undun
ComboFix 09-02-05.02 - kc 2009-02-06 7:35:56.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.894.280 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.
2009-02-04 14:27 . 2009-02-04 14:27 d——– c:\program files\Panda Security
2009-02-04 14:27 . 2008-06-19 16:24 28,544 –a—— c:\windows\System32\drivers\pavboot.sys
2009-02-04 07:35 . 2009-02-04 09:45 250 –a—— c:\windows\gmer.ini
2009-02-03 14:03 . 2009-02-03 14:03 d——– c:\users\kc\AppData\Roaming\Template
2009-02-03 14:03 . 2009-02-03 14:03 0 –a—— c:\users\kc\AppData\Roaming\wklnhst.dat
2009-02-03 11:13 . 2009-02-03 11:13 d——– c:\users\kc\AppData\Roaming\Malwarebytes
2009-02-03 11:13 . 2009-02-03 11:13 d——– c:\users\All Users\Malwarebytes
2009-02-03 11:13 . 2009-02-03 11:13 d——– c:\programdata\Malwarebytes
2009-02-03 11:13 . 2009-02-03 11:13 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-03 11:13 . 2009-01-14 16:11 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-03 11:13 . 2009-01-14 16:11 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-01-29 20:47 . 2009-02-06 00:37 d–h—– C:\$AVG8.VAULT$
2009-01-29 19:35 . 2009-01-29 19:35 107,272 –a—— c:\windows\System32\drivers\avgtdix.sys
2009-01-29 19:35 . 2009-01-29 19:35 10,520 –a—— c:\windows\System32\avgrsstx.dll
2009-01-29 19:34 . 2009-02-05 09:46 d——– c:\windows\System32\drivers\Avg
2009-01-29 19:34 . 2009-01-29 19:34 325,128 –a—— c:\windows\System32\drivers\avgldx86.sys
2009-01-29 19:33 . 2009-01-29 19:33 d——– c:\program files\AVG
2009-01-29 18:24 . 2009-01-29 18:24 d–hs—- C:\found.000
2009-01-28 19:02 . 2009-02-06 00:58 d——– c:\program files\a-squared Anti-Malware
2009-01-27 19:47 . 2009-01-27 19:47 d——– c:\program files\Earth Viewpoint
2009-01-27 19:39 . 2009-02-06 05:51 d——– c:\users\All Users\Google Updater
2009-01-27 19:39 . 2009-02-06 05:51 d——– c:\programdata\Google Updater
2009-01-21 20:48 . 2009-01-21 20:48 d——– c:\program files\Trend Micro
2009-01-21 07:31 . 2009-01-29 12:19 3,153 –a—— C:\rollback.ini
2009-01-20 19:22 . 2009-01-29 18:20 14,997,280 –ahs—- c:\windows\System32\drivers\fidbox.dat
2009-01-20 19:22 . 2009-01-20 19:23 32 –ahs—- c:\windows\System32\drivers\fidbox.idx
2009-01-20 19:16 . 2009-01-20 19:17 d——– c:\users\All Users\ParetoLogic Anti-Virus PLUS
2009-01-20 19:16 . 2009-01-20 19:17 d——– c:\programdata\ParetoLogic Anti-Virus PLUS
2009-01-20 19:09 . 2009-01-29 18:32 d——– c:\program files\ParetoLogic
2009-01-20 19:09 . 2009-01-29 18:32 d——– c:\program files\Common Files\ParetoLogic
2009-01-20 18:18 . 2009-01-20 18:18 d——– c:\users\kc\AppData\Roaming\ParetoLogic
2009-01-20 18:17 . 2009-01-29 18:32 d——– c:\users\All Users\ParetoLogic
2009-01-20 18:17 . 2009-01-29 18:32 d——– c:\programdata\ParetoLogic
2009-01-20 18:16 . 2009-01-20 19:08 d——– c:\users\All Users\Downloaded Installations
2009-01-20 18:16 . 2009-01-20 19:08 d——– c:\programdata\Downloaded Installations
2009-01-20 18:10 . 2009-01-29 19:33 d——– c:\users\All Users\Avg8
2009-01-20 18:10 . 2009-01-29 19:33 d——– c:\programdata\Avg8
2009-01-18 21:05 . 2002-01-05 06:48 974,848 –a—— c:\windows\System32\mfc70.dll
2009-01-18 21:05 . 2002-01-05 05:40 487,424 –a—— c:\windows\System32\msvcp70.dll
2009-01-18 21:05 . 2002-01-05 11:37 344,064 –a—— c:\windows\System32\msvcr70.dll
2009-01-18 21:00 . 2009-01-18 21:00 d——– c:\users\kc\AppData\Roaming\GlarySoft
2009-01-18 20:47 . 2009-01-18 21:02 d——– c:\program files\Free Window Registry Repair
2009-01-18 20:33 . 2006-09-28 16:05 2,414,360 –a—— c:\windows\System32\d3dx9_31.dll
2009-01-15 19:24 . 2009-01-18 19:16 d——– c:\users\All Users\Spybot - Search & Destroy
2009-01-15 19:24 . 2009-01-18 19:16 d——– c:\programdata\Spybot - Search & Destroy
2009-01-15 19:22 . 2009-01-29 18:33 d——– c:\users\All Users\Lavasoft
2009-01-15 19:22 . 2009-01-29 18:33 d——– c:\programdata\Lavasoft
2009-01-15 19:15 . 2008-12-15 19:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-13 19:03 . 2009-01-15 18:57 d-a—— c:\users\All Users\TEMP
2009-01-13 19:03 . 2009-01-15 18:57 d-a—— c:\programdata\TEMP
2009-01-09 12:22 . 2009-01-09 12:22 d——– c:\users\kc\AppData\Roaming\AVS4YOU
2009-01-09 12:22 . 2009-01-09 12:22 d——– c:\users\All Users\AVS4YOU
2009-01-09 12:22 . 2009-01-09 12:22 d——– c:\programdata\AVS4YOU
2009-01-09 12:21 . 2009-01-13 17:53 d——– c:\program files\Common Files\AVSMedia
2009-01-09 12:21 . 2009-01-13 17:53 d——– c:\program files\AVS4YOU
2009-01-08 12:19 . 2009-01-09 12:22 d——– c:\users\kc\AppData\Roaming\DivX
2009-01-08 12:16 . 2009-01-13 17:54 d——– c:\program files\Common Files\PX Storage Engine
2009-01-07 17:20 . 2009-01-07 17:20 d——– c:\program files\Bonjour
2009-01-06 18:46 . 2009-01-20 19:17 d——– c:\users\kc\AppData\Roaming\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 01:40 ——— d—–w c:\program files\Common Files\Adobe
2009-01-28 02:49 ——— d—–w c:\program files\Google
2009-01-16 10:02 ——— d—–w c:\program files\Windows Mail
2009-01-11 18:21 ——— d—–w c:\users\kc\AppData\Roaming\MP3Rocket
2009-01-01 23:31 ——— d—–w c:\users\kc\AppData\Roaming\Apple Computer
2009-01-01 23:30 ——— d—–w c:\programdata\Apple Computer
2009-01-01 23:30 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-01 23:30 ——— d—–w c:\program files\iTunes
2009-01-01 23:30 ——— d—–w c:\program files\iPod
2009-01-01 23:30 ——— d—–w c:\program files\Common Files\Apple
2009-01-01 23:27 ——— d—–w c:\program files\QuickTime
2009-01-01 23:25 ——— d—–w c:\program files\Apple Software Update
2009-01-01 23:24 ——— d—–w c:\programdata\Apple
2008-12-26 02:58 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-12-21 16:23 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-12-21 06:06 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-12-18 01:23 174 –sha-w c:\program files\desktop.ini
2008-12-18 01:15 ——— d—–w c:\program files\Windows Sidebar
2008-12-18 01:15 ——— d—–w c:\program files\Windows Photo Gallery
2008-12-18 01:15 ——— d—–w c:\program files\Windows Journal
2008-12-18 01:15 ——— d—–w c:\program files\Windows Defender
2008-12-18 01:15 ——— d—–w c:\program files\Windows Collaboration
2008-12-18 01:15 ——— d—–w c:\program files\Windows Calendar
2008-12-17 18:35 82,432 —-a-w c:\windows\System32\axaltocm.dll
2008-12-17 18:35 101,888 —-a-w c:\windows\System32\ifxcardm.dll
2008-12-17 16:58 ——— d—–w c:\program files\Windows Live Toolbar
2008-12-17 16:56 ——— d—–w c:\program files\eMachines Games
2008-12-12 18:18 87,336 —-a-w c:\windows\System32\dns-sd.exe
2008-12-12 18:11 61,440 —-a-w c:\windows\System32\dnssd.dll
2008-12-12 10:08 ——— d—–w c:\programdata\Microsoft Help
2008-11-04 03:33 726,008 —-a-w c:\users\kc\gotomypc_437.exe
2008-09-28 04:34 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-09-28 04:34 32,768 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-09-28 04:34 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WeatherEye"="c:\program files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2009-01-16 4519832]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-23 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\System32\msconfig.exe" [2008-01-19 227840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-01-27 2784912]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-29 1601304]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
path=
backup=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix]
–a—— 2006-11-16 17:04 2348584 c:\program files\BigFix\bigfix.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
–a—— 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9CCA9104-B509-48A3-B6E9-DAC270DC0C64}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{FC662692-F118-4429-B594-497971FE51C9}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{19C0E128-CC4E-44B7-89F2-D9D34E72B45D}"= UDP:c:\program files\MP3 Rocket\MP3Rocket.exe:MP3 Rocket 5.1.4
"{CC9EE90B-7FF5-4002-900E-8F400F7EBE9F}"= TCP:c:\program files\MP3 Rocket\MP3Rocket.exe:MP3 Rocket 5.1.4
"{03EC06A2-F3A6-40E8-AD07-122810911EB8}"= Profile=Private|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{38C63BB7-D41A-4BE4-9A6E-C6C750709010}c:\\westwood\\ra2\\game.exe"= UDP:c:\westwood\ra2\game.exe:Main executable for Red Alert 2
"UDP Query User{76CBF90F-7ACB-477B-88F3-2B59FFB27854}c:\\westwood\\ra2\\game.exe"= TCP:c:\westwood\ra2\game.exe:Main executable for Red Alert 2
"{8260EB54-1A97-4E67-B7F3-1BC95CFABEB3}"= UDP:c:\westwood\RA2\Ra2.exe:Red Alert 2
"{EF7795B6-6049-4B94-817C-A944885A0AE7}"= TCP:c:\westwood\RA2\Ra2.exe:Red Alert 2
"TCP Query User{826FD630-0812-4FB5-B2A9-FF3A5C99EF14}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{A9AE7748-236F-4C83-A135-789E935CEC22}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{5D722992-8819-4ABE-B926-D1E400D3C219}"= UDP:c:\program files\MP3 Rocket\MP3Rocket.exe:MP3 Rocket 5.1.7
"{2CDE0719-5D57-43BA-AB9E-8BE7FD0F4268}"= TCP:c:\program files\MP3 Rocket\MP3Rocket.exe:MP3 Rocket 5.1.7
"{40B8D32C-3A44-4A16-845F-D0D6C75D793B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{83ACAA52-050C-4FEE-9139-3A373FD694BF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{E03248B2-9BB5-458F-978C-F31D055F4EF5}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{70A92A74-05A7-4FC9-B40F-AB8ADA349718}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{8B014187-1DA8-4886-BAAF-66D265AE07AD}c:\\program files\\java\\jre1.6.0_01\\bin\\javaw.exe"= UDP:c:\program files\java\jre1.6.0_01\bin\javaw.exe:Java™ Platform SE binary
"UDP Query User{55A66F47-757E-4E27-9B33-B9B18C734D44}c:\\program files\\java\\jre1.6.0_01\\bin\\javaw.exe"= TCP:c:\program files\java\jre1.6.0_01\bin\javaw.exe:Java™ Platform SE binary
"TCP Query User{C4746A8B-B18A-4ACF-B380-44AB487172AF}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= UDP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"UDP Query User{DB549CA6-8F25-458E-8C09-5C19A0B69933}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= TCP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"{45644CA7-6DA4-4662-BB22-A63D22A14975}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{F4FB582D-3791-45EE-ADBD-FE2B42000896}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{E89DF057-EE77-449E-98C2-13F6FFE6138A}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{03B9621A-A0D9-4843-9A82-0FA8C6CBD77C}"= Profile=Private|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6C795C3A-DBA9-445C-894A-0C1BABC59DE6}"= Disabled:c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D7E5D52F-E7D0-4020-905D-4FF249674F18}"= Disabled:c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2009-01-29 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2009-01-29 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-29 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-29 298264]
S2 gupdate1c980f2ca0647e0;Google Update Service (gupdate1c980f2ca0647e0);c:\program files\Google\Update\GoogleUpdate.exe [2009-01-27 119280]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-01-31 29744]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [2006-11-02 2589184]
S3 SaiH075C;SaiH075C;c:\windows\System32\drivers\SaiH075C.sys [2007-05-01 132232]
— Other Services/Drivers In Memory —
*Deregistered* - mchInjDrv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7006874a-8d7c-11dd-9ca5-806e6f6e6963}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2009-02-06 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-27 19:39]
2009-02-04 c:\windows\Tasks\GoogleUpdateTask.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-27 19:47]
2009-02-06 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=T5234
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: eset.eu\www
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 07:40:41
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-02-06 7:43:40
ComboFix-quarantined-files.txt 2009-02-06 14:43:36
Pre-Run: 213,288,841,216 bytes free
Post-Run: 213,333,438,464 bytes free
215 — E O F — 2009-02-06 04:26:53
We did put Go To My PC on here. My husband uses it to access his work computer and do paperwork from home. I ran that program and posted the log. Thank-you again for all you have done so far.
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.894.280 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.
2009-02-04 14:27 . 2009-02-04 14:27 d——– c:\program files\Panda Security
2009-02-04 14:27 . 2008-06-19 16:24 28,544 –a—— c:\windows\System32\drivers\pavboot.sys
2009-02-04 07:35 . 2009-02-04 09:45 250 –a—— c:\windows\gmer.ini
2009-02-03 14:03 . 2009-02-03 14:03 d——– c:\users\kc\AppData\Roaming\Template
2009-02-03 14:03 . 2009-02-03 14:03 0 –a—— c:\users\kc\AppData\Roaming\wklnhst.dat
2009-02-03 11:13 . 2009-02-03 11:13 d——– c:\users\kc\AppData\Roaming\Malwarebytes
2009-02-03 11:13 . 2009-02-03 11:13 d——– c:\users\All Users\Malwarebytes
2009-02-03 11:13 . 2009-02-03 11:13 d——– c:\programdata\Malwarebytes
2009-02-03 11:13 . 2009-02-03 11:13 d——– c:\program files\Malwarebytes' Anti-Malware
2009-02-03 11:13 . 2009-01-14 16:11 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-03 11:13 . 2009-01-14 16:11 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2009-01-29 20:47 . 2009-02-06 00:37 d–h—– C:\$AVG8.VAULT$
2009-01-29 19:35 . 2009-01-29 19:35 107,272 –a—— c:\windows\System32\drivers\avgtdix.sys
2009-01-29 19:35 . 2009-01-29 19:35 10,520 –a—— c:\windows\System32\avgrsstx.dll
2009-01-29 19:34 . 2009-02-05 09:46 d——– c:\windows\System32\drivers\Avg
2009-01-29 19:34 . 2009-01-29 19:34 325,128 –a—— c:\windows\System32\drivers\avgldx86.sys
2009-01-29 19:33 . 2009-01-29 19:33 d——– c:\program files\AVG
2009-01-29 18:24 . 2009-01-29 18:24 d–hs—- C:\found.000
2009-01-28 19:02 . 2009-02-06 00:58 d——– c:\program files\a-squared Anti-Malware
2009-01-27 19:47 . 2009-01-27 19:47 d——– c:\program files\Earth Viewpoint
2009-01-27 19:39 . 2009-02-06 05:51 d——– c:\users\All Users\Google Updater
2009-01-27 19:39 . 2009-02-06 05:51 d——– c:\programdata\Google Updater
2009-01-21 20:48 . 2009-01-21 20:48 d——– c:\program files\Trend Micro
2009-01-21 07:31 . 2009-01-29 12:19 3,153 –a—— C:\rollback.ini
2009-01-20 19:22 . 2009-01-29 18:20 14,997,280 –ahs—- c:\windows\System32\drivers\fidbox.dat
2009-01-20 19:22 . 2009-01-20 19:23 32 –ahs—- c:\windows\System32\drivers\fidbox.idx
2009-01-20 19:16 . 2009-01-20 19:17 d——– c:\users\All Users\ParetoLogic Anti-Virus PLUS
2009-01-20 19:16 . 2009-01-20 19:17 d——– c:\programdata\ParetoLogic Anti-Virus PLUS
2009-01-20 19:09 . 2009-01-29 18:32 d——– c:\program files\ParetoLogic
2009-01-20 19:09 . 2009-01-29 18:32 d——– c:\program files\Common Files\ParetoLogic
2009-01-20 18:18 . 2009-01-20 18:18 d——– c:\users\kc\AppData\Roaming\ParetoLogic
2009-01-20 18:17 . 2009-01-29 18:32 d——– c:\users\All Users\ParetoLogic
2009-01-20 18:17 . 2009-01-29 18:32 d——– c:\programdata\ParetoLogic
2009-01-20 18:16 . 2009-01-20 19:08 d——– c:\users\All Users\Downloaded Installations
2009-01-20 18:16 . 2009-01-20 19:08 d——– c:\programdata\Downloaded Installations
2009-01-20 18:10 . 2009-01-29 19:33 d——– c:\users\All Users\Avg8
2009-01-20 18:10 . 2009-01-29 19:33 d——– c:\programdata\Avg8
2009-01-18 21:05 . 2002-01-05 06:48 974,848 –a—— c:\windows\System32\mfc70.dll
2009-01-18 21:05 . 2002-01-05 05:40 487,424 –a—— c:\windows\System32\msvcp70.dll
2009-01-18 21:05 . 2002-01-05 11:37 344,064 –a—— c:\windows\System32\msvcr70.dll
2009-01-18 21:00 . 2009-01-18 21:00 d——– c:\users\kc\AppData\Roaming\GlarySoft
2009-01-18 20:47 . 2009-01-18 21:02 d——– c:\program files\Free Window Registry Repair
2009-01-18 20:33 . 2006-09-28 16:05 2,414,360 –a—— c:\windows\System32\d3dx9_31.dll
2009-01-15 19:24 . 2009-01-18 19:16 d——– c:\users\All Users\Spybot - Search & Destroy
2009-01-15 19:24 . 2009-01-18 19:16 d——– c:\programdata\Spybot - Search & Destroy
2009-01-15 19:22 . 2009-01-29 18:33 d——– c:\users\All Users\Lavasoft
2009-01-15 19:22 . 2009-01-29 18:33 d——– c:\programdata\Lavasoft
2009-01-15 19:15 . 2008-12-15 19:42 288,768 –a—— c:\windows\System32\drivers\srv.sys
2009-01-13 19:03 . 2009-01-15 18:57 d-a—— c:\users\All Users\TEMP
2009-01-13 19:03 . 2009-01-15 18:57 d-a—— c:\programdata\TEMP
2009-01-09 12:22 . 2009-01-09 12:22 d——– c:\users\kc\AppData\Roaming\AVS4YOU
2009-01-09 12:22 . 2009-01-09 12:22 d——– c:\users\All Users\AVS4YOU
2009-01-09 12:22 . 2009-01-09 12:22 d——– c:\programdata\AVS4YOU
2009-01-09 12:21 . 2009-01-13 17:53 d——– c:\program files\Common Files\AVSMedia
2009-01-09 12:21 . 2009-01-13 17:53 d——– c:\program files\AVS4YOU
2009-01-08 12:19 . 2009-01-09 12:22 d——– c:\users\kc\AppData\Roaming\DivX
2009-01-08 12:16 . 2009-01-13 17:54 d——– c:\program files\Common Files\PX Storage Engine
2009-01-07 17:20 . 2009-01-07 17:20 d——– c:\program files\Bonjour
2009-01-06 18:46 . 2009-01-20 19:17 d——– c:\users\kc\AppData\Roaming\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 01:40 ——— d—–w c:\program files\Common Files\Adobe
2009-01-28 02:49 ——— d—–w c:\program files\Google
2009-01-16 10:02 ——— d—–w c:\program files\Windows Mail
2009-01-11 18:21 ——— d—–w c:\users\kc\AppData\Roaming\MP3Rocket
2009-01-01 23:31 ——— d—–w c:\users\kc\AppData\Roaming\Apple Computer
2009-01-01 23:30 ——— d—–w c:\programdata\Apple Computer
2009-01-01 23:30 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-01 23:30 ——— d—–w c:\program files\iTunes
2009-01-01 23:30 ——— d—–w c:\program files\iPod
2009-01-01 23:30 ——— d—–w c:\program files\Common Files\Apple
2009-01-01 23:27 ——— d—–w c:\program files\QuickTime
2009-01-01 23:25 ——— d—–w c:\program files\Apple Software Update
2009-01-01 23:24 ——— d—–w c:\programdata\Apple
2008-12-26 02:58 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-12-21 16:23 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-12-21 06:06 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-12-18 01:23 174 –sha-w c:\program files\desktop.ini
2008-12-18 01:15 ——— d—–w c:\program files\Windows Sidebar
2008-12-18 01:15 ——— d—–w c:\program files\Windows Photo Gallery
2008-12-18 01:15 ——— d—–w c:\program files\Windows Journal
2008-12-18 01:15 ——— d—–w c:\program files\Windows Defender
2008-12-18 01:15 ——— d—–w c:\program files\Windows Collaboration
2008-12-18 01:15 ——— d—–w c:\program files\Windows Calendar
2008-12-17 18:35 82,432 —-a-w c:\windows\System32\axaltocm.dll
2008-12-17 18:35 101,888 —-a-w c:\windows\System32\ifxcardm.dll
2008-12-17 16:58 ——— d—–w c:\program files\Windows Live Toolbar
2008-12-17 16:56 ——— d—–w c:\program files\eMachines Games
2008-12-12 18:18 87,336 —-a-w c:\windows\System32\dns-sd.exe
2008-12-12 18:11 61,440 —-a-w c:\windows\System32\dnssd.dll
2008-12-12 10:08 ——— d—–w c:\programdata\Microsoft Help
2008-11-04 03:33 726,008 —-a-w c:\users\kc\gotomypc_437.exe
2008-09-28 04:34 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-09-28 04:34 32,768 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-09-28 04:34 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WeatherEye"="c:\program files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2009-01-16 4519832]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-23 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\System32\msconfig.exe" [2008-01-19 227840]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-01-27 2784912]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-29 1601304]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
path=
backup=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix]
–a—— 2006-11-16 17:04 2348584 c:\program files\BigFix\bigfix.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
–a—— 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9CCA9104-B509-48A3-B6E9-DAC270DC0C64}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{FC662692-F118-4429-B594-497971FE51C9}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{19C0E128-CC4E-44B7-89F2-D9D34E72B45D}"= UDP:c:\program files\MP3 Rocket\MP3Rocket.exe:MP3 Rocket 5.1.4
"{CC9EE90B-7FF5-4002-900E-8F400F7EBE9F}"= TCP:c:\program files\MP3 Rocket\MP3Rocket.exe:MP3 Rocket 5.1.4
"{03EC06A2-F3A6-40E8-AD07-122810911EB8}"= Profile=Private|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{38C63BB7-D41A-4BE4-9A6E-C6C750709010}c:\\westwood\\ra2\\game.exe"= UDP:c:\westwood\ra2\game.exe:Main executable for Red Alert 2
"UDP Query User{76CBF90F-7ACB-477B-88F3-2B59FFB27854}c:\\westwood\\ra2\\game.exe"= TCP:c:\westwood\ra2\game.exe:Main executable for Red Alert 2
"{8260EB54-1A97-4E67-B7F3-1BC95CFABEB3}"= UDP:c:\westwood\RA2\Ra2.exe:Red Alert 2
"{EF7795B6-6049-4B94-817C-A944885A0AE7}"= TCP:c:\westwood\RA2\Ra2.exe:Red Alert 2
"TCP Query User{826FD630-0812-4FB5-B2A9-FF3A5C99EF14}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{A9AE7748-236F-4C83-A135-789E935CEC22}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{5D722992-8819-4ABE-B926-D1E400D3C219}"= UDP:c:\program files\MP3 Rocket\MP3Rocket.exe:MP3 Rocket 5.1.7
"{2CDE0719-5D57-43BA-AB9E-8BE7FD0F4268}"= TCP:c:\program files\MP3 Rocket\MP3Rocket.exe:MP3 Rocket 5.1.7
"{40B8D32C-3A44-4A16-845F-D0D6C75D793B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{83ACAA52-050C-4FEE-9139-3A373FD694BF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{E03248B2-9BB5-458F-978C-F31D055F4EF5}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{70A92A74-05A7-4FC9-B40F-AB8ADA349718}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{8B014187-1DA8-4886-BAAF-66D265AE07AD}c:\\program files\\java\\jre1.6.0_01\\bin\\javaw.exe"= UDP:c:\program files\java\jre1.6.0_01\bin\javaw.exe:Java™ Platform SE binary
"UDP Query User{55A66F47-757E-4E27-9B33-B9B18C734D44}c:\\program files\\java\\jre1.6.0_01\\bin\\javaw.exe"= TCP:c:\program files\java\jre1.6.0_01\bin\javaw.exe:Java™ Platform SE binary
"TCP Query User{C4746A8B-B18A-4ACF-B380-44AB487172AF}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= UDP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"UDP Query User{DB549CA6-8F25-458E-8C09-5C19A0B69933}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= TCP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"{45644CA7-6DA4-4662-BB22-A63D22A14975}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{F4FB582D-3791-45EE-ADBD-FE2B42000896}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{E89DF057-EE77-449E-98C2-13F6FFE6138A}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{03B9621A-A0D9-4843-9A82-0FA8C6CBD77C}"= Profile=Private|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6C795C3A-DBA9-445C-894A-0C1BABC59DE6}"= Disabled:c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D7E5D52F-E7D0-4020-905D-4FF249674F18}"= Disabled:c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2009-01-29 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2009-01-29 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-29 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-29 298264]
S2 gupdate1c980f2ca0647e0;Google Update Service (gupdate1c980f2ca0647e0);c:\program files\Google\Update\GoogleUpdate.exe [2009-01-27 119280]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-01-31 29744]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [2006-11-02 2589184]
S3 SaiH075C;SaiH075C;c:\windows\System32\drivers\SaiH075C.sys [2007-05-01 132232]
— Other Services/Drivers In Memory —
*Deregistered* - mchInjDrv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7006874a-8d7c-11dd-9ca5-806e6f6e6963}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2009-02-06 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-27 19:39]
2009-02-04 c:\windows\Tasks\GoogleUpdateTask.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-27 19:47]
2009-02-06 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=T5234
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: eset.eu\www
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 07:40:41
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-02-06 7:43:40
ComboFix-quarantined-files.txt 2009-02-06 14:43:36
Pre-Run: 213,288,841,216 bytes free
Post-Run: 213,333,438,464 bytes free
215 — E O F — 2009-02-06 04:26:53
We did put Go To My PC on here. My husband uses it to access his work computer and do paperwork from home. I ran that program and posted the log. Thank-you again for all you have done so far.