jensvad
Tomk,
Figured it out before I got this reply. Somehow CombFix.exe got renamed to Comb-Fix.exe (not my doing). Simply renamed it back to ComboFix.exe and let it update. Then dragged the TXT file into it and let it scan. Here's the log:
ComboFix 09-06-01.03 - Jens 06/03/2009 14:43.5 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1789.1088 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Jens\Desktop\CFScript.txt
SP: AdwareAlert *disabled* (Updated) {8FE17B8C-999D-4396-B209-DC2ABE34C169}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\eMachines_eMachinesE620_N-A_LXN260Y1708500D44B1601.MRK
c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
c:\windows\system32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
.
((((((((((((((((((((((((( Files Created from 2009-05-03 to 2009-06-03 )))))))))))))))))))))))))))))))
.
2009-06-03 18:47 . 2009-06-03 18:47 ——– d—–w- c:\users\Jens\AppData\Local\temp
2009-06-02 16:40 . 2009-03-30 14:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-02 16:40 . 2009-03-24 20:08 55640 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-02 16:40 . 2009-06-02 16:40 ——– d—–w- c:\programdata\Avira
2009-06-02 16:40 . 2009-06-02 16:40 ——– d—–w- c:\program files\Avira
2009-06-02 15:33 . 2009-06-02 15:46 ——– d-s—w- C:\Combo-Fix
2009-06-01 16:08 . 2009-06-01 16:47 ——– d—–w- C:\Rooter$
2009-05-24 15:58 . 2009-05-24 15:58 ——– d—–w- c:\program files\Trend Micro
2009-05-23 04:36 . 2009-05-23 04:37 41148 —-a-w- C:\MGlogs.zip
2009-05-23 04:36 . 2009-05-23 04:37 ——– d—–w- C:\MGtools
2009-05-21 13:46 . 2009-05-21 13:46 ——– d—–w- C:\Autoruns
2009-05-20 00:45 . 2009-05-20 00:46 ——– d—–w- c:\windows\BDOSCAN8
2009-05-12 18:41 . 2009-05-18 22:58 ——– d—–w- c:\program files\Panda Security
2009-05-12 11:53 . 2008-12-04 05:25 120832 —-a-w- c:\users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\z43igteg.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
2009-05-11 18:17 . 2009-05-11 18:17 ——– d—–w- c:\program files\Common Files\Express Digital
2009-05-11 18:17 . 2009-05-11 18:17 ——– d—–w- c:\programdata\ExpressDigital
2009-05-11 17:59 . 2009-05-11 17:59 ——– d—–w- c:\users\Jens\AppData\Roaming\ExpressDigital
2009-05-11 17:58 . 2009-05-11 17:58 ——– d—–w- c:\program files\Common Files\Nikon
2009-05-11 17:57 . 2009-05-11 17:57 ——– d—–w- c:\program files\ExpressDigital
2009-05-07 18:21 . 2009-05-07 18:21 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2009-05-07 18:20 . 2009-06-02 20:13 ——– d—–w- c:\users\Jens\AppData\Roaming\SUPERAntiSpyware.com
2009-05-07 18:20 . 2009-06-02 20:13 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-05-07 17:06 . 2009-05-07 23:24 ——– d—–w- c:\program files\Exterminate It!
2009-05-07 16:00 . 2009-05-12 18:34 4565024 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-07 15:57 . 2009-05-12 18:25 ——– d—–w- c:\programdata\ParetoLogic
2009-05-07 15:57 . 2009-05-12 18:25 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-05-07 13:32 . 2009-05-07 13:51 ——– d—–w- c:\programdata\Webroot
2009-05-07 13:32 . 2009-05-07 13:32 ——– d—–w- c:\users\Jens\AppData\Roaming\Webroot
2009-05-07 13:32 . 2009-05-07 13:32 ——– d—–w- c:\program files\Webroot
2009-05-06 23:32 . 2009-05-06 23:32 ——– d—–w- c:\program files\Opanda
2009-05-05 20:08 . 2009-05-05 20:08 ——– dc-h–w- c:\programdata\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 20:39 . 2009-02-11 05:37 70120 —-a-w- c:\users\Jens\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-02 20:28 . 2009-04-01 20:36 ——– d—–w- c:\program files\Common Files\AOL
2009-06-02 20:20 . 2008-08-24 10:53 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-02 20:14 . 2009-04-29 18:23 ——– d—–w- c:\program files\ffdshow
2009-06-02 20:13 . 2008-12-12 10:10 ——– d—–w- c:\program files\Google
2009-06-02 20:12 . 2009-03-21 15:27 ——– d—–w- c:\programdata\PC Tools
2009-05-24 17:40 . 2009-02-11 15:00 ——– d—–w- c:\programdata\FLEXnet
2009-05-19 03:40 . 2009-02-24 17:06 ——– d—–w- c:\program files\PowerDataRecovery
2009-05-18 23:03 . 2009-03-11 11:58 ——– d—–w- c:\programdata\Lavasoft
2009-05-12 18:34 . 2009-05-07 16:00 51092 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-05-12 11:54 . 2009-03-12 12:44 ——– d—–w- c:\program files\Windows Live Safety Center
2009-05-08 00:19 . 2009-02-16 18:39 ——– d—–w- c:\program files\Java
2009-05-07 20:30 . 2009-02-12 18:58 ——– d—–w- c:\program files\Steam
2009-05-07 15:08 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Defender
2009-05-07 15:08 . 2009-04-03 16:08 ——– d–h–w- c:\programdata\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
2009-05-03 16:46 . 2008-08-24 11:18 ——– d—–w- c:\programdata\Microsoft Help
2009-05-01 04:56 . 2009-05-01 04:56 129096 —ha-w- c:\windows\system32\mlfcache.dat
2009-05-01 00:48 . 2009-05-01 00:48 ——– d—–w- c:\program files\Common Files\PX Storage Engine
2009-04-29 19:05 . 2009-04-29 19:05 ——– d—–w- c:\program files\Windows Media Components
2009-04-29 18:36 . 2009-03-18 21:07 ——– d—–w- c:\programdata\NCH Software
2009-04-29 16:05 . 2009-04-29 16:05 ——– d—–w- c:\users\Jens\AppData\Roaming\Canon
2009-04-29 16:04 . 2009-03-18 21:07 ——– d—–w- c:\program files\NCH Software
2009-04-29 15:41 . 2009-04-29 15:30 ——– d—–w- c:\program files\Canon
2009-04-29 15:28 . 2008-12-12 10:02 ——– d—–w- c:\program files\Common Files\InstallShield
2009-04-27 22:49 . 2009-04-27 22:49 3366912 —-a-w- c:\windows\system32\GPhotos.scr
2009-04-23 18:12 . 2009-02-12 18:58 ——– d—–w- c:\program files\Common Files\Steam
2009-04-20 00:51 . 2009-04-20 00:50 ——– d—–w- c:\program files\PokerStars
2009-04-16 07:21 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-04-06 18:43 . 2009-04-06 18:42 ——– d—–w- c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor
2009-03-30 17:42 . 2009-03-30 17:42 0 —-a-w- c:\windows\nsreg.dat
2009-03-19 15:08 . 2009-03-19 15:08 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-03-19 15:08 . 2009-03-19 15:08 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-03-17 03:38 . 2009-04-16 03:42 13824 —-a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 03:42 24064 —-a-w- c:\windows\system32\amxread.dll
2009-03-10 23:58 . 2009-03-10 23:58 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-03-09 09:19 . 2009-02-16 18:40 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2009-04-29 18:34 914944 —-a-w- c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-04-29 18:34 43008 —-a-w- c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-04-29 18:34 18944 —-a-w- c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-04-29 18:34 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-04-29 18:34 109568 —-a-w- c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-04-29 18:34 132608 —-a-w- c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-04-29 18:34 107520 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-04-29 18:34 107008 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-04-29 18:34 103936 —-a-w- c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-04-29 18:34 420352 —-a-w- c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-04-29 18:34 72704 —-a-w- c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-04-29 18:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-04-29 18:34 66560 —-a-w- c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-04-29 18:34 169472 —-a-w- c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-04-29 18:34 34816 —-a-w- c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-04-29 18:34 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-04-29 18:34 45568 —-a-w- c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-04-29 18:34 156160 —-a-w- c:\windows\system32\msls31.dll
2009-03-06 13:06 . 2009-03-06 13:06 140800 —-a-w- c:\windows\system32\drivers\Rtlh86.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-05-24_15.41.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-02 16:37 . 2009-06-02 16:37 54272 c:\windows\winsxs\x86_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_ecdf8c290e547f3
9\vcomp90.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 62976 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90RUS.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 46080 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90KOR.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 46592 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90JPN.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 64512 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ITA.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 66048 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90FRA.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 65024 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ESP.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 65024 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ESN.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 56832 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ENU.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 66560 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90DEU.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 39936 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90CHT.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 38912 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90CHS.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 59904 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 59904 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll
+ 2008-01-21 01:58 . 2009-06-03 17:37 59234 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02 . 2009-06-03 17:37 79280 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-11 05:37 . 2009-06-03 17:37 13050 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3198850635-3864095973-2275556364-1000_UserData.bin
+ 2009-06-02 16:40 . 2009-02-13 16:50 28376 c:\windows\System32\drivers\ssmdrv.sys
- 2009-02-11 05:33 . 2009-05-24 14:23 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-11 05:33 . 2009-06-02 18:58 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-11 05:33 . 2009-06-02 18:58 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-02 18:58 . 2009-06-02 18:58 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009060220090603\index.dat
+ 2009-02-11 05:33 . 2009-06-02 18:58 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-05-24 15:37 . 2009-05-24 15:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-06-03 17:35 . 2009-06-03 17:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-24 15:37 . 2009-05-24 15:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-03 17:35 . 2009-06-03 17:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-02 16:37 . 2009-06-02 16:37 655872 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 572928 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 225280 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 161784 c:\windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e\ATL90.dll
+ 2006-11-02 10:33 . 2009-05-27 17:22 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-21 19:33 595684 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-05-27 17:22 101350 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-05-21 19:33 101350 c:\windows\System32\perfc009.dat
- 2009-04-29 18:55 . 2009-05-23 01:09 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-04-29 18:55 . 2009-05-26 22:50 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-06-02 16:37 . 2009-06-02 16:37 3783672 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 3768312 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll
- 2006-11-02 10:22 . 2009-05-09 00:47 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-06-02 19:35 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 12:44 . 2009-06-02 20:37 1635688 c:\windows\System32\FNTCACHE.DAT
+ 2008-08-24 10:15 . 2009-06-02 16:38 40676050 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-22 1037608]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3198850635-3864095973-2275556364-1000]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{093A98ED-E568-4F0F-B2FB-CC70D975C99D}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{DE5A48C5-F572-4A32-9A1B-35F21ABF82AA}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{E297E9A1-3FA1-443E-9542-F4C9C476E98A}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{4BA69C72-496D-4748-B1AB-99070A33E8D9}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{B52A64D0-133F-4E84-AEB2-1F5D0665EBE0}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{FFF650C9-9EE3-430A-ADFB-A340224C7AE7}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{0C44E26D-3970-4D11-B586-D7093BEA60A1}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4D180EA7-9E78-4FD0-96FF-B754BABE6384}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A5B273F6-B093-4160-94ED-AD06063189D5}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{604EF47D-A2EB-44B1-A5EB-5A0F0F490041}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"TCP Query User{1BBB7BF0-5A2B-47BB-B013-D2E3DE048A24}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{0EF6ED46-F2BC-4CA4-89D1-22A36E99FC98}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{99F2EBC7-F774-4DE2-BD1B-C40091BD664E}"= UDP:27662:BitComet 27662 TCP
"{8C756DC5-0200-4EDE-9038-F14A451EDA80}"= TCP:27662:BitComet 27662 UDP
"{6D15FF4E-19DE-4CEF-9792-B778B5CBCC78}"= UDP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{350F64DC-75F0-441F-B470-EF51CD69D96B}"= TCP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{DBDA2FB7-61C5-4F30-A6B8-D495D1CEE99F}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{25B4B7D6-3FAF-497D-AC38-6AF691CEE76F}c:\\program files\\steam\\steamapps\\veddieedder\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\veddieedder\counter-strike source\hl2.exe:hl2
"UDP Query User{DD0F5DAB-A87D-4F66-ACB4-967952971909}c:\\program files\\steam\\steamapps\\veddieedder\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\veddieedder\counter-strike source\hl2.exe:hl2
"{AD2BC52B-7008-4F60-9722-553F33D9314A}"= UDP:c:\program files\Steam\Steam.exe:Steam
"{4C8D3234-D1B1-4141-8BC0-9F824EFAF1A6}"= TCP:c:\program files\Steam\Steam.exe:Steam
"{5113B410-6F6C-4635-8735-9EF590E11AB4}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{941B7D29-0B6C-4045-8B66-929AA75CAFD5}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{907BF0B9-7E97-496B-97F6-DFB572EBE5C3}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{04F88EBD-7707-40B6-A9A5-1B9A1C0A73F3}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{453B8A78-F6FD-4B47-BA7C-AFEE5CF0E57D}"= UDP:27662:BitComet 27662 TCP
"{8819E728-FCE2-470C-963A-45AD1F6D3674}"= TCP:27662:BitComet 27662 UDP
"TCP Query User{D424E666-0A82-475A-8DA8-2B042000192E}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{56FE6D5A-123C-4649-AA4A-20353C13ED33}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{478D719D-62F0-4792-969A-255BF74481BA}"= UDP:c:\program files\SUPERAntiSpyware\RUNSAS.EXE:SUPERAntiSpyware Alternate Start
"{B760B642-8135-47CA-90E6-C3B148A14508}"= TCP:c:\program files\SUPERAntiSpyware\RUNSAS.EXE:SUPERAntiSpyware Alternate Start
"{761747B0-32F4-4D1A-BB95-413015C2E541}"= UDP:c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe:SUPERAntiSpyware Free Edition
"{4AB3D5A3-CDAA-49F1-9744-40450D7699B7}"= TCP:c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe:SUPERAntiSpyware Free Edition
"{506213E9-5FD7-4EEF-B7AB-BDA367C34AE4}"= UDP:c:\program files\SUPERAntiSpyware\SASINST.EXE:SASINST.EXE
"{F1F58DA8-5094-4B1F-8317-456C75200CFE}"= TCP:c:\program files\SUPERAntiSpyware\SASINST.EXE:SASINST.EXE
"{DEB02C8C-9BE5-473F-A990-6CF8756DF51A}"= UDP:c:\program files\SUPERAntiSpyware\SSUpdate.exe:SSUpdate.exe
"{1AF67ED2-CD5F-47D7-BD6E-2BF1F094CDB0}"= TCP:c:\program files\SUPERAntiSpyware\SSUpdate.exe:SSUpdate.exe
"{3554F478-A96D-4168-BB85-2C32A0D1BCB2}"= UDP:c:\program files\Malwarebytes' Anti-Malware\mbam.exe:Malwarebytes' Anti-Malware
"{A04DC243-34A7-4B2B-B875-C24289CAD521}"= TCP:c:\program files\Malwarebytes' Anti-Malware\mbam.exe:Malwarebytes' Anti-Malware
"{E8FBFFCE-B4CE-4103-B441-82605D025EF4}"= UDP:c:\program files\a-squared Free\a2free.exe:a-squared Free
"{30BD205B-86D3-4342-BCB6-89A3C0DBB14B}"= TCP:c:\program files\a-squared Free\a2free.exe:a-squared Free
"{8E5461DB-0AB7-4FA1-A79D-29F98B011C57}"= Disabled:UDP:c:\program files\Sierra\FEARCombat\FEARMP.exe:FEAR Combat
"{5185F3C4-77AD-47A7-A484-947BE2138ED2}"= Disabled:TCP:c:\program files\Sierra\FEARCombat\FEARMP.exe:FEAR Combat
"{C9E7984B-10C6-44FC-9DE6-D601BC27CDA9}"= Disabled:UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{4FF67F03-A4CD-4B97-9DC4-F7BFA391E2B4}"= Disabled:TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{2631842E-6E29-43C6-B522-C02EB02FF319}"= Disabled:UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{F392374F-2059-4E2B-8095-304E2BF46B34}"= Disabled:TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{D3900F41-B16C-4A55-981F-571FB592B5D1}"= UDP:c:\program files\Spyware Doctor\pctsGui.exe:Spyware Doctor
"{0ABBFCD9-F74A-4517-960E-CB1920FD3B74}"= TCP:c:\program files\Spyware Doctor\pctsGui.exe:Spyware Doctor
"{18C89647-D61D-4245-9D37-CE32E8AC3D6A}"= UDP:c:\program files\Spyware Doctor\pctsSvc.exe:pctsSvc.exe
"{16BAB245-CEDE-4EC5-BD66-BF20015F177F}"= TCP:c:\program files\Spyware Doctor\pctsSvc.exe:pctsSvc.exe
"{DC81FD51-AAD9-4E82-9E53-7411B5229FC3}"= UDP:c:\program files\Spyware Doctor\Update.exe:Update.exe
"{72B5CEE2-D24D-415F-91D4-D2A1E69B43B6}"= TCP:c:\program files\Spyware Doctor\Update.exe:Update.exe
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/2/2009 12:40 PM 108289]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 4:11 PM 16384]
R2 ETService;Empowering Technology Service;c:\program files\EMACHINES\eMachines Recovery Management\Service\ETService.exe [12/12/2008 6:09 AM 24576]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 1:42 AM 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 6:03 AM 131072]
R3 UsbFltr;WayTech USB Filter Driver1;c:\windows\System32\drivers\UsbFltr.sys [4/9/2007 9:50 AM 9600]
S3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\System32\drivers\netr28.sys [8/24/2008 7:08 AM 388096]
S3 netr73;Linksys Compact Wireless-G USB Adapter Driver for Vista;c:\windows\System32\drivers\WUSB54GCx86.sys [3/12/2007 10:12 AM 256000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = www.hotmail.com
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0409&s;=2&o;=vb32&d;=1208&m;=e620
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
FF - ProfilePath - c:\users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\z43igteg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/?src=aim
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;=
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-03 14:47
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-03 14:49
ComboFix-quarantined-files.txt 2009-06-03 18:49
ComboFix2.txt 2009-06-02 15:46
ComboFix3.txt 2009-06-01 17:06
ComboFix4.txt 2009-05-26 18:40
ComboFix5.txt 2009-06-03 18:40
Pre-Run: 49,351,512,064 bytes free
Post-Run: 49,326,542,848 bytes free
277 — E O F — 2009-04-29 18:44
Do you still want me to do what you replied with? Going to check windows update now.
Thanks,
Jens
Figured it out before I got this reply. Somehow CombFix.exe got renamed to Comb-Fix.exe (not my doing). Simply renamed it back to ComboFix.exe and let it update. Then dragged the TXT file into it and let it scan. Here's the log:
ComboFix 09-06-01.03 - Jens 06/03/2009 14:43.5 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1789.1088 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Jens\Desktop\CFScript.txt
SP: AdwareAlert *disabled* (Updated) {8FE17B8C-999D-4396-B209-DC2ABE34C169}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\eMachines_eMachinesE620_N-A_LXN260Y1708500D44B1601.MRK
c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
c:\windows\system32\drivers\Msft_User_ZuneDriver_01_07_00.Wdf
.
((((((((((((((((((((((((( Files Created from 2009-05-03 to 2009-06-03 )))))))))))))))))))))))))))))))
.
2009-06-03 18:47 . 2009-06-03 18:47 ——– d—–w- c:\users\Jens\AppData\Local\temp
2009-06-02 16:40 . 2009-03-30 14:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-02 16:40 . 2009-03-24 20:08 55640 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-02 16:40 . 2009-06-02 16:40 ——– d—–w- c:\programdata\Avira
2009-06-02 16:40 . 2009-06-02 16:40 ——– d—–w- c:\program files\Avira
2009-06-02 15:33 . 2009-06-02 15:46 ——– d-s—w- C:\Combo-Fix
2009-06-01 16:08 . 2009-06-01 16:47 ——– d—–w- C:\Rooter$
2009-05-24 15:58 . 2009-05-24 15:58 ——– d—–w- c:\program files\Trend Micro
2009-05-23 04:36 . 2009-05-23 04:37 41148 —-a-w- C:\MGlogs.zip
2009-05-23 04:36 . 2009-05-23 04:37 ——– d—–w- C:\MGtools
2009-05-21 13:46 . 2009-05-21 13:46 ——– d—–w- C:\Autoruns
2009-05-20 00:45 . 2009-05-20 00:46 ——– d—–w- c:\windows\BDOSCAN8
2009-05-12 18:41 . 2009-05-18 22:58 ——– d—–w- c:\program files\Panda Security
2009-05-12 11:53 . 2008-12-04 05:25 120832 —-a-w- c:\users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\z43igteg.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
2009-05-11 18:17 . 2009-05-11 18:17 ——– d—–w- c:\program files\Common Files\Express Digital
2009-05-11 18:17 . 2009-05-11 18:17 ——– d—–w- c:\programdata\ExpressDigital
2009-05-11 17:59 . 2009-05-11 17:59 ——– d—–w- c:\users\Jens\AppData\Roaming\ExpressDigital
2009-05-11 17:58 . 2009-05-11 17:58 ——– d—–w- c:\program files\Common Files\Nikon
2009-05-11 17:57 . 2009-05-11 17:57 ——– d—–w- c:\program files\ExpressDigital
2009-05-07 18:21 . 2009-05-07 18:21 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2009-05-07 18:20 . 2009-06-02 20:13 ——– d—–w- c:\users\Jens\AppData\Roaming\SUPERAntiSpyware.com
2009-05-07 18:20 . 2009-06-02 20:13 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-05-07 17:06 . 2009-05-07 23:24 ——– d—–w- c:\program files\Exterminate It!
2009-05-07 16:00 . 2009-05-12 18:34 4565024 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-05-07 15:57 . 2009-05-12 18:25 ——– d—–w- c:\programdata\ParetoLogic
2009-05-07 15:57 . 2009-05-12 18:25 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-05-07 13:32 . 2009-05-07 13:51 ——– d—–w- c:\programdata\Webroot
2009-05-07 13:32 . 2009-05-07 13:32 ——– d—–w- c:\users\Jens\AppData\Roaming\Webroot
2009-05-07 13:32 . 2009-05-07 13:32 ——– d—–w- c:\program files\Webroot
2009-05-06 23:32 . 2009-05-06 23:32 ——– d—–w- c:\program files\Opanda
2009-05-05 20:08 . 2009-05-05 20:08 ——– dc-h–w- c:\programdata\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 20:39 . 2009-02-11 05:37 70120 —-a-w- c:\users\Jens\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-02 20:28 . 2009-04-01 20:36 ——– d—–w- c:\program files\Common Files\AOL
2009-06-02 20:20 . 2008-08-24 10:53 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-02 20:14 . 2009-04-29 18:23 ——– d—–w- c:\program files\ffdshow
2009-06-02 20:13 . 2008-12-12 10:10 ——– d—–w- c:\program files\Google
2009-06-02 20:12 . 2009-03-21 15:27 ——– d—–w- c:\programdata\PC Tools
2009-05-24 17:40 . 2009-02-11 15:00 ——– d—–w- c:\programdata\FLEXnet
2009-05-19 03:40 . 2009-02-24 17:06 ——– d—–w- c:\program files\PowerDataRecovery
2009-05-18 23:03 . 2009-03-11 11:58 ——– d—–w- c:\programdata\Lavasoft
2009-05-12 18:34 . 2009-05-07 16:00 51092 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-05-12 11:54 . 2009-03-12 12:44 ——– d—–w- c:\program files\Windows Live Safety Center
2009-05-08 00:19 . 2009-02-16 18:39 ——– d—–w- c:\program files\Java
2009-05-07 20:30 . 2009-02-12 18:58 ——– d—–w- c:\program files\Steam
2009-05-07 15:08 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Defender
2009-05-07 15:08 . 2009-04-03 16:08 ——– d–h–w- c:\programdata\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
2009-05-03 16:46 . 2008-08-24 11:18 ——– d—–w- c:\programdata\Microsoft Help
2009-05-01 04:56 . 2009-05-01 04:56 129096 —ha-w- c:\windows\system32\mlfcache.dat
2009-05-01 00:48 . 2009-05-01 00:48 ——– d—–w- c:\program files\Common Files\PX Storage Engine
2009-04-29 19:05 . 2009-04-29 19:05 ——– d—–w- c:\program files\Windows Media Components
2009-04-29 18:36 . 2009-03-18 21:07 ——– d—–w- c:\programdata\NCH Software
2009-04-29 16:05 . 2009-04-29 16:05 ——– d—–w- c:\users\Jens\AppData\Roaming\Canon
2009-04-29 16:04 . 2009-03-18 21:07 ——– d—–w- c:\program files\NCH Software
2009-04-29 15:41 . 2009-04-29 15:30 ——– d—–w- c:\program files\Canon
2009-04-29 15:28 . 2008-12-12 10:02 ——– d—–w- c:\program files\Common Files\InstallShield
2009-04-27 22:49 . 2009-04-27 22:49 3366912 —-a-w- c:\windows\system32\GPhotos.scr
2009-04-23 18:12 . 2009-02-12 18:58 ——– d—–w- c:\program files\Common Files\Steam
2009-04-20 00:51 . 2009-04-20 00:50 ——– d—–w- c:\program files\PokerStars
2009-04-16 07:21 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-04-06 18:43 . 2009-04-06 18:42 ——– d—–w- c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor
2009-03-30 17:42 . 2009-03-30 17:42 0 —-a-w- c:\windows\nsreg.dat
2009-03-19 15:08 . 2009-03-19 15:08 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-03-19 15:08 . 2009-03-19 15:08 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-03-17 03:38 . 2009-04-16 03:42 13824 —-a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 03:42 24064 —-a-w- c:\windows\system32\amxread.dll
2009-03-10 23:58 . 2009-03-10 23:58 98304 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-03-09 09:19 . 2009-02-16 18:40 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2009-04-29 18:34 914944 —-a-w- c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-04-29 18:34 43008 —-a-w- c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-04-29 18:34 18944 —-a-w- c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-04-29 18:34 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-04-29 18:34 109568 —-a-w- c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-04-29 18:34 132608 —-a-w- c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-04-29 18:34 107520 —-a-w- c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-04-29 18:34 107008 —-a-w- c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-04-29 18:34 103936 —-a-w- c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-04-29 18:34 420352 —-a-w- c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-04-29 18:34 72704 —-a-w- c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-04-29 18:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-04-29 18:34 66560 —-a-w- c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-04-29 18:34 169472 —-a-w- c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-04-29 18:34 34816 —-a-w- c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-04-29 18:34 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-04-29 18:34 45568 —-a-w- c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-04-29 18:34 156160 —-a-w- c:\windows\system32\msls31.dll
2009-03-06 13:06 . 2009-03-06 13:06 140800 —-a-w- c:\windows\system32\drivers\Rtlh86.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-05-24_15.41.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-02 16:37 . 2009-06-02 16:37 54272 c:\windows\winsxs\x86_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_ecdf8c290e547f3
9\vcomp90.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 62976 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90RUS.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 46080 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90KOR.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 46592 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90JPN.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 64512 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ITA.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 66048 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90FRA.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 65024 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ESP.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 65024 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ESN.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 56832 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90ENU.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 66560 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90DEU.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 39936 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90CHT.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 38912 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e
1\MFC90CHS.DLL
+ 2009-06-02 16:37 . 2009-06-02 16:37 59904 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 59904 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll
+ 2008-01-21 01:58 . 2009-06-03 17:37 59234 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02 . 2009-06-03 17:37 79280 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-11 05:37 . 2009-06-03 17:37 13050 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3198850635-3864095973-2275556364-1000_UserData.bin
+ 2009-06-02 16:40 . 2009-02-13 16:50 28376 c:\windows\System32\drivers\ssmdrv.sys
- 2009-02-11 05:33 . 2009-05-24 14:23 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-11 05:33 . 2009-06-02 18:58 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-11 05:33 . 2009-06-02 18:58 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-02 18:58 . 2009-06-02 18:58 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009060220090603\index.dat
+ 2009-02-11 05:33 . 2009-06-02 18:58 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-05-24 15:37 . 2009-05-24 15:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-06-03 17:35 . 2009-06-03 17:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-24 15:37 . 2009-05-24 15:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-03 17:35 . 2009-06-03 17:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-06-02 16:37 . 2009-06-02 16:37 655872 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 572928 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 225280 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 161784 c:\windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e\ATL90.dll
+ 2006-11-02 10:33 . 2009-05-27 17:22 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-21 19:33 595684 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-05-27 17:22 101350 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-05-21 19:33 101350 c:\windows\System32\perfc009.dat
- 2009-04-29 18:55 . 2009-05-23 01:09 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-04-29 18:55 . 2009-05-26 22:50 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-06-02 16:37 . 2009-06-02 16:37 3783672 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll
+ 2009-06-02 16:37 . 2009-06-02 16:37 3768312 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll
- 2006-11-02 10:22 . 2009-05-09 00:47 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-06-02 19:35 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 12:44 . 2009-06-02 20:37 1635688 c:\windows\System32\FNTCACHE.DAT
+ 2008-08-24 10:15 . 2009-06-02 16:38 40676050 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-02-22 1037608]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3198850635-3864095973-2275556364-1000]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{093A98ED-E568-4F0F-B2FB-CC70D975C99D}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{DE5A48C5-F572-4A32-9A1B-35F21ABF82AA}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{E297E9A1-3FA1-443E-9542-F4C9C476E98A}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{4BA69C72-496D-4748-B1AB-99070A33E8D9}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{B52A64D0-133F-4E84-AEB2-1F5D0665EBE0}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{FFF650C9-9EE3-430A-ADFB-A340224C7AE7}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{0C44E26D-3970-4D11-B586-D7093BEA60A1}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4D180EA7-9E78-4FD0-96FF-B754BABE6384}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A5B273F6-B093-4160-94ED-AD06063189D5}"= UDP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{604EF47D-A2EB-44B1-A5EB-5A0F0F490041}"= TCP:c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"TCP Query User{1BBB7BF0-5A2B-47BB-B013-D2E3DE048A24}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{0EF6ED46-F2BC-4CA4-89D1-22A36E99FC98}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{99F2EBC7-F774-4DE2-BD1B-C40091BD664E}"= UDP:27662:BitComet 27662 TCP
"{8C756DC5-0200-4EDE-9038-F14A451EDA80}"= TCP:27662:BitComet 27662 UDP
"{6D15FF4E-19DE-4CEF-9792-B778B5CBCC78}"= UDP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{350F64DC-75F0-441F-B470-EF51CD69D96B}"= TCP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{DBDA2FB7-61C5-4F30-A6B8-D495D1CEE99F}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{25B4B7D6-3FAF-497D-AC38-6AF691CEE76F}c:\\program files\\steam\\steamapps\\veddieedder\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\veddieedder\counter-strike source\hl2.exe:hl2
"UDP Query User{DD0F5DAB-A87D-4F66-ACB4-967952971909}c:\\program files\\steam\\steamapps\\veddieedder\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\veddieedder\counter-strike source\hl2.exe:hl2
"{AD2BC52B-7008-4F60-9722-553F33D9314A}"= UDP:c:\program files\Steam\Steam.exe:Steam
"{4C8D3234-D1B1-4141-8BC0-9F824EFAF1A6}"= TCP:c:\program files\Steam\Steam.exe:Steam
"{5113B410-6F6C-4635-8735-9EF590E11AB4}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{941B7D29-0B6C-4045-8B66-929AA75CAFD5}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{907BF0B9-7E97-496B-97F6-DFB572EBE5C3}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{04F88EBD-7707-40B6-A9A5-1B9A1C0A73F3}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{453B8A78-F6FD-4B47-BA7C-AFEE5CF0E57D}"= UDP:27662:BitComet 27662 TCP
"{8819E728-FCE2-470C-963A-45AD1F6D3674}"= TCP:27662:BitComet 27662 UDP
"TCP Query User{D424E666-0A82-475A-8DA8-2B042000192E}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{56FE6D5A-123C-4649-AA4A-20353C13ED33}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{478D719D-62F0-4792-969A-255BF74481BA}"= UDP:c:\program files\SUPERAntiSpyware\RUNSAS.EXE:SUPERAntiSpyware Alternate Start
"{B760B642-8135-47CA-90E6-C3B148A14508}"= TCP:c:\program files\SUPERAntiSpyware\RUNSAS.EXE:SUPERAntiSpyware Alternate Start
"{761747B0-32F4-4D1A-BB95-413015C2E541}"= UDP:c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe:SUPERAntiSpyware Free Edition
"{4AB3D5A3-CDAA-49F1-9744-40450D7699B7}"= TCP:c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe:SUPERAntiSpyware Free Edition
"{506213E9-5FD7-4EEF-B7AB-BDA367C34AE4}"= UDP:c:\program files\SUPERAntiSpyware\SASINST.EXE:SASINST.EXE
"{F1F58DA8-5094-4B1F-8317-456C75200CFE}"= TCP:c:\program files\SUPERAntiSpyware\SASINST.EXE:SASINST.EXE
"{DEB02C8C-9BE5-473F-A990-6CF8756DF51A}"= UDP:c:\program files\SUPERAntiSpyware\SSUpdate.exe:SSUpdate.exe
"{1AF67ED2-CD5F-47D7-BD6E-2BF1F094CDB0}"= TCP:c:\program files\SUPERAntiSpyware\SSUpdate.exe:SSUpdate.exe
"{3554F478-A96D-4168-BB85-2C32A0D1BCB2}"= UDP:c:\program files\Malwarebytes' Anti-Malware\mbam.exe:Malwarebytes' Anti-Malware
"{A04DC243-34A7-4B2B-B875-C24289CAD521}"= TCP:c:\program files\Malwarebytes' Anti-Malware\mbam.exe:Malwarebytes' Anti-Malware
"{E8FBFFCE-B4CE-4103-B441-82605D025EF4}"= UDP:c:\program files\a-squared Free\a2free.exe:a-squared Free
"{30BD205B-86D3-4342-BCB6-89A3C0DBB14B}"= TCP:c:\program files\a-squared Free\a2free.exe:a-squared Free
"{8E5461DB-0AB7-4FA1-A79D-29F98B011C57}"= Disabled:UDP:c:\program files\Sierra\FEARCombat\FEARMP.exe:FEAR Combat
"{5185F3C4-77AD-47A7-A484-947BE2138ED2}"= Disabled:TCP:c:\program files\Sierra\FEARCombat\FEARMP.exe:FEAR Combat
"{C9E7984B-10C6-44FC-9DE6-D601BC27CDA9}"= Disabled:UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{4FF67F03-A4CD-4B97-9DC4-F7BFA391E2B4}"= Disabled:TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{2631842E-6E29-43C6-B522-C02EB02FF319}"= Disabled:UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{F392374F-2059-4E2B-8095-304E2BF46B34}"= Disabled:TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{D3900F41-B16C-4A55-981F-571FB592B5D1}"= UDP:c:\program files\Spyware Doctor\pctsGui.exe:Spyware Doctor
"{0ABBFCD9-F74A-4517-960E-CB1920FD3B74}"= TCP:c:\program files\Spyware Doctor\pctsGui.exe:Spyware Doctor
"{18C89647-D61D-4245-9D37-CE32E8AC3D6A}"= UDP:c:\program files\Spyware Doctor\pctsSvc.exe:pctsSvc.exe
"{16BAB245-CEDE-4EC5-BD66-BF20015F177F}"= TCP:c:\program files\Spyware Doctor\pctsSvc.exe:pctsSvc.exe
"{DC81FD51-AAD9-4E82-9E53-7411B5229FC3}"= UDP:c:\program files\Spyware Doctor\Update.exe:Update.exe
"{72B5CEE2-D24D-415F-91D4-D2A1E69B43B6}"= TCP:c:\program files\Spyware Doctor\Update.exe:Update.exe
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/2/2009 12:40 PM 108289]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 4:11 PM 16384]
R2 ETService;Empowering Technology Service;c:\program files\EMACHINES\eMachines Recovery Management\Service\ETService.exe [12/12/2008 6:09 AM 24576]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 1:42 AM 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 6:03 AM 131072]
R3 UsbFltr;WayTech USB Filter Driver1;c:\windows\System32\drivers\UsbFltr.sys [4/9/2007 9:50 AM 9600]
S3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\System32\drivers\netr28.sys [8/24/2008 7:08 AM 388096]
S3 netr73;Linksys Compact Wireless-G USB Adapter Driver for Vista;c:\windows\System32\drivers\WUSB54GCx86.sys [3/12/2007 10:12 AM 256000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = www.hotmail.com
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l;=0409&s;=2&o;=vb32&d;=1208&m;=e620
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
FF - ProfilePath - c:\users\Jens\AppData\Roaming\Mozilla\Firefox\Profiles\z43igteg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com/?src=aim
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;=
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-03 14:47
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-03 14:49
ComboFix-quarantined-files.txt 2009-06-03 18:49
ComboFix2.txt 2009-06-02 15:46
ComboFix3.txt 2009-06-01 17:06
ComboFix4.txt 2009-05-26 18:40
ComboFix5.txt 2009-06-03 18:40
Pre-Run: 49,351,512,064 bytes free
Post-Run: 49,326,542,848 bytes free
277 — E O F — 2009-04-29 18:44
Do you still want me to do what you replied with? Going to check windows update now.
Thanks,
Jens