Downloaded and ran combo fix.
Below is
- the log file that was generated after combofix ran
- a fresh dds log file
ComboFix:
ComboFix 10-05-24.07 - Eric 05/25/2010 12:07:50.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3062.2075 [GMT -5:00]
Running from: d:\users\Eric\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\SysWoW32
c:\programdata\SysWoW32\_u1552319341v0
c:\programdata\SysWoW32\_u1552319341v1
c:\programdata\SysWoW32\_u1552319341v2
c:\programdata\SysWoW32\_u1552319341v3
c:\programdata\SysWoW32\mu1552319341v4
c:\programdata\SysWoW32\mu1552319341v4.kwd
c:\programdata\SysWoW32\mu1552319341v5
c:\programdata\SysWoW32\mu1552319341v5.kwd
c:\programdata\SysWoW32\mu1552319341v6
c:\programdata\SysWoW32\mu1552319341v6.kwd
c:\programdata\SysWoW32\mu1552319341v7
c:\programdata\SysWoW32\mu1552319341v7.kwd
c:\programdata\SysWoW32\wu1552319341v0
c:\programdata\SysWoW32\wu1552319341v0.kwd
c:\programdata\SysWoW32\wu1552319341v1
c:\programdata\SysWoW32\wu1552319341v1.kwd
c:\programdata\SysWoW32\wu1552319341v2
c:\programdata\SysWoW32\wu1552319341v2.kwd
c:\programdata\SysWoW32\wu1552319341v3
c:\programdata\SysWoW32\wu1552319341v3.kwd
c:\programdata\unrar.exe
c:\users\Becky\AppData\Roaming\Mozilla\Firefox\Profiles\zhahlj4u.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}
c:\users\Becky\AppData\Roaming\Mozilla\Firefox\Profiles\zhahlj4u.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome.manifest
c:\users\Becky\AppData\Roaming\Mozilla\Firefox\Profiles\zhahlj4u.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome\xulcache.jar
c:\users\Becky\AppData\Roaming\Mozilla\Firefox\Profiles\zhahlj4u.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\defaults\preferences\xulcache.js
c:\users\Becky\AppData\Roaming\Mozilla\Firefox\Profiles\zhahlj4u.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\install.rdf
c:\users\Colby\AppData\Roaming\Mozilla\Firefox\Profiles\qxxkve7j.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}
c:\users\Colby\AppData\Roaming\Mozilla\Firefox\Profiles\qxxkve7j.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome.manifest
c:\users\Colby\AppData\Roaming\Mozilla\Firefox\Profiles\qxxkve7j.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome\xulcache.jar
c:\users\Colby\AppData\Roaming\Mozilla\Firefox\Profiles\qxxkve7j.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\defaults\preferences\xulcache.js
c:\users\Colby\AppData\Roaming\Mozilla\Firefox\Profiles\qxxkve7j.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\install.rdf
c:\users\Eric\AppData\Roaming\0200000084ca2e57891C.manifest
c:\users\Eric\AppData\Roaming\0200000084ca2e57891O.manifest
c:\users\Eric\AppData\Roaming\0200000084ca2e57891P.manifest
c:\users\Eric\AppData\Roaming\0200000084ca2e57891S.manifest
c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\q9dq4sph.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}
c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\q9dq4sph.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome.manifest
c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\q9dq4sph.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome\xulcache.jar
c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\q9dq4sph.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\defaults\preferences\xulcache.js
c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\q9dq4sph.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\install.rdf
c:\users\Isaac\AppData\Roaming\Mozilla\Firefox\Profiles\1h5au8vt.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}
c:\users\Isaac\AppData\Roaming\Mozilla\Firefox\Profiles\1h5au8vt.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome.manifest
c:\users\Isaac\AppData\Roaming\Mozilla\Firefox\Profiles\1h5au8vt.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome\xulcache.jar
c:\users\Isaac\AppData\Roaming\Mozilla\Firefox\Profiles\1h5au8vt.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\defaults\preferences\xulcache.js
c:\users\Isaac\AppData\Roaming\Mozilla\Firefox\Profiles\1h5au8vt.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\install.rdf
c:\users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\efg1ao35.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}
c:\users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\efg1ao35.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome.manifest
c:\users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\efg1ao35.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\chrome\xulcache.jar
c:\users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\efg1ao35.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\defaults\preferences\xulcache.js
c:\users\Zach\AppData\Roaming\Mozilla\Firefox\Profiles\efg1ao35.default\extensions\{71d15388-d3d0-4306-a973-2a355218356e}\install.rdf
.
((((((((((((((((((((((((( Files Created from 2010-04-25 to 2010-05-25 )))))))))))))))))))))))))))))))
.
2010-05-25 17:12 . 2010-05-25 17:12 -------- d-----w- c:\users\Eric\AppData\Local\temp
2010-05-25 17:12 . 2010-05-25 17:12 -------- d-----w- c:\users\Zach\AppData\Local\temp
2010-05-24 17:13 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-24 17:13 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-24 17:07 . 2010-05-24 17:07 -------- d-----w- c:\users\Eric\AppData\Local\Adobe
2010-05-24 14:16 . 2010-05-24 14:16 -------- dc----w- c:\program files\Common Files\Java
2010-05-24 14:16 . 2010-05-24 14:16 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-17 15:03 . 2010-05-17 15:03 239496 ----a-w- c:\programdata\WebEx\WebEx\924\atgpcext.dll
2010-05-17 15:03 . 2010-05-17 15:04 -------- d-----w- c:\programdata\WebEx
2010-05-17 15:03 . 2010-05-17 15:03 28472 ----a-w- c:\programdata\WebEx\WebEx\924\atgpcdec.dll
2010-05-17 02:24 . 2010-05-17 02:25 -------- dc----w- c:\program files\Spybot - Search & Destroy
2010-05-12 12:54 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-04-30 13:38 . 2010-04-30 13:38 -------- d-----w- c:\programdata\Alwil Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-24 20:41 . 2008-08-21 14:32 -------- d-----w- c:\users\Eric\AppData\Roaming\Gizmo5
2010-05-24 13:58 . 2008-08-21 21:53 -------- d-----w- c:\program files\Java
2010-05-18 18:24 . 2010-03-11 03:16 -------- d-----w- c:\users\Eric\AppData\Roaming\Skype
2010-05-17 02:58 . 2008-10-20 13:11 -------- dc----w- c:\programdata\Spybot - Search & Destroy
2010-05-13 01:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-05-13 01:20 . 2008-04-06 19:00 -------- d-----w- c:\programdata\Microsoft Help
2010-05-10 00:27 . 2010-01-11 22:59 -------- dc----w- c:\program files\Google
2010-05-06 15:36 . 2009-10-20 17:52 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-01 19:40 . 2008-08-20 22:27 109792 ----a-w- c:\users\Isaac\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-19 19:59 . 2010-04-19 19:59 255472 ----a-w- c:\users\Eric\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
2010-04-15 16:59 . 2010-04-15 16:59 -------- d-----w- c:\users\Eric\AppData\Roaming\Image Zone Express
2010-04-15 16:59 . 2010-04-15 16:59 -------- d-----w- c:\users\Eric\AppData\Roaming\Printer Info Cache
2010-04-13 07:15 . 2010-04-13 07:15 3261624 ----a-w- c:\programdata\TaxCut\2009\Downloads\HRBlockWI.exe
2010-04-13 06:27 . 2010-04-09 15:30 -------- d-----w- c:\programdata\TaxCut
2010-04-13 06:27 . 2010-04-13 06:27 139264 ----a-r- c:\users\Eric\AppData\Roaming\Microsoft\Installer\{BBB33AD6-BCF7-4002-B6A0-6DC679AE5C18}\ARPPRODUCTICON.exe
2010-04-12 23:20 . 2010-04-12 23:20 -------- d-----w- c:\programdata\Wolters Kluwer
2010-04-12 22:59 . 2010-04-12 22:58 -------- dc----w- c:\program files\Common Files\CCHSFS
2010-04-09 22:10 . 2010-04-09 22:10 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-04-09 22:10 . 2010-04-09 22:10 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-04-09 22:10 . 2010-04-09 22:10 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-04-09 22:10 . 2010-04-09 22:10 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-04-09 22:10 . 2010-04-09 22:10 49152 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-04-09 22:10 . 2010-04-09 22:10 40960 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-04-09 22:10 . 2010-04-09 22:10 341600 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-04-09 22:10 . 2010-04-09 22:10 308808 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-04-09 22:10 . 2010-04-09 22:10 14848 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-04-09 22:10 . 2010-02-19 16:45 -------- d-----w- c:\program files\Common Files\Real
2010-04-09 22:10 . 2010-04-09 22:10 -------- dc----w- c:\program files\Real
2010-04-09 22:10 . 2010-04-09 22:10 -------- dc----w- c:\program files\Common Files\xing shared
2010-04-09 16:55 . 2008-08-21 15:10 109792 ----a-w- c:\users\Colby\AppData\Local\GDIPFONTCACHEV1.DAT
2010-04-09 15:36 . 2010-04-09 15:34 21180296 ----a-w- c:\programdata\TaxCut\2009\Update\US30026901cupd.exe
2010-04-09 15:32 . 2009-04-15 02:57 -------- d-----w- c:\users\Eric\AppData\Roaming\TaxCut
2010-04-09 15:31 . 2010-04-09 15:31 -------- dc----w- c:\program files\PDF995
2010-04-08 00:07 . 2010-04-08 00:06 -------- dc----w- c:\program files\TVersity Codec Pack
2010-04-08 00:07 . 2009-10-20 22:38 -------- d-----w- c:\program files\ffdshow
2010-04-07 22:31 . 2010-03-30 17:55 439816 ----a-w- c:\users\Eric\AppData\Roaming\Real\Update\setup3.11\setup.exe
2010-04-05 16:31 . 2010-04-05 16:31 -------- dc----w- c:\program files\Winamp Toolbar
2010-04-05 16:31 . 2010-04-05 16:31 -------- d-----w- c:\programdata\Winamp Toolbar
2010-04-05 16:31 . 2010-04-05 16:31 -------- dc----w- c:\program files\Common Files\PX Storage Engine
2010-03-20 14:21 . 2008-08-21 07:33 109792 ----a-w- c:\users\Eric\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-20 14:20 . 2008-08-21 14:57 109792 ----a-w- c:\users\Becky\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-18 14:06 . 2008-12-12 21:28 1 ----a-w- c:\users\Eric\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-03-09 16:25 . 2010-04-01 04:22 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42 . 2010-04-01 04:22 834048 ----a-w- c:\windows\system32\wininet.dll
2010-03-04 17:33 . 2010-04-14 12:04 430080 ----a-w- c:\windows\system32\vbscript.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2008-04-06 19:10 241752 ----a-w- c:\program files\Lenovo\VeriFace\IcnOvrly.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Google Update"="c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-09-11 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-17 4702208]
"SkDaemond"="c:\program files\Lenovo\Lenovo Standard Keyboard Driver\SkDaemond.exe" [2006-08-14 61440]
"lenscrset"="c:\windows\system32\lenscrset.exe" [2008-04-06 45056]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-09 202256]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-11 03:52 49152 ----a-w- d:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):5c,28,a0,30,f0,51,ca,01
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-18 136176]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-01-20 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-01-20 8456]
R3 MA311;NETGEAR Wireless LAN Driver;c:\windows\system32\DRIVERS\ma311n51.sys [2002-05-01 54784]
R3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
S0 WinI2C-DDC;WinI2C-DDC Kernel Mode Driver;c:\windows\system32\drivers\DDCDrv.sys [2008-02-14 13680]
S2 OKAV Agent Service;OKAV Agent Service;c:\program files\Trend Micro\OKAVAgent\OKAVAgent.exe [2008-02-01 66824]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-12-02 42368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-05-25 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 18:54]
2010-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-28 12:22]
2010-05-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-28 12:22]
2010-05-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3564387887-612188694-4042294045-1004Core.job
- c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-11 15:45]
2010-05-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3564387887-612188694-4042294045-1004UA.job
- c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-11 15:45]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=yie7c
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\q9dq4sph.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\users\Eric\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\users\Eric\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: d:\program files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: d:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: d:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: d:\program files\Netscape6\nppl3260.dll
FF - plugin: d:\program files\Netscape6\nprjplug.dll
FF - plugin: d:\program files\Netscape6\nprpjplug.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
d:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
d:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
d:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-RTHDBPL - c:\users\Eric\AppData\Roaming\SystemProc\lsass.exe
AddRemove-HijackThis - d:\users\Eric\Downloads\HijackThis.exe
AddRemove-Pdf995 - c:\pdf995\setup.exe
AddRemove-{3BB1501C-1670-4b53-8B67-B1C368BC7227} - c:\program files\Lenovo\PCType\pctype.exe
AddRemove-{FBA4F905-F972-4f94-BE38-D9298B482EC5} - c:\program files\Lenovo\ScreenSaver\setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-25 12:12
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-05-25 12:14:15
ComboFix-quarantined-files.txt 2010-05-25 17:14
Pre-Run: 42,257,633,280 bytes free
Post-Run: 44,375,744,512 bytes free
- - End Of File - - 7601BD98D2844CC9D07AE3A238A562C4
***************************************************************
dds.txt
DDS (Ver_10-03-17.01) - NTFSx86
Run by Eric at 12:16:31.88 on Tue 05/25/2010
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_20
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3062.1883 [GMT -5:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
D:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
D:\Program Files\Gizmo5\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Trend Micro\OKAVAgent\OKAVAgent.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Lenovo\Lenovo Standard Keyboard Driver\SkDaemond.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
D:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\System32\svchost.exe -k wdisvc
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
D:\Users\Eric\Desktop\dds.scr
============== Pseudo HJT Report ===============
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=yie7c
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Google Update] "c:\users\eric\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SkDaemond] c:\program files\lenovo\lenovo standard keyboard driver\SkDaemond.exe
mRun: [lenscrset] c:\windows\system32\lenscrset.exe /run
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [QuickTime Task] "d:\program files\quicktime\QTTask.exe" -atboottime
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [HP Software Update] d:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Winamp Search - c:\programdata\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\eric\appdata\roaming\mozilla\firefox\profiles\q9dq4sph.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
d:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
d:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
d:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
d:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 WinI2C-DDC;WinI2C-DDC Kernel Mode Driver;c:\windows\system32\drivers\ddcdrv.sys [2008-4-6 13680]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 149040]
R2 OKAV Agent Service;OKAV Agent Service;c:\program files\trend micro\okavagent\OKAVAgent.exe [2008-2-1 66824]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-12-2 42368]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-28 136176]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-3-11 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-3-11 8456]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-8-21 21504]
S3 MA311;NETGEAR Wireless LAN Driver;c:\windows\system32\drivers\ma311n51.sys [2002-5-1 54784]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904]
=============== Created Last 30 ================
2010-05-25 17:14:18 0 dcsh--w- C:\$RECYCLE.BIN
2010-05-25 17:04:06 98816 ----a-w- c:\windows\sed.exe
2010-05-25 17:04:06 77312 ----a-w- c:\windows\MBR.exe
2010-05-25 17:04:06 256512 ----a-w- c:\windows\PEV.exe
2010-05-25 17:04:06 161792 ----a-w- c:\windows\SWREG.exe
2010-05-24 17:13:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-24 17:13:57 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-24 14:16:14 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-17 15:04:36 0 d-----w- c:\users\eric\appdata\roaming\webex
2010-05-17 15:03:42 0 d-----w- c:\programdata\WebEx
2010-05-17 02:24:47 0 dc----w- c:\program files\Spybot - Search & Destroy
2010-05-12 12:54:28 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-04-30 13:38:42 0 d-----w- c:\programdata\Alwil Software
==================== Find3M ====================
2010-05-06 15:36:38 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-03-09 16:25:21 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42:17 834048 ----a-w- c:\windows\system32\wininet.dll
2010-03-04 17:33:45 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-01-29 23:18:56 51200 ----a-w- c:\windows\inf\infpub.dat
2010-01-29 23:18:56 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-01-29 23:18:21 86016 ----a-w- c:\windows\inf\infstor.dat
2009-11-18 09:18:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-08-21 17:15:16 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-07-31 13:54:40 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-07-31 13:54:40 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-07-31 13:54:40 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2009-10-16 08:16:01 245760 --sha-w- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 12:16:46.43 ===============