Here are the new logs
MBRCheck, version 1.2.3
© 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x0000000c
Kernel Drivers (total 159):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806FF000 \WINDOWS\system32\hal.dll
0xF79AB000 \WINDOWS\system32\KDCOM.DLL
0xF78BB000 \WINDOWS\system32\BOOTVID.dll
0xF745C000 ACPI.sys
0xF79AD000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF744B000 pci.sys
0xF74AB000 isapnp.sys
0xF78BF000 compbatt.sys
0xF78C3000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xF7A73000 pciide.sys
0xF772B000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF742D000 pcmcia.sys
0xF74BB000 MountMgr.sys
0xF740E000 ftdisk.sys
0xF79AF000 dmload.sys
0xF73E8000 dmio.sys
0xF7733000 PartMgr.sys
0xF78C7000 ACPIEC.sys
0xF7A74000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
0xF74CB000 VolSnap.sys
0xF73D0000 atapi.sys
0xF7312000 iaStor.sys
0xF74DB000 disk.sys
0xF74EB000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF72F2000 fltMgr.sys
0xF72E0000 sr.sys
0xF72CA000 DRVMCDB.SYS
0xF74FB000 PxHelp20.sys
0xF72B3000 KSecDD.sys
0xF729C000 WudfPf.sys
0xF720F000 Ntfs.sys
0xF71E2000 NDIS.sys
0xF71C6000 Apsx86.sys
0xF773B000 ApsHM86.sys
0xF7743000 risdptsk.sys
0xF750B000 ohci1394.sys
0xF751B000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xF71AB000 Mup.sys
0xF764B000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xF757B000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF5593000 \SystemRoot\system32\DRIVERS\igxpmp32.sys
0xF557F000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF553E000 \SystemRoot\system32\DRIVERS\e1e5132.sys
0xF784B000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF551A000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF7853000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF54F5000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF52DA000 \SystemRoot\system32\DRIVERS\NETw4x32.sys
0xF758B000 \SystemRoot\system32\DRIVERS\rimmptsk.sys
0xF52C6000 \SystemRoot\system32\DRIVERS\rimsptsk.sys
0xF5275000 \SystemRoot\system32\DRIVERS\rixdptsk.sys
0xF759B000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF785B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF5249000 \SystemRoot\system32\DRIVERS\SynTP.sys
0xF7A03000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF7863000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF786B000 \SystemRoot\system32\DRIVERS\atmeltpm.sys
0xF7993000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0xF7997000 \SystemRoot\system32\DRIVERS\ibmpmdrv.sys
0xF75AB000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF7A0B000 \SystemRoot\System32\Drivers\DLACDBHM.SYS
0xF75BB000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF75CB000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF5226000 \SystemRoot\system32\DRIVERS\ks.sys
0xF79A3000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0xF7873000 \SystemRoot\system32\DRIVERS\tvtpktfilter.sys
0xF7B73000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF75DB000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF7187000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF520F000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF75EB000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF75FB000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF787B000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF51FE000 \SystemRoot\system32\DRIVERS\psched.sys
0xF5E83000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7883000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF788B000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF51CD000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF5E73000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7893000 \SystemRoot\system32\DRIVERS\psadd.sys
0xF789B000 \SystemRoot\system32\DRIVERS\Tvti2c.sys
0xF7A0D000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF5174000 \SystemRoot\system32\DRIVERS\update.sys
0xF716F000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF5E43000 \SystemRoot\system32\DRIVERS\zumbus.sys
0xF5E33000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
0xF5103000 \SystemRoot\System32\Drivers\wdf01000.sys
0xF5E13000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA6C8B000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xA5C56000 \SystemRoot\system32\drivers\ADIHdAud.sys
0xA5C34000 \SystemRoot\system32\drivers\portcls.sys
0xA69E4000 \SystemRoot\system32\drivers\drmk.sys
0xA5B7C000 \SystemRoot\system32\drivers\AEAudio.sys
0xA5B48000 \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
0xA5A56000 \SystemRoot\system32\DRIVERS\HSF_DPV.sys
0xA59A3000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
0xA9167000 \SystemRoot\System32\Drivers\Modem.SYS
0xF79B3000 \SystemRoot\System32\Drivers\i2omgmt.SYS
0xF79B5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xA6EBA000 \SystemRoot\System32\Drivers\Null.SYS
0xF79B7000 \SystemRoot\System32\Drivers\Beep.SYS
0xA9157000 \SystemRoot\System32\Drivers\DLARTL_N.SYS
0xA7D45000 \SystemRoot\System32\drivers\vga.sys
0xF79B9000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79BB000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xA7D3D000 \SystemRoot\System32\Drivers\Msfs.SYS
0xA7D35000 \SystemRoot\System32\Drivers\Npfs.SYS
0xA9AA9000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xA58E4000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xA588B000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xA5863000 \SystemRoot\system32\DRIVERS\netbt.sys
0xA5842000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xA5820000 \SystemRoot\System32\drivers\afd.sys
0xA69A4000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xA6994000 \SystemRoot\system32\DRIVERS\netbios.sys
0xA6964000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xA7D2D000 \SystemRoot\System32\drivers\TSMAPIP.SYS
0xA7D25000 \SystemRoot\System32\drivers\Tppwrif.sys
0xA7D1D000 \SystemRoot\system32\DRIVERS\TPHKDRV.sys
0xA57D5000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xA6954000 \??\C:\WINDOWS\system32\drivers\oreans32.sys
0xA573E000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF79BD000 \??\C:\WINDOWS\system32\Drivers\IBMBLDID.sys
0xA630F000 \SystemRoot\System32\Drivers\Fips.SYS
0xA86AB000 \SystemRoot\System32\drivers\ANC.SYS
0x9D42A000 \SystemRoot\System32\Drivers\Cdfs.SYS
0x9BC54000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0x9C2E7000 \SystemRoot\System32\drivers\Dxapi.sys
0x9C577000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xA54B6000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF024000 \SystemRoot\System32\igxpgd32.dll
0xBF012000 \SystemRoot\System32\igxprd32.dll
0xBF04E000 \SystemRoot\System32\igxpdv32.DLL
0xBF1D8000 \SystemRoot\System32\igxpdx32.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xF68C1000 \SystemRoot\system32\DRIVERS\tvtfilter.sys
0xF68B1000 \SystemRoot\System32\Drivers\DRVNDDM.SYS
0xF7AEE000 \SystemRoot\System32\DLA\DLADResN.SYS
0x9BC3E000 \SystemRoot\System32\DLA\DLAIFS_M.SYS
0xF5B0B000 \SystemRoot\System32\DLA\DLAOPIOM.SYS
0x9D778000 \SystemRoot\System32\DLA\DLAPoolM.SYS
0x9C54F000 \SystemRoot\System32\DLA\DLABOIOM.SYS
0x9BC26000 \SystemRoot\System32\DLA\DLAUDFAM.SYS
0x9BC10000 \SystemRoot\System32\DLA\DLAUDF_M.SYS
0x9C108000 \SystemRoot\system32\DRIVERS\AegisP.sys
0xA1457000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x9DBB5000 \SystemRoot\system32\DRIVERS\s24trans.sys
0x9BB6C000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0x9C0D8000 \SystemRoot\system32\DRIVERS\PROCDD.SYS
0x9BADB000 \SystemRoot\System32\Drivers\HTTP.sys
0x9BB34000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
0xA45DB000 \??\C:\WINDOWS\System32\drivers\pmemnt.sys
0x9BA0C000 \SystemRoot\system32\DRIVERS\srv.sys
0x9B92F000 \SystemRoot\system32\drivers\wdmaud.sys
0x9D44A000 \SystemRoot\system32\drivers\sysaudio.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 80):
0 System Idle Process
4 System
1344 C:\WINDOWS\system32\smss.exe
1396 csrss.exe
1420 C:\WINDOWS\system32\winlogon.exe
1464 C:\WINDOWS\system32\services.exe
1476 C:\WINDOWS\system32\lsass.exe
1672 C:\WINDOWS\system32\ibmpmsvc.exe
1700 C:\WINDOWS\system32\svchost.exe
1788 svchost.exe
1984 C:\WINDOWS\system32\svchost.exe
2024 C:\WINDOWS\system32\svchost.exe
356 C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
556 svchost.exe
760 svchost.exe
772 C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
1308 C:\WINDOWS\system32\spoolsv.exe
1480 svchost.exe
1772 C:\WINDOWS\system32\IPSSVC.EXE
1836 C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
1912 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
2008 C:\WINDOWS\system32\svchost.exe
2036 C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
408 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
748 C:\WINDOWS\system32\svchost.exe
920 C:\Program Files\Lenovo\System Update\SUService.exe
1100 C:\WINDOWS\explorer.exe
1896 C:\WINDOWS\system32\svchost.exe
1840 C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
2060 C:\WINDOWS\system32\TPHDEXLG.exe
2388 C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
2432 C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
2464 C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
2488 C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe
2528 C:\WINDOWS\system32\ZuneBusEnum.exe
2620 C:\WINDOWS\system32\wuauclt.exe
2636 C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
2824 wmpnetwk.exe
2832 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
3092 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3164 C:\WINDOWS\system32\rundll32.exe
3220 C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe
3240 C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
3256 C:\WINDOWS\system32\TpShocks.exe
3268 C:\PROGRA~1\ThinkPad\UTILIT~1\EZEJMNAP.EXE
3340 C:\Program Files\Analog Devices\Core\smax4pnp.exe
3380 C:\WINDOWS\system32\hkcmd.exe
3396 C:\WINDOWS\system32\igfxpers.exe
3476 C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
3496 C:\WINDOWS\system32\DLA\DLACTRLW.EXE
3508 C:\Program Files\Common Files\Lenovo\Logger\logmon.exe
3516 C:\Program Files\Common Files\Installshield\UpdateService\issch.exe
3684 C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.EXE
3768 C:\Program Files\ThinkVantage\AMSG\Amsg.exe
3832 C:\WINDOWS\system32\igfxsrvc.exe
3844 C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
3852 C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
3928 C:\WINDOWS\system32\svchost.exe
456 C:\Program Files\Zune\ZuneLauncher.exe
852 C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
1316 C:\Program Files\Windows Media Player\wmpnscfg.exe
932 wmiprvse.exe
1000 C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
536 C:\Program Files\RocketDock\RocketDock.exe
388 alg.exe
1168 C:\Program Files\Pando Networks\Media Booster\PMB.exe
1176 C:\Program Files\Lenovo\ZOOM\TpScrex.exe
1244 C:\WINDOWS\system32\ctfmon.exe
2240 C:\Program Files\Digital Line Detect\DLG.exe
2700 C:\Program Files\Rainmeter\Rainmeter.exe
3124 C:\Program Files\OpenOffice.org 3\program\soffice.exe
3444 C:\Program Files\OpenOffice.org 3\program\soffice.bin
4004 C:\Program Files\Styler\Styler.exe
2988 C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
3044 C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
1096 C:\WINDOWS\system32\notepad.exe
2776 iexplore.exe
876 C:\Program Files\Internet Explorer\iexplore.exe
3052 C:\Program Files\Internet Explorer\iexplore.exe
1080 C:\Documents and Settings\Mike\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: HITACHIHTS541612J9SA00, Rev: SBDIC7JP
Size Device Name MBR Status
--------------------------------------------
111 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!
SHA1: 680C3DFB3AF5C02B7E098CA7B25CA73D63745DC5
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
ComboFix 10-08-02.01 - Mike 08/02/2010 18:51:44.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.982.510 [GMT -4:00]
Running from: c:\documents and settings\Mike\My Documents\Apps\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Mike\Recent\Thumbs.db
.
MBR is infected with the Whistler Bootkit !!
((((((((((((((((((((((((( Files Created from 2010-07-02 to 2010-08-02 )))))))))))))))))))))))))))))))
.
2010-07-22 19:45 . 2010-08-02 04:16 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2010-07-13 20:04 . 2010-06-14 14:30 743936 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-11 03:10 . 2010-07-11 03:10 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-07-11 03:02 . 2010-07-11 03:02 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2010-07-11 01:27 . 2010-07-11 01:27 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2010-07-11 01:17 . 2010-07-11 01:17 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
2010-07-09 18:30 . 2010-07-09 18:30 -------- d-----w- c:\documents and settings\Mike\Local Settings\Application Data\Help
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-02 21:51 . 2010-03-26 01:01 1 ----a-w- c:\documents and settings\Mike\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-07-27 23:09 . 2010-01-30 20:05 -------- d-----w- c:\program files\Bizarro
2010-07-23 17:46 . 2010-02-19 17:53 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-07-20 01:48 . 2010-02-27 20:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-16 21:18 . 2009-12-29 04:56 -------- d-----w- c:\program files\Common Files\Java
2010-07-09 18:30 . 2009-12-31 02:20 -------- d-----w- c:\program files\CDisplay
2010-07-08 22:16 . 2010-01-16 18:35 -------- d-----w- c:\documents and settings\Mike\Application Data\uTorrent
2010-07-01 03:34 . 2010-06-11 05:13 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-14 14:30 . 2006-04-30 07:10 743936 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-05-23 18:35 . 2010-05-23 18:35 503808 ----a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1f5122f8-n\msvcp71.dll
2010-05-23 18:35 . 2010-05-23 18:35 499712 ----a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1f5122f8-n\jmc.dll
2010-05-23 18:35 . 2010-05-23 18:35 348160 ----a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1f5122f8-n\msvcr71.dll
2010-05-23 18:35 . 2010-05-23 18:35 61440 ----a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6323bfff-n\decora-sse.dll
2010-05-23 18:35 . 2010-05-23 18:35 12800 ----a-w- c:\documents and settings\Mike\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6323bfff-n\decora-d3d.dll
2010-05-15 17:39 . 2009-12-29 04:34 450896 ----a-w- c:\documents and settings\Mike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-14 02:23 . 2010-05-14 02:37 17680 ----a-w- c:\windows\Fonts\PAGAP___.FON
2010-05-06 10:41 . 2006-04-30 06:56 916480 ----a-w- c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-07-11_03.20.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-26 00:48 . 2005-11-10 19:27 49250 c:\windows\system32\javaw.exe
+ 2010-03-26 00:48 . 2005-11-10 19:27 49248 c:\windows\system32\java.exe
- 2010-02-27 20:53 . 2010-01-07 21:07 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2010-02-27 20:53 . 2010-04-29 19:39 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2010-02-27 20:53 . 2010-04-29 19:39 20952 c:\windows\system32\drivers\mbam.sys
- 2010-07-11 01:27 . 2010-07-11 03:06 16384 c:\windows\system32\config\systemprofile\PrivacIE\index.dat
+ 2010-07-11 01:27 . 2010-07-27 03:35 16384 c:\windows\system32\config\systemprofile\PrivacIE\index.dat
- 2009-12-29 05:14 . 2010-07-11 03:19 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-29 05:14 . 2010-08-02 22:43 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-29 05:14 . 2010-07-11 03:19 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-12-29 05:14 . 2010-08-02 22:43 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-12-29 05:24 . 2010-07-11 03:06 32768 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
+ 2009-12-29 05:24 . 2010-07-27 03:35 32768 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
+ 2009-12-29 05:14 . 2010-08-02 22:43 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-12-29 05:14 . 2010-07-11 03:19 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-07-27 03:35 . 2010-07-27 03:35 7680 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{FD66AC26-992F-11DF-B643-0013E852B687}.dat
+ 2010-07-27 03:35 . 2010-07-27 03:35 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FD66AC29-992F-11DF-B643-0013E852B687}.dat
+ 2010-07-27 03:35 . 2010-07-27 03:35 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{FD66AC27-992F-11DF-B643-0013E852B687}.dat
+ 2010-07-27 03:35 . 2010-07-27 03:35 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0574FE4D-9930-11DF-B643-0013E852B687}.dat
+ 2010-07-27 03:35 . 2010-07-27 03:35 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0574FE4C-9930-11DF-B643-0013E852B687}.dat
+ 2010-07-27 03:35 . 2010-07-27 03:35 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0574FE4B-9930-11DF-B643-0013E852B687}.dat
+ 2010-07-27 03:35 . 2010-07-27 03:35 4608 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{0574FE3C-9930-11DF-B643-0013E852B687}.dat
+ 2010-03-26 00:48 . 2005-11-10 21:03 127078 c:\windows\system32\javaws.exe
+ 2010-01-01 00:58 . 2010-07-02 19:39 34045896 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-04-11 2937528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 512000]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2007-06-17 200704]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2007-06-17 208896]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-04-09 58416]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2007-03-09 66176]
"TpShocks"="TpShocks.exe" [2007-03-30 181808]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-03-28 243248]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-04-09 1015808]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-02-26 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-02-26 155648]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-02-26 131072]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-02-08 536576]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-28 81920]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2007-03-22 120368]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 419376]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-05-17 413696]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-05-17 126976]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2004-07-28 221184]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-01-07 158448]
c:\documents and settings\Mike\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
Styler.lnk - c:\documents and settings\Mike\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2010-1-23 15086]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-12-29 50688]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2009-11-1 119296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 07:37 34344 ----a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-12-14 02:06 28672 ----a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bizarro\\DCPlusPlus.exe"=
"c:\\Program Files\\Digsby\\lib\\digsby-app.exe"=
"c:\\Program Files\\MediaMonkey\\MediaMonkey.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Nexon\\Combat Arms\\Engine.exe"=
"c:\\Program Files\\Beat Hazard\\BeatHazard.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56199:TCP"= 56199:TCP:Pando Media Booster
"56199:UDP"= 56199:UDP:Pando Media Booster
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [3/2/2007 9:47 PM 19760]
R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [4/17/2010 4:43 PM 33824]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2/8/2007 5:11 PM 569344]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [10/9/2009 9:07 AM 493248]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [9/13/2006 4:42 PM 35264]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/18/2010 2:22 PM 716272]
.
Contents of the 'Scheduled Tasks' folder
2010-08-02 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-12-29 16:16]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://lenovo.live.com
uInternet Settings,ProxyServer = http=127.0.0.1:5577
uInternet Settings,ProxyOverride = <local>
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\d5whm8nf.default\
FF - prefs.js: browser.startup.homepage - hxxp://scoute.org/blog/?p=238#more-238
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-02 18:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,1c,80,73,f0,0b,8b,0e,45,88,4d,d1,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,1c,80,73,f0,0b,8b,0e,45,88,4d,d1,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1420)
c:\program files\Lenovo\HOTKEY\tphklock.dll
.
Completion time: 2010-08-02 19:00:16
ComboFix-quarantined-files.txt 2010-08-02 23:00
ComboFix2.txt 2010-07-11 03:25
Pre-Run: 17,703,612,416 bytes free
Post-Run: 18,193,735,680 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - E2F39F9C1723419B492B93C5C4DCD540
It's weird, because when combofix had finished running, and was preparing a log report, a window opened up asking me if I wanted to make Internetexplorer my default browser, which it isn't. Also, I now have a IE icon on my desktop, the problems with the muting and clicking still exist though.