ComboFix 10-03-02.02 - Dean 03/02/2010 19:19:56.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.693 [GMT -5:00]
Running from: c:\documents and settings\Dean\My Documents\Downloads\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dean\Local Settings\Temporary Internet Files\ikejaner.vbs
c:\documents and settings\Dean\Local Settings\Temporary Internet Files\kawoq.scr
c:\documents and settings\Dean\Local Settings\Temporary Internet Files\ycuqemavob.lib
c:\program files\Windows Media Player\pidgen.dll
c:\windows\Downloaded Program Files\dlhelper.dll
c:\windows\exufe.bat
c:\windows\patch.exe
c:\windows\system32\Data
c:\windows\system32\ixytapys.reg
c:\windows\system32\yzow.bat
c:\windows\uqawunozabulamuf.dll
.
original MBR restored successfully !
.
((((((((((((((((((((((((( Files Created from 2010-02-03 to 2010-03-03 )))))))))))))))))))))))))))))))
.
2010-03-02 21:59 . 2010-03-02 21:59 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-03-02 21:44 . 2010-03-02 21:44 -------- d-----w- c:\documents and settings\Dean\Local Settings\Application Data\{B0A546A5-0546-4519-BB20-5798965A2F91}
2010-02-28 17:31 . 2010-02-28 17:31 -------- d-----w- c:\documents and settings\HelpAssistant\WINDOWS
2010-02-28 16:53 . 2010-02-28 17:31 -------- d-----w- c:\documents and settings\HelpAssistant
2010-02-27 18:45 . 2010-02-27 18:44 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-27 18:44 . 2010-02-27 18:44 152576 ----a-w- c:\documents and settings\Dean\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-27 18:43 . 2010-02-27 18:43 79488 ----a-w- c:\documents and settings\Dean\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-25 23:26 . 2010-02-25 23:26 -------- d-----w- c:\windows\system32\wbem\Repository
2010-02-25 23:25 . 2010-02-25 23:25 -------- d-----w- c:\program files\Shaders
2010-02-25 23:25 . 2010-02-25 23:25 -------- d-----w- c:\program files\Resource
2010-02-25 23:25 . 2010-02-25 23:25 -------- d-----w- c:\program files\Mods
2010-02-25 23:25 . 2010-02-25 23:25 -------- d-----w- c:\program files\Miles
2010-02-25 23:25 . 2010-02-25 23:25 -------- d-----w- c:\program files\PublicMaps
2010-02-25 23:25 . 2010-02-25 23:25 -------- d-----w- c:\program files\Assets
2010-02-25 23:25 . 2010-02-25 23:25 -------- d-----w- c:\documents and settings\Dean\Application Data\InstallShield Installation Information
2010-02-05 15:39 . 2010-02-05 15:39 251376 ----a-w- c:\documents and settings\Dean\Application Data\Mozilla\plugins\npgoogletalk.dll
2010-02-03 01:40 . 2010-02-03 01:40 -------- d-----w- c:\program files\iPod
2010-02-03 01:40 . 2010-02-03 01:41 -------- d-----w- c:\program files\iTunes
2010-02-03 01:31 . 2010-02-03 01:31 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-03 00:14 . 2008-03-10 22:13 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-02 22:01 . 2004-07-22 20:27 -------- d-----w- c:\program files\SpywareBlaster
2010-03-02 21:59 . 2009-01-29 00:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-02 03:47 . 2005-12-01 00:01 96384 ----a-w- c:\windows\system32\drivers\sptd2573.sys
2010-03-02 03:06 . 2009-10-24 07:16 120 ----a-w- c:\windows\Mhimamisabamomi.dat
2010-03-01 21:50 . 2009-10-24 07:16 0 ----a-w- c:\windows\Kjelejowe.bin
2010-02-28 23:59 . 2009-08-20 01:54 -------- d-----w- c:\program files\AIM Toolbar
2010-02-27 18:44 . 2005-09-11 21:42 -------- d-----w- c:\program files\Java
2010-02-27 00:40 . 2009-05-04 23:23 -------- d-----w- c:\program files\uTorrent
2010-02-26 01:15 . 2009-05-04 23:23 -------- d-----w- c:\documents and settings\Dean\Application Data\uTorrent
2010-02-25 23:25 . 2006-01-09 23:03 -------- d-----w- c:\documents and settings\Dean\Application Data\My Games
2010-02-25 03:20 . 2006-09-15 16:32 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-19 23:37 . 2006-01-12 22:45 658 -c--a-w- c:\program files\ThemeParseLog.txt
2010-02-15 00:45 . 2004-07-22 19:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-11 04:04 . 2008-02-03 14:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-03 01:40 . 2007-08-19 18:54 -------- d-----w- c:\program files\Common Files\Apple
2010-02-03 01:36 . 2005-09-14 13:27 -------- d-----w- c:\program files\QuickTime
2010-01-17 21:07 . 2010-01-17 21:07 -------- d-----w- c:\program files\GoZone
2010-01-07 21:07 . 2009-01-29 00:41 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-01-29 00:41 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-31 16:50 . 2004-10-06 22:02 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2006-06-23 15:33 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 01:45 . 2009-12-18 01:45 57664 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-16 18:43 . 2004-10-06 22:12 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-10-06 22:12 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-10 01:33 . 2004-10-07 00:04 70960 ----a-w- c:\documents and settings\Dean\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-08 19:27 . 2004-10-06 22:02 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-10-06 22:02 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2004-10-06 22:02 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-10-24 07:14 . 2009-10-24 07:14 17444 ----a-w- c:\program files\Common Files\bydanu.dl
2009-10-23 22:54 . 2009-10-24 07:13 167936 ----a-w- c:\program files\_scui.vir
2007-08-25 15:14 . 2006-01-12 22:44 808 ----a-w- c:\program files\_Civ4Config.lnk
2007-08-25 15:14 . 2006-01-12 22:44 793 ----a-w- c:\program files\_Civ4TransferredMaps.lnk
2007-08-25 15:14 . 2006-01-12 22:44 772 ----a-w- c:\program files\_Civ4CustomAssets.lnk
2007-08-25 15:14 . 2006-01-12 22:44 765 ----a-w- c:\program files\_Civ4ScreenShots.lnk
2007-08-25 15:14 . 2006-01-12 22:44 758 ----a-w- c:\program files\_Civ4CustomMaps.lnk
2007-08-25 15:14 . 2006-01-12 22:44 735 ----a-w- c:\program files\_Civ4Replays.lnk
2007-08-25 15:14 . 2006-01-12 22:44 724 ----a-w- c:\program files\_Civ4CustomMods.lnk
2007-08-25 15:14 . 2006-01-12 22:44 719 ----a-w- c:\program files\_Civ4Patch.lnk
2007-08-25 15:14 . 2006-01-12 22:44 709 ----a-w- c:\program files\_Civ4Saves.lnk
2007-08-25 15:14 . 2006-01-12 22:44 702 ----a-w- c:\program files\_Civ4Logs.lnk
2006-01-01 22:26 . 2006-01-12 22:29 10326032 ----a-w- c:\program files\Civilization4.exe
2005-11-17 01:49 . 2006-01-12 22:29 59904 ----a-w- c:\program files\zlib1.dll
2005-11-16 01:59 . 2006-01-12 22:29 193024 ----a-w- c:\program files\binkw32.dll
2005-10-15 07:08 . 2006-01-12 22:04 1867776 ----a-w- c:\program files\python24.dll
2005-10-15 07:08 . 2006-01-12 22:04 387072 ----a-w- c:\program files\Mss32.dll
2005-10-15 06:32 . 2006-01-12 22:29 640000 ----a-w- c:\program files\dbghelp.dll
2005-09-26 04:30 . 2005-09-26 04:30 480 -c--a-w- c:\program files\SolidWorksswxJRNL.BAK
2004-08-03 04:43 . 2004-08-03 04:43 10135688 -c--a-w- c:\program files\MPSetupXP.exe
2004-07-29 20:13 . 2004-07-29 20:13 6465104 -c--a-w- c:\program files\LiveDrvPack_Patch.exe
2004-07-22 20:47 . 2004-07-22 20:47 8586133 -c--a-w- c:\program files\Cole2k.Media.-.Codec.Pack.V5.48.Advanced.zip
2003-12-02 05:03 . 2004-07-22 20:39 156828 -c----w- c:\program files\hijackthis.zip
2003-08-27 18:19 . 2004-09-10 19:00 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ESPN BottomLine"="c:\program files\ESPN\BottomLine\bline.exe" [2002-05-22 155759]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-06-13 2752512]
"Google Update"="c:\documents and settings\Dean\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-13 133104]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-08 86102]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-27 149280]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2005-11-11 7311360]
"nwiz"="nwiz.exe" [2005-11-11 1519616]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2005-11-11 86016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-01-26 185896]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
"vptray"="c:\program files\NavNT\vptray.exe" [2001-09-24 73728]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\Dean\Start Menu\Programs\Startup\
GoZone iSync.lnk - c:\program files\GoZone\GoZone_iSync.exe [2010-1-17 425984]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Wireless-B PCI Adapter Utility.lnk - c:\program files\Linksys\WMP11 Config Utility\WMP11Cfg.exe [2004-7-22 4634624]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\Dean\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Dean\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\patchget.dat"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"3246:TCP"= 3246:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [7/22/2004 3:36 PM 5248]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/11/2009 5:36 PM 30152]
R2 Viewpoint Service;Viewpoint Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/11/2009 5:36 PM 30152]
R3 IPN2120;Instant Wireless-B PCI Adapter Driver;c:\windows\system32\drivers\LSIPNDS.sys [7/22/2004 2:58 PM 95232]
S0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [7/22/2004 3:36 PM 160640]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/30/2005 7:01 PM 664064]
S3 oflpydin;oflpydin;\??\c:\docume~1\Dean\LOCALS~1\Temp\oflpydin.sys --> c:\docume~1\Dean\LOCALS~1\Temp\oflpydin.sys [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [11/4/2006 8:10 PM 3968]
S4 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe --> c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [?]
.
Contents of the 'Scheduled Tasks' folder
2010-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-57989841-515967899-725345543-1004Core.job
- c:\documents and settings\Dean\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-13 03:26]
2010-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-57989841-515967899-725345543-1004UA.job
- c:\documents and settings\Dean\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-13 03:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/
mWindow Title = Windows Internet Explorer provided by Comcast
mSearch Bar = hxxp://www.google.com/
mSearchMigratedDefaultURL = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
mSearchURL = hxxp://www.google.com/
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\AskBarDis\bar\bin\askBar.dll
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - c:\program files\AskBarDis\bar\bin\askBar.dll
HKLM-Run-Gyoxeluwenuqave - c:\windows\uqawunozabulamuf.dll
AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9b.exe
AddRemove-Webshots Desktop - c:\progra~1\Webshots\UNWISE.EXE
AddRemove-XviD - c:\program files\XviD\UninstXviD.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-02 19:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x871C1C48]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf77e5f28
\Driver\ACPI -> ACPI.sys @ 0xf7758cb8
\Driver\atapi -> 0x871c1c48
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: Instant Wireless-B PCI Adapter -> SendCompleteHandler -> 0x8653d330
PacketIndicateHandler -> NDIS.sys @ 0xf7611a21
SendHandler -> NDIS.sys @ 0xf75ef87b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x0DF7FDFC
malicious code @ sector 0x0DF7FDFF !
PE file found in sector at 0x0DF7FE15 !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(676)
c:\windows\System32\NavLogon.dll
.
Completion time: 2010-03-02 19:30:24
ComboFix-quarantined-files.txt 2010-03-03 00:30
ComboFix2.txt 2009-01-29 01:34
Pre-Run: 30,668,607,488 bytes free
Post-Run: 30,670,045,184 bytes free
Current=1 Default=1 Failed=4 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - FD0D32EBE716106CD43B81BD32AC03D0