Morniong
had run Combofix /u as instructed but NP
downloaded and followed below..
THEY ARE GONE:bigthumb::bigthumb:
See log:
anything else you see in the log??
other wise I think were are good
should i remove remove combfix as before?
HR
ComboFix 09-09-25.01 - Administrator 09/26/2009 11:05.5.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.671 [GMT -4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Spybot - Search & Destroy
c:\program files\Spybot - Search & Destroy\advcheck.dll
c:\program files\Spybot - Search & Destroy\HGCWMZUHVHYHRVH.scr
c:\program files\Spybot - Search & Destroy\SpybotSD.exe
.
((((((((((((((((((((((((( Files Created from 2009-08-26 to 2009-09-26 )))))))))))))))))))))))))))))))
.
2009-09-19 04:05 . 2009-09-19 04:05 -------- d-----w- c:\program files\ERUNT
2009-09-17 04:13 . 2009-09-22 01:23 -------- d--h--w- c:\windows\PIF
2009-09-08 03:32 . 2009-09-08 03:32 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-09-06 00:03 . 2004-08-04 04:56 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-09-06 00:03 . 2001-08-18 02:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-09-03 18:07 . 2009-09-03 18:07 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-09-02 21:30 . 2009-09-04 03:55 -------- d-----w- C:\Fraps
2009-09-02 15:39 . 2009-09-08 03:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
2009-09-02 15:33 . 2009-09-02 15:33 -------- d-----w- c:\windows\system32\URTTEMP
2009-09-02 12:24 . 2009-09-02 12:24 -------- d-----w- c:\windows\system32\windows media
2009-09-02 12:24 . 2009-09-02 12:24 -------- d-----w- c:\program files\Windows Media Components
2009-08-29 15:12 . 2009-08-29 15:12 0 ----a-w- c:\windows\nsreg.dat
2009-08-29 15:12 . 2009-08-29 15:12 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-08-29 11:19 . 2009-08-29 11:19 86016 ----a-w- c:\windows\system32\frapsvid.dll
2009-08-28 02:54 . 2009-08-28 02:54 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Help
2009-08-28 02:28 . 2004-08-04 03:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-08-28 02:28 . 2004-08-04 03:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-08-28 00:39 . 2009-08-28 00:39 1329709 ----a-w- c:\windows\Recorder.reg
2009-08-28 00:38 . 2009-08-28 00:38 -------- d-----w- c:\program files\Common Files\Fellowes
2009-08-28 00:37 . 2009-08-28 00:38 -------- d-----w- c:\program files\Pinnacle
2009-08-28 00:23 . 1997-12-23 01:02 23936 ----a-w- c:\windows\system32\drivers\aspi32.sys
2009-08-28 00:23 . 1997-12-23 00:23 5600 ----a-w- c:\windows\system\winaspi.dll
2009-08-28 00:23 . 1997-12-23 00:23 4672 ----a-w- c:\windows\system\wowpost.exe
2009-08-28 00:23 . 1997-12-23 00:23 48128 ----a-w- c:\windows\system32\wnaspi32.dll
2009-08-28 00:23 . 1999-07-07 21:32 138240 ----a-w- c:\windows\system32\Viasetup.dll
2009-08-28 00:23 . 1999-06-29 21:15 25264 ----a-w- c:\windows\system32\ivimci.drv
2009-08-28 00:23 . 1999-08-23 03:00 884736 ----a-w- c:\windows\system32\ivimci32.dll
2009-08-27 17:31 . 2009-08-27 17:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-27 17:31 . 2009-08-27 17:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-26 07:42 . 2009-08-14 05:11 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-26 07:40 . 2009-08-12 03:30 -------- d-----w- c:\program files\Windows Live
2009-09-23 22:03 . 2009-09-23 22:03 -------- d-----w- c:\program files\ESET
2009-09-23 05:47 . 2009-08-12 03:42 -------- d-----w- c:\documents and settings\Administrator\Application Data\Xfire
2009-09-23 03:30 . 2009-08-12 03:42 -------- d-----w- c:\program files\Xfire
2009-09-23 00:54 . 2009-09-23 00:54 -------- d-----w- c:\program files\Gadwin Systems
2009-09-23 00:31 . 2009-08-17 04:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-22 22:42 . 2009-08-22 15:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2009-09-22 22:19 . 2009-08-22 15:31 -------- d-----w- c:\documents and settings\Administrator\Application Data\skypePM
2009-09-22 14:51 . 2009-09-19 04:09 -------- d-----w- c:\program files\Trend Micro
2009-09-22 10:14 . 2009-09-22 10:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-20 06:32 . 2009-08-19 03:12 -------- d-----w- c:\program files\Driver Robot
2009-09-10 18:54 . 2009-09-22 10:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-09-22 10:14 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-02 12:24 . 2007-04-30 20:03 28368 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-02 12:24 . 2009-08-12 03:31 -------- d-----w- c:\program files\Microsoft
2009-08-28 05:11 . 2009-08-14 06:16 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-08-28 05:11 . 2009-08-14 06:16 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-08-28 05:11 . 2009-08-14 06:16 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-08-28 00:27 . 2007-04-30 21:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\CyberLink
2009-08-25 05:05 . 2007-04-30 21:17 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-23 02:10 . 2007-04-30 21:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-22 15:31 . 2009-08-22 15:31 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-22 15:25 . 2009-08-22 15:25 -------- d-----r- c:\program files\Skype
2009-08-22 15:25 . 2009-08-22 15:25 -------- d-----w- c:\program files\Common Files\Skype
2009-08-22 15:25 . 2009-08-22 15:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-08-22 15:02 . 2009-08-22 15:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\teamspeak2
2009-08-22 15:02 . 2009-08-22 15:02 -------- d-----w- c:\program files\Teamspeak2_RC2
2009-08-22 02:34 . 2009-08-22 02:33 -------- d-----w- c:\program files\Good_Fox
2009-08-22 00:49 . 2009-08-22 00:49 -------- d-----w- c:\program files\Fox
2009-08-20 00:51 . 2009-08-20 00:50 -------- d-----w- c:\program files\Realtek AC97
2009-08-19 03:12 . 2009-08-19 03:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\Blitware
2009-08-19 02:04 . 2009-08-19 02:04 -------- d-----w- c:\program files\Logitech
2009-08-19 02:04 . 2009-08-19 02:04 -------- d-----w- c:\program files\Common Files\Logitech
2009-08-14 19:40 . 2009-08-14 15:50 -------- d-----w- c:\program files\ATI Technologies
2009-08-14 19:14 . 2009-08-14 19:14 -------- d-----w- c:\documents and settings\Administrator\Application Data\ATI
2009-08-14 18:37 . 2009-08-14 18:37 -------- d-----w- c:\program files\directx
2009-08-14 15:53 . 2009-08-14 15:53 -------- d-----w- c:\documents and settings\roth\Application Data\ATI
2009-08-14 05:11 . 2009-08-14 05:11 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-08-14 05:10 . 2009-08-14 05:10 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-08-14 05:06 . 2007-04-30 19:46 16168 ----a-w- c:\documents and settings\roth\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-12 03:43 . 2009-08-12 03:43 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-08-12 03:30 . 2009-08-12 03:30 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-08-12 03:14 . 2009-08-12 03:14 -------- d-----w- c:\program files\Common Files\Windows Live
2009-08-12 03:10 . 2009-08-12 03:10 0 ----a-w- c:\windows\ativpsrm.bin
2009-08-12 02:38 . 2009-08-12 02:38 -------- d-----w- c:\program files\MSXML 6.0
2009-08-09 10:30 . 2009-08-09 10:30 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-08-09 10:30 . 2009-08-09 10:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\GetRightToGo
2009-08-06 02:48 . 2009-08-14 05:11 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-08-05 09:11 . 2004-08-04 04:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:53 . 2004-08-04 04:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:53 . 2002-08-29 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-07-26 20:44 . 2009-07-26 20:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 18:55 . 2004-08-04 04:56 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 06:18 . 2004-08-04 04:56 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 16:15 . 2009-07-10 16:15 306544 ----a-w- c:\windows\WLXPGSS.SCR
.
------- Sigcheck -------
[-] 2005-12-17 . 32272BF10467C8ACF1F83138C61D541E . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2008-12-09 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-03-28 57344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2009-06-25 177152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlhr"="c:\windows\System32\AdvPack.Dll" [2004-08-04 99840]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Broadband Networking.lnk - c:\program files\Microsoft Broadband Networking\MSBNTray.exe [2002-8-6 151552]
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Broadband Networking.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Broadband Networking.lnk
backup=c:\windows\pss\Microsoft Broadband Networking.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\AVP2Serv.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R0 VOBID;VOBID;c:\windows\system32\drivers\vobid.sys [5/7/2003 4:36 PM 26679]
R1 vobcom;vobcom;c:\windows\system32\drivers\vobcom.sys [10/4/2001 11:53 AM 9728]
R1 vobiw;vobiw;c:\windows\system32\drivers\vobIW.sys [5/27/2003 12:12 PM 187392]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [8/14/2009 1:11 AM 54752]
R3 cdrdrv;Cdrdrv;c:\windows\system32\drivers\Cdrdrv.sys [12/13/2002 6:33 PM 64000]
S2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [5/1/2007 8:44 AM 6016]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
.
Contents of the 'Scheduled Tasks' folder
2009-09-20 c:\windows\Tasks\Driver Robot.job
- c:\program files\Driver Robot\1.0.9.13\DriverRobot.exe [2009-08-19 13:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hd0rjl1v.default\
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-26 11:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-09-26 11:08
ComboFix-quarantined-files.txt 2009-09-26 15:07
ComboFix2.txt 2009-09-22 14:45
Pre-Run: 59,078,516,736 bytes free
Post-Run: 59,057,725,440 bytes free
214