ComboFix 09-12-26.04 - RM 27/12/2009 22:05:08.2.2 - x86 NETWORK Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.654 [GMT 0:00] Running from: c:\documents and settings\[removed]\Desktop\cfix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\at vcox.dll c:\windows\system32\at)iieXx.dLl c:\windows\system32\atipdlxx.dll c:\windows\system32\au$iod%v.dll . ---- Previous Run ------- . c:\docume~1\RM\LOCALS~1\Temp\wscsvc32.exe c:\windows\system32\at vcox.dll c:\windows\system32\at)iieXx.dLl c:\windows\system32\atipdlxx.dll c:\windows\system32\au$iod%v.dll c:\windows\system32\drivers\H8SRTqpxoiqhkym.sys c:\windows\system32\H8SRTioxbubrrou.dll c:\windows\system32\H8SRTiybmlillxf.dll c:\windows\system32\H8SRTtexylnqjgl.dat c:\windows\system32\install.exe c:\windows\system32\Install.txt c:\windows\system32\krl32mainweq.dll c:\windows\system32\srcr.dat . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_H8SRTd.sys -------\Legacy_H8SRTd.sys -------\Legacy_BOONTY_GAMES -------\Legacy_IPRIP -------\Legacy_OREANS32 -------\Service_Boonty Games -------\Service_Iprip -------\Service_oreans32 ((((((((((((((((((((((((( Files Created from 2009-11-27 to 2009-12-27 ))))))))))))))))))))))))))))))) . 2009-12-24 17:48 . 2009-12-24 17:48 -------- d-----w- C:\rsit 2009-12-24 12:14 . 2009-12-24 12:14 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE 2009-12-24 12:14 . 2009-12-24 12:14 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-12-18 17:30 . 2009-12-18 17:30 -------- d-----w- c:\program files\Trend Micro 2009-12-16 16:01 . 2009-12-16 16:01 -------- d-----w- c:\documents and settings\RM\Application Data\GetRightToGo 2009-12-13 16:57 . 2009-12-13 16:57 -------- d-----w- C:\TESCO_SKILLS_DVD 2009-12-08 20:32 . 2009-12-08 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks 2009-12-04 08:56 . 2009-12-04 08:56 -------- d-----w- c:\documents and settings\Deborah\Local Settings\Application Data\Temp . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-24 17:45 . 2004-12-13 14:56 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000004-00000000-00000000-00001102-00000004-20061102}.dat 2009-12-24 17:45 . 2004-12-13 14:56 384 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000000-00001102-00000004-20061102}.dat 2009-12-24 12:17 . 2005-09-22 10:50 -------- d-----w- c:\program files\Shareaza 2009-12-24 12:16 . 2007-05-09 16:08 -------- d-----w- c:\program files\LimeWire 2009-12-24 12:16 . 2005-09-30 17:13 -------- d-----w- c:\program files\Ares 2009-12-17 00:04 . 2008-06-11 09:34 102360 -c--a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT 2009-12-08 20:06 . 2009-12-08 20:06 5562672 ----a-w- c:\documents and settings\RM\Application Data\TVU Networks\TVU AutoUpgrade\TVUPlayer2.4.9.1.exe 2009-12-02 22:12 . 2007-05-29 18:21 -------- d-----w- c:\documents and settings\Deborah\Application Data\LimeWire 2009-12-02 10:55 . 2007-12-24 16:27 -------- d-----w- c:\program files\McAfee 2009-12-01 19:29 . 2007-12-24 16:23 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-11-22 09:48 . 2005-07-09 21:11 -------- d-----w- c:\documents and settings\Deborah\Application Data\Ahead 2009-11-19 17:08 . 2007-06-13 20:19 -------- d-----w- c:\program files\Games 2009-11-18 10:38 . 2008-02-12 10:01 -------- d-----w- c:\documents and settings\Deborah\Application Data\Samsung 2009-11-10 22:29 . 2009-11-10 22:28 17221104 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\rp\RealPlayerSPGold.exe 2009-11-06 20:31 . 2005-11-13 01:31 16 ----a-w- c:\windows\popcinfo.dat 2009-10-29 07:45 . 2004-08-04 05:00 916480 ----a-w- c:\windows\system32\wininet.dll 2009-10-21 05:38 . 2004-08-04 05:00 75776 ----a-w- c:\windows\system32\strmfilt.dll 2009-10-21 05:38 . 2004-08-04 05:00 25088 ----a-w- c:\windows\system32\httpapi.dll 2009-10-20 16:20 . 2004-08-04 05:00 265728 ----a-w- c:\windows\system32\drivers\http.sys 2009-10-13 10:30 . 2004-08-04 05:00 270336 ----a-w- c:\windows\system32\oakley.dll 2009-10-12 13:38 . 2004-08-04 05:00 149504 ----a-w- c:\windows\system32\rastls.dll 2009-10-12 13:38 . 2004-08-04 05:00 79872 ----a-w- c:\windows\system32\raschap.dll 2009-10-01 23:07 . 2009-10-01 23:07 8406648 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\gtb_us\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe 2009-10-01 23:07 . 2009-10-01 23:07 10309448 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\chr\ChromeInstaller.exe 2009-10-01 23:07 . 2009-10-01 23:07 64000 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\RUP\inst_config\gcapi_dll.dll 2009-10-01 23:07 . 2009-10-01 23:07 52288 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\RUP\inst_config\gtapi.dll 2009-10-01 23:07 . 2009-10-01 23:07 50688 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\RUP\inst_config\fftbapi.dll 2009-10-01 23:07 . 2009-10-01 23:07 114688 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\RUP\inst_config\compat.dll 2009-10-01 23:06 . 2009-10-01 23:06 488968 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\setup.exe 2006-12-08 16:40 . 2006-12-08 16:40 278528 -c--a-w- c:\program files\Common Files\FDEUnInstaller.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-04 68856] "AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-04-16 102400] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008] "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752] "IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-21 29744] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344] "CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056] "SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2008-04-14 53760] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ lsdelete [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\WinMX\\WinMX.exe"= "c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"= "c:\\Program Files\\GameSpy Arcade\\Aphex.exe"= "c:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"= "c:\\Program Files\\Sierra On-Line\\SIGSPat.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"= "c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"= "c:\\WINDOWS\\SYSTEM32\\PnkBstrA.exe"= "c:\\WINDOWS\\SYSTEM32\\PnkBstrB.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\tv players\\PPStream\\PPStream.exe"= "c:\\Program Files\\tv players\\PPStream\\PPSAP.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\SAMSUNG\\Samsung New PC Studio\\npsasvr.exe"= "c:\\Program Files\\SAMSUNG\\Samsung New PC Studio\\npsvsvr.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "6346:TCP"= 6346:TCP:Shareaza "6346:UDP"= 6346:UDP:Shareaza "3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping "3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R0 d347bus;d347bus;c:\windows\SYSTEM32\DRIVERS\d347bus.sys [21/02/2005 20:53 155136] R0 d347prt;d347prt;c:\windows\SYSTEM32\DRIVERS\d347prt.sys [21/02/2005 20:53 5248] S2 FsUsbExService;FsUsbExService;c:\windows\SYSTEM32\FsUsbExService.Exe [08/10/2009 10:57 233472] S2 gupdate1c98c3316aac6a2;Google Update Service (gupdate1c98c3316aac6a2);c:\program files\Google\Update\GoogleUpdate.exe [11/02/2009 10:25 133104] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [28/08/2008 17:31 93320] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\SYSTEM32\DRIVERS\ASPI32.SYS [27/03/2006 12:58 16512] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [03/09/2007 14:00 29744] S3 imhidusb;Immersion's HID USB Driver;c:\windows\SYSTEM32\DRIVERS\imhidusb.sys [15/08/2000 15:49 31056] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc . ------- Supplementary Scan ------- . uStart Page = hxxp://www.orange.co.uk/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab . - - - - ORPHANS REMOVED - - - - HKCU-Run-Shareaza - c:\program files\Shareaza\Shareaza.exe HKLM-Run-NPSStartup - (no file) Notify-urqqool - urqqool.dll SafeBoot-mfehidk SafeBoot-mferkdk SafeBoot-mfetdik SafeBoot-mfetdik.sys ActiveSetup-{A9F32C39-E65C-1A92-EFF1-0AB408982D87} - c:\docume~1\Richard\LOCALS~1\Temp\Crysis02.exe AddRemove-DVD Decrypter - c:\program files\DVD Decrypter\uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-27 22:14 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\PSSdk21] "ImagePath"="\??\c:\windows\system32\Drivers\HNPsSdk.drv" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(760) c:\windows\system32\Ati2evxx.dll . Completion time: 2009-12-27 22:19:39 ComboFix-quarantined-files.txt 2009-12-27 22:19 Pre-Run: 32,578,891,776 bytes free Post-Run: 32,522,113,024 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=30 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - 2F3488B628C3F7D9E08779C0BF60482A