ComboFix 10-07-01.02 - System User 02/07/2010 21:31:55.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.1022.407 [GMT 1:00]
Running from: c:\users\System User\Desktop\com.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\System32\wermgr.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2010-06-02 to 2010-07-02 )))))))))))))))))))))))))))))))
.
2010-07-02 21:24 . 2010-07-02 21:24 -------- d-----w- c:\users\System User\AppData\Local\temp
2010-06-25 18:54 . 2010-06-25 19:05 -------- d-----w- c:\users\System User\AppData\Roaming\Apple Computer
2010-06-25 18:54 . 2010-06-25 18:54 -------- d-----w- c:\users\System User\AppData\Local\Apple Computer
2010-06-25 18:53 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-06-25 18:53 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-06-25 18:53 . 2010-06-25 18:53 -------- dc----w- c:\windows\system32\DRVSTORE
2010-06-25 18:52 . 2010-06-25 18:52 -------- d-----w- c:\program files\iPod
2010-06-25 18:52 . 2010-06-25 18:53 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-25 18:52 . 2010-06-25 18:53 -------- d-----w- c:\program files\iTunes
2010-06-25 18:51 . 2010-06-25 18:52 -------- d-----w- c:\program files\QuickTime
2010-06-25 18:51 . 2010-06-25 18:52 -------- d-----w- c:\programdata\Apple Computer
2010-06-25 18:50 . 2010-06-25 18:50 -------- d-----w- c:\users\System User\AppData\Local\Apple
2010-06-25 18:50 . 2010-06-25 18:50 -------- d-----w- c:\program files\Apple Software Update
2010-06-25 18:48 . 2010-06-25 18:48 -------- d-----w- c:\program files\Bonjour
2010-06-25 18:48 . 2010-06-25 18:52 -------- d-----w- c:\program files\Common Files\Apple
2010-06-25 18:48 . 2010-06-25 18:48 -------- d-----w- c:\programdata\Apple
2010-06-15 19:01 . 2010-06-15 19:01 72504 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-10 17:22 . 2009-08-24 12:47 378368 ----a-w- c:\windows\system32\winhttp.dll
2010-06-09 18:06 . 2009-06-15 15:28 272384 ----a-w- c:\windows\system32\schannel.dll
2010-06-09 18:06 . 2009-06-15 15:23 494592 ----a-w- c:\windows\system32\kerberos.dll
2010-06-03 15:35 . 2010-06-03 15:35 -------- d-----w- C:\found.001
2010-06-03 11:52 . 2008-10-31 23:38 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-03 11:52 . 2008-11-01 03:33 1687040 ----a-w- c:\windows\system32\gameux.dll
2010-06-03 11:52 . 2008-11-01 03:33 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-02 17:33 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-06-29 23:21 . 2010-02-24 18:30 -------- d-----w- c:\users\System User\AppData\Roaming\Spotify
2010-05-21 13:14 . 2010-02-25 09:37 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 15:35 . 2010-05-18 15:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 15:35 . 2010-05-18 15:35 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-05-18 15:35 . 2010-05-18 15:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 15:35 . 2010-05-18 15:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-10 23:37 . 2010-05-10 23:37 655360 ----a-w- c:\users\System User\AppData\Roaming\Spotify\Gracenote\gnsdk_sdkmanager.dll
2010-05-10 23:37 . 2010-05-10 23:37 282624 ----a-w- c:\users\System User\AppData\Roaming\Spotify\Gracenote\gnsdk_musicid_file.dll
2010-05-10 23:37 . 2010-05-10 23:37 208896 ----a-w- c:\users\System User\AppData\Roaming\Spotify\Gracenote\gnsdk_dsp.dll
2010-04-19 08:38 . 2010-02-20 12:02 70176 ----a-w- c:\users\System User\AppData\Local\GDIPFONTCACHEV1.DAT
2007-03-07 12:54 . 2007-03-07 12:54 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-12-16 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 2159104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-02 1004136]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 4390912]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-02-10 90192]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-10 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-10 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.thetechguys.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\System User\AppData\Roaming\Mozilla\Firefox\Profiles\1zo7zya2.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-02 22:24
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-07-02 22:28:09
ComboFix-quarantined-files.txt 2010-07-02 21:28
Pre-Run: 235,898,707,968 bytes free
Post-Run: 235,875,119,104 bytes free
- - End Of File - - 27BADB5F881409706E73A50FD46C3410