peanutt031
It worked! here is the combofix report:
ComboFix 10-06-03.01 - admin 06/05/2010 12:52:27.1.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Not Claire\IDHWTSS1.dll
c:\documents and settings\Not Claire\PrtDLL.dll
c:\windows\Gzyxua.exe
c:\windows\Gzyxud.exe
c:\windows\system32\bb5l6c.dll
c:\windows\system32\bszip.dll
c:\windows\system32\ernel32.dll
c:\windows\system32\hjkkj.bak1
c:\windows\system32\hjkkj.bak2
c:\windows\system32\hjkkj.ini
c:\windows\system32\regedit.exe
c:\windows\system32\wbem\grpconv.exe
c:\windows\system32\grpconv.exe was missing
Restored copy from - c:\i386\grpconv.exe
.
((((((((((((((((((((((((( Files Created from 2010-05-05 to 2010-06-05 )))))))))))))))))))))))))))))))
.
2010-06-05 18:06 . 2004-08-10 11:00 39424 —-a-w- c:\windows\system32\grpconv.exe
2010-06-05 18:06 . 2004-08-10 11:00 39424 —-a-w- c:\windows\system32\dllcache\grpconv.exe
2010-06-04 23:16 . 2010-06-04 23:16 ——– d—–w- c:\windows\McAfee.com
2010-06-04 23:10 . 2010-06-04 23:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-06-04 22:41 . 2010-06-04 22:41 ——– d—–w- c:\program files\Yahoo!
2010-06-04 22:41 . 2010-06-04 22:46 ——– d—–w- c:\program files\CCleaner
2010-06-04 22:31 . 2010-06-04 22:31 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\Mozilla
2010-06-04 22:31 . 2010-06-04 22:31 107134 —-a-w- c:\windows\UninstallFirefox.exe
2010-06-04 22:31 . 2010-06-04 22:31 2301 —-a-w- c:\windows\mozver.dat
2010-06-04 21:56 . 2010-06-04 22:00 ——– d—–w- c:\program files\ewido anti-malware
2010-06-04 21:52 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\3u79iQGM.dll
2010-06-04 11:25 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\179wS7.dll
2010-06-04 02:32 . 2010-06-04 02:32 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-06-04 02:32 . 2010-06-04 02:32 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-04 02:01 . 2010-06-04 02:01 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-06-03 23:06 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\179u1m.dll
2010-06-03 03:44 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\wS7e31kU.dll
2010-06-03 03:36 . 2010-06-03 03:36 199168 —-a-w- c:\windows\Gzyxuc.exe
2010-06-03 03:36 . 2010-06-03 03:36 72192 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\3qGMYWS9.dll
2010-06-03 03:32 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\793179a.dll
2010-06-03 03:21 . 2010-06-03 03:21 ——– d-sh–w- c:\documents and settings\admin\PrivacIE
2010-06-03 03:21 . 2010-06-05 01:04 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\AskToolbar
2010-06-03 03:21 . 2010-06-03 03:21 ——– d—–w- c:\documents and settings\admin\Application Data\SiteAdvisor
2010-06-03 03:19 . 2010-06-03 03:19 56592 —-a-w- c:\documents and settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-03 03:17 . 2010-06-03 03:17 199168 —-a-w- c:\windows\Gzyxub.exe
2010-06-03 03:02 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\q9wSK9y.dll
2010-06-03 01:30 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\31q9wS79.dll
2010-06-03 01:14 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2010-06-03 01:03 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\9o1oCE17k.dll
2010-06-03 01:01 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-03 01:00 . 2010-06-03 01:00 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2010-06-03 01:00 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2010-06-03 01:00 . 2010-06-03 01:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-03 01:00 . 2010-06-03 01:00 ——– d—–w- c:\program files\Lavasoft
2010-06-03 00:51 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\93oCE3a7k.dll
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\documents and settings\admin\Application Data\Malwarebytes
2010-06-03 00:33 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-03 00:33 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-03 00:32 . 2010-06-03 00:32 ——– d—–w- c:\documents and settings\admin\Application Data\GlarySoft
2010-06-03 00:26 . 2010-06-03 00:26 ——– d—–w- c:\documents and settings\admin\Application Data\GTek
2010-06-03 00:25 . 2010-06-03 00:25 ——– d-sh–w- c:\documents and settings\admin\IETldCache
2010-06-03 00:23 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\c1s9eIQ9.dll
2010-06-02 23:37 . 2010-06-02 23:37 ——– d—–w- c:\documents and settings\Not Claire\Application Data\Corel Photo Album
2010-06-02 23:37 . 2010-06-02 23:37 56592 —-a-w- c:\documents and settings\Not Claire\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-02 23:37 . 2010-06-02 23:37 ——– d—–w- c:\documents and settings\Not Claire\Local Settings\Application Data\Corel Photo Album
2010-06-02 23:28 . 2010-06-02 23:28 ——– d—–w- C:\GlarySoft
2010-06-02 23:18 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-06-02 23:18 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll
2010-06-02 23:17 . 2001-08-17 19:02 9600 —-a-w- c:\windows\system32\drivers\hidusb.sys
2010-06-02 23:17 . 2001-08-17 19:02 9600 —-a-w- c:\windows\system32\dllcache\hidusb.sys
2010-06-02 23:12 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\K17gM179.dll
2010-06-02 22:59 . 2010-06-02 22:59 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-06-02 22:59 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\931yW3179.dll
2010-05-25 01:51 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\QGM55.dll
2010-05-19 23:15 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\9317k3y79.dll
2010-05-19 18:15 . 2010-05-19 18:15 ——– d-sh–w- c:\documents and settings\Not Claire\PrivacIE
2010-05-19 17:53 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\555iQ.dll
2010-05-19 17:38 . 2010-05-19 17:38 ——– d-sh–w- c:\documents and settings\Not Claire\IETldCache
2010-05-19 17:32 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\555uO.dll
2010-05-19 17:15 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\79eIQ93.dll
2010-05-19 17:07 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\1e9aA7.dll
2010-05-19 16:56 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\5yW5u.dll
2010-05-19 16:29 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\7uO179i.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-05 17:46 . 2001-08-17 19:52 125056 —-a-w- c:\windows\system32\drivers\ftdisk.sys
2010-06-02 23:36 . 2006-02-09 05:04 6580 -csha-w- c:\windows\system32\KGyGaAvL.sys
2010-06-02 23:36 . 2006-02-09 05:04 104 -csh–r- c:\windows\system32\A7CA297F14.sys
2010-06-02 23:19 . 2007-06-20 14:45 ——– d—–w- c:\documents and settings\Not Claire\Application Data\U3
2010-06-02 23:19 . 2010-06-02 23:18 ——– d—–w- c:\program files\Glary Utilities
2010-04-13 23:00 . 2007-02-05 23:36 ——– d—–w- c:\program files\Full Tilt Poker
2010-04-08 23:45 . 2010-04-08 23:45 ——– d—–w- c:\program files\Ask.com
2010-04-08 23:44 . 2010-04-08 23:44 ——– d—–w- c:\program files\uTorrent
2010-04-07 02:34 . 2010-04-07 02:31 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-07 02:34 . 2006-02-21 21:37 ——– d—–w- c:\program files\iTunes
2010-04-07 02:32 . 2006-02-21 21:37 ——– d—–w- c:\program files\iPod
2010-04-07 02:32 . 2007-07-18 05:26 ——– d—–w- c:\program files\Common Files\Apple
2010-04-07 02:21 . 2010-04-07 02:18 ——– d—–w- c:\program files\QuickTime
2010-04-07 02:10 . 2010-04-07 02:10 ——– d—–w- c:\program files\Bonjour
2010-04-07 01:58 . 2010-04-07 01:58 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-03-23 21:34 . 2010-03-23 21:34 49504 —ha-w- c:\windows\system32\mlfcache.dat
2010-03-22 01:02 . 2010-03-22 01:02 49 —-a-w- c:\windows\drprofile.dat
2010-03-10 06:15 . 2005-08-16 10:18 420352 —-a-w- c:\windows\system32\vbscript.dll
2007-09-19 19:15 . 2007-09-19 19:15 1301304 -c–a-w- c:\program files\WindowsXP-KB917021-v3-x86-ENU.exe
2007-03-05 23:27 . 2007-03-05 23:27 14730232 -c–a-w- c:\program files\DivXInstaller.exe
2007-02-05 23:35 . 2007-02-05 23:35 9418520 -c–a-w- c:\program files\FullTiltSetup.exe
2006-09-18 07:16 . 2006-09-18 07:15 359112 -c–a-w- c:\program files\LimeWireWin.exe
2006-07-17 18:04 . 2006-07-17 18:04 11599984 -c–a-w- c:\program files\PPGRE31.exe
2006-04-24 18:53 . 2006-04-24 18:53 5716424 -c–a-w- c:\program files\PartyPokerSetup.exe
2010-06-04 22:31 . 2010-06-04 22:31 60518 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2010-06-04 22:31 . 2010-06-04 22:31 49248 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2010-06-04 22:31 . 2010-06-04 22:31 165992 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139277676\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139277676\\ee\\aim6.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
R0 dxnenwo;dxnenwo; [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 135664]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-09 64160]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
— Other Services/Drivers In Memory —
*NewlyCreated* - KLMDB
*Deregistered* - klmdb
.
Contents of the 'Scheduled Tasks' folder
2010-06-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
2010-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-06-02 15:21]
2010-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 00:27]
2010-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 00:27]
2010-05-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-09 18:32]
2009-11-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-09 18:32]
2010-06-05 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 21:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
DPF: {C66610D7-B495-40C8-B4E2-546B80145BD7} - hxxps://management.pna.utexas.edu/static/faqs/dot1x/idengines/tools/xc_loader_activex.CAB
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\hq2b3s2e.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-klmdb.sys
AddRemove-BugOff - d:\spyware\MERIJN TOOLS\BUGOFF\BugOff.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-05 13:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1072)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2010-06-05 13:14:56
ComboFix-quarantined-files.txt 2010-06-05 18:14
Pre-Run: 31,726,673,920 bytes free
Post-Run: 31,713,689,600 bytes free
- - End Of File - - 10DF00A60AF528F871015089333D699E
ComboFix 10-06-03.01 - admin 06/05/2010 12:52:27.1.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Not Claire\IDHWTSS1.dll
c:\documents and settings\Not Claire\PrtDLL.dll
c:\windows\Gzyxua.exe
c:\windows\Gzyxud.exe
c:\windows\system32\bb5l6c.dll
c:\windows\system32\bszip.dll
c:\windows\system32\ernel32.dll
c:\windows\system32\hjkkj.bak1
c:\windows\system32\hjkkj.bak2
c:\windows\system32\hjkkj.ini
c:\windows\system32\regedit.exe
c:\windows\system32\wbem\grpconv.exe
c:\windows\system32\grpconv.exe was missing
Restored copy from - c:\i386\grpconv.exe
.
((((((((((((((((((((((((( Files Created from 2010-05-05 to 2010-06-05 )))))))))))))))))))))))))))))))
.
2010-06-05 18:06 . 2004-08-10 11:00 39424 —-a-w- c:\windows\system32\grpconv.exe
2010-06-05 18:06 . 2004-08-10 11:00 39424 —-a-w- c:\windows\system32\dllcache\grpconv.exe
2010-06-04 23:16 . 2010-06-04 23:16 ——– d—–w- c:\windows\McAfee.com
2010-06-04 23:10 . 2010-06-04 23:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-06-04 22:41 . 2010-06-04 22:41 ——– d—–w- c:\program files\Yahoo!
2010-06-04 22:41 . 2010-06-04 22:46 ——– d—–w- c:\program files\CCleaner
2010-06-04 22:31 . 2010-06-04 22:31 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\Mozilla
2010-06-04 22:31 . 2010-06-04 22:31 107134 —-a-w- c:\windows\UninstallFirefox.exe
2010-06-04 22:31 . 2010-06-04 22:31 2301 —-a-w- c:\windows\mozver.dat
2010-06-04 21:56 . 2010-06-04 22:00 ——– d—–w- c:\program files\ewido anti-malware
2010-06-04 21:52 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\3u79iQGM.dll
2010-06-04 11:25 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\179wS7.dll
2010-06-04 02:32 . 2010-06-04 02:32 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-06-04 02:32 . 2010-06-04 02:32 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-04 02:01 . 2010-06-04 02:01 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-06-03 23:06 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\179u1m.dll
2010-06-03 03:44 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\wS7e31kU.dll
2010-06-03 03:36 . 2010-06-03 03:36 199168 —-a-w- c:\windows\Gzyxuc.exe
2010-06-03 03:36 . 2010-06-03 03:36 72192 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\3qGMYWS9.dll
2010-06-03 03:32 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\793179a.dll
2010-06-03 03:21 . 2010-06-03 03:21 ——– d-sh–w- c:\documents and settings\admin\PrivacIE
2010-06-03 03:21 . 2010-06-05 01:04 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\AskToolbar
2010-06-03 03:21 . 2010-06-03 03:21 ——– d—–w- c:\documents and settings\admin\Application Data\SiteAdvisor
2010-06-03 03:19 . 2010-06-03 03:19 56592 —-a-w- c:\documents and settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-03 03:17 . 2010-06-03 03:17 199168 —-a-w- c:\windows\Gzyxub.exe
2010-06-03 03:02 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\q9wSK9y.dll
2010-06-03 01:30 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\31q9wS79.dll
2010-06-03 01:14 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2010-06-03 01:03 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\9o1oCE17k.dll
2010-06-03 01:01 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-03 01:00 . 2010-06-03 01:00 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2010-06-03 01:00 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2010-06-03 01:00 . 2010-06-03 01:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-03 01:00 . 2010-06-03 01:00 ——– d—–w- c:\program files\Lavasoft
2010-06-03 00:51 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\93oCE3a7k.dll
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\documents and settings\admin\Application Data\Malwarebytes
2010-06-03 00:33 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-03 00:33 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-03 00:32 . 2010-06-03 00:32 ——– d—–w- c:\documents and settings\admin\Application Data\GlarySoft
2010-06-03 00:26 . 2010-06-03 00:26 ——– d—–w- c:\documents and settings\admin\Application Data\GTek
2010-06-03 00:25 . 2010-06-03 00:25 ——– d-sh–w- c:\documents and settings\admin\IETldCache
2010-06-03 00:23 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\c1s9eIQ9.dll
2010-06-02 23:37 . 2010-06-02 23:37 ——– d—–w- c:\documents and settings\Not Claire\Application Data\Corel Photo Album
2010-06-02 23:37 . 2010-06-02 23:37 56592 —-a-w- c:\documents and settings\Not Claire\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-02 23:37 . 2010-06-02 23:37 ——– d—–w- c:\documents and settings\Not Claire\Local Settings\Application Data\Corel Photo Album
2010-06-02 23:28 . 2010-06-02 23:28 ——– d—–w- C:\GlarySoft
2010-06-02 23:18 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-06-02 23:18 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll
2010-06-02 23:17 . 2001-08-17 19:02 9600 —-a-w- c:\windows\system32\drivers\hidusb.sys
2010-06-02 23:17 . 2001-08-17 19:02 9600 —-a-w- c:\windows\system32\dllcache\hidusb.sys
2010-06-02 23:12 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\K17gM179.dll
2010-06-02 22:59 . 2010-06-02 22:59 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-06-02 22:59 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\931yW3179.dll
2010-05-25 01:51 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\QGM55.dll
2010-05-19 23:15 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\9317k3y79.dll
2010-05-19 18:15 . 2010-05-19 18:15 ——– d-sh–w- c:\documents and settings\Not Claire\PrivacIE
2010-05-19 17:53 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\555iQ.dll
2010-05-19 17:38 . 2010-05-19 17:38 ——– d-sh–w- c:\documents and settings\Not Claire\IETldCache
2010-05-19 17:32 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\555uO.dll
2010-05-19 17:15 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\79eIQ93.dll
2010-05-19 17:07 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\1e9aA7.dll
2010-05-19 16:56 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\5yW5u.dll
2010-05-19 16:29 . 2010-05-19 16:29 71168 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\7uO179i.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-05 17:46 . 2001-08-17 19:52 125056 —-a-w- c:\windows\system32\drivers\ftdisk.sys
2010-06-02 23:36 . 2006-02-09 05:04 6580 -csha-w- c:\windows\system32\KGyGaAvL.sys
2010-06-02 23:36 . 2006-02-09 05:04 104 -csh–r- c:\windows\system32\A7CA297F14.sys
2010-06-02 23:19 . 2007-06-20 14:45 ——– d—–w- c:\documents and settings\Not Claire\Application Data\U3
2010-06-02 23:19 . 2010-06-02 23:18 ——– d—–w- c:\program files\Glary Utilities
2010-04-13 23:00 . 2007-02-05 23:36 ——– d—–w- c:\program files\Full Tilt Poker
2010-04-08 23:45 . 2010-04-08 23:45 ——– d—–w- c:\program files\Ask.com
2010-04-08 23:44 . 2010-04-08 23:44 ——– d—–w- c:\program files\uTorrent
2010-04-07 02:34 . 2010-04-07 02:31 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-07 02:34 . 2006-02-21 21:37 ——– d—–w- c:\program files\iTunes
2010-04-07 02:32 . 2006-02-21 21:37 ——– d—–w- c:\program files\iPod
2010-04-07 02:32 . 2007-07-18 05:26 ——– d—–w- c:\program files\Common Files\Apple
2010-04-07 02:21 . 2010-04-07 02:18 ——– d—–w- c:\program files\QuickTime
2010-04-07 02:10 . 2010-04-07 02:10 ——– d—–w- c:\program files\Bonjour
2010-04-07 01:58 . 2010-04-07 01:58 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-03-23 21:34 . 2010-03-23 21:34 49504 —ha-w- c:\windows\system32\mlfcache.dat
2010-03-22 01:02 . 2010-03-22 01:02 49 —-a-w- c:\windows\drprofile.dat
2010-03-10 06:15 . 2005-08-16 10:18 420352 —-a-w- c:\windows\system32\vbscript.dll
2007-09-19 19:15 . 2007-09-19 19:15 1301304 -c–a-w- c:\program files\WindowsXP-KB917021-v3-x86-ENU.exe
2007-03-05 23:27 . 2007-03-05 23:27 14730232 -c–a-w- c:\program files\DivXInstaller.exe
2007-02-05 23:35 . 2007-02-05 23:35 9418520 -c–a-w- c:\program files\FullTiltSetup.exe
2006-09-18 07:16 . 2006-09-18 07:15 359112 -c–a-w- c:\program files\LimeWireWin.exe
2006-07-17 18:04 . 2006-07-17 18:04 11599984 -c–a-w- c:\program files\PPGRE31.exe
2006-04-24 18:53 . 2006-04-24 18:53 5716424 -c–a-w- c:\program files\PartyPokerSetup.exe
2010-06-04 22:31 . 2010-06-04 22:31 60518 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2010-06-04 22:31 . 2010-06-04 22:31 49248 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2010-06-04 22:31 . 2010-06-04 22:31 165992 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139277676\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139277676\\ee\\aim6.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
R0 dxnenwo;dxnenwo; [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 135664]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-09 64160]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
— Other Services/Drivers In Memory —
*NewlyCreated* - KLMDB
*Deregistered* - klmdb
.
Contents of the 'Scheduled Tasks' folder
2010-06-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
2010-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-06-02 15:21]
2010-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 00:27]
2010-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 00:27]
2010-05-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-09 18:32]
2009-11-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-09 18:32]
2010-06-05 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-02-04 21:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
DPF: {C66610D7-B495-40C8-B4E2-546B80145BD7} - hxxps://management.pna.utexas.edu/static/faqs/dot1x/idengines/tools/xc_loader_activex.CAB
FF - ProfilePath - c:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\hq2b3s2e.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
SafeBoot-klmdb.sys
AddRemove-BugOff - d:\spyware\MERIJN TOOLS\BUGOFF\BugOff.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-05 13:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1072)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2010-06-05 13:14:56
ComboFix-quarantined-files.txt 2010-06-05 18:14
Pre-Run: 31,726,673,920 bytes free
Post-Run: 31,713,689,600 bytes free
- - End Of File - - 10DF00A60AF528F871015089333D699E