 d——– c:\documents and settings\All Users\Application Data\Logitech
2008-12-23 23:22 . 2008-12-23 23:23 d——– c:\program files\ERUNT
2008-12-23 08:31 . 2008-12-23 08:31 134,880 –a—— c:\windows\system32\drivers\sunkfiltp.sys
2008-12-23 08:31 . 2008-12-23 08:31 3,584 –a—— c:\windows\jrfbzffo.exe
2008-12-23 03:51 . 2008-12-23 03:51 61,440 –a—— c:\windows\system32\drivers\clbp.sys
2008-12-22 01:11 . 2008-12-22 01:11 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-22 01:07 . 2008-12-26 04:12 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-22 01:07 . 2008-12-22 01:07 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-22 01:07 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-22 01:07 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-22 00:43 . 2008-12-22 00:43 d——– c:\program files\Trend Micro
2008-12-21 23:24 . 2008-12-22 01:09 d——– C:\hijackthis
2008-12-21 22:03 . 2008-12-22 08:28 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-11 15:37 . 2008-12-11 15:37 42,320 –a—— c:\windows\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 18:50 148 —-a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2008-12-26 15:59 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-26 15:40 ——— d—–w c:\documents and settings\Owner\Application Data\IGN_DLM
2008-12-26 11:06 ——— d—–w c:\program files\Sony
2008-12-26 09:13 ——— d—–w c:\program files\BitComet
2008-12-23 13:36 ——— d—–w c:\program files\CCP4
2008-12-23 13:36 ——— d—–w c:\program files\CCP3
2008-12-23 08:17 ——— d—–w c:\program files\Symantec
2008-12-23 08:17 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2008-12-23 08:10 ——— d—–w c:\program files\CCP2
2008-12-23 08:06 ——— d—–w c:\program files\Sega
2008-12-23 08:00 ——— d—–w c:\program files\EVEMon
2008-12-23 08:00 ——— d—–w c:\program files\DNA
2008-12-23 07:58 ——— d—–w c:\program files\BigFix
2008-12-22 05:08 ——— d—–w c:\program files\IONCROSS Freelancer Server Operator mk.V.1
2008-12-22 03:02 ——— d—–w c:\documents and settings\Owner\Application Data\Xfire
2008-12-17 03:27 ——— d—–w c:\program files\Steam
2008-12-17 00:56 ——— d-s—w c:\program files\Xfire
2008-12-16 16:48 ——— d—–w c:\program files\World of Warcraft
2008-12-10 06:44 ——— d—–w c:\program files\Stardock
2008-12-10 06:41 ——— d—–w c:\program files\MagicISO
2008-11-25 00:46 ——— d—–w c:\program files\Common Files\Blizzard Entertainment
2008-11-24 23:13 ——— d—–w c:\documents and settings\All Users\Application Data\Blizzard
2008-11-19 16:25 ——— d—–w c:\program files\Activision
2008-11-13 02:00 ——— d—–w c:\documents and settings\Owner\Application Data\EVEMon
2008-10-30 13:23 5,529,600 —-a-w c:\program files\FarCry2.exe
2008-10-30 12:33 22,328 —-a-w c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2008-09-20 12:23 683 —-a-w c:\program files\xerox.rar
2003-12-18 15:33 20,102 —-a-w c:\program files\Readme.txt
2003-09-03 11:46 10,960 —-a-w c:\program files\EULA.txt
2002-10-17 10:44 2,699,264 —-a-w c:\program files\Common Files\dmcr.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"Launch LgDevAgt"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2007-07-17 99600]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-07-17 1687824]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-07-17 2094352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NaturalColorLoad.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NaturalColorLoad.lnk
backup=c:\windows\pss\NaturalColorLoad.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
backup=c:\windows\pss\ERUNT AutoBackup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Impulse Dock.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Impulse Dock.lnk
backup=c:\windows\pss\Impulse Dock.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Memeo AutoSync Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Memeo AutoSync Launcher.lnk
backup=c:\windows\pss\Memeo AutoSync Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^RollerCoaster Tycoon 3 Registration.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk
backup=c:\windows\pss\RollerCoaster Tycoon 3 Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Sins of a Solar Empire Launcher.lnk
backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^WD Anywhere Backup Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk
backup=c:\windows\pss\WD Anywhere Backup Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2007-05-11 02:06 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
–a—— 2008-06-24 23:25 289088 c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 07:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
–a—— 2008-07-21 13:07 2752512 c:\program files\Electronic Arts\EADM\Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2008-08-01 12:36 1103216 c:\program files\Download Manager\DLM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
–a—— 2007-01-19 11:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 20:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-07-07 09:42 2156368 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2008-10-08 22:21 1410296 c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM]
–a—— 2004-03-12 00:18 135168 c:\program files\Digital Media Reader\shwiconEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-10-13 07:23 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a–c— 2004-07-03 04:49 57344 c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
–a–c— 2004-07-06 03:05 2550272 c:\windows\ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
–a—— 2004-03-18 00:10 61952 c:\windows\system32\Hdaudpropshortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Ati HotKey Poller"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"WMPNetworkSvc"=2 (0x2)
"WDBtnMgrSvc.exe"=2 (0x2)
"WANMiniportService"=2 (0x2)
"usnjsvc"=3 (0x3)
"SymWSC"=2 (0x2)
"SBService"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"navapsvc"=2 (0x2)
"LVPrcSrv"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"AOL ACS"=2 (0x2)
"ALG"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Program Files\\OPU IRC Script\\mirc.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_NO_SSE.exe"=
"c:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_SSE.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Launcher.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\PaleStar\\DarkSpace\\.Cache\\DarkSpace\\Client.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10883:TCP"= 10883:TCP:BitComet 10883 TCP
"10883:UDP"= 10883:UDP:BitComet 10883 UDP
"56113:TCP"= 56113:TCP:Pando Media Booster
"56113:UDP"= 56113:UDP:Pando Media Booster
S3 bfastfao;bfastfao;\??\c:\docume~1\Owner\LOCALS~1\Temp\bfastfao.sys []
S4 AutoSyncService;Memeo AutoSync ;"c:\program files\Memeo\AutoSync\MemeoService.exe" [2007-07-06 31768]
S4 WDBtnMgrSvc.exe;WD Drive Manager Service;"c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe" [2008-05-16 102400]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\N]
\Shell\AutoRun\command - N:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70909c92-827d-11dd-bbac-00038a000015}]
\Shell\AutoRun\command - J:\setup.exe
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\baqowxlx.default\
FF - prefs.js: browser.startup.homepage - www.eve-online.com
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 08:35:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\Network1-4008096457-3688145937-1003348303-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\EA GAMES\S*NULL*P*NULL*O*NULL*R*NULL*E*NULL*"!]
"Order"=hex:08,00,00,00,02,00,00,00,76,02,00,00,01,00,00,00,05,00,00,00,78,00,\
00,00,00,00,00,00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,\
00,46,08,00,00,24,39,d8,8b,20,00,45,41,48,45,4c,50,7e,31,2e,4c,4e,4b,00,00,\
2e,00,03,00,04,00,ef,be,24,39,d8,8b,71,39,93,73,14,00,00,00,45,00,41,00,20,\
00,48,00,65,00,6c,00,70,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,\
0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,78,00,00,00,01,00,00,\
00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,00,be,05,00,00,\
24,39,d8,8b,20,00,52,45,41,44,4d,45,7e,31,2e,4c,4e,4b,00,00,2e,00,03,00,04,\
00,ef,be,24,39,d8,8b,71,39,93,73,14,00,00,00,52,00,65,00,61,00,64,00,20,00,\
4d,00,65,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,\
00,00,00,1c,00,00,00,00,00,00,00,00,00,7c,00,00,00,02,00,00,00,6e,00,00,00,\
41,75,67,4d,02,00,00,00,01,00,00,00,5c,00,32,00,6d,06,00,00,24,39,d8,8b,20,\
00,53,50,4f,52,45,43,7e,31,2e,4c,4e,4b,00,00,32,00,03,00,04,00,ef,be,24,39,\
d8,8b,71,39,93,73,14,00,00,00,53,00,70,00,6f,00,72,00,65,00,2e,00,63,00,6f,\
00,6d,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,\
00,00,1c,00,00,00,00,00,00,00,00,00,74,00,00,00,03,00,00,00,66,00,00,00,41,\
75,67,4d,02,00,00,00,01,00,00,00,54,00,32,00,58,07,00,00,24,39,d8,8b,20,00,\
53,50,4f,52,45,7e,31,2e,4c,4e,4b,00,2c,00,03,00,04,00,ef,be,24,39,d8,8b,71,\
39,93,73,14,00,00,00,53,00,50,00,4f,00,52,00,45,00,22,21,2e,00,6c,00,6e,00,\
6b,00,00,00,1a,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1a,00,00,00,00,00,00,\
00,00,00,8a,00,00,00,04,00,00,00,7c,00,00,00,41,75,67,4d,02,00,00,00,01,00,\
00,00,6a,00,32,00,d3,07,00,00,24,39,d8,8b,20,00,55,4e,49,4e,53,54,7e,31,2e,\
4c,4e,4b,00,00,40,00,03,00,04,00,ef,be,24,39,d8,8b,71,39,93,73,14,00,00,00,\
55,00,6e,00,69,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,20,00,53,00,50,00,4f,\
00,52,00,45,00,22,21,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,\
ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00
[HKEY_USERS\Network1-4008096457-3688145937-1003348303-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Electronic Arts\S*NULL*P*NULL*O*NULL*R*NULL*E*NULL*"!]
"Order"=hex:08,00,00,00,02,00,00,00,76,02,00,00,01,00,00,00,05,00,00,00,78,00,\
00,00,00,00,00,00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,\
00,46,08,00,00,52,39,5b,1f,20,00,45,41,48,45,4c,50,7e,31,2e,4c,4e,4b,00,00,\
2e,00,03,00,04,00,ef,be,28,39,1d,6a,69,39,96,9b,14,00,00,00,45,00,41,00,20,\
00,48,00,65,00,6c,00,70,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,\
0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,78,00,00,00,01,00,00,\
00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,00,be,05,00,00,\
52,39,5b,1f,20,00,52,45,41,44,4d,45,7e,31,2e,4c,4e,4b,00,00,2e,00,03,00,04,\
00,ef,be,28,39,1d,6a,69,39,96,9b,14,00,00,00,52,00,65,00,61,00,64,00,20,00,\
4d,00,65,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,\
00,00,00,1c,00,00,00,00,00,00,00,00,00,7c,00,00,00,02,00,00,00,6e,00,00,00,\
41,75,67,4d,02,00,00,00,01,00,00,00,5c,00,32,00,6d,06,00,00,52,39,5b,1f,20,\
00,53,50,4f,52,45,43,7e,31,2e,4c,4e,4b,00,00,32,00,03,00,04,00,ef,be,28,39,\
1d,6a,69,39,96,9b,14,00,00,00,53,00,70,00,6f,00,72,00,65,00,2e,00,63,00,6f,\
00,6d,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,\
00,00,1c,00,00,00,00,00,00,00,00,00,74,00,00,00,03,00,00,00,66,00,00,00,41,\
75,67,4d,02,00,00,00,01,00,00,00,54,00,32,00,58,07,00,00,52,39,5b,1f,20,00,\
53,50,4f,52,45,7e,31,2e,4c,4e,4b,00,2c,00,03,00,04,00,ef,be,28,39,1c,6a,5a,\
39,03,7a,14,00,00,00,53,00,50,00,4f,00,52,00,45,00,22,21,2e,00,6c,00,6e,00,\
6b,00,00,00,1a,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1a,00,00,00,00,00,00,\
00,00,00,8a,00,00,00,04,00,00,00,7c,00,00,00,41,75,67,4d,02,00,00,00,01,00,\
00,00,6a,00,32,00,b6,07,00,00,52,39,5b,1f,20,00,55,4e,49,4e,53,54,7e,31,2e,\
4c,4e,4b,00,00,40,00,03,00,04,00,ef,be,28,39,1c,6a,69,39,96,9b,14,00,00,00,\
55,00,6e,00,69,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,20,00,53,00,50,00,4f,\
00,52,00,45,00,22,21,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,\
ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00
[HKEY_USERS\Network1-4008096457-3688145937-1003348303-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’e*NULL*’B*NULL*’ ’N*NULL*’9 ’x*NULL*’9 ]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,b0,00,00,00,01,00,00,00,01,00,00,00,a4,00,\
00,00,00,00,00,00,96,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,84,00,31,\
00,00,00,00,00,51,39,db,68,10,00,59,58,42,60,46,55,7e,31,00,00,5e,00,03,00,\
04,00,ef,be,51,39,db,68,51,39,e0,68,14,00,00,00,52,01,7d,01,13,20,be,00,1a,\
20,e8,00,1a,20,cc,00,92,01,30,20,92,01,59,00,92,01,78,00,92,01,60,01,92,01,\
42,00,20,00,81,00,60,00,1a,20,c2,00,1a,20,f1,00,81,00,61,01,92,01,66,00,1a,\
20,ea,00,21,20,55,00,81,00,60,00,00,00,18,00,0e,00,00,00,0a,00,ef,be,00,00,\
00,00,18,00,00,00,00,00,00,00,00,00
.
———————— Other Running Processes ————————
.
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\spool\drivers\w32x86\3\HP1006MC.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-02 8:43:22 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2009-01-02 13:43:20
ComboFix2.txt 2008-12-26 09:39:06
Pre-Run: 61,999,808,512 bytes free
Post-Run: 62,054,125,568 bytes free
320
ComboFix 09-01-01.01 - Owner 2009-01-02 8:28:31.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2943.2500 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\downloads\1564315.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\test.ttt
c:\windows\system32\uniq.tll
c:\windows\system32\win32hlp.cnf
—– BITS: Possible infected sites —–
hxxp://auf-jeder.com
c:\windows\system32\userinit.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2008-12-02 to 2009-01-02 )))))))))))))))))))))))))))))))
.
2009-01-02 08:27 . 2009-01-02 08:28 d——– C:\ComboFix
2009-01-01 08:20 . 2009-01-01 08:24 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-27 16:13 . 2006-09-06 17:43 22,752 –a—— c:\windows\system32\spupdsvc.exe
2008-12-27 14:11 . 2008-12-27 14:11 d——– C:\Nexon
2008-12-27 14:11 . 2008-12-27 16:22 d——– c:\documents and settings\All Users\Application Data\NexonUS
2008-12-27 13:48 . 2008-12-27 14:11 d——– c:\program files\Combat arms
2008-12-27 13:48 . 2008-12-27 13:48 d——– c:\documents and settings\All Users\Application Data\PMB Files
2008-12-27 13:47 . 2008-12-27 13:47 d——– c:\program files\Pando Networks
2008-12-26 11:14 . 2008-07-12 08:18 3,851,784 –a—— c:\windows\system32\D3DX9_39.dll
2008-12-26 11:14 . 2008-07-12 08:18 1,493,528 –a—— c:\windows\system32\D3DCompiler_39.dll
2008-12-26 11:14 . 2008-07-31 10:40 509,448 –a—— c:\windows\system32\XAudio2_2.dll
2008-12-26 11:14 . 2008-07-12 08:18 467,984 –a—— c:\windows\system32\d3dx10_39.dll
2008-12-26 11:14 . 2008-07-31 10:41 238,088 –a—— c:\windows\system32\xactengine3_2.dll
2008-12-26 11:14 . 2008-07-31 10:41 68,616 –a—— c:\windows\system32\XAPOFX1_1.dll
2008-12-26 10:59 . 2008-12-26 10:59 d——– c:\program files\Flying Lab Software
2008-12-26 10:43 . 2008-12-26 10:57 d——– C:\POTBS
2008-12-26 04:42 . 2008-12-26 04:43 d——– c:\program files\Spybot - Search & Destroy
2008-12-26 04:42 . 2008-12-26 05:58 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-26 04:41 . 2008-12-26 04:41 d——– c:\program files\System Security Suite 1.04
2008-12-25 17:47 . 2004-08-04 00:56 21,504 –a—— c:\windows\system32\hidserv.dll
2008-12-25 17:47 . 2004-08-04 00:56 21,504 –a–c— c:\windows\system32\dllcache\hidserv.dll
2008-12-25 17:40 . 2008-12-25 17:40 d——– c:\program files\Logitech
2008-12-25 17:40 . 2008-12-25 17:40 d——– c:\documents and settings\All Users\Application Data\Logitech
2008-12-23 23:22 . 2008-12-23 23:23 d——– c:\program files\ERUNT
2008-12-23 08:31 . 2008-12-23 08:31 134,880 –a—— c:\windows\system32\drivers\sunkfiltp.sys
2008-12-23 08:31 . 2008-12-23 08:31 3,584 –a—— c:\windows\jrfbzffo.exe
2008-12-23 03:51 . 2008-12-23 03:51 61,440 –a—— c:\windows\system32\drivers\clbp.sys
2008-12-22 01:11 . 2008-12-22 01:11 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-22 01:07 . 2008-12-26 04:12 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-22 01:07 . 2008-12-22 01:07 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-22 01:07 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-22 01:07 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-22 00:43 . 2008-12-22 00:43 d——– c:\program files\Trend Micro
2008-12-21 23:24 . 2008-12-22 01:09 d——– C:\hijackthis
2008-12-21 22:03 . 2008-12-22 08:28 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-11 15:37 . 2008-12-11 15:37 42,320 –a—— c:\windows\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 18:50 148 —-a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2008-12-26 15:59 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-26 15:40 ——— d—–w c:\documents and settings\Owner\Application Data\IGN_DLM
2008-12-26 11:06 ——— d—–w c:\program files\Sony
2008-12-26 09:13 ——— d—–w c:\program files\BitComet
2008-12-23 13:36 ——— d—–w c:\program files\CCP4
2008-12-23 13:36 ——— d—–w c:\program files\CCP3
2008-12-23 08:17 ——— d—–w c:\program files\Symantec
2008-12-23 08:17 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2008-12-23 08:10 ——— d—–w c:\program files\CCP2
2008-12-23 08:06 ——— d—–w c:\program files\Sega
2008-12-23 08:00 ——— d—–w c:\program files\EVEMon
2008-12-23 08:00 ——— d—–w c:\program files\DNA
2008-12-23 07:58 ——— d—–w c:\program files\BigFix
2008-12-22 05:08 ——— d—–w c:\program files\IONCROSS Freelancer Server Operator mk.V.1
2008-12-22 03:02 ——— d—–w c:\documents and settings\Owner\Application Data\Xfire
2008-12-17 03:27 ——— d—–w c:\program files\Steam
2008-12-17 00:56 ——— d-s—w c:\program files\Xfire
2008-12-16 16:48 ——— d—–w c:\program files\World of Warcraft
2008-12-10 06:44 ——— d—–w c:\program files\Stardock
2008-12-10 06:41 ——— d—–w c:\program files\MagicISO
2008-11-25 00:46 ——— d—–w c:\program files\Common Files\Blizzard Entertainment
2008-11-24 23:13 ——— d—–w c:\documents and settings\All Users\Application Data\Blizzard
2008-11-19 16:25 ——— d—–w c:\program files\Activision
2008-11-13 02:00 ——— d—–w c:\documents and settings\Owner\Application Data\EVEMon
2008-10-30 13:23 5,529,600 —-a-w c:\program files\FarCry2.exe
2008-10-30 12:33 22,328 —-a-w c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2008-09-20 12:23 683 —-a-w c:\program files\xerox.rar
2003-12-18 15:33 20,102 —-a-w c:\program files\Readme.txt
2003-09-03 11:46 10,960 —-a-w c:\program files\EULA.txt
2002-10-17 10:44 2,699,264 —-a-w c:\program files\Common Files\dmcr.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 2061816]
"Launch LgDevAgt"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2007-07-17 99600]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-07-17 1687824]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-07-17 2094352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NaturalColorLoad.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NaturalColorLoad.lnk
backup=c:\windows\pss\NaturalColorLoad.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
backup=c:\windows\pss\ERUNT AutoBackup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Impulse Dock.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Impulse Dock.lnk
backup=c:\windows\pss\Impulse Dock.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Memeo AutoSync Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Memeo AutoSync Launcher.lnk
backup=c:\windows\pss\Memeo AutoSync Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^RollerCoaster Tycoon 3 Registration.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk
backup=c:\windows\pss\RollerCoaster Tycoon 3 Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Sins of a Solar Empire Launcher.lnk
backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^WD Anywhere Backup Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\WD Anywhere Backup Launcher.lnk
backup=c:\windows\pss\WD Anywhere Backup Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2007-05-11 02:06 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
–a—— 2008-06-24 23:25 289088 c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 07:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
–a—— 2008-07-21 13:07 2752512 c:\program files\Electronic Arts\EADM\Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2008-08-01 12:36 1103216 c:\program files\Download Manager\DLM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
–a—— 2007-01-19 11:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 20:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-07-07 09:42 2156368 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2008-10-08 22:21 1410296 c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM]
–a—— 2004-03-12 00:18 135168 c:\program files\Digital Media Reader\shwiconEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-10-13 07:23 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a–c— 2004-07-03 04:49 57344 c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
–a–c— 2004-07-06 03:05 2550272 c:\windows\ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
–a—— 2004-03-18 00:10 61952 c:\windows\system32\Hdaudpropshortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Ati HotKey Poller"=2 (0x2)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"WMPNetworkSvc"=2 (0x2)
"WDBtnMgrSvc.exe"=2 (0x2)
"WANMiniportService"=2 (0x2)
"usnjsvc"=3 (0x3)
"SymWSC"=2 (0x2)
"SBService"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"navapsvc"=2 (0x2)
"LVPrcSrv"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"AOL ACS"=2 (0x2)
"ALG"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Program Files\\OPU IRC Script\\mirc.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_NO_SSE.exe"=
"c:\\Program Files\\Reality Pump\\Earth 2160\\Earth2160_SSE.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Launcher.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\PaleStar\\DarkSpace\\.Cache\\DarkSpace\\Client.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms\\NMService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10883:TCP"= 10883:TCP:BitComet 10883 TCP
"10883:UDP"= 10883:UDP:BitComet 10883 UDP
"56113:TCP"= 56113:TCP:Pando Media Booster
"56113:UDP"= 56113:UDP:Pando Media Booster
S3 bfastfao;bfastfao;\??\c:\docume~1\Owner\LOCALS~1\Temp\bfastfao.sys []
S4 AutoSyncService;Memeo AutoSync ;"c:\program files\Memeo\AutoSync\MemeoService.exe" [2007-07-06 31768]
S4 WDBtnMgrSvc.exe;WD Drive Manager Service;"c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe" [2008-05-16 102400]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\N]
\Shell\AutoRun\command - N:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70909c92-827d-11dd-bbac-00038a000015}]
\Shell\AutoRun\command - J:\setup.exe
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\baqowxlx.default\
FF - prefs.js: browser.startup.homepage - www.eve-online.com
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 08:35:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\Network1-4008096457-3688145937-1003348303-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\EA GAMES\S*NULL*P*NULL*O*NULL*R*NULL*E*NULL*"!]
"Order"=hex:08,00,00,00,02,00,00,00,76,02,00,00,01,00,00,00,05,00,00,00,78,00,\
00,00,00,00,00,00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,\
00,46,08,00,00,24,39,d8,8b,20,00,45,41,48,45,4c,50,7e,31,2e,4c,4e,4b,00,00,\
2e,00,03,00,04,00,ef,be,24,39,d8,8b,71,39,93,73,14,00,00,00,45,00,41,00,20,\
00,48,00,65,00,6c,00,70,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,\
0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,78,00,00,00,01,00,00,\
00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,00,be,05,00,00,\
24,39,d8,8b,20,00,52,45,41,44,4d,45,7e,31,2e,4c,4e,4b,00,00,2e,00,03,00,04,\
00,ef,be,24,39,d8,8b,71,39,93,73,14,00,00,00,52,00,65,00,61,00,64,00,20,00,\
4d,00,65,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,\
00,00,00,1c,00,00,00,00,00,00,00,00,00,7c,00,00,00,02,00,00,00,6e,00,00,00,\
41,75,67,4d,02,00,00,00,01,00,00,00,5c,00,32,00,6d,06,00,00,24,39,d8,8b,20,\
00,53,50,4f,52,45,43,7e,31,2e,4c,4e,4b,00,00,32,00,03,00,04,00,ef,be,24,39,\
d8,8b,71,39,93,73,14,00,00,00,53,00,70,00,6f,00,72,00,65,00,2e,00,63,00,6f,\
00,6d,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,\
00,00,1c,00,00,00,00,00,00,00,00,00,74,00,00,00,03,00,00,00,66,00,00,00,41,\
75,67,4d,02,00,00,00,01,00,00,00,54,00,32,00,58,07,00,00,24,39,d8,8b,20,00,\
53,50,4f,52,45,7e,31,2e,4c,4e,4b,00,2c,00,03,00,04,00,ef,be,24,39,d8,8b,71,\
39,93,73,14,00,00,00,53,00,50,00,4f,00,52,00,45,00,22,21,2e,00,6c,00,6e,00,\
6b,00,00,00,1a,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1a,00,00,00,00,00,00,\
00,00,00,8a,00,00,00,04,00,00,00,7c,00,00,00,41,75,67,4d,02,00,00,00,01,00,\
00,00,6a,00,32,00,d3,07,00,00,24,39,d8,8b,20,00,55,4e,49,4e,53,54,7e,31,2e,\
4c,4e,4b,00,00,40,00,03,00,04,00,ef,be,24,39,d8,8b,71,39,93,73,14,00,00,00,\
55,00,6e,00,69,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,20,00,53,00,50,00,4f,\
00,52,00,45,00,22,21,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,\
ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00
[HKEY_USERS\Network1-4008096457-3688145937-1003348303-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Electronic Arts\S*NULL*P*NULL*O*NULL*R*NULL*E*NULL*"!]
"Order"=hex:08,00,00,00,02,00,00,00,76,02,00,00,01,00,00,00,05,00,00,00,78,00,\
00,00,00,00,00,00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,\
00,46,08,00,00,52,39,5b,1f,20,00,45,41,48,45,4c,50,7e,31,2e,4c,4e,4b,00,00,\
2e,00,03,00,04,00,ef,be,28,39,1d,6a,69,39,96,9b,14,00,00,00,45,00,41,00,20,\
00,48,00,65,00,6c,00,70,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,\
0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,78,00,00,00,01,00,00,\
00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,00,be,05,00,00,\
52,39,5b,1f,20,00,52,45,41,44,4d,45,7e,31,2e,4c,4e,4b,00,00,2e,00,03,00,04,\
00,ef,be,28,39,1d,6a,69,39,96,9b,14,00,00,00,52,00,65,00,61,00,64,00,20,00,\
4d,00,65,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,\
00,00,00,1c,00,00,00,00,00,00,00,00,00,7c,00,00,00,02,00,00,00,6e,00,00,00,\
41,75,67,4d,02,00,00,00,01,00,00,00,5c,00,32,00,6d,06,00,00,52,39,5b,1f,20,\
00,53,50,4f,52,45,43,7e,31,2e,4c,4e,4b,00,00,32,00,03,00,04,00,ef,be,28,39,\
1d,6a,69,39,96,9b,14,00,00,00,53,00,70,00,6f,00,72,00,65,00,2e,00,63,00,6f,\
00,6d,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,\
00,00,1c,00,00,00,00,00,00,00,00,00,74,00,00,00,03,00,00,00,66,00,00,00,41,\
75,67,4d,02,00,00,00,01,00,00,00,54,00,32,00,58,07,00,00,52,39,5b,1f,20,00,\
53,50,4f,52,45,7e,31,2e,4c,4e,4b,00,2c,00,03,00,04,00,ef,be,28,39,1c,6a,5a,\
39,03,7a,14,00,00,00,53,00,50,00,4f,00,52,00,45,00,22,21,2e,00,6c,00,6e,00,\
6b,00,00,00,1a,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1a,00,00,00,00,00,00,\
00,00,00,8a,00,00,00,04,00,00,00,7c,00,00,00,41,75,67,4d,02,00,00,00,01,00,\
00,00,6a,00,32,00,b6,07,00,00,52,39,5b,1f,20,00,55,4e,49,4e,53,54,7e,31,2e,\
4c,4e,4b,00,00,40,00,03,00,04,00,ef,be,28,39,1c,6a,69,39,96,9b,14,00,00,00,\
55,00,6e,00,69,00,6e,00,73,00,74,00,61,00,6c,00,6c,00,20,00,53,00,50,00,4f,\
00,52,00,45,00,22,21,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,\
ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00
[HKEY_USERS\Network1-4008096457-3688145937-1003348303-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’e*NULL*’B*NULL*’ ’N*NULL*’9 ’x*NULL*’9 ]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,b0,00,00,00,01,00,00,00,01,00,00,00,a4,00,\
00,00,00,00,00,00,96,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,84,00,31,\
00,00,00,00,00,51,39,db,68,10,00,59,58,42,60,46,55,7e,31,00,00,5e,00,03,00,\
04,00,ef,be,51,39,db,68,51,39,e0,68,14,00,00,00,52,01,7d,01,13,20,be,00,1a,\
20,e8,00,1a,20,cc,00,92,01,30,20,92,01,59,00,92,01,78,00,92,01,60,01,92,01,\
42,00,20,00,81,00,60,00,1a,20,c2,00,1a,20,f1,00,81,00,61,01,92,01,66,00,1a,\
20,ea,00,21,20,55,00,81,00,60,00,00,00,18,00,0e,00,00,00,0a,00,ef,be,00,00,\
00,00,18,00,00,00,00,00,00,00,00,00
.
———————— Other Running Processes ————————
.
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\spool\drivers\w32x86\3\HP1006MC.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-02 8:43:22 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2009-01-02 13:43:20
ComboFix2.txt 2008-12-26 09:39:06
Pre-Run: 61,999,808,512 bytes free
Post-Run: 62,054,125,568 bytes free
320