Think my desktop PC been infected by bugs/viruses! Any help?
OK now i manage to get combofix to work.
Below is the log:
Quote:
ComboFix 09-01-21.04 - Jay 2009-01-30 20:35:33.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1015.218 [GMT 0:00]
Running from: c:\users\Jay\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Outdated)
FW: Norton 360 *disabled*
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-30 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-01-30 20:13 --------- d-----w c:\programdata\Google Updater
2009-01-30 20:08 --------- d-----w c:\users\Jay\AppData\Roaming\uTorrent
2009-01-30 19:39 --------- d---a-w c:\programdata\TEMP
2009-01-30 16:17 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-30 16:07 --------- d-----w c:\program files\Common Files\Adobe
2009-01-30 10:51 --------- d-----w c:\program files\Spyware Doctor
2009-01-30 10:48 --------- d-----w c:\users\Jay\AppData\Roaming\Malwarebytes
2009-01-30 10:48 --------- d-----w c:\programdata\Malwarebytes
2009-01-30 10:48 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-29 20:07 --------- d-----w c:\program files\trend micro
2009-01-25 19:00 --------- d-----w c:\programdata\FLEXnet
2009-01-25 18:47 --------- d-----w c:\program files\Adobe Media Player
2009-01-25 18:45 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-01-25 18:43 --------- d-----w c:\program files\Common Files\Macrovision Shared
2009-01-24 18:25 --------- d-----w c:\programdata\Access Lock
2009-01-24 18:17 --------- d-----w c:\program files\Access Lock
2009-01-22 10:26 --------- d-----w c:\users\Jay\AppData\Roaming\OpenOffice.org2
2009-01-19 22:20 --------- d-----w c:\programdata\Yahoo! Companion
2009-01-19 22:19 --------- d-----w c:\programdata\Symantec
2009-01-19 22:18 --------- d-----w c:\program files\GetGo Software
2009-01-19 16:16 --------- d-----w c:\users\Jay\AppData\Roaming\Orbit
2009-01-19 15:52 --------- d-----w c:\users\Jay\AppData\Roaming\Megaupload
2009-01-19 15:20 --------- d-----w c:\program files\QuickMediaConverter
2009-01-19 14:25 --------- d-----w c:\users\Jay\AppData\Roaming\GetGo Software
2009-01-19 14:09 --------- d-----w c:\program files\VDOWNLOADER
2009-01-19 14:08 --------- d-----w c:\users\Jay\AppData\Roaming\Desktopicon
2009-01-19 10:44 --------- d-----w c:\users\Jay\AppData\Roaming\DivX
2009-01-19 10:30 --------- d-----w c:\program files\uTorrent
2009-01-19 10:26 --------- d-----w c:\program files\DivX
2009-01-19 10:26 --------- d-----w c:\program files\Common Files\PX Storage Engine
2009-01-14 16:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 16:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-13 13:05 --------- d-----w c:\users\Jay\AppData\Roaming\Notepad++
2009-01-13 11:55 --------- d-----w c:\program files\Notepad++
2009-01-11 18:02 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-01-11 18:02 --------- d-----w c:\program files\Java
2009-01-06 09:15 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 09:15 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 09:15 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-06 09:15 --------- d-----w c:\program files\Symantec
2009-01-03 18:23 --------- d-----w c:\programdata\Yahoo!
2009-01-03 18:23 --------- d-----w c:\program files\Yahoo!
2009-01-03 17:52 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-01 18:04 --------- d-----w c:\users\Jay\AppData\Roaming\Yahoo!
2008-12-20 21:13 --------- d-----w c:\program files\Bonjour
2008-12-20 13:58 174 --sha-w c:\program files\desktop.ini
2008-12-20 13:54 --------- d-----w c:\program files\Windows Mail
2008-12-20 13:52 --------- d-----w c:\programdata\Microsoft Help
2008-12-18 22:39 129 ----a-w C:\DelUS.bat
2008-12-18 22:38 --------- d-----w c:\programdata\PPLiveVA
2008-12-18 22:36 --------- d-----w c:\program files\SwarmPlayer
2008-12-18 22:33 --------- d-----w c:\program files\CoffeeCup Software
2008-12-16 11:41 --------- d-----w c:\users\Jay\AppData\Roaming\PPLiveVA
2008-12-13 17:01 --------- d-----w c:\users\Jay\AppData\Roaming\.SwarmPlayer
2008-12-13 17:00 --------- d-----w c:\users\Jay\AppData\Roaming\.Tribler
2008-12-12 11:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-12-12 11:11 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-12-11 00:33 86,016 ----a-w c:\windows\System32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\System32\dtu100.dll
2008-12-09 02:28 593,920 ----a-w c:\windows\System32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w c:\windows\System32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w c:\windows\System32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w c:\windows\System32\dpu11.dll
2008-12-06 18:15 --------- d-----w c:\program files\WinSCP
2008-11-30 23:07 15,804,416 ----a-w c:\windows\System32\imageres.dll
2008-11-29 21:13 --------- d-----w c:\program files\Safari
2008-11-06 16:37 524,288 ----a-w c:\windows\System32\DivXsm.exe
2008-11-06 16:37 3,596,288 ----a-w c:\windows\System32\qt-dx331.dll
2008-11-06 16:35 200,704 ----a-w c:\windows\System32\ssldivx.dll
2008-11-06 16:35 1,044,480 ----a-w c:\windows\System32\libdivx.dll
2008-11-06 16:33 823,296 ----a-w c:\windows\System32\divx_xx0c.dll
2008-11-06 16:33 823,296 ----a-w c:\windows\System32\divx_xx07.dll
2008-11-06 16:33 815,104 ----a-w c:\windows\System32\divx_xx0a.dll
2008-11-06 16:33 802,816 ----a-w c:\windows\System32\divx_xx11.dll
2008-11-06 16:33 684,032 ----a-w c:\windows\System32\DivX.dll
2008-11-06 16:33 12,288 ----a-w c:\windows\System32\DivXWMPExtType.dll
2008-11-01 03:33 537,600 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:33 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:33 449,536 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:33 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:33 2,144,256 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:33 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 03:33 1,687,040 ----a-w c:\windows\System32\gameux.dll
2008-10-31 23:38 4,247,552 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-31 23:23 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-10-29 06:20 2,923,520 ----a-w c:\windows\explorer.exe
2008-10-22 03:43 95,232 ----a-w c:\windows\System32\PortableDeviceClassExtension.d ll
2008-10-22 03:43 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 03:43 160,768 ----a-w c:\windows\System32\PortableDeviceTypes.dll
2008-10-21 23:31 2,048 ----a-w c:\windows\System32\tzres.dll
2008-10-21 05:16 297,472 ----a-w c:\windows\System32\gdi32.dll
2008-10-21 05:16 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\System32\wuaueng.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\System32\wuapi.dll
2008-10-16 21:09 51,224 ----a-w c:\windows\System32\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w c:\windows\System32\wups2.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\System32\wups.dll
2008-10-16 20:56 1,524,736 ----a-w c:\windows\System32\wucltux.dll
2008-10-16 20:55 83,456 ----a-w c:\windows\System32\wudriver.dll
2008-10-16 14:08 162,064 ----a-w c:\windows\System32\wuwebv.dll
2008-05-15 20:39 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Lo cal\Microsoft\Windows\History\History.IE5\index.da t
2008-05-15 20:39 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Lo cal\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-05-15 20:39 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Ro aming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"Nero PhotoShow Media Manager"="c:\progra~1\Nero\NEROPH~1\data\Xtras\mss ysmgr.exe" [2006-05-10 249856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-11-15 151552]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-07 464168]
"CCUTRAYICON"="c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2006-11-18 182744]
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-09-26 423424]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-08-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-08-24 154136]
"Persistence"="c:\windows\system32\igfxpers.ex e" [2007-08-24 129560]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]
"MSConfig"="c:\windows\system32\msconfig.exe" [2006-11-02 222208]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-11 136600]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-11-03 1168264]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\MpcStar\Codecs\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ala.exe"="c:\program files\access lock\ala.exe" [2005-07-20 579072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e" [2008-08-14 611712]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 c:\windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-16 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
--a------ 2007-02-16 01:39 151552 c:\acer\AcerTour\Reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-09 10:09 63712 c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 07:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 09:51 1836328 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nero PhotoShow Media Manager]
--a------ 2006-05-10 19:52 249856 c:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2007-08-07 00:05 200704 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\MpcStar\Codecs\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-12-27 14:01 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run-]
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run-]
"WarReg_PopUp"=c:\acer\WR_PopUp\WarReg_PopUp.e xe
"Acer Empowering Technology Monitor"=c:\acer\Empowering Technology\SysMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\FirewallRules]
"{FB6B45A3-C732-4633-A7AB-253C1EAFB55C}"= c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{69931EF8-E65D-474E-AF40-F493F860AF3C}"= c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{B2DE75FD-D679-4417-8900-7A12C187678A}"= c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{B922E713-74E5-4F4A-9989-6E6C29A92449}"= c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{D40BF103-6006-4F6C-9740-165D15B50EBA}"= UDP:Profile=Private|Profile=Public:LocalSubnet:Loc alSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{C84BAFBF-4FCB-4814-B662-018A5035C4A2}"= TCP:Profile=Private|Profile=Public:LocalSubnet:Loc alSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{BBA86C52-3F87-4885-9C32-CF683FD8CF55}"= UDP:Profile=Private|Profile=Public:LocalSubnet:Loc alSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{A0B3150A-80FE-42A5-AC73-CDBCCBD3BF41}"= TCP:Profile=Private|Profile=Public:LocalSubnet:Loc alSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{3B8108F6-550F-447F-91E4-1BAF400B4759}"= UDP:Profile=Private|Profile=Public:LocalSubnet:Loc alSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{9BDA73A9-F76C-4DA5-944E-608900972F59}"= TCP:Profile=Private|Profile=Public:LocalSubnet:Loc alSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{AD198510-C252-43EB-B416-059D5969BFCD}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1: Intel(R) Viiv(TM) Media Server Discovery
"{5ADBF990-15F6-4F93-827C-650A5B8126B9}"= TCP:Profile=Private|Profile=Public|1900:LocalSubne t:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{34AEEE7E-7E6C-4459-815E-1A292D7C59C8}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{84153126-C1D9-4442-A758-7CC5AE889E4A}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{116C338F-A5F7-47BE-BF51-1EBA90594BCE}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{F1D3005F-2E18-4F78-9D4E-79E6BB64CE9C}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{50A44FC5-C124-4B1E-8858-8F13FFAE7B73}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A7CF579C-7B4A-4A74-85B4-024009F3EC2E}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EBE24F32-B7A2-4532-8A81-903195D50D63}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{1C6090A9-47CC-4F24-A528-46CFD11B321A}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{1D64C6B9-5AE3-4EDB-9AD9-68C60333E744}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{1D9990EB-FA6B-4DAC-BE98-4F048C829425}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{6F3E1467-8528-46FD-9830-B3F781081F2B}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{53565130-E9E7-4F47-8E2F-8A0EEEFED9E1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E39BCEE8-1FCC-4474-8B84-DB33BEDB39DD}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{B7438F52-9FE8-410C-AD16-4056C8E07C3C}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6D65E25B-C9C7-4470-9782-476EECD3DF23}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A95FDE7B-3787-45E7-BD67-8CB2A37063E5}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6B30E86C-08ED-43F0-AB34-269ED98DE7F8}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D5808180-9093-45A4-9714-7FA83C145E54}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8E46FD03-241A-4C9F-B407-DBFCF7F61C3F}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5809726A-D523-4B40-8C46-85C588CE27DB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{0954EF2B-A4CD-42AF-BDAA-AE7760F015DB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{DA755F64-F344-48A8-9B07-8FEDB9CEB1B2}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{F94EAA66-DF90-4E23-92EF-1BC026157771}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{201345C4-B458-495D-B3AA-6E6907ABFE38}"= UDP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{CAA39B06-CF19-4A04-8B64-31003040F610}"= TCP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{E424D017-9C8E-4961-84CC-E0CB77271BCD}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{23820B35-32EC-46DC-9936-8B6E5193467F}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8966DC93-82AC-449E-A261-9CB9F43D278F}"= UDP:c:\program files\PPLiveVA\PPLiveVA.exe:PPLiveVA
"{FF70A0DF-15AD-4C43-A45A-5DD3D8D5AEBB}"= TCP:c:\program files\PPLiveVA\PPLiveVA.exe:PPLiveVA
"{EE9CB939-3C76-49E1-ACFE-8416A69280DE}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D94D3D23-9C39-46DA-9891-314D809F1102}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{6B16C24A-AA50-404F-8C95-63C351C73C78}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{13A7FDD2-4438-4D9B-8D32-0EB745C62B1B}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{49DE7838-9400-440F-8784-2C841CB17B92}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{C50E6A1C-6299-44BE-9E53-C55FCCAFB253}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{1B4AEA59-43A2-4732-AB81-A42DDC9FF1F8}"= UDP:5353:Adobe CSI CS4
"{EB2C6687-5FCA-4BB5-BA57-9AFBF0082035}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e:Adobe CSI CS4
"{79EA5297-9543-4447-8236-49DC23106201}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.ex e:Adobe CSI CS4
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|S vc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\StandardProfile]
"EnableFirewall"= 0 (0x0)
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsd efs\20090129.001\IDSvix86.sys [2008-09-12 270384]
S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.e xe [2006-10-29 208896]
S2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\system32\DRIVERS\nmsgopro.sys [2006-09-27 28672]
S2 nmsunidr;UniDriver for NMS;c:\windows\system32\DRIVERS\nmsunidr.sys [2006-10-19 7424]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-06-13 356920]
S3 CXRAPTOR;MPC718 Video Capture ;c:\windows\system32\drivers\yuanrap.sys [2007-03-07 146176]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys [2007-10-04 5504]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMN DISV.SYS [2007-01-09 38200]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - AFD
*Deregistered* - AtiPcie
*Deregistered* - Beep
*Deregistered* - bowser
*Deregistered* - cdfs
*Deregistered* - CLFS
*Deregistered* - comHost
*Deregistered* - crcdisk
*Deregistered* - DfsC
*Deregistered* - DXGKrnl
*Deregistered* - eeCtrl
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - fastfat
*Deregistered* - FileInfo
*Deregistered* - FltMgr
*Deregistered* - HTTP
*Deregistered* - IDSvix86
*Deregistered* - IKFileSec
*Deregistered* - IKSysFlt
*Deregistered* - IKSysSec
*Deregistered* - int15
*Deregistered* - IntelDH
*Deregistered* - iScsiPrt
*Deregistered* - kbdclass
*Deregistered* - KSecDD
*Deregistered* - lltdio
*Deregistered* - luafv
*Deregistered* - mchInjDrv
*Deregistered* - mouclass
*Deregistered* - MountMgr
*Deregistered* - mpsdrv
*Deregistered* - MRxDAV
*Deregistered* - mrxsmb
*Deregistered* - mrxsmb10
*Deregistered* - mrxsmb20
*Deregistered* - Msfs
*Deregistered* - msisadrv
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - netbt
*Deregistered* - nmsgopro
*Deregistered* - nmsunidr
*Deregistered* - Npfs
*Deregistered* - nsiproxy
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PEAUTH
*Deregistered* - PptpMiniport
*Deregistered* - PQNTDrv
*Deregistered* - PSched
*Deregistered* - PSDFilter
*Deregistered* - PSDNServ
*Deregistered* - psdvdisk
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - rdbss
*Deregistered* - RDPCDD
*Deregistered* - RDPENCDD
*Deregistered* - RDPWD
*Deregistered* - rspndr
*Deregistered* - SCDEmu
*Deregistered* - secdrv
*Deregistered* - Smb
*Deregistered* - SPBBCDrv
*Deregistered* - spldr
*Deregistered* - SRTSP
*Deregistered* - SRTSPX
*Deregistered* - srv
*Deregistered* - srv2
*Deregistered* - srvnet
*Deregistered* - swenum
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMNDISV
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - Tcpip
*Deregistered* - tcpipreg
*Deregistered* - TDTCP
*Deregistered* - tdx
*Deregistered* - tssecsrv
*Deregistered* - tunmp
*Deregistered* - tunnel
*Deregistered* - umbus
*Deregistered* - VgaSave
*Deregistered* - volmgr
*Deregistered* - volmgrx
*Deregistered* - volsnap
*Deregistered* - Wanarpv6
*Deregistered* - Wdf01000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-01-30 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 08:09]
2009-01-30 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.uk.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*http://uk.yahoo.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Jay\AppData\Roaming\Mozilla\Firefox\Profi les\veqz5ijr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin. dll
FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin2 .dll
FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin3 .dll
FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin4 .dll
FF - plugin: c:\program files\MpcStar\Codecs\QuickTime\Plugins\npqtplugin5 .dll
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 20:36:18
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2009-01-30 20:43:08
ComboFix-quarantined-files.txt 2009-01-30 20:43:01
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 30,342,512,640 bytes free
409 --- E O F --- 2009-01-03 14:10:31
|
|