(continued)
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2008-08-16 to 2008-09-16 )))))))))))))))))))))))))))))))
.
2008-09-15 23:04 . 2008-09-15 23:07 <DIR> d----c--- C:\ComboFox
2008-09-14 15:29 . 2008-09-14 16:00 <DIR> d----c--- C:\SmitfraudFix
2008-09-14 15:25 . 2008-09-14 15:56 4,424 --a------ C:\WINDOWS\system32\tmp.reg
2008-09-14 15:22 . 2008-09-14 15:23 1,578,399 --a------ C:\SmitfraudFix.exe
2008-09-14 10:30 . 2008-09-14 10:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-13 20:32 . 2007-11-27 22:56 91,328 --a------ C:\WINDOWS\system32\drivers\msfwdrv.sys
2008-09-13 20:31 . 2007-11-27 22:56 116,416 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2008-09-13 20:27 . 2008-05-15 16:15 53,168 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2008-09-13 20:24 . 2007-03-29 08:56 409,600 -----c--- C:\WINDOWS\system32\dllcache\qmgr.dll
2008-09-13 20:24 . 2007-03-29 08:56 18,944 -----c--- C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2008-09-13 20:24 . 2007-03-29 08:56 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-09-13 20:24 . 2007-03-29 08:56 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll
2008-09-13 20:15 . 2008-09-16 00:02 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-09-13 14:35 . 2008-09-13 14:36 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-09-13 14:34 . 2008-09-13 14:35 <DIR> d-------- C:\Documents and Settings\ROBERT\Application Data\SystemRequirementsLab
2008-09-13 14:29 . 2008-09-13 14:35 <DIR> d-------- C:\Documents and Settings\ROBERT\Application Data\Download Manager
2008-09-13 14:24 . 2008-09-13 14:25 <DIR> d-------- C:\Documents and Settings\ROBERT\Application Data\SPORE
2008-09-13 14:24 . 2008-09-13 14:24 <DIR> dr-h----- C:\Documents and Settings\ROBERT\Application Data\SecuROM
2008-09-13 14:24 . 2008-09-13 14:24 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-09-13 14:15 . 2008-09-13 14:15 <DIR> d----c--- C:\ProgramData
2008-09-13 14:15 . 2008-09-13 14:15 4,330 --a------ C:\WINDOWS\system32\ealregsnapshot1.reg
2008-09-03 03:17 . 2008-09-03 03:52 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-31 13:12 . 2008-08-31 13:14 <DIR> d-------- C:\Program Files\QuickTime
2008-08-29 22:08 . 2008-08-29 22:08 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-29 22:08 . 2008-08-29 22:08 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-24 18:45 . 2008-08-24 18:49 <DIR> d-------- C:\Documents and Settings\Every1\Application Data\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 04:03 --------- d-----w C:\Documents and Settings\ROBERT\Application Data\OpenOffice.org2
2008-09-14 22:03 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-14 22:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-09-13 18:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-13 18:23 --------- d-----w C:\Program Files\Electronic Arts
2008-09-13 17:20 --------- d-----w C:\Documents and Settings\ROBERT\Application Data\uTorrent
2008-08-26 01:48 --------- d-----w C:\Program Files\Java
2008-08-26 01:36 --------- d-----w C:\Documents and Settings\ROBERT\Application Data\ShoppingReport
2008-08-15 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\NOS
2008-08-14 22:26 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-08-14 01:51 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-07-28 17:45 --------- d-----w C:\Documents and Settings\ROBERT\Application Data\DivX
2008-07-27 20:43 --------- d-----w C:\Documents and Settings\ROBERT\Application Data\U3
2008-07-26 22:55 --------- d-----w C:\Program Files\Quicken
2008-07-23 00:32 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-22 16:38 --------- d-----w C:\Documents and Settings\Every1\Application Data\ShoppingReport
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 -c--a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 -c--a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:34 586,240 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-17 23:43 --------- d-----w C:\Program Files\DivX
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 22:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-18 17:52 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-18 18:51 425 ----a-w C:\Program Files\Common Files\AnswerWorks 5.0
2007-01-18 23:07 5,816 ------w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2006-09-02 05:47 1,822,093,720 ------w C:\Program Files\dndsetup_us_trial.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 50528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-06-28 26112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-03-27 126104]
"A Verizon App"="C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE" [2005-05-23 50744]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2006-08-10 230512]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2006-08-10 185456]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2005-06-16 401408]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe" [2006-02-01 1880064]
"Motive SmartBridge"="C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe" [2006-06-23 438359]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"Monitor"="C:\WINDOWS\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-08-08 67112]
C:\Documents and Settings\ROBERT\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCar eMP]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Common Files\\AOL\\1153455590\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1153455590\\EE\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1153455590\\EE\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\wowclient-downloader.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
R2 NwSapAgent;SAP Agent;C:\WINDOWS\System32\svchost.exe [2004-08-04 14336]
R2 OcHealthMon;Windows Live OneCare Health Monitor;C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-08-08 28200]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
R3 PAC207;CIF USB Camera;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2006-11-10 505984]
S3 getPlus(R) Helper;getPlus(R) Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [ ]
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys [2006-09-27 10664]
S3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WINDOWS\system32\drivers\adm8830.sys [2001-08-17 747392]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{234f25e2-541c-11dd-8b5c-00e04c9b3459}]
\Shell\AutoRun\command - F:\StartPortableApps.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Tlom - C:\WINDOWS\system32\FNTS~1\nopdb.exe
HKLM-Run-AOLDialer - C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
HKLM-Run-AIM Sniffer - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\ROBERT\Application Data\Mozilla\Firefox\Profiles\156yovky.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.myspace.com
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npclntax_SeekmoSA.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-16 00:01:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Yahoo!\Antivirus\iSafe.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.bin
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
.
**************************************************************************
.
Completion time: 2008-09-16 0:20:51 - machine was rebooted [ROBERT]
ComboFix-quarantined-files.txt 2008-09-16 04:19:55
Pre-Run: 6,304,993,280 bytes free
Post-Run: 7,238,311,936 bytes free
WinXP_EN_HOM_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
627 --- E O F --- 2008-09-10 07:03:55