It's not on your desktop.
c:\docume~1\Parent\LOCALS~1\Temp\gktq9m2d.tmp\ComboFix.exe
Something weird just happened after I done all of this. I kept getting tons of error messages about the hard drive not having much memory and then it closed my computer and then opened. Some virus came up, but I got rid of it in the task manager. Now my desktop won't appear no matter what I do. I did another combofix check and heres the results. It just seems like this process made my computer act worse:
ComboFix 10-11-25.06 - Parent 11/26/2010 18:12:23.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1782.1272 [GMT -5:00]
Running from: c:\docume~1\Parent\LOCALS~1\Temp\vfnbt3i4.tmp\ComboFix.exe
AV: Total Protection Service *On-access scanning disabled* (Updated) {8C354827-2F54-4E28-90DC-AD391E77808C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Parent\Application Data\Adobe\AdobeUpdate .exe
c:\documents and settings\Parent\Application Data\Adobe\plugs
c:\documents and settings\Parent\Application Data\Adobe\plugs\KB11645218.exe
c:\documents and settings\Parent\Application Data\Adobe\plugs\KB11672109.exe
c:\documents and settings\Parent\Local Settings\Application Data\{E9A78BE3-0A6B-4C8D-8073-7E1E37A9F67B}
c:\documents and settings\Parent\Local Settings\Application Data\{E9A78BE3-0A6B-4C8D-8073-7E1E37A9F67B}\chrome.manifest
c:\documents and settings\Parent\Local Settings\Application Data\{E9A78BE3-0A6B-4C8D-8073-7E1E37A9F67B}\chrome\content\_cfg.js
c:\documents and settings\Parent\Local Settings\Application Data\{E9A78BE3-0A6B-4C8D-8073-7E1E37A9F67B}\chrome\content\overlay.xul
c:\documents and settings\Parent\Local Settings\Application Data\{E9A78BE3-0A6B-4C8D-8073-7E1E37A9F67B}\install.rdf
c:\windows\asutacokuvo.dll
c:\windows\system\winspool.drv
c:\windows\system32\msswinst.dll
c:\windows\t50ENM2.dll
Infected copy of c:\windows\system32\drivers\VolSnap.sys was found and disinfected
Restored copy from - c:\windows\system32\dllcache\volsnap.sys
Infected copy of c:\windows\system32\msgsvc.dll was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\msgsvc.dll
.
((((((((((((((((((((((((( Files Created from 2010-10-26 to 2010-11-26 )))))))))))))))))))))))))))))))
.
2010-11-26 22:42 . 2010-11-26 22:42 0 —-a-w- c:\windows\Kzeye.bin
2010-11-26 22:40 . 2010-11-26 22:41 53248 —-a-w- c:\windows\system32\drivers\sst4E.sys
2010-11-26 22:40 . 2010-11-26 22:40 122880 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\1164D.tmp
2010-11-26 22:40 . 2010-11-26 22:40 0 —-a-w- c:\windows\system32\drivers\sst4E.tmp
2010-11-25 23:13 . 2010-11-25 23:13 ——– d—–w- C:\_OTL
2010-11-22 19:29 . 2010-11-22 19:29 ——– d—–w- c:\program files\Paint.NET
2010-11-22 19:29 . 2010-11-24 21:52 ——– d—–w- c:\documents and settings\Parent\Local Settings\Application Data\Paint.NET
2010-11-22 19:28 . 2010-11-22 19:28 ——– d—–w- c:\program files\Reference Assemblies
2010-11-22 19:26 . 2010-11-22 19:26 ——– d—–r- C:\AHCache
2010-11-18 16:28 . 2010-11-26 21:31 ——– d—–w- c:\documents and settings\Parent\Local Settings\Application Data\SecondLife
2010-11-18 16:28 . 2010-11-18 16:28 ——– d—–w- c:\documents and settings\Parent\Application Data\SecondLife
2010-11-18 16:27 . 2010-11-18 16:33 ——– d—–w- c:\program files\SecondLifeViewer2
2010-11-17 04:41 . 2010-11-17 04:41 323624 —-a-w- c:\windows\system32\wiaaut.dll
2010-11-12 01:03 . 2010-11-12 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-11-12 01:03 . 2010-11-12 01:03 ——– d—–w- c:\program files\NOS
2010-11-11 00:24 . 2010-11-11 00:24 ——– d—–w- c:\documents and settings\Parent\Application Data\Malwarebytes
2010-11-11 00:24 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-11 00:24 . 2010-11-11 00:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-11-11 00:24 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-11-11 00:24 . 2010-11-11 00:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-11-10 23:39 . 2010-11-11 01:05 ——– d—–w- c:\program files\Common Files\PC Tools
2010-11-10 23:39 . 2010-11-11 00:15 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-11-10 23:36 . 2010-11-10 23:39 ——– d—–w- c:\documents and settings\Parent\Application Data\GetRightToGo
2010-11-10 00:16 . 2010-11-10 00:16 ——– d—–w- c:\windows\system32\wbem\Repository
2010-10-31 02:29 . 2010-10-31 02:29 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-10-30 17:50 . 2010-10-30 17:50 ——– d—–w- c:\documents and settings\Parent\Application Data\U3
2010-10-28 18:31 . 2010-10-31 02:31 ——– d—–w- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 16:23 . 2002-12-31 12:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2002-12-31 12:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2002-12-31 12:00 954368 —-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2002-12-31 12:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-09 13:38 . 2002-12-31 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-09-09 13:38 . 2002-12-31 12:00 1830912 —-a-w- c:\windows\system32\inetcpl.cpl
2010-09-09 13:38 . 2002-12-31 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-09-09 13:38 . 2002-12-31 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-09-08 15:57 . 2002-12-31 12:00 389120 —-a-w- c:\windows\system32\html.iec
2010-09-08 15:17 . 2010-09-08 15:17 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 15:17 . 2010-09-08 15:17 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-09-01 11:51 . 2002-12-31 12:00 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2002-12-31 12:00 1852800 —-a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-11-25_23.54.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-26 23:19 . 2010-11-26 23:19 16384 c:\windows\Temp\Perflib_Perfdata_7f4.dat
+ 2002-12-31 12:00 . 2010-11-26 23:08 51480 c:\windows\system32\perfc009.dat
- 2002-12-31 12:00 . 2010-11-25 22:31 51480 c:\windows\system32\perfc009.dat
+ 2010-06-17 03:28 . 2010-11-26 19:26 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-06-17 03:28 . 2010-11-13 22:41 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-11-26 22:40 . 2010-11-26 19:26 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-06-17 03:28 . 2010-11-13 22:41 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2002-12-31 12:00 . 2010-11-26 23:08 395318 c:\windows\system32\perfh009.dat
- 2002-12-31 12:00 . 2010-11-25 22:31 395318 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-04-22 737280]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\SecondLifeViewer2\\SLVoice.exe"=
R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [12/31/2002 7:00 AM 189448]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [6/12/2008 2:21 PM 1164536]
R2 rimspci;rimspci;c:\windows\system32\drivers\rimspe86.sys [6/16/2010 11:11 PM 48640]
R2 rixdpcie;rixdpcie;c:\windows\system32\drivers\rixdpe86.sys [6/16/2010 11:11 PM 38912]
R2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2/18/2010 4:26 PM 1664304]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [6/16/2010 11:11 PM 113664]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [12/31/2002 7:00 AM 41216]
S2 EngineServer;EngineServer;"c:\program files\McAfee\Managed VirusScan\VScan\EngineServer.exe" –> c:\program files\McAfee\Managed VirusScan\VScan\EngineServer.exe [?]
S2 myAgtSvc;McAfee Virus and Spyware Protection Service;"c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe" /ServiceStart –> c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.Exe [?]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [12/31/2002 7:00 AM 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-11-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: se-2011-download.com
Trusted Zone: se-2011-payment.com
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
Trusted Zone: se-2011-download.com
Trusted Zone: se-2011-payment.com
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Kwula - c:\windows\t50ENM2.dll
HKLM-Run-Jxugolifasufoli - c:\windows\asutacokuvo.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-11-26 18:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: WDC_____ rev.02.0 -> Harddisk0\DR0 -> \Device\Scsi\ahcix861
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89BA8446]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x89bae504]; MOV EAX, [0x89bae580]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x89657558]
3 CLASSPNP[0xBA108FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000076[0x89BBF920]
5 ACPI[0xB9F7F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x89BBFA38]
\Driver\ahcix86[0x89BDA8A0] -> IRP_MJ_CREATE -> 0x89BA8446
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Scsi\ahcix861Port0Path0Target0Lun0 -> \??\SCSI#Disk&Ven_WDC&Prod_WD1600BEKT-60&Rev_02.0#4&29fc4c67&0&000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
- - - - - - - > 'lsass.exe'(812)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3332)
c:\windows\system32\WININET.dll
c:\windows\system32\IEFRAME.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\idt\wdm\STacSV.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2010-11-26 18:23:38 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-26 23:23
ComboFix2.txt 2010-11-25 23:58
Pre-Run: 142,780,112,896 bytes free
Post-Run: 142,783,275,008 bytes free
- - End Of File - - 2A80B62F910AD0CE90B77B946385E92B