Hey TomK,
Have posted the Combo Fix log below.
Cheers
Free
ComboFix 11-07-12.09 - Hills 13/07/2011 19:11:07.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.224.62 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Hills\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2011-06-13 to 2011-07-13 )))))))))))))))))))))))))))))))
.
.
2011-07-13 07:41 . 2011-06-06 22:55 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-07-13 07:12 . 2011-06-06 22:55 7074640 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1A39E423-4D41-4A78-B3E1-C31269F55650}\mpengine.dll
2011-07-12 07:10 . 2011-07-12 07:11 ——– d—–w- c:\program files\Microsoft Security Client
2011-07-12 06:47 . 2011-07-12 06:47 ——– d–h–w- c:\windows\system32\GroupPolicy
2011-07-10 12:47 . 2011-07-10 12:47 388096 —-a-r- c:\documents and settings\Hills\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-10 12:47 . 2011-07-10 12:47 ——– d—–w- c:\program files\Trend Micro
2011-07-10 11:43 . 2011-07-10 11:43 ——– d-sh–w- c:\documents and settings\Hills\IECompatCache
2011-07-09 10:41 . 2011-07-09 10:41 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-07-08 08:40 . 2009-06-30 00:37 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys
2011-07-08 08:40 . 2011-07-09 03:01 ——– d—–w- c:\program files\Panda Security
2011-07-04 09:23 . 2001-08-17 12:36 7168 -c–a-w- c:\windows\system32\dllcache\EXCH_snprfdll.dll
2011-07-04 09:23 . 2001-08-17 12:36 12288 -c–a-w- c:\windows\system32\dllcache\EXCH_smtpctrs.dll
2011-07-04 09:20 . 2001-08-17 12:36 26112 -c–a-w- c:\windows\system32\dllcache\EXCH_seos.dll
2011-07-04 09:20 . 2001-08-17 12:36 57856 -c–a-w- c:\windows\system32\dllcache\EXCH_scripto.dll
2011-07-04 09:17 . 2001-08-17 12:36 23040 -c–a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
2011-07-04 09:11 . 2001-08-17 12:36 38912 -c–a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2011-07-04 09:07 . 2001-08-17 12:36 65536 -c–a-w- c:\windows\system32\dllcache\EXCH_mailmsg.dll
2011-07-04 09:02 . 2001-08-18 23:00 10096640 -c–a-w- c:\windows\system32\dllcache\hwxcht.dll
2011-07-04 09:02 . 2001-08-17 03:28 488383 -c–a-w- c:\windows\system32\dllcache\hsf_v124.sys
2011-07-04 09:02 . 2001-08-17 03:28 50751 -c–a-w- c:\windows\system32\dllcache\hsf_tone.sys
2011-07-04 09:02 . 2001-08-17 03:28 73279 -c–a-w- c:\windows\system32\dllcache\hsf_spkp.sys
2011-07-04 09:02 . 2001-08-17 03:28 44863 -c–a-w- c:\windows\system32\dllcache\hsf_soar.sys
2011-07-04 09:02 . 2001-08-17 03:28 57471 -c–a-w- c:\windows\system32\dllcache\hsf_samp.sys
2011-07-04 09:00 . 2001-08-17 12:36 31232 -c–a-w- c:\windows\system32\dllcache\hpgt42tk.dll
2011-07-04 08:59 . 2008-04-13 18:45 59136 -c–a-w- c:\windows\system32\dllcache\gckernel.sys
2011-07-04 08:58 . 2001-08-17 02:10 22090 -c–a-w- c:\windows\system32\dllcache\fem556n5.sys
2011-07-04 08:57 . 2001-08-17 02:19 37120 -c–a-w- c:\windows\system32\dllcache\es1370mp.sys
2011-07-04 08:56 . 2001-08-17 02:10 24653 -c–a-w- c:\windows\system32\dllcache\el574nd4.sys
2011-07-04 08:55 . 2001-08-17 12:36 31305 -c–a-w- c:\windows\system32\dllcache\disrvpp.dll
2011-07-04 08:54 . 2001-08-17 03:52 179584 -c–a-w- c:\windows\system32\dllcache\dac2w2k.sys
2011-07-04 08:53 . 2001-08-17 03:51 20736 -c–a-w- c:\windows\system32\dllcache\cmbp0wdm.sys
2011-07-04 08:52 . 2001-08-17 03:51 13824 -c–a-w- c:\windows\system32\dllcache\bulltlp3.sys
2011-07-04 08:51 . 2001-08-17 02:13 37568 -c–a-w- c:\windows\system32\dllcache\avmwan.sys
2011-07-04 08:50 . 2004-08-03 12:32 10880 -c–a-w- c:\windows\system32\dllcache\admjoy.sys
2011-07-04 08:49 . 2001-08-18 23:00 6144 -c–a-w- c:\windows\system32\dllcache\ftpsapi2.dll
2011-07-03 04:40 . 2011-07-03 04:40 ——– d—–w- c:\windows\system32\wbem\Repository\FS
2011-07-03 04:40 . 2011-07-03 04:40 ——– d—–w- c:\windows\system32\wbem\Repository
2011-07-03 04:36 . 2011-07-03 04:36 ——– d—–w- c:\windows\system32\wbem\repository.old
2011-07-03 02:12 . 2011-07-03 02:12 ——– d—–w- c:\program files\Common Files\Java
2011-07-03 02:11 . 2011-07-03 02:10 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-07-03 02:10 . 2011-07-03 02:10 ——– d—–w- c:\program files\Java
2011-06-30 01:56 . 2011-06-30 01:56 ——– d—–w- c:\windows\system32\FxsTmp
2011-06-29 03:01 . 2011-06-29 03:01 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-06-29 03:01 . 2011-06-29 03:01 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-06-21 15:51 . 2001-11-28 23:57 110592 —-a-w- c:\windows\system32\ccrpbds6.dll
2011-06-21 15:50 . 2000-01-03 21:39 212992 —-a-w- c:\program files\Common Files\InstallShield\Engine\6\Intel 32\ILog.dll
2011-06-21 14:08 . 2000-05-22 06:58 608448 —-a-w- c:\windows\system32\COMCTL32.OCX
2011-06-19 03:18 . 2011-06-19 03:22 ——– d—–w- c:\program files\Common Files\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-09 10:15 . 2010-04-01 02:50 101720 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-07-04 11:32 . 2011-06-09 04:27 165232 —ha-w- c:\documents and settings\Hills\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
2011-07-03 02:10 . 2010-05-07 02:29 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-06-19 06:13 . 2011-05-18 06:33 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02 . 2007-07-27 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-21 10:11 . 2011-05-21 10:11 22 –sha-w- c:\documents and settings\Hills\Application Data\Sys2662.Config.Repository.bin
2011-05-21 09:28 . 2011-05-21 09:27 1060864 —-a-w- c:\windows\system32\mfc71.dll
2011-05-21 09:27 . 2011-05-21 09:27 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-05-21 09:27 . 2011-05-21 09:27 1700352 —-a-w- c:\windows\system32\gdiplus.dll
2011-05-17 09:13 . 2011-05-17 09:13 436792 —-a-w- c:\windows\system32\drivers\sptd.sys
2011-05-02 23:05 . 2011-05-02 23:05 3661824 —-a-w- c:\windows\system32\ffdshow.ax
2011-05-02 22:30 . 2011-05-02 22:30 1144147 —-a-w- c:\windows\system32\ffmpegmt.dll
2011-05-02 22:27 . 2011-05-02 22:27 3935545 —-a-w- c:\windows\system32\ffmpeg.dll
2011-05-02 20:23 . 2011-05-02 20:23 324096 —-a-w- c:\windows\system32\TomsMoComp_ff.dll
2011-05-02 20:19 . 2011-05-02 20:19 100352 —-a-w- c:\windows\system32\ff_wmv9.dll
2011-05-02 20:19 . 2011-05-02 20:19 80896 —-a-w- c:\windows\system32\ff_vfw.dll
2011-05-02 15:31 . 2009-07-20 23:30 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2007-07-27 12:00 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2007-07-27 12:00 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:22 . 2011-05-21 09:45 20800 —-a-w- c:\windows\system32\cnat.exe
2011-04-26 11:07 . 2007-07-27 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-04-26 11:07 . 2007-07-27 12:00 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-04-25 16:11 . 2007-07-27 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2007-07-27 12:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2007-07-27 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2007-07-27 12:00 385024 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2007-07-27 12:00 105472 —-a-w- c:\windows\system32\drivers\mup.sys
2011-04-20 13:07 . 2011-04-20 13:07 19072 —-a-w- c:\windows\system32\drivers\PS2.sys
2011-04-18 03:18 . 2011-04-18 03:18 165648 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2011-06-29 03:01 . 2011-03-24 14:05 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-03-16 325000]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]
backup=c:\windows\pss\NETGEAR WG111v2 Smart Wizard.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Hills^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\360Amigo
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"SeagateDashboardService"=2 (0x2)
"idsvc"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"SeaPort"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"MsMpSvc"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
.
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/07/2011 6:40 PM 28552]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17/05/2011 7:13 PM 436792]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [11/04/2011 2:01 PM 22504]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [21/07/2009 9:45 AM 177280]
S0 ncnvyc;ncnvyc;c:\windows\system32\drivers\pqnersy.sys –> c:\windows\system32\drivers\pqnersy.sys [?]
S1 MpKsl0fb37875;MpKsl0fb37875;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BB8ED481-7EDF-406B-9F35-59CE2BA53447}\MpKsl0fb37875.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BB8ED481-7EDF-406B-9F35-59CE2BA53447}\MpKsl0fb37875.sys [?]
S1 MpKsl1d181bf8;MpKsl1d181bf8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B2ED5FF7-D054-4783-A86D-760B190F89E4}\MpKsl1d181bf8.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B2ED5FF7-D054-4783-A86D-760B190F89E4}\MpKsl1d181bf8.sys [?]
S1 MpKsl21812df6;MpKsl21812df6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B2615E64-93D4-40D5-B8BC-C090A313DEE2}\MpKsl21812df6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B2615E64-93D4-40D5-B8BC-C090A313DEE2}\MpKsl21812df6.sys [?]
S1 MpKsl25caf545;MpKsl25caf545;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32BB4219-4D88-48E2-A5E5-936BDE97230F}\MpKsl25caf545.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32BB4219-4D88-48E2-A5E5-936BDE97230F}\MpKsl25caf545.sys [?]
S1 MpKsl33b3a1ac;MpKsl33b3a1ac;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5BC72CD4-71EB-4AC8-8FF3-4D88EB0DB0A4}\MpKsl33b3a1ac.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5BC72CD4-71EB-4AC8-8FF3-4D88EB0DB0A4}\MpKsl33b3a1ac.sys [?]
S1 MpKsl4053706f;MpKsl4053706f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7248DF8A-4F44-464F-BA4B-5F98EC90A592}\MpKsl4053706f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7248DF8A-4F44-464F-BA4B-5F98EC90A592}\MpKsl4053706f.sys [?]
S1 MpKsl4083cabc;MpKsl4083cabc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C32B66C4-BE68-4E67-8D4A-CE7AF8EACC18}\MpKsl4083cabc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C32B66C4-BE68-4E67-8D4A-CE7AF8EACC18}\MpKsl4083cabc.sys [?]
S1 MpKsl46e9b91d;MpKsl46e9b91d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F0DDAAE1-6C69-4B3E-BB6C-E424FDD4720A}\MpKsl46e9b91d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F0DDAAE1-6C69-4B3E-BB6C-E424FDD4720A}\MpKsl46e9b91d.sys [?]
S1 MpKsl493a3a28;MpKsl493a3a28;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F55D21BC-324A-41DE-B81F-0A7EB91827FE}\MpKsl493a3a28.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F55D21BC-324A-41DE-B81F-0A7EB91827FE}\MpKsl493a3a28.sys [?]
S1 MpKsl4ce43e45;MpKsl4ce43e45;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EA57B3D9-0282-4B83-8FAA-F25FCAEDF375}\MpKsl4ce43e45.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EA57B3D9-0282-4B83-8FAA-F25FCAEDF375}\MpKsl4ce43e45.sys [?]
S1 MpKsl512dd4b4;MpKsl512dd4b4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB0C375A-7721-4759-8E3F-59539922C84A}\MpKsl512dd4b4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FB0C375A-7721-4759-8E3F-59539922C84A}\MpKsl512dd4b4.sys [?]
S1 MpKsl53b0c832;MpKsl53b0c832;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{213F7A1D-E50D-4D06-A227-C59F23A15CF5}\MpKsl53b0c832.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{213F7A1D-E50D-4D06-A227-C59F23A15CF5}\MpKsl53b0c832.sys [?]
S1 MpKsl54faf401;MpKsl54faf401;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{95EE9ADC-ABB9-4B41-A22A-00EEE94B4DFF}\MpKsl54faf401.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{95EE9ADC-ABB9-4B41-A22A-00EEE94B4DFF}\MpKsl54faf401.sys [?]
S1 MpKsl559256ec;MpKsl559256ec;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{46AFE2D0-A218-4DEC-94DE-0A0A103F6C19}\MpKsl559256ec.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{46AFE2D0-A218-4DEC-94DE-0A0A103F6C19}\MpKsl559256ec.sys [?]
S1 MpKsl6476238b;MpKsl6476238b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2AF13516-A17C-4702-BC7C-6FCF83949039}\MpKsl6476238b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2AF13516-A17C-4702-BC7C-6FCF83949039}\MpKsl6476238b.sys [?]
S1 MpKsl6a3759a4;MpKsl6a3759a4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{53E26349-05FB-44FE-8D8B-195C14019141}\MpKsl6a3759a4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{53E26349-05FB-44FE-8D8B-195C14019141}\MpKsl6a3759a4.sys [?]
S1 MpKsl6b90c65f;MpKsl6b90c65f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5DBBD9B5-AF9B-4330-9643-342FE97EC9DC}\MpKsl6b90c65f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5DBBD9B5-AF9B-4330-9643-342FE97EC9DC}\MpKsl6b90c65f.sys [?]
S1 MpKsl6d015d6d;MpKsl6d015d6d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5FFEB89F-3873-4D73-AE03-E16C9B999AA0}\MpKsl6d015d6d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5FFEB89F-3873-4D73-AE03-E16C9B999AA0}\MpKsl6d015d6d.sys [?]
S1 MpKsl71926a0c;MpKsl71926a0c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BB119949-977E-4161-AC27-28214FED85FE}\MpKsl71926a0c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BB119949-977E-4161-AC27-28214FED85FE}\MpKsl71926a0c.sys [?]
S1 MpKsl7eef24e0;MpKsl7eef24e0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6397DD5E-B2F2-4E75-802F-DC089BBFCB6F}\MpKsl7eef24e0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6397DD5E-B2F2-4E75-802F-DC089BBFCB6F}\MpKsl7eef24e0.sys [?]
S1 MpKsl8a57a207;MpKsl8a57a207;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D21DAE6C-D3F4-4D5E-B082-5658742802F5}\MpKsl8a57a207.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D21DAE6C-D3F4-4D5E-B082-5658742802F5}\MpKsl8a57a207.sys [?]
S1 MpKsl93571654;MpKsl93571654;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F94DC3CE-FA93-4E3E-A3C0-DD4333470F1A}\MpKsl93571654.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F94DC3CE-FA93-4E3E-A3C0-DD4333470F1A}\MpKsl93571654.sys [?]
S1 MpKsl96adc073;MpKsl96adc073;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{213F7A1D-E50D-4D06-A227-C59F23A15CF5}\MpKsl96adc073.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{213F7A1D-E50D-4D06-A227-C59F23A15CF5}\MpKsl96adc073.sys [?]
S1 MpKsl98d60509;MpKsl98d60509;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5DBBD9B5-AF9B-4330-9643-342FE97EC9DC}\MpKsl98d60509.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5DBBD9B5-AF9B-4330-9643-342FE97EC9DC}\MpKsl98d60509.sys [?]
S1 MpKsl9fb5136b;MpKsl9fb5136b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2AF13516-A17C-4702-BC7C-6FCF83949039}\MpKsl9fb5136b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2AF13516-A17C-4702-BC7C-6FCF83949039}\MpKsl9fb5136b.sys [?]
S1 MpKsladef329c;MpKsladef329c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D5966E74-4F00-4C32-B3B7-5F1C6CCD234C}\MpKsladef329c.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D5966E74-4F00-4C32-B3B7-5F1C6CCD234C}\MpKsladef329c.sys [?]
S1 MpKslb15c7bd2;MpKslb15c7bd2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32BB4219-4D88-48E2-A5E5-936BDE97230F}\MpKslb15c7bd2.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{32BB4219-4D88-48E2-A5E5-936BDE97230F}\MpKslb15c7bd2.sys [?]
S1 MpKslc72a02d3;MpKslc72a02d3;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F94DC3CE-FA93-4E3E-A3C0-DD4333470F1A}\MpKslc72a02d3.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F94DC3CE-FA93-4E3E-A3C0-DD4333470F1A}\MpKslc72a02d3.sys [?]
S1 MpKslcc4e918a;MpKslcc4e918a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{46AFE2D0-A218-4DEC-94DE-0A0A103F6C19}\MpKslcc4e918a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{46AFE2D0-A218-4DEC-94DE-0A0A103F6C19}\MpKslcc4e918a.sys [?]
S1 MpKslcdf7b8d1;MpKslcdf7b8d1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A4E6679-33F7-4CF8-81C7-B65D02B3DC30}\MpKslcdf7b8d1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3A4E6679-33F7-4CF8-81C7-B65D02B3DC30}\MpKslcdf7b8d1.sys [?]
S1 MpKsleb30e3b0;MpKsleb30e3b0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F0DDAAE1-6C69-4B3E-BB6C-E424FDD4720A}\MpKsleb30e3b0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F0DDAAE1-6C69-4B3E-BB6C-E424FDD4720A}\MpKsleb30e3b0.sys [?]
S1 MpKslebbeb1ad;MpKslebbeb1ad;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6F298684-3AA3-4456-B7FD-23D4453A67B3}\MpKslebbeb1ad.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6F298684-3AA3-4456-B7FD-23D4453A67B3}\MpKslebbeb1ad.sys [?]
S1 MpKslecf18eb9;MpKslecf18eb9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{213F7A1D-E50D-4D06-A227-C59F23A15CF5}\MpKslecf18eb9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{213F7A1D-E50D-4D06-A227-C59F23A15CF5}\MpKslecf18eb9.sys [?]
S1 MpKslf2f10a77;MpKslf2f10a77;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2EEE4FB2-39DD-4964-8023-946A65526B54}\MpKslf2f10a77.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2EEE4FB2-39DD-4964-8023-946A65526B54}\MpKslf2f10a77.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\Hills\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> c:\docume~1\Hills\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\Hills\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS –> c:\docume~1\Hills\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 1:16 PM 130384]
S3 alcan5ln;SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [22/07/2009 10:13 AM 36256]
S3 CrucialSMBusScan;CrucialSMBusScan;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\CrucialSMBusScan_XP32.sys –> c:\docume~1\ADMINI~1\LOCALS~1\Temp\CrucialSMBusScan_XP32.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys –> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 1:16 PM 753504]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [20/07/2010 9:00 PM 136176]
S4 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [20/07/2010 9:00 PM 136176]
S4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [24/12/2010 2:44 PM 229376]
S4 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [7/07/2010 5:32 AM 14088]
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-13 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-26 07:24]
.
2011-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 10:59]
.
2011-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 10:59]
.
2011-07-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 05:39]
.
2011-07-13 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 05:39]
.
2011-07-13 c:\windows\Tasks\User_Feed_Synchronization-{10E034B1-B71A-4087-9E07-C1D0A21684BB}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:31]
.
2011-07-13 c:\windows\Tasks\User_Feed_Synchronization-{52F6F575-AC44-42F4-8EBB-0811180128D0}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
uSearchURL,(Default) = hxxp://www.forumswatcher.com/search.htm
TCP: DhcpNameServer = [removed] [removed] [removed]
FF - ProfilePath - c:\documents and settings\Hills\Application Data\Mozilla\Firefox\Profiles\7ostmh8m.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo-FileServe
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - prefs.js: keyword.URL - hxxp://www.google.com.au/
FF - prefs.js: network.proxy.type - 0
FF - user.js: keyword.URL - hxxp://www.google.com.au/
FF - user.js: keyword.enabled - 1
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-SiS7012 - c:\progra~1\SiS7012\Uninst\uninst2k.exe PCI\VEN_1039&DEV_7012
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-07-13 19:42
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1440)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-07-13 19:50:02 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-13 09:49
.
Pre-Run: 9,932,787,712 bytes free
Post-Run: 9,834,328,064 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - BD5897ADD9451C5AC31FF6811217CD5E