hey there.
thanks for the tip. i just ran combofix again. this time it must have worked properly cos it told me it would produce a txt file.
here it is below.
by the way can you give me some pointers.
i had to uninstall my virgin media pc guard to run combofix as it has active virus and spyware apps on it. cos i couldn't remember the password to open the program to let me disable them! and now my pc is so much faster. and while i type this the pc aint crashed once. touch wood!!! can you tell what you think the best free anti virus + spyward program is out to download, is it avg free. preferrably one which is good but fast?
cheers here is the combolog txt file.
also can you tell how to speed up the pc. eg removing the files that start up automatically cos it usually take long time before can start something as all these programs are trying to start!!
ComboFix 09-07-01.04 - Mickey 02/07/2009 19:44.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.44.1033.18.447.98 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboaFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\windows\system32\drivers\MSIVXqfjdvnrdixdorchavfqxdkgjecgegpmb.sys
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXjdwgjuktwlhntiepwjaufsralupidndp.dll
c:\windows\system32\MSIVXvwnlkcaxjnwioxpsmimrigbtayvhrane.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_MSIVXserv.sys
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))))))))
.
2009-07-02 18:51 . 2009-07-02 18:52 ——– d—–w- c:\users\Mickey\AppData\Local\temp
2009-07-02 18:51 . 2009-07-02 18:51 ——– d—–w- c:\users\Kelly\AppData\Local\temp
2009-07-02 18:31 . 2009-07-02 18:31 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb18BF.tmp.exe
2009-07-01 18:25 . 2009-07-01 18:25 ——– d-s—w- C:\Combo-Fix
2009-07-01 08:43 . 2009-07-01 08:43 ——– d—–w- c:\users\Kelly\AppData\Roaming\CyberLink
2009-07-01 08:36 . 2009-07-01 08:36 ——– d—–w- c:\users\Kelly\AppData\Local\Apple Computer
2009-06-29 09:04 . 2009-06-29 09:04 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbDBEE.tmp.exe
2009-06-28 08:32 . 2009-06-28 08:32 ——– d—–w- c:\users\Mickey\AppData\Local\Apple
2009-06-28 08:25 . 2009-06-28 08:25 ——– d—–w- c:\users\Mickey\AppData\Local\Apple Computer
2009-06-27 16:12 . 2009-06-27 16:11 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb6F28.tmp.exe
2009-06-27 15:51 . 2009-06-27 15:51 ——– d—–w- c:\program files\iPod
2009-06-17 22:17 . 2009-06-17 22:17 ——– d—–w- c:\users\Kelly\AppData\Roaming\Malwarebytes
2009-06-17 21:48 . 2009-03-19 15:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-17 21:48 . 2008-04-17 11:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-06-17 21:39 . 2009-06-23 18:52 ——– d—–w- c:\program files\iTunes
2009-06-17 21:39 . 2009-06-17 21:47 ——– d—–w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-17 21:25 . 2009-06-17 21:26 ——– d—–w- c:\program files\QuickTime
2009-06-17 21:18 . 2009-06-17 21:18 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-17 19:17 . 2009-06-17 19:17 ——– d–h–w- c:\windows\PIF
2009-06-16 18:53 . 2009-06-17 19:59 117760 —-a-w- c:\users\Mickey\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-16 18:52 . 2009-06-16 18:52 ——– d—–w- c:\programdata\SUPERAntiSpyware.com
2009-06-16 18:47 . 2009-06-16 18:47 ——– d—–w- c:\users\Mickey\AppData\Roaming\SUPERAntiSpyware.com
2009-06-15 21:26 . 2009-06-15 21:26 ——– d—–w- c:\users\Mickey\AppData\Roaming\Malwarebytes
2009-06-15 21:02 . 2009-05-26 12:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 21:02 . 2009-06-23 18:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 21:02 . 2009-06-15 21:02 ——– d—–w- c:\programdata\Malwarebytes
2009-06-15 21:02 . 2009-05-26 12:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-14 21:13 . 2009-06-14 21:13 ——– d—–w- C:\1fd72c35818bff34e24c1e4c14831d0f
2009-06-14 20:19 . 2009-06-14 20:19 ——– d—–w- c:\windows\Sun
2009-06-11 18:28 . 2009-04-21 12:04 2028032 —-a-w- c:\windows\system32\win32k.sys
2009-06-11 18:27 . 2009-04-23 12:56 696832 —-a-w- c:\windows\system32\localspl.dll
2009-06-11 18:22 . 2009-04-23 13:01 788992 —-a-w- c:\windows\system32\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 19:04 . 2007-12-31 19:58 ——– d—–w- c:\users\Kelly\AppData\Roaming\Virgin Broadband
2009-07-01 19:04 . 2007-12-31 13:50 ——– d—–w- c:\users\Mickey\AppData\Roaming\Virgin Broadband
2009-07-01 19:04 . 2007-12-31 13:49 ——– d—–w- c:\programdata\Virgin Broadband
2009-07-01 19:04 . 2007-12-31 13:47 ——– d—–w- c:\program files\Virgin Broadband
2009-06-23 17:20 . 2008-05-26 21:40 1356 —-a-w- c:\users\Mickey\AppData\Local\d3d9caps.dat
2009-06-17 21:42 . 2008-01-01 15:46 ——– d—–w- c:\program files\Common Files\Apple
2009-05-13 21:03 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-10 20:53 . 2009-05-10 20:53 ——– d—–w- c:\program files\Apple Software Update
2009-04-24 16:22 . 2009-06-11 18:23 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:14 . 2009-06-11 18:23 56320 —-a-w- c:\windows\system32\iesetup.dll
2009-04-24 16:14 . 2009-06-11 18:23 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 16:11 . 2009-06-11 18:23 72704 —-a-w- c:\windows\system32\admparse.dll
2009-04-24 13:53 . 2009-06-11 18:23 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-24 12:25 . 2009-06-11 18:23 48128 —-a-w- c:\windows\system32\mshtmler.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-16 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-01-24 319488]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-07 464168]
"PCMService"="c:\acer\Empowering Technology\eMode\PCM\PCMService.exe" [2007-01-13 151552]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-06 57344]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-16 151552]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"Broadbandadvisor.exe"="c:\program files\Virgin Broadband\advisor\Broadbandadvisor.exe" [2007-08-07 2061552]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 528384]
"Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-23 4423680]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-16 151552]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-2-14 528384]
ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-6-29 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A3FC06DA-DC2E-412B-8BA2-841286041986}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{602A864E-D914-428B-B1D5-8EF09128712F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5005C520-8B41-4CF4-BD29-9CBA1EFB039C}"= UDP:c:\acer\Empowering Technology\eMode\PCM\PCMService.exe:CyberLink PowerCinema Resident Program
"{89FBBB22-34FD-4C8C-992E-FF69A60C42A8}"= TCP:c:\acer\Empowering Technology\eMode\PCM\PCMService.exe:CyberLink PowerCinema Resident Program
"{E83D495F-7451-4DD5-BF2C-9295CAE063BC}"= UDP:c:\program files\360Share Pro\Gui\360SharePro.exe:360Share Pro
"{FDE0259F-FFE5-4A3C-93F6-3CCCD31B3231}"= TCP:c:\program files\360Share Pro\Gui\360SharePro.exe:360Share Pro
"{941F6F98-93BD-4208-B72E-0E0FFB78F30B}"= UDP:c:\program files\Java\jre1.5.0_09\bin\javaw.exe:javaw
"{86D26736-A89A-43ED-80FD-014409AD44C8}"= TCP:c:\program files\Java\jre1.5.0_09\bin\javaw.exe:javaw
"{D50A7996-A45A-4502-82B0-92B59BA2717D}"= UDP:c:\program files\Java\jre1.5.0_09\bin\javaws.exe:javaws
"{F3EE06F5-8989-4BF0-AD61-3E6388EBAAFA}"= TCP:c:\program files\Java\jre1.5.0_09\bin\javaws.exe:javaws
"{61E63B01-72F7-4AA6-B672-37E8B455A479}"= UDP:c:\program files\Java\jre1.5.0_09\bin\java.exe:java
"{FE67E60F-F94F-451B-B465-DA35178F821D}"= TCP:c:\program files\Java\jre1.5.0_09\bin\java.exe:java
"{E76900A3-1889-42A8-B6E5-620C3D26F8F9}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{AF1BF9C9-275E-44FB-B3E7-48F8F61061A2}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{3CFA809D-7201-49EC-96DB-65B5C8F2EB09}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{A8755A13-F0A5-4B82-8998-97E44E6775CA}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{7F8C35AD-1C00-48CF-A9FF-50B2EA086F1C}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{6C3C10A8-6C6C-4126-8341-776A4EC1A23C}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{E37F97B0-0B38-4B07-A7CF-F6B38921EBFC}c:\\users\\mickey\\program files\\dna\\btdna.exe"= UDP:c:\users\mickey\program files\dna\btdna.exe:btdna.exe
"UDP Query User{8204E6AE-C376-45F3-B401-13F5EFE9DD9C}c:\\users\\mickey\\program files\\dna\\btdna.exe"= TCP:c:\users\mickey\program files\dna\btdna.exe:btdna.exe
"TCP Query User{39A5A3F4-4F49-46C3-88A5-C94A2F8C6389}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{FAE4FF25-E48C-4FCC-A702-1EC08579BEAE}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{6D9DE3A9-7F46-43BD-AA71-59C5AB0253C3}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{431CC742-061E-4BF7-A600-F9739A544BB7}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{D12CFB78-B712-4049-BF76-AD4F574B55AD}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{99E18B0A-97BD-425C-9EFE-1ABEF6AFFBC2}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{4A4EF83A-410F-4D34-9C27-2FD27FBBE6A9}"= UDP:c:\program files\PLUSCOM\WU-ZD1211B Wireless Utility\ZDWlan.exe:WU-ZD1211B Wireless Utility
"{FB1BB5E5-0148-4EE2-9FF1-2D3B37EA7CCB}"= TCP:c:\program files\PLUSCOM\WU-ZD1211B Wireless Utility\ZDWlan.exe:WU-ZD1211B Wireless Utility
"{8AB6C5B9-E41E-4048-99FC-EF6BA2011AE6}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{1721A3CE-B613-40D1-9B5D-C7263259CB98}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{FDDDB41E-8ABA-41EC-9E88-22F4259559C6}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{C049EC61-0581-4DCB-9E3E-EBE686645328}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{54A8FB84-BC50-4B7A-9729-79C32CAD96C5}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"{A50E877B-B206-43AF-9CF0-8FF21E11A751}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
"TCP Query User{8EDB4F17-D927-4F2F-8FBB-3A7D9A9AB1B3}c:\\windows\\system32\\java.exe"= UDP:c:\windows\system32\java.exe:Java™ 2 Platform Standard Edition binary
"UDP Query User{87FBE4C2-A96F-4E6C-ADA1-119544A70CF7}c:\\windows\\system32\\java.exe"= TCP:c:\windows\system32\java.exe:Java™ 2 Platform Standard Edition binary
"{26F1F4D8-63F2-49A0-BBED-12A74EDDB68F}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{8CA77966-50D9-41A2-B2A4-96381166660B}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{28DBE92B-18AC-4434-99CE-202A74C780B2}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{EA8A15D0-5865-4C7F-ADE7-80FB97C62D06}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{832E5870-7504-41FF-954F-3BC94021A5BA}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{28850772-7E07-48DF-B27D-D75C0C193B07}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2007-12-26 288768]
R3 ZDPSp60;ZDPSp60 NDIS Protocol Driver;c:\windows\system32\Drivers\ZDPSp60.sys [x]
S3 athrusb6;Atheros Wireless LAN USB device driver 6 Series;c:\windows\system32\DRIVERS\athru6.sys [2007-07-05 873472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPER help.exe
HKLM-Run-Setresolution - c:\acersw\config\1440x900.cmd
HKLM-Run-Apanel - c:\acersw\config\NewSetApanel.cmd
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
mStart Page = hxxp://en.uk.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-02 19:52
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1465822639-1801902029-3587921670-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*5*ø[]
@Class="Shell"
[HKEY_USERS\S-1-5-21-1465822639-1801902029-3587921670-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*5*ø[\OpenWithList]
@Class="Shell"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'Explorer.exe'(3696)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
Completion time: 2009-07-02 19:55
ComboFix-quarantined-files.txt 2009-07-02 18:55
Pre-Run: 42,240,909,312 bytes free
Post-Run: 42,214,576,128 bytes free
219 — E O F — 2009-07-01 08:55