GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-01-04 21:43:48
Windows 5.1.2600 Service Pack 3
Running: foezn5s4.exe; Driver: D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uwldapob.sys
---- System - GMER 1.0.15 ----
SSDT ADFA9FC6 ZwCreateKey
SSDT ADFA9FBC ZwCreateThread
SSDT ADFA9FCB ZwDeleteKey
SSDT ADFA9FD5 ZwDeleteValueKey
SSDT ADFA9FDA ZwLoadKey
SSDT ADFA9FA8 ZwOpenProcess
SSDT ADFA9FAD ZwOpenThread
SSDT ADFA9FE4 ZwReplaceKey
SSDT ADFA9FDF ZwRestoreKey
SSDT ADFA9FD0 ZwSetValueKey
SSDT ADFA9FB7 ZwTerminateProcess
Code \??\D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys pIofCallDriver
---- Kernel code sections - GMER 1.0.15 ----
? ijuukafp.sys The system cannot find the file specified. !
.text D:\WINDOWS.0\system32\DRIVERS\nv4_mini.sys section is writeable [0xB70EE380, 0x3DF545, 0xE8000020]
? D:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? D:\WINDOWS.0\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. !
---- User IAT/EAT - GMER 1.0.15 ----
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\explorer.exe [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT D:\WINDOWS.0\explorer.exe[2476] @ D:\WINDOWS.0\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [5CB777BD] D:\WINDOWS.0\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
-----------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:45:28, on 04/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
D:\WINDOWS.0\System32\smss.exe
D:\WINDOWS.0\system32\winlogon.exe
D:\WINDOWS.0\system32\services.exe
D:\WINDOWS.0\system32\lsass.exe
D:\WINDOWS.0\system32\nvsvc32.exe
D:\WINDOWS.0\system32\svchost.exe
D:\WINDOWS.0\System32\svchost.exe
D:\WINDOWS.0\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
D:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS.0\system32\CTSvcCDA.EXE
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Kodak\AiO\center\KodakSvc.exe
D:\WINDOWS.0\RTHDCPL.EXE
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Google\Google Talk\googletalk.exe
D:\WINDOWS.0\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\WINDOWS.0\system32\ctfmon.exe
D:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
D:\WINDOWS.0\system32\svchost.exe
D:\WINDOWS.0\system32\MsPMSPSv.exe
D:\Program Files\Kodak\AiO\Center\EKDiscovery.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS.0\System32\svchost.exe
D:\WINDOWS.0\system32\notepad.exe
D:\WINDOWS.0\explorer.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\uninstall\helper.exe
D:\WINDOWS.0\system32\NOTEPAD.EXE
D:\WINDOWS.0\system32\NOTEPAD.EXE
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sky.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=488
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: IEPlugin Class - {11222041-111B-46E3-BD29-EFB2449479B1} - D:\PROGRA~1\ArcSoft\MEDIAC~1\INTERN~1\ARCURL~1.DLL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] D:\Program Files\Unlocker\UnlockerAssistant.exe -H
O4 - HKLM\..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS.0\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS.0\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [googletalk] D:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] D:\WINDOWS.0\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] D:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Global Startup: Philips GoGear OPUS Device Manager.lnk = D:\Program Files\Philips\GoGear OPUS Device Manager\GoGear_OPUS_DeviceManager.exe
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS.0\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS.0\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - D:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS.0\system32\CTSvcCDA.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - D:\Program Files\Kodak\AiO\Center\EKDiscovery.exe
O23 - Service: Kodak AiO Device Service (KodakSvc) - Eastman Kodak Company - D:\Program Files\Kodak\AiO\center\KodakSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - D:\WINDOWS.0\system32\nvsvc32.exe
--
End of file - 7842 bytes
-----------------------
ComboFix 10-01-04.01 - [redacted] 04/01/2010 21:29:19.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2455 [GMT 0:00]
Running from: d:\documents and settings\[redacted]\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\xcrashdump.dat
d:\documents and settings\Administrator\Application Data\02000000aaafdd86720C.manifest
d:\documents and settings\Administrator\Application Data\02000000aaafdd86720O.manifest
d:\documents and settings\Administrator\Application Data\02000000aaafdd86720P.manifest
d:\documents and settings\Administrator\Application Data\02000000aaafdd86720S.manifest
d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\extensions\{54c9efd9-cac6-40bb-9ca4-37ffa67ce996}
d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\extensions\{54c9efd9-cac6-40bb-9ca4-37ffa67ce996}\chrome.manifest
d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\extensions\{54c9efd9-cac6-40bb-9ca4-37ffa67ce996}\chrome\xulcache.jar
d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\extensions\{54c9efd9-cac6-40bb-9ca4-37ffa67ce996}\defaults\preferences\xulcache.js
d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\extensions\{54c9efd9-cac6-40bb-9ca4-37ffa67ce996}\install.rdf
d:\documents and settings\Administrator\Application Data\SystemProc
d:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
d:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
d:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
d:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
d:\windows.0\system32\0RFE8TvaJc5qwWZ.vbs
d:\windows.0\system32\1787794179
d:\windows.0\system32\4OTx9.vbs
d:\windows.0\system32\86C2Y.vbs
d:\windows.0\system32\9mX52Ha.vbs
d:\windows.0\system32\ETmRs5FjmTYLl.vbs
d:\windows.0\system32\ftlmtiVrbUvZI.vbs
d:\windows.0\system32\fZ9DKtlSA1IbXqG.vbs
d:\windows.0\system32\h825EOL68PP6e.vbs
d:\windows.0\system32\hhhzZmF.vbs
d:\windows.0\system32\JTYHE3y.vbs
d:\windows.0\system32\NkxAK.vbs
d:\windows.0\system32\o9qFM.vbs
d:\windows.0\system32\oc4wOkV.vbs
d:\windows.0\system32\OJ8rS.vbs
d:\windows.0\system32\RfTMlH7xkCxo3EE.vbs
d:\windows.0\system32\RGcB8wOOcklG2Mq.vbs
d:\windows.0\system32\Rn3N09M.vbs
d:\windows.0\system32\sysinfo.exe
d:\windows.0\system32\tb2fbMT.vbs
d:\windows.0\system32\tzlWrnMArJgGVOc.vbs
d:\windows.0\system32\unrar.exe
d:\windows.0\system32\Ve4i26cbAAZrsfJ.vbs
d:\windows.0\system32\Wg6pM84.vbs
d:\windows.0\system32\z3HCcz7.vbs
d:\windows.0\system32\zd4wbeYqMd9OMKs.vbs
.
((((((((((((((((((((((((( Files Created from 2009-12-04 to 2010-01-04 )))))))))))))))))))))))))))))))
.
2010-01-04 21:17 . 2010-01-04 21:17 5061520 ----a-w- d:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-04 13:22 . 2009-07-28 15:33 55656 ----a-w- d:\windows.0\system32\drivers\avgntflt.sys
2010-01-04 13:22 . 2009-03-30 09:33 96104 ----a-w- d:\windows.0\system32\drivers\avipbb.sys
2010-01-04 13:22 . 2009-02-13 11:29 22360 ----a-w- d:\windows.0\system32\drivers\avgntmgr.sys
2010-01-04 13:22 . 2009-02-13 11:17 45416 ----a-w- d:\windows.0\system32\drivers\avgntdd.sys
2010-01-04 13:22 . 2010-01-04 13:22 -------- d-----w- d:\program files\Avira
2010-01-04 13:22 . 2010-01-04 13:22 -------- d-----w- d:\documents and settings\All Users\Application Data\Avira
2009-12-28 18:21 . 2009-12-28 18:21 -------- d-----w- d:\program files\Trend Micro
2009-12-27 12:27 . 2009-12-27 12:27 -------- d-----w- d:\documents and settings\Administrator\Application Data\Philips
2009-12-27 12:26 . 2009-12-27 12:26 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\ArcSoft
2009-12-27 12:26 . 2009-12-27 14:33 -------- d-----w- d:\documents and settings\Administrator\Application Data\ArcSoft
2009-12-27 12:25 . 2009-12-27 12:26 -------- d-----w- d:\documents and settings\All Users\Application Data\ArcSoft
2009-12-27 12:25 . 2003-02-21 04:42 348160 ----a-w- d:\windows.0\system32\msvcr71.dll
2009-12-27 12:25 . 2009-12-27 12:25 -------- d-----w- d:\program files\Common Files\ArcSoft
2009-12-27 12:25 . 2009-12-27 12:25 -------- d-----w- d:\program files\ArcSoft
2009-12-27 12:25 . 2004-05-04 11:53 1645320 ----a-w- d:\windows.0\system32\gdiplus.dll
2009-12-27 12:25 . 2003-03-18 22:14 499712 ----a-r- d:\windows.0\system32\msvcp71.dll
2009-12-27 12:24 . 2009-12-27 12:24 -------- d-----w- d:\program files\Philips
2009-12-27 12:23 . 2009-12-27 12:23 -------- d-----w- d:\documents and settings\Administrator\Application Data\InstallShield
2009-12-26 21:52 . 2009-12-26 23:19 -------- d-----w- d:\program files\Windows Live Safety Center
2009-12-23 19:36 . 2009-12-23 19:36 -------- d-----w- d:\documents and settings\Administrator\Application Data\NCH Software
2009-12-23 19:36 . 2009-12-27 12:28 -------- d-----w- d:\documents and settings\All Users\Application Data\NCH Software
2009-12-23 19:36 . 2009-12-27 12:28 -------- d-----w- d:\program files\NCH Software
2009-12-21 18:59 . 2009-12-21 19:10 -------- d-----w- d:\program files\Movavi Video Converter 9
2009-12-21 18:59 . 2009-12-21 18:59 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Downloaded Installations
2009-12-13 13:18 . 2009-08-25 01:30 13312 ----a-w- d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\extensions\[redacted]\components\nsTwitterFoxSign.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-04 21:17 . 2009-09-11 16:25 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2010-01-04 21:00 . 2009-09-12 15:00 -------- d-----w- d:\documents and settings\Administrator\Application Data\Spotify
2010-01-04 13:30 . 2009-10-21 22:21 -------- d-----w- d:\program files\LimeWire
2010-01-04 13:13 . 2009-10-21 22:27 -------- d-----w- d:\documents and settings\Administrator\Application Data\LimeWire
2009-12-30 14:55 . 2009-09-11 16:25 38224 ----a-w- d:\windows.0\system32\drivers\mbamswissarmy.sys
2009-12-30 14:54 . 2009-09-11 16:25 19160 ----a-w- d:\windows.0\system32\drivers\mbam.sys
2009-12-28 14:57 . 2009-09-20 19:52 -------- d-----w- d:\program files\Paint Shop Pro 7
2009-12-27 12:26 . 2009-09-11 17:20 -------- d--h--w- d:\program files\InstallShield Installation Information
2009-12-21 01:46 . 2009-10-27 15:30 -------- d-----w- d:\program files\Steam
2009-12-05 15:06 . 2009-12-05 15:06 -------- d-----w- d:\program files\Veetle
2009-11-18 14:46 . 2009-11-18 14:29 -------- d-----w- d:\program files\MixMeister EZ Vinyl Converter
2009-11-17 15:26 . 2009-11-17 15:23 -------- d-----w- d:\program files\Hot Keyboard Pro
2009-11-17 15:26 . 2009-11-17 15:26 -------- d-----w- d:\documents and settings\Administrator\Application Data\Hot Keyboard
2009-11-11 00:23 . 2009-11-11 00:23 -------- d-----w- d:\program files\Sky Broadband
2009-11-08 12:49 . 2009-11-08 12:49 14728 ---ha-w- d:\windows.0\system32\mlfcache.dat
2009-11-02 01:56 . 2009-11-02 01:56 1925024 ----a-w- d:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-10-21 22:22 . 2009-10-21 22:22 411368 ----a-w- d:\windows.0\system32\deploytk.dll
2009-10-21 22:21 . 2009-10-21 22:21 152576 ----a-w- d:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
.
------- Sigcheck -------
[-] 2008-12-30 . 5AE1C2695F6523AD98B948F2887D8C5E . 361600 . . [5.1.2600.5649] . . d:\windows.0\system32\drivers\tcpip.sys
d:\windows.0\System32\wscntfy.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MSMSGS"="d:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UnlockerAssistant"="d:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-01 15872]
"nwiz"="d:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvMediaCenter"="d:\windows.0\system32\NvMcTray.dll" [2009-08-17 86016]
"NvCplDaemon"="d:\windows.0\system32\NvCpl.dll" [2009-08-17 13877248]
"RTHDCPL"="RTHDCPL.EXE" [2009-08-24 18702336]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"googletalk"="d:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Conime"="d:\windows.0\system32\conime.exe" [2008-04-14 27648]
"EKIJ5000StatusMonitor"="d:\windows.0\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2009-04-07 1511424]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-10-21 149280]
"ArcSoft Connection Service"="d:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
"avgnt"="d:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2008-04-14 99840]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
Philips GoGear OPUS Device Manager.lnk - d:\program files\Philips\GoGear OPUS Device Manager\GoGear_OPUS_DeviceManager.exe [2009-12-27 1402232]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Spotify\\spotify.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\Program Files\\Steam\\SteamApps\\common\\football manager 2009\\fm.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9322:TCP"= 9322:TCP:EKDiscovery
"9323:TCP"= 9323:TCP:EKDiscovery
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;d:\program files\Avira\AntiVir Desktop\sched.exe [04/01/2010 13:22 108289]
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;d:\program files\Kodak\AiO\Center\EKDiscovery.exe [04/05/2009 11:15 279960]
R2 KodakSvc;Kodak AiO Device Service;d:\program files\Kodak\AiO\Center\KodakSvc.exe [17/04/2009 11:08 32768]
S1 drqiimfd;drqiimfd;\??\d:\windows.0\system32\drivers\drqiimfd.sys --> d:\windows.0\system32\drivers\drqiimfd.sys [?]
S1 uhpwlxpj;uhpwlxpj;\??\d:\windows.0\system32\drivers\uhpwlxpj.sys --> d:\windows.0\system32\drivers\uhpwlxpj.sys [?]
S2 gupdate;Google Update Service (gupdate);d:\program files\Google\Update\GoogleUpdate.exe [14/09/2009 00:33 133104]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASPI32
.
Contents of the 'Scheduled Tasks' folder
2009-12-21 d:\windows.0\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-01-04 d:\windows.0\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-09-14 00:32]
2010-01-04 d:\windows.0\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-09-14 00:32]
2009-12-23 d:\windows.0\Tasks\videopadSevenDaysInit.job
- d:\program files\NCH Software\VideoPad\videopad.exe [2009-12-23 19:36]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.sky.com
uInternet Settings,ProxyOverride = *.local
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com
FF - ProfilePath - d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.oleole.com/blogs/arseblog
FF - prefs.js: keyword.URL -
hxxp://www.google.com/search?ie=UTF-8&o ... &gfns=1&q=
FF - component: d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: d:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\t0evfd4i.default\extensions\[redacted]\components\nsTwitterFoxSign.dll
FF - component: d:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - plugin: d:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\program files\Veetle\Player\npvlc.dll
FF - plugin: d:\program files\Veetle\plugins\npVeetle.dll
.
- - - - ORPHANS REMOVED - - - -
BHO-{04E28BBF-FA52-40FD-90A8-1BD3B2F0AD64} - d:\windows.0\System32\dataclen32.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-04 21:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-01-04 21:33:47
ComboFix-quarantined-files.txt 2010-01-04 21:33
Pre-Run: 368,662,368,256 bytes free
Post-Run: 368,641,916,928 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS.0
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS.0="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff
- - End Of File - - 884329024B6B049978D722F91C8EBC5C
-------------------------
Malwarebytes' Anti-Malware 1.43
Database version: 3493
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
04/01/2010 21:21:20
mbam-log-2010-01-04 (21-21-20).txt
Scan type: Quick Scan
Objects scanned: 100444
Time elapsed: 2 minute(s), 42 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 4
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 37
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
D:\WINDOWS.0\system32\btpanui32.dll (Trojan.Tracur) -> Delete on reboot.
D:\WINDOWS.0\system32\__c0029F10.dat (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\d8bdf464720 (Trojan.Tracur) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0029f10 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gasfkyewmttapq (Rootkit.TDSS) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rthdbpl (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: d:\windows.0\system32\btpanui32.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\btpanui32.dll -> Delete on reboot.
Folders Infected:
D:\WINDOWS.0\system32\SysWoW32 (Worm.Archive) -> Quarantined and deleted successfully.
Files Infected:
D:\WINDOWS.0\system32\btpanui32.dll (Trojan.Tracur) -> Delete on reboot.
D:\WINDOWS.0\system32\__c0029F10.dat (Trojan.Vundo) -> Delete on reboot.
D:\Documents and Settings\Administrator\My Documents\downloads\QuickTime_Update_KB673901.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c002D096.dat (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c0066B6E.dat (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c006F366.dat (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00ABDE6.dat (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00AF216.dat (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00E93D8.dat (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00F3383.dat (Trojan.Vundo) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\mi48737854v4.kwd (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\mi48737854v6.kwd (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\mi48737854v7.kwd (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\mu48737854v5 (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\mu48737854v5.kwd (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\wu48737854v0.kwd (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\wu48737854v1 (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\wu48737854v1.kwd (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\wu48737854v2.kwd (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\wu48737854v3 (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\SysWoW32\wu48737854v3.kwd (Worm.Archive) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00137A4.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c003BA21.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c0048749.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c0055D10.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c005B93C.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c0070C67.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c0074304.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00A6A50.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00B1C1C.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00B5524.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00DDB0C.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00DF151.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00E9DDF.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00EBD85.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\system32\__c00FB58A.dat (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS.0\GnuHashes.ini (Malware.Trace) -> Quarantined and deleted successfully.
The Google problem no longer persists and the tab opening by itself also appears to have stopped after following the steps so far.