G/day oldman960.
Each time I see your name I think it is my son he calls me oldman but I tell him I'm only 64 and there are older men then me LOL.
Well combofizx /u did not work kept saying that ComboFix is not on this comp. Downloaded a new Combofix and still cbf \u would not run
so I ran a full Combofix scan would that be ok.
With the 2 links you gave what do I do with then …..
ComboFix 09-03-26.03 - Owner 2009-03-28 16:31:17.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.550 [GMT 11:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-28 )))))))))))))))))))))))))))))))
.
2009-03-27 08:27 . 2009-03-27 08:27 644 –a—— c:\windows\system32\%LocalXml%
2009-03-24 12:30 . 2009-03-24 12:34 d——– C:\Combo-Fix
2009-03-24 12:28 . 2009-03-24 12:28 128 –a—— c:\windows\system32\perf.dat
2009-03-22 18:50 . 2009-03-22 18:50 d——– C:\Inetpub
2009-03-22 08:18 . 2009-03-22 08:18 0 –a—— c:\documents and settings\Owner\Application Data\TrustDefender.dll
2009-03-19 19:54 . 2009-03-19 19:54 d——– C:\System Utilities
2009-03-17 19:47 . 2007-06-17 01:00 14,336 –a—— c:\windows\system32\drivers\Amps2prt.sys
2009-03-17 19:47 . 2007-02-10 23:55 13,824 –a—— c:\windows\system32\drivers\Amusbprt.sys
2009-03-17 19:47 . 2006-04-11 13:56 10,240 –a—— c:\windows\system32\drivers\Arfumx86.sys
2009-03-17 19:47 . 2007-01-24 17:46 8,704 –a—— c:\windows\system32\drivers\Amfilter.sys
2009-03-03 11:45 . 2009-03-16 21:24 d——– c:\program files\Eusing Free Registry Cleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-28 03:02 ——— d—–w c:\program files\SpywareBlaster
2009-03-28 02:49 ——— d—–w c:\program files\Kaspersky Lab
2009-03-27 20:41 ——— d—–w c:\program files\Google
2009-03-26 13:15 ——— d—–w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-26 11:23 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-03-26 11:23 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-26 11:05 ——— d—–w c:\program files\Optus Internet Security Suite
2009-03-26 11:02 ——— d—–w c:\documents and settings\All Users\Application Data\F-Secure
2009-03-26 09:42 410,984 -c–a-w c:\windows\system32\deploytk.dll
2009-03-26 09:37 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-22 21:12 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2009-03-21 09:44 ——— d—–w c:\program files\A4Tech
2009-03-21 09:38 ——— d—–w c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2009-03-18 05:43 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-18 05:43 ——— d—–w c:\program files\ATI Technologies
2009-03-02 10:03 ——— d—–w c:\documents and settings\All Users\Application Data\fssg
2009-02-28 07:31 ——— d—–w c:\program files\Microsoft Silverlight
2009-02-26 11:04 ——— d—–w c:\program files\Kaspersky Anti Virus 6.0.2.621
2009-02-26 07:36 ——— dc—-w c:\program files\Common Files\WindowsLiveInstaller
2009-02-26 07:36 ——— d—–w c:\program files\Winamp
2009-02-26 07:36 ——— d—–w c:\program files\Java
2009-02-26 07:36 ——— d—–w c:\program files\FinePixViewer
2009-02-26 07:36 ——— d—–w c:\program files\DVD Wizard Pro
2009-02-26 07:36 ——— d—–w c:\program files\DivX
2009-02-26 07:36 ——— d—–w c:\program files\Common Files\Vbox
2009-02-26 07:36 ——— d—–w c:\program files\Common Files\Ahead
2009-02-26 07:36 ——— d—–w c:\program files\Apple Software Update
2009-02-26 07:36 ——— d—–w c:\program files\Acoustica Spin It Again
2009-02-25 00:16 ——— d—–w c:\program files\SUPERAntiSpyware
2009-02-23 12:51 ——— d—–w c:\program files\Acoustica Shared Effects
2009-02-21 21:22 ——— d—–w c:\program files\Windows Live
2009-02-16 11:11 ——— d—–w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-02-12 10:58 ——— d—–w c:\documents and settings\All Users\Application Data\DriverCure
2009-02-12 07:55 ——— d—–w c:\program files\NCH Software
2009-02-12 07:55 ——— d—–w c:\program files\AGI
2009-02-12 07:55 ——— d—–w c:\program files\7-Zip
2009-02-12 07:55 ——— d—–w c:\documents and settings\Owner\Application Data\Uniblue
2009-02-12 07:55 ——— d—–w c:\documents and settings\Owner\Application Data\BitTorrent
2009-02-12 06:12 ——— d—–w c:\documents and settings\Administrator\Application Data\Sonic
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 08:03 307,576 -c–a-w c:\windows\WLXPGSS.SCR
2009-02-06 07:52 49,504 —-a-w c:\windows\system32\sirenacm.dll
2009-02-05 00:38 ——— d—–w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-02-03 05:55 ——— d—–w c:\program files\Common Files\xing shared
2009-02-03 05:55 ——— d—–w c:\program files\Common Files\Real
2009-02-03 05:54 ——— d—–w c:\program files\Real
2009-02-03 05:41 ——— d—–w c:\program files\AskBarDis
2009-02-03 05:40 ——— d—–w c:\documents and settings\Owner\Application Data\Foxit
2009-02-03 05:00 ——— d—–w c:\documents and settings\Owner\Application Data\DriverCure
2009-02-03 04:59 ——— d—–w c:\documents and settings\All Users\Application Data\ParetoLogic
2009-02-03 01:37 ——— d—–w c:\program files\iTunes
2009-02-03 01:37 ——— d—–w c:\program files\iPod
2009-02-03 01:37 ——— d—–w c:\program files\Common Files\Apple
2009-02-03 01:37 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-03 01:31 ——— d—–w c:\program files\QuickTime
2009-02-01 12:49 ——— d—–w c:\program files\KYE
2009-02-01 12:49 ——— d—–w c:\program files\Common Files\snpstd
2009-01-31 05:42 8 -c–a-w c:\documents and settings\Owner\Application Data\usb.dat
2009-01-31 03:49 ——— d—–w c:\program files\MP3 Player Utilities
2009-01-29 22:47 ——— d—–w c:\program files\Microsoft Office Outlook Connector
2009-01-29 22:47 ——— d—–w c:\program files\Microsoft
2009-01-29 22:46 ——— d—–w c:\program files\Microsoft Sync Framework
2009-01-29 22:43 ——— d—–w c:\program files\Windows Live SkyDrive
2009-01-29 22:33 ——— d—–w c:\program files\Common Files\Windows Live
2009-01-29 07:37 ——— d—–w c:\program files\MSBuild
2009-01-29 07:36 ——— d—–w c:\program files\Reference Assemblies
2009-01-05 22:33 3,751,995 -c–a-w c:\windows\system32\GPhotos.scr
2008-12-31 06:04 691,560 -c–a-w c:\windows\system32\OGACheckControl.dll
2008-12-31 06:04 528,744 -c–a-w c:\windows\system32\OGAVerify.exe
2008-12-31 06:04 502,120 -c–a-w c:\windows\system32\OGAAddin.dll
2008-12-12 03:47 190 -c–a-w c:\documents and settings\Owner\Fix.reg
2008-05-19 06:18 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008051920080520\index.dat
2008-05-19 06:19 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"TrustDefenderWD"="c:\program files\TrustDefender\TrustDefender\WinUserAppLauncher.exe" [2009-03-21 15528]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-26 148888]
"iKeyWorks"="c:\program files\A4Tech\Keyboard\Ikeymain.exe" [2007-06-25 65536]
"HydraVisionDesktopManager"="c:\program files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe" [2003-09-15 270336]
"HydraVisionViewport"="c:\program files\ATI Technologies\ATI HYDRAVISION\HydraMD.exe" [2003-09-15 364544]
"PCTVOICE"="pctspk.exe" [2001-08-17 c:\windows\system32\pctspk.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-01-14 525664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \
0
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
—–c— 2003-08-19 02:01 110592 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\kav\\kav7.0\\english\\setup.exe"=
"c:\\Program Files\\TrustDefender\\TrustDefender\\TrustDefender.exe"=
R1 TRIXX;TRIXX;c:\program files\TRIXX\TRIXXDriver.sys [2005-08-16 15360]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-01-30 55136]
R2 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2008-12-04 226656]
S2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [2005-12-15 75925]
S2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;c:\windows\system32\drivers\wf2ktunr.sys [2005-12-15 36423]
S2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;c:\windows\system32\drivers\wf2kXbar.sys [2005-12-15 10005]
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\drivers\Amps2prt.sys [2009-03-17 14336]
S3 FwHookDrv;FwHookDrv;c:\program files\TrustDefender\TrustDefender\FwHookDrv.sys [2008-07-30 9896]
S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [2006-01-18 167424]
S4 TrustDefender;TrustDefender;c:\program files\TrustDefender\TrustDefender\TrustDefender.exe [2008-07-30 1683624]
.
Contents of the 'Scheduled Tasks' folder
2009-03-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-28 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-03-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 17:04]
2009-03-28 c:\windows\Tasks\User_Feed_Synchronization-{BD0500D5-94D0-49A9-A55F-C28465FABBC6}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ninemsn.com.au/
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://ninemsn.com.au/|http://rover.ebay.com/rover/1/710-47297-17704-0/4?mfe=startTab&mpre=http%3A%2F%2Fwww.ebay.co.uk%2F
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\99z819kb.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayFormSubmitObserver.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
—- FIREFOX POLICIES —-
.
.
——- File Associations ——-
.
regfile\shell\edit\command=%SystemRoot%\system32\NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-28 16:32:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1214440339-413027322-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\System\ControlSet001\Control\ContentIndex\Language\Nbliu*]
"Locale"=dword:00000000
"WBreakerClass"="{369647e0-17b0-11ce-9950-00aa004bbb1f}"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(556)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-03-28 16:34:12
ComboFix-quarantined-files.txt 2009-03-28 05:34:10
ComboFix2.txt 2009-03-26 08:56:53
Pre-Run: 136,721,399,808 bytes free
Post-Run: 136,876,462,080 bytes free
318 — E O F — 2009-03-19 22:22:17