ComboFix 11-08-02.02 - Gary 03/08/2011 21:08:37.2.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3319.2755 [GMT 1:00]
Running from: c:\documents and settings\Gary\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Gary\Desktop\CFScript.txt
.
FILE ::
"c:\docume~1\Gary\LOCALS~1\Temp\DMSKSSRh.sys"
"c:\documents and settings\Gary\Local Settings\Application Data\BIT11.tmp"
"c:\documents and settings\Gary\Start Menu\Programs\Startup\rabrnoiv.exe"
"c:\program files\mirc617.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Gary\Local Settings\Application Data\BIT11.tmp
c:\documents and settings\gary\local settings\application data\mtjfdlyf\rabrnoiv.exe
c:\documents and settings\Gary\Start Menu\Programs\Startup\rabrnoiv.exe
C:\FOUND.007
c:\found.007\FILE0000.CHK
c:\found.007\FILE0001.CHK
c:\found.007\FILE0002.CHK
c:\found.007\FILE0003.CHK
c:\found.007\FILE0004.CHK
c:\found.007\FILE0005.CHK
c:\found.007\FILE0006.CHK
c:\found.007\FILE0007.CHK
c:\found.007\FILE0008.CHK
c:\found.007\FILE0009.CHK
c:\found.007\FILE0010.CHK
c:\found.007\FILE0011.CHK
c:\found.007\FILE0012.CHK
c:\found.007\FILE0013.CHK
c:\found.007\FILE0014.CHK
c:\found.007\FILE0015.CHK
c:\found.007\FILE0016.CHK
c:\found.007\FILE0017.CHK
c:\found.007\FILE0018.CHK
c:\found.007\FILE0019.CHK
c:\found.007\FILE0020.CHK
c:\found.007\FILE0021.CHK
c:\found.007\FILE0022.CHK
c:\found.007\FILE0023.CHK
c:\found.007\FILE0024.CHK
c:\found.007\FILE0025.CHK
c:\found.007\FILE0026.CHK
c:\found.007\FILE0027.CHK
c:\found.007\FILE0028.CHK
c:\found.007\FILE0029.CHK
c:\found.007\FILE0030.CHK
c:\found.007\FILE0031.CHK
c:\found.007\FILE0032.CHK
c:\found.007\FILE0033.CHK
c:\found.007\FILE0034.CHK
c:\found.007\FILE0035.CHK
c:\found.007\FILE0036.CHK
c:\found.007\FILE0037.CHK
C:\FOUND.008
c:\found.008\FILE0000.CHK
c:\found.008\FILE0001.CHK
c:\program files\mirc617.exe
c:\documents and settings\Gary\Local Settings\Application Data\mtjfdlyf . . . . Failed to delete
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DMSKSSRH
-------\Service_DMSKSSRh
.
.
((((((((((((((((((((((((( Files Created from 2011-07-03 to 2011-08-03 )))))))))))))))))))))))))))))))
.
.
2011-08-02 21:34 . 2011-08-02 21:34 -------- d-----w- c:\documents and settings\Gary\Application Data\Avira
2011-08-02 18:05 . 2011-08-02 18:05 -------- d-----w- c:\program files\ESET
2011-08-01 21:59 . 2011-08-01 21:59 -------- d-----w- c:\documents and settings\Gary\Local Settings\Application Data\mtjfdlyf
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-06 18:52 . 2008-08-20 13:09 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 18:52 . 2008-05-20 17:31 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-02 14:02 . 1979-12-31 23:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2007-06-28 23:52 . 2007-06-28 23:52 25755448 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-02_20.56.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-03 20:27 . 2011-08-03 20:27 16384 c:\windows\Temp\Perflib_Perfdata_608.dat
- 2011-08-02 20:55 . 2011-08-02 20:55 16384 c:\windows\Temp\Perflib_Perfdata_608.dat
+ 2011-08-03 20:27 . 2011-08-03 20:27 16384 c:\windows\Temp\Perflib_Perfdata_5d8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2010-06-01 5252408]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-10-21 1032640]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2011-02-23 2251064]
"RabRnoiv"="c:\documents and settings\Gary\Local Settings\Application Data\mtjfdlyf\rabrnoiv.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 40960]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"SoundMan"="SOUNDMAN.EXE" [2004-09-23 77824]
"AlcWzrd"="ALCWZRD.EXE" [2004-09-24 2559488]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-03-17 157552]
"btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [2009-09-14 1584640]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-29 202256]
"kdx"="c:\program files\Kontiki\KHost.exe" [2008-10-21 1032640]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= firefox.exe
"2"= opera.exe
"3"= chrome.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,,c:\documents and settings\Gary\Local Settings\Application Data\mtjfdlyf\rabrnoiv.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2010-01-15 18:47 16680 ------w- c:\program files\Citrix\GoToAssist\570\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\hp\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Google\\Google Earth\\PLUGIN\\geplugin.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\BTBB\\BTHelpBrowser.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\BTBB\\BTHelpNotifier.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
.
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15/11/2009 21:04 135664]
S3 DCamUSBLTN;M318B Digital Video Camera;c:\windows\system32\DRIVERS\vq318vid.sys --> c:\windows\system32\DRIVERS\vq318vid.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [15/11/2009 21:04 135664]
S3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX2000/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [09/07/2009 18:04 30560]
S3 S3U10Scanner;600 CU Still Image Device Service;c:\windows\system32\drivers\UsbScan.sys [14/12/2006 13:48 15104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 20:04]
.
2011-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-15 20:04]
.
2011-08-01 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2985075561-484364312-3234489201-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
2011-08-03 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2985075561-484364312-3234489201-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 21:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://bt.yahoo.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Microsoft Internet Explorer Provided by Wanadoo
uInternet Connection Wizard,ShellNext = hxxp://www.wanadoo.co.uk/cd_redirects/st35install.htm
uInternet Settings,ProxyServer = http=127.0.0.1:9090
uInternet Settings,ProxyOverride = *.local;<local>
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: gamehouse.com\global.fb
Trusted Zone: microsoft.com\download.windowsupdate
Trusted Zone: microsoft.com\update
Trusted Zone: plentyoffish.com\www
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-03 21:30
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
detected NTDLL code modification:
ZwQueryDirectoryFile
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\documents and settings\Gary\Start Menu\Programs\Startup\rabrnoiv.exe 131072 bytes
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(556)
c:\program files\Citrix\GoToAssist\570\G2AWinLogon.dll
.
- - - - - - - > 'explorer.exe'(2152)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\SOUNDMAN.EXE
c:\windows\ALCWZRD.EXE
c:\program files\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
.
**************************************************************************
.
Completion time: 2011-08-03 21:39:14 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-03 20:39
ComboFix2.txt 2011-08-02 21:06
.
Pre-Run: 21,998,206,976 bytes free
Post-Run: 21,992,570,880 bytes free
.
- - End Of File - - 0702532D3789832A90E05EE1B0634F8E