- installed & ran ATF Cleaner
- installed & ran Malwarebyte's Anti-Malware and removed selected items
- ran HijackThis and clicked "fix checked" to the seleted items
- downloaded & ran Rooter.exe
- performed Kaspersky online virus scan
- downloaded & ran ComboFix
If you need to see the logs from those, except ComboFix, see my previous threads at the following link:http://forums.whatthetech.com/Homepage_Hij…tp_t101138.html
Here is the ComboFix log:
ComboFix 09-03-26.03 - Lewis 2009-03-27 14:49:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.218 [GMT -3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lewis\Application Data\inst.exe
.
((((((((((((((((((((((((( Files Created from 2009-02-27 to 2009-03-27 )))))))))))))))))))))))))))))))
.
2009-03-20 12:41 . 2009-03-20 12:41 d–hs—- c:\documents and settings\LocalService\IETldCache
2009-03-20 12:05 . 2009-03-20 12:20 d–h-c— c:\windows\ie8
2009-03-16 11:51 . 2009-03-16 11:51 d——– c:\program files\iPod
2009-03-16 11:49 . 2009-03-16 11:53 d——– c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-16 11:40 . 2009-03-16 11:43 d——– c:\program files\QuickTime
2009-03-14 18:47 . 2009-03-14 18:47 d——– c:\program files\TagScanner
2009-03-12 04:40 . 2009-03-12 04:44 d——– C:\Rooter$
2009-03-11 10:31 . 2009-03-11 10:31 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-03-09 23:46 . 2009-03-25 23:28 d——– c:\documents and settings\Lewis\YPOPs
2009-03-09 21:38 . 2007-04-09 14:23 28,040 –a—— c:\windows\system32\mdimon.dll
2009-03-09 21:38 . 2009-03-09 21:38 376 –a—— c:\windows\ODBC.INI
2009-03-09 21:23 . 2009-03-09 21:23 d——– c:\program files\Microsoft ActiveSync
2009-03-09 21:08 . 2009-03-09 21:24 d——– c:\windows\SHELLNEW
2009-03-09 21:07 . 2009-03-09 21:07 d——– c:\program files\Microsoft.NET
2009-03-08 20:19 . 2009-03-12 15:49 d——– c:\program files\YPOPs
2009-03-08 14:22 . 2009-03-08 14:22 49,152 ——— c:\windows\system32\msrating.dll.mui
2009-03-08 14:22 . 2009-03-08 14:22 2,560 ——— c:\windows\system32\mshta.exe.mui
2009-03-08 14:21 . 2009-03-08 14:21 4,096 ——— c:\windows\system32\ie4uinit.exe.mui
2009-03-08 14:20 . 2009-03-08 14:20 81,920 ——— c:\windows\system32\iedkcs32.dll.mui
2009-03-08 12:02 . 2009-03-08 12:02 d——– c:\program files\PicLensIE
2009-03-08 04:33 . 2009-03-08 04:33 18,944 —–c— c:\windows\system32\dllcache\corpol.dll
2009-03-07 16:29 . 2009-03-07 16:29 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-07 16:29 . 2009-03-07 16:29 d——– c:\documents and settings\Lewis\Application Data\Malwarebytes
2009-03-07 16:29 . 2009-03-07 16:29 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-07 16:29 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-07 16:29 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-07 16:24 . 2009-03-07 16:24 d–hs—- c:\documents and settings\Lewis\PrivacIE
2009-03-07 16:24 . 2009-03-07 16:24 d–hs—- c:\documents and settings\Lewis\IECompatCache
2009-03-07 16:22 . 2009-03-07 16:22 d–hs—- c:\documents and settings\Lewis\IETldCache
2009-03-07 16:00 . 2009-03-20 12:33 d——– c:\windows\ie8updates
2009-03-07 15:57 . 2009-03-20 12:20 1,374 –a—— c:\windows\imsins.BAK
2009-03-07 15:51 . 2009-02-28 01:55 105,984 —–c— c:\windows\system32\dllcache\iecompat.dll
2009-03-07 15:36 . 2009-03-07 15:36 d——– c:\program files\Trend Micro
2009-03-06 20:08 . 2009-03-06 20:08 d——– c:\documents and settings\Lewis\Application Data\AccurateRip
2009-03-06 20:07 . 2009-03-06 21:31 d——– c:\program files\Exact Audio Copy
2009-03-06 20:07 . 2009-03-06 20:08 d——– c:\documents and settings\Lewis\Application Data\AD ON Multimedia
2009-03-06 18:37 . 2009-03-06 18:41 d——– c:\program files\OpenVPN
2009-03-04 16:44 . 2009-03-04 16:50 d——– c:\program files\GMATPrep
2009-03-02 19:04 . 2009-03-02 19:04 d——– c:\program files\Audacity
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-27 17:17 ——— d—–w c:\documents and settings\Lewis\Application Data\uTorrent
2009-03-27 11:57 ——— d—–w c:\program files\LogMeIn
2009-03-26 02:22 ——— d—–w c:\program files\Google
2009-03-17 13:49 ——— d—–w c:\documents and settings\Lewis\Application Data\foobar2000
2009-03-16 14:53 ——— d—–w c:\program files\iTunes
2009-03-16 14:51 ——— d—–w c:\program files\Common Files\Apple
2009-03-11 13:31 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-03-11 13:30 ——— d—–w c:\program files\Java
2009-03-09 23:32 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-08 07:34 914,944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 07:34 43,008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 07:33 420,352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 07:33 18,944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 07:32 72,704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 07:32 71,680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 07:31 48,128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 07:31 45,568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 07:31 34,816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 07:22 156,160 —-a-w c:\windows\system32\msls31.dll
2009-03-05 19:44 ——— d—–w c:\documents and settings\Lewis\Application Data\Vso
2009-03-04 19:44 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-26 09:29 ——— d—–w c:\program files\Microsoft Silverlight
2009-02-25 19:03 ——— d—–w c:\program files\Windows Live
2009-02-25 19:02 ——— d—–w c:\program files\Windows Live SkyDrive
2009-02-25 04:34 ——— d—–w c:\program files\ATI Technologies
2009-02-25 04:22 ——— d—–w c:\program files\Microsoft Office Outlook Connector
2009-02-25 04:22 ——— d—–w c:\program files\Microsoft
2009-02-18 23:40 ——— d—–w c:\program files\uTorrent
2009-02-17 01:19 ——— d—–w c:\documents and settings\Lewis\Application Data\EmailNotifier
2009-02-17 01:19 ——— d—–w c:\documents and settings\All Users\Application Data\Megaupload
2009-02-17 01:19 ——— d—–w c:\documents and settings\All Users\Application Data\EmailNotifier
2009-02-17 01:17 ——— d—–w c:\program files\Megaupload
2009-02-17 01:14 ——— d—–w c:\documents and settings\Lewis\Application Data\InstallShield
2009-02-15 20:54 ——— d—–w c:\program files\iTunes Genre Art Manager
2009-02-12 18:38 ——— d—–w c:\documents and settings\All Users\Application Data\vsosdk
2009-02-12 13:08 ——— d—–w c:\documents and settings\Lewis\Application Data\U3
2009-02-11 17:01 ——— d—–w c:\documents and settings\Lewis\Application Data\Digsby
2009-02-11 17:01 ——— d—–w c:\documents and settings\All Users\Application Data\Digsby
2009-02-10 01:15 ——— d—–w c:\program files\VSO
2009-02-10 01:07 47,360 —-a-w c:\windows\system32\drivers\pcouffin.sys
2009-02-10 01:07 47,360 —-a-w c:\documents and settings\Lewis\Application Data\pcouffin.sys
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2009-02-08 22:03 ——— d—–w c:\program files\QuickMediaConverter
2009-02-06 21:52 49,504 —-a-w c:\windows\system32\sirenacm.dll
2009-02-05 12:48 ——— d—–w c:\program files\Common Files\InstallShield
2009-02-05 12:45 ——— d—–w c:\program files\Sonic
2009-02-05 12:44 ——— d—–w c:\program files\Common Files\Sonic Shared
2009-02-05 12:31 ——— d—–w c:\program files\Samsung
2009-02-05 12:28 ——— d—–w c:\documents and settings\Lewis\Application Data\Sonic
2009-02-05 12:28 ——— d—–w c:\documents and settings\Lewis\Application Data\Leadertech
2009-01-28 01:11 ——— d—–w c:\documents and settings\Lewis\Application Data\DivX
2009-01-27 21:46 ——— d—–w c:\program files\Bonjour
2009-01-27 13:30 ——— d—–w c:\program files\DivX
2009-01-07 21:21 26,144 —-a-w c:\windows\system32\spupdsvc.exe
2009-01-07 21:20 265,720 —-a-w c:\windows\system32\msdbg2.dll
2009-01-07 21:20 26,112 —-a-w c:\windows\system32\idndl.dll
2009-01-07 21:20 24,576 —-a-w c:\windows\system32\nlsdl.dll
2009-01-07 21:20 23,552 —-a-w c:\windows\system32\normaliz.dll
2008-12-28 22:48 2,330,643 —-a-w c:\windows\system32\x264vfw.dll
2008-07-19 15:50 7,486 –sha-r c:\windows\system32\killVBS.vbs
2008-05-24 23:58 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052420080525\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Google Update"="c:\documents and settings\Lewis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-03-08 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-11 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
"iLike"="c:\program files\iLike\1.2.10\ilikesidebar.exe" [2008-09-10 63024]
c:\documents and settings\Lewis\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-04-15 157008]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 3746856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02 546288]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 19:35 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"= DrvTrNTm.dll
"wave"= DrvTrNTm.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\ZPoC\\ZPoc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\Lewis\\Local Settings\\Application Data\\Google\\Google Talk, Labs Edition\\GoogleTalkLabsEdition.exe"=
"c:\\Documents and Settings\\Lewis\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Lewis\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"52530:TCP"= 52530:TCP:uTorrent
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2008-07-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-09-17 47640]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2008-04-14 200192]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [2008-07-12 120472]
S2 gupdate1c8ef3c3f7440de;Google Update Service (gupdate1c8ef3c3f7440de);c:\program files\Google\Update\GoogleUpdate.exe [2008-07-26 133104]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-07-06 31592]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2006-10-01 26624]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
— Other Services/Drivers In Memory —
*Deregistered* - Viewpoint Manager Service
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - WinDefend
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - WSearch
*Deregistered* - wuauserv
*Deregistered* - WudfSvc
*Deregistered* - WZCSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ff0912d-1075-11dd-a062-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ff09149-1075-11dd-a062-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c6a20c-4018-11dd-a0ab-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c6a20d-4018-11dd-a0ab-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69d69b7a-60a1-11dd-a0e0-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7673fc2-55aa-11dd-a0cf-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c064000c-3fc1-11dd-a0a9-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f55566f0-f38c-11dd-a178-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa1b7f50-1896-11dd-a06a-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-27 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-08-29 11:47]
2009-03-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1972579041-682003330-1004.job
- c:\documents and settings\Lewis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-08 14:24]
2009-03-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2009-03-12 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2008-04-16 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2008-04-16 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe []
2009-03-27 c:\windows\Tasks\User_Feed_Synchronization-{DD417806-D794-49CF-B554-A3DB5EC47752}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 04:31]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{C9D0879E-F33F-4CA8-9137-6F2A0AEDCFB9} - (no file)
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
——- Supplementary Scan ——-
.
uStart Page =
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: plaxo.com\www
DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} - hxxp://www.christianrock2.net/amp3dj.cab
FF - ProfilePath - c:\documents and settings\Lewis\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\
FF - prefs.js: browser.search.selectedEngine - Google US
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://br.search.yahoo.com/search?ei=ISO-8859-1&fr;=megaup&p;=
FF - component: c:\documents and settings\Lewis\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: c:\documents and settings\Lewis\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\Lewis\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Lewis\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-27 14:51:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-03-27 14:54:40
ComboFix-quarantined-files.txt 2009-03-27 17:54:01
Pre-Run: 4,279,439,360 bytes free
Post-Run: 4,358,119,424 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
290 — E O F — 2009-03-13 15:25:25
Please let me know what I should do next. Is it time to try to set my homepage yet?