ComboFix 08-08-08.07 - Parent 2008-08-08 19:15:09.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.154 [GMT -4:00]
Running from: C:\Documents and Settings\Parent\My Documents\larryhadalittlelamb\Combo-Fix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Parent\Application Data\macromedia\Flash Player\#SharedObjects\AFBFUEMB\interclick.com
C:\Documents and Settings\Parent\Application Data\macromedia\Flash Player\#SharedObjects\AFBFUEMB\interclick.com\ud.sol
C:\Documents and Settings\Parent\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Parent\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system\oeminfo.ini
C:\WINDOWS\system32\_proxy.dll
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\afinding.exe
C:\WINDOWS\system32\comsa32.sys
C:\WINDOWS\system32\disk.dll
C:\WINDOWS\system32\fhpatch.dll
C:\WINDOWS\system32\IPHOST.dll
C:\WINDOWS\system32\iphy.dll
C:\WINDOWS\system32\IpSvchostF.dll
C:\WINDOWS\system32\maomaochong.exe
C:\WINDOWS\system32\mmchost.dll
C:\WINDOWS\system32\Nobicyt.exe
C:\WINDOWS\system32\riphy.dll
C:\WINDOWS\system32\routing.exe
C:\WINDOWS\system32\tmp0_576143751796.bk
C:\WINDOWS\system32\tmp1_70517412096.bk
C:\WINDOWS\system32\WServing.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AFINDING
-------\Legacy_ROUTING
-------\Legacy_SEICTRL
-------\Legacy_WSERVING
-------\Service_afinding
-------\Service_routing
-------\Service_seictrl
-------\Service_wserving
-------\Legacy_nobicyt
-------\Service_nobicyt
((((((((((((((((((((((((( Files Created from 2008-07-08 to 2008-08-08 )))))))))))))))))))))))))))))))
.
2008-08-08 18:52 . 2008-08-08 18:52 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-08 10:39 . 2003-03-18 17:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-08-08 10:38 . 2008-08-08 10:38 <DIR> d-------- C:\Program Files\Alwil Software
2008-08-08 10:22 . 2008-08-08 10:22 <DIR> d----c--- C:\Deckard
2008-08-07 21:35 . 2008-08-07 19:06 4,598,536 --a------ C:\WINDOWS\system32\syspilog.pil
2008-08-07 21:35 . 2008-08-07 19:06 34,292 --a------ C:\WINDOWS\system32\sss.exe
2008-08-07 19:06 . 2008-08-07 19:06 0 --a------ C:\WINDOWS\system32\39866AC4
2008-07-28 18:08 . 2008-07-28 18:08 8,192 --ahs---- C:\WINDOWS\Thumbs.db
2008-07-24 17:07 . 2008-07-24 19:09 <DIR> d-------- C:\Program Files\Phun
2008-07-20 23:22 . 2008-07-20 23:22 398 --a------ C:\WINDOWS\AudioConverter.INI
2008-07-20 23:17 . 2008-07-20 23:22 <DIR> d----c--- C:\AudioConverter
2008-07-20 23:16 . 2008-07-20 23:16 <DIR> d-------- C:\Program Files\easetech
2008-07-20 20:07 . 2008-08-07 20:24 <DIR> d-------- C:\Program Files\Security Task Manager
2008-07-20 20:07 . 2008-08-08 12:50 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-07-19 14:59 . 2008-07-19 14:59 <DIR> d-------- C:\Program Files\Pyra Productions
2008-07-19 14:07 . 2008-07-19 14:10 <DIR> d-------- C:\Program Files\Easy Icon Maker
2008-07-18 17:22 . 2008-07-18 17:22 238 --a------ C:\WINDOWS\Downfall.INI
2008-07-18 16:34 . 2008-07-18 16:34 <DIR> d-------- C:\Program Files\Pivot Stickfigure Animator
2008-07-16 15:16 . 2008-07-16 15:18 <DIR> d-------- C:\Program Files\QuickTime
2008-07-16 15:13 . 2008-07-16 15:13 <DIR> d-------- C:\Program Files\Apple Software Update
2008-07-16 15:13 . 2008-07-16 15:13 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-08 16:55 --------- d-----w C:\Documents and Settings\Parent\Application Data\DNA
2008-08-08 16:49 --------- d-----w C:\Program Files\Steam
2008-08-07 00:36 24 ----a-w C:\Documents and Settings\Parent\jagex_runescape_preferences.dat
2008-08-06 12:35 --------- d-----w C:\Program Files\McAfee
2008-08-01 21:23 --------- d-----w C:\Program Files\Google
2008-07-16 19:16 --------- dc----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-06 15:37 --------- d-----w C:\Program Files\Rocks'n'Diamonds
2008-07-05 22:34 --------- d-----w C:\Documents and Settings\Parent\Application Data\Teeworlds
2008-07-05 18:12 --------- d-----w C:\Program Files\Image-Line
2008-07-05 18:11 --------- d-----w C:\Program Files\VstPlugins
2008-07-05 18:09 --------- d-----w C:\Program Files\ASIO4ALL v2
2008-07-05 18:07 --------- d-----w C:\Program Files\Outsim
2008-07-04 18:13 --------- dc----w C:\Documents and Settings\All Users\Application Data\NexonUS
2008-07-03 22:33 --------- d-----w C:\Program Files\nbos
2008-07-03 22:33 --------- d-----w C:\Documents and Settings\Parent\Application Data\NBOS
2008-07-03 21:31 --------- d-----w C:\Documents and Settings\Parent\Application Data\.crossfire
2008-07-03 21:30 --------- d-----w C:\Program Files\Crossfire GTK Client
2008-07-03 21:28 --------- d-----w C:\Program Files\Common Files\GTK
2008-07-03 19:47 --------- d-----w C:\Documents and Settings\Parent\Application Data\uk.co.planetside
2008-07-03 19:44 --------- d-----w C:\Program Files\Terragen
2008-06-30 01:19 --------- d-----w C:\Program Files\LEGO Company
2008-06-26 21:32 --------- d-----w C:\Documents and Settings\Parent\Application Data\SPORE Creature Creator
2008-06-26 19:15 --------- d-----w C:\Program Files\Common Files\McAfee
2008-06-26 18:57 --------- d-----w C:\Program Files\Clonk Endeavour
2008-06-26 18:56 --------- d-----w C:\Documents and Settings\Parent\Application Data\Clonk
2008-06-22 03:31 --------- d-----w C:\Program Files\KoolMoves Demo
2008-06-22 00:11 --------- d-----w C:\Program Files\ProcedurallyGeneratedGames
2008-06-20 21:33 --------- dc----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-20 21:33 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-06-20 21:33 --------- d-----w C:\Documents and Settings\Parent\Application Data\Malwarebytes
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 21:48 34,296 ----a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-19 21:47 17,144 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-06-19 02:04 --------- d--h--r C:\Documents and Settings\Parent\Application Data\SecuROM
2008-06-19 02:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-19 02:02 --------- d-----w C:\Program Files\Electronic Arts
2008-06-16 22:44 --------- d-----w C:\Documents and Settings\Parent\Application Data\IEPro
2008-06-16 22:05 --------- d-----r C:\Documents and Settings\Parent\Application Data\SpaceTime 3D
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 03:08 --------- d-----w C:\Program Files\Audacity
2008-06-12 15:09 --------- d-----w C:\Program Files\PyraProductions
2008-06-12 14:43 --------- d-----w C:\Program Files\Install Creator
2008-06-10 18:32 --------- d-----w C:\Program Files\Framsticks
2008-06-06 23:51 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2008-06-06 23:51 139,264 ----a-w C:\WINDOWS\War3Unin.exe
2008-06-04 14:50 185,344 ----a-w C:\WINDOWS\patchw32.dll
2008-05-29 02:05 5,607 ----a-w C:\WINDOWS\~GLH0000.TMP
2008-05-29 02:05 155,136 ----a-w C:\WINDOWS\~GLC0000.TMP
2007-08-12 01:04 32 -c--a-r C:\Documents and Settings\All Users\hash.dat
2000-02-02 00:01 40,960 --sh--r C:\WINDOWS\system32\KarnaDrv.dll
.
------- Sigcheck -------
Cryptography Services Error !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25D596E9-BD03-4D4A-8310-5DF3B31E8D26}]
2008-07-31 16:58 184816 --a----t- C:\Program Files\Google\Update\1.2.121.17\GoopdateBho.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-10-30 11:01 392832]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-08 08:17 289088]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]
"Steam"="c:\program files\steam\steam.exe" [2008-04-19 19:12 1271032]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 08:00 15360]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2008-06-13 18:27 2752512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MVS Splash"="C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe" [2008-01-22 23:09 468288]
"McAfee Managed Services Tray"="C:\Program Files\McAfee\Managed VirusScan\Agent\StartMyagtTry.exe" [2008-01-22 23:09 87360]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-25 09:57 185896]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 10:38 78008]
"RTHDCPL"="RTHDCPL.EXE" [2002-12-31 08:00 16049664 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.JDCT"= jl_jdct.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"=
"C:\\Program Files\\Java\\jre1.5.0_12\\bin\\javaw.exe"=
"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
"C:\\Program Files\\BYOND\\bin\\byond.exe"=
"C:\\Program Files\\BYOND\\bin\\dreamseeker.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\SecondLife\\SecondLife.exe"=
"C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"C:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Documents and Settings\\Parent\\My Documents\\BurningSand2.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\IEPro\\MiniDM.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\Nexon\Combat Arms\CombatArms.exe"= C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe"= C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\\Nexon\\Combat Arms\\NMService.exe"=
S1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 10:35]
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 10:37]
S2 EngineServer;EngineServer;C:\Program Files\McAfee\Managed VirusScan\VScan\EngineServer.exe [2007-12-01 12:30]
S2 gupdate1c8e20299b95e4;Google Update Service (gupdate1c8e20299b95e4);C:\Program Files\Google\Update\GoogleUpdate.exe [2008-07-09 16:25]
S2 macidwe;macidwe Service;C:\WINDOWS\system32\macidwe.exe [2002-12-31 08:00]
S2 myAgtSvc;McAfee Virus and Spyware Protection Service;C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [2008-01-22 23:09]
S2 perfs;perfs Service;C:\WINDOWS\system32\perfs.exe [2002-12-31 08:00]
S2 sobicyt;sobicyt Service;C:\WINDOWS\system32\sobicyt.exe [2002-12-31 08:00]
S2 tdxdowkc;tdxdowkc Service;C:\WINDOWS\system32\tdxdowkc.exe [2002-12-31 08:00]
S3 GameConsoleService;GameConsoleService;C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe [2007-08-28 19:06]
S3 JL2005C;Dual Mode Camera;C:\WINDOWS\system32\Drivers\jl2005c.sys [2007-02-14 21:03]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{10a77790-f28e-11db-b04b-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6cba5d2d-f4cd-11db-b3ec-806d6172696f}]
\Shell\AutoRun\command - D:\ltree\autorun\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e63f5ad-087b-11dc-9ac1-806d6172696f}]
\Shell\AutoRun\command - D:\ltree\autorun\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e9323aad-f3fe-11db-b907-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec46b1ad-19d1-11dc-ad3e-806d6172696f}]
\Shell\AutoRun\command - D:\ltree\autorun\autorun.exe
.
Contents of the 'Scheduled Tasks' folder
2008-07-16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-08 C:\WINDOWS\Tasks\GoogleUpdateTask.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2008-07-09 16:25]
2007-12-07 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-01-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-08 C:\WINDOWS\Tasks\User_Feed_Synchronization-{39641254-8A6A-478E-82B4-A0803A7A90E2}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 11:58]
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{E60A0B68-2F3C-A1D2-A901-9381E036D21A} - C:\WINDOWS\system32\Karna2Drv.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Parent\Application Data\Mozilla\Firefox\Profiles\kq4wounh.default\
FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - C:\Program Files\BYOND\bin\npbyond.dll
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\Google\Lively\nplively.dll
FF -: plugin - C:\Program Files\Google\Update\1.2.121.17\npGoogleOneClick.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbyond.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-08 19:26:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
.
**************************************************************************
.
Completion time: 2008-08-08 19:40:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-08 23:39:57
Pre-Run: 34,539,421,696 bytes free
Post-Run: 34,457,366,528 bytes free
260 --- E O F --- 2008-07-18 15:25:45
Combofix's file. Going to post Hijackthis' in a second.