Chikeeto
Topic Starter
Hello,
Sorry I had to start a new topic, I was unable to get to my computer for a few days.
I uninstalled AVG so that combofix would run and here are the results:
ComboFix 12-07-12.02 - Cazzimodo 14/07/2012 17:05:30.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2006.927 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Cazzimodo\AppData\Local\.#
c:\users\Cazzimodo\AppData\Local\eikwevuk.log
c:\users\Cazzimodo\AppData\Local\gebtquyn.log
c:\users\Cazzimodo\AppData\Local\ilrryeuh\qrjejeex.exe
c:\users\Cazzimodo\AppData\Local\kstjseyl.log
c:\users\Cazzimodo\AppData\Local\sjqjddqt.log
c:\users\Cazzimodo\AppData\Local\tjgybktk.log
c:\users\Cazzimodo\AppData\Local\wceqmydo.log
c:\users\Cazzimodo\AppData\Roaming\.#
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2938.###
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2968.###
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2998.###
.
.
((((((((((((((((((((((((( Files Created from 2012-06-14 to 2012-07-14 )))))))))))))))))))))))))))))))
.
.
2012-07-14 16:19 . 2012-07-14 16:24 ——– d—–w- c:\users\Cazzimodo\AppData\Local\temp
2012-07-14 16:19 . 2012-07-14 16:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-07-13 14:39 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{706ED08E-829F-43C8-91C9-16331763E815}\mpengine.dll
2012-07-12 02:10 . 2012-06-13 13:40 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-07-11 15:36 . 2012-06-05 16:47 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 15:36 . 2012-06-05 16:47 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-07-11 15:36 . 2012-06-05 16:47 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-07-11 15:35 . 2012-06-04 15:26 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 15:35 . 2012-06-02 00:04 278528 —-a-w- c:\windows\system32\schannel.dll
2012-07-11 15:35 . 2012-06-02 00:03 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-06-30 10:33 . 2012-06-30 10:33 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-06-30 10:33 . 2012-07-04 20:48 829920 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2012-06-30 10:33 . 2012-07-04 20:48 2042848 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2012-06-22 18:44 . 2012-07-04 20:48 16864 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2012-06-22 08:49 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2012-06-22 08:49 . 2012-03-01 14:46 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-06-22 08:49 . 2012-03-01 14:46 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-06-22 08:49 . 2012-02-29 14:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-06-22 08:49 . 2012-02-29 13:44 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-06-22 08:49 . 2012-02-29 13:41 1069056 —-a-w- c:\windows\system32\DWrite.dll
2012-06-22 03:39 . 2012-06-22 03:39 ——– d—–w- c:\program files\Windows Portable Devices
2012-06-22 03:07 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2012-06-22 03:07 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2012-06-22 03:07 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2012-06-22 02:56 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-22 02:56 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-22 02:56 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-22 02:56 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-22 02:55 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-22 02:55 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-22 02:55 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-22 02:54 . 2012-06-02 14:19 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-22 02:54 . 2012-06-02 14:12 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-22 02:51 . 2012-02-29 15:11 5120 —-a-w- c:\windows\system32\wmi.dll
2012-06-22 02:51 . 2012-02-29 15:11 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-06-22 02:51 . 2012-02-29 15:09 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-06-22 02:51 . 2012-02-29 13:32 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-06-22 02:38 . 2012-06-22 02:38 307200 —-a-w- c:\program files\Internet Explorer\iediagcmd.exe
2012-06-22 02:38 . 2012-06-22 02:38 161792 —-a-w- c:\windows\system32\msls31.dll
2012-06-22 02:38 . 2012-06-22 02:38 107008 —-a-w- c:\program files\Internet Explorer\iecleanup.exe
2012-06-22 02:36 . 2012-06-22 02:36 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2012-06-22 02:36 . 2012-06-22 02:36 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2012-06-22 02:36 . 2012-06-22 02:36 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2012-06-22 02:36 . 2012-06-22 02:36 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2012-06-22 02:36 . 2012-06-22 02:36 98816 —-a-w- c:\windows\system32\mfps.dll
2012-06-22 02:36 . 2012-06-22 02:36 2873344 —-a-w- c:\windows\system32\mf.dll
2012-06-22 02:34 . 2012-06-22 02:34 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2012-06-22 02:34 . 2012-06-22 02:34 252928 —-a-w- c:\windows\system32\dxdiag.exe
2012-06-22 02:34 . 2012-06-22 02:34 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2012-06-22 02:34 . 2012-06-22 02:34 519680 —-a-w- c:\windows\system32\d3d11.dll
2012-06-22 02:34 . 2012-06-22 02:34 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2012-06-22 02:34 . 2012-06-22 02:34 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-06-22 02:34 . 2012-06-22 02:34 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-06-21 07:58 . 2012-04-23 16:00 984064 —-a-w- c:\windows\system32\crypt32.dll
2012-06-21 07:58 . 2012-04-23 16:00 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-06-21 07:58 . 2012-04-23 16:00 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-06-21 07:58 . 2011-07-29 16:01 293376 —-a-w- c:\windows\system32\psisdecd.dll
2012-06-21 07:58 . 2011-07-29 16:01 217088 —-a-w- c:\windows\system32\psisrndr.ax
2012-06-21 07:58 . 2011-07-29 16:00 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2012-06-21 07:58 . 2011-07-29 16:00 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2012-06-21 07:58 . 2011-10-14 16:03 189952 —-a-w- c:\windows\system32\winmm.dll
2012-06-21 07:58 . 2011-10-14 16:00 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-06-21 07:57 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2012-06-21 07:57 . 2012-02-01 15:11 1218048 —-a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-06-21 07:57 . 2012-02-01 15:10 964608 —-a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-06-21 07:57 . 2012-02-01 15:10 1404928 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2012-06-21 07:57 . 2012-02-01 15:10 983040 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-06-21 07:57 . 2012-02-01 15:10 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-06-21 07:57 . 2012-02-01 13:58 47104 —-a-w- c:\program files\Windows Journal\PDIALOG.exe
2012-06-21 07:57 . 2012-03-30 12:39 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-21 07:57 . 2012-03-20 23:28 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-21 07:57 . 2011-11-18 17:47 66560 —-a-w- c:\windows\system32\packager.dll
2012-06-21 07:57 . 2011-11-25 15:59 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-06-21 07:56 . 2011-10-25 15:58 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-06-21 07:56 . 2011-10-25 15:58 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-06-21 07:56 . 2011-11-16 16:23 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-06-21 07:56 . 2011-11-16 16:21 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-06-21 07:56 . 2011-11-16 16:23 72704 —-a-w- c:\windows\system32\secur32.dll
2012-06-21 07:56 . 2011-11-16 14:12 9728 —-a-w- c:\windows\system32\lsass.exe
2012-06-21 07:56 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2012-06-21 07:56 . 2011-12-14 16:17 680448 —-a-w- c:\windows\system32\msvcrt.dll
2012-06-21 07:56 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2012-06-21 07:56 . 2011-11-18 20:23 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-06-21 07:56 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2012-06-21 07:56 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2012-06-21 07:55 . 2012-03-01 11:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-06-21 07:55 . 2011-08-25 16:15 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2012-06-21 07:55 . 2011-08-25 16:14 238080 —-a-w- c:\windows\system32\oleacc.dll
2012-06-21 07:55 . 2011-08-25 13:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2012-06-21 07:55 . 2011-08-25 16:14 563712 —-a-w- c:\windows\system32\oleaut32.dll
2012-06-21 07:55 . 2012-05-01 14:03 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-21 07:55 . 2012-04-03 08:16 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-06-21 07:55 . 2012-04-03 08:16 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-21 07:55 . 2011-09-30 15:57 707584 —-a-w- c:\program files\Common Files\System\wab32.dll
2012-06-21 07:41 . 2010-05-04 19:13 231424 —-a-w- c:\windows\system32\msshsq.dll
2012-06-21 07:32 . 2012-01-09 15:54 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\ca-ES
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\eu-ES
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\vi-VN
2012-06-20 10:18 . 2012-07-02 17:02 ——– d—–w- c:\users\Cazzimodo\AppData\Local\ilrryeuh
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-22 02:34 . 2012-06-22 02:34 4096 —-a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2012-03-27 04:09 . 2012-03-27 04:09 293736 —-a-w- c:\program files\iTunesOutlookAddIn.dll
2012-03-27 04:09 . 2012-03-27 04:09 421736 —-a-w- c:\program files\iTunesHelper.exe
2012-03-27 04:09 . 2012-03-27 04:09 124776 —-a-w- c:\program files\iTunesMiniPlayer.dll
2012-03-27 04:09 . 2012-03-27 04:09 156520 —-a-w- c:\program files\iTunesHelper.dll
2012-03-27 04:09 . 2012-03-27 04:09 402792 —-a-w- c:\program files\iTunesAdmin.dll
2012-03-27 04:09 . 2012-03-27 04:09 9777000 —-a-w- c:\program files\iTunes.exe
2012-03-27 04:09 . 2012-03-27 04:09 21006696 —-a-w- c:\program files\iTunes.dll
2012-03-27 04:09 . 2012-03-27 04:09 797208 —-a-w- c:\program files\gnsdk_sdkmanager.dll
2012-03-27 04:09 . 2012-03-27 04:09 649576 —-a-w- c:\program files\iPodUpdaterExt.dll
2012-03-27 04:09 . 2012-03-27 04:09 3029528 —-a-w- c:\program files\gnsdk_dsp.dll
2012-03-27 04:09 . 2012-03-27 04:09 281112 —-a-w- c:\program files\gnsdk_submit.dll
2012-03-27 04:09 . 2012-03-27 04:09 240152 —-a-w- c:\program files\gnsdk_musicid.dll
2012-03-06 19:44 . 2012-03-06 19:44 112488 —-a-w- c:\program files\ITDetector.ocx
2012-07-04 20:48 . 2012-06-30 10:33 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Spotify Web Helper"="c:\users\Cazzimodo\Documents\Chikeeto's\Data\SpotifyWebHelper.exe" [2012-05-08 932528]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-08-25 200704]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-07-04 132392]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunesHelper.exe" [2012-03-27 421736]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-25 442460]
.
c:\users\Cazzimodo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-12-13 113664]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-31 1616976]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-11-18 17:56 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 17:38]
.
2012-07-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-25 18:56]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 16:18]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 16:18]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438885860-2208462255-2878762706-1000Core.job
- c:\users\Cazzimodo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 20:51]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438885860-2208462255-2878762706-1000UA.job
- c:\users\Cazzimodo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 20:51]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Cazzimodo\AppData\Roaming\Mozilla\Firefox\Profiles\mujlpshm.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.msn.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B3ed1ed09-536e-4385-a872-ae321c84fb7f%7D&mid=55e481a82585f07cebe73cfb4df89ed7-3c586feca70c5e74c334782c57fba0110f1190c3&ds=AVG&v=10.0.0.7&lang=us&pr=fr&d=2011-12-10%2014%3A33%3A45&sap=ku&q=
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKCU-Run-Exetender - c:\program files\Free Ride Games\GPlayer.exe
HKCU-Run-Facebook Update - c:\users\Cazzimodo\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKCU-Run-QrjEjeex - c:\users\Cazzimodo\AppData\Local\ilrryeuh\qrjejeex.exe
HKCU-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
AddRemove-Spotify - c:\users\Cazzimodo\Desktop\uninstall.exe
AddRemove-{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06} - c:\users\Cazzimodo\Documents\Chikeeto's\EAUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-14 17:23
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
c:\program files\Dell\DellDock\DockLogin.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Pen_Tablet.exe
c:\windows\system32\Wacom_Tablet.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\windows\system32\Pen_Tablet.exe
c:\windows\system32\WTablet\Wacom_TabletUser.exe
c:\windows\system32\Wacom_Tablet.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2012-07-14 17:31:11 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-14 16:30
.
Pre-Run: 15,890,980,864 bytes free
Post-Run: 18,242,781,184 bytes free
.
- - End Of File - - 5C0A0035F72AEC471A89929056ACD025
Sorry I had to start a new topic, I was unable to get to my computer for a few days.
I uninstalled AVG so that combofix would run and here are the results:
ComboFix 12-07-12.02 - Cazzimodo 14/07/2012 17:05:30.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2006.927 [GMT 1:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Cazzimodo\AppData\Local\.#
c:\users\Cazzimodo\AppData\Local\eikwevuk.log
c:\users\Cazzimodo\AppData\Local\gebtquyn.log
c:\users\Cazzimodo\AppData\Local\ilrryeuh\qrjejeex.exe
c:\users\Cazzimodo\AppData\Local\kstjseyl.log
c:\users\Cazzimodo\AppData\Local\sjqjddqt.log
c:\users\Cazzimodo\AppData\Local\tjgybktk.log
c:\users\Cazzimodo\AppData\Local\wceqmydo.log
c:\users\Cazzimodo\AppData\Roaming\.#
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2938.###
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2968.###
c:\users\Cazzimodo\AppData\Roaming\.#\MBX@BC4@1BA2998.###
.
.
((((((((((((((((((((((((( Files Created from 2012-06-14 to 2012-07-14 )))))))))))))))))))))))))))))))
.
.
2012-07-14 16:19 . 2012-07-14 16:24 ——– d—–w- c:\users\Cazzimodo\AppData\Local\temp
2012-07-14 16:19 . 2012-07-14 16:19 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-07-13 14:39 . 2012-05-31 03:41 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{706ED08E-829F-43C8-91C9-16331763E815}\mpengine.dll
2012-07-12 02:10 . 2012-06-13 13:40 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-07-11 15:36 . 2012-06-05 16:47 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-11 15:36 . 2012-06-05 16:47 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-07-11 15:36 . 2012-06-05 16:47 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-07-11 15:35 . 2012-06-04 15:26 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 15:35 . 2012-06-02 00:04 278528 —-a-w- c:\windows\system32\schannel.dll
2012-07-11 15:35 . 2012-06-02 00:03 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-06-30 10:33 . 2012-06-30 10:33 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2012-06-30 10:33 . 2012-07-04 20:48 829920 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2012-06-30 10:33 . 2012-07-04 20:48 2042848 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2012-06-22 18:44 . 2012-07-04 20:48 16864 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2012-06-22 08:49 . 2011-03-12 21:55 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2012-06-22 08:49 . 2012-03-01 14:46 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2012-06-22 08:49 . 2012-03-01 14:46 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2012-06-22 08:49 . 2012-02-29 14:08 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2012-06-22 08:49 . 2012-02-29 13:44 683008 —-a-w- c:\windows\system32\d2d1.dll
2012-06-22 08:49 . 2012-02-29 13:41 1069056 —-a-w- c:\windows\system32\DWrite.dll
2012-06-22 03:39 . 2012-06-22 03:39 ——– d—–w- c:\program files\Windows Portable Devices
2012-06-22 03:07 . 2009-09-10 02:00 92672 —-a-w- c:\windows\system32\UIAnimation.dll
2012-06-22 03:07 . 2009-09-10 02:01 3023360 —-a-w- c:\windows\system32\UIRibbon.dll
2012-06-22 03:07 . 2009-09-10 02:00 1164800 —-a-w- c:\windows\system32\UIRibbonRes.dll
2012-06-22 02:56 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-22 02:56 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-22 02:56 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-22 02:56 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-22 02:55 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-22 02:55 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-22 02:55 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-22 02:54 . 2012-06-02 14:19 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-22 02:54 . 2012-06-02 14:12 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-22 02:51 . 2012-02-29 15:11 5120 —-a-w- c:\windows\system32\wmi.dll
2012-06-22 02:51 . 2012-02-29 15:11 172032 —-a-w- c:\windows\system32\wintrust.dll
2012-06-22 02:51 . 2012-02-29 15:09 157696 —-a-w- c:\windows\system32\imagehlp.dll
2012-06-22 02:51 . 2012-02-29 13:32 12800 —-a-w- c:\windows\system32\drivers\fs_rec.sys
2012-06-22 02:38 . 2012-06-22 02:38 307200 —-a-w- c:\program files\Internet Explorer\iediagcmd.exe
2012-06-22 02:38 . 2012-06-22 02:38 161792 —-a-w- c:\windows\system32\msls31.dll
2012-06-22 02:38 . 2012-06-22 02:38 107008 —-a-w- c:\program files\Internet Explorer\iecleanup.exe
2012-06-22 02:36 . 2012-06-22 02:36 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2012-06-22 02:36 . 2012-06-22 02:36 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2012-06-22 02:36 . 2012-06-22 02:36 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2012-06-22 02:36 . 2012-06-22 02:36 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2012-06-22 02:36 . 2012-06-22 02:36 98816 —-a-w- c:\windows\system32\mfps.dll
2012-06-22 02:36 . 2012-06-22 02:36 2873344 —-a-w- c:\windows\system32\mf.dll
2012-06-22 02:34 . 2012-06-22 02:34 369664 —-a-w- c:\windows\system32\WMPhoto.dll
2012-06-22 02:34 . 2012-06-22 02:34 252928 —-a-w- c:\windows\system32\dxdiag.exe
2012-06-22 02:34 . 2012-06-22 02:34 195584 —-a-w- c:\windows\system32\dxdiagn.dll
2012-06-22 02:34 . 2012-06-22 02:34 519680 —-a-w- c:\windows\system32\d3d11.dll
2012-06-22 02:34 . 2012-06-22 02:34 974848 —-a-w- c:\windows\system32\WindowsCodecs.dll
2012-06-22 02:34 . 2012-06-22 02:34 321024 —-a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-06-22 02:34 . 2012-06-22 02:34 189440 —-a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-06-21 07:58 . 2012-04-23 16:00 984064 —-a-w- c:\windows\system32\crypt32.dll
2012-06-21 07:58 . 2012-04-23 16:00 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-06-21 07:58 . 2012-04-23 16:00 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-06-21 07:58 . 2011-07-29 16:01 293376 —-a-w- c:\windows\system32\psisdecd.dll
2012-06-21 07:58 . 2011-07-29 16:01 217088 —-a-w- c:\windows\system32\psisrndr.ax
2012-06-21 07:58 . 2011-07-29 16:00 57856 —-a-w- c:\windows\system32\MSDvbNP.ax
2012-06-21 07:58 . 2011-07-29 16:00 69632 —-a-w- c:\windows\system32\Mpeg2Data.ax
2012-06-21 07:58 . 2011-10-14 16:03 189952 —-a-w- c:\windows\system32\winmm.dll
2012-06-21 07:58 . 2011-10-14 16:00 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-06-21 07:57 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2012-06-21 07:57 . 2012-02-01 15:11 1218048 —-a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-06-21 07:57 . 2012-02-01 15:10 964608 —-a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-06-21 07:57 . 2012-02-01 15:10 1404928 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\InkObj.dll
2012-06-21 07:57 . 2012-02-01 15:10 983040 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-06-21 07:57 . 2012-02-01 15:10 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-06-21 07:57 . 2012-02-01 13:58 47104 —-a-w- c:\program files\Windows Journal\PDIALOG.exe
2012-06-21 07:57 . 2012-03-30 12:39 905600 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-06-21 07:57 . 2012-03-20 23:28 53120 —-a-w- c:\windows\system32\drivers\partmgr.sys
2012-06-21 07:57 . 2011-11-18 17:47 66560 —-a-w- c:\windows\system32\packager.dll
2012-06-21 07:57 . 2011-11-25 15:59 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-06-21 07:56 . 2011-10-25 15:58 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-06-21 07:56 . 2011-10-25 15:58 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-06-21 07:56 . 2011-11-16 16:23 377344 —-a-w- c:\windows\system32\winhttp.dll
2012-06-21 07:56 . 2011-11-16 16:21 1259008 —-a-w- c:\windows\system32\lsasrv.dll
2012-06-21 07:56 . 2011-11-16 16:23 72704 —-a-w- c:\windows\system32\secur32.dll
2012-06-21 07:56 . 2011-11-16 14:12 9728 —-a-w- c:\windows\system32\lsass.exe
2012-06-21 07:56 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2012-06-21 07:56 . 2011-12-14 16:17 680448 —-a-w- c:\windows\system32\msvcrt.dll
2012-06-21 07:56 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
2012-06-21 07:56 . 2011-11-18 20:23 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-06-21 07:56 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2012-06-21 07:56 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2012-06-21 07:55 . 2012-03-01 11:01 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-06-21 07:55 . 2011-08-25 16:15 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2012-06-21 07:55 . 2011-08-25 16:14 238080 —-a-w- c:\windows\system32\oleacc.dll
2012-06-21 07:55 . 2011-08-25 13:31 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2012-06-21 07:55 . 2011-08-25 16:14 563712 —-a-w- c:\windows\system32\oleaut32.dll
2012-06-21 07:55 . 2012-05-01 14:03 180736 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-21 07:55 . 2012-04-03 08:16 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-06-21 07:55 . 2012-04-03 08:16 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-06-21 07:55 . 2011-09-30 15:57 707584 —-a-w- c:\program files\Common Files\System\wab32.dll
2012-06-21 07:41 . 2010-05-04 19:13 231424 —-a-w- c:\windows\system32\msshsq.dll
2012-06-21 07:32 . 2012-01-09 15:54 613376 —-a-w- c:\windows\system32\rdpencom.dll
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\ca-ES
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\eu-ES
2012-06-21 02:24 . 2012-06-21 02:27 ——– d—–w- c:\windows\system32\vi-VN
2012-06-20 10:18 . 2012-07-02 17:02 ——– d—–w- c:\users\Cazzimodo\AppData\Local\ilrryeuh
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-22 02:34 . 2012-06-22 02:34 4096 —-a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2012-03-27 04:09 . 2012-03-27 04:09 293736 —-a-w- c:\program files\iTunesOutlookAddIn.dll
2012-03-27 04:09 . 2012-03-27 04:09 421736 —-a-w- c:\program files\iTunesHelper.exe
2012-03-27 04:09 . 2012-03-27 04:09 124776 —-a-w- c:\program files\iTunesMiniPlayer.dll
2012-03-27 04:09 . 2012-03-27 04:09 156520 —-a-w- c:\program files\iTunesHelper.dll
2012-03-27 04:09 . 2012-03-27 04:09 402792 —-a-w- c:\program files\iTunesAdmin.dll
2012-03-27 04:09 . 2012-03-27 04:09 9777000 —-a-w- c:\program files\iTunes.exe
2012-03-27 04:09 . 2012-03-27 04:09 21006696 —-a-w- c:\program files\iTunes.dll
2012-03-27 04:09 . 2012-03-27 04:09 797208 —-a-w- c:\program files\gnsdk_sdkmanager.dll
2012-03-27 04:09 . 2012-03-27 04:09 649576 —-a-w- c:\program files\iPodUpdaterExt.dll
2012-03-27 04:09 . 2012-03-27 04:09 3029528 —-a-w- c:\program files\gnsdk_dsp.dll
2012-03-27 04:09 . 2012-03-27 04:09 281112 —-a-w- c:\program files\gnsdk_submit.dll
2012-03-27 04:09 . 2012-03-27 04:09 240152 —-a-w- c:\program files\gnsdk_musicid.dll
2012-03-06 19:44 . 2012-03-06 19:44 112488 —-a-w- c:\program files\ITDetector.ocx
2012-07-04 20:48 . 2012-06-30 10:33 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Spotify Web Helper"="c:\users\Cazzimodo\Documents\Chikeeto's\Data\SpotifyWebHelper.exe" [2012-05-08 932528]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-08-25 200704]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-07-04 132392]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunesHelper.exe" [2012-03-27 421736]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-25 442460]
.
c:\users\Cazzimodo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-12-13 113664]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.207\SSScheduler.exe [2011-6-17 272528]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-31 1616976]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-9-23 1295656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-11-18 17:56 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-01 17:38]
.
2012-07-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-25 18:56]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 16:18]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 16:18]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438885860-2208462255-2878762706-1000Core.job
- c:\users\Cazzimodo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 20:51]
.
2012-07-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2438885860-2208462255-2878762706-1000UA.job
- c:\users\Cazzimodo\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-24 20:51]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Cazzimodo\AppData\Roaming\Mozilla\Firefox\Profiles\mujlpshm.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.msn.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B3ed1ed09-536e-4385-a872-ae321c84fb7f%7D&mid=55e481a82585f07cebe73cfb4df89ed7-3c586feca70c5e74c334782c57fba0110f1190c3&ds=AVG&v=10.0.0.7&lang=us&pr=fr&d=2011-12-10%2014%3A33%3A45&sap=ku&q=
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKCU-Run-Exetender - c:\program files\Free Ride Games\GPlayer.exe
HKCU-Run-Facebook Update - c:\users\Cazzimodo\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKCU-Run-QrjEjeex - c:\users\Cazzimodo\AppData\Local\ilrryeuh\qrjejeex.exe
HKCU-RunOnce-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
HKLM-Run-ROC_roc_dec12 - c:\program files\AVG Secure Search\ROC_roc_dec12.exe
AddRemove-Spotify - c:\users\Cazzimodo\Desktop\uninstall.exe
AddRemove-{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06} - c:\users\Cazzimodo\Documents\Chikeeto's\EAUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-14 17:23
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
c:\program files\Dell\DellDock\DockLogin.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Pen_Tablet.exe
c:\windows\system32\Wacom_Tablet.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\windows\system32\Pen_Tablet.exe
c:\windows\system32\WTablet\Wacom_TabletUser.exe
c:\windows\system32\Wacom_Tablet.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2012-07-14 17:31:11 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-14 16:30
.
Pre-Run: 15,890,980,864 bytes free
Post-Run: 18,242,781,184 bytes free
.
- - End Of File - - 5C0A0035F72AEC471A89929056ACD025