ComboFix 12-01-05.01 - pbuehrer 01/05/2012 13:00:18.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2598 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\TEMP c:\documents and settings\pbuehrer\g2mdlhlpx.exe c:\documents and settings\pbuehrer\Local Settings\Application Data\assembly\tmp c:\documents and settings\pbuehrer\Local Settings\Application Data\assembly\tmp\Y6DLT18G\Interop.PowerPoint.DLL c:\documents and settings\pbuehrer\Local Settings\Application Data\ie_runner_app.exe c:\documents and settings\pbuehrer\My Documents\My Music\My Music.url c:\documents and settings\pbuehrer\My Documents\My Videos\My Video.url c:\program files\win32 c:\program files\win32\soldisk.sys c:\program files\win32\solfs.sys c:\windows\EventSystem.log c:\windows\system32\BSTIEPrintCtl1.dll c:\windows\system32\NWGINA.DLL c:\windows\system32\SET182.tmp . . ((((((((((((((((((((((((( Files Created from 2011-12-05 to 2012-01-05 ))))))))))))))))))))))))))))))) . . 2012-01-05 17:28 . 2012-01-05 17:31 -------- d-----w- c:\windows\7E7D778E121D4BBDBA29FAA81B9FBD8C.TMP 2012-01-04 16:26 . 2012-01-04 16:26 -------- d-----w- c:\windows\system\nls 2012-01-04 16:25 . 2012-01-04 16:25 -------- d-----w- c:\windows\system32\NetWare 2012-01-04 16:25 . 2012-01-04 16:25 -------- d-----w- c:\program files\CUAgent 2012-01-04 15:32 . 2012-01-04 15:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\McAfee 2012-01-04 15:32 . 2012-01-04 15:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\Sprint 2012-01-04 15:31 . 2012-01-04 15:31 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2012-01-04 14:28 . 2008-08-08 21:06 131165 ----a-w- c:\windows\system32\spflist.exe 2011-12-23 13:34 . 2010-10-04 22:57 15360 ----a-w- c:\windows\system32\drivers\nnrnstdi.sys 2011-12-23 13:34 . 2010-10-04 22:57 10368 ----a-w- c:\windows\system32\drivers\km_filter.sys 2011-12-23 13:32 . 2010-10-04 23:01 24192 ----a-w- c:\windows\system32\drivers\nielprt.sys 2011-12-23 13:32 . 2010-10-04 23:01 9088 ----a-w- c:\windows\system32\drivers\nielgfx.sys 2011-12-22 20:53 . 2011-12-22 20:53 -------- d-----w- c:\program files\NetRatingsNetSight 2011-12-21 16:06 . 2011-12-21 16:06 -------- d-----w- c:\documents and settings\pbuehrer\Application Data\McAfee 2011-12-21 16:03 . 2011-12-21 16:02 74848 ----a-w- c:\windows\system32\MfeOtlkAddin.dll 2011-12-21 16:02 . 2011-12-21 16:02 -------- d-sh--w- c:\documents and settings\Default User\IETldCache . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-01-05 18:22 . 2008-10-10 18:34 0 ----a-w- c:\documents and settings\pbuehrer\Local Settings\Application Data\WavXMapDrive.bat 2012-01-04 16:22 . 2008-09-23 07:30 0 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\WavXMapDrive.bat 2011-12-21 16:02 . 2009-10-23 01:07 22816 ----a-w- c:\windows\system32\MFEOtlk.dll 2011-12-02 16:40 . 2011-05-18 12:17 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-23 13:25 . 2008-04-25 16:16 1859584 ----a-w- c:\windows\system32\win32k.sys 2011-11-04 19:20 . 2008-04-25 16:16 916992 ----a-w- c:\windows\system32\wininet.dll 2011-11-04 19:20 . 2008-04-25 16:16 43520 ------w- c:\windows\system32\licmgr10.dll 2011-11-04 19:20 . 2008-04-25 16:16 1469440 ------w- c:\windows\system32\inetcpl.cpl 2011-11-04 11:23 . 2008-04-25 16:16 385024 ------w- c:\windows\system32\html.iec 2011-11-01 16:07 . 2008-04-25 16:16 1288704 ----a-w- c:\windows\system32\ole32.dll 2011-10-28 05:31 . 2008-04-25 16:16 33280 ----a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37 . 2008-04-25 16:16 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52 . 2008-04-14 00:01 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13 . 2008-04-25 16:16 186880 ----a-w- c:\windows\system32\encdec.dll 2011-10-10 14:22 . 2008-04-25 21:27 692736 ----a-w- c:\windows\system32\inetcomm.dll 2009-11-18 16:49 . 2009-11-18 16:49 682266 ----a-w- c:\program files\unins000.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-27 1024000] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-12-06 405504] "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184] "WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2007-09-10 92160] "SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-09-14 218424] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640] "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080] "acevents"="c:\program files\ActivIdentity\ActivClient\acevents.exe" [2009-06-03 153640] "accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2009-06-03 400936] "NvMediaCenter"="NvMCTray.dll" [2011-01-07 111208] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-07 13880424] "NVHotkey"="nvHotkey.dll" [2011-01-07 178792] "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192] "Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2010-05-25 75072] "RDVCHG"="c:\program files\Sprint\Sprint SmartView\RDVCHG.exe" [2010-05-25 316736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2011-06-08 333120] "NielsenOnline"="c:\program files\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2010-11-17 47424] "NDPS"="c:\windows\system32\dpmw32.exe" [2004-05-17 32859] "NWTRAY"="NWTRAY.EXE" [2002-03-12 28672] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2008-04-14 53760] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 217194] ActivClient Agent.lnk - c:\program files\ActivIdentity\ActivClient\acsagent.exe [2009-6-3 130600] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "CompatibleRUPSecurity"= 1 (0x1) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc] 2009-06-03 21:14 113152 ----a-w- c:\program files\ActivIdentity\ActivClient\ackpbsc.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock] 2009-06-03 21:13 299520 ----a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gemsafe] 2006-11-16 20:20 73728 ----a-w- c:\program files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 wvauth nwv1_0 . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\dpmw32.exe"= "c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Sprint\\Sprint SmartView\\SwiApiMux.exe"= "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"= . R0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys [12/23/2011 8:32 AM 24192] R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMHELPR.SYS [10/16/2008 10:37 AM 4064] R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [12/23/2011 8:34 AM 15360] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [1/5/2010 7:56 AM 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 67656] R1 SolDisk;SolDisk;c:\windows\system32\drivers\soldisk.sys [11/18/2009 11:49 AM 38344] R1 SolFS;SolFS;c:\windows\system32\drivers\solfs.sys [11/18/2009 11:49 AM 285256] R2 NielsenUpdate;Nielsen Update;c:\program files\NetRatingsNetSight\NetSight\NielsenUpdate.exe [12/22/2011 3:54 PM 303936] R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [4/25/2008 11:16 AM 5120] R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [12/23/2011 8:34 AM 10368] R3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys [12/23/2011 8:32 AM 9088] S2 74B318A013F490E8;74B318A013F490E8;\??\c:\documents and settings\pbuehrer\Desktop\74B318A013F490E8\74B318A013F490E8 --> c:\documents and settings\pbuehrer\Desktop\74B318A013F490E8\74B318A013F490E8 [?] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/5/2011 7:32 PM 136176] S3 ac.sharedstore;ActivIdentity Shared Store Service;c:\program files\Common Files\ActivIdentity\ac.sharedstore.exe [6/3/2009 4:16 PM 207400] S3 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [11/27/2007 6:11 PM 185896] S3 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [4/25/2008 11:16 AM 14336] S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [1/1/2010 9:07 AM 18560] S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/5/2011 7:32 PM 136176] S3 NvtlService;NovaCore SDK Service;c:\program files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe [1/11/2010 1:10 PM 82944] S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [10/12/2007 3:04 PM 174720] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 12872] S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [10/17/2007 11:11 PM 56448] S3 SSLDrv;SSL-VPN NetExtender Adapter;c:\windows\system32\drivers\SSLDrv.sys [10/23/2007 7:09 PM 20504] . --- Other Services/Drivers In Memory --- . *Deregistered* - BMLoad . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] 2009-03-08 08:32 128512 ----a-w- c:\windows\system32\advpack.dll . Contents of the 'Scheduled Tasks' folder . 2011-10-11 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 20:42] . 2012-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-06 00:32] . 2012-01-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-07-06 00:32] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 LSP: bmnet.dll Trusted Zone: centraldesktop.com\psi Trusted Zone: delphiforums.com\forums Trusted Zone: dod.mil\www.defensetravel Trusted Zone: e-rewards.com\www Trusted Zone: earthlink.net\www Trusted Zone: kelloggs.com Trusted Zone: mypoints.com\www Trusted Zone: navy.mil\ile-lms.nko Trusted Zone: navy.mil\webmail.east.nmci Trusted Zone: navy.mil\www.navyreserve Trusted Zone: navy.mil\www.nko Trusted Zone: pageturnpro.com\www Trusted Zone: youtube.com\www DPF: {445F47D7-E043-4BD6-82EB-7A1BD0EBA773} - hxxp://www.psapoll.com/CopyGuardIE.cab DPF: {71D73A47-975F-11D1-AA77-00A0C98D86D4} - hxxp://10.0.5.11/shorewaredirector/VoiceMessage.ocx DPF: {88DD90B6-C770-4CFF-B7A4-3AFD16BB8824} - hxxp://10.0.5.11/aspnet_client/system_web/2_0_50727/crystalreportviewers12/ActiveXControls/PrintControl.cab DPF: {FA6424B7-D971-11D1-9697-00A0C928D512} - hxxp://10.0.5.11/shorewaredirector/TwentyFour7.ocx . - - - - ORPHANS REMOVED - - - - . AddRemove-C1RPTING - c:\program files\Common Files\Novell\ni\bin\install.exe -remove ..\data\ip.db ..\data\remove.rsp AddRemove-CONSOLE1 - c:\program files\Common Files\Novell\ni\bin\install.exe -remove ..\data\ip.db ..\data\remove.rsp AddRemove-{342C7C88-D335-4bc2-8CF1-281857629CE2} - c:\program files\HP\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzscr01.exe AddRemove-{5469D537-9B44-4c78-BF2D-5F9807564F74} - c:\program files\HP\Digital Imaging\{5469D537-9B44-4c78-BF2D-5F9807564F74}\setup\hpzscr01.exe AddRemove-Consumer Input Software - c:\program files\Consumer Input\uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-01-05 13:22 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\74B318A013F490E8] "ImagePath"="\??\c:\documents and settings\pbuehrer\Desktop\74B318A013F490E8\74B318A013F490E8" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\ . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(1184) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\program files\ActivIdentity\ActivClient\ackpbsc.dll c:\program files\ActivIdentity\ActivClient\aclog.dll c:\program files\ActivIdentity\ActivClient\accrypto.dll c:\program files\ActivIdentity\ActivClient\ACLIBEAY.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_150c9e8b\MFC80.DLL c:\program files\ActivIdentity\ActivClient\acevtsub.dll c:\program files\ActivIdentity\ActivClient\asphat32.dll c:\program files\ActivIdentity\ActivClient\acerrmes.dll c:\program files\ActivIdentity\ActivClient\aiwinext.dll c:\program files\ActivIdentity\ActivClient\aspcom.dll c:\program files\ActivIdentity\ActivClient\Resources\acerrmrc.dll c:\program files\ActivIdentity\ActivClient\Resources\asphatrc.dll c:\program files\ActivIdentity\ActivClient\acunlock.dll c:\program files\ActivIdentity\ActivClient\aipingui.dll c:\program files\ActivIdentity\ActivClient\aicext.dll c:\program files\ActivIdentity\ActivClient\Resources\aipinguirc.dll c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll c:\program files\ActivIdentity\ActivClient\resources\acCobAPIlrc.dll c:\program files\ActivIdentity\ActivClient\Resources\acunlockrc.dll c:\windows\system32\NETWIN32.DLL . - - - - - - - > 'lsass.exe'(1240) c:\windows\system32\wvauth.dll c:\windows\system32\biolsp.dll c:\windows\system32\bmnet.dll . - - - - - - - > 'explorer.exe'(836) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll c:\windows\system32\NETWIN32.DLL c:\windows\system32\mshtml.dll c:\windows\system32\msls31.dll c:\program files\McAfee\Common Framework\McTrayLegacySupportPlugin.dll c:\program files\McAfee\Common Framework\McTrayInterfaceLib.dll c:\program files\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Roxio\Drag-to-Disc\Shellex.dll c:\program files\Common Files\Roxio Shared\9.0\DLLShared\DLAAPI_W.DLL c:\program files\Roxio\Drag-to-Disc\ShellRes.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\nvsvc32.exe c:\windows\System32\WLTRYSVC.EXE c:\windows\System32\bcmwltry.exe c:\windows\System32\SCardSvr.exe c:\program files\Cisco Systems\VPN Client\cvpnd.exe c:\program files\McAfee\Common Framework\FrameworkService.exe c:\program files\Dell\QuickSet\NICCONFIGSVC.exe c:\windows\system32\HPZipm12.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\windows\system32\SearchIndexer.exe c:\program files\McAfee\Common Framework\naPrdMgr.exe c:\windows\system32\msdtc.exe c:\windows\system32\SearchProtocolHost.exe c:\windows\system32\RunDLL32.exe c:\windows\system32\rundll32.exe c:\windows\system32\NWTRAY.EXE c:\program files\McAfee\Common Framework\McTray.exe c:\windows\system32\SearchFilterHost.exe . ************************************************************************** . Completion time: 2012-01-05 13:28:48 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-05 18:28 . Pre-Run: 50,597,421,056 bytes free Post-Run: 51,607,486,464 bytes free . WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect . - - End Of File - - A8A603E4AD93ABAF00A1EED84EB6CC0F