PaulPool
New Member
I've tried everything I can think of to help my girlfriend's laptop. Well that I can remotely since I'm not able to get over there to get my hands on it.
Its that increasingly-sneakier fake antivirus program.
Even in safemode she can not reinstall malwarebytes nor combofix from an external drive, well she said she can but it won't open. Somehow she was able to install and run combofix but not malwarebytes, I had told her to change the file name before she saved it. She's not able to track from the Task Manager which process it is. Right now it stopped allowing her to get online or on aim.
I've tried various methods to get her to install and run different programs to get rid of it. After one point she got an error trying to log in something about unauthenticated access. Combofix had found a rootkit which required a restart I've included the log as a txt file.
ComboFix 10-10-22.03 - ebonee 10/22/2010 17:58:52.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3034.1776 [GMT -5:00]
Running from: c:\users\ebonee\Downloads\pauliepoo.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\program files\Search Toolbar\tbcore3.dll
c:\program files\Search Toolbar\tbhelper.dll
c:\users\ebonee\AppData\Local\Windows Server
c:\users\ebonee\GoToAssistDownloadHelper.exe
E:\Autorun.inf
Infected copy of c:\windows\system32\drivers\partmgr.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((( Files Created from 2010-09-22 to 2010-10-22 )))))))))))))))))))))))))))))))
.
2010-10-22 23:07 . 2010-10-22 23:07 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-10-22 23:07 . 2010-10-22 23:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-22 19:23 . 2010-10-22 19:23 -------- d-----w- c:\users\ebonee\AppData\Local\Citrix
2010-10-22 19:22 . 2010-10-22 19:22 -------- d-----w- c:\users\ebonee\AppData\Local\Apps
2010-10-22 19:22 . 2010-10-22 19:23 -------- d-----w- c:\users\ebonee\AppData\Local\Deployment
2010-10-22 18:57 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{09CC0087-FB87-4721-AEFF-AA76E23E6D91}\mpengine.dll
2010-10-22 06:29 . 2010-10-22 06:29 -------- d-----w- C:\program31270p
2010-10-22 06:29 . 2010-10-22 06:29 -------- d-----w- C:\program2
2010-10-22 06:26 . 2010-10-22 06:26 -------- d-----w- c:\program files\Clarus
2010-10-22 06:19 . 2010-10-22 06:19 -------- d-----w- C:\program1
2010-10-22 05:49 . 2010-10-22 06:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware(2)
2010-10-21 19:02 . 2010-10-21 19:02 -------- d-----w- C:\acccore
2010-10-19 20:24 . 2010-10-19 20:25 -------- d-----w- c:\program files\IZArc
2010-10-13 00:05 . 2010-09-10 18:18 10626560 ----a-w- c:\windows\system32\wmp(200).dll
2010-10-13 00:05 . 2010-09-10 16:37 8147456 ----a-w- c:\windows\system32\wmploc(201).DLL
2010-10-13 00:04 . 2010-08-10 15:02 274432 ----a-w- c:\windows\system32\schannel(185).dll
2010-10-13 00:04 . 2010-06-28 16:15 1315840 ----a-w- c:\windows\system32\ole32(184).dll
2010-10-13 00:04 . 2010-08-20 15:21 866816 ----a-w- c:\windows\system32\wmpmde(202).dll
2010-10-13 00:04 . 2010-08-31 15:40 531968 ----a-w- c:\windows\system32\comctl32(151).dll
2010-10-13 00:04 . 2010-09-08 17:26 833024 ----a-w- c:\windows\system32\wininet(199).dll
2010-10-13 00:04 . 2010-09-08 17:26 1174528 ----a-w- c:\windows\system32\urlmon(197).dll
2010-10-13 00:04 . 2010-09-08 17:23 270848 ----a-w- c:\windows\system32\iertutil(169).dll
2010-10-07 00:05 . 2010-10-07 00:05 -------- d-----w- c:\users\Public\Roaming
2010-10-02 05:09 . 2010-10-02 05:09 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-10-01 03:13 . 2010-10-18 22:07 -------- d-----w- c:\users\ebonee\AppData\Roaming\DivX
2010-10-01 03:04 . 2010-10-02 05:10 -------- d-----w- c:\program files\DivX
2010-10-01 03:04 . 2010-10-02 05:10 -------- d-----w- c:\programdata\DivX
2010-10-01 01:08 . 2010-10-01 01:08 -------- d-----w- c:\program files\Xvid
2010-10-01 01:08 . 2008-12-14 01:01 77824 ----a-w- c:\windows\system32\xvid.ax
2010-10-01 01:08 . 2008-12-05 02:46 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-10-01 01:08 . 2008-12-05 02:42 815104 ----a-w- c:\windows\system32\xvidcore.dll
2010-09-29 22:30 . 2010-06-22 12:57 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-28 22:46 . 2010-09-28 22:46 -------- d-----w- c:\users\ebonee\AppData\Roaming\Watchtower
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 16:41 . 2010-04-01 07:47 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-08-17 13:32 . 2010-09-14 19:17 126464 ----a-w- c:\windows\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Aim"="c:\program files\AIM\aim.exe" [2010-03-08 3972440]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-26 39408]
"SightSpeed"="c:\program files\Dell Video Chat\DellVideoChat.exe" [2008-12-18 4823928]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Google Update"="c:\users\ebonee\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-26 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-03-31 217088]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-31 483428]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-31 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-31 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-31 150552]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-21 3810304]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-01-09 405639]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-01-30 206064]
"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1384.0\mswinext.exe" [2010-02-17 243032]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"OA009Cfg.exe"="OA009Cfg.exe" [2008-10-06 32768]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
c:\users\ebonee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-26 135664]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe [2008-01-21 21504]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 vsdatant7;vsdatant7;c:\windows\system32\drivers\vsdatant.win7.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [2009-03-31 81920]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 SftService;SoftThinks Agent Service;c:\program files\Dell DataSafe Local Backup\sftservice.EXE [2009-04-17 636144]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-12-31 144128]
S3 OA009Ufd;Creative Camera OA009 Upper Filter Driver;c:\windows\system32\DRIVERS\OA009Ufd.sys [2009-03-06 133632]
S3 OA009Vid;Creative Camera OA009 Function Driver;c:\windows\system32\DRIVERS\OA009Vid.sys [2009-03-19 271552]
S3 WefiEngSvc;WeFi Engine Service;c:\program files\WeFi\WefiEngSvc.exe [2010-05-05 137560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
Akamai REG_MULTI_SZ Akamai
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-26 08:36]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-26 08:36]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2976465232-2936503366-3671267662-1000Core.job
- c:\users\ebonee\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-29 08:47]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2976465232-2936503366-3671267662-1000UA.job
- c:\users\ebonee\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-29 08:47]
2010-10-11 c:\windows\Tasks\Norton Security Scan for ebonee.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-04-15 18:46]
2010-10-22 c:\windows\Tasks\User_Feed_Synchronization-{A7AA0DB0-4183-40A6-B01C-54DBA0EEFCD7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
2010-10-22 c:\windows\Tasks\WefiStartup.job
- c:\program files\WeFi\WefiStartup.exe [2010-05-05 06:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:6522
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\ebonee\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\ebonee\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
Trusted Zone: facebook.com\www
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
WebBrowser-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
HKCU-Run-AdobeBridge - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe
AddRemove-{DE5BFF9C-84D1-4B09-9C20-54633044CB85} - h:\watchtowerlibrary\Watchtower Library 2008\E\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-22 18:08
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
Completion time: 2010-10-22 18:10:03
ComboFix-quarantined-files.txt 2010-10-22 23:10
Pre-Run: 214,752,342,016 bytes free
Post-Run: 214,808,002,560 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=47 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47
- - End Of File - - DFB05A823327F95CBBA73D802AC76531
Its that increasingly-sneakier fake antivirus program.
Even in safemode she can not reinstall malwarebytes nor combofix from an external drive, well she said she can but it won't open. Somehow she was able to install and run combofix but not malwarebytes, I had told her to change the file name before she saved it. She's not able to track from the Task Manager which process it is. Right now it stopped allowing her to get online or on aim.
I've tried various methods to get her to install and run different programs to get rid of it. After one point she got an error trying to log in something about unauthenticated access. Combofix had found a rootkit which required a restart I've included the log as a txt file.
ComboFix 10-10-22.03 - ebonee 10/22/2010 17:58:52.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3034.1776 [GMT -5:00]
Running from: c:\users\ebonee\Downloads\pauliepoo.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbar.dll
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\program files\Search Toolbar\tbcore3.dll
c:\program files\Search Toolbar\tbhelper.dll
c:\users\ebonee\AppData\Local\Windows Server
c:\users\ebonee\GoToAssistDownloadHelper.exe
E:\Autorun.inf
Infected copy of c:\windows\system32\drivers\partmgr.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((( Files Created from 2010-09-22 to 2010-10-22 )))))))))))))))))))))))))))))))
.
2010-10-22 23:07 . 2010-10-22 23:07 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-10-22 23:07 . 2010-10-22 23:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-22 19:23 . 2010-10-22 19:23 -------- d-----w- c:\users\ebonee\AppData\Local\Citrix
2010-10-22 19:22 . 2010-10-22 19:22 -------- d-----w- c:\users\ebonee\AppData\Local\Apps
2010-10-22 19:22 . 2010-10-22 19:23 -------- d-----w- c:\users\ebonee\AppData\Local\Deployment
2010-10-22 18:57 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{09CC0087-FB87-4721-AEFF-AA76E23E6D91}\mpengine.dll
2010-10-22 06:29 . 2010-10-22 06:29 -------- d-----w- C:\program31270p
2010-10-22 06:29 . 2010-10-22 06:29 -------- d-----w- C:\program2
2010-10-22 06:26 . 2010-10-22 06:26 -------- d-----w- c:\program files\Clarus
2010-10-22 06:19 . 2010-10-22 06:19 -------- d-----w- C:\program1
2010-10-22 05:49 . 2010-10-22 06:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware(2)
2010-10-21 19:02 . 2010-10-21 19:02 -------- d-----w- C:\acccore
2010-10-19 20:24 . 2010-10-19 20:25 -------- d-----w- c:\program files\IZArc
2010-10-13 00:05 . 2010-09-10 18:18 10626560 ----a-w- c:\windows\system32\wmp(200).dll
2010-10-13 00:05 . 2010-09-10 16:37 8147456 ----a-w- c:\windows\system32\wmploc(201).DLL
2010-10-13 00:04 . 2010-08-10 15:02 274432 ----a-w- c:\windows\system32\schannel(185).dll
2010-10-13 00:04 . 2010-06-28 16:15 1315840 ----a-w- c:\windows\system32\ole32(184).dll
2010-10-13 00:04 . 2010-08-20 15:21 866816 ----a-w- c:\windows\system32\wmpmde(202).dll
2010-10-13 00:04 . 2010-08-31 15:40 531968 ----a-w- c:\windows\system32\comctl32(151).dll
2010-10-13 00:04 . 2010-09-08 17:26 833024 ----a-w- c:\windows\system32\wininet(199).dll
2010-10-13 00:04 . 2010-09-08 17:26 1174528 ----a-w- c:\windows\system32\urlmon(197).dll
2010-10-13 00:04 . 2010-09-08 17:23 270848 ----a-w- c:\windows\system32\iertutil(169).dll
2010-10-07 00:05 . 2010-10-07 00:05 -------- d-----w- c:\users\Public\Roaming
2010-10-02 05:09 . 2010-10-02 05:09 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-10-01 03:13 . 2010-10-18 22:07 -------- d-----w- c:\users\ebonee\AppData\Roaming\DivX
2010-10-01 03:04 . 2010-10-02 05:10 -------- d-----w- c:\program files\DivX
2010-10-01 03:04 . 2010-10-02 05:10 -------- d-----w- c:\programdata\DivX
2010-10-01 01:08 . 2010-10-01 01:08 -------- d-----w- c:\program files\Xvid
2010-10-01 01:08 . 2008-12-14 01:01 77824 ----a-w- c:\windows\system32\xvid.ax
2010-10-01 01:08 . 2008-12-05 02:46 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2010-10-01 01:08 . 2008-12-05 02:42 815104 ----a-w- c:\windows\system32\xvidcore.dll
2010-09-29 22:30 . 2010-06-22 12:57 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-28 22:46 . 2010-09-28 22:46 -------- d-----w- c:\users\ebonee\AppData\Roaming\Watchtower
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 16:41 . 2010-04-01 07:47 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-08-17 13:32 . 2010-09-14 19:17 126464 ----a-w- c:\windows\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Aim"="c:\program files\AIM\aim.exe" [2010-03-08 3972440]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-26 39408]
"SightSpeed"="c:\program files\Dell Video Chat\DellVideoChat.exe" [2008-12-18 4823928]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Google Update"="c:\users\ebonee\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-03-26 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-03-31 217088]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-31 483428]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-31 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-31 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-31 150552]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-12-21 3810304]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2009-01-09 405639]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-01-30 206064]
"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1384.0\mswinext.exe" [2010-02-17 243032]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"OA009Cfg.exe"="OA009Cfg.exe" [2008-10-06 32768]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
c:\users\ebonee\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-26 135664]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe [2008-01-21 21504]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 vsdatant7;vsdatant7;c:\windows\system32\drivers\vsdatant.win7.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\aestsrv.exe [2009-03-31 81920]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 SftService;SoftThinks Agent Service;c:\program files\Dell DataSafe Local Backup\sftservice.EXE [2009-04-17 636144]
S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys [2008-12-31 144128]
S3 OA009Ufd;Creative Camera OA009 Upper Filter Driver;c:\windows\system32\DRIVERS\OA009Ufd.sys [2009-03-06 133632]
S3 OA009Vid;Creative Camera OA009 Function Driver;c:\windows\system32\DRIVERS\OA009Vid.sys [2009-03-19 271552]
S3 WefiEngSvc;WeFi Engine Service;c:\program files\WeFi\WefiEngSvc.exe [2010-05-05 137560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
Akamai REG_MULTI_SZ Akamai
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-26 08:36]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-26 08:36]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2976465232-2936503366-3671267662-1000Core.job
- c:\users\ebonee\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-29 08:47]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2976465232-2936503366-3671267662-1000UA.job
- c:\users\ebonee\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-29 08:47]
2010-10-11 c:\windows\Tasks\Norton Security Scan for ebonee.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-04-15 18:46]
2010-10-22 c:\windows\Tasks\User_Feed_Synchronization-{A7AA0DB0-4183-40A6-B01C-54DBA0EEFCD7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
2010-10-22 c:\windows\Tasks\WefiStartup.job
- c:\program files\WeFi\WefiStartup.exe [2010-05-05 06:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:6522
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\ebonee\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\ebonee\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
Trusted Zone: facebook.com\www
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
WebBrowser-{0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
HKCU-Run-AdobeBridge - (no file)
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe
AddRemove-{DE5BFF9C-84D1-4B09-9C20-54633044CB85} - h:\watchtowerlibrary\Watchtower Library 2008\E\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-22 18:08
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
Completion time: 2010-10-22 18:10:03
ComboFix-quarantined-files.txt 2010-10-22 23:10
Pre-Run: 214,752,342,016 bytes free
Post-Run: 214,808,002,560 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=47 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47
- - End Of File - - DFB05A823327F95CBBA73D802AC76531
Last edited by a moderator: