Please note, after ComboFix was finished and produced the text file, I closed the text file to see if my desktop returned. This caused my computer to crash with the message: "STOP: c000113c Unknown Hard Error." I had to turn off the computer and then back on to provide the combofix contents:
ComboFix 11-06-17.04 - Admin 06/19/2011 23:14:01.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1677 [GMT -7:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Admin\Application Data\Adobe\plugs
c:\documents and settings\Admin\Application Data\Adobe\shed
c:\documents and settings\Admin\Application Data\chrtmp
c:\documents and settings\Admin\Application Data\inst.exe
c:\documents and settings\Admin\Application Data\Setup.exe
c:\documents and settings\Admin\Local Settings\Application Data\{95D238F2-8F56-445F-98EF-8299181B8A68}
c:\documents and settings\Admin\Local Settings\Application Data\{95D238F2-8F56-445F-98EF-8299181B8A68}\chrome\content\_cfg.js
c:\documents and settings\Admin\Local Settings\Application Data\{95D238F2-8F56-445F-98EF-8299181B8A68}\chrome\content\overlay.xul
c:\documents and settings\Admin\Local Settings\Application Data\{95D238F2-8F56-445F-98EF-8299181B8A68}\install.rdf
c:\documents and settings\Admin\WINDOWS
c:\windows\system32\system
.
c:\windows\system32\midimap.dll . . . is infected!!
.
.
((((((((((((((((((((((((( Files Created from 2011-05-20 to 2011-06-20 )))))))))))))))))))))))))))))))
.
.
2011-06-19 21:14 . 2011-06-19 21:14 -------- d-----w- c:\program files\7-Zip
2011-06-18 12:03 . 2011-06-18 12:03 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2011-06-16 16:36 . 2011-06-16 16:36 -------- d-----w- c:\documents and settings\Admin\Application Data\Malwarebytes
2011-06-16 16:36 . 2011-05-29 16:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-16 16:36 . 2011-06-16 16:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-06-16 16:36 . 2011-05-29 16:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-16 16:36 . 2011-06-16 16:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-06-16 16:01 . 2011-06-16 16:01 -------- d-----w- c:\windows\system32\wbem\Repository
2011-06-16 15:57 . 2011-06-20 02:30 -------- d-----w- c:\program files\World of Warcraft
2011-06-16 15:20 . 2011-06-16 15:20 0 ----a-w- c:\windows\Jsewe.bin
2011-06-16 15:18 . 2011-06-16 15:56 -------- d-----w- c:\documents and settings\All Users\Application Data\eN28258ClAaH28258
2011-06-16 06:19 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2011-06-16 06:17 . 2011-04-21 13:52 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-16 06:16 . 2011-04-30 03:01 758784 ------w- c:\windows\system32\dllcache\vgx.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-02 15:30 . 2009-12-09 14:28 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:47 . 2011-04-19 05:22 457856 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11 . 2009-04-15 02:06 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2009-04-15 02:02 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 16:11 . 2009-03-08 18:34 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 12:01 . 2009-03-08 18:35 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:52 . 2008-04-29 02:58 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
.
[-] 2009-04-14 . 25A740D70E8007814A48D3FA1B34FA34 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\ff0686f2f699fa07ed5ad0848fa3055b\SP3QFE\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\ff0686f2f699fa07ed5ad0848fa3055b\SP3GDR\tcpip.sys
.
[-] 2009-04-15 02:01 . 305A986FA2FF569D333CCA2AE3AE321D . 1444864 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2009-04-15 . DB3B9755F265C37319DF9AFF4FDDF717 . 568832 . . [5.1.2600.5714] . . c:\windows\system32\winlogon.exe
.
[-] 2009-04-15 . 99C1ACB1B8F0F2CECC56515E502B5120 . 575488 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
.
[-] 2009-04-15 . 6DA7EDB6D1289B0B8A6DED512EBCB1AB . 1440768 . . [6.00.2900.5634] . . c:\windows\explorer.exe
.
[-] 2008-04-15 . DD973467A6C5CFE264F112CB3946E8BD . 263680 . . [5.1.2600.5512] . . c:\windows\regedit.exe
.
[-] 2009-04-15 . 2547D2CF090AC7636898F16957EBCEDC . 502272 . . [1.0626.6002.16497] . . c:\windows\system32\usp10.dll
.
.
[-] 2009-04-15 . CBF5945651C96E471B3A004BBDC36864 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
.
.
[-] 2009-04-15 . 448937CF6D5D4A4009532DF67B205F92 . 32256 . . [5.1.2600.5512] . . c:\windows\system32\midimap.dll
.
c:\windows\System32\drivers\beep.sys ... is missing !!
c:\windows\System32\wscntfy.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
"RunNarrator"="Narrator.exe" [2009-04-15 53248]
.
c:\documents and settings\Admin\Start Menu\Programs\Startup\
Efficient Reminder Free.lnk - c:\program files\Efficient Reminder Free\EfficientReminderFree.exe [2010-8-27 10257920]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^TimeLeft.lnk]
path=c:\documents and settings\Admin\Start Menu\Programs\Startup\TimeLeft.lnk
backup=c:\windows\pss\TimeLeft.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Status Monitor 3 Environment Check.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check.lnk
backup=c:\windows\pss\EPSON Status Monitor 3 Environment Check.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MacroMaker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MacroMaker.lnk
backup=c:\windows\pss\MacroMaker.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 09:04 39792 -c--a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2009-04-15 02:01 37376 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 -c--a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
2010-07-25 23:30 3220912 ----a-w- c:\program files\Internet Download Manager\IDMan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2007-04-11 23:32 56080 -c--a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
2007-04-11 23:32 56080 -c--a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando Media Booster]
2010-01-09 19:13 2935480 ----a-w- c:\program files\Pando Networks\Media Booster\PMB.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerStrip]
2008-09-17 15:12 737408 ----a-w- c:\program files\PowerStrip\PStrip.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 19:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2002-04-17 18:42 69632 -c--a-w- c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2006-08-15 15:47 1404928 -c--a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2010-03-09 02:52 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\mIRC\\mirc.exe"=
"c:\\mirc-babra\\mirc.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Old Computer Files\\mirc-diamonds\\mirc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Admin\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-x.x.x.x-4.0.0.12911-Downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56589:TCP"= 56589:TCP:Pando Media Booster
"56589:UDP"= 56589:UDP:Pando Media Booster
"6881:TCP"= 6881:TCP:Blizzard Downloader: 6881
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9/8/2010 6:49 AM 64288]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/16/2011 9:36 AM 366640]
R2 PStrip;PStrip;c:\windows\system32\drivers\pstrip.sys [7/14/2007 6:37 PM 27992]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/16/2011 9:36 AM 22712]
S0 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]
S3 FARMNTIO;FARMNTIO;c:\windows\system32\drivers\FarMntIo.sys [12/11/2009 12:05 AM 13184]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 LLRING0;LLRING0;\??\c:\program files\FortressMU\FMU S4 V3\fortress 3d\MuGuard\llck1.sys --> c:\program files\FortressMU\FMU S4 V3\fortress 3d\MuGuard\llck1.sys [?]
S3 Usblink;Usblink Driver;c:\windows\system32\drivers\ulink.sys [12/9/2009 4:19 PM 40060]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2010-08-16 20:43 451872 -c--a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
2009-03-08 18:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-20 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 22:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\Microsoft Office-2002\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_674125AABFE11C21.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\o564exhs.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-tcactive - c:\program files\The Cleaner\tcap.exe
AddRemove-Ashampoo Burning Studio 10_is1 - c:\program files\Ashampoo\Ashampoo Burning Studio 10\unins000.exe
AddRemove-DVD Shrink_is1 - c:\dvd rip\DVD Shrink\unins000.exe
AddRemove-{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1 - c:\program files\VSO\ConvertX\4\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-06-19 23:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
GMER - Rootkit Detector and Remover
Windows 5.1.2600 Disk: WDC_WD6400AAKS-75A7B0 rev.01.03B01 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x89B5C31B
user & kernel MBR OK
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1935655697-1580818891-1644491937-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2d,2e,01,e1,86,3f,ee,46,82,50,9d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2d,2e,01,e1,86,3f,ee,46,82,50,9d,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2d,2e,01,e1,86,3f,ee,46,82,50,9d,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):7b,47,c9,1b,c9,cb,7e,02,ce,f6,b0,b7,b0,17,6d,de,79,38,af,ec,82,
91,67,1b,a0,51,b3,41,f2,41,19,cd,c4,a4,8c,de,48,b6,be,ab,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f8eeab2b-dc06-4946-916b-ec1b4f33bc90}]
@Denied: (Full) (Everyone)
"Model"=dword:00000155
"Therad"=dword:00000015
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(464)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
.
- - - - - - - > 'lsass.exe'(524)
c:\windows\system32\WININET.dll
c:\windows\system32\setupapi.dll
.
Completion time: 2011-06-19 23:27:30
ComboFix-quarantined-files.txt 2011-06-20 06:27
.
Pre-Run: 241,772,118,016 bytes free
Post-Run: 242,107,703,296 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /noexecute=alwaysoff
.
- - End Of File - - DC35A97A0815395980893FB06C5F15D0