Here is the combofix log you asked for. The DDS scan has stopped working. A quick black screen pops up, and then disappears again. C'fix log below...
ComboFix 10-03-27.03 - Adam 28/03/2010 21:03:26.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.991.428 [GMT 11:00]
Running from: c:\documents and settings\Adam\Desktop\getting rid of virus\ComboFix.exe
Command switches used :: c:\documents and settings\Adam\Desktop\getting rid of virus\CFscript.txt
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FILE ::
"c:\documents and settings\Caleb\Application Data\ufxw.exe"
file zipped: c:\documents and settings\Adam\Application Data\ufxw.exe
file zipped: c:\documents and settings\Caleb\My Documents\Downloads\img353.pif
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Adam\Application Data\ufxw.exe
c:\documents and settings\Caleb\Application Data\ufxw.exe
c:\documents and settings\Caleb\My Documents\Downloads\img353.pif
c:\program files\uTorrent
c:\program files\uTorrent\uTorrent.exe
.
((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-28 )))))))))))))))))))))))))))))))
.
2010-03-26 00:46 . 2010-03-26 00:46 -------- d-----w- c:\program files\ESET
2010-03-17 13:47 . 2010-03-17 13:47 77824 ----a-w- c:\documents and settings\Adam\Application Data\Wuala\Program0\WDokan.dll
2010-03-17 13:47 . 2010-03-17 13:47 353792 ----a-w- c:\documents and settings\Adam\Application Data\Wuala\Program0\orangevolt-4n-1.1.1.dll
2010-03-15 06:19 . 2010-03-15 06:19 -------- d-----w- c:\documents and settings\Caleb\Application Data\YouTube Downloader
2010-03-11 11:52 . 2010-03-11 11:52 388096 ----a-r- c:\documents and settings\Adam\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-03-11 11:52 . 2010-03-11 11:52 -------- d-----w- c:\program files\TrendMicro
2010-03-09 08:23 . 2010-03-09 08:23 -------- d--h--w- c:\windows\PIF
2010-03-06 04:26 . 2010-03-06 05:05 -------- d-----w- c:\documents and settings\Adam\Application Data\mIRC
2010-03-06 04:26 . 2010-03-06 04:26 -------- d-----w- c:\program files\mIRC
2010-03-05 12:16 . 2010-03-05 12:16 -------- d-----w- c:\documents and settings\Adam\Application Data\Ahead
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-04-12 00:00 . 2009-11-17 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-03-26 02:04 . 2009-11-16 23:12 -------- d-----w- c:\documents and settings\Adam\Application Data\uTorrent
2010-03-22 05:32 . 2009-11-17 19:16 -------- d-----w- c:\documents and settings\Adam\Application Data\DC++
2010-03-17 18:13 . 2009-12-19 01:41 -------- d-----w- c:\documents and settings\Adam\Application Data\Wuala
2010-03-11 14:37 . 2009-11-17 04:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-10 11:45 . 2009-11-17 19:34 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-10 06:30 . 2009-11-26 04:57 -------- d-----w- c:\documents and settings\Caleb\Application Data\Apple Computer
2010-03-10 00:29 . 2009-11-16 01:44 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-02-24 11:11 . 2009-11-27 07:24 56884 ---ha-w- c:\windows\system32\mlfcache.dat
2010-02-23 23:16 . 2009-11-16 01:45 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-20 00:54 . 2010-02-20 00:52 -------- d-----w- c:\program files\iTunes
2010-02-20 00:53 . 2010-02-20 00:53 -------- d-----w- c:\program files\iPod
2010-02-20 00:53 . 2009-11-16 22:52 -------- d-----w- c:\program files\Common Files\Apple
2010-02-20 00:45 . 2010-02-20 00:43 -------- d-----w- c:\program files\QuickTime
2010-02-20 00:28 . 2010-02-20 00:28 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-07 21:21 . 2009-11-26 03:29 70008 ----a-w- c:\documents and settings\Caleb\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-07 04:31 . 2009-11-16 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-02-07 04:27 . 2009-11-16 01:44 70008 ----a-w- c:\documents and settings\Adam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-07 02:36 . 2010-02-07 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Cakewalk
2010-02-04 06:04 . 2010-02-04 06:04 -------- d-----w- c:\program files\Microsoft
2010-02-04 06:03 . 2010-02-04 06:02 -------- d-----w- c:\program files\Windows Live
2010-02-04 06:03 . 2010-02-04 06:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-02-04 05:57 . 2010-02-04 05:57 -------- d-----w- c:\program files\Common Files\Windows Live
2010-02-02 21:11 . 2010-02-02 12:07 -------- d-----w- c:\documents and settings\Adam\Application Data\Move Networks
2010-02-02 12:07 . 2010-02-02 12:07 127903 ----a-w- c:\documents and settings\Adam\Application Data\Move Networks\uninstall.exe
2010-02-02 12:07 . 2009-05-27 23:29 4183416 ----a-w- c:\documents and settings\Adam\Application Data\Move Networks\plugins\npqmp071502000008.dll
2010-01-04 23:58 . 2010-01-04 23:58 52356 ----a-w- c:\documents and settings\Adam\Application Data\Wuala\Program0\fec16.dll
2009-12-31 16:50 . 2008-04-13 13:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys
.
------- Sigcheck -------
[-] 2008-05-14 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-20_23.46.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-28 07:37 . 2010-03-28 07:37 16384 c:\windows\Temp\Perflib_Perfdata_694.dat
+ 2010-03-24 12:40 . 2010-03-24 12:40 5527040 c:\windows\Installer\9cd538.msp
+ 2009-10-27 09:34 . 2009-10-27 09:34 5009408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\authplay.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-07-14 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 77824]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-20 1093208]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-08 149280]
"UsbBoost"="c:\program files\UsbBoost\TurboHddUsb.exe" [2009-12-19 3788800]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\Adam\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
FirePod Control Panel.lnk - c:\program files\PreSonus\1394AudioDriver_FIREPOD\FirePod.exe [2009-11-17 1126400]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-11-16 331776]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\progra~1\Qualcomm\Eudora\EuShlExt.dll" [2005-11-14 86016]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"x:\\HALO\\halo.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\Adam\\Application Data\\Wuala\\Roaming\\Wuala.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [19/12/2009 12:34 PM 7936]
R2 ScFBPNT;CanoScan FBP Port Driver;c:\windows\system32\drivers\SCFBPNT.SYS [8/12/2009 1:48 PM 16288]
S3 FNETTBOH;FNETTBOH;c:\windows\system32\drivers\FNETTBOH.SYS [19/12/2009 12:34 PM 23680]
S3 ps_1394;ps_1394;c:\windows\system32\drivers\ps_1394.sys [17/11/2009 9:45 AM 97152]
S3 ps_avs;ps_avs;c:\windows\system32\drivers\ps_avs.sys [17/11/2009 9:45 AM 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-12-06 12:18 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-03-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
2010-03-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 07:02]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Adam\Application Data\Mozilla\Firefox\Profiles\pd67blls.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Adam\Application Data\Move Networks\plugins\npqmp071502000008.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-uTorrent - c:\program files\uTorrent\uTorrent.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-28 21:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
.
Completion time: 2010-03-28 21:14:00
ComboFix-quarantined-files.txt 2010-03-28 10:13
ComboFix2.txt 2010-03-24 12:16
ComboFix3.txt 2010-03-23 02:38
ComboFix4.txt 2010-03-23 02:20
ComboFix5.txt 2010-03-28 10:02
Pre-Run: 126,497,615,872 bytes free
Post-Run: 126,479,900,672 bytes free
- - End Of File - - CA61ECB7A51E7861942407168145F78C
ComboFix 10-03-27.03 - Adam 28/03/2010 21:03:26.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.991.428 [GMT 11:00]
Running from: c:\documents and settings\Adam\Desktop\getting rid of virus\ComboFix.exe
Command switches used :: c:\documents and settings\Adam\Desktop\getting rid of virus\CFscript.txt
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FILE ::
"c:\documents and settings\Caleb\Application Data\ufxw.exe"
file zipped: c:\documents and settings\Adam\Application Data\ufxw.exe
file zipped: c:\documents and settings\Caleb\My Documents\Downloads\img353.pif
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Adam\Application Data\ufxw.exe
c:\documents and settings\Caleb\Application Data\ufxw.exe
c:\documents and settings\Caleb\My Documents\Downloads\img353.pif
c:\program files\uTorrent
c:\program files\uTorrent\uTorrent.exe
.
((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-28 )))))))))))))))))))))))))))))))
.
2010-03-26 00:46 . 2010-03-26 00:46 -------- d-----w- c:\program files\ESET
2010-03-17 13:47 . 2010-03-17 13:47 77824 ----a-w- c:\documents and settings\Adam\Application Data\Wuala\Program0\WDokan.dll
2010-03-17 13:47 . 2010-03-17 13:47 353792 ----a-w- c:\documents and settings\Adam\Application Data\Wuala\Program0\orangevolt-4n-1.1.1.dll
2010-03-15 06:19 . 2010-03-15 06:19 -------- d-----w- c:\documents and settings\Caleb\Application Data\YouTube Downloader
2010-03-11 11:52 . 2010-03-11 11:52 388096 ----a-r- c:\documents and settings\Adam\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-03-11 11:52 . 2010-03-11 11:52 -------- d-----w- c:\program files\TrendMicro
2010-03-09 08:23 . 2010-03-09 08:23 -------- d--h--w- c:\windows\PIF
2010-03-06 04:26 . 2010-03-06 05:05 -------- d-----w- c:\documents and settings\Adam\Application Data\mIRC
2010-03-06 04:26 . 2010-03-06 04:26 -------- d-----w- c:\program files\mIRC
2010-03-05 12:16 . 2010-03-05 12:16 -------- d-----w- c:\documents and settings\Adam\Application Data\Ahead
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-04-12 00:00 . 2009-11-17 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-03-26 02:04 . 2009-11-16 23:12 -------- d-----w- c:\documents and settings\Adam\Application Data\uTorrent
2010-03-22 05:32 . 2009-11-17 19:16 -------- d-----w- c:\documents and settings\Adam\Application Data\DC++
2010-03-17 18:13 . 2009-12-19 01:41 -------- d-----w- c:\documents and settings\Adam\Application Data\Wuala
2010-03-11 14:37 . 2009-11-17 04:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-10 11:45 . 2009-11-17 19:34 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-10 06:30 . 2009-11-26 04:57 -------- d-----w- c:\documents and settings\Caleb\Application Data\Apple Computer
2010-03-10 00:29 . 2009-11-16 01:44 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-02-24 11:11 . 2009-11-27 07:24 56884 ---ha-w- c:\windows\system32\mlfcache.dat
2010-02-23 23:16 . 2009-11-16 01:45 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-20 00:54 . 2010-02-20 00:52 -------- d-----w- c:\program files\iTunes
2010-02-20 00:53 . 2010-02-20 00:53 -------- d-----w- c:\program files\iPod
2010-02-20 00:53 . 2009-11-16 22:52 -------- d-----w- c:\program files\Common Files\Apple
2010-02-20 00:45 . 2010-02-20 00:43 -------- d-----w- c:\program files\QuickTime
2010-02-20 00:28 . 2010-02-20 00:28 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-07 21:21 . 2009-11-26 03:29 70008 ----a-w- c:\documents and settings\Caleb\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-07 04:31 . 2009-11-16 23:18 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-02-07 04:27 . 2009-11-16 01:44 70008 ----a-w- c:\documents and settings\Adam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-07 02:36 . 2010-02-07 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Cakewalk
2010-02-04 06:04 . 2010-02-04 06:04 -------- d-----w- c:\program files\Microsoft
2010-02-04 06:03 . 2010-02-04 06:02 -------- d-----w- c:\program files\Windows Live
2010-02-04 06:03 . 2010-02-04 06:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-02-04 05:57 . 2010-02-04 05:57 -------- d-----w- c:\program files\Common Files\Windows Live
2010-02-02 21:11 . 2010-02-02 12:07 -------- d-----w- c:\documents and settings\Adam\Application Data\Move Networks
2010-02-02 12:07 . 2010-02-02 12:07 127903 ----a-w- c:\documents and settings\Adam\Application Data\Move Networks\uninstall.exe
2010-02-02 12:07 . 2009-05-27 23:29 4183416 ----a-w- c:\documents and settings\Adam\Application Data\Move Networks\plugins\npqmp071502000008.dll
2010-01-04 23:58 . 2010-01-04 23:58 52356 ----a-w- c:\documents and settings\Adam\Application Data\Wuala\Program0\fec16.dll
2009-12-31 16:50 . 2008-04-13 13:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys
.
------- Sigcheck -------
[-] 2008-05-14 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-03-20_23.46.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-28 07:37 . 2010-03-28 07:37 16384 c:\windows\Temp\Perflib_Perfdata_694.dat
+ 2010-03-24 12:40 . 2010-03-24 12:40 5527040 c:\windows\Installer\9cd538.msp
+ 2009-10-27 09:34 . 2009-10-27 09:34 5009408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\authplay.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-07-14 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 77824]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-20 1093208]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDTray"="c:\program files\Ahead\ODD Toolkit\DVDTray.exe" [2004-09-03 65536]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-13 611712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-08 149280]
"UsbBoost"="c:\program files\UsbBoost\TurboHddUsb.exe" [2009-12-19 3788800]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03 435096]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
c:\documents and settings\Adam\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
FirePod Control Panel.lnk - c:\program files\PreSonus\1394AudioDriver_FIREPOD\FirePod.exe [2009-11-17 1126400]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-11-16 331776]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\progra~1\Qualcomm\Eudora\EuShlExt.dll" [2005-11-14 86016]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"x:\\HALO\\halo.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\Adam\\Application Data\\Wuala\\Roaming\\Wuala.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [19/12/2009 12:34 PM 7936]
R2 ScFBPNT;CanoScan FBP Port Driver;c:\windows\system32\drivers\SCFBPNT.SYS [8/12/2009 1:48 PM 16288]
S3 FNETTBOH;FNETTBOH;c:\windows\system32\drivers\FNETTBOH.SYS [19/12/2009 12:34 PM 23680]
S3 ps_1394;ps_1394;c:\windows\system32\drivers\ps_1394.sys [17/11/2009 9:45 AM 97152]
S3 ps_avs;ps_avs;c:\windows\system32\drivers\ps_avs.sys [17/11/2009 9:45 AM 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-12-06 12:18 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-03-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
2010-03-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 07:02]
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Adam\Application Data\Mozilla\Firefox\Profiles\pd67blls.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Adam\Application Data\Move Networks\plugins\npqmp071502000008.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-uTorrent - c:\program files\uTorrent\uTorrent.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-28 21:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
.
Completion time: 2010-03-28 21:14:00
ComboFix-quarantined-files.txt 2010-03-28 10:13
ComboFix2.txt 2010-03-24 12:16
ComboFix3.txt 2010-03-23 02:38
ComboFix4.txt 2010-03-23 02:20
ComboFix5.txt 2010-03-28 10:02
Pre-Run: 126,497,615,872 bytes free
Post-Run: 126,479,900,672 bytes free
- - End Of File - - CA61ECB7A51E7861942407168145F78C