here it is
ComboFix 10-06-03.01 - Claire 06/06/2010 9:55.5.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-05-06 to 2010-06-06 )))))))))))))))))))))))))))))))
.
2010-06-06 01:05 . 2010-06-06 01:05 ——– d—–w- c:\documents and settings\Claire\Local Settings\Application Data\PCHealth
2010-06-05 18:06 . 2004-08-10 11:00 39424 —-a-w- c:\windows\system32\grpconv.exe
2010-06-05 18:06 . 2004-08-10 11:00 39424 —-a-w- c:\windows\system32\dllcache\grpconv.exe
2010-06-05 03:22 . 2010-06-05 03:22 ——– d—–w- c:\documents and settings\Claire\Local Settings\Application Data\Mozilla
2010-06-04 23:10 . 2010-06-04 23:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-06-04 22:41 . 2010-06-04 22:41 ——– d—–w- c:\program files\Yahoo!
2010-06-04 22:41 . 2010-06-04 22:46 ——– d—–w- c:\program files\CCleaner
2010-06-04 22:31 . 2010-06-04 22:31 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\Mozilla
2010-06-04 22:31 . 2010-06-04 22:31 107134 —-a-w- c:\windows\UninstallFirefox.exe
2010-06-04 22:31 . 2010-06-04 22:31 2301 —-a-w- c:\windows\mozver.dat
2010-06-04 21:56 . 2010-06-04 22:00 ——– d—–w- c:\program files\ewido anti-malware
2010-06-04 02:32 . 2010-06-04 02:32 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-06-04 02:32 . 2010-06-04 02:32 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-04 02:01 . 2010-06-04 02:01 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-06-03 03:21 . 2010-06-03 03:21 ——– d-sh–w- c:\documents and settings\admin\PrivacIE
2010-06-03 03:21 . 2010-06-03 03:21 ——– d—–w- c:\documents and settings\admin\Application Data\SiteAdvisor
2010-06-03 03:19 . 2010-06-03 03:19 56592 —-a-w- c:\documents and settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-03 01:14 . 2010-06-06 02:48 15688 —-a-w- c:\windows\system32\lsdelete.exe
2010-06-03 01:01 . 2010-06-06 02:48 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-03 01:00 . 2010-06-03 01:00 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2010-06-03 01:00 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2010-06-03 01:00 . 2010-06-03 01:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-06-03 01:00 . 2010-06-03 01:00 ——– d—–w- c:\program files\Lavasoft
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\documents and settings\admin\Application Data\Malwarebytes
2010-06-03 00:33 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-03 00:33 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-03 00:33 . 2010-06-03 00:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-03 00:32 . 2010-06-03 00:32 ——– d—–w- c:\documents and settings\admin\Application Data\GlarySoft
2010-06-03 00:22 . 2006-01-31 21:54 ——– d—–w- c:\documents and settings\admin\Application Data\Corel
2010-06-02 23:37 . 2010-06-02 23:37 ——– d—–w- c:\documents and settings\Not Claire\Application Data\Corel Photo Album
2010-06-02 23:37 . 2010-06-02 23:37 56592 —-a-w- c:\documents and settings\Not Claire\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-02 23:37 . 2010-06-02 23:37 ——– d—–w- c:\documents and settings\Not Claire\Local Settings\Application Data\Corel Photo Album
2010-06-02 23:28 . 2010-06-02 23:28 ——– d—–w- C:\GlarySoft
2010-06-02 23:18 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-06-02 23:18 . 2004-08-04 05:56 21504 —-a-w- c:\windows\system32\dllcache\hidserv.dll
2010-06-02 23:17 . 2001-08-17 19:02 9600 —-a-w- c:\windows\system32\drivers\hidusb.sys
2010-06-02 23:17 . 2001-08-17 19:02 9600 —-a-w- c:\windows\system32\dllcache\hidusb.sys
2010-06-02 22:59 . 2010-06-02 22:59 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-05-19 18:15 . 2010-05-19 18:15 ——– d-sh–w- c:\documents and settings\Not Claire\PrivacIE
2010-05-19 17:38 . 2010-05-19 17:38 ——– d-sh–w- c:\documents and settings\Not Claire\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-05 17:46 . 2001-08-17 19:52 125056 —-a-w- c:\windows\system32\drivers\ftdisk.sys
2010-06-03 00:26 . 2010-06-03 00:26 ——– d—–w- c:\documents and settings\admin\Application Data\GTek
2010-06-02 23:36 . 2006-02-09 05:04 6580 -csha-w- c:\windows\system32\KGyGaAvL.sys
2010-06-02 23:36 . 2006-02-09 05:04 104 -csh–r- c:\windows\system32\A7CA297F14.sys
2010-06-02 23:19 . 2007-06-20 14:45 ——– d—–w- c:\documents and settings\Not Claire\Application Data\U3
2010-06-02 23:19 . 2010-06-02 23:18 ——– d—–w- c:\program files\Glary Utilities
2010-04-13 23:00 . 2007-02-05 23:36 ——– d—–w- c:\program files\Full Tilt Poker
2010-04-08 23:44 . 2010-04-08 23:44 ——– d—–w- c:\program files\uTorrent
2010-04-07 01:58 . 2010-04-07 01:58 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-03-23 21:34 . 2010-03-23 21:34 49504 —ha-w- c:\windows\system32\mlfcache.dat
2010-03-22 01:02 . 2010-03-22 01:02 49 —-a-w- c:\windows\drprofile.dat
2010-03-10 06:15 . 2005-08-16 10:18 420352 —-a-w- c:\windows\system32\vbscript.dll
2007-09-19 19:15 . 2007-09-19 19:15 1301304 -c–a-w- c:\program files\WindowsXP-KB917021-v3-x86-ENU.exe
2007-03-05 23:27 . 2007-03-05 23:27 14730232 -c–a-w- c:\program files\DivXInstaller.exe
2007-02-05 23:35 . 2007-02-05 23:35 9418520 -c–a-w- c:\program files\FullTiltSetup.exe
2006-09-18 07:16 . 2006-09-18 07:15 359112 -c–a-w- c:\program files\LimeWireWin.exe
2006-07-17 18:04 . 2006-07-17 18:04 11599984 -c–a-w- c:\program files\PPGRE31.exe
2006-04-24 18:53 . 2006-04-24 18:53 5716424 -c–a-w- c:\program files\PartyPokerSetup.exe
2010-06-04 22:31 . 2010-06-04 22:31 60518 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2010-06-04 22:31 . 2010-06-04 22:31 49248 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2010-06-04 22:31 . 2010-06-04 22:31 165992 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-06-06 524632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139277676\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139277676\\ee\\aim6.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
R0 dxnenwo;dxnenwo; [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 135664]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-06 64160]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-06 1029456]
.
Contents of the 'Scheduled Tasks' folder
2010-06-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 02:48]
2010-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-06 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-06-02 15:21]
2010-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 00:27]
2010-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-02 00:27]
2010-05-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-09 18:32]
2009-11-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-03-09 18:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/webhp?sourceid=navclient&ie=UTF-8
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
DPF: {C66610D7-B495-40C8-B4E2-546B80145BD7} - hxxps://management.pna.utexas.edu/static/faqs/dot1x/idengines/tools/xc_loader_activex.CAB
FF - ProfilePath - c:\documents and settings\Claire\Application Data\Mozilla\Firefox\Profiles\fazd6zky.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\SiteAdvisor\6261\FF\components\FFHook.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-06 10:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1068)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(3360)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2010-06-06 10:15:27
ComboFix-quarantined-files.txt 2010-06-06 15:15
ComboFix2.txt 2010-06-06 01:55
ComboFix3.txt 2010-06-05 22:48
ComboFix4.txt 2010-06-05 21:58
ComboFix5.txt 2010-06-06 14:54
Pre-Run: 31,130,374,144 bytes free
Post-Run: 31,098,191,872 bytes free
- - End Of File - - 7DF59383A0A79A2039105681E5DDEE03