ComboFix 10-01-04.01 - RM 07/01/2010 11:17:51.5.2 - x86 NETWORK Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.655 [GMT 0:00] Running from: c:\documents and settings\[removed]\Desktop\Malware Dec 09\ComboFix.exe Command switches used :: c:\documents and settings\RM\Desktop\Malware Dec 09\cfScript.txt AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} FILE :: "c:\windows\system32\Drivers\HNPsSdk.drv" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\at vcox.dll c:\windows\system32\at)iieXx.dLl c:\windows\system32\atipdlxx.dll c:\windows\system32\au$iod%v.dll c:\windows\system32\Data c:\windows\system32\Data\CTP0358W.DAT . ((((((((((((((((((((((((( Files Created from 2009-12-07 to 2010-01-07 ))))))))))))))))))))))))))))))) . 2009-12-24 17:48 . 2009-12-24 17:48 -------- d-----w- C:\rsit 2009-12-24 12:14 . 2009-12-24 12:14 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE 2009-12-24 12:14 . 2009-12-24 12:14 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-12-18 17:30 . 2009-12-18 17:30 -------- d-----w- c:\program files\Trend Micro 2009-12-16 16:01 . 2009-12-16 16:01 -------- d-----w- c:\documents and settings\RM\Application Data\GetRightToGo 2009-12-13 16:57 . 2009-12-13 16:57 -------- d-----w- C:\TESCO_SKILLS_DVD 2009-12-08 20:32 . 2009-12-08 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-01-03 18:01 . 2008-01-11 16:27 125 -c--a-w- c:\documents and settings\RM\Local Settings\Application Data\fusioncache.dat 2009-12-30 19:08 . 2004-12-13 14:56 384 ----a-w- c:\windows\system32\DVCStateBkp-{00000004-00000000-00000000-00001102-00000004-20061102}.dat 2009-12-30 19:08 . 2004-12-13 14:56 384 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000000-00001102-00000004-20061102}.dat 2009-12-29 15:20 . 2007-12-22 18:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell 2009-12-17 00:04 . 2008-06-11 09:34 102360 -c--a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT 2009-12-08 20:06 . 2009-12-08 20:06 5562672 ----a-w- c:\documents and settings\RM\Application Data\TVU Networks\TVU AutoUpgrade\TVUPlayer2.4.9.1.exe 2009-12-02 11:00 . 2009-12-02 11:00 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee 2009-12-02 10:55 . 2007-12-24 16:27 -------- d-----w- c:\program files\McAfee 2009-12-01 19:29 . 2007-12-24 16:23 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2009-11-27 13:49 . 2008-08-28 18:50 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore 2009-11-22 09:48 . 2005-07-09 21:11 -------- d-----w- c:\documents and settings\Deborah\Application Data\Ahead 2009-11-19 17:08 . 2007-06-13 20:19 -------- d-----w- c:\program files\Games 2009-11-18 10:38 . 2008-02-12 10:01 -------- d-----w- c:\documents and settings\Deborah\Application Data\Samsung 2009-11-10 22:29 . 2009-11-10 22:28 17221104 ----a-w- c:\documents and settings\Deborah\Application Data\Real\Update\setup\rp\RealPlayerSPGold.exe 2009-11-06 20:31 . 2005-11-13 01:31 16 ----a-w- c:\windows\popcinfo.dat 2009-10-29 07:45 . 2004-08-04 05:00 916480 ----a-w- c:\windows\system32\wininet.dll 2009-10-21 05:38 . 2004-08-04 05:00 75776 ----a-w- c:\windows\system32\strmfilt.dll 2009-10-21 05:38 . 2004-08-04 05:00 25088 ----a-w- c:\windows\system32\httpapi.dll 2009-10-20 16:20 . 2004-08-04 05:00 265728 ----a-w- c:\windows\system32\drivers\http.sys 2009-10-13 10:30 . 2004-08-04 05:00 270336 ----a-w- c:\windows\system32\oakley.dll 2009-10-12 13:38 . 2004-08-04 05:00 149504 ----a-w- c:\windows\system32\rastls.dll 2009-10-12 13:38 . 2004-08-04 05:00 79872 ----a-w- c:\windows\system32\raschap.dll 2006-12-08 16:40 . 2006-12-08 16:40 278528 -c--a-w- c:\program files\Common Files\FDEUnInstaller.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-04 68856] "AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-04-16 102400] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008] "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752] "IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-21 29744] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344] "CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056] "SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064] "McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2009-07-08 5134864] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2008-04-14 53760] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ lsdelete [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\WinMX\\WinMX.exe"= "c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"= "c:\\Program Files\\GameSpy Arcade\\Aphex.exe"= "c:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"= "c:\\Program Files\\Sierra On-Line\\SIGSPat.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"= "c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"= "c:\\WINDOWS\\SYSTEM32\\PnkBstrA.exe"= "c:\\WINDOWS\\SYSTEM32\\PnkBstrB.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\tv players\\PPStream\\PPStream.exe"= "c:\\Program Files\\tv players\\PPStream\\PPSAP.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\SAMSUNG\\Samsung New PC Studio\\npsasvr.exe"= "c:\\Program Files\\SAMSUNG\\Samsung New PC Studio\\npsvsvr.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R0 d347bus;d347bus;c:\windows\SYSTEM32\DRIVERS\d347bus.sys [21/02/2005 20:53 155136] R0 d347prt;d347prt;c:\windows\SYSTEM32\DRIVERS\d347prt.sys [21/02/2005 20:53 5248] S2 FsUsbExService;FsUsbExService;c:\windows\SYSTEM32\FsUsbExService.Exe [08/10/2009 10:57 233472] S2 gupdate1c98c3316aac6a2;Google Update Service (gupdate1c98c3316aac6a2);c:\program files\Google\Update\GoogleUpdate.exe [11/02/2009 10:25 133104] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [28/08/2008 17:31 93320] S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\SYSTEM32\DRIVERS\ASPI32.SYS [27/03/2006 12:58 16512] S3 FsUsbExDisk;FsUsbExDisk;c:\windows\SYSTEM32\FsUsbExDisk.Sys [08/10/2009 10:57 36608] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [03/09/2007 14:00 29744] S3 imhidusb;Immersion's HID USB Driver;c:\windows\SYSTEM32\DRIVERS\imhidusb.sys [15/08/2000 15:49 31056] . Contents of the 'Scheduled Tasks' folder 2009-12-09 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 11:34] 2009-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 10:25] 2009-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-11 10:25] 2009-12-15 c:\windows\Tasks\jucheck.job - c:\program files\Java\jre1.6.0_07\bin\jucheck.exe [2008-09-13 03:27] 2009-10-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-24 11:22] 2009-10-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-24 11:22] 2009-12-09 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job - c:\program files\Internet Bits\Spybot - Search & Destroy\SpybotSD.exe [2004-05-12 16:46] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.orange.co.uk/ uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.21.0.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-01-07 11:28 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(760) c:\windows\system32\Ati2evxx.dll . Completion time: 2010-01-07 11:34:09 ComboFix-quarantined-files.txt 2010-01-07 11:34 ComboFix2.txt 2009-12-29 16:44 ComboFix3.txt 2009-12-27 22:19 Pre-Run: 31,618,490,368 bytes free Post-Run: 31,576,608,768 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=30 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - 73B0F394EC43D0C9C31066F3C696119F