ComboFix Log:
ComboFix 09-10-13.04 - user 10/15/2009 10:16.2.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.223.97 [GMT 5.5:30]
Running from: d:\documents and settings\user\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\user\Desktop\CFScript.txt
FILE ::
"d:\windows\system32\01.tmp"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\All Users\WindowsLive.exe
d:\documents and settings\user\Application Data\WindowsLive.exe
d:\windows\Fonts\unwise_.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WINDOWS_HOSTS_CONTROLLER
-------\Service_Windows Hosts Controller
((((((((((((((((((((((((( Files Created from 2009-09-15 to 2009-10-15 )))))))))))))))))))))))))))))))
.
2009-10-14 16:52 . 2009-10-14 16:52 -------- d-----w- d:\documents and settings\user\Application Data\MozillaControl
2009-10-14 16:52 . 2009-10-14 16:52 141454 ----a-w- d:\windows\system32\man8.exe
2009-10-14 15:02 . 2009-10-14 15:03 1050713 ----a-w- d:\windows\system32\rss.exe
2009-10-12 14:35 . 2009-10-12 14:35 -------- d-----w- D:\FOUND.028
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-15 04:54 . 2002-01-06 23:31 196 ----a-w- d:\windows\system32\drivers\ALCICH.DAT
2009-09-10 09:24 . 2001-12-31 20:46 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 09:23 . 2001-12-31 20:46 19160 ----a-w- d:\windows\system32\drivers\mbam.sys
1998-12-08 13:23 . 1998-12-08 13:23 99840 ----a-w- d:\program files\Common Files\IRAABOUT.DLL
1998-12-08 13:23 . 1998-12-08 13:23 70144 ----a-w- d:\program files\Common Files\IRAMDMTR.DLL
1998-12-08 13:23 . 1998-12-08 13:23 48640 ----a-w- d:\program files\Common Files\IRALPTTR.DLL
1998-12-08 13:23 . 1998-12-08 13:23 31744 ----a-w- d:\program files\Common Files\IRAWEBTR.DLL
1998-12-08 13:23 . 1998-12-08 13:23 186368 ----a-w- d:\program files\Common Files\IRAREG.DLL
1998-12-08 13:23 . 1998-12-08 13:23 17920 ----a-w- d:\program files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((( SnapShot@2009-10-14_14.38.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-15 04:55 . 2009-10-15 04:55 16384 d:\windows\temp\Perflib_Perfdata_548.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes Anti-Malware (reboot)"="d:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2002-01-01 149280]
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=d:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=d:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=d:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=d:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=d:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=d:\documents and settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=d:\windows\pss\NkbMonitor.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"d:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"d:\\Program Files\\Messenger\\MSMSGS.EXE"=
"d:\\Program Files\\LimeWire\\LimeWire.exe"=
"d:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"d:\\Program Files\\BitTorrent\\bittorrent.exe"=
"d:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9999:TCP"= 9999:TCP:PORT1
"1013:TCP"= 1013:TCP:BS
"55322:TCP"= 55322:TCP:FD
"9991:TCP"= 9991:TCP:PORT2
"58311:TCP"= 58311:TCP:FD
"56500:TCP"= 56500:TCP:FD
"36203:TCP"= 36203:TCP:FD
"60715:TCP"= 60715:TCP:FD
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);d:\windows\system32\drivers\RMSPPPOE.SYS [1/1/2002 12:09 AM 31424]
.
Contents of the 'Scheduled Tasks' folder
2009-10-15 d:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- d:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 10:24]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: &Windows Live Search - d:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: &Yahoo! Search - file:///d:\program files\Yahoo!\Common/ycsrch.htm
IE: Open in new background tab - d:\program files\Windows Live Toolbar\Components\en-in\msntabres.dll.mui/229?bd5c537a7d664a57afed0ed06658bb63
IE: Open in new foreground tab - d:\program files\Windows Live Toolbar\Components\en-in\msntabres.dll.mui/230?bd5c537a7d664a57afed0ed06658bb63
IE: Yahoo! &Dictionary - file:///d:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///d:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///d:\program files\Yahoo!\Common/ycsms.htm
TCP: {B3EDBC60-91DF-486C-9929-938433EAA145} = 218.248.255.194 218.248.255.162
FF - ProfilePath - d:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\7boyuqg7.default\
FF - plugin: d:\program files\BitTorrent_DNA\npbtdna.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npbittorrent.dll
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-Windows Live - d:\documents and settings\All Users\WindowsLive.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-15 10:25
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
------------------------ Other Running Processes ------------------------
.
d:\windows\SYSTEM32\CTSVCCDA.EXE
d:\program files\JAVA\JRE6\BIN\JQS.EXE
d:\windows\SYSTEM32\HPZIPM12.EXE
d:\windows\SYSTEM32\WDFMGR.EXE
d:\windows\SYSTEM32\MSPMSPSV.EXE
.
**************************************************************************
.
Completion time: 2009-10-15 10:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-15 04:58
Pre-Run: 11,133,091,840 bytes free
Post-Run: 11,115,757,568 bytes free
149
Thanks. Today, small windows have started opening up. One of these said "Operation timed out when attemting to contact linkbee.com"