ComboFix 12-11-05.03 - Owner 11/06/2012 8:47.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.942 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\Owner\LOCALS~1\Temp\8aefdf3f-82dc-462e-be91-2ca1c43911cf\CliSecureRT.dll
c:\documents and settings\Owner\Local Settings\Temp\8aefdf3f-82dc-462e-be91-2ca1c43911cf\CliSecureRT.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-10-06 to 2012-11-06 )))))))))))))))))))))))))))))))
.
.
2012-11-04 02:15 . 2012-11-04 02:15 -------- d-----w- c:\documents and settings\Owner\.swt
2012-11-04 02:14 . 2012-11-06 02:28 -------- d-----w- c:\documents and settings\Owner\Application Data\Azureus
2012-11-04 02:14 . 2012-11-04 02:15 -------- d-----w- c:\program files\Vuze
2012-10-27 18:23 . 2012-10-27 18:23 -------- d-----w- C:\RK_Quarantine
2012-10-09 07:29 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2012-10-09 07:24 . 2009-07-31 04:57 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2012-10-09 07:24 . 2009-11-21 16:36 470528 -c----w- c:\windows\system32\dllcache\aclayers.dll
2012-10-09 07:18 . 2009-03-06 14:44 283648 -c----w- c:\windows\system32\dllcache\pdh.dll
2012-10-09 07:18 . 2005-07-26 04:39 60416 -c----w- c:\windows\system32\dllcache\colbact.dll
2012-10-09 07:18 . 2009-02-09 10:20 399360 -c----w- c:\windows\system32\dllcache\rpcss.dll
2012-10-09 07:18 . 2009-02-09 10:20 616960 -c----w- c:\windows\system32\dllcache\advapi32.dll
2012-10-09 07:18 . 2009-02-09 10:20 473088 -c----w- c:\windows\system32\dllcache\fastprox.dll
2012-10-09 07:18 . 2009-02-06 17:14 110592 -c----w- c:\windows\system32\dllcache\services.exe
2012-10-09 07:18 . 2009-02-09 10:20 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2012-10-09 07:01 . 2009-07-17 16:27 1435648 -c----w- c:\windows\system32\dllcache\query.dll
2012-10-08 12:46 . 2009-12-16 12:58 343040 -c----w- c:\windows\system32\dllcache\mspaint.exe
2012-10-08 07:01 . 2004-08-04 07:56 221184 ----a-w- c:\windows\system32\wmpns.dll
2012-10-07 16:53 . 2012-10-09 07:11 -------- d-----w- c:\windows\system32\CatRoot_bak
2012-10-07 15:52 . 2009-12-14 07:35 33280 -c----w- c:\windows\system32\dllcache\csrsrv.dll
2012-10-07 15:52 . 2008-07-03 13:16 8454656 -c----w- c:\windows\system32\dllcache\shell32.dll
2012-10-07 15:52 . 2009-09-04 20:45 58880 -c----w- c:\windows\system32\dllcache\msasn1.dll
2012-10-07 15:52 . 2010-04-20 05:51 285696 -c----w- c:\windows\system32\dllcache\atmfd.dll
2012-10-07 15:52 . 2008-06-24 16:23 74240 -c----w- c:\windows\system32\dllcache\mscms.dll
2012-10-07 15:52 . 2009-10-12 13:54 69632 -c----w- c:\windows\system32\dllcache\raschap.dll
2012-10-07 15:52 . 2009-10-12 13:54 112128 -c----w- c:\windows\system32\dllcache\rastls.dll
2012-10-07 15:47 . 2010-02-12 04:47 100864 -c----w- c:\windows\system32\dllcache\6to4svc.dll
2012-10-07 15:47 . 2009-06-25 08:44 168448 -c----w- c:\windows\system32\dllcache\schannel.dll
2012-10-07 15:41 . 2009-11-27 16:37 84992 -c----w- c:\windows\system32\dllcache\avifil32.dll
2012-10-07 15:41 . 2009-11-27 16:37 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll
2012-10-07 15:41 . 2009-11-27 16:37 11264 -c----w- c:\windows\system32\dllcache\msrle32.dll
2012-10-07 15:41 . 2010-01-29 15:08 683520 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2012-10-07 15:41 . 2010-01-29 15:08 1315840 -c----w- c:\windows\system32\dllcache\msoe.dll
2012-10-07 15:36 . 2006-10-04 08:48 215552 -c----w- c:\windows\system32\dllcache\osk.exe
2012-10-07 15:36 . 2006-10-04 08:48 72704 -c----w- c:\windows\system32\dllcache\magnify.exe
2012-10-07 15:36 . 2006-10-04 08:48 53760 -c----w- c:\windows\system32\dllcache\narrator.exe
2012-10-07 15:36 . 2010-03-05 14:57 65536 -c----w- c:\windows\system32\dllcache\asycfilt.dll
2012-10-07 15:36 . 2010-02-16 13:17 2137088 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2012-10-07 15:36 . 2010-02-16 13:19 2181376 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2012-10-07 15:36 . 2010-02-16 12:39 2016768 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2012-10-07 15:36 . 2010-02-16 12:39 2058368 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2012-10-07 15:36 . 2009-08-05 09:11 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2012-10-07 15:36 . 2010-02-24 12:31 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2012-10-07 15:35 . 2010-06-14 14:30 743936 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2012-10-07 15:35 . 2008-10-23 13:01 283648 -c----w- c:\windows\system32\dllcache\gdi32.dll
2012-10-07 15:35 . 2009-10-23 14:27 3555328 -c----w- c:\windows\system32\dllcache\moviemk.exe
2012-10-07 15:35 . 2008-05-01 14:30 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2012-10-07 15:35 . 2009-07-17 18:55 58880 -c----w- c:\windows\system32\dllcache\atl.dll
2012-10-07 15:30 . 2009-06-05 07:42 655872 -c----w- c:\windows\system32\dllcache\mstscax.dll
2012-10-07 15:30 . 2009-10-13 10:53 266752 -c----w- c:\windows\system32\dllcache\oakley.dll
2012-10-07 15:29 . 2010-01-13 14:10 85504 -c----w- c:\windows\system32\dllcache\cabview.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-06 15:27 . 2009-10-02 23:39 24920 ----a-w- c:\windows\system32\drivers\klmouflt.sys
2012-10-06 15:27 . 2012-05-25 23:38 24408 ----a-w- c:\windows\system32\drivers\klkbdflt.sys
2012-09-29 23:54 . 2012-10-06 12:01 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-18 01:39 . 2012-08-18 01:39 200632 ----a-w- c:\windows\system32\klogon.dll
2012-08-16 08:52 . 2012-08-16 08:52 261448 ----a-w- c:\windows\system32\betwinservicexp.exe
2012-08-16 08:52 . 2012-08-16 08:52 249856 ----a-w- c:\windows\system32\slsapi.dll
2012-08-16 08:52 . 2012-08-16 08:52 20800 ----a-w- c:\windows\system32\drivers\betwinvf.sys
2012-08-16 08:52 . 2012-08-16 08:52 13640 ----a-w- c:\windows\system32\drivers\betwinsystem.sys
2012-08-16 08:52 . 2012-08-16 08:52 16192 ----a-w- c:\windows\system32\drivers\betwinmf.sys
2012-08-16 08:52 . 2012-08-16 08:52 16192 ----a-w- c:\windows\system32\drivers\betwinkf.sys
2012-08-13 22:24 . 2012-10-06 13:09 74072 ----a-w- c:\windows\system32\drivers\klflt.sys
2012-08-13 20:49 . 2012-08-13 20:49 144344 ----a-w- c:\windows\system32\drivers\kneps.sys
2004-10-01 19:00 . 2010-09-01 20:17 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2010-05-12 20:42 . 2012-10-26 21:43 124344 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-05-12 21:22 . 2012-10-26 21:43 13240 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-05-12 20:43 . 2012-10-26 21:43 70592 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-05-12 20:42 . 2012-10-26 21:43 91576 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-05-12 20:42 . 2012-10-26 21:43 22464 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-05-12 20:41 . 2012-10-26 21:43 255416 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-05-12 20:42 . 2012-10-26 21:43 31160 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-05-12 20:42 . 2012-10-26 21:43 40384 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2010-04-14 17:55 . 2012-10-26 21:43 652640 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-05-12 20:43 . 2012-10-26 21:43 24000 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-10-26 21:44 . 2012-10-26 21:43 261600 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-03 39408]
"Akamai NetSession Interface"="c:\documents and settings\Owner\Local Settings\Application Data\Akamai\netsession_win.exe" [2012-10-09 4441920]
"KiesHelper"="c:\program files\Samsung\Kies\KiesHelper.exe" [2011-11-30 935312]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-11-30 21392]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17416880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-05-12 300472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"KiesTrayAgent"="c:\program files\Samsung\Kies\KiesTrayAgent.exe" [2011-11-30 3508624]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe" [2012-08-18 218880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17416880]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Adobe\\Adobe Flash Builder 4.5\\FlashBuilder.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7935:TCP"= 7935:TCP:Adobe Flash Builder 4.5
"1044:TCP"= 1044:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [4/16/2010 3:22 PM 65584]
R1 kltdi;kltdi;c:\windows\system32\drivers\kltdi.sys [6/8/2012 10:38 AM 43608]
R1 kneps;kneps;c:\windows\system32\drivers\kneps.sys [8/13/2012 3:49 PM 144344]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/18/2001 7:00 AM 14336]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [10/6/2012 7:01 AM 399432]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/6/2012 7:01 AM 676936]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [6/27/2012 1:09 PM 35672]
R3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\drivers\klkbdflt.sys [5/25/2012 6:38 PM 24408]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [10/2/2009 6:39 PM 24920]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/6/2012 7:01 AM 22856]
S0 BeTwinVideo;BeTwinVideo;c:\windows\system32\drivers\betwinvf.sys [8/16/2012 3:52 AM 20800]
S1 BeTwinSystem;BeTwinSystem;c:\windows\system32\drivers\betwinsystem.sys [8/16/2012 3:52 AM 13640]
S3 BeTwinKeyboard;BeTwinKeyboard;c:\windows\system32\drivers\betwinkf.sys [8/16/2012 3:52 AM 16192]
S3 BeTwinMouse;BeTwinMouse;c:\windows\system32\drivers\betwinmf.sys [8/16/2012 3:52 AM 16192]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [12/18/2011 9:38 PM 78136]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [12/18/2011 9:38 PM 181432]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 12:37 PM 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
.
2012-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-03 11:06]
.
2012-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-03 11:06]
.
2012-11-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1292428093-1757981266-682003330-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-11 10:37]
.
2012-11-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1292428093-1757981266-682003330-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-11 10:37]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://win8.microsoft.com
uInternet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Anti-Banner - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2013\ie_banner_deny.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{F69E475D-D94F-43AF-AE7B-DE24AB6DEFF8}: NameServer = 200.74.244.126,8.8.8.8
DPF: {6416C78A-E810-445C-8712-1785809FA433} - hxxps://remoteaccess.tdbank.ca/CitrixLogonPoint/TDBFG/EPAClient/EPAClient.exe
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\kvrfbzev.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.questscan.com/?tmp=nemo_results_removelink&prt=QstscanPB&keywords=
FF - ExtSQL: 2012-10-06 09:10; [email protected]; c:\program files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF - ExtSQL: 2012-10-06 09:10; [email protected]; c:\program files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF - ExtSQL: 2012-10-06 09:11; [email protected]; c:\program files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF - ExtSQL: 2012-10-06 09:11; [email protected]; c:\program files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
FF - ExtSQL: 2012-10-06 09:11; [email protected]; c:\program files\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\[email protected]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-11-06 09:45
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_b5e8a4c.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(4580)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\brss01a.exe
c:\program files\Citrix\ICA Client\wfcrun32.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2012-11-06 09:56:52 - machine was rebooted
ComboFix-quarantined-files.txt 2012-11-06 14:56
ComboFix2.txt 2012-10-28 16:46
ComboFix3.txt 2012-10-26 13:28
.
Pre-Run: 35,178,291,200 bytes free
Post-Run: 35,192,471,552 bytes free
.
- - End Of File - - 17757373202E1F5A4AD9A43681D4EA0C