Edited: Here's the RougeKiller report
RogueKiller V6.1.1 [09/28/2011] by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-to...-Remontees.html
Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Flor [Admin rights]
Mode: Scan -- Date : 10/02/2011 15:18:22
Bad processes: 3
[SUSP PATH] 375815461:3665992169.exe -- c:\windows\375815461:3665992169.exe -> KILLED [TermProc]
[SUSP PATH] 0.9951517197561167.exe -- c:\windows\temp\0.9951517197561167.exe -> KILLED [TermProc]
[RESIDUE] 375815461:3665992169.exe -- c:\windows\375815461:3665992169.exe -> KILLED [TermProc]
Registry Entries: 2
[SUSP PATH] setup_9.0.0.722_02.10.2011_20-49.lnk : C:\Documents and Settings\Flor\Desktop\Virus Removal Tool\setup_9.0.0.722_02.10.2011_20-49\startup.exe -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
Particular Files / Folders:
Driver: [LOADED]
SSDT[277] : NtWriteVirtualMemory @ 0x805B43CC -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BAB52)
SSDT[267] : NtUnmapViewOfSection @ 0x805B2E48 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BE552)
SSDT[258] : NtTerminateThread @ 0x805D2BDC -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA9C8)
SSDT[257] : NtTerminateProcess @ 0x805D29E2 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BAA68)
SSDT[255] : NtSystemDebugControl @ 0x806180BA -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BDA3E)
SSDT[254] : NtSuspendThread @ 0x805D48F4 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BEA2A)
SSDT[253] : NtSuspendProcess @ 0x805D4A82 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BE8F0)
SSDT[247] : NtSetValueKey @ 0x80622662 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B9816)
SSDT[240] : NtSetSystemInformation @ 0x8060FD06 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BE7FE)
SSDT[237] : NtSetSecurityObject @ 0x805C062E -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BDDAA)
SSDT[230] : NtSetInformationToken @ 0x805FA7B4 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BD154)
SSDT[213] : NtSetContextThread @ 0x805D173A -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BAE38)
SSDT[210] : NtSecureConnectPort @ 0x805A3D64 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BBB0E)
SSDT[207] : NtSaveKey @ 0x80625BCC -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B8EAE)
SSDT[206] : NtResumeThread @ 0x805D49BA -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BEBC8)
SSDT[204] : NtRestoreKey @ 0x80625AD0 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B928E)
SSDT[200] : NtRequestWaitReplyPort @ 0x805A2D76 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BD8B4)
SSDT[195] : NtReplyWaitReceivePort @ 0x805A64B4 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC6F2)
SSDT[194] : NtReplyPort @ 0x805A54EC -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC82C)
SSDT[193] : NtReplaceKey @ 0x806261C4 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B8F16)
SSDT[192] : NtRenameKey @ 0x80623B12 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B9C2C)
SSDT[180] : NtQueueApcThread @ 0x805D1276 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BDFA0)
SSDT[177] : NtQueryValueKey @ 0x80622314 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B999C)
SSDT[167] : NtQuerySection @ 0x805B85E0 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BE6AE)
SSDT[161] : NtQueryMultipleValueKey @ 0x8062323E -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B9D72)
SSDT[160] : NtQueryKey @ 0x80625810 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA13A)
SSDT[128] : NtOpenThread @ 0x805CB6CC -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA7BE)
SSDT[126] : NtOpenSemaphore @ 0x80615148 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC4C8)
SSDT[125] : NtOpenSection @ 0x805AA3EC -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BE10E)
SSDT[122] : NtOpenProcess @ 0x805CB440 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA8CC)
SSDT[120] : NtOpenMutant @ 0x80617776 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC288)
SSDT[119] : NtOpenKey @ 0x806254CE -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B96C0)
SSDT[116] : NtOpenFile @ 0x8057A1A6 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BB016)
SSDT[114] : NtOpenEvent @ 0x8060F04E -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC3A8)
SSDT[111] : NtNotifyChangeKey @ 0x806262DE -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA1CE)
SSDT[108] : NtMapViewOfSection @ 0x805B203A -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BE374)
SSDT[99] : NtLoadKey2 @ 0x80625F20 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B94EE)
SSDT[98] : NtLoadKey @ 0x80626314 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B94DC)
SSDT[97] : NtLoadDriver @ 0x80584160 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BDC0C)
SSDT[84] : NtFsControlFile @ 0x805792A2 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BB500)
SSDT[73] : NtEnumerateValueKey @ 0x80624BA6 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA0A2)
SSDT[71] : NtEnumerateKey @ 0x8062493C -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA00A)
SSDT[68] : NtDuplicateObject @ 0x805BE008 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BED26)
SSDT[66] : NtDeviceIoControlFile @ 0x8057926E -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BB6F2)
SSDT[65] : NtDeleteValueKey @ 0x8062475C -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B9EBE)
SSDT[63] : NtDeleteKey @ 0x8062458C -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B9B0A)
SSDT[57] : NtDebugActiveProcess @ 0x80643B30 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BDB1A)
SSDT[56] : NtCreateWaitablePort @ 0x805A5110 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC162)
SSDT[53] : NtCreateThread @ 0x805D1018 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BAC1C)
SSDT[51] : NtCreateSemaphore @ 0x8061504E -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC432)
SSDT[50] : NtCreateSection @ 0x805AB3C8 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA426)
SSDT[46] : NtCreatePort @ 0x805A50EC -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC0CC)
SSDT[44] : NtCreateNamedPipeFile @ 0x805790E2 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA27E)
SSDT[43] : NtCreateMutant @ 0x8061769E -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC1F8)
SSDT[41] : NtCreateKey @ 0x806240F0 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13B9500)
SSDT[37] : NtCreateFile @ 0x805790A8 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BB270)
SSDT[35] : NtCreateEvent @ 0x8060EF4E -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BC312)
SSDT[31] : NtConnectPort @ 0x805A45D0 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BBDC8)
SSDT[25] : NtClose @ 0x805BC530 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BAF94)
SSDT[11] : NtAdjustPrivilegesToken @ 0x805EC464 -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13BA690)
S_SSDT[552] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CACE8)
S_SSDT[549] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CAC90)
S_SSDT[529] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CB698)
S_SSDT[502] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CAEEE)
S_SSDT[491] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CAFD2)
S_SSDT[476] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CAE36)
S_SSDT[475] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CADE2)
S_SSDT[460] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CAE8E)
S_SSDT[416] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CAD96)
S_SSDT[414] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CB04A)
S_SSDT[383] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CAD4A)
S_SSDT[378] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CAF3C)
S_SSDT[312] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CB2C6)
S_SSDT[307] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CB7E6)
S_SSDT[292] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CB182)
S_SSDT[237] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CB25E)
S_SSDT[227] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CB1EE)
S_SSDT[13] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\3045403drv.sys @ 0xB13CB118)
HOSTS File:
127.0.0.1 localhost
127.0.0.1
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1001namen.com
127.0.0.1 1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
[...]
Finished : << RKreport[1].txt >>
RKreport[1].txt
Also, i ran ComboFix, and this is the log
ComboFix 11-10-02.03 - Flor 10/02/2011 17:17:35.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2558.2160 [GMT -7:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: /killall
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Flor\TrueSight.sys
c:\documents and settings\Flor\WINDOWS
c:\windows\$NtUninstallKB48276$
c:\windows\$NtUninstallKB48276$\2224677766
c:\windows\$NtUninstallKB48276$\628975126\@
c:\windows\$NtUninstallKB48276$\628975126\bckfg.tmp
c:\windows\$NtUninstallKB48276$\628975126\cfg.ini
c:\windows\$NtUninstallKB48276$\628975126\Desktop.ini
c:\windows\$NtUninstallKB48276$\628975126\keywords
c:\windows\$NtUninstallKB48276$\628975126\kwrd.dll
c:\windows\$NtUninstallKB48276$\628975126\L\husioman
c:\windows\$NtUninstallKB48276$\628975126\lsflt7.ver
c:\windows\$NtUninstallKB48276$\628975126\U\00000001.@
c:\windows\$NtUninstallKB48276$\628975126\U\00000002.@
c:\windows\$NtUninstallKB48276$\628975126\U\80000000.@
c:\windows\$NtUninstallKB48276$\628975126\U\80000032.@
c:\windows\iun6002.exe
c:\windows\system32\comct332.ocx
c:\windows\system32\d3d9caps.dat
.
Infected copy of c:\windows\system32\drivers\redbook.sys was found and disinfected
Restored copy from - The cat found it

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_257d6616
-------\Legacy_TrueSight
-------\Service_TrueSight
.
.
((((((((((((((((((((((((( Files Created from 2011-09-03 to 2011-10-03 )))))))))))))))))))))))))))))))
.
.
2011-10-03 00:08 . 2008-04-13 18:40 57600 -c--a-w- c:\windows\system32\dllcache\redbook.sys
2011-10-03 00:08 . 2008-04-13 18:40 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-10-02 22:58 . 2011-10-02 22:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-02 22:58 . 2011-09-01 00:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-02 20:25 . 2011-10-02 23:02 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-10-02 20:06 . 2011-10-02 20:06 -------- d-----w- c:\program files\ESET
2011-10-02 20:06 . 2011-10-02 20:06 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2011-10-02 19:40 . 2007-05-30 12:10 10872 ----a-w- c:\windows\system32\drivers\AvgAsCln.sys
2011-10-02 19:40 . 2011-10-02 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft
2011-10-02 17:32 . 2009-10-22 20:54 37392 ----a-w- c:\windows\system32\drivers\44662672.sys
2011-10-02 17:32 . 2009-09-26 00:59 128016 ----a-w- c:\windows\system32\drivers\44662671.sys
2011-10-02 06:03 . 2011-10-02 23:40 -------- d-----w- c:\documents and settings\Administrator
2011-10-01 21:40 . 2011-10-01 21:40 784 ----a-w- c:\windows\trz11.tmp
2011-09-09 04:05 . 2011-09-29 01:51 -------- d-----w- c:\program files\Bookshelf
2011-09-09 04:04 . 2011-09-09 04:04 249856 ------w- c:\windows\Setup1.exe
2011-09-09 04:04 . 2011-09-09 04:04 73216 ----a-w- c:\windows\ST6UNST.EXE
2011-09-09 03:27 . 2011-09-09 03:27 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-09 03:21 . 2011-09-02 23:26 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-09-09 03:21 . 2011-09-02 23:26 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-09-03 10:17 . 2011-09-09 09:12 599040 -c----w- c:\windows\system32\dllcache\crypt32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2004-08-04 10:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-08-09 20:57 . 2011-08-09 20:57 154136 ----a-w- c:\windows\system32\drivers\eamon.sys
2011-08-04 16:20 . 2011-08-04 16:20 103112 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2011-08-04 16:20 . 2011-08-04 16:20 118104 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2011-07-15 13:29 . 2004-08-04 10:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2004-08-04 10:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-09-03 06:01 . 2011-03-15 00:47 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="c:\program files\Ares\Ares.exe" [2009-09-14 3062272]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-03-15 399224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-02 1392640]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-08-10 3076144]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-09-01 449608]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
2009-09-14 17:33 3062272 ----a-w- c:\program files\Ares\Ares.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BestPopUpKiller]
2005-03-04 19:53 245760 ----a-w- c:\program files\BestPopUpKiller\BestPopupKiller.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2005-10-28 23:25 94208 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2006-11-02 03:48 1392640 ----a-w- c:\windows\system32\WLTRAY.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HistoryKill]
2005-03-29 07:02 252416 ----a-w- c:\program files\HistoryKill\histkill.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 22:33 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2007-10-25 23:33 563984 ----a-w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2007-10-25 23:37 2178832 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 17:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 00:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-03-25 00:30 282624 ----a-w- c:\windows\stsystra.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-12 06:12 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-03-08 19:48 761947 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2011-03-15 17:45 399224 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 0 (0x0)
"AllowInboundMaskRequest"= 0 (0x0)
"AllowInboundRouterRequest"= 0 (0x0)
"AllowOutboundDestinationUnreachable"= 0 (0x0)
"AllowOutboundSourceQuench"= 0 (0x0)
"AllowOutboundParameterProblem"= 0 (0x0)
"AllowOutboundTimeExceeded"= 0 (0x0)
"AllowRedirect"= 0 (0x0)
"AllowOutboundPacketTooBig"= 0 (0x0)
.
R0 44662672;44662672 Boot Guard Driver;c:\windows\system32\drivers\44662672.sys [10/2/2011 10:32 AM 37392]
R1 44662671;44662671;c:\windows\system32\drivers\44662671.sys [10/2/2011 10:32 AM 128016]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/2/2011 3:58 PM 366152]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/2/2011 3:58 PM 22216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 3:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - IPFILTERDRIVER
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page = https://login.live.c...bcxt=mai&snsc=1
mStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 206.13.28.12 206.13.31.12
FF - ProfilePath - c:\documents and settings\Flor\Application Data\Mozilla\Firefox\Profiles\yd5zviro.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-facemoods - c:\program files\facemoods.com\facemoods\1.4.17.5\facemoodssrv.exe
MSConfigStartUp-Software Informer - c:\program files\Software Informer\softinfo.exe
AddRemove-Product_Name - c:\windows\iun6002.exe
AddRemove-Silvestri_2009 - c:\windows\iun6002.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-02 17:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(3852)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Ahead\lib\NeroDigitalExt.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\Ati2evxx.exe
.
**************************************************************************
.
Completion time: 2011-10-02 17:42:46 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-03 00:42
.
Pre-Run: 49,586,601,984 bytes free
Post-Run: 49,969,221,632 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - C3279630DFA71D69AD0AD4DEFDED883F
Edited by siddharta, 02 October 2011 - 06:48 PM.