Ok, I have a few things to report here. The first time I tried to run combofix, it gave me a warning that my McAfee antivirus software was active and that that could interfere with combofix. However (if you read my first post), I had uninstalled McAfee, which is what started all these problems. I had then tried a couple of system restores, and after those restores, the McAfee icon appeared again. But when I tried to uninstall it, (through the Windows uninstall program option), Windows informed me it had already been uninstalled.
Furthermore, when I opened the McAfee Security Center, both the Real-Time Scanning and the Firewall were off. So, I assumed this meant McAfee was actually NOT active. So, I went ahead and ran combofix.
It seemed to run fine, except that maybe it has stalled near the end of its run? It has left me with a window titled, "Administrator: ComboFix - Find 3M", the contents of which says: "Almost done … This window will close in a short while. Please wait a few seconds for the report log to pop up. Combofix's log shall be located at C:\COMBOFIX.TXT".
I have now waited several hours for this window to disappear, since it says it would. It is still up on my screen. So, I went ahead and grabbed the combofix.txt log file anyway, because it seems to have been created and completed.
So:
1) Should I close the Combofix window that remains open? Or is it still working and I should leave it open?
2) What is the next step?
Here is the combofix.txt log file. It seems to think that the McAfee antivirus and firewall were enabled, but again, I made sure they were both disabled. I don't even think McAfee is properly installed anymore anyway, so I don't know how it could be enabled and functioning. I look forward to your response.
ComboFix 13-07-25.02 - User 26/07/2013 17:57:38.1.2 - x86 MINIMAL
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.2.1033.18.1791.1356 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
FW: McAfee Firewall *Enabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-06-27 to 2013-07-27 )))))))))))))))))))))))))))))))
.
.
2013-07-27 01:03 . 2013-07-27 01:04 ——– d—–w- c:\users\User\AppData\Local\temp
2013-07-27 01:03 . 2013-07-27 01:03 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp
2013-07-27 01:03 . 2013-07-27 01:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-07-25 02:52 . 2013-07-25 02:52 ——– d—–w- C:\FRST
2013-07-11 12:45 . 2013-06-04 01:50 2049024 —-a-w- c:\windows\system32\win32k.sys
2013-07-11 12:45 . 2013-04-17 10:10 1069056 —-a-w- c:\windows\system32\DWrite.dll
2013-07-11 12:45 . 2013-04-17 10:10 798208 —-a-w- c:\windows\system32\FntCache.dll
2013-07-11 12:45 . 2013-04-17 11:28 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2013-07-11 12:45 . 2013-04-17 11:28 189952 —-a-w- c:\windows\system32\d3d10core.dll
2013-07-11 12:45 . 2013-04-17 10:33 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2013-07-11 12:45 . 2013-04-17 11:28 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2013-07-11 12:45 . 2013-04-17 11:28 1029120 —-a-w- c:\windows\system32\d3d10.dll
2013-07-11 12:45 . 2013-04-17 10:34 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2013-07-11 12:45 . 2013-04-17 10:14 683008 —-a-w- c:\windows\system32\d2d1.dll
2013-07-11 12:45 . 2013-06-01 04:06 505344 —-a-w- c:\windows\system32\qedit.dll
2013-07-11 12:45 . 2013-05-08 04:04 1548288 —-a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-11 12:45 . 2013-04-09 03:51 936960 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-12 04:10 . 2012-10-06 00:29 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 04:10 . 2011-12-15 15:51 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-08 04:37 . 2013-06-13 02:32 905576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-02 22:03 . 2013-06-13 02:31 3603832 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-02 22:03 . 2013-06-13 02:31 3551096 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-05-02 04:04 . 2013-06-13 02:32 443904 —-a-w- c:\windows\system32\win32spl.dll
2013-05-02 04:03 . 2013-06-13 02:32 37376 —-a-w- c:\windows\system32\printcom.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\Sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"="KEY" [X]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 5369856]
"Skytel"="Skytel.exe" [2007-11-20 1826816]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2012-10-25 421888]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe /noballoononstart [2008-12-28 385024]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ASETRES.EXE [2008-4-14 20480]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe 9999 [2008-4-8 535336]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-09-01 169624]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2013-07-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-06 04:10]
.
2013-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-06 00:01]
.
2013-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-06 00:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&s=1&o=vb32&d=1208&m=aspire_m1640
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
Trusted Zone: intuit.com\globalcommunities
TCP: DhcpNameServer = [removed] [removed]
Handler: intu-tt2011 - {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - c:\program files\TurboTax 2011\ic2011pp.dll
Handler: intu-tt2012 - {02F985EF-502B-4597-993F-6BF9E004C138} - c:\program files\TurboTax 2012\ic2012pp.dll
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-RemoteControl - K\POWERDVD\PDVDSERV.EXE
HKLM-Run-LanguageShortcut - GUAGE.EXE
HKLM-Run-Apanel - EL.CMD
HKLM-Run-eRecoveryService - (no file)
HKLM-Run-NVRaidService - VRAIDSERVICE.EXE
HKLM-Run-SunJavaUpdateSched - FILES\JAVA\JAVA UPDATE\JUSCHED.EXE
HKLM-Run-ALUAlert - OTIFY.EXE
HKLM-Run-AppleSyncNotifier - OTIFIER.EXE
HKLM-Run-Adobe ARM - FILES\ADOBE\ARM\1.0\ADOBEARM.EXE
HKLM-Run-APSDaemon - .EXE
HKLM-Run-AdobeAAMUpdater-1.0 - FILES\ADOBE\OOBE\PDAPP\UWA\UPDATERSTARTUPUTILITY.EXE
HKLM-Run-iTunesHelper - ESHELPER.EXE
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-07-26 18:04
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-07-26 18:06:55
ComboFix-quarantined-files.txt 2013-07-27 01:06
.
Pre-Run: 21,969,915,904 bytes free
Post-Run: 22,136,631,296 bytes free
.
- - End Of File - - FD61D8C147BF5B847DE192307B307327
A863475757CC50891AA8458C415E4B25