OK…. here ya go…… Had to run them in safe mode…
RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog :
http://tigzyrk.blogspot.com/
Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Safe mode
User : luci [Admin rights]
Mode : Scan – Date : 05/29/2013 23:43:44
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[…]\Run : Yontoo Desktop ("C:\Users\luci\AppData\Roaming\Yontoo\YontooDesktop.exe") [7] -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-1081050017-354470238-1449442463-1000[…]\Run : Yontoo Desktop ("C:\Users\luci\AppData\Roaming\Yontoo\YontooDesktop.exe") [7] -> FOUND
[HJ DESK] HKCU\[…]\ClassicStartMenu : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
[HJ DESK] HKCU\[…]\NewStartPanel : {645FF040-5081-101B-9F08-00AA002F954E} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
–> C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK2555GSX +++++
— User —
[MBR] c0a1f90d6b71eeaad3004f91e939b89f
[BSP] 92162bda169209246dbaa76b51240f40 : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 229585 Mo
2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 473264128 | Size: 7389 Mo
User = LL1 … OK!
User = LL2 … OK!
+++++ PhysicalDrive1: SanDisk Cruzer USB Device +++++
— User —
[MBR] edbe5daab2e704ce9b071d7fd7f46b36
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [XXXXXX] FAT32 (0x0b) [VISIBLE] Offset (sectors): 16 | Size: 3814 Mo
User = LL1 … OK!
Error reading LL2 MBR!
Finished : << RKreport[1]_S_05292013_02d2343.txt >>
RKreport[1]_S_05292013_02d2343.txt
ComboFix 13-05-29.01 - luci 05/29/2013 23:51:03.1.1 - x86 MINIMAL
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.2939.2436 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Outdated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton 360 *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton 360 *Disabled/Outdated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\FunWebProducts
c:\windows\system32\pt
c:\windows\system32\pt\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-30 )))))))))))))))))))))))))))))))
.
.
2013-05-30 03:57 . 2013-05-30 03:57 ——– d—–w- c:\users\Jim\AppData\Local\temp
2013-05-30 03:57 . 2013-05-30 03:57 ——– d—–w- c:\users\luci\AppData\Local\temp
2013-05-30 03:57 . 2013-05-30 03:57 ——– d—–w- c:\users\Guest\AppData\Local\temp
2013-05-30 03:57 . 2013-05-30 03:57 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-05-25 06:09 . 2013-05-25 06:09 ——– d—–w- c:\users\luci\AppData\Roaming\Template
2013-05-23 23:02 . 2013-05-23 23:02 ——– d—–w- c:\programdata\ErrorEND
2013-05-22 03:31 . 2013-05-05 19:12 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2013-05-21 02:54 . 2013-04-15 14:20 638328 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-05-21 02:54 . 2013-04-13 10:56 37376 —-a-w- c:\windows\system32\cdd.dll
2013-05-21 02:54 . 2013-04-09 01:36 2049024 —-a-w- c:\windows\system32\win32k.sys
2013-05-21 02:15 . 2013-05-21 02:15 ——– d—–w- C:\found.001
2013-05-20 13:33 . 2013-05-20 13:33 ——– d—–w- C:\found.000
2013-05-05 22:28 . 2013-05-05 22:28 ——– d—–w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-15 14:11 . 2012-07-22 12:39 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-05-15 14:11 . 2011-10-22 14:23 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-11 13:25 . 2013-04-10 11:32 3603816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-11 13:25 . 2013-04-10 11:32 3551080 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-03-09 03:45 . 2013-04-10 11:32 49152 —-a-w- c:\windows\system32\csrsrv.dll
2013-03-09 01:28 . 2013-04-10 11:32 64000 —-a-w- c:\windows\system32\smss.exe
2013-03-08 03:53 . 2013-04-10 11:32 376320 —-a-w- c:\windows\system32\winsrv.dll
2013-03-08 03:52 . 2013-04-10 11:32 2067968 —-a-w- c:\windows\system32\mstscax.dll
2013-03-03 19:07 . 2013-04-10 11:32 1082232 —-a-w- c:\windows\system32\drivers\ntfs.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-04-24 430080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-06-10 39408]
"Yontoo Desktop"="c:\users\luci\AppData\Roaming\Yontoo\YontooDesktop.exe" [2013-02-15 42784]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-02-28 18642024]
"OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-21 719672]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-02-06 431456]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-07 1029416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-06-02 505720]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"NDSTray.exe"="NDSTray.exe" [BU]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-07-05 30192]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"B2C_AGENT"="c:\programdata\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe" [2012-03-28 404568]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-05-09 716800]
.
c:\users\luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft SharePoint Workspace.lnk - c:\program files\Microsoft Office\Office14\GROOVE.EXE [2012-9-20 30785672]
OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2013-1-8 228448]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - COMHOST
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-22 14:11]
.
2013-05-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-13 23:14]
.
2013-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-13 23:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-vProt - c:\program files\AVG SafeGuard toolbar\vprot.exe
HKLM-Run-Lexmark X1100 Series - c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-05-29 23:57
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i??????g?R,$??h?????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(1844)
c:\windows\system32\ieframe.dll
c:\windows\System32\netshell.dll
.
Completion time: 2013-05-29 23:59:17
ComboFix-quarantined-files.txt 2013-05-30 03:59
.
Pre-Run: 165,322,227,712 bytes free
Post-Run: 166,172,708,864 bytes free
.
- - End Of File - - 5DA5CBA3AFE2D9DDA7CEE132EFB58D2B