SmitFraudFix v2.228
Scan done at 18:58:16.87, Mon 09/24/2007
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\msmdev.dll Deleted
Deleting [HKEY_CLASSES_ROOT\CLSID\{CEA7C5F8-89AC-43F5-82F0-6731BC037B63}]
C:\WINDOWS\msmhost.dll Deleted
Deleting [HKEY_CLASSES_ROOT\CLSID\{6196A80E-8472-4E0C-BB7E-E972DB8D375F}]
C:\WINDOWS\nsduo.dll Deleted
C:\DOCUME~1\Owner\Desktop\Error Cleaner.url Deleted
C:\DOCUME~1\Owner\Desktop\Privacy Protector.url Deleted
C:\DOCUME~1\Owner\Desktop\Spyware?Malware Protection.url Deleted
C:\DOCUME~1\Owner\FAVORI~1\Error Cleaner.url Deleted
C:\DOCUME~1\Owner\FAVORI~1\Privacy Protector.url Deleted
C:\Program Files\VideoAccessCodec\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{C42DC141-63C6-40BB-99C2-F61657047EB8}: DhcpNameServer=24.93.41.125 24.93.41.126
HKLM\SYSTEM\CS1\Services\Tcpip\..\{C42DC141-63C6-40BB-99C2-F61657047EB8}: DhcpNameServer=24.93.41.125 24.93.41.126
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.93.41.125 24.93.41.126
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.93.41.125 24.93.41.126
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
ComboFix 07-09-21.2 - "Owner" 2007-09-24 19:06:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1396 [GMT -5:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\Mike\Desktop\Error Cleaner.url
C:\DOCUME~1\Mike\Desktop\Privacy Protector.url
C:\DOCUME~1\Mike\Desktop\Spyware&Malware Protection.url
C:\DOCUME~1\Mike\FAVORI~1\Error Cleaner.url
C:\DOCUME~1\Mike\FAVORI~1\Privacy Protector.url
C:\DOCUME~1\Mike\FAVORI~1\Spyware&Malware Protection.url
C:\DOCUME~1\Owner\APPLIC~1\macromedia\Flash Player\#SharedObjects\PDYAH5HL\www.broadcaster.com
C:\DOCUME~1\Owner\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\Owner\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt
.
((((((((((((((((((((((((( Files Created from 2007-08-25 to 2007-09-25 )))))))))))))))))))))))))))))))
.
2007-09-24 19:05 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-24 18:58 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-09-24 17:41 5,038 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-24 17:40 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-09-24 17:40 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-09-24 17:40 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-09-24 17:33 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-24 12:11 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-09-21 19:17 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-09-21 18:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-21 18:19 <DIR> d-------- C:\DOCUME~1\Mike\APPLIC~1\SiteAdvisor
2007-09-21 18:19 <DIR> d-------- C:\DOCUME~1\Mike\APPLIC~1\McAfee
2007-09-21 18:08 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\McAfee
2007-09-21 16:36 341,568 --a------ C:\WINDOWS\system32\mcinsctl.dll
2007-09-21 16:36 277,616 --a------ C:\WINDOWS\system32\mcgdmgr.dll
2007-09-21 16:35 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\SiteAdvisor
2007-09-21 16:33 86,880 --a------ C:\WINDOWS\system32\drivers\WscNetDr.sys
2007-09-21 16:33 <DIR> d-------- C:\Program Files\SiteAdvisor
2007-09-21 16:33 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\SiteAdvisor
2007-09-21 16:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
2007-09-21 16:32 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-09-21 16:32 35,048 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-09-21 16:32 34,120 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2007-09-21 16:32 31,944 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2007-09-21 16:32 168,392 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2007-09-21 16:32 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2007-09-21 16:31 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2007-09-21 16:31 <DIR> d-------- C:\Program Files\McAfee.com
2007-09-21 16:31 <DIR> d-------- C:\Program Files\McAfee
2007-09-21 16:31 <DIR> d-------- C:\Program Files\Common Files\McAfee
2007-09-21 16:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-09-21 16:22 <DIR> d-------- C:\Program Files\PowerISO
2007-09-21 11:53 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Symantec
2007-09-19 14:39 <DIR> d-------- C:\Program Files\iTunes
2007-09-19 14:39 <DIR> d-------- C:\Program Files\iPod
2007-09-19 14:38 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-09-19 14:38 <DIR> d-------- C:\Program Files\Apple Software Update
2007-09-19 14:38 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-24 1rogram Files\Common Files\InstallShield
2007-09-24 1OCUME~1\Owner\APPLIC~1\Apple Computer
2007-09-23 1OCUME~1\Owner\APPLIC~1\uTorrent
2007-09-21 1rogram Files\Common Files\Symantec Shared
2007-09-21 1OCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-09-21 1rogram Files\Symantec
2007-09-20 1OCUME~1\Mike\APPLIC~1\uTorrent
2007-09-19 1rogram Files\QuickTime
2007-09-19 1OCUME~1\Mike\APPLIC~1\Apple Computer
2007-09-19 1OCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-09-06 1rogram Files\Real
2007-08-06 19:15 33052 --a------ C:\WINDOWS\system32\drivers\scdemu.sys
2007-08-06 0rogram Files\InterActual
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-24 2rogram Files\InstallShield Installation Information
2007-06-26 01:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-04-05 12:23 40798696 --a------ C:\Program Files\NAV071420.exe
2007-04-23 16:03:36 80 --sh--r C:\WINDOWS\system32\AA40C398BB.dll
2007-04-17 17:02:58 88 --sh--r C:\WINDOWS\system32\BB98C340AA.sys
2007-04-17 17:03:03 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 14:21 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 08:11]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-09-07 14:35]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 20:43]
"nwiz"="nwiz.exe" [2006-08-11 20:43 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 20:43]
"GalleryPlayerCM"="C:\Program Files\RGB Labs\GalleryPlayer\Assemblies\GalleryPlayerCM.exe" [2006-05-08 17:20]
"GalleryPlayerDM"="C:\Program Files\RGB Labs\GalleryPlayer\Assemblies\GalleryPlayerDM.exe" [2006-05-08 17:20]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 17:30]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-16 20:40]
"Adobe Version Cue CS2"="C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 17:58]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 01:12]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-14 10:00]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-06 19:05]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 15:30]
"MWLExe"="C:\Program Files\Mcafee\MWL\MWLGui.exe" [2007-03-12 11:40]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-01-19 17:11]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2006-10-02 14:09]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2006-11-09 20:34]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2006-11-01 10:35]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2007-05-24 16:00:47]
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
R3 SenFiltService;SenFilt Service;C:\WINDOWS\system32\drivers\Senfilt.sys
S3 SE27bus;Sony Ericsson Device 039 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE27bus.sys
S3 SE27mdfl;Sony Ericsson Device 039 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE27mdfl.sys
S3 SE27mdm;Sony Ericsson Device 039 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE27mdm.sys
S3 SE27mgmt;Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE27mgmt.sys
S3 se27nd5;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS);C:\WINDOWS\system32\DRIVERS\se27nd5.sys
S3 SE27obex;Sony Ericsson Device 039 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE27obex.sys
S3 se27unic;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM);C:\WINDOWS\system32\DRIVERS\se27unic.sys
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-09-21 21:33:49 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-09-21 21:33:48 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-24 19:08:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-24 19:09:56
C:\ComboFix-quarantined-files.txt ... 2007-09-24 19:09
.
--- E O F ---