All right Phil!
Here we go....
ComboFix 09-09-01.04 - Rachel 09/01/2009 19:56.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.446.200 [GMT -5:00]
Running from: c:\documents and settings\Rachel\Desktop\Bunnyfix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\15977394
c:\documents and settings\All Users\Application Data\15977394\15977394
c:\documents and settings\All Users\Application Data\15977394\15977394.exe
c:\documents and settings\All Users\Application Data\15977394\pc15977394ins
c:\documents and settings\All Users\Application Data\esacomub.inf
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Rachel\Cookies\josi.pif
c:\recycler\NPROTECT
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Fonts\HELSM___.TTF
c:\windows\Fonts\INK2METR.TTF
c:\windows\Fonts\OPUSM___.TTF
c:\windows\Installer\18c019.msp
c:\windows\Installer\20a96.msi
c:\windows\patch.exe
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\dahovibo.dll
c:\windows\system32\delejome.dll
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\kbiwkmmetjimqx.sys
c:\windows\system32\hatakuvu.dll
c:\windows\system32\kbiwkmbvsmrril.dll
c:\windows\system32\kbiwkmjklypdur.dll
c:\windows\system32\kbiwkmldyiuwyr.dat
c:\windows\system32\kbiwkmxvakcdpq.dat
c:\windows\system32\lolapeva.dll
c:\windows\system32\mdm.exe
c:\windows\system32\naluwota.dll
c:\windows\system32\nepusenu.dll
c:\windows\system32\simejufa.dll
c:\windows\system32\tapi.nfo
c:\windows\system32\terovozo.dll
c:\windows\system32\tuviloko.exe
c:\windows\system32\volosejo.dll
c:\windows\system32\vovugesi.dll
c:\windows\system32\wisdstr.exe
c:\windows\system32\yavayusa.dll
----- BITS: Possible infected sites -----
hxxp://82.98.231.97
c:\windows\system32\drivers\beep.sys . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ANTIPPRO2009_100
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_AntipPro2009_100
-------\Service_kbiwkmbqvmttap
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.
2009-09-02 00:19 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-02 00:19 . 2009-09-02 00:19 -------- d-----w- C:\ILU
2009-09-02 00:19 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-01 22:43 . 2009-09-01 22:43 -------- d---a-w- C:\KILLBAD
2009-09-01 02:48 . 2009-09-01 12:21 -------- d-----w- C:\suckmydick
2009-09-01 00:43 . 2009-09-01 00:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-09-01 00:35 . 2009-09-01 00:35 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-09-01 00:18 . 2009-09-01 00:18 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Identities
2009-08-31 06:48 . 2009-08-31 06:48 -------- d---a-w- C:\PKBOO
2009-08-31 05:55 . 2009-08-31 05:55 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-08-31 05:25 . 2009-08-31 05:25 -------- d-----w- c:\program files\CCleaner
2009-08-31 03:49 . 2009-08-31 03:49 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-08-31 03:07 . 2009-08-31 03:07 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-31 02:36 . 2009-08-31 02:36 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-23 00:13 . 2009-08-23 00:13 -------- d-----w- c:\documents and settings\All Users\Application Data\TVU Networks
2009-08-23 00:12 . 2009-08-23 00:13 -------- d-----w- c:\program files\TVUPlayer
2009-08-20 00:49 . 2009-08-20 00:49 -------- d-----w- c:\documents and settings\Rachel\fontconfig
2009-08-20 00:41 . 2009-08-31 05:00 -------- d-----w- c:\program files\MPlayer for Windows
2009-08-20 00:12 . 2009-08-20 00:12 -------- d-----w- c:\program files\Common Files\NSV
2009-08-15 01:23 . 2009-08-15 01:24 -------- d-----w- C:\REPSPL
2009-08-12 02:14 . 2009-08-12 02:15 5519752 ----a-w- c:\documents and settings\Rachel\Application Data\TVU networks\TVU AutoUpgrade\TVUPlayer2.4.7.2.exe
2009-08-11 23:55 . 2009-06-05 07:42 655872 -c----w- c:\windows\system32\dllcache\mstscax.dll
2009-08-08 12:02 . 2009-08-08 12:02 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-08 08:14 . 2009-08-08 08:14 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-08 08:13 . 2009-08-08 08:13 -------- d-----w- c:\program files\MSBuild
2009-08-08 08:13 . 2009-08-08 08:13 -------- d-----w- c:\program files\Reference Assemblies
2009-08-08 08:11 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-08 08:11 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-08 08:11 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-08 08:11 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-08 08:11 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-08 08:11 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-08 08:11 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-08 08:11 . 2009-08-08 08:12 -------- d-----w- C:\a6934de93bf88e0a3bce6630233dd5
2009-08-08 08:02 . 2009-08-08 08:02 -------- d-----w- c:\program files\MSXML 6.0
2009-08-05 09:11 . 2009-08-05 09:11 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-05 08:01 . 2009-08-05 08:01 56972 ---ha-w- c:\windows\system32\mlfcache.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 22:41 . 2009-06-24 01:05 -------- d-----w- c:\program files\McAfee
2009-09-01 22:36 . 2009-06-01 22:35 88576 --sha-w- c:\windows\system32\huverego.dll
2009-09-01 12:56 . 2009-06-01 12:56 49152 --sha-w- c:\windows\system32\ziperame.dll
2009-09-01 06:16 . 2007-12-01 06:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-31 06:55 . 2009-05-31 06:55 209408 --sha-w- c:\windows\system32\luliwedo.dll
2009-08-31 06:55 . 2009-05-31 06:55 209408 --sha-w- c:\windows\system32\wimavapa.dll
2009-08-31 03:31 . 2009-06-28 02:44 -------- d-----w- c:\program files\Windows Media Connect 2
2009-08-31 02:23 . 2009-08-31 02:23 16669 ----a-w- c:\documents and settings\All Users\Application Data\icyw.dat
2009-08-29 22:13 . 2009-06-24 01:27 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-08-15 01:23 . 2009-07-12 13:20 737280 ----a-w- c:\windows\iun6002.exe
2009-08-14 12:33 . 2008-12-27 03:14 -------- d-----w- c:\documents and settings\Rachel\Application Data\uTorrent
2009-08-09 09:20 . 2005-11-18 06:46 74424 ----a-w- c:\documents and settings\Rachel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:11 . 2003-03-31 19:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-28 03:09 . 2006-02-24 20:09 -------- d-----w- c:\documents and settings\Rachel\Application Data\Apple Computer
2009-07-27 23:35 . 2009-07-27 23:34 -------- d-----w- c:\program files\iTunes
2009-07-27 23:34 . 2006-10-04 16:16 -------- d-----w- c:\program files\iPod
2009-07-27 23:33 . 2007-10-22 19:48 -------- d-----w- c:\program files\Common Files\Apple
2009-07-27 23:13 . 2009-07-27 23:13 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-21 00:31 . 2008-12-13 19:37 -------- d-----w- c:\program files\Veetle
2009-07-20 09:04 . 2009-07-20 09:00 -------- d-----w- c:\program files\Image-Line
2009-07-20 09:04 . 2009-07-20 09:04 -------- d-----w- c:\program files\ASIO4ALL v2
2009-07-17 18:55 . 2003-03-31 19:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 10:00 . 2009-01-31 13:00 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-14 04:43 . 2004-08-04 07:56 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-13 07:46 . 2007-12-01 06:27 -------- d-----w- c:\program files\Google
2009-07-13 07:45 . 2006-06-02 20:06 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-12 13:19 . 2009-07-12 13:19 -------- d-----w- c:\program files\Replay Converter
2009-07-03 17:09 . 2005-06-18 05:49 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-30 00:14 . 2009-06-30 00:14 0 ----a-w- c:\windows\nsreg.dat
2009-06-25 08:44 . 2005-06-15 17:50 298496 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:44 . 2003-03-31 19:00 724480 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:44 . 2003-03-31 19:00 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:44 . 2003-03-31 19:00 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:44 . 2003-03-31 19:00 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:44 . 2003-03-31 19:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 00:01 . 2009-06-25 00:01 127872 ----a-w- c:\documents and settings\Rachel\Application Data\Move Networks\uninstall.exe
2009-06-25 00:01 . 2009-06-16 06:35 4183416 ----a-w- c:\documents and settings\Rachel\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-06-25 00:00 . 2009-06-25 00:00 1686272 ----a-w- c:\documents and settings\Rachel\Application Data\Move Networks\MoveMediaPlayerWin_071503000010.exe
2009-06-22 11:34 . 2003-03-31 19:00 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:55 . 2003-03-31 19:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2003-03-31 19:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 06:35 . 2009-06-16 06:35 97144 ----a-w- c:\documents and settings\Rachel\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-12 15:06 . 2009-06-12 15:06 77824 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\ess\bindbins\BindBins.exe
2009-06-12 15:06 . 2009-06-12 15:06 30720 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\fwork\netfw.exe
2009-06-12 15:05 . 2009-06-12 15:05 23510720 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\fwork\dotnetfx.exe
2009-06-12 15:05 . 2009-06-12 15:05 1179648 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140002_adafe\EasyShrx.Dll
2009-06-12 15:05 . 2009-06-12 15:05 114688 ----a-w- c:\documents and settings\All Users\Application Data\Kodak\EasyShareSetup\$Registration\KodakCameraAPI_7.8.20.2.dll
2009-06-12 11:50 . 2003-03-31 19:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:21 . 2003-03-31 19:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:32 . 2003-03-31 19:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-05 07:42 . 2005-11-16 18:40 655872 ----a-w- c:\windows\system32\mstscax.dll
2007-03-09 07:12 . 2007-03-09 07:12 27648 --sha-w- c:\windows\system32\AVSredirect.dll
2009-06-01 12:56 . 2009-06-01 12:56 49152 --sha-w- c:\windows\system32\guderasa.dll
2009-06-01 12:56 . 2009-06-01 12:56 49152 --sha-w- c:\windows\system32\ririzaki.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SweetIM"="c:\program files\Macrogaming\SweetIM\SweetIM.exe" [2006-01-02 40960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-05-22 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-05-22 610304]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-06-25 335872]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2003-07-17 184412]
"Display Settings"="c:\program files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 45056]
"QT4HPOT"="c:\program files\HPQ\One-Touch\OneTouch.EXE" [2003-10-03 106496]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-02 65536]
"RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-07-18 868352]
"SweetIM"="c:\program files\Macrogaming\SweetIM\SweetIM.exe" [2006-01-02 40960]
"OxigenClientAdmin"="c:\program files\Oxigen\bin\Oxigen.exe" [2007-06-23 887264]
"OxigenTrayIcon"="c:\program files\Oxigen\bin\OxiTray.exe" [2007-06-23 557536]
"Google IME Autoupdater"="c:\program files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-04-10 37888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-05-01 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-04-09 1176808]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 158208]
"vamanipetu"="c:\windows\system32\ririzaki.dll" [2009-06-01 49152]
"midalolis"="c:\windows\system32\huverego.dll" [2009-09-01 88576]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
D-Link AirPlus G Wireless Utility.lnk - c:\program files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe [2005-11-17 782412]
D-Link REG Utility.lnk - c:\program files\D-Link\AirPlus G Wireless Adapter Utility\Reg.exe [2005-11-17 24576]
FirePod Control Panel.lnk - c:\program files\PreSonus\1394AudioDriver_FirePod\FirePod.exe [2008-12-2 1126400]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-5-10 282624]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{c3ee902a-027d-4d77-829b-1697267ddd6c}"= "c:\windows\system32\huverego.dll" [2009-09-01 88576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"metotozon"= {c3ee902a-027d-4d77-829b-1697267ddd6c} - c:\windows\system32\huverego.dll [2009-09-01 88576]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HPQ\\Notebook Utilities\\HPWirelessCfg.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Oxigen\\bin\\OxiProc.exe"=
"c:\\Program Files\\uusee\\UUSeePlayer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\StreamTorrent 1.0\\StreamTorrent.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\explorer.exe"=
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [6/23/2009 8:11 PM 203280]
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;c:\windows\system32\drivers\caliaud.sys [11/16/2005 1:53 PM 291328]
R3 CALIHALA;CALIHALA;c:\windows\system32\drivers\calihal.sys [11/16/2005 1:53 PM 244608]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;c:\windows\system32\drivers\DP83815.sys [7/16/2003 9:01 PM 28280]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?]
S3 W35UND;IS89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\drivers\W35UND.SYS [9/12/2006 5:18 PM 117632]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-01 23:47]
2009-07-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-24 13:57]
2009-08-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-24 13:57]
.
- - - - ORPHANS REMOVED - - - -
BHO-{19c97a07-5c6d-464d-8765-8d59d54aa792} - c:\windows\system32\nepusenu.dll
HKLM-Run-CPM5b294dbd - c:\windows\system32\lolapeva.dll
SafeBoot-mfehidk
SafeBoot-mferkdk
SafeBoot-mfetdik
SafeBoot-mfetdik.sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\Rachel\Application Data\Mozilla\Firefox\Profiles\0bpq0kpp.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Rachel\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJPI142.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPOJI610.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-01 20:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????9?7?7?0??????? ?deB???????????????B? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\kbiwkmbqvmttap]
"imagepath"="\systemroot\system32\drivers\kbiwkmmetjimqx.sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\kbiwkmbqvmttap]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\kbiwkmmetjimqx.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1348)
c:\windows\system32\WININET.dll
c:\program files\Macrogaming\SweetIM\mgAdaptersProxy.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\ririzaki.dll
c:\windows\system32\huverego.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\HPConfig.exe
c:\program files\HPQ\Notebook Utilities\HPWirelessMgr.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\windows\system32\MsPMSPSv.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-09-02 20:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-02 01:29
Pre-Run: 14,684,491,776 bytes free
Post-Run: 14,734,770,176 bytes free
346 --- E O F --- 2009-08-27 08:01