jsmith82
Topic Starter
I have been having problems getting rid of an unknown infection or infections on my desktop for the last month, it runs the Windows XP OS and I use Microsoft Security Essentials as AV program. I was reading a topic posted by someone with a similar problem so I already completed the tasks that were suggested to them. I downloaded and ran both ATF cleaner and combo fix. I have posted the log from combo fix below, can someone please tell me what to do next? Thanks
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.112 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\MSN6
c:\documents and settings\All Users\Application Data\MSN6\au.ini
c:\documents and settings\Owner\Application Data\ezLife
c:\documents and settings\Owner\Application Data\Messenger
c:\documents and settings\Owner\Application Data\Messenger\Drivers\Aud32\msgasst84.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\Aud32\msgutil84.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\conf.sys
c:\documents and settings\Owner\Application Data\Messenger\Drivers\IgfxSys.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\MsgUpdate.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\serial.sys
c:\documents and settings\Owner\Application Data\MSN6
c:\documents and settings\Owner\Application Data\MSN6\msndata.dat
c:\documents and settings\Owner\Application Data\Smart-Ads-Solutions
c:\documents and settings\Owner\Application Data\SystemProc
C:\Documents
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\windows\system32\flags.ini
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\system32\kbdsock.dll
c:\windows\system32\mshlps.dll
c:\windows\system32\uses32.dat
c:\windows\system32\warning.html
—– BITS: Possible infected sites —–
hxxp://85.12.18.119
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-12-24 to 2010-01-24 )))))))))))))))))))))))))))))))
.
2010-01-22 22:26 . 2010-01-22 22:26 30784 —-a-w- c:\windows\system32\drivers\xfkkyisy.sys
2010-01-22 04:46 . 2010-01-22 05:29 ——– d—–w- c:\documents and settings\Owner\.lincity-ng
2010-01-20 23:10 . 2010-01-20 23:10 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Eastman_Kodak_Company
2010-01-20 23:10 . 2010-01-20 23:10 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Eastman Kodak Company
2010-01-20 02:49 . 2010-01-20 02:49 ——– d—–w- c:\documents and settings\Owner\.lincity
2010-01-20 02:47 . 2010-01-22 04:54 ——– d—–w- c:\program files\LinCity-NG
2010-01-20 02:44 . 2010-01-20 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-01-19 20:13 . 2010-01-19 20:13 30784 —-a-w- c:\windows\system32\drivers\csofzotk.sys
2010-01-19 20:03 . 2010-01-19 20:03 30784 —-a-w- c:\windows\system32\drivers\rhidanio.sys
2010-01-19 18:28 . 2010-01-19 18:40 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2010-01-19 18:28 . 2010-01-20 02:44 ——– d—–w- c:\program files\IObit
2010-01-19 01:45 . 2010-01-19 01:45 ——– d-sh–w- c:\documents and settings\Kayla\PrivacIE
2010-01-17 18:13 . 2010-01-17 18:14 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Google
2010-01-17 16:14 . 2010-01-17 16:14 48285 —-a-w- c:\windows\system32\rybrywrprkzny.exe
2010-01-17 04:19 . 2010-01-17 04:19 ——– d—–w- c:\documents and settings\The Smiths\Local Settings\Application Data\Google
2010-01-17 04:17 . 2010-01-17 04:18 ——– d—–w- c:\documents and settings\The Smiths
2010-01-16 17:43 . 2010-01-16 17:43 30784 —-a-w- c:\windows\system32\drivers\rzirkovx.sys
2010-01-15 06:41 . 2010-01-15 06:41 53788 —ha-w- c:\windows\system32\mlfcache.dat
2010-01-15 06:23 . 2010-01-15 06:24 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-01-13 13:51 . 2010-01-13 13:51 30784 —-a-w- c:\windows\system32\drivers\ijxqeapu.sys
2010-01-12 18:53 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 15:02 . 2010-01-14 16:12 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-10 04:43 . 2010-01-10 04:50 ——– d—–w- c:\program files\Windows Live Safety Center
2010-01-10 04:04 . 2010-01-10 04:04 45568 –sh–w- c:\windows\system32\zijaputa.dll
2010-01-10 03:10 . 2010-01-10 03:10 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-10 02:55 . 2010-01-10 02:55 ——– d-sh–w- c:\documents and settings\Owner\.COMMgr
2010-01-08 15:01 . 2010-01-08 15:01 494080 —-a-w- c:\windows\system32\vclenowrbhoxi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-24 05:48 . 2008-06-20 17:18 ——– d—–w- c:\documents and settings\Owner\Application Data\LimeWire
2010-01-24 01:58 . 2008-07-09 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-22 23:02 . 2008-05-30 02:29 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-22 23:02 . 2008-05-30 02:29 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2010-01-20 17:03 . 2009-07-11 03:42 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-19 20:13 . 2010-01-19 20:13 96512 —-a-w- c:\windows\system32\drivers\atapi.sysFD1A42C6
2010-01-17 18:13 . 2010-01-17 18:13 70960 —-a-w- c:\documents and settings\Kayla\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-17 04:18 . 2010-01-17 04:18 70960 —-a-w- c:\documents and settings\The Smiths\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-14 03:58 . 2008-06-13 03:55 ——– d—–w- c:\program files\Java
2010-01-14 03:43 . 2009-03-17 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-10 15:38 . 2008-06-19 19:22 ——– d—–w- c:\program files\Hells Kitchen
2010-01-10 08:11 . 2008-10-13 04:21 ——– d—–w- c:\documents and settings\Owner\Application Data\Yahoo!
2010-01-10 03:38 . 2008-05-31 04:19 70960 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-25 20:15 . 2008-06-24 20:31 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-22 08:00 . 2006-10-28 12:11 63 —-a-w- c:\windows\Fonts\Readme.txt
2009-12-21 19:14 . 2006-06-23 15:33 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-17 02:08 . 2008-05-30 03:47 ——– d—–w- c:\program files\Google
2009-12-13 05:02 . 2008-06-20 17:15 ——– d—–w- c:\program files\LimeWire
2009-11-21 15:51 . 2002-09-03 16:26 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 08:42 . 2009-11-16 08:42 286720 —-a-w- c:\windows\system32\thbocwwa.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-31 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-01-06 2335952]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-21 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2002-06-19 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2002-06-19 114688]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-02-15 1052672]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-06 122368]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-14 149280]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-11-14 1278736]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-6-18 147456]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [1/19/2010 9:44 PM 312592]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [2/28/2008 4:57 PM 18944]
S2 gupdate1c9f2161b370444;Google Update Service (gupdate1c9f2161b370444);c:\program files\Google\Update\GoogleUpdate.exe [6/20/2009 9:13 PM 133104]
S3 MailScan;MailScan;\??\c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys [?]
S3 TFilter;TFilter;\??\c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-30 06:59]
2010-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-21 02:13]
2010-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-21 02:13]
2010-01-24 c:\windows\Tasks\User_Feed_Synchronization-{F30DD53A-C370-4B8A-9FDA-32233C3929F7}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.centurylink.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: mlb.com\secure
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{02ac71e4-2e16-426e-9c3a-fc0f2f27b08e} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-24 01:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-01-24 01:06:25
ComboFix-quarantined-files.txt 2010-01-24 06:06
Pre-Run: 52,789,854,208 bytes free
Post-Run: 52,784,582,656 bytes free
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.112 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\MSN6
c:\documents and settings\All Users\Application Data\MSN6\au.ini
c:\documents and settings\Owner\Application Data\ezLife
c:\documents and settings\Owner\Application Data\Messenger
c:\documents and settings\Owner\Application Data\Messenger\Drivers\Aud32\msgasst84.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\Aud32\msgutil84.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\conf.sys
c:\documents and settings\Owner\Application Data\Messenger\Drivers\IgfxSys.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\MsgUpdate.dll
c:\documents and settings\Owner\Application Data\Messenger\Drivers\serial.sys
c:\documents and settings\Owner\Application Data\MSN6
c:\documents and settings\Owner\Application Data\MSN6\msndata.dat
c:\documents and settings\Owner\Application Data\Smart-Ads-Solutions
c:\documents and settings\Owner\Application Data\SystemProc
C:\Documents
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
c:\program files\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\windows\system32\flags.ini
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\system32\kbdsock.dll
c:\windows\system32\mshlps.dll
c:\windows\system32\uses32.dat
c:\windows\system32\warning.html
—– BITS: Possible infected sites —–
hxxp://85.12.18.119
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-12-24 to 2010-01-24 )))))))))))))))))))))))))))))))
.
2010-01-22 22:26 . 2010-01-22 22:26 30784 —-a-w- c:\windows\system32\drivers\xfkkyisy.sys
2010-01-22 04:46 . 2010-01-22 05:29 ——– d—–w- c:\documents and settings\Owner\.lincity-ng
2010-01-20 23:10 . 2010-01-20 23:10 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Eastman_Kodak_Company
2010-01-20 23:10 . 2010-01-20 23:10 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Eastman Kodak Company
2010-01-20 02:49 . 2010-01-20 02:49 ——– d—–w- c:\documents and settings\Owner\.lincity
2010-01-20 02:47 . 2010-01-22 04:54 ——– d—–w- c:\program files\LinCity-NG
2010-01-20 02:44 . 2010-01-20 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-01-19 20:13 . 2010-01-19 20:13 30784 —-a-w- c:\windows\system32\drivers\csofzotk.sys
2010-01-19 20:03 . 2010-01-19 20:03 30784 —-a-w- c:\windows\system32\drivers\rhidanio.sys
2010-01-19 18:28 . 2010-01-19 18:40 ——– d—–w- c:\documents and settings\Owner\Application Data\IObit
2010-01-19 18:28 . 2010-01-20 02:44 ——– d—–w- c:\program files\IObit
2010-01-19 01:45 . 2010-01-19 01:45 ——– d-sh–w- c:\documents and settings\Kayla\PrivacIE
2010-01-17 18:13 . 2010-01-17 18:14 ——– d—–w- c:\documents and settings\Kayla\Local Settings\Application Data\Google
2010-01-17 16:14 . 2010-01-17 16:14 48285 —-a-w- c:\windows\system32\rybrywrprkzny.exe
2010-01-17 04:19 . 2010-01-17 04:19 ——– d—–w- c:\documents and settings\The Smiths\Local Settings\Application Data\Google
2010-01-17 04:17 . 2010-01-17 04:18 ——– d—–w- c:\documents and settings\The Smiths
2010-01-16 17:43 . 2010-01-16 17:43 30784 —-a-w- c:\windows\system32\drivers\rzirkovx.sys
2010-01-15 06:41 . 2010-01-15 06:41 53788 —ha-w- c:\windows\system32\mlfcache.dat
2010-01-15 06:23 . 2010-01-15 06:24 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-01-13 13:51 . 2010-01-13 13:51 30784 —-a-w- c:\windows\system32\drivers\ijxqeapu.sys
2010-01-12 18:53 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 15:02 . 2010-01-14 16:12 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-10 04:43 . 2010-01-10 04:50 ——– d—–w- c:\program files\Windows Live Safety Center
2010-01-10 04:04 . 2010-01-10 04:04 45568 –sh–w- c:\windows\system32\zijaputa.dll
2010-01-10 03:10 . 2010-01-10 03:10 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-10 02:55 . 2010-01-10 02:55 ——– d-sh–w- c:\documents and settings\Owner\.COMMgr
2010-01-08 15:01 . 2010-01-08 15:01 494080 —-a-w- c:\windows\system32\vclenowrbhoxi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-24 05:48 . 2008-06-20 17:18 ——– d—–w- c:\documents and settings\Owner\Application Data\LimeWire
2010-01-24 01:58 . 2008-07-09 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-22 23:02 . 2008-05-30 02:29 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-22 23:02 . 2008-05-30 02:29 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2010-01-20 17:03 . 2009-07-11 03:42 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-19 20:13 . 2010-01-19 20:13 96512 —-a-w- c:\windows\system32\drivers\atapi.sysFD1A42C6
2010-01-17 18:13 . 2010-01-17 18:13 70960 —-a-w- c:\documents and settings\Kayla\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-17 04:18 . 2010-01-17 04:18 70960 —-a-w- c:\documents and settings\The Smiths\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-14 03:58 . 2008-06-13 03:55 ——– d—–w- c:\program files\Java
2010-01-14 03:43 . 2009-03-17 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-10 15:38 . 2008-06-19 19:22 ——– d—–w- c:\program files\Hells Kitchen
2010-01-10 08:11 . 2008-10-13 04:21 ——– d—–w- c:\documents and settings\Owner\Application Data\Yahoo!
2010-01-10 03:38 . 2008-05-31 04:19 70960 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-25 20:15 . 2008-06-24 20:31 ——– d—–w- c:\program files\Common Files\Adobe
2009-12-22 08:00 . 2006-10-28 12:11 63 —-a-w- c:\windows\Fonts\Readme.txt
2009-12-21 19:14 . 2006-06-23 15:33 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-17 02:08 . 2008-05-30 03:47 ——– d—–w- c:\program files\Google
2009-12-13 05:02 . 2008-06-20 17:15 ——– d—–w- c:\program files\LimeWire
2009-11-21 15:51 . 2002-09-03 16:26 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 08:42 . 2009-11-16 08:42 286720 —-a-w- c:\windows\system32\thbocwwa.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-31 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-01-06 2335952]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe" [2009-07-21 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2002-06-19 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2002-06-19 114688]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-02-15 1052672]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-08-06 122368]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-14 149280]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-11-14 1278736]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-6-18 147456]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [1/19/2010 9:44 PM 312592]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [2/28/2008 4:57 PM 18944]
S2 gupdate1c9f2161b370444;Google Update Service (gupdate1c9f2161b370444);c:\program files\Google\Update\GoogleUpdate.exe [6/20/2009 9:13 PM 133104]
S3 MailScan;MailScan;\??\c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\MailScan.sys [?]
S3 TFilter;TFilter;\??\c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys –> c:\progra~1\AVANQU~1\SYSTEM~1\TFilter.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-30 06:59]
2010-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-21 02:13]
2010-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-21 02:13]
2010-01-24 c:\windows\Tasks\User_Feed_Synchronization-{F30DD53A-C370-4B8A-9FDA-32233C3929F7}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.centurylink.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: mlb.com\secure
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{02ac71e4-2e16-426e-9c3a-fc0f2f27b08e} - (no file)
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-24 01:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-01-24 01:06:25
ComboFix-quarantined-files.txt 2010-01-24 06:06
Pre-Run: 52,789,854,208 bytes free
Post-Run: 52,784,582,656 bytes free