mbam chin09 rootkit

View previous topic View next topic Go down

mbam chin09 rootkit

Post by Jaber93031 on 23rd January 2010, 9:36 pm

Hi
Having a rough time here
Thanks in advance for any help you can give.
Y'all are doing a good thing here

Acrobat.com
Acrobat.com
Ad-aware 6 Professional
Adobe Acrobat 5.0
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Adobe Shockwave Player 11.5
America Online
Apple Mobile Device Support
Apple Software Update
Belkin F5D8073 N Wireless ExpressCard Adapter
Bonjour
Critical Update for Windows Media Player 11 (KB959772)
Dell ResourceCD
Easy CD Creator 5 Basic
ffdshow [rev 3026] [2009-07-05]
File Shredder 2.0
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows Media Format SDK (KB910998)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Image Zone 3.5
HP Imaging Device Functions 6.1
hp officejet 4200 series
HP Photosmart Essential
HP PSC & OfficeJet 3.5
HP PSC & OfficeJet 6.1.A
HP Software Update
HP Solution Center and Imaging Support Tools 6.1
HP Update
ImageMixer VCD2
iTunes
Java DB 10.5.3.0
Java(TM) 6 Update 18
Java(TM) 6 Update 5
Java(TM) SE Development Kit 6 Update 18
K-Lite Codec Pack 4.6.2 (Basic)
Logitech MouseWare 9.79.1
Macromedia Flash Player
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Learning and Research Plus Support Files
Microsoft National Language Support Downlevel APIs
Microsoft Picture It! Express 7.0
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works 6.0
Microsoft Works and Money 2001 Setup Launcher
Mozilla Firefox (3.6)
MSN Toolbar
MSN Toolbar(01.02.3000.1001)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Netscape (7.01)
Netscape Communicator 4.51
Nokia Connectivity Adapter Cable DKU-5
NotePadSync
OpenMG Limited Patch 4.1-05-13-31-01
OpenMG Secure Module 4.1.00
QuickTime
RealArcade
RealPlayer Basic
SAMSUNG Mobile Modem Driver Set
SBC Self Support Tool
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Shockwave
SonicStage 3.0
Sony USB Driver
Uniblue RegistryBooster 2009
Uniblue RegistryBooster 2009
Uniblue SpeedUpMyPC 2009
Uniblue SpeedUpMyPC 2009
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB973874)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.762
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Visual IP InSight(SBC)
VLC media player 1.0.3
Windows Genuine Advantage v1.3.0254.0
Windows Internet Explorer 8
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows XP Service Pack 3
WinRAR archiver
Word Riot Deluxe
WordPerfect Office 2002
WordPerfect Office 2002

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Belahzur on 23rd January 2010, 11:34 pm

Hello.
Can you post a normal Hijack This scan log please?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

hijack this log

Post by Jaber93031 on 24th January 2010, 1:13 am

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 5:10:26 PM, on 1/23/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\GtDetectSc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\dwwin.exe

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [UniblueSpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\Launcher.exe -minimize
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - Winlogon Notify: efbeaeaedc - C:\WINDOWS\system32\efbeaeaedc.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GT Detect (GtDetectSc) - OptionNV - C:\WINDOWS\system32\GtDetectSc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - C:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 4031 bytes

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Belahzur on 24th January 2010, 1:16 am

Hello.
Have you removed some components of Mcafee? also, you machine has a flash drive infection, and your external hardware is likely infected, have you plugged any external hardware (USB device items) into the machine recently?

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O20 - Winlogon Notify: efbeaeaedc - C:\WINDOWS\system32\efbeaeaedc.dll



  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 24th January 2010, 2:14 am

Hi
Yes I have tried to remove Mcafee lately.
If I need to reload it I have the CD
I used a flash drive to set up my home network and got a message that said adaware was blocking a harmful program m.exe
When I tried to format the flash drive there was a program that would not delete still on it
I will follow your instructions and post the mbam log
Thanks

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 25th January 2010, 8:15 pm

mbam refuses to launch
double click on setup icon on desktop
cursor gets a timer then stops doing anything

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 11:56:04 AM, on 1/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\GtDetectSc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\dwwin.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Documents and Settings\Charlene Johnson\Desktop\mbam-setup.exe
C:\Documents and Settings\Charlene Johnson\Desktop\mbam-setup.exe
C:\Documents and Settings\Charlene Johnson\Desktop\mbam-setup.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [UniblueSpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\Launcher.exe -minimize
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GT Detect (GtDetectSc) - OptionNV - C:\WINDOWS\system32\GtDetectSc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - C:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 3967 bytes

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Belahzur on 25th January 2010, 9:39 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 26th January 2010, 8:46 pm

ComboFix 10-01-26.01 - Charlene Johnson 01/26/2010 11:53:17.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.181 [GMT -8:00]
Running from: c:\documents and settings\Charlene Johnson\Desktop\Virus Tools\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Charlene Johnson\Local Settings\Application Data\DoubleD
c:\documents and settings\Charlene Johnson\Local Settings\Application Data\DoubleD\GamingHarbor Toolbar\4.2.0.21210\bin\stbup.exe
c:\documents and settings\Charlene\Local Settings\Temporary Internet Files\temp.dmf
c:\documents and settings\Charlene\Local Settings\Temporary Internet Files\Tvm.log
C:\ErrLog.txt
C:\log.udt
c:\progra~1\COMMON~1\{18B5B~1
c:\program files\Common Files\smc.exe
c:\program files\Internet Explorer\SET5.tmp
c:\program files\Internet Explorer\SETA.tmp
C:\setup.exe
c:\windows\1247744B34D5A4E5212B75143C3BBD4.exe
c:\windows\176B499AFA201281B353C9D6A19D497.exe
c:\windows\1A34A905344A9B28EA6F0C61F78E27.exe
c:\windows\1D0279277C1D2E0596D8DF6919FF70.exe
c:\windows\22C6CDA46534AAB7F9C8D1A0188D4B.exe
c:\windows\26BBDDDDBAA266995E248B1F3AC3D5C.exe
c:\windows\286088FBE6AE8A3633C8270FB4E747.exe
c:\windows\2BEEDAB749B527F3E2B9E8DDE1BF6549.exe
c:\windows\3466078985CEC703FC9B14DC2CBD.exe
c:\windows\35D8807F2CDF1D85309181D8EBC5B96E.exe
c:\windows\38CC4259749A31F4AB9EFB47995AA53.exe
c:\windows\3AA49A6D79FC1BCE265C819A37983291.exe
c:\windows\4170D691C84A21D7834F087AACE4B5D.exe
c:\windows\42E49F78CB681B17189F935C13A93.exe
c:\windows\478853E2A343633B34E67117F47A6C.exe
c:\windows\49893F4AC3C32DD54CB473D4D6BB7EF.exe
c:\windows\49D61C4A77C6F978CD5E1EEC3DBD5DA.exe
c:\windows\4D99B5611D7FCCD24DD26FA991ED2AF.exe
c:\windows\558A2EB275E277335E48A3DEBEB5E.exe
c:\windows\55D345ABBEA8FB74743F2987FF562E2.exe
c:\windows\57E313204F8F7A4DBF14D179450C4.exe
c:\windows\5B6A1154FDD5476B2BD1F3AF2E72E65D.exe
c:\windows\6471CC922C27C523A449531C94AF82A7.exe
c:\windows\6AB789F7C39578142E58292837AABBEE.exe
c:\windows\6F62CABEAE126EAD3824436D517337.exe
c:\windows\72BD01873702CA73DBE2A416DD373.exe
c:\windows\76DC0D62224BAD7B15E4F57078E42.exe
c:\windows\7AB1AE11C8A8E4863A3F162A6D3616C5.exe
c:\windows\7BF1C08F20771B85B6D964E25B176C74.exe
c:\windows\7C3BFD89B5140C7D6C0568A2D7E18F2.exe
c:\windows\84A1FCB01CF9897B5676822B35211DE.exe
c:\windows\911A1E91A2C5881945C499569EE0785D.exe
c:\windows\92B8B4B4B67FFAB134742C51A4718C6.exe
c:\windows\944FC776187BB921AB47E97DA83361C.exe
c:\windows\946E69B31807CAABCF020BFBFC827C.exe
c:\windows\9AA3B9B726332678633A6B7EEAD5A61.exe
c:\windows\9FB4E4FDC6BF9F4547BCB4C8993F5DF.exe
c:\windows\cdmxtras
c:\windows\patch.exe
c:\windows\Readme.txt
c:\windows\system32\_000021_.tmp.dll
c:\windows\system32\_000022_.tmp.dll
c:\windows\system32\_000023_.tmp.dll
c:\windows\system32\_000024_.tmp.dll
c:\windows\system32\2fbc8e01ad857778e619146aeb056f8a.exe
c:\windows\system32\932e7b970fdae9ddd8c62578244fa986.exe
c:\windows\system32\crosof~1.net
c:\windows\system32\drivers\H8SRTesixlllnmw.sys
c:\windows\system32\fnts~1
c:\windows\system32\fnts~1\regedit.exe
c:\windows\system32\H8SRTjedpjbhwer.dll
c:\windows\system32\H8SRTjqqwbeycfx.dll
c:\windows\system32\h8srtkrl32mainweq.dll
c:\windows\system32\H8SRTrlitexnopt.dat
c:\windows\system32\H8SRTrrisrrmowy.dll
c:\windows\system32\krl32mainweq.dll
c:\windows\system32\model.dat
c:\windows\system32\srcr.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
-------\Legacy_NNSERV
-------\Service_NNServ


((((((((((((((((((((((((( Files Created from 2009-12-26 to 2010-01-26 )))))))))))))))))))))))))))))))
.

2010-01-26 09:45 . 2010-01-26 10:02 -------- d-----w- C:\Combo-Fix14529C
2010-01-26 09:43 . 2010-01-26 09:44 -------- d-----w- C:\Combo-Fix
2010-01-26 09:43 . 2010-01-26 09:42 389120 ----a-w- c:\windows\system32\CF29328.exe
2010-01-26 09:41 . 2010-01-26 09:41 389120 ----a-w- c:\windows\system32\CF29090.exe
2010-01-26 09:27 . 2010-01-26 09:27 -------- d-----w- C:\VundoFix Backups
2010-01-26 04:33 . 2010-01-26 04:33 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-26 04:06 . 2010-01-26 04:06 -------- d-----w- c:\program files\Simple Port Forwarding
2010-01-26 04:06 . 2010-01-26 04:06 -------- d-----w- c:\windows\Simple Port Forwarding
2010-01-26 03:17 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-26 03:17 . 2010-01-26 03:18 -------- d-----w- c:\program files\Innocent
2010-01-26 03:17 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-26 01:37 . 2010-01-26 01:37 162320 ----a-w- c:\windows\B9448128476A724E84D3E7B5BEEACC.exe
2010-01-25 19:02 . 2010-01-25 19:02 162320 ----a-w- c:\windows\B5BC938E5347A8AE33E607DC21436F8.exe
2010-01-25 09:06 . 2010-01-25 09:06 162320 ----a-w- c:\windows\F03D3497C294A4C2E760CD286D7245F0.exe
2010-01-24 16:38 . 2010-01-24 16:38 162320 ----a-w- c:\windows\B37457BBC857A75B9FDD1CDA98C96B3.exe
2010-01-24 12:05 . 2010-01-24 12:05 162320 ----a-w- c:\windows\D41B63992E26C9F81E1C2818BDACE2.exe
2010-01-24 08:55 . 2010-01-24 08:55 162320 ----a-w- c:\windows\F9C69851E1DD6E36391765A625E0D1.exe
2010-01-24 05:02 . 2010-01-24 05:02 162320 ----a-w- c:\windows\A1468B7618A234D674445C2CF6D97CFE.exe
2010-01-24 04:25 . 2010-01-24 04:25 162320 ----a-w- c:\windows\FBC9E8C8B596289A8AA582482D9BC379.exe
2010-01-24 02:53 . 2010-01-24 04:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-23 21:26 . 2010-01-23 21:26 -------- d-----w- c:\program files\TrendMicro
2010-01-23 20:46 . 2010-01-23 20:46 -------- d-----w- c:\program files\Sun
2010-01-23 20:45 . 2010-01-23 20:44 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-23 07:01 . 2010-01-23 07:01 162320 ----a-w- c:\windows\C430DB11402B9E7A5B8F8D5FDC4FFAD5.exe
2010-01-23 01:43 . 2010-01-23 01:43 162320 ----a-w- c:\windows\E6B4AD1BDF0F2ADFAFC511116EF8E.exe
2010-01-22 23:12 . 2010-01-26 04:35 -------- d-----w- c:\program files\Lavasoft
2010-01-22 16:47 . 2010-01-22 16:47 162320 ----a-w- c:\windows\BD4AFC3418AD5B66E06E16E9564DEDCA.exe
2010-01-22 16:04 . 2010-01-22 16:04 162320 ----a-w- c:\windows\D41028563785B5242BAC4723CE28C38.exe
2010-01-22 08:17 . 2010-01-22 08:17 162320 ----a-w- c:\windows\D32EEA40AF6B237495B3DBF224C92641.exe
2010-01-22 08:11 . 2010-01-23 04:23 131112 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-22 07:37 . 2010-01-22 07:37 162320 ----a-w- c:\windows\F63684EFA3EDF931A22A9AC83DA4CC.exe
2010-01-22 06:50 . 2010-01-22 06:50 162320 ----a-w- c:\windows\FDD5FE215276B285EBA47F668987B1D.exe
2010-01-22 03:27 . 2010-01-22 03:27 162320 ----a-w- c:\windows\B29686088DD78FA65AB22BB68787533.exe
2010-01-22 01:22 . 2010-01-22 01:22 162320 ----a-w- c:\windows\CBE77B731C91D4134A23C3C4F7FD85.exe
2010-01-22 01:20 . 2010-01-22 01:20 -------- d-----w- c:\documents and settings\Charlene Johnson\ErrorLogs
2010-01-22 00:47 . 2010-01-22 00:48 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2010-01-22 00:18 . 2010-01-22 00:18 162320 ----a-w- c:\windows\BB8CDB5E81831AE2E25022C452471FCA.exe
2010-01-22 00:07 . 2010-01-22 00:07 -------- d-----w- c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2010-01-21 23:30 . 2010-01-21 23:30 162320 ----a-w- c:\windows\D3748B1C4E895BA537593F34E5B18EED.exe
2010-01-21 22:28 . 2010-01-21 22:28 162320 ----a-w- c:\windows\A5523DD98CF4B99AD1FA99FC76DF6B.exe
2010-01-21 21:30 . 2010-01-21 21:30 162320 ----a-w- c:\windows\A55631D398DC27EFDAF61E59F028641E.exe
2010-01-21 20:49 . 2010-01-21 20:49 162320 ----a-w- c:\windows\EA167ECEFE66FF88AFD3AD3E8AAE1EB.exe
2010-01-21 20:20 . 2010-01-21 20:21 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2010-01-21 19:08 . 2010-01-22 00:51 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\Uniblue
2010-01-21 18:01 . 2010-01-21 18:01 162320 ----a-w- c:\windows\B44781D64668721B3F52B8D6B8F2CFBC.exe
2010-01-21 17:21 . 2010-01-21 17:21 162320 ----a-w- c:\windows\EAA510C34D27FD3DD923679775271663.exe
2010-01-21 05:57 . 2010-01-21 05:57 162320 ----a-w- c:\windows\AC216EF6A70D98BB6FC43C44B1FE4C.exe
2010-01-21 03:59 . 2010-01-21 03:59 162320 ----a-w- c:\windows\D91B2613DDE697CCF99D1B38843322C.exe
2010-01-20 22:37 . 2010-01-20 22:37 162320 ----a-w- c:\windows\B58466B63654A7709FC75A2E863889.exe
2010-01-20 20:59 . 2010-01-20 20:59 282640 ----a-w- c:\windows\system32\a62919e691a57a38c247a68b23625674.exe
2010-01-20 20:55 . 2010-01-26 16:59 116224 ------w- c:\windows\system32\efbeaeaedc.dll
2010-01-20 20:55 . 2010-01-20 20:55 162320 ----a-w- c:\windows\EA2F303BACD49614ADAAB172E8D56D9.exe
2010-01-20 19:01 . 2010-01-20 19:01 162320 ----a-w- c:\windows\B1E7B8E994BE2BBEDA51FD3DE4FF60.exe
2010-01-18 17:17 . 2010-01-18 17:17 696832 ----a-w- c:\windows\is-C56IE.exe
2010-01-18 17:17 . 2010-01-18 17:17 696832 ----a-w- c:\windows\is-VE2HE.exe
2010-01-18 17:16 . 2010-01-18 17:16 696832 ----a-w- c:\windows\is-HT9V6.exe
2010-01-18 17:13 . 2010-01-18 17:13 696832 ----a-w- c:\windows\is-A6MQ2.exe
2010-01-18 02:04 . 2010-01-18 02:04 -------- d-----w- c:\documents and settings\Charlene Johnson\Local Settings\Application Data\Threat Expert
2010-01-18 01:43 . 2010-01-20 05:12 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-17 21:53 . 2010-01-17 21:55 -------- d-----w- C:\WINSSLog
2010-01-17 21:46 . 2010-01-17 21:55 -------- d-----w- C:\9738c56b1665e4eb2f2ea99250feb77b
2010-01-17 16:02 . 2010-01-17 16:02 -------- d-----w- C:\aa7be623a5b666aa7a28a1
2010-01-17 06:32 . 2010-01-17 06:32 -------- d-----w- C:\f1d816dfd744640e0962
2010-01-17 06:19 . 2010-01-17 06:19 -------- d-----w- C:\9f49b76490a8dca6c059e7f9b723184f
2010-01-16 00:43 . 2010-01-16 00:43 -------- d-----w- c:\program files\Google
2010-01-14 21:15 . 2005-01-17 20:30 70619374 ----a-w- C:\KB888111_Supported_OS_All_Languages.zip
2010-01-13 21:09 . 2010-01-13 22:51 -------- d---a-w- C:\3590F75ABA9E485486C100C1A9D4FF06ZZ..ZZ.ZZZ....ZZ
2010-01-12 23:13 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 21:35 . 2010-01-12 21:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-10 05:04 . 2010-01-21 23:34 -------- d-----w- c:\program files\Yahoo!
2010-01-08 21:28 . 2010-01-08 21:28 -------- d-----w- c:\program files\File Shredder
2010-01-05 04:08 . 2010-01-05 04:08 -------- d-----w- C:\07fa843b86f7f83f1860d93996a1fa9c
2010-01-05 02:42 . 2010-01-05 03:01 -------- d-----w- C:\230a824188e94d8b0d554376
2010-01-04 04:22 . 2010-01-04 04:22 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee.com Personal Firewall
2010-01-04 04:22 . 2010-01-04 04:24 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\McAfee.com Personal Firewall
2010-01-04 03:59 . 2005-08-17 00:18 80640 ----a-w- c:\windows\system32\drivers\MpFirewall.sys
2010-01-04 03:59 . 2005-08-17 00:13 9216 ----a-w- c:\windows\system32\MpfApi.dll
2010-01-04 03:59 . 2010-01-04 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2010-01-04 03:46 . 2005-08-10 19:22 114464 ----a-w- c:\windows\system32\drivers\naiavf5x.sys
2010-01-04 03:31 . 2005-09-19 17:05 288320 ----a-r- c:\windows\system32\mcgdmgr.dll
2010-01-04 03:31 . 2005-09-19 17:05 349760 ----a-r- c:\windows\system32\mcinsctl.dll
2010-01-04 03:31 . 2010-01-04 03:59 -------- d-----w- c:\program files\McAfee.com
2010-01-04 01:16 . 2010-01-04 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-26 20:27 . 2010-01-26 20:27 162320 ----a-w- c:\windows\D46BA236EA9BDCE8B4C51C89D375EAF4.exe
2010-01-26 16:59 . 2010-01-26 16:59 116224 ------w- c:\windows\system32\cbee9d2d3ab7a2c06ee5b3b6b8c66de7.TMP
2010-01-26 04:35 . 2009-02-15 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-26 04:31 . 2008-10-01 01:28 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\uTorrent
2010-01-25 22:38 . 2009-09-02 06:07 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-24 07:24 . 2009-11-23 01:42 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\vlc
2010-01-23 20:51 . 2007-07-19 04:38 -------- d-----w- c:\program files\Common Files\Java
2010-01-23 20:44 . 2007-07-19 04:39 -------- d-----w- c:\program files\Java
2010-01-21 18:35 . 2010-01-21 18:35 116224 ------w- c:\windows\system32\fc8dbece339d30b1af441e112d47d8dc.TMP
2010-01-21 16:53 . 2010-01-21 16:53 116224 ------w- c:\windows\system32\bb1e50624b3baaad61d5ded1e786610c.TMP
2010-01-20 17:46 . 2009-09-01 19:42 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 05:00 . 2007-06-25 19:53 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-20 04:58 . 2009-07-30 03:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-20 04:58 . 2005-04-12 16:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-20 04:55 . 2003-02-05 03:11 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-18 02:58 . 2008-10-01 01:28 -------- d-----w- c:\program files\uTorrent
2010-01-17 21:45 . 2004-07-22 12:10 278031 ------w- c:\windows\system32\9cc445b94c1007b9bda5e01a5ccd6712.TMP
2010-01-14 22:13 . 2010-01-14 22:13 278031 ------w- c:\windows\system32\7c03360cf6eb5d7231e9bd1683fcc030.TMP
2010-01-11 01:46 . 2010-01-11 01:46 118 ----a-w- c:\documents and settings\Charlene Johnson\Application Data\netstat.bat
2010-01-10 20:18 . 2010-01-10 20:18 278031 ------w- c:\windows\system32\e13ffcbd4948633c02e47013d05dbc30.TMP
2010-01-10 20:18 . 2004-07-22 12:10 278031 ------w- c:\windows\system32\75a0d9cff891415910ed3a0ef541da08.TMP
2010-01-09 07:07 . 2009-03-15 21:37 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\dvdcss
2010-01-05 18:26 . 2010-01-05 18:26 278031 ------w- c:\windows\system32\dbbac2692f81bcef7c38fc0271b9c572.TMP
2010-01-05 01:02 . 2005-11-11 17:09 58192 ----a-w- c:\documents and settings\Charlene Johnson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-05 01:01 . 2009-09-20 21:48 -------- d-----w- c:\program files\Texas Holdem Poker 3D Deluxe Edition DeLEGiON
2010-01-05 00:54 . 2009-03-13 03:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-05 00:49 . 2009-02-06 22:02 -------- d-----w- c:\program files\Microsoft Works
2010-01-05 00:29 . 2008-01-28 06:19 -------- d-----w- c:\program files\SAMSUNG
2010-01-04 03:38 . 2005-10-26 17:30 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2010-01-02 04:07 . 2006-06-15 02:38 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\Apple Computer
2010-01-02 01:05 . 2010-01-02 01:05 278031 ------w- c:\windows\system32\7f93cf809ce4cef3094a1f37c8120d2f.TMP
2010-01-01 19:57 . 2008-03-27 21:20 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\MSN6
2010-01-01 08:21 . 2010-01-01 08:21 278031 ------w- c:\windows\system32\16f969ec579b94484d3c1117cbcb6297.TMP
2009-12-31 20:11 . 2009-12-31 20:07 948 ----a-w- c:\program files\Common Files\tmp.txt
2009-12-31 19:16 . 2009-12-31 19:39 11847 ----a-w- c:\program files\Common Files\tmp1.txt
2009-12-31 18:19 . 2009-12-31 18:19 278031 ------w- c:\windows\system32\adc6fc0a1e0bea52fa41e31b8c5a465e.TMP
2009-12-21 19:14 . 2005-06-18 06:49 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-11 05:16 . 2004-05-27 04:18 28466 ----a-w- c:\windows\system32\nvModes.dat
2010-01-05 00:15 . 2010-01-05 00:15 119312 ----a-w- c:\program files\mozilla firefox\components\badeafbeebc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efbeaeaedc]
2010-01-26 16:59 116224 ------w- c:\windows\system32\efbeaeaedc.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qfmq
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"67:UDP"= 67:UDP:DHCP Discovery Service

R2 GtDetectSc;GT Detect;c:\windows\system32\GtDetectSc.exe [9/21/2006 10:21 AM 167936]
S1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys --> c:\windows\system32\drivers\SBREDrv.sys [?]
S3 GTFFBUS;GT FF BUS;c:\windows\system32\drivers\gtffbus.sys [9/20/2006 5:03 AM 16128]
S3 GTMNDISIRPXP;GT M 3G+ IRP NDIS;c:\windows\system32\drivers\Gtm51Irp.sys [9/20/2006 5:03 AM 113408]
S3 GTUQBUS;GT UQ BUS;c:\windows\system32\drivers\gtuqbus.sys [9/20/2006 5:03 AM 34560]
S3 SPC610NC;SPC 610NC Laptop Camera;c:\windows\system32\drivers\SPC610NC.SYS [3/23/2008 3:58 PM 409728]

--- Other Services/Drivers In Memory ---

*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder

2010-01-26 c:\windows\Tasks\User_Feed_Synchronization-{B6499046-B7ED-49E4-AEDC-A3DCC43DF66A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:31]
.
.
------- Supplementary Scan -------
.
Trusted Zone: eharmony.com\www
DPF: DirectAnimation Java Classes - [You must be registered and logged in to see this link.]
DPF: Microsoft XML Parser for Java - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\Charlene Johnson\Application Data\Mozilla\Firefox\Profiles\z36pw8lm.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: keyword.URL - [You must be registered and logged in to see this link.]
FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
WebBrowser-{D0523BB4-21E7-11DD-9AB7-415B56D89593} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
HKCU-Run-UniblueSpeedUpMyPC - c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
AddRemove-McAfee Personal Firewall Plus - c:\progra~1\mcafee.com\shared\mcappins.exe
AddRemove-Mcafee SecurityCenter - c:\progra~1\mcafee.com\shared\mcappins.exe
AddRemove-VirusScan Online - c:\progra~1\mcafee.com\shared\mcappins.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-01-26 12:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...


c:\windows\system32\f76d82f05f051340fe3745591fc825e8.sys 36864 bytes executable

scan completed successfully
hȋdden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet006\Services\f76d82f05f051340fe3745591fc825e8]
"ImagePath"="system32\f76d82f05f051340fe3745591fc825e8.sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(512)
c:\windows\system32\efbeaeaedc.dll
c:\windows\system32\Wininet.dll

- - - - - - - > 'explorer.exe'(4076)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
c:\windows\wanmpsvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2010-01-26 12:37:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-26 20:37

Pre-Run: 429,780,992 bytes free
Post-Run: 2,482,475,008 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 4BD596381CD23093856D84E61F85A722

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Belahzur on 27th January 2010, 1:28 am


  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    File::
    c:\windows\B9448128476A724E84D3E7B5BEEACC.exe
    c:\windows\B5BC938E5347A8AE33E607DC21436F8.exe
    c:\windows\F03D3497C294A4C2E760CD286D7245F0.exe
    c:\windows\B37457BBC857A75B9FDD1CDA98C96B3.exe
    c:\windows\D41B63992E26C9F81E1C2818BDACE2.exe
    c:\windows\F9C69851E1DD6E36391765A625E0D1.exe
    c:\windows\A1468B7618A234D674445C2CF6D97CFE.exe
    c:\windows\FBC9E8C8B596289A8AA582482D9BC379.exe
    c:\windows\C430DB11402B9E7A5B8F8D5FDC4FFAD5.exe
    c:\windows\E6B4AD1BDF0F2ADFAFC511116EF8E.exe
    c:\windows\BD4AFC3418AD5B66E06E16E9564DEDCA.exe
    c:\windows\D41028563785B5242BAC4723CE28C38.exe
    c:\windows\D32EEA40AF6B237495B3DBF224C92641.exe
    c:\windows\F63684EFA3EDF931A22A9AC83DA4CC.exe
    c:\windows\FDD5FE215276B285EBA47F668987B1D.exe
    c:\windows\B29686088DD78FA65AB22BB68787533.exe
    c:\windows\CBE77B731C91D4134A23C3C4F7FD85.exe
    c:\windows\BB8CDB5E81831AE2E25022C452471FCA.exe
    c:\windows\D3748B1C4E895BA537593F34E5B18EED.exe
    c:\windows\A5523DD98CF4B99AD1FA99FC76DF6B.exe
    c:\windows\A55631D398DC27EFDAF61E59F028641E.exe
    c:\windows\EA167ECEFE66FF88AFD3AD3E8AAE1EB.exe
    c:\windows\B44781D64668721B3F52B8D6B8F2CFBC.exe
    c:\windows\EAA510C34D27FD3DD923679775271663.exe
    c:\windows\AC216EF6A70D98BB6FC43C44B1FE4C.exe
    c:\windows\D91B2613DDE697CCF99D1B38843322C.exe
    c:\windows\B58466B63654A7709FC75A2E863889.exe
    c:\windows\system32\a62919e691a57a38c247a68b23625674.exe
    c:\windows\system32\efbeaeaedc.dll
    c:\windows\EA2F303BACD49614ADAAB172E8D56D9.exe
    c:\windows\B1E7B8E994BE2BBEDA51FD3DE4FF60.exe
    c:\windows\D46BA236EA9BDCE8B4C51C89D375EAF4.exe
    c:\windows\system32\9cc445b94c1007b9bda5e01a5ccd6712.TMP
    c:\windows\system32\7c03360cf6eb5d7231e9bd1683fcc030.TMP
    c:\documents and settings\Charlene Johnson\Application Data\netstat.bat
    c:\windows\system32\e13ffcbd4948633c02e47013d05dbc30.TMP
    c:\windows\system32\75a0d9cff891415910ed3a0ef541da08.TMP
    c:\windows\system32\dbbac2692f81bcef7c38fc0271b9c572.TMP
    c:\windows\system32\7f93cf809ce4cef3094a1f37c8120d2f.TMP
    c:\windows\system32\16f969ec579b94484d3c1117cbcb6297.TMP
    c:\program files\Common Files\tmp.txt
    c:\program files\Common Files\tmp1.txt
    c:\windows\system32\adc6fc0a1e0bea52fa41e31b8c5a465e.TMP
    c:\program files\mozilla firefox\components\badeafbeebc.dll

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efbeaeaedc]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qfmq]
    [-HKEY_LOCAL_MACHINE\System\ControlSet006\Services\f76d82f05f051340fe3745591fc825e8]

    Firefox::
    FF - ProfilePath - c:\documents and settings\Charlene Johnson\Application Data\Mozilla\Firefox\Profiles\z36pw8lm.default\
    FF - prefs.js: browser.search.selectedEngine - Ask
    FF - prefs.js: keyword.URL - [You must be registered and logged in to see this link.]

    RegLock::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
  4. Save this as CFScript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 28th January 2010, 3:33 am

ComboFix 10-01-27.03 - Charlene Johnson 01/27/2010 18:43:15.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.116 [GMT -8:00]
Running from: c:\documents and settings\Charlene Johnson\Desktop\Virus Tools\ComboFix.exe
Command switches used :: c:\documents and settings\Charlene Johnson\Desktop\CFScript.txt

FILE ::
"c:\documents and settings\Charlene Johnson\Application Data\netstat.bat"
"c:\program files\Common Files\tmp.txt"
"c:\program files\Common Files\tmp1.txt"
"c:\program files\mozilla firefox\components\badeafbeebc.dll"
"c:\windows\A1468B7618A234D674445C2CF6D97CFE.exe"
"c:\windows\A5523DD98CF4B99AD1FA99FC76DF6B.exe"
"c:\windows\A55631D398DC27EFDAF61E59F028641E.exe"
"c:\windows\AC216EF6A70D98BB6FC43C44B1FE4C.exe"
"c:\windows\B1E7B8E994BE2BBEDA51FD3DE4FF60.exe"
"c:\windows\B29686088DD78FA65AB22BB68787533.exe"
"c:\windows\B37457BBC857A75B9FDD1CDA98C96B3.exe"
"c:\windows\B44781D64668721B3F52B8D6B8F2CFBC.exe"
"c:\windows\B58466B63654A7709FC75A2E863889.exe"
"c:\windows\B5BC938E5347A8AE33E607DC21436F8.exe"
"c:\windows\B9448128476A724E84D3E7B5BEEACC.exe"
"c:\windows\BB8CDB5E81831AE2E25022C452471FCA.exe"
"c:\windows\BD4AFC3418AD5B66E06E16E9564DEDCA.exe"
"c:\windows\C430DB11402B9E7A5B8F8D5FDC4FFAD5.exe"
"c:\windows\CBE77B731C91D4134A23C3C4F7FD85.exe"
"c:\windows\D32EEA40AF6B237495B3DBF224C92641.exe"
"c:\windows\D3748B1C4E895BA537593F34E5B18EED.exe"
"c:\windows\D41028563785B5242BAC4723CE28C38.exe"
"c:\windows\D41B63992E26C9F81E1C2818BDACE2.exe"
"c:\windows\D46BA236EA9BDCE8B4C51C89D375EAF4.exe"
"c:\windows\D91B2613DDE697CCF99D1B38843322C.exe"
"c:\windows\E6B4AD1BDF0F2ADFAFC511116EF8E.exe"
"c:\windows\EA167ECEFE66FF88AFD3AD3E8AAE1EB.exe"
"c:\windows\EA2F303BACD49614ADAAB172E8D56D9.exe"
"c:\windows\EAA510C34D27FD3DD923679775271663.exe"
"c:\windows\F03D3497C294A4C2E760CD286D7245F0.exe"
"c:\windows\F63684EFA3EDF931A22A9AC83DA4CC.exe"
"c:\windows\F9C69851E1DD6E36391765A625E0D1.exe"
"c:\windows\FBC9E8C8B596289A8AA582482D9BC379.exe"
"c:\windows\FDD5FE215276B285EBA47F668987B1D.exe"
"c:\windows\system32\16f969ec579b94484d3c1117cbcb6297.TMP"
"c:\windows\system32\75a0d9cff891415910ed3a0ef541da08.TMP"
"c:\windows\system32\7c03360cf6eb5d7231e9bd1683fcc030.TMP"
"c:\windows\system32\7f93cf809ce4cef3094a1f37c8120d2f.TMP"
"c:\windows\system32\9cc445b94c1007b9bda5e01a5ccd6712.TMP"
"c:\windows\system32\a62919e691a57a38c247a68b23625674.exe"
"c:\windows\system32\adc6fc0a1e0bea52fa41e31b8c5a465e.TMP"
"c:\windows\system32\dbbac2692f81bcef7c38fc0271b9c572.TMP"
"c:\windows\system32\e13ffcbd4948633c02e47013d05dbc30.TMP"
"c:\windows\system32\efbeaeaedc.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Charlene Johnson\Application Data\netstat.bat
c:\program files\Common Files\tmp.txt
c:\program files\Common Files\tmp1.txt
c:\program files\mozilla firefox\components\badeafbeebc.dll
c:\windows\48607339832E4B526074C0AE2C3523CB.exe
c:\windows\75E06E866E79C32FD6D1EA6B8818127E.exe
c:\windows\80FEF031B636D4B67FF0E8996F172C.exe
c:\windows\A1468B7618A234D674445C2CF6D97CFE.exe
c:\windows\A5523DD98CF4B99AD1FA99FC76DF6B.exe
c:\windows\A55631D398DC27EFDAF61E59F028641E.exe
c:\windows\AC216EF6A70D98BB6FC43C44B1FE4C.exe
c:\windows\B1E7B8E994BE2BBEDA51FD3DE4FF60.exe
c:\windows\B29686088DD78FA65AB22BB68787533.exe
c:\windows\B37457BBC857A75B9FDD1CDA98C96B3.exe
c:\windows\B44781D64668721B3F52B8D6B8F2CFBC.exe
c:\windows\B58466B63654A7709FC75A2E863889.exe
c:\windows\B5BC938E5347A8AE33E607DC21436F8.exe
c:\windows\B9448128476A724E84D3E7B5BEEACC.exe
c:\windows\BB8CDB5E81831AE2E25022C452471FCA.exe
c:\windows\BD4AFC3418AD5B66E06E16E9564DEDCA.exe
c:\windows\C430DB11402B9E7A5B8F8D5FDC4FFAD5.exe
c:\windows\CBE77B731C91D4134A23C3C4F7FD85.exe
c:\windows\D32EEA40AF6B237495B3DBF224C92641.exe
c:\windows\D3748B1C4E895BA537593F34E5B18EED.exe
c:\windows\D41028563785B5242BAC4723CE28C38.exe
c:\windows\D41B63992E26C9F81E1C2818BDACE2.exe
c:\windows\D46BA236EA9BDCE8B4C51C89D375EAF4.exe
c:\windows\D91B2613DDE697CCF99D1B38843322C.exe
c:\windows\E6B4AD1BDF0F2ADFAFC511116EF8E.exe
c:\windows\EA167ECEFE66FF88AFD3AD3E8AAE1EB.exe
c:\windows\EA2F303BACD49614ADAAB172E8D56D9.exe
c:\windows\EAA510C34D27FD3DD923679775271663.exe
c:\windows\F03D3497C294A4C2E760CD286D7245F0.exe
c:\windows\F63684EFA3EDF931A22A9AC83DA4CC.exe
c:\windows\F9C69851E1DD6E36391765A625E0D1.exe
c:\windows\FBC9E8C8B596289A8AA582482D9BC379.exe
c:\windows\FDD5FE215276B285EBA47F668987B1D.exe
c:\windows\system32\146a8b4f1b988547b10babe1dd5b2301.exe
c:\windows\system32\16f969ec579b94484d3c1117cbcb6297.TMP
c:\windows\system32\75a0d9cff891415910ed3a0ef541da08.TMP
c:\windows\system32\7c03360cf6eb5d7231e9bd1683fcc030.TMP
c:\windows\system32\7f93cf809ce4cef3094a1f37c8120d2f.TMP
c:\windows\system32\9cc445b94c1007b9bda5e01a5ccd6712.TMP
c:\windows\system32\a62919e691a57a38c247a68b23625674.exe
c:\windows\system32\adc6fc0a1e0bea52fa41e31b8c5a465e.TMP
c:\windows\system32\dbbac2692f81bcef7c38fc0271b9c572.TMP
c:\windows\system32\e13ffcbd4948633c02e47013d05dbc30.TMP
c:\windows\system32\efbeaeaedc.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-28 )))))))))))))))))))))))))))))))
.

2010-01-28 02:37 . 2010-01-28 02:37 389120 ----a-w- c:\windows\system32\CF18713.exe
2010-01-27 21:00 . 2010-01-27 21:00 207888 ----a-w- c:\windows\system32\a38bb923feae0d8f9021412672c0d946.exe
2010-01-27 21:00 . 2010-01-27 21:00 282640 ----a-w- c:\windows\system32\d94a2d8f9690df987402e5bd5dad514f.exe
2010-01-27 20:40 . 2010-01-27 20:40 162320 ----a-w- c:\windows\C42542BE26D490BA576D587F268457B.exe
2010-01-27 19:55 . 2010-01-27 19:55 389120 ----a-w- c:\windows\system32\CF5448.exe
2010-01-27 10:13 . 2010-01-27 10:13 162320 ----a-w- c:\windows\DB15D640D2BA466A5FD283D4ACC42A.exe
2010-01-27 09:19 . 2010-01-27 09:19 162320 ----a-w- c:\windows\DAF38F6CA39BFD3D3A3AF1D92FA44F.exe
2010-01-26 09:45 . 2010-01-26 10:02 -------- d-----w- C:\Combo-Fix14529C
2010-01-26 09:43 . 2010-01-26 09:44 -------- d-----w- C:\Combo-Fix
2010-01-26 09:43 . 2010-01-26 09:42 389120 ----a-w- c:\windows\system32\CF29328.exe
2010-01-26 09:41 . 2010-01-26 09:41 389120 ----a-w- c:\windows\system32\CF29090.exe
2010-01-26 09:27 . 2010-01-26 09:27 -------- d-----w- C:\VundoFix Backups
2010-01-26 04:06 . 2010-01-26 04:06 -------- d-----w- c:\program files\Simple Port Forwarding
2010-01-26 04:06 . 2010-01-26 04:06 -------- d-----w- c:\windows\Simple Port Forwarding
2010-01-26 03:17 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-26 03:17 . 2010-01-26 03:18 -------- d-----w- c:\program files\Innocent
2010-01-26 03:17 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-24 02:53 . 2010-01-24 04:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-23 21:26 . 2010-01-23 21:26 -------- d-----w- c:\program files\TrendMicro
2010-01-23 20:46 . 2010-01-23 20:46 -------- d-----w- c:\program files\Sun
2010-01-23 20:45 . 2010-01-23 20:44 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-22 23:12 . 2010-01-27 09:57 -------- d-----w- c:\program files\Lavasoft
2010-01-22 08:11 . 2010-01-23 04:23 131112 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-22 01:20 . 2010-01-22 01:20 -------- d-----w- c:\documents and settings\Charlene Johnson\ErrorLogs
2010-01-22 00:47 . 2010-01-22 00:48 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2010-01-22 00:07 . 2010-01-22 00:07 -------- d-----w- c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2010-01-21 20:20 . 2010-01-21 20:21 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2010-01-21 19:08 . 2010-01-22 00:51 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\Uniblue
2010-01-18 17:17 . 2010-01-18 17:17 696832 ----a-w- c:\windows\is-C56IE.exe
2010-01-18 17:17 . 2010-01-18 17:17 696832 ----a-w- c:\windows\is-VE2HE.exe
2010-01-18 17:16 . 2010-01-18 17:16 696832 ----a-w- c:\windows\is-HT9V6.exe
2010-01-18 17:13 . 2010-01-18 17:13 696832 ----a-w- c:\windows\is-A6MQ2.exe
2010-01-18 02:04 . 2010-01-18 02:04 -------- d-----w- c:\documents and settings\Charlene Johnson\Local Settings\Application Data\Threat Expert
2010-01-18 01:43 . 2010-01-20 05:12 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-17 21:53 . 2010-01-17 21:55 -------- d-----w- C:\WINSSLog
2010-01-17 21:46 . 2010-01-17 21:55 -------- d-----w- C:\9738c56b1665e4eb2f2ea99250feb77b
2010-01-17 16:02 . 2010-01-17 16:02 -------- d-----w- C:\aa7be623a5b666aa7a28a1
2010-01-17 06:32 . 2010-01-17 06:32 -------- d-----w- C:\f1d816dfd744640e0962
2010-01-17 06:19 . 2010-01-17 06:19 -------- d-----w- C:\9f49b76490a8dca6c059e7f9b723184f
2010-01-16 00:43 . 2010-01-16 00:43 -------- d-----w- c:\program files\Google
2010-01-14 21:15 . 2005-01-17 20:30 70619374 ----a-w- C:\KB888111_Supported_OS_All_Languages.zip
2010-01-13 21:09 . 2010-01-13 22:51 -------- d---a-w- C:\3590F75ABA9E485486C100C1A9D4FF06ZZ..ZZ.ZZZ....ZZ
2010-01-12 23:13 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 21:35 . 2010-01-12 21:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-10 05:04 . 2010-01-21 23:34 -------- d-----w- c:\program files\Yahoo!
2010-01-08 21:28 . 2010-01-08 21:28 -------- d-----w- c:\program files\File Shredder
2010-01-05 04:08 . 2010-01-05 04:08 -------- d-----w- C:\07fa843b86f7f83f1860d93996a1fa9c
2010-01-05 02:42 . 2010-01-05 03:01 -------- d-----w- C:\230a824188e94d8b0d554376
2010-01-04 04:22 . 2010-01-04 04:22 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee.com Personal Firewall
2010-01-04 04:22 . 2010-01-04 04:24 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\McAfee.com Personal Firewall
2010-01-04 03:59 . 2005-08-17 00:18 80640 ----a-w- c:\windows\system32\drivers\MpFirewall.sys
2010-01-04 03:59 . 2005-08-17 00:13 9216 ----a-w- c:\windows\system32\MpfApi.dll
2010-01-04 03:59 . 2010-01-04 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2010-01-04 03:46 . 2005-08-10 19:22 114464 ----a-w- c:\windows\system32\drivers\naiavf5x.sys
2010-01-04 03:31 . 2005-09-19 17:05 288320 ----a-r- c:\windows\system32\mcgdmgr.dll
2010-01-04 03:31 . 2005-09-19 17:05 349760 ----a-r- c:\windows\system32\mcinsctl.dll
2010-01-04 03:31 . 2010-01-04 03:59 -------- d-----w- c:\program files\McAfee.com
2010-01-04 01:16 . 2010-01-04 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-28 03:05 . 2010-01-28 03:05 116224 ------w- c:\windows\system32\efbeaeaedc.dll
2010-01-28 03:05 . 2010-01-28 03:05 162320 ----a-w- c:\windows\FC46424A6ABF03721B04A727FBC9080.exe
2010-01-28 02:38 . 2008-10-01 01:28 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\uTorrent
2010-01-27 18:11 . 2010-01-27 18:11 116224 ------w- c:\windows\system32\42eb0fd8e6dacf6c1d1d940240c3c82e.TMP
2010-01-27 10:06 . 2005-05-19 05:25 -------- d-----w- c:\program files\Sony
2010-01-26 16:59 . 2010-01-26 16:59 116224 ------w- c:\windows\system32\cbee9d2d3ab7a2c06ee5b3b6b8c66de7.TMP
2010-01-26 16:59 . 2010-01-20 20:55 116224 ------w- c:\windows\system32\58365212c72a921e7684d746721dcf24.TMP
2010-01-26 04:35 . 2009-02-15 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-25 22:38 . 2009-09-02 06:07 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-24 07:24 . 2009-11-23 01:42 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\vlc
2010-01-23 20:51 . 2007-07-19 04:38 -------- d-----w- c:\program files\Common Files\Java
2010-01-23 20:44 . 2007-07-19 04:39 -------- d-----w- c:\program files\Java
2010-01-21 18:35 . 2010-01-21 18:35 116224 ------w- c:\windows\system32\fc8dbece339d30b1af441e112d47d8dc.TMP
2010-01-21 16:53 . 2010-01-21 16:53 116224 ------w- c:\windows\system32\bb1e50624b3baaad61d5ded1e786610c.TMP
2010-01-20 17:46 . 2009-09-01 19:42 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 05:00 . 2007-06-25 19:53 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-20 04:58 . 2009-07-30 03:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-20 04:58 . 2005-04-12 16:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-20 04:55 . 2003-02-05 03:11 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-18 02:58 . 2008-10-01 01:28 -------- d-----w- c:\program files\uTorrent
2010-01-09 07:07 . 2009-03-15 21:37 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\dvdcss
2010-01-05 01:02 . 2005-11-11 17:09 58192 ----a-w- c:\documents and settings\Charlene Johnson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-05 01:01 . 2009-09-20 21:48 -------- d-----w- c:\program files\Texas Holdem Poker 3D Deluxe Edition DeLEGiON
2010-01-05 00:54 . 2009-03-13 03:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-05 00:49 . 2009-02-06 22:02 -------- d-----w- c:\program files\Microsoft Works
2010-01-05 00:29 . 2008-01-28 06:19 -------- d-----w- c:\program files\SAMSUNG
2010-01-04 03:38 . 2005-10-26 17:30 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2010-01-02 04:07 . 2006-06-15 02:38 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\Apple Computer
2010-01-01 19:57 . 2008-03-27 21:20 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\MSN6
2009-12-21 19:14 . 2005-06-18 06:49 916480 ------w- c:\windows\system32\wininet.dll
2009-12-11 05:16 . 2004-05-27 04:18 28466 ----a-w- c:\windows\system32\nvModes.dat
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2005-10-18 18:58 . 2005-10-18 18:58 278528 c:\documents and settings\All Users\Start Menu\Programs\iTunes\iTunes\bak\iTunesHelper.exe
2008-11-20 21:20 . 2008-11-20 21:20 290088 c:\documents and settings\All Users\Start Menu\Programs\iTunes\iTunes\iTunesHelper.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efbeaeaedc]
2010-01-28 03:05 116224 ------w- c:\windows\system32\efbeaeaedc.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"67:UDP"= 67:UDP:DHCP Discovery Service

S1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys --> c:\windows\system32\drivers\SBREDrv.sys [?]
S3 GTFFBUS;GT FF BUS;c:\windows\system32\drivers\gtffbus.sys [9/20/2006 5:03 AM 16128]
S3 GTMNDISIRPXP;GT M 3G+ IRP NDIS;c:\windows\system32\drivers\Gtm51Irp.sys [9/20/2006 5:03 AM 113408]
S3 GTUQBUS;GT UQ BUS;c:\windows\system32\drivers\gtuqbus.sys [9/20/2006 5:03 AM 34560]
S3 SPC610NC;SPC 610NC Laptop Camera;c:\windows\system32\drivers\SPC610NC.SYS [3/23/2008 3:58 PM 409728]

--- Other Services/Drivers In Memory ---

*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder

2010-01-28 c:\windows\Tasks\User_Feed_Synchronization-{B6499046-B7ED-49E4-AEDC-A3DCC43DF66A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:31]
.
.
------- Supplementary Scan -------
.
Trusted Zone: eharmony.com\www
DPF: DirectAnimation Java Classes - [You must be registered and logged in to see this link.]
DPF: Microsoft XML Parser for Java - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\Charlene Johnson\Application Data\Mozilla\Firefox\Profiles\z36pw8lm.default\
FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-01-27 19:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...


c:\windows\system32\f76d82f05f051340fe3745591fc825e8.sys 36864 bytes executable
c:\windows\system32\efbeaeaedc.dll 116224 bytes executable

scan completed successfully
hȋdden files: 2

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet006\Services\f76d82f05f051340fe3745591fc825e8]
"ImagePath"="system32\f76d82f05f051340fe3745591fc825e8.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(512)
c:\windows\system32\efbeaeaedc.dll
c:\windows\system32\Wininet.dll

- - - - - - - > 'explorer.exe'(132)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\GtDetectSc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
c:\windows\wanmpsvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2010-01-27 19:17:52 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-28 03:17
ComboFix2.txt 2010-01-26 20:37

Pre-Run: 3,156,422,656 bytes free
Post-Run: 3,170,775,040 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - BA66F19826637D73A09290FF44E879F7

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 28th January 2010, 3:35 am

Brilliant!
Much much better

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Belahzur on 28th January 2010, 5:40 pm

Hello.
Nope, the rootkit is still there, and the autorun infection is still there.

Did you plug in any removable media (external hardware)?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 28th January 2010, 7:28 pm

Just my ipod but it seems to be working fine oh! and also my printer.
I wonder if I should let you know that I could not get combofix from bleeping computers.com
When I would put bleeping computers in the browser window using both IE and mozilla the browser window would disappear
I went to a torrent site and got a bundle of antivirus software that had combofix included and I launched it from there
I read a mention that you should only get combofix from bleepingcomputers?

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Belahzur on 29th January 2010, 12:23 am

Hello.


  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    KILLALL::

    File::
    c:\windows\system32\a38bb923feae0d8f9021412672c0d946.exe
    c:\windows\system32\d94a2d8f9690df987402e5bd5dad514f.exe
    c:\windows\C42542BE26D490BA576D587F268457B.exe
    c:\windows\DB15D640D2BA466A5FD283D4ACC42A.exe
    c:\windows\DAF38F6CA39BFD3D3A3AF1D92FA44F.exe
    c:\windows\system32\efbeaeaedc.dll
    c:\windows\FC46424A6ABF03721B04A727FBC9080.exe
    c:\windows\system32\42eb0fd8e6dacf6c1d1d940240c3c82e.TMP
    c:\windows\system32\cbee9d2d3ab7a2c06ee5b3b6b8c66de7.TMP
    c:\windows\system32\58365212c72a921e7684d746721dcf24.TMP
    c:\windows\system32\fc8dbece339d30b1af441e112d47d8dc.TMP
    c:\windows\system32\bb1e50624b3baaad61d5ded1e786610c.TMP

    AWF::
    c:\documents and settings\All Users\Start Menu\Programs\iTunes\iTunes\bak\iTunesHelper.exe

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efbeaeaedc]
    [-HKEY_LOCAL_MACHINE\System\ControlSet006\Services\f76d82f05f051340fe3745591fc825e8]

    Rootkit::
    c:\windows\system32\f76d82f05f051340fe3745591fc825e8.sys
    c:\windows\system32\efbeaeaedc.dll
  4. Save this as CFScript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 30th January 2010, 1:34 am

ComboFix 10-01-29.05 - Charlene Johnson 01/29/2010 16:37:53.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.118 [GMT -8:00]
Running from: c:\documents and settings\Charlene Johnson\Desktop\Virus Tools\ComboFix.exe
Command switches used :: c:\documents and settings\Charlene Johnson\Desktop\Virus Tools\CFScript.txt

FILE ::
"c:\windows\C42542BE26D490BA576D587F268457B.exe"
"c:\windows\DAF38F6CA39BFD3D3A3AF1D92FA44F.exe"
"c:\windows\DB15D640D2BA466A5FD283D4ACC42A.exe"
"c:\windows\FC46424A6ABF03721B04A727FBC9080.exe"
"c:\windows\system32\42eb0fd8e6dacf6c1d1d940240c3c82e.TMP"
"c:\windows\system32\58365212c72a921e7684d746721dcf24.TMP"
"c:\windows\system32\a38bb923feae0d8f9021412672c0d946.exe"
"c:\windows\system32\bb1e50624b3baaad61d5ded1e786610c.TMP"
"c:\windows\system32\cbee9d2d3ab7a2c06ee5b3b6b8c66de7.TMP"
"c:\windows\system32\d94a2d8f9690df987402e5bd5dad514f.exe"
"c:\windows\system32\efbeaeaedc.dll"
"c:\windows\system32\fc8dbece339d30b1af441e112d47d8dc.TMP"
.

((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

2010-01-29 22:22 . 2010-01-29 22:23 -------- d-----w- C:\Combo-Fix4244C
2010-01-29 04:35 . 2010-01-29 04:35 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\Malwarebytes
2010-01-28 02:37 . 2010-01-28 02:37 389120 ----a-w- c:\windows\system32\CF18713.exe
2010-01-27 19:55 . 2010-01-27 19:55 389120 ----a-w- c:\windows\system32\CF5448.exe
2010-01-26 09:45 . 2010-01-26 10:02 -------- d-----w- C:\Combo-Fix14529C
2010-01-26 09:43 . 2010-01-26 09:44 -------- d-----w- C:\Combo-Fix
2010-01-26 09:43 . 2010-01-26 09:42 389120 ----a-w- c:\windows\system32\CF29328.exe
2010-01-26 09:41 . 2010-01-26 09:41 389120 ----a-w- c:\windows\system32\CF29090.exe
2010-01-26 09:27 . 2010-01-26 09:27 -------- d-----w- C:\VundoFix Backups
2010-01-26 04:06 . 2010-01-26 04:06 -------- d-----w- c:\program files\Simple Port Forwarding
2010-01-26 04:06 . 2010-01-26 04:06 -------- d-----w- c:\windows\Simple Port Forwarding
2010-01-26 03:17 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-26 03:17 . 2010-01-26 03:18 -------- d-----w- c:\program files\Innocent
2010-01-26 03:17 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-24 02:53 . 2010-01-24 04:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-23 21:26 . 2010-01-23 21:26 -------- d-----w- c:\program files\TrendMicro
2010-01-23 20:46 . 2010-01-23 20:46 -------- d-----w- c:\program files\Sun
2010-01-23 20:45 . 2010-01-23 20:44 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-22 23:12 . 2010-01-27 09:57 -------- d-----w- c:\program files\Lavasoft
2010-01-22 08:11 . 2010-01-23 04:23 131112 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-22 01:20 . 2010-01-22 01:20 -------- d-----w- c:\documents and settings\Charlene Johnson\ErrorLogs
2010-01-22 00:47 . 2010-01-22 00:48 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2010-01-22 00:07 . 2010-01-22 00:07 -------- d-----w- c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2010-01-21 20:20 . 2010-01-21 20:21 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2010-01-21 19:08 . 2010-01-22 00:51 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\Uniblue
2010-01-18 17:17 . 2010-01-18 17:17 696832 ----a-w- c:\windows\is-C56IE.exe
2010-01-18 17:17 . 2010-01-18 17:17 696832 ----a-w- c:\windows\is-VE2HE.exe
2010-01-18 17:16 . 2010-01-18 17:16 696832 ----a-w- c:\windows\is-HT9V6.exe
2010-01-18 17:13 . 2010-01-18 17:13 696832 ----a-w- c:\windows\is-A6MQ2.exe
2010-01-18 02:04 . 2010-01-18 02:04 -------- d-----w- c:\documents and settings\Charlene Johnson\Local Settings\Application Data\Threat Expert
2010-01-18 01:43 . 2010-01-20 05:12 -------- d-----w- c:\program files\Common Files\PC Tools
2010-01-17 21:53 . 2010-01-17 21:55 -------- d-----w- C:\WINSSLog
2010-01-17 21:46 . 2010-01-17 21:55 -------- d-----w- C:\9738c56b1665e4eb2f2ea99250feb77b
2010-01-17 16:02 . 2010-01-17 16:02 -------- d-----w- C:\aa7be623a5b666aa7a28a1
2010-01-17 06:32 . 2010-01-17 06:32 -------- d-----w- C:\f1d816dfd744640e0962
2010-01-17 06:19 . 2010-01-17 06:19 -------- d-----w- C:\9f49b76490a8dca6c059e7f9b723184f
2010-01-16 00:43 . 2010-01-16 00:43 -------- d-----w- c:\program files\Google
2010-01-14 21:15 . 2005-01-17 20:30 70619374 ----a-w- C:\KB888111_Supported_OS_All_Languages.zip
2010-01-13 21:09 . 2010-01-13 22:51 -------- d---a-w- C:\3590F75ABA9E485486C100C1A9D4FF06ZZ..ZZ.ZZZ....ZZ
2010-01-12 23:13 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 21:35 . 2010-01-12 21:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-10 05:04 . 2010-01-21 23:34 -------- d-----w- c:\program files\Yahoo!
2010-01-08 21:28 . 2010-01-08 21:28 -------- d-----w- c:\program files\File Shredder
2010-01-05 04:08 . 2010-01-05 04:08 -------- d-----w- C:\07fa843b86f7f83f1860d93996a1fa9c
2010-01-05 02:42 . 2010-01-05 03:01 -------- d-----w- C:\230a824188e94d8b0d554376
2010-01-04 04:22 . 2010-01-04 04:22 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee.com Personal Firewall
2010-01-04 04:22 . 2010-01-04 04:24 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\McAfee.com Personal Firewall
2010-01-04 03:59 . 2005-08-17 00:18 80640 ----a-w- c:\windows\system32\drivers\MpFirewall.sys
2010-01-04 03:59 . 2005-08-17 00:13 9216 ----a-w- c:\windows\system32\MpfApi.dll
2010-01-04 03:59 . 2010-01-04 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2010-01-04 03:46 . 2005-08-10 19:22 114464 ----a-w- c:\windows\system32\drivers\naiavf5x.sys
2010-01-04 03:31 . 2005-09-19 17:05 288320 ----a-r- c:\windows\system32\mcgdmgr.dll
2010-01-04 03:31 . 2005-09-19 17:05 349760 ----a-r- c:\windows\system32\mcinsctl.dll
2010-01-04 03:31 . 2010-01-04 03:59 -------- d-----w- c:\program files\McAfee.com
2010-01-04 01:16 . 2010-01-04 01:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 00:37 . 2008-10-01 01:28 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\uTorrent
2010-01-27 10:06 . 2005-05-19 05:25 -------- d-----w- c:\program files\Sony
2010-01-26 04:35 . 2009-02-15 23:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-25 22:38 . 2009-09-02 06:07 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-24 07:24 . 2009-11-23 01:42 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\vlc
2010-01-23 20:51 . 2007-07-19 04:38 -------- d-----w- c:\program files\Common Files\Java
2010-01-23 20:44 . 2007-07-19 04:39 -------- d-----w- c:\program files\Java
2010-01-20 17:46 . 2009-09-01 19:42 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-20 05:00 . 2007-06-25 19:53 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-20 04:58 . 2009-07-30 03:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-20 04:58 . 2005-04-12 16:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-20 04:55 . 2003-02-05 03:11 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-18 02:58 . 2008-10-01 01:28 -------- d-----w- c:\program files\uTorrent
2010-01-09 07:07 . 2009-03-15 21:37 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\dvdcss
2010-01-05 01:02 . 2005-11-11 17:09 58192 ----a-w- c:\documents and settings\Charlene Johnson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-05 01:01 . 2009-09-20 21:48 -------- d-----w- c:\program files\Texas Holdem Poker 3D Deluxe Edition DeLEGiON
2010-01-05 00:54 . 2009-03-13 03:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-05 00:49 . 2009-02-06 22:02 -------- d-----w- c:\program files\Microsoft Works
2010-01-05 00:29 . 2008-01-28 06:19 -------- d-----w- c:\program files\SAMSUNG
2010-01-04 03:38 . 2005-10-26 17:30 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2010-01-02 04:07 . 2006-06-15 02:38 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\Apple Computer
2010-01-01 19:57 . 2008-03-27 21:20 -------- d-----w- c:\documents and settings\Charlene Johnson\Application Data\MSN6
2009-12-22 01:28 . 2010-01-05 00:04 144518 ----a-w- c:\windows\PCHealth\HelpCtr\Config\Cache\Personal_32_1033.dat
2009-12-21 19:14 . 2005-06-18 06:49 916480 ------w- c:\windows\system32\wininet.dll
2009-12-11 05:16 . 2004-05-27 04:18 28466 ----a-w- c:\windows\system32\nvModes.dat
2009-11-21 15:51 . 2002-09-03 16:26 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2005-10-18 18:58 . 2005-10-18 18:58 278528 c:\documents and settings\All Users\Start Menu\Programs\iTunes\iTunes\bak\iTunesHelper.exe
2008-11-20 21:20 . 2008-11-20 21:20 290088 c:\documents and settings\All Users\Start Menu\Programs\iTunes\iTunes\iTunesHelper.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"67:UDP"= 67:UDP:DHCP Discovery Service

R2 GtDetectSc;GT Detect;c:\windows\system32\GtDetectSc.exe [9/21/2006 10:21 AM 167936]
S1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys --> c:\windows\system32\drivers\SBREDrv.sys [?]
S3 GTFFBUS;GT FF BUS;c:\windows\system32\drivers\gtffbus.sys [9/20/2006 5:03 AM 16128]
S3 GTMNDISIRPXP;GT M 3G+ IRP NDIS;c:\windows\system32\drivers\Gtm51Irp.sys [9/20/2006 5:03 AM 113408]
S3 GTUQBUS;GT UQ BUS;c:\windows\system32\drivers\gtuqbus.sys [9/20/2006 5:03 AM 34560]
S3 SPC610NC;SPC 610NC Laptop Camera;c:\windows\system32\drivers\SPC610NC.SYS [3/23/2008 3:58 PM 409728]

--- Other Services/Drivers In Memory ---

*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 c:\windows\Tasks\User_Feed_Synchronization-{B6499046-B7ED-49E4-AEDC-A3DCC43DF66A}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:31]
.
.
------- Supplementary Scan -------
.
DPF: DirectAnimation Java Classes - [You must be registered and logged in to see this link.]
DPF: Microsoft XML Parser for Java - [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\Charlene Johnson\Application Data\Mozilla\Firefox\Profiles\z36pw8lm.default\
FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-01-29 17:12
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2040)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\xpsp3res.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\progra~1\mcafee.com\agent\mctskshd.exe
c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
c:\windows\wanmpsvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-29 17:25:46 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-30 01:25
ComboFix2.txt 2010-01-30 00:30
ComboFix3.txt 2010-01-28 03:17
ComboFix4.txt 2010-01-26 20:37

Pre-Run: 2,886,393,856 bytes free
Post-Run: 2,808,651,776 bytes free

Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 9BBD26D4FDF5D99949DEC494A53205C6

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 30th January 2010, 1:37 am

I was able to run Malwarebytes successfully and I have the logs for them if you need them
I ran the combofix after the malwarebytes
I got a weird error message after the malwarebytes run. It said my computer might be infected with virut

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Belahzur on 30th January 2010, 5:00 pm

Nearly done.

I need you to uninstall iTunes, the malware has infected it and my fix hasn't fixed it.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Re: mbam chin09 rootkit

Post by Jaber93031 on 1st February 2010, 8:34 pm

ITunes has been uninstalled
I appreciate you hanging in there with me and I am recommending you to all my friends.

Jaber93031
Novice
Novice

Posts Posts : 11
Joined Joined : 2010-01-08
OS OS : windows xp
Points Points : 25423
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum