ComboFix 09-12-06.07 - BEN 12/06/2009 14:40.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.198 [GMT -6:00]
Running from: c:\documents and settings\BEN\desktop\commy.exe
Command switches used :: /stepdel
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\xcrashdump.dat
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.
2009-12-05 22:48 . 2009-12-05 22:48 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-11-29 21:58 . 2009-11-29 21:58 -------- d-----w- c:\documents and settings\BEN\Application Data\Malwarebytes
2009-11-29 21:58 . 2009-12-03 22:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-29 21:58 . 2009-12-03 22:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 21:58 . 2009-11-29 21:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-29 21:58 . 2009-12-05 22:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-29 02:50 . 2009-12-05 23:16 -------- d-----w- c:\documents and settings\BEN\Local Settings\Application Data\edhqjo
2009-11-19 02:06 . 2009-11-19 02:06 -------- d-----w- c:\documents and settings\JENA\Local Settings\Application Data\Apple Computer
2009-11-11 14:58 . 2009-11-11 14:58 1794456 ----a-w- c:\documents and settings\BEN\Application Data\Move Networks\MoveMediaPlayerWin_071701000002.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 20:37 . 2004-12-10 01:30 -------- d-----w- c:\program files\McAfee
2009-12-06 20:21 . 2007-08-31 01:11 -------- d-----w- c:\program files\Google
2009-12-05 20:48 . 1980-01-01 06:00 95360 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-12-05 19:55 . 2008-07-03 02:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-11-29 20:24 . 2009-06-01 22:40 -------- d-----w- c:\documents and settings\BEN\Application Data\Move Networks
2009-11-20 00:19 . 2008-10-01 03:20 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-11-19 05:13 . 2009-03-29 02:05 256 ----a-w- c:\windows\system32\pool.bin
2009-11-14 04:38 . 2009-10-13 14:48 -------- d-----w- c:\program files\Full Tilt Poker.Net
2009-11-11 14:58 . 2009-10-19 23:01 143976 ----a-w- c:\documents and settings\BEN\Application Data\Move Networks\uninstall.exe
2009-11-11 14:58 . 2009-10-15 00:50 5642688 ----a-w- c:\documents and settings\BEN\Application Data\Move Networks\plugins\npqmp071701000002.dll
2009-10-22 00:54 . 2009-07-28 23:49 -------- d-----w- c:\documents and settings\BEN\Application Data\Roxio
2009-10-19 23:02 . 2009-06-16 06:35 4183416 ----a-w- c:\documents and settings\BEN\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-10-18 19:22 . 2009-04-25 02:14 -------- d-----w- c:\documents and settings\BEN\Application Data\Apple Computer
2009-10-18 19:16 . 2009-10-18 19:15 -------- d-----w- c:\program files\iTunes
2009-10-18 19:16 . 2009-10-18 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-18 19:15 . 2009-10-18 19:15 -------- d-----w- c:\program files\iPod
2009-10-18 19:15 . 2009-04-25 02:09 -------- d-----w- c:\program files\Common Files\Apple
2009-10-18 19:12 . 2009-10-18 19:12 -------- d-----w- c:\program files\QuickTime
2009-10-18 19:06 . 2009-10-18 19:06 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2009-10-15 00:50 . 2009-10-15 00:50 97216 ----a-w- c:\documents and settings\BEN\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-10-13 14:48 . 2004-12-02 22:03 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-30 22:05 . 2009-09-30 22:05 97600 ----a-w- c:\documents and settings\JENA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-30 22:05 . 2009-09-30 22:05 127872 ----a-w- c:\documents and settings\JENA\Application Data\Move Networks\uninstall.exe
2009-09-30 22:05 . 2009-06-16 06:35 4183416 ----a-w- c:\documents and settings\JENA\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-09-16 15:22 . 2009-08-18 01:30 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 15:22 . 2009-08-18 01:30 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 15:22 . 2009-08-18 01:30 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 15:22 . 2009-07-08 18:44 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 15:22 . 2009-08-18 01:11 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-11 14:33 . 2004-08-04 11:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe Autorun" [X]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"PrinTray"="c:\windows\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-25 36864]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"MMTray"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2004-04-19 131072]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-19 53248]
"Lexmark X83 Button Monitor"="c:\progra~1\LEXMAR~1\ACMonitor_X83.exe" [2001-10-18 40960]
"Lexmark X83 Button Manager"="c:\progra~1\LEXMAR~1\AcBtnMgr_X83.exe" [2001-06-14 53248]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-05-06 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-05-06 118784]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-08-24 57344]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-04 344064]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2004-12-2 156784]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [8/17/2009 7:33 PM 210216]
S2 BulkUsb;Genesys Logic USB Scanner Controller NT 5.0;c:\windows\SYSTEM32\DRIVERS\usbscan.sys [12/9/2004 12:48 AM 15104]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/1/2009 11:01 AM 133104]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\SYSTEM32\DRIVERS\nwusbser2.sys [4/19/2007 10:09 AM 99200]
S3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\DRIVERS\PTDWBus.sys --> c:\windows\system32\DRIVERS\PTDWBus.sys [?]
S3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\DRIVERS\PTDWMdm.sys --> c:\windows\system32\DRIVERS\PTDWMdm.sys [?]
S3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\DRIVERS\PTDWVsp.sys --> c:\windows\system32\DRIVERS\PTDWVsp.sys [?]
S3 PWCTLDRV;The NECHostController Filter Driver; [x]
S3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys --> c:\windows\system32\DRIVERS\pwi_bus.sys [?]
S3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys --> c:\windows\system32\DRIVERS\pwi_mdfl.sys [?]
S3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys --> c:\windows\system32\DRIVERS\pwi_mdm.sys [?]
S3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys --> c:\windows\system32\DRIVERS\pwi_oflt.sys [?]
S3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys --> c:\windows\system32\DRIVERS\pwi_serd.sys [?]
.
------- Supplementary Scan -------
.
mSearch Bar =
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: {7C42B751-DF90-4186-B03C-C57492B55AE6} = 216.180.99.2,216.180.122.2
FF - ProfilePath - c:\documents and settings\BEN\Application Data\Mozilla\Firefox\Profiles\u69bc9i6.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
www.msn.comFF - plugin: c:\documents and settings\BEN\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\BEN\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\program files\Java\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Atoms, Bonding and Structure - c:\program files\Atoms
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
AddRemove-{00180409-78E1-11D2-B60F-006097C998E7} - c:\program files\Microsoft Office\ART\uninstall.exe {00180409-78E1-11D2-B60F-006097C998E7}
**************************************************************************
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(532)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-06 14:56
ComboFix-quarantined-files.txt 2009-12-06 20:55
Pre-Run: 54,559,252,480 bytes free
Post-Run: 54,917,603,328 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - C27DD09EA02F4E46F6CE71130FF7895F