Rodrigo333
Topic Starter
Hello Guys;
Did a little Research on removing Searchqu, installed and ran Combo fix with no problems; however, I just do not know what to put in the codes as the only example you all have was a fix for FireFox and I need a code for IE. Could you all help me?
This was the Tread I was following: http://forums.whatthetech.com/Searchqu_problem_t112079.html
I think all I have to do is a proper txt file drag and drop of the correct code into the Combo Fix Icon - I could be wrong.
Here is the results from Combo Fix:
ComboFix 10-09-12.01 - Main User 09/12/2010 15:43:42.4.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.3061.1730 [GMT -6:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\Main User\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - drivers: deleted 204 bytes in 1 streams.
((((((((((((((((((((((((( Files Created from 2010-08-12 to 2010-09-12 )))))))))))))))))))))))))))))))
.
2010-09-12 21:47:58 . 2010-09-12 21:47:58 ——– d—–w- C:\Users\Rodrigo Ramirez\AppData\Local\temp
2010-09-12 21:47:58 . 2010-09-12 21:47:58 ——– d—–w- C:\Users\Public\AppData\Local\temp
2010-09-12 21:47:58 . 2010-09-12 21:47:58 ——– d—–w- C:\Users\Default\AppData\Local\temp
2010-09-12 19:54:49 . 2010-09-12 20:02:44 ——– d—–w- C:\UBCD4Win
2010-09-12 17:43:16 . 2010-04-29 21:39:38 38224 —-a-w- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-09-12 17:43:15 . 2010-04-29 21:39:26 20952 —-a-w- C:\Windows\system32\drivers\mbam.sys
2010-09-12 17:43:14 . 2010-09-12 17:47:52 ——– d—–w- C:\Program Files\Malwarebytes' Anti-Malware
2010-09-12 17:28:29 . 2010-09-12 17:28:29 ——– d—–w- C:\Users\Main User\AppData\Roaming\Malwarebytes
2010-09-12 17:28:24 . 2010-09-12 17:28:24 ——– d—–w- C:\ProgramData\Malwarebytes
2010-09-12 17:20:14 . 2010-09-12 17:20:14 ——– d—–w- C:\ProgramData\Avira
2010-09-12 17:20:14 . 2010-09-12 17:20:14 ——– d—–w- C:\Program Files\Avira
2010-09-12 17:20:14 . 2009-03-30 16:33:07 96104 —-a-w- C:\Windows\system32\drivers\avipbb.sys
2010-09-12 17:20:14 . 2009-03-24 22:08:22 55640 —-a-w- C:\Windows\system32\drivers\avgntflt.sys
2010-08-16 04:08:26 . 2010-08-16 04:08:26 ——– d—–w- C:\Users\Main User\AppData\Local\HP
2010-08-16 04:03:33 . 2010-08-16 04:03:43 ——– d—–w- C:\Users\Main User\AppData\Roaming\HP
2010-08-14 09:01:15 . 2010-08-14 09:01:15 ——– d—–w- C:\Program Files\MSXML 4.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-12 17:31:01 . 2009-09-06 14:35:49 ——– d—–w- C:\Program Files\Google
2010-09-12 16:44:53 . 2009-05-04 16:13:11 ——– d—–w- C:\ProgramData\McAfee
2010-09-12 16:39:17 . 2009-10-01 13:32:46 5972 —-a-w- C:\Users\Main User\AppData\Local\d3d9caps.dat
2010-09-12 16:29:52 . 2009-05-04 16:03:14 ——– d—–w- C:\Program Files\Creative
2010-09-12 16:29:08 . 2009-05-04 16:03:02 ——– d–h–w- C:\Program Files\InstallShield Installation Information
2010-09-12 16:26:28 . 2009-05-04 16:22:55 ——– d—–w- C:\ProgramData\WildTangent
2010-09-12 15:54:58 . 2009-09-06 14:36:07 ——– d—–w- C:\Users\Main User\AppData\Roaming\Skype
2010-09-12 15:06:14 . 2009-07-13 14:17:15 24636 —-a-w- C:\Users\Main User\AppData\Roaming\wklnhst.dat
2010-09-12 14:02:39 . 2009-09-06 14:40:30 ——– d—–w- C:\Users\Main User\AppData\Roaming\skypePM
2010-09-09 20:53:25 . 2009-05-04 16:21:57 ——– d—–w- C:\ProgramData\Dell
2010-08-26 06:54:01 . 2009-05-04 16:42:58 ——– d—–w- C:\Program Files\Microsoft Silverlight
2010-08-14 09:03:32 . 2009-05-04 16:15:51 ——– d—–w- C:\Program Files\Microsoft Works
2010-08-10 03:28:52 . 2010-08-10 03:03:02 139791 —-a-w- C:\Windows\hpoins15.dat
2010-08-10 03:26:05 . 2010-08-10 03:26:05 ——– d—–w- C:\ProgramData\WEBREG
2010-08-10 03:24:32 . 2010-06-29 00:20:12 ——– d—–w- C:\ProgramData\HP
2010-08-10 03:12:40 . 2010-08-10 03:12:40 ——– d—–w- C:\ProgramData\HPSSUPPLY
2010-08-10 03:12:40 . 2010-06-29 00:24:25 ——– d—–w- C:\Program Files\HP
2010-08-10 03:10:05 . 2010-08-10 03:10:05 ——– d—–w- C:\ProgramData\HP Product Assistant
2010-08-10 03:09:44 . 2010-08-10 03:09:44 ——– d—–w- C:\Program Files\Common Files\HP
2010-08-10 03:09:12 . 2010-08-10 03:09:12 ——– d—–w- C:\Program Files\Hewlett-Packard
2010-08-10 03:08:56 . 2010-08-10 03:08:56 ——– d—–w- C:\Program Files\Common Files\Hewlett-Packard
2010-08-10 02:38:06 . 2009-07-09 18:07:30 ——– d—–w- C:\ProgramData\GbPlugin
2010-08-10 02:33:22 . 2010-08-10 02:33:22 ——– d—–w- C:\ProgramData\Hewlett-Packard
2010-08-10 01:28:56 . 2009-07-09 18:07:30 ——– d—–w- C:\Program Files\GbPlugin
2010-08-01 18:36:19 . 2009-12-27 17:14:19 0 —-a-w- C:\Windows\system32\drivers\lvuvc.hs
2010-07-27 14:20:04 . 2009-07-16 13:40:08 45472 —-a-w- C:\Windows\system32\drivers\gbpkm.sys
2010-07-22 02:40:47 . 2010-07-22 02:40:46 ——– d—–w- C:\ProgramData\Office Genuine Advantage
2010-07-20 02:34:51 . 2010-03-25 17:37:31 ——– d—–w- C:\Program Files\iTunes
2010-07-20 02:33:52 . 2010-07-20 02:33:52 ——– d—–w- C:\Program Files\iPod
2010-07-20 02:33:51 . 2010-03-25 17:33:22 ——– d—–w- C:\Program Files\Common Files\Apple
2010-07-20 02:31:02 . 2010-07-20 02:30:22 ——– d—–w- C:\Program Files\QuickTime
2010-07-20 02:28:19 . 2010-07-20 02:28:17 ——– d—–w- C:\Program Files\Apple Software Update
2010-07-16 14:19:08 . 2010-07-16 14:19:08 73000 —-a-w- C:\ProgramData\Apple Computer\Installer Cache\iTunes 9.2.1.4\SetupAdmin.exe
2010-06-26 06:05:49 . 2010-08-12 23:04:17 916480 —-a-w- C:\Windows\system32\wininet.dll
2010-06-26 06:02:15 . 2010-08-12 23:04:15 71680 —-a-w- C:\Windows\system32\iesetup.dll
2010-06-26 06:02:15 . 2010-08-12 23:04:15 109056 —-a-w- C:\Windows\system32\iesysprep.dll
2010-06-26 04:25:02 . 2010-08-12 23:04:15 133632 —-a-w- C:\Windows\system32\ieUnatt.exe
2010-06-21 13:18:15 . 2010-08-12 23:04:02 2036736 —-a-w- C:\Windows\system32\win32k.sys
2010-06-18 16:43:54 . 2010-08-12 23:04:00 36352 —-a-w- C:\Windows\system32\rtutils.dll
2010-06-18 14:43:36 . 2010-08-12 23:03:51 302080 —-a-w- C:\Windows\system32\drivers\srv.sys
2010-06-18 14:43:14 . 2010-08-12 23:03:50 144896 —-a-w- C:\Windows\system32\drivers\srv2.sys
2010-06-16 15:59:54 . 2010-08-12 23:03:48 898952 —-a-w- C:\Windows\system32\drivers\tcpip.sys
2009-05-04 18:23:28 . 2009-05-04 18:20:40 8192 –sha-w- C:\Windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2010-09-12_20.46.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58:36 . 2010-09-12 21:37:54 55036 C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02:52 . 2010-09-12 21:37:55 77916 C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-05-23 14:21:28 . 2010-09-12 21:37:55 11052 C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-866736814-394752019-3221223061-1000_UserData.bin
+ 2008-02-03 15:42:35 . 2010-09-12 21:38:22 32768 C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-02-03 15:42:35 . 2010-09-12 19:57:17 32768 C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-02-03 15:42:35 . 2010-09-12 19:57:17 32768 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-02-03 15:42:35 . 2010-09-12 21:38:22 32768 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-02-03 15:42:36 . 2010-09-12 21:38:22 16384 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-02-03 15:42:36 . 2010-09-12 19:57:17 16384 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-17 15:55:57 . 2010-09-12 21:32:14 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-17 15:55:57 . 2010-09-12 17:34:25 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-17 15:55:57 . 2010-09-12 17:34:25 32768 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-17 15:55:57 . 2010-09-12 21:32:14 32768 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-17 15:55:57 . 2010-09-12 17:34:25 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-17 15:55:57 . 2010-09-12 21:32:14 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-09-12 17:47:58 . 2010-09-12 17:47:58 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-09-12 21:36:06 . 2010-09-12 21:36:06 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-09-12 17:47:58 . 2010-09-12 17:47:58 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-09-12 21:36:06 . 2010-09-12 21:36:06 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33:01 . 2010-09-12 21:43:19 595684 C:\Windows\System32\perfh009.dat
- 2006-11-02 10:33:01 . 2010-09-12 17:55:50 595684 C:\Windows\System32\perfh009.dat
+ 2006-11-02 10:33:01 . 2010-09-12 21:43:19 101350 C:\Windows\System32\perfc009.dat
- 2006-11-02 10:33:01 . 2010-09-12 17:55:50 101350 C:\Windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 02:32:56 1233920]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 22:44:34 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-21 02:33:00 1008184]
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray.exe" [2009-01-14 08:39:32 483420]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-05-08 09:33:00 133656]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 15:57:28 128296]
"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2008-04-18 10:08:06 36864]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2009-06-01 18:51:52 1468296]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-05-08 09:33:10 141848]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 18:37:58 174872]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-05-08 09:32:58 166424]
"dellsupportcenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2009-01-30 05:50:06 206064]
"Dell DataSafe Online"="C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 23:15:00 1807600]
"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2008-12-18 09:58:18 3810304]
"Adobe Reader Speed Launcher"="c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 07:38:00 34672]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 23:02:54 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 23:06:30 2027792]
"BrStsWnd"="C:\Program Files\Brownie\BrstsWnd.exe" [2009-05-20 02:56:36 3618104]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 08:29:02 47392]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2010-03-19 04:16:10 421888]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2010-07-16 13:41:58 141608]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 03:34:40 49152]
"avgnt"="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 19:08:47 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 22:44:34 3883856]
C:\Users\Rodrigo Ramirez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
C:\Users\Main User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2008-3-13 1207376]
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - C:\Program Files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]
2010-07-27 14:18:52 335136 —-a-w- C:\Program Files\GbPlugin\gbieh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-05-04 16:18:51 10536 —-a-w- C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [BU]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 23:16:40 22904]
S0 GbpKm;Gbp KernelMode;C:\Windows\system32\drivers\gbpkm.sys [2010-07-27 14:20:04 45472]
S2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe [2009-01-14 08:38:56 81920]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 22:48:22 108289]
S2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 18:05:28 155648]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;C:\BANCOB~1\Firebird\bin\fbguard.exe [2008-06-13 19:24:04 81920]
S2 GbpSv;Gbp Service;C:\PROGRA~1\GbPlugin\GbpSv.exe [2010-07-27 14:20:32 55072]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-03-24 06:26:30 183808]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;C:\BANCOB~1\Firebird\bin\fbserver.exe [2008-06-13 19:22:52 2723840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-09-12 C:\Windows\Tasks\User_Feed_Synchronization-{C16EB28D-AA9E-432A-94E0-2C7235A96E1F}.job
- C:\Windows\system32\msfeedssync.exe [2010-08-12 23:04:15 . 2010-06-26 04:24:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.searchqu.com/
Trusted Zone: bancobrasil.com.br\www14
Trusted Zone: bancobrasil.com.br\www2
Trusted Zone: bb.com.br\www
Trusted Zone: bdhoras.com.br\www
DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-12 15:48:03
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
Completion time: 2010-09-12 15:49:45
ComboFix-quarantined-files.txt 2010-09-12 21:49:43
ComboFix2.txt 2010-09-12 21:11:42
Pre-Run: 200,076,333,056 bytes free
Post-Run: 200,043,614,208 bytes free
- - End Of File - - E728CFD3C1892DAB99AADFED4E8DBF9E
Did a little Research on removing Searchqu, installed and ran Combo fix with no problems; however, I just do not know what to put in the codes as the only example you all have was a fix for FireFox and I need a code for IE. Could you all help me?
This was the Tread I was following: http://forums.whatthetech.com/Searchqu_problem_t112079.html
I think all I have to do is a proper txt file drag and drop of the correct code into the Combo Fix Icon - I could be wrong.
Here is the results from Combo Fix:
ComboFix 10-09-12.01 - Main User 09/12/2010 15:43:42.4.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.3061.1730 [GMT -6:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\Main User\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - drivers: deleted 204 bytes in 1 streams.
((((((((((((((((((((((((( Files Created from 2010-08-12 to 2010-09-12 )))))))))))))))))))))))))))))))
.
2010-09-12 21:47:58 . 2010-09-12 21:47:58 ——– d—–w- C:\Users\Rodrigo Ramirez\AppData\Local\temp
2010-09-12 21:47:58 . 2010-09-12 21:47:58 ——– d—–w- C:\Users\Public\AppData\Local\temp
2010-09-12 21:47:58 . 2010-09-12 21:47:58 ——– d—–w- C:\Users\Default\AppData\Local\temp
2010-09-12 19:54:49 . 2010-09-12 20:02:44 ——– d—–w- C:\UBCD4Win
2010-09-12 17:43:16 . 2010-04-29 21:39:38 38224 —-a-w- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-09-12 17:43:15 . 2010-04-29 21:39:26 20952 —-a-w- C:\Windows\system32\drivers\mbam.sys
2010-09-12 17:43:14 . 2010-09-12 17:47:52 ——– d—–w- C:\Program Files\Malwarebytes' Anti-Malware
2010-09-12 17:28:29 . 2010-09-12 17:28:29 ——– d—–w- C:\Users\Main User\AppData\Roaming\Malwarebytes
2010-09-12 17:28:24 . 2010-09-12 17:28:24 ——– d—–w- C:\ProgramData\Malwarebytes
2010-09-12 17:20:14 . 2010-09-12 17:20:14 ——– d—–w- C:\ProgramData\Avira
2010-09-12 17:20:14 . 2010-09-12 17:20:14 ——– d—–w- C:\Program Files\Avira
2010-09-12 17:20:14 . 2009-03-30 16:33:07 96104 —-a-w- C:\Windows\system32\drivers\avipbb.sys
2010-09-12 17:20:14 . 2009-03-24 22:08:22 55640 —-a-w- C:\Windows\system32\drivers\avgntflt.sys
2010-08-16 04:08:26 . 2010-08-16 04:08:26 ——– d—–w- C:\Users\Main User\AppData\Local\HP
2010-08-16 04:03:33 . 2010-08-16 04:03:43 ——– d—–w- C:\Users\Main User\AppData\Roaming\HP
2010-08-14 09:01:15 . 2010-08-14 09:01:15 ——– d—–w- C:\Program Files\MSXML 4.0
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-12 17:31:01 . 2009-09-06 14:35:49 ——– d—–w- C:\Program Files\Google
2010-09-12 16:44:53 . 2009-05-04 16:13:11 ——– d—–w- C:\ProgramData\McAfee
2010-09-12 16:39:17 . 2009-10-01 13:32:46 5972 —-a-w- C:\Users\Main User\AppData\Local\d3d9caps.dat
2010-09-12 16:29:52 . 2009-05-04 16:03:14 ——– d—–w- C:\Program Files\Creative
2010-09-12 16:29:08 . 2009-05-04 16:03:02 ——– d–h–w- C:\Program Files\InstallShield Installation Information
2010-09-12 16:26:28 . 2009-05-04 16:22:55 ——– d—–w- C:\ProgramData\WildTangent
2010-09-12 15:54:58 . 2009-09-06 14:36:07 ——– d—–w- C:\Users\Main User\AppData\Roaming\Skype
2010-09-12 15:06:14 . 2009-07-13 14:17:15 24636 —-a-w- C:\Users\Main User\AppData\Roaming\wklnhst.dat
2010-09-12 14:02:39 . 2009-09-06 14:40:30 ——– d—–w- C:\Users\Main User\AppData\Roaming\skypePM
2010-09-09 20:53:25 . 2009-05-04 16:21:57 ——– d—–w- C:\ProgramData\Dell
2010-08-26 06:54:01 . 2009-05-04 16:42:58 ——– d—–w- C:\Program Files\Microsoft Silverlight
2010-08-14 09:03:32 . 2009-05-04 16:15:51 ——– d—–w- C:\Program Files\Microsoft Works
2010-08-10 03:28:52 . 2010-08-10 03:03:02 139791 —-a-w- C:\Windows\hpoins15.dat
2010-08-10 03:26:05 . 2010-08-10 03:26:05 ——– d—–w- C:\ProgramData\WEBREG
2010-08-10 03:24:32 . 2010-06-29 00:20:12 ——– d—–w- C:\ProgramData\HP
2010-08-10 03:12:40 . 2010-08-10 03:12:40 ——– d—–w- C:\ProgramData\HPSSUPPLY
2010-08-10 03:12:40 . 2010-06-29 00:24:25 ——– d—–w- C:\Program Files\HP
2010-08-10 03:10:05 . 2010-08-10 03:10:05 ——– d—–w- C:\ProgramData\HP Product Assistant
2010-08-10 03:09:44 . 2010-08-10 03:09:44 ——– d—–w- C:\Program Files\Common Files\HP
2010-08-10 03:09:12 . 2010-08-10 03:09:12 ——– d—–w- C:\Program Files\Hewlett-Packard
2010-08-10 03:08:56 . 2010-08-10 03:08:56 ——– d—–w- C:\Program Files\Common Files\Hewlett-Packard
2010-08-10 02:38:06 . 2009-07-09 18:07:30 ——– d—–w- C:\ProgramData\GbPlugin
2010-08-10 02:33:22 . 2010-08-10 02:33:22 ——– d—–w- C:\ProgramData\Hewlett-Packard
2010-08-10 01:28:56 . 2009-07-09 18:07:30 ——– d—–w- C:\Program Files\GbPlugin
2010-08-01 18:36:19 . 2009-12-27 17:14:19 0 —-a-w- C:\Windows\system32\drivers\lvuvc.hs
2010-07-27 14:20:04 . 2009-07-16 13:40:08 45472 —-a-w- C:\Windows\system32\drivers\gbpkm.sys
2010-07-22 02:40:47 . 2010-07-22 02:40:46 ——– d—–w- C:\ProgramData\Office Genuine Advantage
2010-07-20 02:34:51 . 2010-03-25 17:37:31 ——– d—–w- C:\Program Files\iTunes
2010-07-20 02:33:52 . 2010-07-20 02:33:52 ——– d—–w- C:\Program Files\iPod
2010-07-20 02:33:51 . 2010-03-25 17:33:22 ——– d—–w- C:\Program Files\Common Files\Apple
2010-07-20 02:31:02 . 2010-07-20 02:30:22 ——– d—–w- C:\Program Files\QuickTime
2010-07-20 02:28:19 . 2010-07-20 02:28:17 ——– d—–w- C:\Program Files\Apple Software Update
2010-07-16 14:19:08 . 2010-07-16 14:19:08 73000 —-a-w- C:\ProgramData\Apple Computer\Installer Cache\iTunes 9.2.1.4\SetupAdmin.exe
2010-06-26 06:05:49 . 2010-08-12 23:04:17 916480 —-a-w- C:\Windows\system32\wininet.dll
2010-06-26 06:02:15 . 2010-08-12 23:04:15 71680 —-a-w- C:\Windows\system32\iesetup.dll
2010-06-26 06:02:15 . 2010-08-12 23:04:15 109056 —-a-w- C:\Windows\system32\iesysprep.dll
2010-06-26 04:25:02 . 2010-08-12 23:04:15 133632 —-a-w- C:\Windows\system32\ieUnatt.exe
2010-06-21 13:18:15 . 2010-08-12 23:04:02 2036736 —-a-w- C:\Windows\system32\win32k.sys
2010-06-18 16:43:54 . 2010-08-12 23:04:00 36352 —-a-w- C:\Windows\system32\rtutils.dll
2010-06-18 14:43:36 . 2010-08-12 23:03:51 302080 —-a-w- C:\Windows\system32\drivers\srv.sys
2010-06-18 14:43:14 . 2010-08-12 23:03:50 144896 —-a-w- C:\Windows\system32\drivers\srv2.sys
2010-06-16 15:59:54 . 2010-08-12 23:03:48 898952 —-a-w- C:\Windows\system32\drivers\tcpip.sys
2009-05-04 18:23:28 . 2009-05-04 18:20:40 8192 –sha-w- C:\Windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2010-09-12_20.46.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58:36 . 2010-09-12 21:37:54 55036 C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02:52 . 2010-09-12 21:37:55 77916 C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-05-23 14:21:28 . 2010-09-12 21:37:55 11052 C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-866736814-394752019-3221223061-1000_UserData.bin
+ 2008-02-03 15:42:35 . 2010-09-12 21:38:22 32768 C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-02-03 15:42:35 . 2010-09-12 19:57:17 32768 C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-02-03 15:42:35 . 2010-09-12 19:57:17 32768 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-02-03 15:42:35 . 2010-09-12 21:38:22 32768 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-02-03 15:42:36 . 2010-09-12 21:38:22 16384 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-02-03 15:42:36 . 2010-09-12 19:57:17 16384 C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-17 15:55:57 . 2010-09-12 21:32:14 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-17 15:55:57 . 2010-09-12 17:34:25 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-17 15:55:57 . 2010-09-12 17:34:25 32768 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-17 15:55:57 . 2010-09-12 21:32:14 32768 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-17 15:55:57 . 2010-09-12 17:34:25 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-17 15:55:57 . 2010-09-12 21:32:14 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-09-12 17:47:58 . 2010-09-12 17:47:58 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-09-12 21:36:06 . 2010-09-12 21:36:06 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-09-12 17:47:58 . 2010-09-12 17:47:58 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-09-12 21:36:06 . 2010-09-12 21:36:06 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33:01 . 2010-09-12 21:43:19 595684 C:\Windows\System32\perfh009.dat
- 2006-11-02 10:33:01 . 2010-09-12 17:55:50 595684 C:\Windows\System32\perfh009.dat
+ 2006-11-02 10:33:01 . 2010-09-12 21:43:19 101350 C:\Windows\System32\perfc009.dat
- 2006-11-02 10:33:01 . 2010-09-12 17:55:50 101350 C:\Windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 02:32:56 1233920]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 22:44:34 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-21 02:33:00 1008184]
"SysTrayApp"="C:\Program Files\IDT\WDM\sttray.exe" [2009-01-14 08:39:32 483420]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-05-08 09:33:00 133656]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 15:57:28 128296]
"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2008-04-18 10:08:06 36864]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2009-06-01 18:51:52 1468296]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-05-08 09:33:10 141848]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 18:37:58 174872]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-05-08 09:32:58 166424]
"dellsupportcenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2009-01-30 05:50:06 206064]
"Dell DataSafe Online"="C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" [2009-11-13 23:15:00 1807600]
"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2008-12-18 09:58:18 3810304]
"Adobe Reader Speed Launcher"="c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 07:38:00 34672]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 23:02:54 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 23:06:30 2027792]
"BrStsWnd"="C:\Program Files\Brownie\BrstsWnd.exe" [2009-05-20 02:56:36 3618104]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 08:29:02 47392]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2010-03-19 04:16:10 421888]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2010-07-16 13:41:58 141608]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 03:34:40 49152]
"avgnt"="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 19:08:47 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 22:44:34 3883856]
C:\Users\Rodrigo Ramirez\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
C:\Users\Main User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - C:\Program Files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2008-3-13 1207376]
C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - C:\Program Files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]
2010-07-27 14:18:52 335136 —-a-w- C:\Program Files\GbPlugin\gbieh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-05-04 16:18:51 10536 —-a-w- C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [BU]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 23:16:40 22904]
S0 GbpKm;Gbp KernelMode;C:\Windows\system32\drivers\gbpkm.sys [2010-07-27 14:20:04 45472]
S2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe [2009-01-14 08:38:56 81920]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 22:48:22 108289]
S2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 18:05:28 155648]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;C:\BANCOB~1\Firebird\bin\fbguard.exe [2008-06-13 19:24:04 81920]
S2 GbpSv;Gbp Service;C:\PROGRA~1\GbPlugin\GbpSv.exe [2010-07-27 14:20:32 55072]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2008-03-24 06:26:30 183808]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;C:\BANCOB~1\Firebird\bin\fbserver.exe [2008-06-13 19:22:52 2723840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-09-12 C:\Windows\Tasks\User_Feed_Synchronization-{C16EB28D-AA9E-432A-94E0-2C7235A96E1F}.job
- C:\Windows\system32\msfeedssync.exe [2010-08-12 23:04:15 . 2010-06-26 04:24:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.searchqu.com/
Trusted Zone: bancobrasil.com.br\www14
Trusted Zone: bancobrasil.com.br\www2
Trusted Zone: bb.com.br\www
Trusted Zone: bdhoras.com.br\www
DPF: {DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931} - hxxps://www14.bancobrasil.com.br/plugin/GbpDist.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-12 15:48:03
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
Completion time: 2010-09-12 15:49:45
ComboFix-quarantined-files.txt 2010-09-12 21:49:43
ComboFix2.txt 2010-09-12 21:11:42
Pre-Run: 200,076,333,056 bytes free
Post-Run: 200,043,614,208 bytes free
- - End Of File - - E728CFD3C1892DAB99AADFED4E8DBF9E