QUOTE (Katana @ Sep 2 2009, 05:35 AM)

A couple of questions for you ...
1) Is this an Office/Work Machine ?
2) Do you know what this file is for ? beep.bat
3) Do you know anything about the Logon scripts showing in your log ?
Hi again Katana,
1) It is a laptop that I use for the company I work for. It is on a domain often, but I have full perms. The only thing I can't do is manually stop TrendMicro, because it is passworded.
2) Beep.bat is nothing; it issues a single dos command. I wrote it myself to reset a data value.
3) The login scripts are for my office mapped network drive. They are safe.
4) "How is it running now?" ... it appears fine, but that is the odd thing about this; I can reboot a few times and it seems to come back. But for the moment, it seems fine.
5) Kaspersky did find a few things that all others missed.
6) This AM I was getting a blue screen (something to do with tcp/ip). I had to choose "use last known configuration", at which time, it booted fine.
Logs you requested:
Add-Remove:7-Zip 4.65
AAC Decoder
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
ALK|FleetSuite Tolls 19
ALK|FleetSuite Tolls Streets 19.0
ALPS Touch Pad Driver
AniTa Terminal
Apple Software Update
AutoUpdate
Avanquest update
BitTorrent
Broadcom Advanced Control Suite
Cisco Systems VPN Client 4.8.00.0440
Command Prompt Here PowerToy
COMODO Internet Security
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
CutePDF Writer 2.7
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
FaxMan SDK V 4.1.2.0
FileSync
Foxit Reader
Fujitsu fi-4120C2
Google Chrome
Google Toolbar for Internet Explorer
GSview 4.8
H.264 Decoder
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix 2055 for SQL Server 2000 ENU (KB960082)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Intel® Graphics Media Accelerator Driver
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 6
Java 6 Update 11
JukeItUp!
Kofax Scan Demo
Kofax TWAIN Data Source
LimeWire PRO 5.0.11
Logitech Harmony Remote Software 7
MagicDisc 2.7.106
Malwarebytes' Anti-Malware
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Basic Edition 2003
Microsoft Office PowerPoint 2003
Microsoft Office Visio Standard 2003
Microsoft Silverlight
Microsoft SQL Server 2005
Microsoft SQL Server 2005 (UC2007)
Microsoft SQL Server 2005 Analysis Services
Microsoft SQL Server 2005 Analysis Services (UC2007)
Microsoft SQL Server 2005 Backward compatibility
Microsoft SQL Server 2005 Books Online (English)
Microsoft SQL Server 2005 Integration Services
Microsoft SQL Server 2005 Notification Services
Microsoft SQL Server 2005 Tools
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft Visual Studio 2005 Premier Partner Edition - ENU
Microsoft Visual Studio 2005 Premier Partner Edition - ENU Service Pack 1 (KB926601)
Microsoft Windows Services for UNIX
Microsoft Works 6-9 Converter
MKV Splitter
Motorola Driver Installation 3.7.0
Motorola Phone Tools
Mozilla Firefox (2.0)
MS Runtime
MSXML 6.0 Parser
NTRU Hybrid TSS v2.0.25
ObjectStore 6.2.1
Paint Shop Pro 7 Try And Buy
POP Peeper
QuickSet
QuickTime
Remote Control USB Driver
Rosetta Stone V3
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Sentinel System Driver
SmartDraw 6
SnagIt 5
SnagIt 9
SQLXML4
Starcraft
Target Context Menu (Remove Only)
Trend Micro OfficeScan Client
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB942763)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.762
VirtualReScan
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VNC Free Edition 4.1.3
VRS Service Pack-1
WebEx
WebFldrs XP
Windows Defender
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
WinPatrol 2008
--------------------------------------------------------------------------------------
Combo FixComboFix 09-09-01.08 - mattd 09/02/2009 17:34.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.434 [GMT -5:00]
Running from: c:\documents and settings\mattd\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mattd\Desktop\CFScript.txt
AV: Trend Micro OfficeScan Antivirus *On-access scanning enabled* (Updated) {806EEB56-F26D-4ADC-9880-7088DDA66B8D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FILE ::
"c:\program files\vnqlxzgb.txt"
file zipped: c:\program files\vnqlxzgb.txt
file zipped: c:\windows\system32\drivers\ntfs.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\vnqlxzgb.txt
.
--------------- FCopy ---------------
c:\windows\ServicePackFiles\i386\ntfs.sys --> c:\windows\system32\drivers\ntfs.sys
.
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.
2009-08-31 20:52 . 2009-08-31 20:52 -------- d-----w- C:\bol
2009-08-30 23:55 . 2009-08-31 04:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2009-08-30 23:55 . 2009-09-01 15:01 179792 ----a-w- c:\windows\system32\guard32.dll
2009-08-30 23:55 . 2009-09-01 15:01 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-08-30 23:55 . 2009-09-01 15:01 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-08-30 23:55 . 2009-09-01 15:01 132168 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-08-30 23:55 . 2009-08-30 23:55 -------- d-----w- c:\program files\COMODO
2009-08-30 03:47 . 2009-08-30 03:47 -------- d-----w- c:\program files\Windows Defender
2009-08-27 12:21 . 2009-09-02 02:30 94016 ----a-w- c:\windows\system32\drivers\agp440.sys
2009-08-27 12:21 . 2009-09-02 02:30 94016 ----a-w- c:\windows\system32\dllcache\agp440.sys
2009-08-27 12:08 . 2009-08-27 12:08 -------- d-----w- c:\documents and settings\mattd\Local Settings\Application Data\Microsoft Help
2009-08-27 11:53 . 2009-08-27 11:54 -------- d-----w- C:\b94fc99b4234241569f8
2009-08-27 11:52 . 2009-08-27 11:55 -------- d-----w- C:\af68abf42d22c0317532447fccccfb74
2009-08-24 01:04 . 2009-08-24 01:22 -------- d-----w- c:\windows\system32\NtmsData
2009-08-23 14:12 . 2009-08-25 17:22 44 ----a-w- c:\windows\system32\statistics.dat
2009-08-23 13:51 . 2009-08-25 17:20 54 ----a-w- c:\windows\system32\rp_stats.dat
2009-08-23 13:51 . 2009-08-25 17:20 39 ----a-w- c:\windows\system32\rp_rules.dat
2009-08-22 17:44 . 2009-08-22 17:44 -------- d-----w- c:\documents and settings\mattd\Application Data\Malwarebytes
2009-08-22 17:44 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 17:44 . 2009-08-22 17:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-22 17:44 . 2009-08-22 17:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 17:44 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 13:23 . 2009-08-31 14:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-18 17:44 . 2009-08-18 17:44 -------- d-----w- c:\program files\Active Data Recovery Software
2009-08-17 19:06 . 2009-08-17 19:06 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-08-17 19:06 . 2009-08-17 19:06 -------- d-----w- c:\documents and settings\mattd\Local Settings\Application Data\TechSmith
2009-08-13 14:45 . 2009-08-13 14:45 -------- d-----w- c:\documents and settings\mattd\$USERHOME
2009-08-13 02:29 . 2009-06-12 12:31 80896 ------w- c:\windows\system32\dllcache\tlntsess.exe
2009-08-13 02:29 . 2009-06-12 12:31 76288 ------w- c:\windows\system32\dllcache\telnet.exe
2009-08-13 02:28 . 2009-06-10 06:14 132096 ------w- c:\windows\system32\dllcache\wkssvc.dll
2009-08-13 02:28 . 2009-06-10 14:13 84992 ------w- c:\windows\system32\dllcache\avifil32.dll
2009-08-13 02:27 . 2009-07-17 19:01 58880 ------w- c:\windows\system32\dllcache\atl.dll
2009-08-13 02:27 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 02:25 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-13 02:24 . 2009-06-25 08:25 54272 ------w- c:\windows\system32\dllcache\wdigest.dll
2009-08-13 02:24 . 2009-06-25 08:25 136192 ------w- c:\windows\system32\dllcache\msv1_0.dll
2009-08-13 02:24 . 2009-06-24 11:18 92928 ------w- c:\windows\system32\dllcache\ksecdd.sys
2009-08-13 02:24 . 2009-06-25 08:25 301568 ------w- c:\windows\system32\dllcache\kerberos.dll
2009-08-10 18:35 . 2009-08-10 18:35 721912 ----a-w- c:\documents and settings\mattd\gotomypc_428.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 21:17 . 2009-03-05 15:47 -------- d-----w- c:\documents and settings\mattd\Application Data\SmartDraw
2009-08-29 02:15 . 2009-04-22 14:11 -------- d-----w- c:\program files\Trend Micro
2009-08-29 00:20 . 2009-03-24 02:24 -------- d-----w- c:\program files\Common Files\Remote Control Software Common
2009-08-27 12:13 . 2007-10-01 21:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-27 12:07 . 2007-10-01 21:14 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-08-26 14:33 . 2006-09-27 08:13 -------- d-----w- c:\program files\CyberLink
2009-08-26 14:33 . 2006-09-27 08:09 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-26 14:32 . 2009-06-11 17:47 -------- d-----w- c:\program files\Citrix
2009-08-25 00:34 . 2009-04-04 04:05 -------- d-----w- c:\documents and settings\mattd\Application Data\BitTorrent
2009-08-17 19:06 . 2009-03-05 22:40 -------- d-----w- c:\program files\TechSmith
2009-08-17 19:03 . 2007-11-20 20:55 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-17 16:09 . 2006-11-13 16:14 -------- d-----w- c:\program files\AniTa
2009-08-05 09:01 . 2004-08-11 22:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 01:03 . 2009-07-28 19:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Rosetta Stone
2009-07-28 20:00 . 2009-07-28 20:00 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-07-28 19:59 . 2009-07-28 19:59 -------- d-----w- c:\program files\Rosetta Stone
2009-07-20 02:45 . 2009-04-08 00:14 -------- d-----w- c:\program files\JukeItUp Ecstasy Edition
2009-07-17 19:01 . 2004-08-11 22:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 23:06 . 2009-07-16 23:06 -------- d-----w- c:\program files\Microsoft Works
2009-07-16 17:16 . 2009-07-16 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2009-07-16 17:13 . 2009-07-16 17:13 -------- d-----w- c:\program files\Avanquest update
2009-07-16 17:13 . 2009-07-16 17:13 -------- d-----w- c:\program files\Motorola Phone Tools
2009-07-13 15:08 . 2004-08-11 22:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2004-08-11 22:00 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-11 22:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-11 22:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-11 22:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-11 22:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-11 22:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-11 22:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-11 22:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-11 22:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-11 22:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-11 22:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-11 22:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 13:40 . 2009-06-16 13:40 1498149 ----a-w- C:\xp32.zip
2009-06-12 12:31 . 2004-08-11 22:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-11 22:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-11 17:46 . 2009-06-11 17:46 60744 ----a-w- c:\documents and settings\mattd\g2mdlhlpx.exe
2009-06-10 14:19 . 2004-08-11 22:11 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-11 22:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2004-08-11 22:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2006-10-11 08:04 . 2006-11-13 16:17 61036 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2006-10-11 08:04 . 2006-11-13 16:17 48742 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2006-10-11 08:05 . 2006-11-13 16:17 29313 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2006-10-11 08:05 . 2006-11-13 16:17 41082 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2006-10-11 08:04 . 2006-11-13 16:17 166510 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-02_02.23.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-02 13:57 . 2009-09-02 13:57 16384 c:\windows\Temp\Perflib_Perfdata_4b0.dat
+ 2004-08-11 22:00 . 2008-04-14 05:45 574976 c:\windows\system32\dllcache\ntfs.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2009-02-18 709928]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-09-01 1796368]
c:\documents and settings\mattd\Start Menu\Programs\Startup\
beep.bat [2009-3-12 13]
POP Peeper.lnk - c:\program files\POP Peeper\POPPeeper.exe [2009-1-21 1470464]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SnagIt 5.lnk - c:\program files\TechSmith\SnagIt\SnagIt32.exe [2009-8-24 1179648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ pswdsync scecli
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-606747145-630328440-1801674531-1124\Scripts\Logon\0\0]
"Script"=xdrivemapping.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-606747145-630328440-1801674531-1124\Scripts\Logon\1\0]
"Script"=xdrivemapping.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-606747145-630328440-1801674531-1167\Scripts\Logon\0\0]
"Script"=connectXDrive.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-606747145-630328440-1801674531-3673\Scripts\Logon\0\0]
"Script"=xdrivemapping.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-606747145-630328440-1801674531-3673\Scripts\Logon\1\0]
"Script"=xdrivemapping.bat
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\RosettaStoneLtdServices.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"<NO NAME>"=
"61153:TCP"= 61153:TCP:Trend Micro OfficeScan Listener
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [8/30/2009 6:55 PM 132168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [8/30/2009 6:55 PM 25160]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [4/6/2009 5:42 PM 8576]
R2 Mapsvc;User Name Mapping;c:\sfu\Mapper\mapsvc.exe [11/8/2003 2:42 PM 111728]
R2 msftesql$UC2007;SQL Server FullText Search (UC2007);c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe [8/26/2005 4:00 PM 92880]
R2 MSOLAP$UC2007;SQL Server Analysis Services (UC2007);c:\program files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe [10/14/2005 3:46 AM 14557912]
R2 MSSQL$UC2007;SQL Server (UC2007);c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe [10/14/2005 3:51 AM 28768528]
R2 RshSvc;Remote Shell Service;c:\sfu\common\rshsvc.exe [11/8/2003 2:46 PM 16800]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\TmXPFlt.sys [11/26/2008 1:42 PM 225296]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [11/26/2008 1:42 PM 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R2 zzInterix;Interix Subsystem Startup;c:\windows\system32\PSXRUN.EXE [11/8/2003 2:45 PM 66480]
R3 Portmap;Portmap;c:\windows\system32\drivers\portmap.sys [11/8/2003 2:42 PM 35072]
R3 PsxDrv;PsxDrv;c:\windows\system32\drivers\PSXDRV.SYS [11/8/2003 2:45 PM 6128]
R3 RpcXdr;RpcXdr;c:\windows\system32\drivers\rpcxdr.sys [11/8/2003 2:42 PM 55872]
S2 InAspi32;InAspi32;c:\windows\system32\drivers\InAspi32.sys [11/19/2007 3:57 PM 8704]
S2 MsDtsServer;SQL Server Integration Services;c:\program files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [10/14/2005 3:45 AM 199384]
S2 ObjectStore Cache Manager R6.0;ObjectStore Cache Manager R6.0;c:\odi\OStore\BIN\OSCMGR6.EXE --> c:\odi\OStore\BIN\OSCMGR6.EXE [?]
S2 ObjectStore Server R6.0;ObjectStore Server R6.0;c:\odi\OStore\BIN\OSSERVER.EXE --> c:\odi\OStore\BIN\OSSERVER.EXE [?]
S2 TmProxy;OfficeScan NT Proxy Service;c:\program files\Trend Micro\OfficeScan Client\TmProxy.exe [2/18/2009 12:27 PM 652552]
S3 bddepsrv;BitDefender Deployment Service;c:\windows\_BDDEP_\bddepsrv.exe [3/4/2009 5:09 PM 118112256]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys --> c:\windows\system32\Drivers\BW2NDIS5.sys [?]
S3 FTSRVR;McLeod Imaging Server;c:\tm\tmsimg\bin\ftsrvrsvc.exe [2/6/2009 10:00 AM 629248]
S3 LME 9.0;LME 9.0;c:\mcleod_900\Win2000_tools\scheduler_service\LMEschedulerService.exe --> c:\mcleod_900\Win2000_tools\scheduler_service\LMEschedulerService.exe [?]
S3 LME 9.1;LME 9.1;c:\mcleod_910\Win2000_tools\scheduler_service\LMESchedulerService.exe [2/4/2009 10:30 AM 32768]
S3 LME Scheduler (demo_820);LME Scheduler (demo_820);c:\mcleod_820\win2000_tools\scheduler_service\lmeschedulerservice.exe --> c:\mcleod_820\win2000_tools\scheduler_service\lmeschedulerservice.exe [?]
S3 SQLAgent$UC2007;SQL Server Agent (UC2007);c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\SQLAGENT90.EXE [10/14/2005 3:51 AM 318680]
S3 tcpsvc;PC*MILER TCP/IP Interface;c:\program files\ALK Technologies\Tolls190\TCPIP\tcpsvc.exe [11/13/2006 4:52 PM 16384]
S4 CronService;Windows Cron Service;c:\sfu\common\cron.exe [11/8/2003 2:46 PM 47536]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [12/2/2006 6:17 AM 2805000]
S4 PerlSock;Perl Socket Service;c:\sfu\Perl\bin\PerlSock.exe [11/8/2003 3:05 PM 225357]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder
2009-09-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {7B133798-FAA8-4A7E-950D-BEB35D3363AF} - hxxp://71.8.85.66:1024/img/LinksysViewer.cab
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-02 17:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\msftesql$UC2007]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe\" -s:MSSQL.2 -f:UC2007"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1348)
c:\windows\system32\guard32.dll
c:\windows\system32\igfxdev.dll
- - - - - - - > 'lsass.exe'(1404)
c:\windows\system32\guard32.dll
c:\windows\system32\pswdsync.dll
.
Completion time: 2009-09-02 17:44
ComboFix-quarantined-files.txt 2009-09-02 22:44
ComboFix2.txt 2009-09-02 02:26
Pre-Run: 26,675,863,552 bytes free
Post-Run: 26,631,495,680 bytes free
246 --- E O F --- 2009-08-27 15:18
--------------------------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, September 2, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, September 03, 2009 00:36:06
Records in database: 2740933
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
X:\
Scan statistics:
Objects scanned: 153916
Threats found: 5
Infected objects found: 11
Suspicious objects found: 0
Scan duration: 03:44:17
File name / Threat / Threats count
C:\Documents and Settings\mattd\My Documents\Utilities\os\dmx10 - touch screen jukebox os.zip Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1
C:\Documents and Settings\mattd\My Documents\Utilities\os\dmx10 - touch screen jukebox os.zip Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Documents and Settings\mattd\My Documents\Utilities\os\nec ready 120lt os.zip Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 3
C:\mcleod_910\Win2000_tools\Install Files\tightvnc-1.2.3-setup.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b 1
C:\mcleod_910\Win2000_tools\tightvnc-1.2.3-setup.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b 1
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ntfs.sys.vir Infected: Virus.Win32.Protector.c 1
C:\Qoobox\Quarantine\[4]-Submit_2009-09-02_17.33.48.zip Infected: Virus.Win32.Protector.c 1
Selected area has been scanned.