Results of MBRCheck and ComboFix
I ran MBR without incident.
Combofix was more interesting:
1. During stage 3 of the scan, mcafee quarantined a virus and removed a trojan
I am sure I turned off mcafee real time scan for at least an hour.
2. After the start of the reboot, I got a warning that "NirCmd.dll failed to initialize because Windows stations shutting down", but after a while the reboot continued.
3. During preparation of the log report, the Adobe updater popped up. I waited about 10 minutes and (very reluctantly) closed the adobe updater window.
4. mcafee then removed another trojan during the report prep.
Combofix seems to have removed itself from my desktop.
Thanks,
Guy
=============== MBR Check ===========================
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000000d
Kernel Drivers (total 187):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EE000 \WINDOWS\system32\hal.dll
0xF89F8000 \WINDOWS\system32\KDCOM.DLL
0xF8908000 \WINDOWS\system32\BOOTVID.dll
0xF84A9000 ACPI.sys
0xF89FA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF8498000 pci.sys
0xF84F8000 isapnp.sys
0xF8AC0000 pciide.sys
0xF8778000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF89FC000 aliide.sys
0xF89FE000 cmdide.sys
0xF8A00000 toside.sys
0xF8A02000 viaide.sys
0xF8A04000 intelide.sys
0xF8508000 MountMgr.sys
0xF8479000 ftdisk.sys
0xF8780000 PartMgr.sys
0xF8518000 VolSnap.sys
0xF890C000 cpqarray.sys
0xF8461000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF8449000 atapi.sys
0xF8910000 aha154x.sys
0xF8788000 sparrow.sys
0xF8914000 symc810.sys
0xF8528000 aic78xx.sys
0xF8918000 dac960nt.sys
0xF8538000 ql10wnt.sys
0xF891C000 amsint.sys
0xF8790000 asc.sys
0xF8920000 asc3550.sys
0xF8798000 mraid35x.sys
0xF87A0000 i2omp.sys
0xF8924000 ini910u.sys
0xF8548000 ql1240.sys
0xF8558000 aic78u2.sys
0xF87A8000 symc8xx.sys
0xF87B0000 sym_hi.sys
0xF87B8000 sym_u3.sys
0xF87C0000 ABP480N5.SYS
0xF87C8000 asc3350p.sys
0xF8A06000 cd20xrnt.sys
0xF8568000 ultra.sys
0xF8430000 adpu160m.sys
0xF87D0000 dpti2o.sys
0xF8578000 ql1080.sys
0xF8588000 ql1280.sys
0xF8598000 ql12160.sys
0xF87D8000 perc2.sys
0xF8A08000 perc2hib.sys
0xF87E0000 hpn.sys
0xF8928000 cbidf2k.sys
0xF8404000 dac2w2k.sys
0xF85A8000 disk.sys
0xF85B8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF83E4000 fltmgr.sys
0xF83D2000 sr.sys
0xF8375000 mfehidk.sys
0xF8360000 drvmcdb.sys
0xF85C8000 PxHelp20.sys
0xF8349000 KSecDD.sys
0xF82BC000 Ntfs.sys
0xF828F000 NDIS.sys
0xF8A0A000 CorLog.sys
0xF87E8000 CorMem.sys
0xF85D8000 sisagp.sys
0xF85E8000 viaagp.sys
0xF8275000 Mup.sys
0xF85F8000 agp440.sys
0xF8608000 alim1541.sys
0xF8618000 amdagp.sys
0xF8628000 agpCPQ.sys
0xF8748000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF76BB000 \SystemRoot\system32\DRIVERS\ialmnt5.sys
0xF76A7000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF8860000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF7683000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF8868000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF8758000 \SystemRoot\system32\DRIVERS\IntelC53.sys
0xF7660000 \SystemRoot\system32\DRIVERS\ks.sys
0xF7539000 \SystemRoot\system32\DRIVERS\IntelC51.sys
0xF74A4000 \SystemRoot\system32\DRIVERS\IntelC52.sys
0xF8870000 \SystemRoot\system32\DRIVERS\mohfilt.sys
0xF8878000 \SystemRoot\System32\Drivers\Modem.SYS
0xF747E000 \SystemRoot\system32\DRIVERS\e100b325.sys
0xF8880000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF8768000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF8888000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF8890000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF821D000 \SystemRoot\system32\DRIVERS\serial.sys
0xF8174000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF746A000 \SystemRoot\system32\DRIVERS\parport.sys
0xF820D000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF8A56000 \SystemRoot\system32\drivers\sscdbhk5.sys
0xF81FD000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF81ED000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF742A000 \SystemRoot\system32\drivers\smwdm.sys
0xF7406000 \SystemRoot\system32\drivers\portcls.sys
0xF81DD000 \SystemRoot\system32\drivers\drmk.sys
0xF7353000 \SystemRoot\system32\drivers\senfilt.sys
0xF81CD000 \SystemRoot\system32\DRIVERS\dfmirage.sys
0xF8AFF000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF733F000 \SystemRoot\system32\DRIVERS\mfendisk.sys
0xF81BD000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF8164000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF7328000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF81AD000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF819D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF8898000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF7317000 \SystemRoot\system32\DRIVERS\psched.sys
0xF818D000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF72F3000 \SystemRoot\system32\drivers\mfeavfk.sys
0xF72A8000 \SystemRoot\system32\drivers\mfefirek.sys
0xF88A0000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF88A8000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF8648000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF8A5C000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF724A000 \SystemRoot\system32\DRIVERS\update.sys
0xF7911000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF7BAF000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7B8F000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF8A68000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF89E0000 \SystemRoot\system32\drivers\MODEMCSA.sys
0xF88C8000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xF89F0000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xF8A6A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF8AF3000 \SystemRoot\System32\Drivers\Null.SYS
0xF8A6C000 \SystemRoot\System32\Drivers\Beep.SYS
0xF88D8000 \SystemRoot\system32\drivers\ssrtln.sys
0xF88E0000 \SystemRoot\System32\drivers\vga.sys
0xF8A6E000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF8A70000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF88E8000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF88F0000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF8251000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xEF078000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xEF01F000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xEF00C000 \SystemRoot\system32\drivers\mfetdi2k.sys
0xEEFE6000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xEEFBE000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF8241000 \SystemRoot\System32\drivers\ws2ifsl.sys
0xEEF9C000 \SystemRoot\System32\drivers\afd.sys
0xF7889000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF823D000 \SystemRoot\System32\Drivers\CorPci.sys
0xF7879000 \SystemRoot\System32\Drivers\corserial.sys
0xEEF49000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xEEED9000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF7869000 \SystemRoot\System32\Drivers\Fips.SYS
0xF7859000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF88F8000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xEECFB000 \SystemRoot\system32\DRIVERS\VX3000.sys
0xF7829000 \SystemRoot\system32\DRIVERS\STREAM.SYS
0xF7809000 \SystemRoot\system32\drivers\usbaudio.sys
0xF86D8000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xEECE3000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF8AAE000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xEF139000 \SystemRoot\System32\drivers\Dxapi.sys
0xEF0CB000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF8B7F000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF020000 \SystemRoot\System32\ialmdnt5.dll
0xBF012000 \SystemRoot\System32\ialmrnt5.dll
0xBF042000 \SystemRoot\System32\ialmdev5.DLL
0xBF077000 \SystemRoot\System32\ialmdd5.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xF8698000 \SystemRoot\system32\drivers\drvnddm.sys
0xF8C39000 \SystemRoot\system32\dla\tfsndres.sys
0xEEB8D000 \SystemRoot\system32\dla\tfsnifs.sys
0xEECBF000 \SystemRoot\system32\dla\tfsnopio.sys
0xF8ABC000 \SystemRoot\system32\dla\tfsnpool.sys
0xF88D0000 \SystemRoot\system32\dla\tfsnboio.sys
0xF86A8000 \SystemRoot\system32\dla\tfsncofs.sys
0xF8C3A000 \SystemRoot\system32\dla\tfsndrct.sys
0xEEB74000 \SystemRoot\system32\dla\tfsnudf.sys
0xEEB5B000 \SystemRoot\system32\dla\tfsnudfa.sys
0xEEBBF000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xEE8D6000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xEE78E000 \SystemRoot\system32\DRIVERS\srv.sys
0xEE639000 \SystemRoot\system32\drivers\wdmaud.sys
0xEE86E000 \SystemRoot\system32\drivers\sysaudio.sys
0xEE45F000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xEDCF2000 \SystemRoot\System32\Drivers\HTTP.sys
0xEE36F000 \SystemRoot\system32\drivers\cfwids.sys
0xEDC3C000 \SystemRoot\system32\drivers\mfeapfk.sys
0xEE82E000 \SystemRoot\system32\drivers\mfebopk.sys
0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll
Processes (total 46):
0 System Idle Process
4 System
896 C:\WINDOWS\SYSTEM32\smss.exe
1020 csrss.exe
1044 C:\WINDOWS\SYSTEM32\winlogon.exe
1088 C:\WINDOWS\SYSTEM32\services.exe
1100 C:\WINDOWS\SYSTEM32\lsass.exe
1272 C:\WINDOWS\SYSTEM32\svchost.exe
1360 svchost.exe
1480 C:\WINDOWS\SYSTEM32\svchost.exe
1532 svchost.exe
1600 svchost.exe
2012 C:\WINDOWS\SYSTEM32\spoolsv.exe
208 C:\WINDOWS\explorer.exe
268 svchost.exe
332 C:\Program Files\Java\jre6\bin\jqs.exe
360 C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
408 C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
564 C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
680 C:\Program Files\Microsoft LifeCam\MSCamS32.exe
716 C:\Program Files\Dantz\Retrospect\retrorun.exe
1012 C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
1472 C:\Program Files\Dell Support Center\bin\sprtsvc.exe
1748 C:\WINDOWS\SYSTEM32\svchost.exe
1132 C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
1996 C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
844 C:\Program Files\Canon\CAL\CALMAIN.exe
2328 C:\Program Files\Analog Devices\Core\smax4pnp.exe
2352 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2360 C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
2380 C:\WINDOWS\SYSTEM32\hkcmd.exe
2392 C:\WINDOWS\SYSTEM32\igfxpers.exe
2548 C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
2556 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
2780 C:\WINDOWS\vVX3000.exe
2804 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
2852 C:\Program Files\verizon\VSP\VerizonServicepoint.exe
2860 C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
2876 C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
2932 C:\WINDOWS\SYSTEM32\WDBtnMgr.exe
3124 C:\Program Files\McAfee.com\Agent\mcagent.exe
3240 C:\WINDOWS\SYSTEM32\ctfmon.exe
3444 alg.exe
3412 C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
1140 mcupdmgr.exe
1628 C:\Documents and Settings\Guy\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`02738a00 (NTFS)
PhysicalDrive0 Model Number: ST380011A, Rev: 8.16
Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: E66C176942DF42CCFE7A0113EAFF39E82F8B0047
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done!
================= ComboFix log =============================
ComboFix 11-01-13.01 - Guy 01/14/2011 9:22.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.258 [GMT -5:00]
Running from: c:\documents and settings\Guy\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Guy\g2mdlhlpx.exe
c:\documents and settings\Guy\GoToAssistDownloadHelper.exe
c:\documents and settings\Guy\Recent\Thumbs.db
C:\Thumbs.db
c:\windows\ST6UNST.000
c:\windows\system32\drivers\sst1B9.sys
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_sst1B9
-------\Service_sst1B9
((((((((((((((((((((((((( Files Created from 2010-12-14 to 2011-01-14 )))))))))))))))))))))))))))))))
.
2011-01-13 00:53 . 2011-01-13 00:52 211968 ----a-w- c:\windows\Dhubia.exe
2011-01-08 01:44 . 2011-01-08 01:44 -------- d-----w- c:\documents and settings\Guy\Application Data\Mozilla Firefox - Guys Profile Backups
2011-01-07 14:49 . 2011-01-08 01:44 -------- d-----w- c:\documents and settings\Administrator.HOMENETID
2011-01-05 17:30 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-05 17:30 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-17 02:29 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-17 02:26 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-13 18:04 . 2004-08-04 11:00 52352 ----a-w- c:\windows\system32\drivers\volsnap.sys
2010-11-18 18:12 . 2004-08-04 11:00 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2004-08-04 11:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2004-08-04 11:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2004-08-04 11:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2004-08-04 11:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-03 23:46 . 2010-11-03 23:47 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-03 23:46 . 2010-11-03 23:47 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-03 12:25 . 2004-08-04 11:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-04 11:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-04 11:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2004-08-04 11:00 1853312 ----a-w- c:\windows\system32\win32k.sys
2005-03-25 08:17 . 2005-12-21 22:42 327680 ----a-w- c:\program files\RCSDK.dll
2005-03-25 08:17 . 2005-12-21 22:42 659456 ----a-w- c:\program files\RCRAPCLS.dll
2005-03-25 08:08 . 2005-12-21 22:42 77824 ----a-w- c:\program files\pscl2STI.dll
2004-11-25 14:29 . 2005-12-21 22:42 282624 ----a-w- c:\program files\rcParse.dll
2004-11-22 16:12 . 2005-12-21 22:42 434176 ----a-w- c:\program files\psdkdll.dll
2004-11-19 11:20 . 2005-12-21 22:42 184320 ----a-w- c:\program files\rcDvlp.dll
2004-11-08 08:32 . 2005-12-21 22:42 356352 ----a-w- c:\program files\rcDcd.dll
2004-10-13 04:35 . 2005-12-21 22:42 98304 ----a-w- c:\program files\pscSetup.dll
2004-10-13 04:34 . 2005-12-21 22:42 135168 ----a-w- c:\program files\pscCllct.dll
2004-10-13 04:34 . 2005-12-21 22:42 57344 ----a-w- c:\program files\pscAdimg.dll
2004-09-28 12:46 . 2005-12-21 22:42 360448 ----a-w- c:\program files\RC2DVLP.dll
2004-01-14 08:08 . 2005-12-21 22:42 598016 ----a-w- c:\program files\RcCamDat.dll
2002-05-21 12:46 . 2005-12-21 22:42 122880 ----a-w- c:\program files\CmSelDlg.dll
1999-04-08 16:18 . 2005-12-21 22:42 49152 ----a-w- c:\program files\_ISREG32.DLL
2010-10-14 02:28 . 2010-09-16 02:44 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Google Update"="c:\documents and settings\Guy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-08-27 136176]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-09-26 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-01-28 185896]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"VX3000"="c:\windows\vVX3000.exe" [2010-05-20 762736]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2009-03-12 2303216]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"WD Button Manager"="WDBtnMgr.exe" [2006-03-29 335872]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Documents and Settings\\Guy\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
R0 CorLog;CorLog;c:\windows\SYSTEM32\DRIVERS\CorLog.sys [5/16/2008 3:03 PM 11392]
R0 CorMem;CorMem;c:\windows\SYSTEM32\DRIVERS\cormem.sys [5/16/2008 3:03 PM 35328]
R1 CorPci;CorPci;c:\windows\SYSTEM32\DRIVERS\CorPci.sys [5/16/2008 3:03 PM 18688]
R1 CorSerial;CorSerial;c:\windows\SYSTEM32\DRIVERS\corserial.sys [5/16/2008 3:03 PM 56704]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [8/8/2010 9:53 PM 84072]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [10/3/2008 12:24 PM 93320]
R2 McMPFSvc;McAfee Personal Firewall;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [8/8/2010 9:52 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [8/8/2010 9:52 PM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [8/8/2010 9:53 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [8/8/2010 9:53 PM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [8/8/2010 9:53 PM 55840]
R3 dfmirage;dfmirage;c:\windows\SYSTEM32\DRIVERS\dfmirage.sys [11/25/2005 5:43 PM 31896]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [8/8/2010 9:53 PM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [8/8/2010 9:53 PM 88544]
S2 PICLPTNT;PICLPTNT;\??\c:\epic\PICLPTNT.SYS --> c:\epic\PICLPTNT.SYS [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [8/8/2010 9:53 PM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [8/8/2010 9:53 PM 84264]
S3 silabenm;Silicon Labs CP210x USB to UART Bridge Serial Port Enumerator Driver;c:\windows\SYSTEM32\DRIVERS\silabenm.sys [6/16/2008 10:02 AM 17920]
S3 silabser;Silicon Labs CP210x USB to UART Bridge Driver;c:\windows\SYSTEM32\DRIVERS\silabser.sys [6/16/2008 10:02 AM 61440]
--- Other Services/Drivers In Memory ---
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
2011-01-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2663308291-3766851088-3620130130-1006Core.job
- c:\documents and settings\Guy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-27 17:37]
2011-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2663308291-3766851088-3620130130-1006UA.job
- c:\documents and settings\Guy\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-27 17:37]
2008-01-13 c:\windows\Tasks\Microsoft_Hardware_Launch_explorer_exe.job
- c:\windows\explorer.exe [2004-08-04 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:8074
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: netflix.com
FF - ProfilePath - c:\documents and settings\Guy\Application Data\Mozilla\Firefox\Profiles\ncn1zto4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\McAfee\SiteAdvisor
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
HKCU-Run-TxIgLSBpYUyoPp.exe - c:\documents and settings\All Users\Application Data\TxIgLSBpYUyoPp.exe
HKCU-Run-l0FlWS98OXhWG1d - c:\docume~1\ALLUSE~1\APPLIC~1\l0FlWS98OXhWG1d.exe
HKCU-Run-LbifbJavy - c:\docume~1\ALLUSE~1\APPLIC~1\LbifbJavy.exe
HKCU-Run-EwKYhuUIUyB7SckX - c:\docume~1\ALLUSE~1\APPLIC~1\EwKYhuUIUyB7SckX.exe
HKCU-Run-T0wDKWPX0FGa - c:\docume~1\ALLUSE~1\APPLIC~1\T0wDKWPX0FGa.exe
HKCU-Run-SHf9QntLJK - c:\docume~1\ALLUSE~1\APPLIC~1\SHf9QntLJK.exe
HKCU-Run-jwyrmUI5Mmd - c:\docume~1\ALLUSE~1\APPLIC~1\jwyrmUI5Mmd.exe
HKCU-Run-nZzGLQKAxj - c:\docume~1\ALLUSE~1\APPLIC~1\nZzGLQKAxj.exe
HKLM-Run-MimBoot - c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe
SafeBoot-klmdb.sys
AddRemove-ImageJ_is1 - c:\documents and settings\Guy\My Documents\Corning\UPGRADE 2008\Snake Lausanne\ImageJ\ImageJ\unins000.exe
AddRemove-PicBasic Pro Compiler_is1 - c:\pbp\unins000.exe
AddRemove-SLABCOMM&10C4&EA60 - c:\windows\system32\Silabs\DriverUninstaller.exe VCP CP210x Cardinal\SLABCOMM&10C4&EA60
AddRemove-Verizon Online DSL_is1 - c:\program files\Common Files\SupportSoft\Verizon\vzuninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-14 09:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3148)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Dantz\Retrospect\retrorun.exe
c:\progra~1\Dantz\RETROS~1\wdsvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\progra~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
c:\windows\system32\WDBtnMgr.exe
c:\program files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
c:\program files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
.
**************************************************************************
.
Completion time: 2011-01-14 10:05:10 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-14 15:04
Pre-Run: 30,931,259,392 bytes free
Post-Run: 30,764,101,632 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 7FBF403089AF6565E5E296F01485C6D1