That one took a while, finally done. Computer already feels like it's going faster, did that do anything?
Attached is the combofix file.
ComboFix 09-07-07.A2 - Tony 08/07/2009 14:55.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.61.1033.18.1919.828 [GMT 10:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
SP: Norton Internet Security *disabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Tony\Tony.exe
c:\windows\PGMonitor.exe
c:\windows\system32\acovcnt.exe
c:\windows\system32\drivers\UACkffppckpsawnjhxpe.sys
c:\windows\system32\UACgyulbdmgpqhdrvyob.dll
c:\windows\system32\UAChtnvtqipbsmeflqto.db
c:\windows\system32\uacinit.dll
c:\windows\system32\UACmabxwpyrcwoeljwio.dll
c:\windows\system32\UACmnwlujfwbyojhlfit.dat
c:\windows\system32\UACmrxwnhmjgpxpbepqc.dll
c:\windows\system32\UACsjyjouueenumpkprk.dll
c:\windows\system32\UACsoittuqpowbkpscuo.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.
2009-07-08 05:19 . 2009-07-08 05:19 ——– d—–w- c:\users\Tony\AppData\Local\temp
2009-07-07 05:34 . 2009-07-07 05:34 ——– d—–w- c:\users\Tony\AppData\Roaming\Malwarebytes
2009-07-07 05:28 . 2009-06-17 01:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-07 05:28 . 2009-07-07 11:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-07 05:28 . 2009-07-07 05:28 ——– d—–w- c:\programdata\Malwarebytes
2009-07-07 05:28 . 2009-06-17 01:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-21 07:38 . 2009-06-21 07:38 ——– d—–w- c:\users\Tony\AppData\Roaming\Megaupload
2009-06-21 07:37 . 2009-06-21 07:37 ——– d—–w- c:\program files\Megaupload
2009-06-21 07:36 . 2009-06-21 07:36 ——– d—–w- c:\users\Tony\AppData\Roaming\InstallShield
2009-06-15 01:14 . 2009-04-30 12:42 428032 —-a-w- c:\windows\system32\EncDec.dll
2009-06-15 01:14 . 2009-04-30 12:52 292352 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-15 01:14 . 2009-04-30 12:44 1244672 —-a-w- c:\windows\system32\mcmde.dll
2009-06-13 00:52 . 2009-06-13 00:52 ——– d—–w- c:\program files\Xvid
2009-06-12 10:59 . 2009-06-12 10:59 ——– d—–w- c:\program files\MKVtoolnix
2009-06-12 10:50 . 2009-06-12 10:55 ——– d—–w- c:\users\Tony\AppData\Local\StaxRip
2009-06-12 10:49 . 2009-06-12 10:49 ——– d—–w- c:\program files\StaxRip
2009-06-12 02:27 . 2009-04-21 11:55 2030080 —-a-w- c:\windows\system32\win32k.sys
2009-06-12 02:27 . 2009-04-23 13:01 788992 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-12 02:27 . 2009-04-23 12:56 696832 —-a-w- c:\windows\system32\localspl.dll
2009-06-11 11:58 . 2009-06-13 04:33 ——– d—–w- c:\program files\megui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-07 15:19 . 2008-03-12 09:46 12 —-a-w- c:\windows\bthservsdp.dat
2009-07-07 13:16 . 2008-04-15 08:32 89960 —-a-w- c:\users\Tony\AppData\Roaming\nvModes.dat
2009-07-03 05:15 . 2008-04-12 10:49 ——– d—–w- c:\users\Tony\AppData\Roaming\.BitTornado
2009-07-02 11:38 . 2009-01-09 13:16 ——– d—–w- c:\users\Tony\AppData\Roaming\dvdcss
2009-06-21 07:37 . 2008-03-12 12:06 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-21 07:16 . 2008-03-12 12:26 ——– d—–w- c:\program files\PowerForPhone
2009-06-21 07:14 . 2009-03-19 04:44 ——– d—–w- c:\program files\Free Download Manager
2009-06-21 07:14 . 2009-03-19 04:44 ——– d—–w- c:\users\Tony\AppData\Roaming\Free Download Manager
2009-06-21 04:19 . 2008-04-12 10:01 ——– d—–w- c:\users\Tony\AppData\Roaming\Apple Computer
2009-06-16 03:16 . 2008-03-12 09:53 ——– d—–w- c:\programdata\Microsoft Help
2009-06-05 12:11 . 2009-06-05 12:11 1878984 —-a-w- c:\users\Tony\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-05-24 02:46 . 2009-03-18 11:44 ——– d—–w- c:\users\Tony\AppData\Roaming\AccurateRip
2009-05-15 04:26 . 2008-04-15 10:21 ——– d—–w- c:\users\Tony\AppData\Roaming\LimeWire
2009-05-15 00:30 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-04-27 01:38 . 2008-04-12 07:43 105296 —-a-w- c:\users\Tony\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-24 16:22 . 2009-06-12 02:26 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:14 . 2009-06-12 02:26 56320 —-a-w- c:\windows\system32\iesetup.dll
2009-04-24 16:14 . 2009-06-12 02:26 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 16:11 . 2009-06-12 02:26 72704 —-a-w- c:\windows\system32\admparse.dll
2009-04-24 13:53 . 2009-06-12 02:26 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-24 12:25 . 2009-06-12 02:26 48128 —-a-w- c:\windows\system32\mshtmler.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08 143360 —-a-w- c:\program files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-04-12 1232896]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-06-20 451872]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"iSproggler"="c:\program files\iSproggler-1.1.0\iSproggler\iSproggler.exe" [2008-12-16 17694283]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-04-14 2321600]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-03-12 1006264]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-05-14 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-14 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-14 81920]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-09-03 630784]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 61440]
"ASUSTPE"="c:\windows\system32\ASUSTPE.exe" [2007-01-16 106496]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 857648]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2008-03-12 37232]
"ASUS Screen Saver Protector"="c:\windows\ASScrPro.exe" [2008-03-12 33136]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-13 144784]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-30 648072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-03 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-23 33648]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-07-06 4669440]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-06-15 1826816]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
VPN Client.lnk - c:\windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2008-4-14 6144]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{10F25708-3450-401E-B70F-B4C309A4BA64}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6BC3C445-B836-4CFE-9A37-888FD2CD98CC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{59C470D3-DA2F-40B6-8B05-706CC4DE85C6}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{BC823DCF-CAEB-44F6-9D18-4E8B2FE1F38C}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{07B72A99-2056-4A16-80FF-3FED4975C096}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{A2D3C555-9D43-4C64-BAB4-E9ADAD0D7412}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{8081456E-9BDF-4ACB-9F5E-872065EA032F}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{14BF6034-45EB-46FB-B017-36FD45CA5BB5}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{96BB88C9-05A7-440C-AA79-A53887955481}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E22C0CA2-FED3-4590-B507-21BC506DFC5C}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20080521.001\IDSvix86.sys [22/05/2008 11:12 AM 261680]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/04/2008 6:24 PM 109616]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [3/10/2008 1:14 PM 37936]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-06-22 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Tony.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-01-14 01:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.asus.com
uInternet Settings,ProxyOverride = *.local
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\f5ty5po5.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-08 15:19
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\users\Tony\AppData\Local\Temp\catchme.dll 53248 bytes executable
C:\ADSM_PData_0150
scan completed successfully
hidden files: 2
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3955432054-374707567-2575976948-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{D356F652-8C25-9B6B-EDA8-FB6BC88E097B}*]
"hakkngpbjcalomja"=hex:6b,61,6d,6a,62,69,62,6d,67,67,6d,6b,6d,66,65,6d,6d,6e,
6b,62,69,6a,00,00
"iaallijhecieobkdeh"=hex:6b,61,6d,6a,6d,6c,65,6c,67,66,6b,6d,64,64,6e,63,65,63,
68,6b,61,61,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-07-08 15:24
ComboFix-quarantined-files.txt 2009-07-08 05:24
Pre-Run: 40,970,657,792 bytes free
Post-Run: 41,764,454,400 bytes free
201 — E O F — 2009-07-07 11:39