Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

IE and FF both being redirected


  • This topic is locked This topic is locked
2 replies to this topic

#1 jrpereira

jrpereira

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:33 AM

Posted 08 June 2010 - 02:24 AM

Ok, I have run SDFix and Combofix (with /killall), SuperAnti Virus, Sophos, MBam and no avail. Posting all logs, let me know if anything is missing. My client noticed his USB keyboard was not working as the first sign. Now that works but can't hit Windows Update or any search results that might lead to some anti-spyware site such as this one. Can however type in the URLs manually.

Dumping Logs:

SDFix: Version 1.240
Run by David Schleifer on Mon 06/07/2010 at 10:11 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-07 22:26:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"="C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe:*:Enabled:Assassin's Creed Update"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Curious Labs\\Poser 6\\Poser.exe"="C:\\Program Files\\Curious Labs\\Poser 6\\Poser.exe:*:Enabled:Poser executable file"
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"="C:\\WINDOWS\\system32\\usmt\\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"="C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe:*:Disabled:Assassin's Creed Dx10"
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"="C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe:*:Disabled:Assassin's Creed Dx9"
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"="C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe:*:Disabled:CyberLink PowerDVD DX"
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"="C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe:*:Disabled:CyberLink PowerDVD DX Resident Program"
"C:\\Program Files\\Microsoft Games\\Halo\\halo.exe"="C:\\Program Files\\Microsoft Games\\Halo\\halo.exe:*:Disabled:Halo"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Disabled:Microsoft Office OneNote"
"C:\\Program Files\\Red Storm Entertainment\\RavenShield\\system\\ravenshield.exe"="C:\\Program Files\\Red Storm Entertainment\\RavenShield\\system\\ravenshield.exe:*:Disabled:ravenshield"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"="C:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat:*:Disabled:The Battle for Middle-earth™ II"
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Disabled:SmartFTP Client 3.0"
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe:*:Enabled:Age of Empires III"
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe:*:Enabled:Age of Empires III - The Asian Dynasties"
"C:\\Program Files\\Sierra Online\\Battlestar Galactica\\BSG.exe"="C:\\Program Files\\Sierra Online\\Battlestar Galactica\\BSG.exe:*:Enabled:Battlestar Galactica"
"C:\\Program Files\\e frontier\\Poser 7\\Poser.exe"="C:\\Program Files\\e frontier\\Poser 7\\Poser.exe:*:Enabled:Poser executable file"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Activision\\Sfc3\\SFC3.exe"="C:\\Program Files\\Activision\\Sfc3\\SFC3.exe:*:Enabled:Starfleet Command III - TNG"
"C:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"="C:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe:*:Enabled:Pando Media Booster"
"C:\\Program Files\\Turbine\\DDO Unlimited\\dndclient.exe"="C:\\Program Files\\Turbine\\DDO Unlimited\\dndclient.exe:*:Enabled:dndclient"
"C:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"="C:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"="C:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe:*:Enabled:Assassin's Creed II"
"C:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"="C:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe:*:Enabled:Assassin's Creed II Update"
"C:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"="C:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe:*:Enabled:Assassin's Creed II Uplay"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"="C:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX"
"C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"="C:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :



Files with Hidden Attributes :

Wed 28 May 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 9 Mar 2010 2,137,488 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\647b7f1fd178462604e3d6377163c8ee\BIT12.tmp"
Sun 7 Mar 2010 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d8df5e51a03c2f6e36bfed210fa65f37\BITF.tmp"
Sat 3 Oct 2009 444 ...HR --- "C:\Documents and Settings\David Schleifer\Application Data\SecuROM\UserData\securom_v7_01.bak"

Finished!

Logfile of random's system information tool 1.07 (written by random/random)
Run by David Schleifer at 2010-06-08 01:59:58
Microsoft Windows XP Professional Service Pack 3
System drive C: has 699 GB (74%) free of 949 GB
Total RAM: 3325 MB (91% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:00:00 AM, on 6/8/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\David Schleifer\Desktop\Working\RSIT.exe
C:\Program Files\trend micro\David Schleifer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080502
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [EPSON Stylus C88 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE /P23 "EPSON Stylus C88 Series" /O6 "USB001" /M "Stylus C88"
O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe resetprofile
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\Wtablet\TabUserW.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1240319352015
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1240319334921
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ARHPJ - Unknown owner - C:\DOCUME~1\DAVIDS~1\LOCALS~1\Temp\ARHPJ.exe (file missing)
O23 - Service: AVDTQUEHEG - Unknown owner - C:\DOCUME~1\DAVIDS~1\LOCALS~1\Temp\AVDTQUEHEG.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: XFII - Sysinternals - www.sysinternals.com - C:\DOCUME~1\DAVIDS~1\LOCALS~1\Temp\XFII.exe

--
End of file - 6200 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\OGALogon.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\Dell\BAE\BAE.dll [2006-11-09 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
Locked

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-03-08 13680640]
"NVRaidService"=C:\WINDOWS\system32\nvraidservice.exe [2007-10-26 184352]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-01-14 16855552]
"PDVDDXSrv"=C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2007-09-17 124200]
"EPSON Stylus C88 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE [2005-01-27 98304]
"kmw_run.exe"=C:\WINDOWS\system32\kmw_run.exe [2006-08-03 106496]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2009-09-05 417792]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-03-08 86016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"=C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe [2008-01-15 106496]
"Pando Media Booster"=C:\Program Files\Pando Networks\Media Booster\PMB.exe [2010-03-08 2937528]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
TabUserW.exe.lnk - C:\WINDOWS\system32\Wtablet\TabUserW.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe"="C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:*:Enabled:Assassin's Creed Update"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Curious Labs\Poser 6\Poser.exe"="C:\Program Files\Curious Labs\Poser 6\Poser.exe:*:Enabled:Poser executable file"
"C:\WINDOWS\system32\usmt\migwiz.exe"="C:\WINDOWS\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe"="C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:*:Disabled:Assassin's Creed Dx10"
"C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe"="C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:*:Disabled:Assassin's Creed Dx9"
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe"="C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Disabled:CyberLink PowerDVD DX"
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Disabled:CyberLink PowerDVD DX Resident Program"
"C:\Program Files\Microsoft Games\Halo\halo.exe"="C:\Program Files\Microsoft Games\Halo\halo.exe:*:Disabled:Halo"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Disabled:Microsoft Office OneNote"
"C:\Program Files\Red Storm Entertainment\RavenShield\system\ravenshield.exe"="C:\Program Files\Red Storm Entertainment\RavenShield\system\ravenshield.exe:*:Disabled:ravenshield"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Electronic Arts\The Battle for Middle-earth ™ II\game.dat"="C:\Program Files\Electronic Arts\The Battle for Middle-earth ™ II\game.dat:*:Disabled:The Battle for Middle-earth™ II"
"C:\Program Files\SmartFTP Client\SmartFTP.exe"="C:\Program Files\SmartFTP Client\SmartFTP.exe:*:Disabled:SmartFTP Client 3.0"
"C:\Program Files\Microsoft Games\Age of Empires III\age3.exe"="C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:*:Enabled:Age of Empires III"
"C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe"="C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe:*:Enabled:Age of Empires III - The Asian Dynasties"
"C:\Program Files\Sierra Online\Battlestar Galactica\BSG.exe"="C:\Program Files\Sierra Online\Battlestar Galactica\BSG.exe:*:Enabled:Battlestar Galactica"
"C:\Program Files\e frontier\Poser 7\Poser.exe"="C:\Program Files\e frontier\Poser 7\Poser.exe:*:Enabled:Poser executable file"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Activision\Sfc3\SFC3.exe"="C:\Program Files\Activision\Sfc3\SFC3.exe:*:Enabled:Starfleet Command III - TNG"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
"C:\Program Files\Turbine\DDO Unlimited\dndclient.exe"="C:\Program Files\Turbine\DDO Unlimited\dndclient.exe:*:Enabled:dndclient"
"C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe"="C:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher"
"C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe"="C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedIIGame.exe:*:Enabled:Assassin's Creed II"
"C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe"="C:\Program Files\Ubisoft\Assassin's Creed II\AssassinsCreedII.exe:*:Enabled:Assassin's Creed II Update"
"C:\Program Files\Ubisoft\Assassin's Creed II\UPlayBrowser.exe"="C:\Program Files\Ubisoft\Assassin's Creed II\UPlayBrowser.exe:*:Enabled:Assassin's Creed II Uplay"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe"="C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX"
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - D:\.\Autorun\UBIAUTORUN.EXE .\cd2.ini


======List of files/folders created in the last 1 months======

2010-06-08 01:54:10 ----D---- C:\rsit
2010-06-08 01:36:47 ----D---- C:\Program Files\Nemesis Anti-Spyware
2010-06-08 00:15:02 ----A---- C:\ComboFix.txt
2010-06-07 23:58:35 ----D---- C:\ComboFix
2010-06-07 20:44:10 ----D---- C:\Program Files\Sophos
2010-06-07 19:45:04 ----D---- C:\Config.Msi
2010-06-07 19:10:37 ----D---- C:\WINDOWS\ERUNT
2010-06-07 19:06:22 ----D---- C:\SDFix
2010-06-05 13:14:53 ----D---- C:\WINDOWS\temp
2010-06-05 12:37:51 ----A---- C:\WINDOWS\ntbtlog.txt
2010-06-05 12:10:13 ----D---- C:\NV38243472.TMP
2010-06-05 12:10:12 ----D---- C:\NV828172.TMP
2010-06-05 11:58:38 ----D---- C:\Documents and Settings\David Schleifer\Application Data\Malwarebytes
2010-06-05 11:58:31 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-06-05 11:34:48 ----A---- C:\WINDOWS\NIRCMD.exe
2010-06-05 11:34:48 ----A---- C:\WINDOWS\MBR.exe
2010-06-05 11:34:46 ----A---- C:\WINDOWS\zip.exe
2010-06-05 11:34:46 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-06-05 11:34:46 ----A---- C:\WINDOWS\SWSC.exe
2010-06-05 11:34:46 ----A---- C:\WINDOWS\SWREG.exe
2010-06-05 11:34:46 ----A---- C:\WINDOWS\sed.exe
2010-06-05 11:34:46 ----A---- C:\WINDOWS\PEV.exe
2010-06-05 11:34:46 ----A---- C:\WINDOWS\grep.exe
2010-06-05 11:31:27 ----D---- C:\WINDOWS\pss
2010-06-05 11:18:10 ----SHD---- C:\WINDOWS\CSC
2010-06-05 10:37:24 ----A---- C:\Boot.bak
2010-06-05 10:37:20 ----RASHD---- C:\cmdcons
2010-06-05 10:33:27 ----D---- C:\WINDOWS\ERDNT
2010-06-05 10:33:14 ----D---- C:\Qoobox

======List of files/folders modified in the last 1 months======

2010-06-08 02:00:00 ----D---- C:\Program Files\Trend Micro
2010-06-08 01:57:30 ----RD---- C:\Program Files
2010-06-08 01:57:15 ----D---- C:\WINDOWS\system32
2010-06-08 01:44:42 ----D---- C:\WINDOWS\Prefetch
2010-06-08 01:44:41 ----D---- C:\WINDOWS\Debug
2010-06-08 01:42:37 ----D---- C:\WINDOWS\system32\drivers
2010-06-08 01:32:50 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-06-08 01:20:50 ----D---- C:\MDT
2010-06-08 00:12:54 ----D---- C:\WINDOWS
2010-06-08 00:12:53 ----A---- C:\WINDOWS\system.ini
2010-06-08 00:09:17 ----D---- C:\WINDOWS\AppPatch
2010-06-08 00:09:16 ----D---- C:\Program Files\Common Files
2010-06-08 00:03:08 ----D---- C:\WINDOWS\system32\CatRoot2
2010-06-07 23:58:47 ----SHD---- C:\System Volume Information
2010-06-07 23:58:47 ----D---- C:\WINDOWS\system32\Restore
2010-06-07 19:49:49 ----D---- C:\Program Files\Spybot - Search & Destroy
2010-06-07 19:45:54 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-07 19:45:13 ----SHD---- C:\WINDOWS\Installer
2010-06-07 19:42:02 ----D---- C:\WINDOWS\network diagnostic
2010-06-07 19:20:00 ----RSHD---- C:\WINDOWS\system32\dllcache
2010-06-07 19:02:10 ----D---- C:\Program Files\Google
2010-06-07 19:02:10 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2010-06-07 19:02:08 ----SD---- C:\WINDOWS\Tasks
2010-06-07 18:35:10 ----A---- C:\WINDOWS\win.ini
2010-06-07 18:14:53 ----D---- C:\Program Files\Enigma Software Group
2010-06-05 13:05:14 ----A---- C:\WINDOWS\TMP0001.TMP
2010-06-05 12:31:21 ----D---- C:\Program Files\Mozilla Firefox
2010-06-05 12:31:04 ----D---- C:\Program Files\Java
2010-06-05 12:30:37 ----D---- C:\Program Files\Common Files\Java
2010-06-05 12:29:16 ----D---- C:\WINDOWS\Minidump
2010-06-05 12:10:09 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-06-05 12:09:56 ----D---- C:\dell
2010-06-05 10:37:24 ----RASH---- C:\boot.ini
2010-06-05 10:04:14 ----HD---- C:\WINDOWS\inf
2010-06-02 20:22:22 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-06-02 20:09:33 ----D---- C:\Documents and Settings\David Schleifer\Application Data\Adobe
2010-05-20 20:58:15 ----D---- C:\Art Center

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 SAVRKBootTasks;Boot Tasks Driver; \??\C:\WINDOWS\system32\SAVRKBootTasks.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 KMW_KBD;Kensington Input Devices Class filter driver; C:\WINDOWS\System32\DRIVERS\KMW_KBD.sys [2006-08-03 5376]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2008-01-14 54016]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2008-01-14 22016]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
S1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 catchme;catchme; \??\C:\DOCUME~1\DAVIDS~1\LOCALS~1\Temp\catchme.sys []
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-01-14 4620288]
S3 KMW_SYS;Kensington MouseWorks Mouse filter driver; C:\WINDOWS\system32\DRIVERS\KMW_SYS.sys [2006-08-03 91648]
S3 KMW_USB;Kensington MouseWorks USB filter driver; C:\WINDOWS\system32\DRIVERS\KMW_USB.sys [2006-08-03 10112]
S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\10.tmp []
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-03-08 6288672]
S3 NVR0Dev;NVR0Dev; \??\C:\WINDOWS\nvoclock.sys []
S3 physX32;physX32; C:\WINDOWS\system32\DRIVERS\physX32.sys [2007-06-26 117888]
S3 SBRE;SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys []
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
S2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S2 nTuneService;Performance Service; C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe [2008-01-15 155648]
S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-03-08 163908]
S2 TabletService;TabletService; C:\WINDOWS\system32\Tablet.exe [2003-05-29 618496]
S2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S3 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-05-10 68096]
S3 ARHPJ;ARHPJ; C:\DOCUME~1\DAVIDS~1\LOCALS~1\Temp\ARHPJ.exe []
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 AVDTQUEHEG;AVDTQUEHEG; C:\DOCUME~1\DAVIDS~1\LOCALS~1\Temp\AVDTQUEHEG.exe []
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-21 545568]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-12-02 74384]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 XFII;XFII; C:\DOCUME~1\DAVIDS~1\LOCALS~1\Temp\XFII.exe [2010-06-08 445312]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

ComboFix 10-06-07.03 - David Schleifer 06/08/2010 2:13.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.2949 [GMT -5:00]
Running from: c:\documents and settings\David Schleifer\Desktop\Working\ComboFix.exe
Command switches used :: /killall
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

Infected copy of c:\windows\system32\drivers\kbdhid.sys was found and disinfected
Restored copy from - Kitty had a snack tongue.gif
.
((((((((((((((((((((((((( Files Created from 2010-05-08 to 2010-06-08 )))))))))))))))))))))))))))))))
.

2010-06-08 06:54 . 2010-06-08 06:54 -------- d-----w- C:\rsit
2010-06-08 06:36 . 2010-06-08 06:37 -------- d-----w- c:\program files\Nemesis Anti-Spyware
2010-06-08 02:52 . 2010-05-26 15:45 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
2010-06-08 01:44 . 2010-06-08 01:44 -------- d-----w- c:\program files\Sophos
2010-06-08 00:20 . 2010-06-08 00:20 578560 ----a-w- c:\windows\system32\dllcache\user32.dll
2010-06-08 00:10 . 2010-06-08 00:10 -------- d-----w- c:\windows\ERUNT
2010-06-08 00:06 . 2010-06-08 03:28 -------- d-----w- C:\SDFix
2010-06-05 17:10 . 2010-06-05 17:10 -------- d-----w- C:\NV38243472.TMP
2010-06-05 17:10 . 2010-06-05 17:10 -------- d-----w- C:\NV828172.TMP
2010-06-05 16:58 . 2010-06-05 16:58 -------- d-----w- c:\documents and settings\David Schleifer\Application Data\Malwarebytes
2010-06-05 16:58 . 2010-06-05 16:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-04 00:14 . 2010-06-04 00:14 503808 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7b4b76f7-n\msvcp71.dll
2010-06-04 00:14 . 2010-06-04 00:14 499712 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7b4b76f7-n\jmc.dll
2010-06-04 00:14 . 2010-06-04 00:14 348160 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-7b4b76f7-n\msvcr71.dll
2010-06-04 00:14 . 2010-06-04 00:14 61440 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3f8ccde3-n\decora-sse.dll
2010-06-04 00:14 . 2010-06-04 00:14 12800 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3f8ccde3-n\decora-d3d.dll
2010-06-02 22:47 . 2010-06-02 22:47 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-05-15 04:41 . 2010-05-15 04:41 503808 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5f433bce-n\msvcp71.dll
2010-05-15 04:41 . 2010-05-15 04:41 499712 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5f433bce-n\jmc.dll
2010-05-15 04:41 . 2010-05-15 04:41 348160 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5f433bce-n\msvcr71.dll
2010-05-15 04:41 . 2010-05-15 04:41 61440 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-76b9dda6-n\decora-sse.dll
2010-05-15 04:41 . 2010-05-15 04:41 12800 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-76b9dda6-n\decora-d3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-08 07:25 . 2008-05-10 12:43 320 ----a-w- c:\windows\system32\wacom.dat
2010-06-08 07:00 . 2008-05-02 02:19 -------- d-----w- c:\program files\Trend Micro
2010-06-08 06:57 . 2010-01-22 23:58 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-08 00:49 . 2008-05-08 23:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-08 00:45 . 2008-05-08 23:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-08 00:02 . 2008-05-02 02:23 -------- d-----w- c:\program files\Google
2010-06-07 23:14 . 2008-05-09 00:11 -------- d-----w- c:\program files\Enigma Software Group
2010-06-05 18:05 . 2008-05-14 23:19 7304 ----a-w- c:\windows\TMP0001.TMP
2010-06-05 17:31 . 2008-05-02 02:14 -------- d-----w- c:\program files\Java
2010-06-05 17:30 . 2008-05-02 02:14 -------- d-----w- c:\program files\Common Files\Java
2010-05-08 22:56 . 2010-05-08 22:56 61440 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-44e413b0-n\decora-sse.dll
2010-05-08 22:56 . 2010-05-08 22:56 12800 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-44e413b0-n\decora-d3d.dll
2010-04-12 22:29 . 2010-05-08 22:56 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-10 15:19 . 2010-04-10 15:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-03-27 17:29 . 2010-03-27 17:29 45080 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-20 21:42 . 2010-03-20 21:42 152576 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-03-20 21:42 . 2010-03-20 21:42 79488 ----a-w- c:\documents and settings\David Schleifer\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-06-05_15.56.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-08 07:25 . 2010-06-08 07:25 16384 c:\windows\temp\Perflib_Perfdata_4fc.dat
+ 2010-06-08 00:10 . 2010-06-08 00:10 225280 c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2010-06-08 00:10 . 2008-08-07 20:27 163328 c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2010-06-08 03:00 . 2010-06-08 03:00 225280 c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2010-06-08 00:10 . 2008-08-07 20:27 163328 c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2008-05-17 15:39 . 2010-04-30 16:51 32058312 c:\windows\system32\MRT.exe
+ 2010-06-08 00:10 . 2010-06-08 00:10 10559488 c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2010-06-08 03:00 . 2010-06-08 03:00 10559488 c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-01-15 106496]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-03-08 2937528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-08 13680640]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2007-10-26 184352]
"RTHDCPL"="RTHDCPL.EXE" [2008-01-15 16855552]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"EPSON Stylus C88 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 98304]
"kmw_run.exe"="kmw_run.exe" [2006-08-03 106496]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"nwiz"="nwiz.exe" [2009-03-08 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-08 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-5-10 113664]
TabUserW.exe.lnk - c:\windows\system32\Wtablet\TabUserW.exe [2003-5-29 77824]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Curious Labs\\Poser 6\\Poser.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Red Storm Entertainment\\RavenShield\\system\\ravenshield.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"c:\\Program Files\\Sierra Online\\Battlestar Galactica\\BSG.exe"=
"c:\\Program Files\\e frontier\\Poser 7\\Poser.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Activision\\Sfc3\\SFC3.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Turbine\\DDO Unlimited\\dndclient.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedIIGame.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\AssassinsCreedII.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed II\\UPlayBrowser.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56183:TCP"= 56183:TCP:Pando Media Booster
"56183:UDP"= 56183:UDP:Pando Media Booster

R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [6/7/2010 9:52 PM 18816]
R3 physX32;physX32;c:\windows\system32\drivers\physX32.sys [5/1/2008 9:00 PM 117888]
S3 ARHPJ;ARHPJ;c:\docume~1\DAVIDS~1\LOCALS~1\Temp\ARHPJ.exe --> c:\docume~1\DAVIDS~1\LOCALS~1\Temp\ARHPJ.exe [?]
S3 AVDTQUEHEG;AVDTQUEHEG;c:\docume~1\DAVIDS~1\LOCALS~1\Temp\AVDTQUEHEG.exe --> c:\docume~1\DAVIDS~1\LOCALS~1\Temp\AVDTQUEHEG.exe [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\10.tmp --> c:\windows\system32\10.tmp [?]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S3 XFII;XFII;c:\docume~1\DAVIDS~1\LOCALS~1\Temp\XFII.exe --> c:\docume~1\DAVIDS~1\LOCALS~1\Temp\XFII.exe [?]
.
Contents of the 'Scheduled Tasks' folder

2009-10-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-06-08 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-08 02:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x89557EC5]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ccf28
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> atapi.sys @ 0xb9eee852
IoDeviceObjectType -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9db2bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9dbfa21
SendHandler -> NDIS.sys @ 0xb9d9d87b
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\10.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2882316855-4176995488-1437449821-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:fd,f1,3e,82,33,82,e5,41,9f,f7,a4,8d,35,c6,c2,e8,0c,93,c2,b1,e9,85,45,
e8,79,0b,77,b2,90,98,2c,2d,3c,e4,42,6d,1f,d2,71,3c,81,b8,24,f8,1e,59,1f,73,\
"??"=hex:08,7b,9c,f9,17,d2,4e,00,ee,c4,52,ac,01,89,4a,29
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(764)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(4036)
c:\windows\system32\WININET.dll
c:\windows\system32\tabhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\Tablet.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\kmw_run.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-06-08 02:31:04 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-08 07:30
ComboFix2.txt 2010-06-08 05:15
ComboFix3.txt 2010-06-08 01:35
ComboFix4.txt 2010-06-07 23:54
ComboFix5.txt 2010-06-08 07:10

Pre-Run: 729,306,689,536 bytes free
Post-Run: 729,286,340,608 bytes free

- - End Of File - - DC13895EC108FF31D4AE4BB9CD976028

Edited by boopme, 08 June 2010 - 02:58 PM.


BC AdBot (Login to Remove)

 


#2 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:08:33 AM

Posted 11 June 2010 - 02:14 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE



Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#3 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:08:33 AM

Posted 15 June 2010 - 12:35 PM

Due to the lack of feedback, this topic is now closed.
If you need this topic reopened, please PM a staff member and we will reopen it for you (include the address of this thread in your request). This applies to the original topic starter only. Everyone else with similar problems, please start a new topic.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users