[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3B7F8709-6366-4025-8CD2-7C79C8A00239}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{32C3E4DF-49F1-4653-8EDE-41BB8456CF60}"= UDP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{D03FABDA-5584-4DA7-8C6E-1BCF8426072D}"= TCP:c:\program files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{FED71BD6-39CA-43B6-8316-41BEC288DFD5}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{775C15B2-4385-42CA-91C7-4264A4AF282F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A109EA17-330B-421E-AE48-87773CF5C90B}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{71AE2D43-6567-437F-BB44-4DAAD39CDCEC}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{1359579D-D3ED-4534-A7F6-01AB0FCF3568}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{9FC54113-4CE7-4489-938F-415505611D5B}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{7413D919-3DCD-4B4A-83F7-582BD2964607}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{618A153E-47AE-44D7-87B9-93C2E5ED8F96}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{1720A24D-E37F-472F-895A-8E8ED55CAC1C}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{2B67DCD0-F19D-4D96-A41D-A8820ECD10B4}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"{33AA5C77-B7D9-4F1E-8177-0DA12E37970E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B37FE9B2-3B31-4389-9E79-7E43EAFEF284}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{8305F09F-843C-4459-9A1E-C0203D32F993}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{75495040-A1EE-467F-B2B3-EDE2975F1A73}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{D34D19DA-D6A2-4874-AE27-E4989B9B1C5E}"= UDP:86:BroadCam Web Server
"{8A02FB6E-68DB-4B70-A4B4-294A4D08FDA6}"= TCP:67
HCP Discovery Service
"{07BE147A-A03C-4A4A-99D0-8BFA25BD8F0E}"= TCP:67
HCP Discovery Service
"{26446228-E7A8-41B2-BA4B-9A0F943872A3}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{71F73568-6AD1-45A3-986E-70FFE06337A2}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"TCP Query User{14C789C1-0176-433A-9120-BAAE76B2043C}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{B09B9456-E149-469F-B6A3-C242FE788816}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{C786E933-5D6B-40B0-8B49-9EE2685E405D}c:\\program files\\soulseek\\slsk.exe"= UDP:c:\program files\soulseek\slsk.exe:SoulSeek
"UDP Query User{40481033-C6DE-4AD0-9A69-D88746BDBADF}c:\\program files\\soulseek\\slsk.exe"= TCP:c:\program files\soulseek\slsk.exe:SoulSeek
"TCP Query User{6BDC2699-4022-446F-9573-76BCD38C1827}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{139E57B7-05EA-4D0E-AFBA-D0B446AD8DA0}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{453C1F4C-9628-456E-BF89-059B43AC54CF}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{FC31940F-E8AB-47DB-BCBA-3591E6141DA0}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{01B75D8C-1514-4BB1-A164-D88C1F63F8B8}"= UDP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe
ure Networks Network Magic Service
"{7738A8D3-C634-419E-B354-7AD8C87B55F8}"= TCP:c:\program files\Pure Networks\Network Magic\nmsrvc.exe
ure Networks Network Magic Service
"TCP Query User{A10CC4E0-294E-4F23-BDFC-F6EEB1A81DBC}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{6AB54B2C-53EA-492A-89F6-83709F50144F}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{E07578C3-C878-4600-9C2A-C084C9CFCD82}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C70F6B90-400D-4D55-80A1-0380D525E2D0}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4B16F088-F94A-436C-990B-04EDA0142517}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D0CC7B81-9C13-4456-8C40-6ABFE340BFCD}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{41BA362D-CE89-42FB-BCC2-0AE098F4D204}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{4B2E0EA1-073C-4BEE-B848-2859630A70D5}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{DD556CDE-79E9-4251-8D02-A691A9C04D9A}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{C70CAED8-4E17-44A8-B2D8-CF43494EA91A}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{AC7EC220-3916-4FAB-959F-9A67AA5C3673}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{26595EB5-C300-4CA5-BFFB-4F1A5B03DC6B}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{8B14D1A2-D8D2-448D-84B9-19E58A2771E1}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{BA561D42-0282-45E7-BDB1-984E3A879C7A}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= c:\toshiba\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\toshiba\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"= c:\program files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"= c:\program files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit
R3 EyelineService;Eyeline Service;c:\program files\NCH Software\Eyeline\eyeline.exe [2008-01-06 425988]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
R3 TpChoice;Touch Pad Detection Filter driver; [x]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-06-10 34312]
S1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\DRIVERS\tmlwf.sys [2007-09-18 141840]
S2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-06-10 468224]
S2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\DRIVERS\tmwfp.sys [2007-09-18 228368]
S2 WXRSS;TVTonic RSS;c:\program files\Wavexpress\TVTonic\WXRSS.exe [2008-08-02 142336]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - IPNAT
.
Contents of the 'Scheduled Tasks' folder
2009-04-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3635030261-218505837-1128197117-1000.job
- c:\users\Brundrett\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-02 20:20]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
MSConfigStartUp-NDSTray - NDSTray.exe
MSConfigStartUp-TOSCDSPD - TOSCDSPD.EXE
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyServer = 142.150.238.13:3124
uInternet Settings,ProxyOverride = *.local
LSP: c:\windows\system32\wpclsp.dll
FF - ProfilePath - c:\users\Brundrett\AppData\Roaming\Mozilla\Firefox\Profiles\iurzkuxa.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\users\Brundrett\AppData\Roaming\Mozilla\Firefox\Profiles\iurzkuxa.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll
FF - component: c:\users\Brundrett\AppData\Roaming\Mozilla\Firefox\Profiles\iurzkuxa.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayFormSubmitObserver.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\np32dsw.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npDivxPlayerPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npnul32.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 3\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\users\Brundrett\AppData\Local\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\users\Brundrett\AppData\Roaming\Mozilla\Firefox\Profiles\iurzkuxa.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-16 15:13
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\CMI-CreateHive{274AB9BD-5778-42E7-84B9-863B8D8DF87A}\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(732)
c:\windows\system32\psqlpwd.dll
c:\program files\Protector Suite QL\homefus2.dll
c:\program files\Protector Suite QL\infra.dll
- - - - - - - > 'Explorer.exe'(2660)
c:\program files\Protector Suite QL\farchns.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Pure Networks\Network Magic\nmrsrc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\audiodg.exe
c:\program files\Protector Suite QL\upeksvr.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\toshiba\IVP\ISM\pinger.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\System32\TODDSrv.exe
c:\program files\Toshiba\Power Saver\TosCoSrv.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-04-16 15:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-16 19:19
Pre-Run: 30,963,372,032 bytes free
Post-Run: 30,811,312,128 bytes free
444 --- E O F --- 2009-04-15 22:16