

LoGiCaL__ wrote:I'm guessing it's windows. A little more info would be nice. Have you tried messing with the pc in safe-mode? Checking to make sure it's not configured to go to a proxy? Have you also gave any scanners a shot?




HKLM\Software\Microsoft\Active Setup\Installed Components\{evNTC15M-TWXn-den4-wwNM-OZRpymfjrgGI}\5Pl92n0RaPnn1Gf: “”%Appdata%\ServiceVBOX.exe” /ActiveX”
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\5Pl92n0RaPnn1Gf: “%Appdata%\ServiceVBOX.exe”
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\5Pl92n0RaPnn1Gf: “%Appdata%\ServiceVBOX.exe”
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: “%Appdata%\ServiceVBOX.exe”
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: “%Appdata%\ServiceVBOX.exe,%WinDir%\System32\userinit.exe,”





ComboFix 12-07-12.02 - TheDarkestHour 07/12/2012 15:49:33.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.191.94 [GMT 1:00]
Running from: c:\documents and settings\TheDarkestHour\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\TheDarkestHour\Application Data\Media Finder\Extensions\IEPLugin32.dll
.
c:\windows\system32\drivers\usbehci.sys . . . is missing!!
.
.
((((((((((((((((((((((((( Files Created from 2012-06-12 to 2012-07-12 )))))))))))))))))))))))))))))))
.
.
2012-07-12 11:41 . 2012-07-12 11:41 -------- d-----w- c:\windows\Sun
2012-07-12 11:34 . 2012-07-12 11:34 -------- d-----w- c:\program files\BabylonToolbar
2012-07-12 11:34 . 2012-07-12 11:35 1492 ----a-w- C:\user.js
2012-07-12 11:34 . 2012-07-12 11:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon
2012-07-12 11:34 . 2012-07-12 11:34 -------- d-----w- c:\documents and settings\TheDarkestHour\Application Data\Babylon
2012-07-12 11:33 . 2012-07-12 11:35 -------- d-----w- c:\documents and settings\TheDarkestHour\Application Data\YourFileDownloader
2012-07-12 11:33 . 2012-07-12 11:33 -------- d-----w- c:\program files\YourFileDownloader
2012-07-12 11:21 . 2012-07-12 11:23 -------- d-----w- c:\documents and settings\TheDarkestHour\Application Data\Media Finder
2012-07-12 11:21 . 2012-07-12 11:23 -------- d-----w- c:\program files\Media Finder
2012-07-06 22:35 . 2012-07-06 22:35 -------- d-----w- c:\documents and settings\TheDarkestHour\Application Data\RBotPlus
2012-07-06 22:35 . 2012-07-06 22:35 -------- d-----w- c:\program files\RBPlus
2012-07-06 22:21 . 2012-07-06 22:21 -------- d-----w- C:\Casino
2012-07-05 23:25 . 2012-06-05 14:10 75096 ----a-w- c:\windows\system32\VBoxDisp.dll
2012-07-05 23:25 . 2012-06-05 14:10 104280 ----a-w- c:\windows\system32\drivers\VBoxVideo.sys
2012-07-05 23:25 . 2012-06-05 14:10 954712 ----a-w- c:\windows\system32\VBoxTray.exe
2012-07-05 23:25 . 2012-06-05 14:10 745816 ----a-w- c:\windows\system32\VBoxControl.exe
2012-07-05 23:25 . 2012-06-05 14:10 108376 ----a-w- c:\windows\system32\drivers\VBoxGuest.sys
2012-07-05 23:25 . 2012-07-05 23:25 -------- dc----w- c:\windows\system32\DRVSTORE
2012-07-05 23:25 . 2012-07-05 23:25 -------- d-----w- c:\program files\Oracle
2012-06-14 10:49 . 2001-08-17 21:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2012-06-14 10:49 . 2001-08-17 21:36 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2012-06-14 10:49 . 2001-08-17 21:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2012-06-14 10:49 . 2001-08-17 21:36 8192 ----a-w- c:\windows\system32\kbdkor.dll
2012-06-14 10:49 . 2001-08-17 13:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2012-06-14 10:49 . 2001-08-17 13:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2012-06-14 10:49 . 2001-08-17 13:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2012-06-14 10:49 . 2001-08-17 13:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2012-06-14 10:49 . 2001-08-17 13:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2012-06-14 10:49 . 2001-08-17 13:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2012-06-14 10:49 . 2008-04-14 04:39 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2012-06-14 10:49 . 2008-04-14 04:39 6144 ----a-w- c:\windows\system32\kbd106.dll
2012-06-14 10:08 . 2012-06-14 10:09 -------- d-----w- c:\documents and settings\TheDarkestHour\Local Settings\Application Data\BearShare
2012-06-14 10:07 . 2012-06-14 10:07 -------- d-----w- c:\documents and settings\All Users\Application Data\BearShare
2012-06-14 10:07 . 2012-06-14 10:07 -------- d-----w- c:\program files\BearShare Applications
2012-06-14 10:07 . 2012-06-14 10:08 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CA469C75-B6C8-4E68-A33B-1230FFA6CFDB}
2012-06-14 10:07 . 2012-06-14 10:07 -------- d-----w- c:\documents and settings\TheDarkestHour\Local Settings\Application Data\PackageAware
2012-06-14 08:38 . 2012-06-14 08:46 -------- d-----w- c:\documents and settings\TheDarkestHour\.frostwire5
2012-06-14 08:37 . 2012-06-14 08:37 -------- d-----w- c:\program files\FrostWire 5
2012-06-14 08:37 . 2012-06-14 08:37 -------- d-----w- c:\program files\Common Files\Java
2012-06-14 08:35 . 2012-06-14 08:32 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-06-14 08:35 . 2012-06-14 08:32 476960 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-06-14 08:35 . 2012-06-14 08:32 472864 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-14 08:31 . 2012-06-14 08:31 -------- d-----w- c:\program files\Java
2012-06-14 08:11 . 2005-02-25 03:35 22752 ----a-w- c:\windows\system32\spupdsvc.exe
2012-06-14 08:08 . 2012-06-14 08:24 -------- d--h--w- c:\windows\$hf_mig$
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 11:33 . 2012-06-09 17:16 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-12 11:33 . 2012-06-09 17:16 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-05 14:10 . 2012-06-05 14:10 745816 ----a-w- c:\windows\system32\VBoxOGLfeedbackspu.dll
2012-06-05 14:10 . 2012-06-05 14:10 483672 ----a-w- c:\windows\system32\VBoxOGLarrayspu.dll
2012-06-05 14:10 . 2012-06-05 14:10 151896 ----a-w- c:\windows\system32\VBoxOGLerrorspu.dll
2012-06-05 14:10 . 2012-06-05 14:10 1380696 ----a-w- c:\windows\system32\VBoxOGLpackspu.dll
2012-06-05 14:10 . 2012-06-05 14:10 115032 ----a-w- c:\windows\system32\VBoxOGLpassthroughspu.dll
2012-06-05 14:10 . 2012-06-05 14:10 1069400 ----a-w- c:\windows\system32\VBoxService.exe
2012-06-05 14:10 . 2012-06-05 14:10 1007960 ----a-w- c:\windows\system32\VBoxOGL.dll
2012-06-05 14:10 . 2012-06-05 14:10 754008 ----a-w- c:\windows\system32\VBoxMRXNP.dll
2012-06-05 14:10 . 2012-06-05 14:10 85848 ----a-w- c:\windows\system32\drivers\VBoxMouse.sys
2012-06-05 14:10 . 2012-06-05 14:10 250200 ----a-w- c:\windows\system32\VBoxOGLcrutil.dll
2012-06-05 14:10 . 2012-06-05 14:10 225112 ----a-w- c:\windows\system32\drivers\VBoxSF.sys
2012-06-05 14:09 . 2012-06-05 14:09 67416 ----a-w- c:\windows\system32\VBoxHook.dll
2012-06-02 14:19 . 2009-08-06 18:24 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2012-06-09 16:25 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2012-06-09 16:25 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2012-06-09 16:25 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2009-08-06 18:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2012-06-09 16:25 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2012-06-09 16:25 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2009-08-06 18:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2009-08-06 18:24 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2008-04-14 04:41 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2009-08-06 18:24 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2012-06-09 16:25 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2012-06-09 16:25 1933848 ----a-w- c:\windows\system32\wuaueng.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Media Finder"="c:\program files\Media Finder\Media Finder.exe" [2012-06-28 8613888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"VBoxTray"="c:\windows\system32\VBoxTray.exe" [2012-06-05 954712]
.
c:\documents and settings\TheDarkestHour\Start Menu\Programs\Startup\
ctfmon.lnk - c:\windows\system32\rundll32.exe [2008-4-14 33280]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FrostWire 5\\FrostWire.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"c:\\Program Files\\YourFileDownloader\\Downloader.exe"=
"c:\\Program Files\\YourFileDownloader\\YourFile.exe"=
.
R0 VBoxGuest;VirtualBox Guest Driver;c:\windows\system32\drivers\VBoxGuest.sys [7/6/2012 12:25 AM 108376]
R1 VBoxSF;VirtualBox Shared Folders;c:\windows\system32\drivers\VBoxSF.sys [6/5/2012 3:10 PM 225112]
R3 VBoxMouse;VirtualBox Guest Mouse Service;c:\windows\system32\drivers\VBoxMouse.sys [6/5/2012 3:10 PM 85848]
S2 VBoxService;VirtualBox Guest Additions Service;system32\VBoxService.exe --> system32\VBoxService.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6/9/2012 6:16 PM 250056]
S3 VBoxVideo;VBoxVideo;c:\windows\system32\drivers\VBoxVideo.sys [7/6/2012 12:25 AM 104280]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-09 11:34]
.
2012-07-12 c:\windows\Tasks\Your File Updater.job
- c:\program files\YourFileDownloader\YourFileUpdater.exe [2012-07-12 11:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.babylon.com/?affID=112555&babsrc=HP_ss&mntrId=b82a7e6d000000000000080027851d2c
IE: Download with &Media Finder - c:\program files\Media Finder\hook.html
TCP: DhcpNameServer = 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-12 15:55
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-12 15:57:40
ComboFix-quarantined-files.txt 2012-07-12 14:57
.
Pre-Run: 7,390,814,208 bytes free
Post-Run: 7,501,234,176 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 2FBC541BD82513F72BFADEF366EF63E7





Users browsing this forum: No registered users and 0 guests