Jump to content

Redirect problem


Recommended Posts

Hello

I've been infected with a redirect malware. IE searches are redirected to different sites. I've run mbam and removed several issues, but the redirect remains. I've also run Superantispyware. That removed a few things also. Another artifact is that the DHCP client service doesn't always start automatically. I have to reboot about three times, then start it manually.

Need help.

Thanks.

Link to post
Share on other sites

Hello dna! Welcome to MalwareBytes' Anti-Malware Forums!

My name is Borislav and I will be glad to help you solve your problems with malware. Before we begin, please note the following:

  • The process of cleaning your system may take some time, so please be patient.
  • Stay with the topic until I tell you that your system is clean. Missing symptoms does not mean that everything is okay.
  • Instructions that I give are for your system only!
  • If you don't know or can't understand something please ask.
  • Do not install or uninstall any software or hardware, while work on.

Please follow these instructions:

http://forums.malwarebytes.org/index.php?showtopic=9573

Post all logs if you can.

Link to post
Share on other sites

ok. Here's the dds log. I had a blue screen crash after running GMER while trying to zip the attach.txt file and ark.txt.

DDS (Ver_10-03-17.01) - NTFSx86

Run by David Nakaki at 14:44:47.78 on Mon 05/31/2010

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.2414 [GMT -7:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\AskBarDis\bar\bin\AskService.exe

C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe

C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Google\Update\GoogleUpdate.exe

c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe

C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe

c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe

C:\Program Files\McAfee\MPF\MPFSrv.exe

C:\Program Files\McAfee\MSK\MskSrver.exe

C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe

C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

C:\Program Files\Dell Support Center\bin\sprtsvc.exe

C:\WINDOWS\system32\svchost.exe -k netsvcs

c:\PROGRA~1\mcafee.com\agent\mcagent.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\WINDOWS\system32\SearchIndexer.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\nvraidservice.exe

C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe

C:\Program Files\Dell Video Chat\DellVideoChat.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wbem\unsecapp.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe

C:\Documents and Settings\David Nakaki\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/

uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us

uDefault_Page_URL = hxxp://www.msn.com

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uWindow Title = Internet Explorer, optimized for Bing and MSN

mSearch Bar = hxxp://www.google.com/ie

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

mSearchAssistant = hxxp://www.google.com/ie

uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll

BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Download Manager Browser Helper Object: {19c8e43b-07b3-49cb-bffc-6777b593e6f8} - c:\progra~1\common~1\fluxdvd\downlo~1\XEBDLH~1.DLL

BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll

BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll

BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll

BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll

BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll

BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll

BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll

BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll

BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll

TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll

TB: @c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll

TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

uRun: [NVIDIA nTune] c:\program files\nvidia corporation\ntune\nTuneCmd.exe resetprofile

uRun: [sightSpeed] "c:\program files\dell video chat\DellVideoChat.exe" -bootmode

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

uRun: [sUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [Alcmtr] ALCMTR.EXE

mRun: [NVRaidService] c:\windows\system32\nvraidservice.exe

mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"

mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup

mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey

mRun: [Dell DataSafe Online] "c:\program files\dell datasafe online\DataSafeOnline.exe" /m

mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter

mRun: [CinemaNowMediaManagerApp]

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [bing Bar] "c:\program files\msn toolbar\platform\5.0.1449.0\mswinext.exe"

mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume

dRun: [bjgnmrsr] c:\documents and settings\networkservice\local settings\application data\aqeoglvip\ifmkcmytssd.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL

Trusted Zone: cinemanow.com

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll

Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll

Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL

Notify: AtiExtEvent - Ati2evxx.dll

Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-16 214664]

R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]

R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]

R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-3-8 464264]

R2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-3-8 234888]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\mcsacore.exe [2010-5-24 93320]

R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-1-16 359952]

R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-1-16 144704]

R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-1-16 606736]

R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-1-16 79816]

R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-1-16 35272]

R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-1-16 40552]

S2 gupdate1ca7f273eefbc52;Google Update Service (gupdate1ca7f273eefbc52);c:\program files\google\update\GoogleUpdate.exe [2009-12-17 133104]

S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-1-16 30192]

S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-1-16 34248]

=============== Created Last 30 ================

2010-05-31 21:35:19 0 ----a-w- c:\documents and settings\david nakaki\defogger_reenable

2010-05-29 07:10:53 0 d-----w- c:\docume~1\davidn~1\applic~1\SUPERAntiSpyware.com

2010-05-29 07:10:53 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com

2010-05-29 07:10:48 0 d-----w- c:\program files\SUPERAntiSpyware

2010-05-27 05:31:15 0 d-----w- c:\program files\CCleaner

2010-05-25 06:35:50 0 d-----w- c:\program files\Yahoo!

2010-05-25 04:47:34 0 d-----w- c:\program files\Support Tools

2010-05-24 01:16:12 5815 ----a-w- c:\windows\system32\nvnrm.nvu

2010-05-24 01:16:12 3636 ----a-w- c:\windows\system32\drivers\nvphy.bin

2010-05-24 01:16:12 356352 ----a-w- c:\windows\system32\nvunrm.exe

2010-05-24 01:04:46 0 d-----w- C:\NV37803716.TMP

2010-05-24 01:04:46 0 d-----w- C:\NV1100284.TMP

2010-05-24 00:51:44 0 d-----w- C:\NV33242512.TMP

2010-05-24 00:51:44 0 d-----w- C:\NV30361528.TMP

2010-05-24 00:34:12 0 d-----w- C:\NV6241616.TMP

2010-05-24 00:34:12 0 d-----w- C:\NV4363192.TMP

2010-05-23 23:42:56 0 d-----w- c:\windows\system32\vmm32

2010-05-23 16:43:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-05-23 16:43:52 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-05-23 16:43:52 0 d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-05-23 14:44:13 0 d-----w- c:\windows\system32\wbem\Repository

2010-05-22 21:00:39 0 d-----w- c:\docume~1\davidn~1\applic~1\Malwarebytes

2010-05-22 21:00:23 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-05-22 14:28:25 0 d-----w- c:\docume~1\alluse~1\applic~1\DivX

2010-05-21 07:24:50 0 d-sh--w- c:\documents and settings\david nakaki\IECompatCache

2010-05-21 07:24:10 0 d-sh--w- c:\documents and settings\david nakaki\PrivacIE

2010-05-21 07:19:55 0 d-sh--w- c:\documents and settings\david nakaki\IETldCache

2010-05-21 07:17:29 0 dc-h--w- c:\windows\ie8

2010-05-21 07:17:05 0 d-----w- c:\program files\Microsoft

2010-05-21 07:17:03 0 d-----w- c:\program files\MSN Toolbar

2010-05-21 07:16:41 0 d-----w- c:\program files\Bing Bar Installer

2010-05-21 07:16:25 0 d--h--w- c:\windows\msdownld.tmp

2010-05-17 08:44:31 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-05-04 13:32:18 0 d-----w- c:\program files\iPod

2010-05-04 13:32:13 0 d-----w- c:\program files\iTunes

2010-05-04 13:29:05 0 d-----w- c:\program files\Bonjour

==================== Find3M ====================

2010-04-08 20:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-04-08 20:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe

2010-03-31 01:58:04 133616 ------w- c:\windows\system32\PxAFS.DLL

2010-03-31 01:58:04 125424 ------w- c:\windows\system32\pxinsi64.exe

2010-03-08 17:59:18 94208 ----a-w- c:\windows\system32\dpl100.dll

============= FINISH: 14:46:08.59 ===============

attach.zip

Link to post
Share on other sites

Step 1

STEP 01

Please go into the Control Panel, Add/Remove and for now remove ALL versions of JAVA

Then run this tool to help cleanup any left over Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please download JavaRa and unzip it to your desktop.

***Please close any instances of Internet Explorer (or other web browser) before continuing!***

  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location and post it back when you reply
    Then look for the following Java folders and if found delete them.
    C:\Program Files\Java
    C:\Program Files\Common Files\Java
    C:\Windows\Sun
    C:\Documents and Settings\All Users\Application Data\Java
    C:\Documents and Settings\All Users\Application Data\Sun\Java
    C:\Documents and Settings\username\Application Data\Java
    C:\Documents and Settings\username\Application Data\Sun\Java

Step 2

  • Launch Malwarebytes' Anti-Malware
  • Go to "Update" tab and select "Check for Updates". If an update is found, it will download and install the latest version.
  • Go to "Scanner" tab and select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

In your next reply, please include these log(s) in this sequence:

  1. JavaRa log
  2. MalwareBytes' Anti-Malware log

Link to post
Share on other sites

Here are the log files

JavaRa 1.15 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Tue Jun 01 06:59:24 2010

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007

------------------------------------

Finished reporting.

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4161

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

6/1/2010 7:12:39 AM

mbam-log-2010-06-01 (07-12-39).txt

Scan type: Quick scan

Objects scanned: 134854

Time elapsed: 5 minute(s), 16 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

**Note: If you need more detailed information, please visit the web page of ComboFix in BleepingComputer. **

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Stay with me until given the 'all clear' even if symptoms diminish. Lack of symptoms does not always mean the job is complete.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by me or another helper.

Please download ComboFix from

Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  1. If you are using Firefox, make sure that your download settings are as follows:
    • Open Tools -> Options -> Main tab
    • Set to Always ask me where to Save the files.

[*]During the download, rename Combofix to Combo-Fix as follows:

CF_download_FF.gif

CF_download_rename.gif

[*]It is important you rename Combofix during the download, but not after.

[*]Please do not rename Combofix to other names, but only to the one indicated.

[*]Close any open browsers.

[*]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

-----------------------------------------------------------

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause unpredictable results.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    -----------------------------------------------------------


  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

-----------------------------------------------------------

[*]Double click on combo-Fix.exe & follow the prompts.

[*]When finished, it will produce a report for you.

[*]Please post the C:\Combo-Fix.txt for further review.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

Link to post
Share on other sites

Here's the ComboFix log

ComboFix 10-06-01.01 - David Nakaki 06/02/2010 6:31.1.4 - x86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.2929 [GMT -7:00]

Running from: c:\documents and settings\David Nakaki\Desktop\Combo-Fix.exe

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

.

((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 )))))))))))))))))))))))))))))))

.

2010-05-31 16:08 . 2008-04-14 12:00 185344 -c--a-w- c:\windows\system32\dllcache\thawbrkr.dll

2010-05-31 16:08 . 2008-04-14 12:00 185344 ----a-w- c:\windows\system32\Thawbrkr.dll

2010-05-31 16:08 . 2008-04-14 12:00 10752 -c--a-w- c:\windows\system32\dllcache\c_iscii.dll

2010-05-31 16:08 . 2008-04-14 12:00 10752 ----a-w- c:\windows\system32\c_iscii.dll

2010-05-31 16:08 . 2008-04-14 12:00 5632 -c--a-w- c:\windows\system32\dllcache\kbdusa.dll

2010-05-31 16:08 . 2008-04-14 12:00 5632 ----a-w- c:\windows\system32\kbdusa.dll

2010-05-31 16:08 . 2008-04-14 12:00 6144 -c--a-w- c:\windows\system32\dllcache\ftlx041e.dll

2010-05-31 16:08 . 2008-04-14 12:00 6144 ----a-w- c:\windows\system32\ftlx041e.dll

2010-05-31 16:08 . 2008-04-14 12:00 19456 -c--a-w- c:\windows\system32\dllcache\agt0401.dll

2010-05-31 16:08 . 2008-04-14 12:00 19456 -c--a-w- c:\windows\system32\dllcache\agt040d.dll

2010-05-29 07:11 . 2010-05-31 15:52 63488 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll

2010-05-29 07:11 . 2010-05-29 07:11 52224 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

2010-05-29 07:11 . 2010-05-31 15:51 117760 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\program files\SUPERAntiSpyware

2010-05-29 06:53 . 2010-05-29 06:53 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

2010-05-27 05:31 . 2010-05-27 05:31 -------- d-----w- c:\program files\CCleaner

2010-05-25 06:35 . 2010-05-25 06:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion

2010-05-25 06:35 . 2010-05-25 06:35 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Yahoo!

2010-05-25 06:35 . 2010-05-25 06:35 -------- d-----w- c:\program files\Yahoo!

2010-05-25 04:47 . 2010-05-25 04:47 -------- d-----w- c:\program files\Support Tools

2010-05-24 01:16 . 2008-01-15 03:20 3636 ----a-w- c:\windows\system32\drivers\nvphy.bin

2010-05-24 01:16 . 2008-01-15 03:20 356352 ----a-w- c:\windows\system32\nvunrm.exe

2010-05-24 01:04 . 2010-05-24 01:04 -------- d-----w- C:\NV37803716.TMP

2010-05-24 01:04 . 2010-05-24 01:04 -------- d-----w- C:\NV1100284.TMP

2010-05-24 00:51 . 2010-05-24 00:51 -------- d-----w- C:\NV33242512.TMP

2010-05-24 00:51 . 2010-05-24 00:51 -------- d-----w- C:\NV30361528.TMP

2010-05-24 00:34 . 2010-05-24 00:34 -------- d-----w- C:\NV6241616.TMP

2010-05-24 00:34 . 2010-05-24 00:34 -------- d-----w- C:\NV4363192.TMP

2010-05-23 23:42 . 2010-05-23 23:42 45056 ----a-r- c:\documents and settings\David Nakaki\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe

2010-05-23 23:42 . 2010-05-23 23:42 10134 ----a-r- c:\documents and settings\David Nakaki\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe

2010-05-23 23:42 . 2010-05-23 23:42 -------- d-----w- c:\windows\system32\vmm32

2010-05-23 16:43 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-05-23 16:43 . 2010-05-23 16:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-05-23 16:43 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-05-23 14:44 . 2010-05-23 14:44 -------- d-----w- c:\windows\system32\wbem\Repository

2010-05-22 21:00 . 2010-05-22 21:00 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Malwarebytes

2010-05-22 21:00 . 2010-05-22 21:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-05-22 14:31 . 2010-05-22 14:31 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll

2010-05-22 14:29 . 2010-05-22 14:29 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe

2010-05-22 14:28 . 2010-05-22 14:28 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe

2010-05-22 14:28 . 2010-05-22 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX

2010-05-21 07:24 . 2010-05-21 07:24 -------- d-sh--w- c:\documents and settings\David Nakaki\IECompatCache

2010-05-21 07:24 . 2010-05-21 07:24 -------- d-sh--w- c:\documents and settings\David Nakaki\PrivacIE

2010-05-21 07:23 . 2010-05-21 07:23 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-05-21 07:19 . 2010-05-21 07:19 -------- d-sh--w- c:\documents and settings\David Nakaki\IETldCache

2010-05-21 07:17 . 2010-05-21 07:17 -------- dc-h--w- c:\windows\ie8

2010-05-21 07:17 . 2010-05-21 07:17 -------- d-----w- c:\program files\Microsoft

2010-05-21 07:17 . 2010-05-21 07:17 -------- d-----w- c:\program files\MSN Toolbar

2010-05-21 07:16 . 2010-05-21 07:17 -------- d-----w- c:\program files\Bing Bar Installer

2010-05-21 07:16 . 2010-05-21 07:18 -------- d--h--w- c:\windows\msdownld.tmp

2010-05-21 06:07 . 2010-05-21 06:07 -------- d-----w- c:\documents and settings\David Nakaki\Local Settings\Application Data\tfoscaifg

2010-05-19 08:17 . 2010-05-19 08:17 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\aqeoglvip

2010-05-17 08:44 . 2010-05-17 08:44 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-05-07 04:39 . 2010-05-07 04:39 -------- d-----w- c:\program files\Microsoft Silverlight

2010-05-04 13:32 . 2010-05-04 13:32 -------- d-----w- c:\program files\iPod

2010-05-04 13:32 . 2010-05-04 13:32 -------- d-----w- c:\program files\iTunes

2010-05-04 13:29 . 2010-05-04 13:29 -------- d-----w- c:\program files\Bonjour

2010-05-04 13:27 . 2010-05-04 13:27 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-05-31 21:38 . 2009-01-16 22:31 -------- d-----w- c:\program files\McAfee

2010-05-27 06:06 . 2009-03-08 16:40 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Azureus

2010-05-25 06:36 . 2009-01-16 22:30 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee

2010-05-23 23:42 . 2009-01-16 22:30 -------- d-----w- c:\program files\Dell

2010-05-22 14:31 . 2010-02-07 22:59 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\DivX

2010-05-22 14:29 . 2009-12-17 14:43 -------- d-----w- c:\program files\Common Files\DivX Shared

2010-05-22 14:28 . 2010-05-22 14:30 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll

2010-05-22 14:28 . 2010-05-22 14:30 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe

2010-05-19 05:24 . 2009-03-08 19:28 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Apple Computer

2010-05-12 13:30 . 2009-01-16 22:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-05-04 13:32 . 2009-03-08 19:27 -------- d-----w- c:\program files\Common Files\Apple

2010-04-14 20:19 . 2010-04-14 20:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7602.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-13 21:19 . 2010-04-13 21:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7599.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-12 22:19 . 2010-04-12 22:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7595.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-11 23:19 . 2010-04-11 23:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7592.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-11 00:19 . 2010-04-11 00:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7589.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-10 01:20 . 2010-04-10 01:20 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7586.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-08 20:20 . 2010-04-08 20:20 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-04-08 20:20 . 2010-04-08 20:20 107808 ----a-w- c:\windows\system32\dns-sd.exe

2010-04-06 05:16 . 2010-02-02 14:27 -------- d-----w- c:\program files\QuickTime

2010-04-06 04:38 . 2010-04-06 04:38 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-03-31 01:58 . 2007-12-11 01:37 133616 ------w- c:\windows\system32\PxAFS.DLL

2010-03-31 01:58 . 2007-11-14 20:08 125424 ------w- c:\windows\system32\pxinsi64.exe

2010-03-31 01:58 . 2007-11-14 09:00 44944 ------w- c:\windows\system32\drivers\pxhelp20.sys

2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]

2008-12-10 01:40 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-10 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-10 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-01-15 106496]

"SightSpeed"="c:\program files\Dell Video Chat\DellVideoChat.exe" [2008-08-15 4812664]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-16 39408]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-05-18 2397424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2008-01-15 16855552]

"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-08-19 203296]

"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-10-27 30192]

"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]

"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2008-11-03 1745648]

"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 243544]

"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-12 288088]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]

2009-01-16 22:34 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Vuze\\Azureus.exe"=

"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=

"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Dell Video Chat\\DellVideoChat.exe"=

S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]

S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 AM 67656]

S2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [3/8/2009 9:40 AM 464264]

S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [3/8/2009 9:40 AM 234888]

S2 gupdate1ca7f273eefbc52;Google Update Service (gupdate1ca7f273eefbc52);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 7:43 AM 133104]

S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [5/24/2010 11:36 PM 93320]

S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/16/2009 3:30 PM 30192]

.

Contents of the 'Scheduled Tasks' folder

2010-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 14:43]

2010-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 14:43]

2010-05-15 c:\windows\Tasks\McDefragTask.job

- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-16 19:22]

2010-05-01 c:\windows\Tasks\McQcTask.job

- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-16 19:22]

2010-05-29 c:\windows\Tasks\OGALogon.job

- c:\windows\system32\OGAEXEC.exe [2009-08-03 23:07]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

mSearch Bar = hxxp://www.google.com/ie

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html

Trusted Zone: cinemanow.com

.

- - - - ORPHANS REMOVED - - - -

HKLM-Run-CinemaNowMediaManagerApp - (no file)

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-06-02 06:35

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(224)

c:\program files\SUPERAntiSpyware\SASWINLO.DLL

c:\windows\system32\Ati2evxx.dll

c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll

.

Completion time: 2010-06-02 06:36:50

ComboFix-quarantined-files.txt 2010-06-02 13:36

Pre-Run: 432,028,839,936 bytes free

Post-Run: 432,165,928,960 bytes free

- - End Of File - - 2321E56FA277B4E71524AC445982CBF7

Link to post
Share on other sites

Open Notepad and copy and paste the text in the code box below into it:

DirLook::
c:\documents and settings\David Nakaki\Local Settings\Application Data\tfoscaifg
c:\documents and settings\NetworkService\Local Settings\Application Data\aqeoglvip

Save the file to your desktop and name it CFScript.txt

Then drag the CFScript.txt into the ComboFix.exe as shown in the screenshot below.

CFScriptB-4.gif

This will start ComboFix again. It may ask to reboot. Post the contents of Combofix.txt in your next reply.

Note: These instructions and script were created specifically for this user. If you are not this user, do NOT follow these instructions or use this script as it could damage the workings of your system.

Link to post
Share on other sites

Here's the latest ComboFix log.

ComboFix 10-06-01.03 - David Nakaki 06/02/2010 7:45.2.4 - x86 MINIMAL

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.3036 [GMT -7:00]

Running from: c:\documents and settings\David Nakaki\Desktop\Combo-Fix.exe

Command switches used :: c:\documents and settings\David Nakaki\Desktop\CFScript.txt

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

.

((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 )))))))))))))))))))))))))))))))

.

2010-05-31 16:08 . 2008-04-14 12:00 185344 -c--a-w- c:\windows\system32\dllcache\thawbrkr.dll

2010-05-31 16:08 . 2008-04-14 12:00 185344 ----a-w- c:\windows\system32\Thawbrkr.dll

2010-05-31 16:08 . 2008-04-14 12:00 10752 -c--a-w- c:\windows\system32\dllcache\c_iscii.dll

2010-05-31 16:08 . 2008-04-14 12:00 10752 ----a-w- c:\windows\system32\c_iscii.dll

2010-05-31 16:08 . 2008-04-14 12:00 5632 -c--a-w- c:\windows\system32\dllcache\kbdusa.dll

2010-05-31 16:08 . 2008-04-14 12:00 5632 ----a-w- c:\windows\system32\kbdusa.dll

2010-05-31 16:08 . 2008-04-14 12:00 6144 -c--a-w- c:\windows\system32\dllcache\ftlx041e.dll

2010-05-31 16:08 . 2008-04-14 12:00 6144 ----a-w- c:\windows\system32\ftlx041e.dll

2010-05-31 16:08 . 2008-04-14 12:00 19456 -c--a-w- c:\windows\system32\dllcache\agt0401.dll

2010-05-31 16:08 . 2008-04-14 12:00 19456 -c--a-w- c:\windows\system32\dllcache\agt040d.dll

2010-05-29 07:11 . 2010-05-31 15:52 63488 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll

2010-05-29 07:11 . 2010-05-29 07:11 52224 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

2010-05-29 07:11 . 2010-05-31 15:51 117760 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\program files\SUPERAntiSpyware

2010-05-29 06:53 . 2010-05-29 06:53 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

2010-05-27 05:31 . 2010-05-27 05:31 -------- d-----w- c:\program files\CCleaner

2010-05-25 06:35 . 2010-05-25 06:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion

2010-05-25 06:35 . 2010-05-25 06:35 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Yahoo!

2010-05-25 06:35 . 2010-05-25 06:35 -------- d-----w- c:\program files\Yahoo!

2010-05-25 04:47 . 2010-05-25 04:47 -------- d-----w- c:\program files\Support Tools

2010-05-24 01:16 . 2008-01-15 03:20 3636 ----a-w- c:\windows\system32\drivers\nvphy.bin

2010-05-24 01:16 . 2008-01-15 03:20 356352 ----a-w- c:\windows\system32\nvunrm.exe

2010-05-24 01:04 . 2010-05-24 01:04 -------- d-----w- C:\NV37803716.TMP

2010-05-24 01:04 . 2010-05-24 01:04 -------- d-----w- C:\NV1100284.TMP

2010-05-24 00:51 . 2010-05-24 00:51 -------- d-----w- C:\NV33242512.TMP

2010-05-24 00:51 . 2010-05-24 00:51 -------- d-----w- C:\NV30361528.TMP

2010-05-24 00:34 . 2010-05-24 00:34 -------- d-----w- C:\NV6241616.TMP

2010-05-24 00:34 . 2010-05-24 00:34 -------- d-----w- C:\NV4363192.TMP

2010-05-23 23:42 . 2010-05-23 23:42 45056 ----a-r- c:\documents and settings\David Nakaki\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe

2010-05-23 23:42 . 2010-05-23 23:42 10134 ----a-r- c:\documents and settings\David Nakaki\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe

2010-05-23 23:42 . 2010-05-23 23:42 -------- d-----w- c:\windows\system32\vmm32

2010-05-23 16:43 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-05-23 16:43 . 2010-05-23 16:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-05-23 16:43 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-05-23 14:44 . 2010-05-23 14:44 -------- d-----w- c:\windows\system32\wbem\Repository

2010-05-22 21:00 . 2010-05-22 21:00 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Malwarebytes

2010-05-22 21:00 . 2010-05-22 21:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-05-22 14:31 . 2010-05-22 14:31 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll

2010-05-22 14:29 . 2010-05-22 14:29 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe

2010-05-22 14:28 . 2010-05-22 14:28 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe

2010-05-22 14:28 . 2010-05-22 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX

2010-05-21 07:24 . 2010-05-21 07:24 -------- d-sh--w- c:\documents and settings\David Nakaki\IECompatCache

2010-05-21 07:24 . 2010-05-21 07:24 -------- d-sh--w- c:\documents and settings\David Nakaki\PrivacIE

2010-05-21 07:23 . 2010-05-21 07:23 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-05-21 07:19 . 2010-05-21 07:19 -------- d-sh--w- c:\documents and settings\David Nakaki\IETldCache

2010-05-21 07:17 . 2010-05-21 07:17 -------- dc-h--w- c:\windows\ie8

2010-05-21 07:17 . 2010-05-21 07:17 -------- d-----w- c:\program files\Microsoft

2010-05-21 07:17 . 2010-05-21 07:17 -------- d-----w- c:\program files\MSN Toolbar

2010-05-21 07:16 . 2010-05-21 07:17 -------- d-----w- c:\program files\Bing Bar Installer

2010-05-21 07:16 . 2010-05-21 07:18 -------- d--h--w- c:\windows\msdownld.tmp

2010-05-21 06:07 . 2010-05-21 06:07 -------- d-----w- c:\documents and settings\David Nakaki\Local Settings\Application Data\tfoscaifg

2010-05-19 08:17 . 2010-05-19 08:17 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\aqeoglvip

2010-05-17 08:44 . 2010-05-17 08:44 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-05-07 04:39 . 2010-05-07 04:39 -------- d-----w- c:\program files\Microsoft Silverlight

2010-05-04 13:32 . 2010-05-04 13:32 -------- d-----w- c:\program files\iPod

2010-05-04 13:32 . 2010-05-04 13:32 -------- d-----w- c:\program files\iTunes

2010-05-04 13:29 . 2010-05-04 13:29 -------- d-----w- c:\program files\Bonjour

2010-05-04 13:27 . 2010-05-04 13:27 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-05-31 21:38 . 2009-01-16 22:31 -------- d-----w- c:\program files\McAfee

2010-05-27 06:06 . 2009-03-08 16:40 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Azureus

2010-05-25 06:36 . 2009-01-16 22:30 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee

2010-05-23 23:42 . 2009-01-16 22:30 -------- d-----w- c:\program files\Dell

2010-05-22 14:31 . 2010-02-07 22:59 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\DivX

2010-05-22 14:29 . 2009-12-17 14:43 -------- d-----w- c:\program files\Common Files\DivX Shared

2010-05-22 14:28 . 2010-05-22 14:30 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll

2010-05-22 14:28 . 2010-05-22 14:30 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe

2010-05-19 05:24 . 2009-03-08 19:28 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Apple Computer

2010-05-12 13:30 . 2009-01-16 22:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-05-04 13:32 . 2009-03-08 19:27 -------- d-----w- c:\program files\Common Files\Apple

2010-04-14 20:19 . 2010-04-14 20:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7602.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-13 21:19 . 2010-04-13 21:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7599.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-12 22:19 . 2010-04-12 22:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7595.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-11 23:19 . 2010-04-11 23:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7592.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-11 00:19 . 2010-04-11 00:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7589.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-10 01:20 . 2010-04-10 01:20 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7586.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-08 20:20 . 2010-04-08 20:20 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-04-08 20:20 . 2010-04-08 20:20 107808 ----a-w- c:\windows\system32\dns-sd.exe

2010-04-06 05:16 . 2010-02-02 14:27 -------- d-----w- c:\program files\QuickTime

2010-04-06 04:38 . 2010-04-06 04:38 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-03-31 01:58 . 2007-12-11 01:37 133616 ------w- c:\windows\system32\PxAFS.DLL

2010-03-31 01:58 . 2007-11-14 20:08 125424 ------w- c:\windows\system32\pxinsi64.exe

2010-03-31 01:58 . 2007-11-14 09:00 44944 ------w- c:\windows\system32\drivers\pxhelp20.sys

2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll

.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

---- Directory of c:\documents and settings\David Nakaki\Local Settings\Application Data\tfoscaifg ----

---- Directory of c:\documents and settings\NetworkService\Local Settings\Application Data\aqeoglvip ----

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]

2008-12-10 01:40 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-10 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-10 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-01-15 106496]

"SightSpeed"="c:\program files\Dell Video Chat\DellVideoChat.exe" [2008-08-15 4812664]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-16 39408]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-05-18 2397424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2008-01-15 16855552]

"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-08-19 203296]

"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-10-27 30192]

"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]

"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2008-11-03 1745648]

"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 243544]

"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-12 288088]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]

2009-01-16 22:34 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Vuze\\Azureus.exe"=

"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=

"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Dell Video Chat\\DellVideoChat.exe"=

S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]

S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 AM 67656]

S2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [3/8/2009 9:40 AM 464264]

S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [3/8/2009 9:40 AM 234888]

S2 gupdate1ca7f273eefbc52;Google Update Service (gupdate1ca7f273eefbc52);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 7:43 AM 133104]

S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [5/24/2010 11:36 PM 93320]

S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/16/2009 3:30 PM 30192]

.

Contents of the 'Scheduled Tasks' folder

2010-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 14:43]

2010-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 14:43]

2010-05-15 c:\windows\Tasks\McDefragTask.job

- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-16 19:22]

2010-05-01 c:\windows\Tasks\McQcTask.job

- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-16 19:22]

2010-05-29 c:\windows\Tasks\OGALogon.job

- c:\windows\system32\OGAEXEC.exe [2009-08-03 23:07]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

mSearch Bar = hxxp://www.google.com/ie

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html

Trusted Zone: cinemanow.com

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-06-02 07:50

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(224)

c:\program files\SUPERAntiSpyware\SASWINLO.DLL

c:\windows\system32\Ati2evxx.dll

c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll

.

Completion time: 2010-06-02 07:51:01

ComboFix-quarantined-files.txt 2010-06-02 14:50

ComboFix2.txt 2010-06-02 13:36

Pre-Run: 432,147,607,552 bytes free

Post-Run: 432,117,362,688 bytes free

- - End Of File - - B7E16DD283B9325F44D8A1CF90C77CA6

Link to post
Share on other sites

Step 1

Please manually delete the following folders:

c:\documents and settings\David Nakaki\Local Settings\Application Data\tfoscaifg

c:\documents and settings\NetworkService\Local Settings\Application Data\aqeoglvip

Step 2

Please read the following through carefully so that you understand what to do.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
  • Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK. (If Vista, click on the Vista Orb and copy and paste the following into the Search field. (make sure you include the quotation marks) Then press Ctrl+Shift+Enter.)
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v
  • If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
  • It may ask you to reboot the computer to complete the process. Allow it to do so.
  • When it is done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents of that file here.

Link to post
Share on other sites

Here's the TDSSKiller text file

08:32:32:734 3308 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48

08:32:32:734 3308 ================================================================================

08:32:32:734 3308 SystemInfo:

08:32:32:734 3308 OS Version: 5.1.2600 ServicePack: 3.0

08:32:32:734 3308 Product type: Workstation

08:32:32:734 3308 ComputerName: D6NGWYH1

08:32:32:734 3308 UserName: David Nakaki

08:32:32:734 3308 Windows directory: C:\WINDOWS

08:32:32:734 3308 Processor architecture: Intel x86

08:32:32:734 3308 Number of processors: 4

08:32:32:734 3308 Page size: 0x1000

08:32:32:734 3308 Boot type: Normal boot

08:32:32:734 3308 ================================================================================

08:32:33:000 3308 Initialize success

08:32:33:000 3308

08:32:33:000 3308 Scanning Services ...

08:32:33:078 3308 Raw services enum returned 360 services

08:32:33:093 3308

08:32:33:093 3308 Scanning Drivers ...

08:32:33:375 3308 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS

08:32:33:406 3308 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys

08:32:33:406 3308 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys

08:32:33:437 3308 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys

08:32:33:484 3308 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys

08:32:33:515 3308 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys

08:32:33:515 3308 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys

08:32:33:531 3308 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys

08:32:33:531 3308 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys

08:32:33:546 3308 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys

08:32:33:546 3308 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys

08:32:33:562 3308 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys

08:32:33:578 3308 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys

08:32:33:593 3308 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys

08:32:33:593 3308 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys

08:32:33:625 3308 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys

08:32:33:625 3308 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys

08:32:33:640 3308 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys

08:32:33:656 3308 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys

08:32:33:687 3308 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys

08:32:33:734 3308 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys

08:32:33:812 3308 ati2mtag (32983412e7d9c783f7fdcfd5146784af) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys

08:32:33:875 3308 AtiHdmiService (41c8f0eda10da14378d304c20ba6e558) C:\WINDOWS\system32\drivers\AtiHdmi.sys

08:32:33:875 3308 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys

08:32:33:890 3308 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys

08:32:33:906 3308 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys

08:32:33:921 3308 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\WINDOWS\system32\drivers\BVRPMPR5.SYS

08:32:34:031 3308 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys

08:32:34:031 3308 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys

08:32:34:031 3308 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys

08:32:34:046 3308 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys

08:32:34:046 3308 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys

08:32:34:062 3308 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys

08:32:34:078 3308 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys

08:32:34:078 3308 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys

08:32:34:093 3308 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys

08:32:34:109 3308 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys

08:32:34:109 3308 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys

08:32:34:140 3308 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys

08:32:34:171 3308 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys

08:32:34:171 3308 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys

08:32:34:218 3308 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys

08:32:34:218 3308 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys

08:32:34:234 3308 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys

08:32:34:250 3308 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys

08:32:34:265 3308 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys

08:32:34:281 3308 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys

08:32:34:296 3308 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys

08:32:34:296 3308 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys

08:32:34:312 3308 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys

08:32:34:312 3308 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys

08:32:34:343 3308 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys

08:32:34:359 3308 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys

08:32:34:375 3308 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys

08:32:34:390 3308 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys

08:32:34:406 3308 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys

08:32:34:437 3308 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys

08:32:34:437 3308 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys

08:32:34:453 3308 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys

08:32:34:484 3308 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys

08:32:34:500 3308 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys

08:32:34:593 3308 IntcAzAudAddService (eb5608fd4f2961517ac9f5cac88b023b) C:\WINDOWS\system32\drivers\RtkHDAud.sys

08:32:34:625 3308 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys

08:32:34:640 3308 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys

08:32:34:656 3308 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys

08:32:34:671 3308 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys

08:32:34:671 3308 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys

08:32:34:703 3308 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys

08:32:34:703 3308 IPSec (a91f4e41a92132e57c0bcddc65df6411) C:\WINDOWS\system32\DRIVERS\ipsec.sys

08:32:34:703 3308 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ipsec.sys. Real md5: a91f4e41a92132e57c0bcddc65df6411, Fake md5: 23c74d75e36e7158768dd63d92789a91

08:32:34:703 3308 File "C:\WINDOWS\system32\DRIVERS\ipsec.sys" infected by TDSS rootkit ... 08:32:35:390 3308 Backup copy found, using it..

08:32:35:406 3308 will be cured on next reboot

08:32:35:500 3308 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys

08:32:35:531 3308 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys

08:32:35:546 3308 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys

08:32:35:546 3308 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys

08:32:35:578 3308 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys

08:32:35:609 3308 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys

08:32:35:625 3308 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys

08:32:35:671 3308 mfeavfk (bafdd5e28baea99d7f4772af2f5ec7ee) C:\WINDOWS\system32\drivers\mfeavfk.sys

08:32:35:687 3308 mfebopk (1d003e3056a43d881597d6763e83b943) C:\WINDOWS\system32\drivers\mfebopk.sys

08:32:35:718 3308 mfehidk (3f138a1c8a0659f329f242d1e389b2cf) C:\WINDOWS\system32\drivers\mfehidk.sys

08:32:35:750 3308 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\WINDOWS\system32\drivers\mferkdk.sys

08:32:35:781 3308 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\WINDOWS\system32\drivers\mfesmfk.sys

08:32:35:781 3308 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys

08:32:35:796 3308 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys

08:32:35:796 3308 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys

08:32:35:812 3308 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys

08:32:35:828 3308 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys

08:32:35:859 3308 MPFP (136157e79849b9e5316ba4008d6075a8) C:\WINDOWS\system32\Drivers\Mpfp.sys

08:32:35:890 3308 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys

08:32:35:890 3308 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys

08:32:35:937 3308 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys

08:32:35:953 3308 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys

08:32:35:984 3308 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

08:32:35:984 3308 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys

08:32:36:000 3308 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys

08:32:36:000 3308 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys

08:32:36:015 3308 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys

08:32:36:046 3308 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys

08:32:36:046 3308 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys

08:32:36:062 3308 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys

08:32:36:078 3308 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys

08:32:36:093 3308 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys

08:32:36:109 3308 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys

08:32:36:109 3308 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys

08:32:36:140 3308 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys

08:32:36:140 3308 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys

08:32:36:187 3308 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys

08:32:36:203 3308 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys

08:32:36:250 3308 NVENETFD (d314fe034d68c09d412727886e24f5fb) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys

08:32:36:281 3308 nvgts (a0b3f3a5049931657164f0ffcf0b208e) C:\WINDOWS\system32\drivers\nvgts.sys

08:32:36:312 3308 nvnetbus (f99fbb623ed78367574ee461b5b32c2c) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys

08:32:36:343 3308 NVR0Dev (812f257ed1cd53fcb1f9f9cc910f4809) C:\WINDOWS\nvoclock.sys

08:32:36:359 3308 nvrd32 (c9128fe14e5c1e55710781b5c276f2ed) C:\WINDOWS\system32\drivers\nvrd32.sys

08:32:36:390 3308 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys

08:32:36:390 3308 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys

08:32:36:390 3308 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys

08:32:36:421 3308 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys

08:32:36:421 3308 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys

08:32:36:421 3308 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys

08:32:36:453 3308 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys

08:32:36:453 3308 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys

08:32:36:468 3308 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys

08:32:36:515 3308 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys

08:32:36:515 3308 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys

08:32:36:531 3308 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys

08:32:36:531 3308 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys

08:32:36:531 3308 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys

08:32:36:562 3308 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys

08:32:36:578 3308 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys

08:32:36:578 3308 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys

08:32:36:593 3308 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys

08:32:36:593 3308 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys

08:32:36:609 3308 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys

08:32:36:640 3308 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys

08:32:36:640 3308 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys

08:32:36:640 3308 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys

08:32:36:656 3308 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys

08:32:36:671 3308 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys

08:32:36:687 3308 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys

08:32:36:734 3308 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys

08:32:36:750 3308 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys

08:32:36:781 3308 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys

08:32:36:859 3308 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS

08:32:36:875 3308 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS

08:32:36:875 3308 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys

08:32:36:906 3308 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys

08:32:36:921 3308 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys

08:32:36:921 3308 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys

08:32:36:968 3308 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys

08:32:36:984 3308 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys

08:32:36:984 3308 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys

08:32:37:031 3308 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys

08:32:37:046 3308 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys

08:32:37:078 3308 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys

08:32:37:093 3308 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys

08:32:37:109 3308 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys

08:32:37:109 3308 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys

08:32:37:109 3308 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys

08:32:37:140 3308 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys

08:32:37:171 3308 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys

08:32:37:218 3308 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys

08:32:37:218 3308 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys

08:32:37:234 3308 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys

08:32:37:234 3308 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys

08:32:37:250 3308 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys

08:32:37:265 3308 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys

08:32:37:281 3308 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys

08:32:37:312 3308 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys

08:32:37:312 3308 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys

08:32:37:328 3308 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys

08:32:37:359 3308 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys

08:32:37:406 3308 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys

08:32:37:421 3308 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

08:32:37:421 3308 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys

08:32:37:437 3308 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys

08:32:37:437 3308 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys

08:32:37:453 3308 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys

08:32:37:453 3308 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys

08:32:37:468 3308 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys

08:32:37:500 3308 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys

08:32:37:531 3308 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys

08:32:37:546 3308 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys

08:32:37:562 3308 Reboot required for cure complete..

08:32:37:593 3308 Cure on reboot scheduled successfully

08:32:37:593 3308

08:32:37:593 3308 Completed

08:32:37:593 3308

08:32:37:593 3308 Results:

08:32:37:593 3308 Registry objects infected / cured / cured on reboot: 0 / 0 / 0

08:32:37:593 3308 File objects infected / cured / cured on reboot: 1 / 0 / 1

08:32:37:593 3308

08:32:37:593 3308 KLMD(ARK) unloaded successfully

Link to post
Share on other sites

Delete your copy of ComboFix and then follow these instructions in Normal mode:

**Note: If you need more detailed information, please visit the web page of ComboFix in BleepingComputer. **

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Stay with me until given the 'all clear' even if symptoms diminish. Lack of symptoms does not always mean the job is complete.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by me or another helper.

Please download ComboFix from

Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  1. If you are using Firefox, make sure that your download settings are as follows:
    • Open Tools -> Options -> Main tab
    • Set to Always ask me where to Save the files.

[*]During the download, rename Combofix to Combo-Fix as follows:

CF_download_FF.gif

CF_download_rename.gif

[*]It is important you rename Combofix during the download, but not after.

[*]Please do not rename Combofix to other names, but only to the one indicated.

[*]Close any open browsers.

[*]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

-----------------------------------------------------------

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause unpredictable results.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    -----------------------------------------------------------


  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

-----------------------------------------------------------

[*]Double click on combo-Fix.exe & follow the prompts.

[*]When finished, it will produce a report for you.

[*]Please post the C:\Combo-Fix.txt for further review.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

Link to post
Share on other sites

Here's the latest ComboFix log

ComboFix 10-06-01.05 - David Nakaki 06/02/2010 8:56.3.4 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.2529 [GMT -7:00]

Running from: c:\documents and settings\David Nakaki\Desktop\Combo-Fix.exe

AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

.

((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 )))))))))))))))))))))))))))))))

.

2010-05-31 16:08 . 2008-04-14 12:00 185344 -c--a-w- c:\windows\system32\dllcache\thawbrkr.dll

2010-05-31 16:08 . 2008-04-14 12:00 185344 ----a-w- c:\windows\system32\Thawbrkr.dll

2010-05-31 16:08 . 2008-04-14 12:00 10752 -c--a-w- c:\windows\system32\dllcache\c_iscii.dll

2010-05-31 16:08 . 2008-04-14 12:00 10752 ----a-w- c:\windows\system32\c_iscii.dll

2010-05-31 16:08 . 2008-04-14 12:00 5632 -c--a-w- c:\windows\system32\dllcache\kbdusa.dll

2010-05-31 16:08 . 2008-04-14 12:00 5632 ----a-w- c:\windows\system32\kbdusa.dll

2010-05-31 16:08 . 2008-04-14 12:00 6144 -c--a-w- c:\windows\system32\dllcache\ftlx041e.dll

2010-05-31 16:08 . 2008-04-14 12:00 6144 ----a-w- c:\windows\system32\ftlx041e.dll

2010-05-31 16:08 . 2008-04-14 12:00 19456 -c--a-w- c:\windows\system32\dllcache\agt0401.dll

2010-05-31 16:08 . 2008-04-14 12:00 19456 -c--a-w- c:\windows\system32\dllcache\agt040d.dll

2010-05-29 07:11 . 2010-05-31 15:52 63488 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll

2010-05-29 07:11 . 2010-05-29 07:11 52224 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

2010-05-29 07:11 . 2010-05-31 15:51 117760 ----a-w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\SUPERAntiSpyware.com

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2010-05-29 07:10 . 2010-05-29 07:10 -------- d-----w- c:\program files\SUPERAntiSpyware

2010-05-29 06:53 . 2010-05-29 06:53 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache

2010-05-27 05:31 . 2010-05-27 05:31 -------- d-----w- c:\program files\CCleaner

2010-05-25 06:35 . 2010-05-25 06:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion

2010-05-25 06:35 . 2010-05-25 06:35 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Yahoo!

2010-05-25 06:35 . 2010-05-25 06:35 -------- d-----w- c:\program files\Yahoo!

2010-05-25 04:47 . 2010-05-25 04:47 -------- d-----w- c:\program files\Support Tools

2010-05-24 01:16 . 2008-01-15 03:20 3636 ----a-w- c:\windows\system32\drivers\nvphy.bin

2010-05-24 01:16 . 2008-01-15 03:20 356352 ----a-w- c:\windows\system32\nvunrm.exe

2010-05-24 01:04 . 2010-05-24 01:04 -------- d-----w- C:\NV37803716.TMP

2010-05-24 01:04 . 2010-05-24 01:04 -------- d-----w- C:\NV1100284.TMP

2010-05-24 00:51 . 2010-05-24 00:51 -------- d-----w- C:\NV33242512.TMP

2010-05-24 00:51 . 2010-05-24 00:51 -------- d-----w- C:\NV30361528.TMP

2010-05-24 00:34 . 2010-05-24 00:34 -------- d-----w- C:\NV6241616.TMP

2010-05-24 00:34 . 2010-05-24 00:34 -------- d-----w- C:\NV4363192.TMP

2010-05-23 23:42 . 2010-05-23 23:42 45056 ----a-r- c:\documents and settings\David Nakaki\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe

2010-05-23 23:42 . 2010-05-23 23:42 10134 ----a-r- c:\documents and settings\David Nakaki\Application Data\Microsoft\Installer\{42929F0F-CE14-47AF-9FC7-FF297A603021}\ARPPRODUCTICON.exe

2010-05-23 23:42 . 2010-05-23 23:42 -------- d-----w- c:\windows\system32\vmm32

2010-05-23 16:43 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-05-23 16:43 . 2010-05-23 16:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-05-23 16:43 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-05-23 14:44 . 2010-05-23 14:44 -------- d-----w- c:\windows\system32\wbem\Repository

2010-05-22 21:00 . 2010-05-22 21:00 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Malwarebytes

2010-05-22 21:00 . 2010-05-22 21:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-05-22 14:31 . 2010-05-22 14:31 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll

2010-05-22 14:29 . 2010-05-22 14:29 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe

2010-05-22 14:29 . 2010-05-22 14:29 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe

2010-05-22 14:28 . 2010-05-22 14:28 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe

2010-05-22 14:28 . 2010-05-22 14:31 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX

2010-05-21 07:24 . 2010-05-21 07:24 -------- d-sh--w- c:\documents and settings\David Nakaki\IECompatCache

2010-05-21 07:24 . 2010-05-21 07:24 -------- d-sh--w- c:\documents and settings\David Nakaki\PrivacIE

2010-05-21 07:23 . 2010-05-21 07:23 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache

2010-05-21 07:19 . 2010-05-21 07:19 -------- d-sh--w- c:\documents and settings\David Nakaki\IETldCache

2010-05-21 07:17 . 2010-05-21 07:17 -------- dc-h--w- c:\windows\ie8

2010-05-21 07:17 . 2010-05-21 07:17 -------- d-----w- c:\program files\Microsoft

2010-05-21 07:17 . 2010-05-21 07:17 -------- d-----w- c:\program files\MSN Toolbar

2010-05-21 07:16 . 2010-05-21 07:17 -------- d-----w- c:\program files\Bing Bar Installer

2010-05-21 07:16 . 2010-05-21 07:18 -------- d--h--w- c:\windows\msdownld.tmp

2010-05-17 08:44 . 2010-05-17 08:44 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-05-07 04:39 . 2010-05-07 04:39 -------- d-----w- c:\program files\Microsoft Silverlight

2010-05-04 13:32 . 2010-05-04 13:32 -------- d-----w- c:\program files\iPod

2010-05-04 13:32 . 2010-05-04 13:32 -------- d-----w- c:\program files\iTunes

2010-05-04 13:29 . 2010-05-04 13:29 -------- d-----w- c:\program files\Bonjour

2010-05-04 13:27 . 2010-05-04 13:27 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-06-02 15:34 . 2008-04-25 16:16 75264 ----a-w- c:\windows\system32\drivers\ipsec.sys

2010-05-31 21:38 . 2009-01-16 22:31 -------- d-----w- c:\program files\McAfee

2010-05-27 06:06 . 2009-03-08 16:40 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Azureus

2010-05-25 06:36 . 2009-01-16 22:30 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee

2010-05-23 23:42 . 2009-01-16 22:30 -------- d-----w- c:\program files\Dell

2010-05-22 14:31 . 2010-02-07 22:59 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\DivX

2010-05-22 14:29 . 2009-12-17 14:43 -------- d-----w- c:\program files\Common Files\DivX Shared

2010-05-22 14:28 . 2010-05-22 14:30 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll

2010-05-22 14:28 . 2010-05-22 14:30 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe

2010-05-19 05:24 . 2009-03-08 19:28 -------- d-----w- c:\documents and settings\David Nakaki\Application Data\Apple Computer

2010-05-12 13:30 . 2009-01-16 22:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-05-04 13:32 . 2009-03-08 19:27 -------- d-----w- c:\program files\Common Files\Apple

2010-04-14 20:19 . 2010-04-14 20:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7602.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-13 21:19 . 2010-04-13 21:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7599.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-12 22:19 . 2010-04-12 22:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7595.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-11 23:19 . 2010-04-11 23:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7592.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-11 00:19 . 2010-04-11 00:19 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7589.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-10 01:20 . 2010-04-10 01:20 8851392 ----a-w- c:\documents and settings\David Nakaki\Application Data\Azureus\tmp\AZU7586.tmp\Vuze_4.4.0.0a_win32.exe

2010-04-08 20:20 . 2010-04-08 20:20 91424 ----a-w- c:\windows\system32\dnssd.dll

2010-04-08 20:20 . 2010-04-08 20:20 107808 ----a-w- c:\windows\system32\dns-sd.exe

2010-04-06 05:16 . 2010-02-02 14:27 -------- d-----w- c:\program files\QuickTime

2010-04-06 04:38 . 2010-04-06 04:38 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}

2010-03-31 01:58 . 2007-12-11 01:37 133616 ------w- c:\windows\system32\PxAFS.DLL

2010-03-31 01:58 . 2007-11-14 20:08 125424 ------w- c:\windows\system32\pxinsi64.exe

2010-03-31 01:58 . 2007-11-14 09:00 44944 ------w- c:\windows\system32\drivers\pxhelp20.sys

2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll

.

((((((((((((((((((((((((((((( SnapShot@2010-06-02_13.35.52 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-06-02 15:35 . 2010-06-02 15:35 16384 c:\windows\Temp\Perflib_Perfdata_c18.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]

2008-12-10 01:40 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-10 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-10 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]

[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-01-15 106496]

"SightSpeed"="c:\program files\Dell Video Chat\DellVideoChat.exe" [2008-08-15 4812664]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-16 39408]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-05-18 2397424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2008-01-15 16855552]

"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-08-19 203296]

"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]

"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-10-27 30192]

"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]

"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2008-11-03 1745648]

"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 243544]

"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-12 288088]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]

2009-01-16 22:34 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"c:\\Program Files\\Vuze\\Azureus.exe"=

"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=

"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Dell Video Chat\\DellVideoChat.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 AM 67656]

R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [3/8/2009 9:40 AM 464264]

R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [3/8/2009 9:40 AM 234888]

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [5/24/2010 11:36 PM 93320]

S2 gupdate1ca7f273eefbc52;Google Update Service (gupdate1ca7f273eefbc52);c:\program files\Google\Update\GoogleUpdate.exe [12/17/2009 7:43 AM 133104]

S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [1/16/2009 3:30 PM 30192]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - KLMDB

*Deregistered* - klmdb

.

Contents of the 'Scheduled Tasks' folder

2010-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2010-06-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 14:43]

2010-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-17 14:43]

2010-05-15 c:\windows\Tasks\McDefragTask.job

- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-16 19:22]

2010-05-01 c:\windows\Tasks\McQcTask.job

- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-16 19:22]

2010-06-02 c:\windows\Tasks\OGALogon.job

- c:\windows\system32\OGAEXEC.exe [2009-08-03 23:07]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.yahoo.com/

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

mSearch Bar = hxxp://www.google.com/ie

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html

Trusted Zone: cinemanow.com

.

- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-06-02 09:00

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(728)

c:\program files\SUPERAntiSpyware\SASWINLO.DLL

c:\windows\system32\Ati2evxx.dll

c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll

- - - - - - - > 'explorer.exe'(4572)

c:\program files\Windows Desktop Search\deskbar.dll

c:\program files\Windows Desktop Search\en-us\dbres.dll.mui

c:\program files\Windows Desktop Search\dbres.dll

c:\program files\Windows Desktop Search\wordwheel.dll

c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui

c:\program files\Windows Desktop Search\msnlExtRes.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\OneX.DLL

c:\windows\system32\eappprxy.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\WPDShServiceObj.dll

c:\windows\system32\PortableDeviceTypes.dll

c:\windows\system32\PortableDeviceApi.dll

.

Completion time: 2010-06-02 09:02:09

ComboFix-quarantined-files.txt 2010-06-02 16:02

ComboFix2.txt 2010-06-02 14:51

ComboFix3.txt 2010-06-02 13:36

Pre-Run: 428,553,031,680 bytes free

Post-Run: 428,571,463,680 bytes free

- - End Of File - - 1CCF686374C939E9EF2EC3407FD24A0F

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.