5:29 PM 1/4/2010
Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\Owner>chkdsk c: /f
The type of the file system is NTFS.
Cannot lock current drive.
Chkdsk cannot run because the volume is in use by another
process. Would you like to schedule this volume to be
checked the next time the system restarts? (Y/N) y
This volume will be checked the next time the system restarts.
C:\Documents and Settings\Owner>
Tried via Safe mode with command prompt, same message.
5:46 PM 1/4/2010
Tried via My Computer and C: Drive Right Click, Properties, Tools Tab, Error Checking: Check Now.
Error system popup:
Windows was unable to complete the disk check.
===
Pushing forward with Combofix.
Disabled or closed AD Aware and all programs in taskbar.
However Pandascan has informed me before there is Avira Anti Virus running but possibly disabled. However there is no icon there. And the icon is usually there even if the antivirus is temporarily disabled. Should not be an issue however.
Will report back after scan with Combofix.
5:55 PM 1/4/2010
Combofix says:
Cannot rename Combofix as D_T use preferrably alphanumerics instead.
The program quit itself. Trying again. Renaming as something else.
Will update and edit again after successful scan.
6:29 PM 1/4/2010
ComboFix 10-01-04.01 - Owner 01/04/2010 18:04:22.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1411 [GMT -8:00]
Running from: c:\documents and settings\Owner\Desktop\DT.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\H8SRThlcbdliays.sys
c:\windows\system32\drivers\wmndrswwxjfo.sys
c:\windows\system32\drivers\wyvvkobfcupl.sys
c:\windows\system32\H8SRTjqyrsrpkns.dll
c:\windows\system32\H8SRTkxvcygsbrk.dll
c:\windows\system32\H8SRTtfokftulsi.dll
c:\windows\system32\H8SRTxmlnxceryo.dat
c:\windows\system32\srcr.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
-------\Legacy_wmndrswwxjfo
-------\Legacy_wyvvkobfcupl
-------\Service_wmndrswwxjfo
-------\Service_wyvvkobfcupl
((((((((((((((((((((((((( Files Created from 2009-12-05 to 2010-01-05 )))))))))))))))))))))))))))))))
.
2010-01-04 07:26 . 2009-12-02 13:19 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-01-04 07:18 . 2009-12-02 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-01-04 07:16 . 2010-01-04 07:16 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-01-04 07:16 . 2010-01-04 07:16 -------- d-----w- c:\program files\Lavasoft
2010-01-02 10:06 . 2010-01-02 10:06 -------- d-----w- c:\program files\YouTube Downloader
2010-01-02 10:05 . 2009-12-30 22:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-02 10:05 . 2009-12-30 22:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 10:02 . 2009-03-30 17:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-02 10:02 . 2009-02-13 19:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-02 10:02 . 2009-02-13 19:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-02 10:02 . 2010-01-02 10:02 -------- d-----w- c:\program files\Avira
2010-01-02 10:02 . 2010-01-02 10:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-01-02 08:45 . 2008-04-14 01:12 151552 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2010-01-02 08:45 . 2008-04-14 01:12 151552 ----a-w- c:\windows\system32\irftp.exe
2010-01-02 08:45 . 2008-04-14 01:12 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2010-01-02 08:45 . 2008-04-14 01:12 8192 ----a-w- c:\windows\system32\wshirda.dll
2010-01-02 08:45 . 2008-04-14 01:11 28160 -c--a-w- c:\windows\system32\dllcache\irmon.dll
2010-01-02 08:45 . 2008-04-14 01:11 28160 ----a-w- c:\windows\system32\irmon.dll
2010-01-02 00:30 . 2010-01-02 00:30 -------- d-----w- C:\54c70206bd02a4851e4769d48c
2009-12-31 19:32 . 2009-12-31 19:32 -------- d-----w- c:\program files\twhirl
2009-12-31 19:21 . 2009-05-07 07:04 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-12-31 19:02 . 2010-01-03 19:44 -------- d-----w- C:\HJT
2009-12-31 10:20 . 2009-12-31 10:19 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-31 08:29 . 2009-12-31 08:32 -------- d-----w- C:\Qoofix
2009-12-31 08:22 . 2009-12-31 08:22 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-12-31 08:09 . 2009-06-30 17:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-12-31 08:09 . 2009-12-31 08:09 -------- d-----w- c:\program files\Panda Security
2009-12-31 00:42 . 2009-12-31 00:42 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-12-31 00:41 . 2009-12-31 00:41 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-12-30 23:10 . 2010-01-04 00:19 860 ----a-w- c:\windows\system32\krl32mainweq.dll
2009-12-23 19:53 . 2009-12-23 19:53 -------- d-----w- c:\program files\Unlocker
2009-12-14 06:25 . 2009-12-14 06:25 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-14 06:24 . 2009-12-14 06:24 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2009-12-07 08:51 . 2010-01-04 06:50 -------- d-----w- C:\w
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 02:17 . 2007-07-14 03:55 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-05 02:14 . 2007-05-20 08:48 17920 -c--a-w- c:\windows\system32\rpcnetp.exe
2010-01-05 02:14 . 2007-05-18 07:36 56680 -c--a-w- c:\windows\system32\Rpcnet.dll
2010-01-04 07:18 . 2010-01-04 07:18 862040 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-01-04 07:18 . 2010-01-04 07:18 206944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-01-04 07:18 . 2010-01-04 07:17 390288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-01-04 07:17 . 2010-01-04 07:17 537576 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-01-04 07:17 . 2010-01-04 07:17 370744 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-01-04 07:17 . 2010-01-04 07:17 194104 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-04 07:17 . 2010-01-04 07:17 6296864 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-01-04 07:17 . 2010-01-04 07:17 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-01-04 07:17 . 2010-01-04 07:17 816272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-01-04 07:17 . 2010-01-04 07:17 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-01-04 07:17 . 2010-01-04 07:17 1643272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-01-04 07:17 . 2010-01-04 07:17 788880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-01-04 07:17 . 2010-01-04 07:17 1181328 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-01-04 07:16 . 2008-07-17 04:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-04 07:03 . 2007-05-18 06:48 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-04 07:03 . 2007-05-18 06:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-03 00:46 . 2007-05-18 23:44 -------- d-----w- c:\program files\DivX
2010-01-03 00:45 . 2009-03-27 13:23 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-01-02 10:07 . 2007-07-22 07:02 -------- d-----w- c:\program files\Startup Faster 2004
2010-01-02 10:05 . 2009-10-06 10:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-02 09:53 . 2008-03-30 14:37 -------- d-----w- c:\program files\Collage Maker
2010-01-02 09:53 . 2006-05-22 21:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-02 09:53 . 2007-08-18 03:22 -------- d-----w- c:\program files\Beston
2010-01-02 09:49 . 2006-05-22 18:25 -------- d-----w- c:\program files\Intel
2010-01-02 09:43 . 2007-05-30 23:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2010-01-02 09:42 . 2007-05-18 06:44 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-02 09:41 . 2007-09-20 04:46 -------- d-----w- c:\program files\SpywareBlaster
2010-01-02 09:39 . 2007-05-30 23:37 -------- d-----w- c:\program files\Common Files\AOL
2010-01-02 09:39 . 2007-05-30 23:37 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-01-01 21:50 . 2007-05-18 09:32 29464 -c--a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-01 02:30 . 2008-11-17 10:29 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-01 01:49 . 2008-09-26 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-12-31 10:45 . 2007-05-22 12:25 -------- d-----w- c:\program files\LimeWire
2009-12-31 10:19 . 2007-05-22 12:26 -------- d-----w- c:\program files\Java
2009-12-31 10:18 . 2009-12-31 09:50 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-31 10:18 . 2009-12-31 09:50 79488 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-31 03:26 . 2007-06-23 12:30 -------- d-----w- c:\program files\Windows Live Safety Center
2009-12-28 23:21 . 2007-05-24 06:01 -------- d-----w- c:\documents and settings\Owner\Application Data\Move Networks
2009-12-26 03:36 . 2009-12-26 03:36 143976 ----a-w- c:\documents and settings\Owner\Application Data\Move Networks\uninstall.exe
2009-12-26 03:36 . 2009-10-15 00:50 5642688 ----a-w- c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071701000002.dll
2009-12-26 03:36 . 2009-12-26 03:35 1794456 ----a-w- c:\documents and settings\Owner\Application Data\Move Networks\MoveMediaPlayerWin_071701000002.exe
2009-12-18 03:38 . 2009-12-31 00:40 38784 ----a-w- c:\documents and settings\Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-14 06:25 . 2009-12-14 06:25 117760 ----a-w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-11 22:04 . 2007-05-18 10:57 -------- d-----w- c:\program files\SuperBot
2009-12-09 01:42 . 2009-11-11 22:45 -------- d-----w- c:\program files\Celtx
2009-12-09 01:10 . 2007-05-18 12:03 -------- d-----w- c:\program files\Common Files\Stardock
2009-12-09 01:09 . 2008-03-10 02:59 -------- d-----w- c:\documents and settings\Owner\Application Data\SlimBrowser
2009-12-07 14:10 . 2010-01-04 07:16 2953352 -c--a-w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
2009-11-25 11:01 . 2009-11-25 11:01 -------- d-----w- c:\program files\MSXML 4.0
2009-11-25 10:29 . 2006-05-22 21:34 -------- d-----w- c:\program files\Google
2009-11-25 10:21 . 2007-08-03 11:31 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-11-25 10:14 . 2008-01-23 09:47 -------- d-----w- c:\program files\Common Files\Nero
2009-11-25 10:13 . 2008-01-23 09:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-11-23 23:00 . 2008-01-23 10:01 -------- d-----w- c:\documents and settings\Owner\Application Data\OpenOffice.org2
2009-11-23 12:43 . 2009-10-06 09:49 -------- d-----w- c:\program files\Protection Sys
2009-11-19 08:46 . 2009-11-19 08:46 -------- d-----w- c:\program files\Xmarks
2009-11-18 11:27 . 2007-05-20 08:49 17920 -c--a-w- c:\windows\system32\rpcnetp.dll
2009-11-15 15:13 . 2009-11-15 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-13 12:01 . 2009-11-13 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-11-12 11:15 . 2009-11-12 11:13 -------- d-----w- c:\documents and settings\Owner\Application Data\Download Manager
2009-11-12 10:53 . 2009-11-12 10:53 -------- d-----w- c:\documents and settings\Owner\Application Data\GARMIN
2009-11-12 10:37 . 2009-11-12 10:37 -------- d-----w- c:\program files\DIFX
2009-11-12 10:37 . 2009-11-12 10:37 -------- d-----w- c:\program files\Garmin
2009-11-11 22:47 . 2009-11-11 22:47 -------- d-----w- c:\documents and settings\Owner\Application Data\Greyfirst
2009-11-03 04:42 . 2009-10-02 23:50 195456 -c----w- c:\windows\system32\MpSigStub.exe
2009-10-30 07:50 . 2009-10-30 07:50 93360 -c--a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-29 07:45 . 2006-05-22 17:25 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-22 04:53 . 2007-10-15 05:43 664 -c--a-w- c:\windows\system32\d3d9caps.dat
2009-10-21 16:45 . 2008-01-22 01:43 33792 ----a-w- c:\windows\system32\identprv.dll
2009-10-21 05:38 . 2006-05-22 17:25 75776 -c--a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-05-22 17:21 25088 -c--a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-03 23:00 265728 -c--a-w- c:\windows\system32\drivers\http.sys
2009-10-16 23:50 . 2009-11-13 12:09 2520888 -c--a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\t44mhm3e.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
2009-10-15 00:50 . 2009-10-15 00:50 97216 ----a-w- c:\documents and settings\Owner\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-10-13 10:30 . 2006-05-22 17:23 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-05-22 17:24 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-05-22 17:24 79872 ----a-w- c:\windows\system32\raschap.dll
2009-01-27 01:34 . 2009-01-27 01:34 1044480 -c--a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 -c--a-w- c:\program files\opera\program\plugins\ssldivx.dll
.
------- Sigcheck -------
[-] 2008-04-14 . 561A50497324F378E30F55D09B4E1258 . 975872 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . 561A50497324F378E30F55D09B4E1258 . 975872 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2007-11-24 22:08 . 2519DF50405AFCDE47302C80708C6AFC . 1478612 . . [1.0.0.0] . . c:\windows\system32\updater\explorer.exe
[-] 2007-07-01 . 46057846DDF9CF274A40FCD72F162105 . 974336 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
[-] 2007-06-13 . 7712DF0CDDE3A5AC89843E61CD5B3658 . 1033216 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-13 . 97BD6515465659FF8F3B7BE375B2EA87 . 1033216 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupFaster"="c:\program files\Startup Faster 2004\StrpFstCfg.exe" [2007-01-22 1926624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 55808]
c:\documents and settings\Owner\Start Menu\Programs\Startup\StartupFaster
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-18 630784]
Shortcut to Homer.exe.lnk - c:\documents and settings\Owner\My Documents\Homer\Homer.exe [2007-2-10 290304]
StartupFaster.ini [2010-1-4 2754]
thoosje's sidebar.lnk - c:\program files\Thoosje Vista Sidebar v1.7.8\thoosje's sidebar.exe [2007-2-12 524288]
TransBar.lnk - c:\windows\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-6-1 65536]
UberIcon.lnk - c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-5-20 180224]
Y'z Shadow.lnk - c:\windows\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-20 155648]
c:\documents and settings\All Users\Start Menu\Programs\Startup\StartupFaster
LapNetWizard.exe [2008-5-31 970752]
StartupFaster.ini [2010-1-4 870]
twhirl.lnk - c:\program files\twhirl\twhirl.exe [2009-12-31 95232]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\c:\0autocheck autochk *\0OODBS\0pgdfgsvc C 1\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe"
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"NeroFilterCheck"=c:\program files\Common Files\Nero\Lib\NeroCheck.exe
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Netscape\\Netscape Browser\\netscape.exe"=
"c:\\Program Files\\mozilla.org\\SeaMonkey\\seamonkey.exe"=
"c:\\Program Files\\Babelgum\\babelgum.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/3/2010 11:18 PM 64288]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [12/31/2009 12:09 AM 28552]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [1/2/2010 2:02 AM 108289]
R2 CamthWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CamthWDM.sys [1/10/2007 9:39 PM 243584]
R2 FlashDrv;FlashDrv;c:\progra~1\Fujitsu\FlashAid\FlashDrv.sys [5/22/2006 1:33 PM 7196]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/2/2009 5:19 AM 1181328]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\drivers\fuj02e3.sys [5/22/2006 9:39 AM 4864]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 AntiVirUpgradeService;Avira Upgrade Service; [x]
S2 sbbotdi;sbbotdi; [x]
S3 ADVNTDRV;ADVNTDRV;c:\windows\system32\drivers\ADVNTDRV.SYS [11/18/1999 12:20 AM 3872]
S3 Aldebaran;Aldebaran - Storage Filter Drivers;\??\c:\windows\system32\Drivers\Aldebaran.sys --> c:\windows\system32\Drivers\Aldebaran.sys [?]
S3 camvid40;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [4/21/2008 8:40 PM 1239552]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [7/30/2007 1:21 PM 20856]
S3 QCAbsee;Logitech QuickCam Web (0801);c:\windows\system32\drivers\OVCA.sys [6/18/2007 10:18 PM 25088]
S3 RkPavproc1;RkPavproc1;\??\c:\windows\system32\drivers\RkPavproc1.sys --> c:\windows\system32\drivers\RkPavproc1.sys [?]
S3 SDTHOOK;SDTHOOK;c:\windows\system32\drivers\SDTHOOK.SYS [1/2/2008 3:35 AM 44928]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [11/22/2007 12:21 PM 223128]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/22/2007 12:14 PM 642560]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" --> c:\program files\Viewpoint\Common\ViewpointService.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]
2004-08-04 12:00 11776 -c--a-w- c:\program files\Windows Sidebar\regsvr32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]
2004-08-04 12:00 11776 -c--a-w- c:\program files\Windows Sidebar\regsvr32.exe
.
Contents of the 'Scheduled Tasks' folder
2010-01-05 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 07:17]
2010-01-05 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 07:17]
2010-01-05 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 07:17]
2010-01-05 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 07:17]
2010-01-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 07:17]
2010-01-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
2010-01-04 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\schedule.exe [2007-11-09 06:05]
2010-01-05 c:\windows\Tasks\User_Feed_Synchronization-{63EBB53A-2CF2-45E1-9009-640B0132E94C}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.spywareinfoforum.com/index.php?showtopic=127008&st=0&p=711059&fromsearch=1?#entry711059
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\t44mhm3e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\t44mhm3e.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\Owner\Local Settings\Application Data\HuluDesktop\instances\0.9.10.1\nphdplg.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbabelgum.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
Notify-!SASWinLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-04 18:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ImagePath"="\??\c:\windows\system32\drivers\rootrepeal
[1].sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rootrepeal[1]]
"ImagePath"="\??\c:\windows\system32\drivers\rootrepeal
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1080236475-3595978650-3415084167-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FFD8A042-8A64-5DF2-A697-CD4EE07F667F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oaccbokccmlhfdfegpjbhihndlhkaf"=hex:6a,61,62,64,64,63,6b,65,65,70,65,6c,66,6e,
6f,6d,65,67,6e,6c,00,ba
"naiblmimachfpedhjlfnhkbdcfgk"=hex:6a,61,68,64,63,70,6e,69,66,65,69,6f,65,6b,
6c,68,6a,6c,66,6b,00,ba
[HKEY_USERS\S-1-5-21-1080236475-3595978650-3415084167-1003\Software\YourCompanyName\YourProductName\Version*]
"VersionData"=hex:e2,c9,d3,19,1d,de,68,b5,98,11,33,59,b6,5c,9c,45,bd,72,d7,a4,
c2,d1,f0,52,76,95,6d,e4,ec,0e,aa,81,94,5d,1d,35,03,d1,54,4f,a1,41,7b,dc,f2,\
[HKEY_LOCAL_MACHINE\software\Adobe\Premiere Pro\2.0\DefaultPreset]
@DACL=(02 0000)
@="DV - NTSC\\Standard 48kHz.prpreset"
[HKEY_LOCAL_MACHINE\software\Adobe\Premiere Pro\2.0\Help]
@DACL=(02 0000)
"Support"="
http://www.adobe.com.../premiere.html"
"Registration"="\"
http://store.adobe.com/cgi-bin/WebObjects/WEC?pageID=RegMp1\""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="720155804B0D0FE02814DC31D814A8D42B8C0F5D5C214AF1BB4EDF4913446A62B7337204F4ADAA1D25E406122855711B92C7B92BC5A4531EC1799B0BEEC2470B265209CD325C34C82C09DE5E3E924640DAD87BF965621A5A41BA0EB4F3AC311BAA35B7A1D5C83FC6B6B0F97E8A243E192D657B6EE5795B8BAC55144D288CAA2AA9D6308AE38335FBB62F009B2EC5487BA5BAF676A56EAB18EFAC9F21C84E0E4EF6533AD4940451528CF8AAA3FE1626C2D2C7BD3EB8A871EBE6C836C143C504A65DEEAE90D325263890AB4A480618EDCBB92234BB6576E7F6E2D86F023DFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667A6171C11EC38DE3D5D575E7D6A3B98088EDD5E5BE2F6E667CA82E73E5B4BE94AA8A07B68961DC591308F4D1916F79C7D2478FE920B44B91A0859FE447D79082A0EB210B103729E781CF65E2F8E0AE1805D5D2770448CAD5C64F26EE4EAF996105F86C5E05F96B89CD75E22202448956008C3440BFAC800503BDC2DDA1028A0F9C14E257FAE1AFE58F13B515F1519A2F8BC876064C6543F6E4DF7B4D67CF2F51B3F9238099B22233BDBDA2958C2F6BB53F35A8774E09F3C5F3CFB04FBE4DFA8D7C02C107073E817096A5B6AE833F055328D404C24A92C0E8090709FE320078FCC19CBBF1AA43A95385633D86210A8A909CA11C45422928FE234B48B99AA94C6C8FCF2DFDD467819F63E28BC0C28543481D27B0BD872FDDCCB78F8531E25492E4C84F70A8A919862222356E31F6DBE37762F00BAF5E6AD5AB50F458663D178E68F2A876161622474CEE92E1F4A744537FA4F71F7696C742DCD117136D2998A59FBD01E8594B8B71943DDF2422EF85A7E50857AE6609539BEF6F82C7AC9097D30B1BB9020CF3B84DBFBA93CA6E1560599718718B1FE1BF73EC3A5F6ED154E5E5B0293845D30B2D08CA8DFF6A8EF915F590A6F9984DB57401D80DBA82E7B3FD48CF26475EBC40BF5402CF6E0A8D44D96537A3DA41302483513A8C1E9DEB4D297BCC01FB000145560CE1EC68F8A8356EE6058D1B113F0918C18EFE2B7A5EAA3F1A6D7975BD116471153CA8D6AB8E1193D9DEA748E3C1A79946C392FE42E40F3C548DC86E91BB9B81F2EB0EBAB9FCAA7EB6CAECFD9CD67EBA910A0F9972747A607E5A488289C5D27B18483E8662E0B3779F155EF0B09B0F6C04BF17A49428943BD85BA1DB51A58B307BE2CECFA5B65237897C1CAE833C6CDE027AFCBC7B5817685F35DA903DBF2A2708744C4A29D8FE80E0A0F349017EC48A5F08EEE343E200F90BE7E77D92C6ADD52CF1CA2E9F2B22A75BA07E7F301D8DE3C3CF7C40519480221B9C5B0525CEEF028CB379B2FDC6EAD7D5EAB83D542B6B26A5F0B178409D36690FC0D67DCBE258DFCF3CD29A6DD"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3432)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\WININET.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\netshell.dll
c:\windows\system32\credui.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\rpcnet.exe
c:\windows\System32\snmp.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Avira\AntiVir Desktop\avgnt.exe
c:\windows\system32\rundll32.exe
c:\windows\System32\drivers\PhiBtn.exe
c:\windows\System32\drivers\Tray900.exe
c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
c:\program files\Apoint2K\Apoint.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Apoint2K\HidFind.exe
c:\program files\Apoint2K\Apntex.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
.
**************************************************************************
.
Completion time: 2010-01-04 18:26:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-05 02:26
Pre-Run: 6,822,232,064 bytes free
Post-Run: 6,785,654,784 bytes free
- - End Of File - - 0BBA041A6A5D93E4B558CCA4CCAD5BA4
Fresh HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:30:19 PM, on 1/4/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\rpcnet.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\drivers\PhiBtn.exe
C:\WINDOWS\System32\drivers\Tray900.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\notepad.exe
C:\HJT\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.spywarein...=1?#entry711059
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
N4 - Mozilla: # Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see
http://www.mozilla.o...zing.html#prefs
*/
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.download.dir", "C:\\Documents and Settings\\Owner\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CSeaMonkey%5Csearchplugins%5Cgoogle.src");
user_pref("browser.search.mode", 1);
user_pref("browser.search.opentabforcontextsearch", true);
user_pref("browser.startup.homepage", "
http://www.google.com");
user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1.16");
user_pref("browser.startup.page", 0);
user_pref("browser.tabs.autoHide", false);
user_pref("browser.tabs.loadGroup", 0);
user_pref("browser.tabs.open
N4 - Mozilla: # Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see
http://www.mozilla.o...zing.html#prefs
*/
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.download.dir", "C:\\Documents and Settings\\Owner\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5Cmozilla.org%5CSeaMonkey%5Csearchplugins%5Cgoogle.src");
user_pref("browser.search.mode", 1);
user_pref("browser.search.opentabforcontextsearch", true);
user_pref("browser.startup.homepage", "
http://www.google.com");
user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1.16");
user_pref("browser.startup.page", 0);
user_pref("browser.tabs.autoHide", false);
user_pref("browser.tabs.loadGroup", 0);
user_pref("browser.tabs.open
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [StartupFaster] "C:\Program Files\Startup Faster 2004\StrpFstCfg.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: StartupFaster
O4 - Global Startup: StartupFaster
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O9 - Extra 'Tools' menuitem: Xmarks for IE... - {638F11AA-DF27-433b-BA2E-7281CE561D71} - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.computers.us.fujitsu.com/
O16 - DPF: Garmin Communicator Plug-In -
https://my.garmin.co...inAxControl.CAB
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) -
http://download.sp.f.../fslauncher.cab
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) -
https://download.mac...director/sw.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitd...can8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onec...lscbase8942.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) -
http://upload.facebo...oUploader55.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.ad...Plus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\wbsys.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Upgrade Service (AntiVirUpgradeService) - Avira GmbH - (no file)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\WINDOWS\system32\rpcnet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 8998 bytes
Avira Anti Virus icon has reappeared now.
Running Malwarebytes immediately. And probably will try Spybot S&D soon, let me know if you would like to see those logs also.
6:35 PM 1/4/2010
C:\WINDOWS\system32\krl32mainweq.dll (Trojan.DNSChanger) -> Quarantined and deleted successfully.
7:07 PM 1/4/2010
Spybot came back good, just cookies.
Doing a Trend Micro scan now and will rerun Malware Bytes again after.
Still same problems with Chkdsk.
7:13 PM 1/4/2010
No Threats found on Housecall Quick scan, do you recommend I do a full scan now?
7:20 PM 1/4/2010
Malware Bytes Quick scan came back good too. Suggest a Full Scan?
Attempting reboot now for try at Chkdsk on restart.
7:27 PM 1/4/2010
No success on Chkdsk run on restart.
Also looks like my hosts files were wiped out and there wasn't any protection after the Combofix run. Seemed to reset a lot of my Start menu settings.
We shall see it that's the last of it. It was particularly nasty in moving from directory to directory like that trying to hide itself.
Also wondering if there is a safe hostfiles list to block bad sites you know of?
Edited by D_T, 05 January 2010 - 12:57 AM.