Sorry, I didnt realise that CFscript was to be added to combo fix before every scan.
I added Cfscript and ran combofix.
---
ComboFix 11-03-29.01 - Martha 29/03/2011 22:11:08.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.247.122 [GMT 1:00]
Running from: c:\documents and settings\Martha\Desktop\Something.com.exe
Command switches used :: c:\documents and settings\Martha\Desktop\CFScript.txt
AV: McAfee VirusScan *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\utorrentbar
c:\program files\utorrentbar\GottenAppsContextMenu.xml
c:\program files\utorrentbar\OtherAppsContextMenu.xml
c:\program files\utorrentbar\SharedAppsContextMenu.xml
c:\program files\utorrentbar\tbuTor.dll
c:\program files\utorrentbar\toolbar.cfg
c:\program files\utorrentbar\ToolbarContextMenu.xml
c:\program files\utorrentbar\UNWISE.EXE
c:\program files\utorrentbar\uTorrentBarToolbarHelper.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-02-28 to 2011-03-29 )))))))))))))))))))))))))))))))
.
.
2011-03-27 21:44 . 2011-03-27 21:44 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-03-20 08:15 . 2011-03-20 08:16 -------- d-----w- c:\program files\ERUNT
2011-03-19 19:09 . 2011-03-20 17:21 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-03-19 19:09 . 2011-03-20 00:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-03-19 18:12 . 2011-03-19 18:12 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2011-03-18 12:17 . 2011-03-18 12:17 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-03-18 12:04 . 2011-03-18 12:04 -------- d-----w- c:\documents and settings\Martha\Local Settings\Application Data\Sunbelt Software
2011-03-18 11:55 . 2011-03-19 11:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-03-16 15:56 . 2011-03-16 15:58 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-03-13 14:47 . 2011-03-14 11:07 -------- d-----w- c:\documents and settings\Martha\Application Data\FileZilla
2011-03-13 13:01 . 2011-03-13 13:05 -------- d-----w- c:\program files\FileZilla FTP Client
2011-03-10 10:40 . 2004-04-19 17:53 1706800 ----a-w- c:\windows\system32\gdiplus.dll
2011-03-10 10:40 . 2009-02-06 19:33 180224 ----a-w- c:\windows\system32\cnvshell.dll
2011-03-10 10:39 . 2011-03-10 11:20 -------- d-----w- c:\program files\ImageConverter Plus
2011-03-09 12:53 . 2011-03-09 12:53 -------- d-----w- c:\documents and settings\Martha\Local Settings\Application Data\CutePDF Writer
2011-03-09 12:12 . 2011-03-13 00:10 -------- d-----w- c:\program files\Acro Software
2011-03-09 10:29 . 2011-03-09 10:29 -------- d-----w- c:\documents and settings\Martha\Word flyer templates
2011-03-07 12:11 . 2011-03-07 12:11 -------- d-----w- c:\documents and settings\Martha\Local Settings\Application Data\Conduit
2011-03-03 12:28 . 2011-03-03 12:28 -------- d-----w- c:\documents and settings\Martha\Application Data\Serif
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-27 09:51 . 2011-03-27 09:51 5154 ----a-w- C:\DDSLogAttach.zip
2011-03-18 13:44 . 2005-04-25 23:06 24576 ----a-w- c:\windows\system32\userinit.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-03-28_20.32.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-04-25 23:31 . 2011-03-29 19:39 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2005-04-25 23:31 . 2011-03-28 18:45 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-04-25 23:31 . 2011-03-29 19:39 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-04-25 23:31 . 2011-03-28 18:45 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2011-03-27 19:51 . 2011-03-28 18:45 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-03-29 18:59 . 2011-03-29 19:39 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-03-05 11:42 . 2011-03-29 19:39 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2010-03-05 11:42 . 2011-03-28 18:45 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-15 932288]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
.
c:\documents and settings\Martha\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
procexp.exe [2010-8-3 3887480]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
.
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21/04/2010 00:01 136176]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MBACKMONITOR
*Deregistered* - PROCEXP141
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-20 15:07]
.
2011-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-20 23:00]
.
2011-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-20 23:00]
.
2011-02-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-02-05 12:22]
.
2011-03-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-02-05 12:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.urban75.net/vbulletin/
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Convert with ImageConverter Plus... - c:\program files\ImageConverter Plus\icpwebintegration.exe/200
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-29 22:23
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-03-29 22:28:42
ComboFix-quarantined-files.txt 2011-03-29 21:28
ComboFix2.txt 2011-03-29 17:29
ComboFix3.txt 2011-03-28 20:38
ComboFix4.txt 2011-03-27 18:59
.
Pre-Run: 6,978,945,024 bytes free
Post-Run: 6,954,582,016 bytes free
.
- - End Of File - - FEB2C64EBEFC71F1D9743BDB39393269