ComboFix 09-09-20.04 - corey 09/21/2009 12:24.1.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.809 [GMT -5:00]
Running from: c:\documents and settings\corey\Desktop\Combo-Fix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Windows Police Pro
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\svchast.exe
c:\windows\system32\bennuar.old
c:\windows\system32\bincd32.dat
c:\windows\system32\bszip.dll
c:\windows\system32\desot.exe
c:\windows\system32\drivers\gasfkylnktcsvm.sys
c:\windows\system32\gasfkycrxwmxoo.dll
c:\windows\system32\gasfkydilyejgy.dll
c:\windows\system32\gasfkyhlwowjof.dat
c:\windows\system32\gasfkyhonhsdkb.dat
c:\windows\system32\gasfkyxcpswkkb.dll
c:\windows\system32\sonhelp.htm
c:\windows\system32\sysnet.dat
c:\windows\UA000035.DLL
c:\windows\wpd99.drv
c:\windows\system32\mstsc.exe . . . is infected!!
c:\windows\system32\wiaacmgr.exe . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_gasfkytpldqukf
-------\Service_gasfkytpldqukf
-------\Legacy_AntipPolice_
-------\Service_AntipPolice_
((((((((((((((((((((((((( Files Created from 2009-08-21 to 2009-09-21 )))))))))))))))))))))))))))))))
.
2009-09-21 00:15 . 2009-09-21 00:15 -------- d-----w- c:\program files\Trend Micro
2009-09-20 22:45 . 2009-09-20 22:52 -------- d-----w- C:\ComboFix
2009-09-20 19:39 . 2009-09-21 04:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-20 18:56 . 2008-12-11 13:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-09-20 18:56 . 2009-08-24 19:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-09-20 18:56 . 2009-08-19 16:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-09-20 18:56 . 2009-09-20 18:57 -------- d-----w- c:\program files\Common Files\PC Tools
2009-09-20 18:56 . 2008-12-10 16:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-09-20 18:56 . 2009-09-20 19:01 -------- d-----w- c:\program files\Spyware Doctor
2009-09-20 18:56 . 2009-09-20 18:56 -------- d-----w- c:\documents and settings\corey\Application Data\PC Tools
2009-09-20 18:56 . 2009-09-20 18:56 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-09-20 18:46 . 2009-09-20 18:46 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-09-20 18:36 . 2009-09-20 18:36 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-20 18:30 . 2009-09-20 18:30 -------- d-----w- c:\documents and settings\corey\Application Data\Malwarebytes
2009-09-20 18:29 . 2009-09-20 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-20 18:20 . 2009-09-20 18:20 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-09-20 18:06 . 2009-09-20 18:06 -------- d-----w- c:\program files\GiPo@Utilities
2009-09-20 18:06 . 2009-09-20 18:06 -------- d-----w- c:\program files\Common Files\Gibinsoft Shared
2009-09-20 17:37 . 2009-09-20 17:37 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-09-14 22:30 . 2009-09-14 22:30 -------- d-----w- c:\program files\Native Instruments
2009-09-14 22:06 . 2009-09-14 22:06 -------- d-----w- c:\program files\Steinberg
2009-09-14 22:06 . 2009-09-14 22:06 -------- d-----w- c:\program files\Kjaerhus Audio
2009-09-14 01:04 . 2006-06-20 08:56 225280 ----a-w- c:\windows\system32\rewire.dll
2009-09-10 00:26 . 2009-09-20 23:03 -------- d-sh--w- c:\documents and settings\corey\PrivacIE
2009-09-10 00:25 . 2009-09-10 00:25 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-09-10 00:25 . 2009-09-20 23:03 -------- d-sh--w- c:\documents and settings\corey\IETldCache
2009-09-10 00:18 . 2009-09-10 00:18 -------- d-----w- c:\windows\ie8updates
2009-09-10 00:16 . 2009-09-10 00:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-09-10 00:16 . 2009-09-10 00:16 -------- d-----w- c:\documents and settings\corey\Application Data\Yahoo!
2009-09-10 00:14 . 2009-09-10 00:16 -------- dc-h--w- c:\windows\ie8
2009-09-10 00:13 . 2009-09-10 00:18 -------- d--h--w- c:\windows\msdownld.tmp
2009-09-09 23:20 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-09-09 23:20 . 2009-07-03 17:09 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-09-09 23:20 . 2009-07-03 17:09 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-09 23:20 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-09-09 23:20 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-09 23:20 . 2009-07-03 17:09 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-09-07 17:01 . 2009-09-07 17:01 -------- d-----w- c:\program files\BitTorrent
2009-09-05 14:45 . 2009-09-05 14:45 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-05 14:45 . 2009-09-05 14:45 -------- d-----w- c:\documents and settings\corey\Local Settings\Application Data\AOL OCP
2009-09-05 14:45 . 2009-09-05 14:45 -------- d-----w- c:\program files\AIM6
2009-09-05 14:45 . 2009-09-05 14:45 -------- d-----w- c:\program files\Netflix
2009-09-05 14:45 . 2009-09-05 14:45 -------- d-----w- c:\program files\Music Mixer 4
2009-09-05 14:45 . 2009-09-05 14:45 -------- d-----w- c:\program files\Veoh Networks
2009-09-05 14:44 . 2009-09-09 23:12 -------- d-----w- c:\program files\LimeWire
2009-09-03 22:12 . 2009-09-14 01:05 -------- d-----w- c:\program files\ASIO4ALL v2
2009-09-03 22:08 . 2009-09-03 22:32 -------- d-----w- c:\program files\Image-Line
2009-09-02 20:06 . 2009-09-05 14:44 -------- d-----w- c:\program files\Mozilla Firefox(2)
2009-08-26 04:05 . 2009-08-26 04:05 -------- d-----w- c:\documents and settings\corey\Application Data\AVS4YOU
2009-08-26 04:04 . 2009-08-26 04:04 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-08-26 04:03 . 2009-09-05 14:44 -------- d-----w- c:\program files\AVS4YOU
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-20 23:03 . 2006-12-11 20:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-20 21:52 . 2006-06-11 03:21 60064 ----a-w- c:\documents and settings\corey\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-20 18:23 . 2007-10-02 02:51 -------- d-----w- c:\program files\Vstplugins
2009-09-14 01:01 . 2006-08-24 17:56 -------- d-----w- c:\documents and settings\corey\Application Data\BitTorrent
2009-09-09 23:11 . 2006-07-03 00:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-26 02:59 . 2008-11-08 22:24 -------- d-----w- c:\program files\Common Files\AOL
2009-08-14 11:58 . 2009-09-20 18:56 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-07-03 17:09 . 2002-12-31 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2006-07-03 15:33 . 2006-07-03 15:33 5632 --sha-w- c:\program files\Thumbs.db
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2006-10-04 53760]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoWinKeys"= 01000000
"NoRecentDocsNetHood"= 01000000
"NoSMMyPictures"= 01000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
backup=c:\windows\pss\HotSync Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"BthServ"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"CryptSvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9/20/2009 1:56 PM 206256]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/8/2008 5:25 PM 24652]
S3 kbeepm;kbeepm;\??\c:\docume~1\corey\LOCALS~1\Temp\kbeepm.sys --> c:\docume~1\corey\LOCALS~1\Temp\kbeepm.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [9/20/2009 1:56 PM 348752]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://google.com/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-21 12:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1757981266-1580436667-1343024091-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\.application\bootstrap]
@DACL=(02 0000)
@="bootstrap.application.1"
[HKEY_LOCAL_MACHINE\software\Classes\.xaml\bootstrap]
@DACL=(02 0000)
@="bootstrap.xaml.1"
[HKEY_LOCAL_MACHINE\software\Classes\.xbap\bootstrap]
@DACL=(02 0000)
@="bootstrap.xbap.1"
[HKEY_LOCAL_MACHINE\software\Classes\.xps\bootstrap]
@DACL=(02 0000)
@="bootstrap.xps.1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(724)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2009-09-21 12:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-21 17:36
Pre-Run: 36,498,518,016 bytes free
Post-Run: 37,255,786,496 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
197 --- E O F --- 2007-07-14 09:07