Hi Blade81,
I have a weird problem. When I go to
C:\Windows\System32\drivers\etc I see a hosts file with no entry but the default localhost. But when I use run and put
C:\Windows\System32\drivers\etc\hosts I see a hosts file with the bad entries.
64.86.16.97 google.ae
64.86.16.97 google.as
64.86.16.97 google.at
etc...
I am able to delete the empty hosts file, but when I run
C:\Windows\System32\drivers\etc\hosts the hosts file with the bad entries will still pop-up, which is very strange.
Anyway, here's the the combofix log. By the way, my brother used combofix but didn't disable the Anti Virus which then resulted in failure to remove the malware.
ComboFix 09-11-01.04 - User 02/11/2009 14:45.4.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.61.1033.18.2047.1249 [GMT 8:00]
Running from: c:\users\User\Documents\INSTALLER\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: AntiVir Desktop *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\User\AppData\Roaming\Desktopicon
.
((((((((((((((((((((((((( Files Created from 2009-10-02 to 2009-11-02 )))))))))))))))))))))))))))))))
.
2009-10-28 04:22 . 2009-10-28 04:22 -------- d-----w- c:\program files\ERUNT
2009-10-28 02:23 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-28 02:23 . 2009-09-10 15:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-24 00:14 . 2009-10-26 01:54 -------- d-----w- c:\program files\Unlocker
2009-10-14 05:36 . 2009-08-31 13:55 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-10-14 05:36 . 2009-08-31 13:55 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-10-14 03:25 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-14 03:25 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-10-14 03:25 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-10-14 03:25 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
2009-10-14 03:25 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
2009-10-14 03:25 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
2009-10-14 03:22 . 2008-04-05 03:34 15360 ----a-w- c:\windows\system32\pacerprf.dll
2009-10-14 03:22 . 2008-04-05 01:21 72192 ----a-w- c:\windows\system32\drivers\pacer.sys
2009-10-14 03:17 . 2009-08-05 14:22 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 03:17 . 2009-08-05 14:22 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-13 15:23 . 2009-10-13 15:23 -------- d-----w- C:\PerfLogs
2009-10-13 14:34 . 2009-10-13 14:34 -------- d-----w- c:\programdata\Avg7
2009-10-13 04:01 . 2009-10-13 04:01 -------- d-----w- c:\users\User\AppData\Roaming\Malwarebytes
2009-10-13 04:00 . 2009-10-13 04:00 -------- d-----w- c:\programdata\Malwarebytes
2009-10-10 01:57 . 2009-10-10 01:58 -------- d-----w- c:\users\User\AppData\Local\AnVir
2009-10-10 01:41 . 1998-06-17 16:00 89360 ----a-w- c:\windows\system32\VB5DB.DLL
2009-10-09 23:13 . 2009-10-26 03:19 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-09 23:13 . 2009-10-10 01:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-09 23:04 . 2009-10-09 23:04 -------- d-----w- c:\program files\CCleaner
2009-10-09 22:55 . 2009-10-09 23:01 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2009-10-09 22:33 . 2009-10-09 22:33 -------- d-----w- c:\program files\Trend Micro
2009-10-09 11:53 . 2009-10-14 00:53 -------- d-sh--w- c:\programdata\cad9f57
2009-10-09 11:07 . 2009-10-09 11:07 -------- d-----w- c:\users\User\Battlefield 1942
2009-10-09 08:17 . 2009-10-09 08:17 -------- d-----w- C:\Hotspot Shield
2009-10-09 08:13 . 2009-11-01 10:59 -------- d-----w- c:\program files\Hotspot Shield
2009-10-07 00:43 . 2009-10-07 00:52 -------- d-----w- C:\Old PC Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-31 20:13 . 2008-03-29 00:25 68808 ----a-w- c:\users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-30 20:17 . 2008-08-23 01:22 -------- d-----w- c:\programdata\Microsoft Help
2009-10-30 20:16 . 2008-08-23 01:24 -------- d-----w- c:\program files\Microsoft Works
2009-10-18 11:02 . 2009-10-18 11:02 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-10-15 00:54 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-13 15:34 . 2008-03-29 04:15 -------- d-----w- c:\programdata\NVIDIA
2009-10-13 15:25 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-10-13 15:25 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-10-13 15:25 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-10-13 15:25 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-10-13 15:25 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-10-13 15:25 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-10-13 15:13 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-10-13 15:13 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-10-13 14:36 . 2008-04-06 08:22 -------- d-----w- c:\program files\Google
2009-10-13 03:21 . 2008-04-11 04:52 -------- d-----w- c:\programdata\HP Product Assistant
2009-10-13 03:01 . 2009-10-13 03:01 691712 ----a-w- c:\windows\isRS-000.tmp
2009-10-10 01:48 . 2008-04-19 01:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-09 22:42 . 2008-04-06 09:18 -------- d-----w- c:\program files\Windows Live Toolbar
2009-10-05 05:13 . 2008-08-21 04:27 2516 --sha-w- c:\programdata\KGyGaAvL.sys
2009-10-03 06:09 . 2009-10-03 06:09 -------- d-----w- c:\users\User\AppData\Roaming\Apple Computer
2009-10-03 06:09 . 2009-10-03 06:08 -------- d-----w- c:\programdata\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-10-03 06:09 . 2009-10-03 06:08 -------- d-----w- c:\program files\iTunes
2009-10-03 06:08 . 2009-10-03 06:08 -------- d-----w- c:\program files\iPod
2009-10-03 06:08 . 2009-10-03 06:05 -------- d-----w- c:\program files\Common Files\Apple
2009-10-03 06:08 . 2009-10-03 06:06 -------- d-----w- c:\programdata\Apple Computer
2009-10-03 06:07 . 2009-10-03 06:07 -------- d-----w- c:\program files\Bonjour
2009-10-03 06:07 . 2009-10-03 06:06 -------- d-----w- c:\program files\QuickTime
2009-10-03 06:06 . 2009-10-03 06:05 -------- d-----w- c:\program files\Apple Software Update
2009-10-03 06:05 . 2009-10-03 06:05 -------- d-----w- c:\programdata\Apple
2009-10-02 22:23 . 2009-10-02 22:23 -------- d-----w- c:\program files\Chikka Messenger
2009-10-01 02:29 . 2009-10-03 04:54 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-30 01:22 . 2009-09-30 01:22 -------- d-----w- c:\program files\Opera
2009-09-28 23:46 . 2009-09-28 23:47 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-28 23:46 . 2009-09-28 23:46 -------- d-----w- c:\program files\Java
2009-09-28 23:35 . 2009-09-28 23:35 -------- d-----w- c:\programdata\Avira
2009-09-28 23:35 . 2009-09-28 23:35 -------- d-----w- c:\program files\Avira
2009-09-15 20:04 . 2009-09-15 20:04 37376 ----a-w- c:\windows\system32\drivers\HssDrv.sys
2009-09-15 20:04 . 2009-09-15 20:04 32768 ----a-w- c:\windows\system32\drivers\taphss.sys
2009-09-14 09:44 . 2009-10-14 02:01 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-04 12:24 . 2009-10-14 02:01 61440 ----a-w- c:\windows\system32\msasn1.dll
2009-08-28 12:39 . 2009-09-29 07:46 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-29 07:46 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 13:32 . 2009-10-14 05:24 833024 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:29 . 2009-10-14 05:24 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 10:58 . 2009-10-14 05:24 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-17 15:33 . 2009-08-17 15:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 17:07 . 2009-09-29 06:33 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 16:29 . 2009-09-29 06:33 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-09-29 06:33 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:16 . 2009-09-29 06:33 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-09-29 06:33 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-09-29 06:33 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-09-29 06:33 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-09-29 06:33 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-09-29 06:33 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-09-29 06:33 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-07 02:24 . 2009-10-02 09:28 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-07 02:24 . 2009-10-02 09:29 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2009-10-02 09:29 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 02:23 . 2009-10-02 09:28 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2009-10-02 09:29 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-07 01:45 . 2009-10-02 09:29 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-08-07 01:44 . 2009-10-02 09:28 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-08-06 11:23 . 2009-10-02 09:21 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-08-06 10:44 . 2009-10-02 09:21 33792 ----a-w- c:\windows\system32\wuapp.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-10-26_02.55.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-29 00:49 . 2009-11-02 06:40 43406 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-11-02 06:40 62040 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-03-29 00:26 . 2009-11-02 06:40 10174 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1528258781-958764860-922923996-1000_UserData.bin
+ 2008-08-23 01:24 . 2008-11-10 03:41 67472 c:\windows\System32\spool\drivers\w32x86\msonpui.dll
+ 2008-08-23 01:24 . 2008-11-10 03:41 67472 c:\windows\System32\spool\drivers\w32x86\3\msonpui.dll
+ 2008-08-23 01:24 . 2008-11-10 03:41 32656 c:\windows\System32\msonpmon.dll
+ 2006-11-02 13:02 . 2009-11-02 06:40 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2009-10-26 01:55 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2009-11-02 06:40 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2009-10-26 01:55 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2009-11-02 06:40 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:02 . 2009-10-26 01:55 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-08-23 01:24 . 2009-10-30 20:17 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-08-23 01:24 . 2009-10-15 00:35 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-08-23 01:24 . 2009-10-30 20:17 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-08-23 01:24 . 2009-10-15 00:35 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-08-23 01:24 . 2009-10-15 00:35 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-08-23 01:24 . 2009-10-30 20:17 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-10-30 20:16 . 2009-10-30 20:16 10576 c:\windows\assembly\GAC\Policy.11.0.office\12.0.0.0__71e9bce111e9429c\Policy.11.0.Office.dll
+ 2009-10-30 20:16 . 2009-10-30 20:16 11112 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Vbe.Interop.dll
+ 2009-10-30 20:16 . 2009-10-30 20:16 11128 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2009-10-30 20:16 . 2009-10-30 20:16 11136 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.SmartTag.dll
+ 2009-10-30 20:17 . 2009-10-30 20:17 11152 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.PowerPoint.dll
+ 2009-10-30 20:16 . 2009-10-30 20:16 11128 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Graph.dll
+ 2009-10-30 20:16 . 2009-10-30 20:16 11144 c:\windows\assembly\GAC\Policy.11.0.Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Policy.11.0.Microsoft.Office.Interop.Excel.dll
+ 2009-10-30 20:16 . 2009-10-30 20:16 63336 c:\windows\assembly\GAC\Microsoft.Vbe.Interop\12.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-10-30 20:16 . 2009-10-30 20:16 19320 c:\windows\assembly\GAC\Microsoft.Office.Interop.SmartTag\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.SmartTag.dll
+ 2009-10-28 02:23 . 2009-09-10 15:10 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\spwmp.dll
+ 2009-10-28 02:23 . 2009-09-10 15:10 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\dxmasf.dll
+ 2009-09-29 06:13 . 2009-07-15 12:39 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\spwmp.dll
+ 2009-09-29 06:13 . 2009-07-15 12:39 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\dxmasf.dll
+ 2009-10-28 02:23 . 2009-09-10 20:45 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\spwmp.dll
+ 2009-10-28 02:23 . 2009-09-10 20:45 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\dxmasf.dll
+ 2009-09-29 06:13 . 2009-07-14 12:58 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\spwmp.dll
+ 2009-09-29 06:13 . 2009-07-14 12:59 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\dxmasf.dll
+ 2009-10-28 02:23 . 2009-09-10 17:30 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\spwmp.dll
+ 2009-10-28 02:23 . 2009-09-10 17:31 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\dxmasf.dll
+ 2009-10-28 02:23 . 2009-09-10 17:39 7680 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\spwmp.dll
+ 2009-10-28 02:23 . 2009-09-10 17:40 4096 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\dxmasf.dll
- 2009-10-26 01:55 . 2009-10-26 01:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-11-02 06:38 . 2009-11-02 06:38 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-10-26 01:55 . 2009-10-26 01:55 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-11-02 06:38 . 2009-11-02 06:38 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-10-28 02:23 . 2009-09-10 15:10 310784 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6002.22223_none_b05140d2ecdc475e\unregmp2.exe
+ 2009-10-28 02:23 . 2009-09-10 14:58 310784 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6002.18111_none_afd0735fd3b858f5\unregmp2.exe
+ 2009-10-28 02:23 . 2009-09-10 15:23 310784 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6001.22520_none_ae67ce0cefb8a635\unregmp2.exe
+ 2009-10-28 02:23 . 2009-09-10 15:21 310784 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6001.18330_none_add35f6fd6a32535\unregmp2.exe
+ 2009-10-28 02:23 . 2009-09-10 15:14 311296 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6000.21125_none_ac866714f28dca12\unregmp2.exe
+ 2009-10-28 02:23 . 2009-09-10 15:29 311296 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6000.16926_none_abfdf271d96f105d\unregmp2.exe
+ 2009-10-28 02:23 . 2009-09-10 15:10 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmpshare.exe
+ 2009-10-28 02:23 . 2009-09-10 15:10 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmplayer.exe
+ 2009-10-28 02:23 . 2009-09-10 15:10 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmpconfig.exe
+ 2009-09-29 06:13 . 2009-07-15 12:39 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmpshare.exe
+ 2009-10-28 02:23 . 2009-09-10 14:58 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmplayer.exe
+ 2009-09-29 06:13 . 2009-07-15 12:39 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmpconfig.exe
+ 2009-10-28 02:23 . 2009-09-10 15:23 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmpshare.exe
+ 2009-10-28 02:23 . 2009-09-10 15:23 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmplayer.exe
+ 2009-10-28 02:23 . 2009-09-10 15:23 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmpconfig.exe
+ 2009-09-29 06:13 . 2009-07-14 10:58 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmpshare.exe
+ 2009-10-28 02:23 . 2009-09-10 15:21 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmplayer.exe
+ 2009-09-29 06:13 . 2009-07-14 10:59 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmpconfig.exe
+ 2009-10-28 02:23 . 2009-09-10 15:14 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmpshare.exe
+ 2009-10-28 02:23 . 2009-09-10 15:14 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmplayer.exe
+ 2009-10-28 02:23 . 2009-09-10 15:14 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmpconfig.exe
+ 2009-10-28 02:23 . 2009-09-10 15:29 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmpshare.exe
+ 2009-10-28 02:23 . 2009-09-10 15:29 168960 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmplayer.exe
+ 2009-10-28 02:23 . 2009-09-10 15:29 107520 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmpconfig.exe
+ 2008-08-23 01:24 . 2008-11-10 03:41 864144 c:\windows\System32\spool\drivers\w32x86\msonpdrv.dll
+ 2008-08-23 01:24 . 2008-11-10 03:41 864144 c:\windows\System32\spool\drivers\w32x86\3\msonpdrv.dll
- 2006-11-02 10:33 . 2009-10-26 02:01 599942 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-11-02 06:43 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-10-26 02:01 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-11-02 06:43 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 12:47 . 2009-10-30 20:34 285304 c:\windows\System32\FNTCACHE.DAT
+ 2008-08-23 01:24 . 2009-10-30 20:17 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-08-23 01:24 . 2009-10-15 00:35 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-08-23 01:24 . 2009-10-30 20:17 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2008-08-23 01:24 . 2009-10-15 00:35 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2008-08-23 01:24 . 2009-10-15 00:35 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2008-08-23 01:24 . 2009-10-30 20:17 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2008-08-23 01:24 . 2009-10-30 20:17 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2008-08-23 01:24 . 2009-10-15 00:35 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-10-30 20:15 . 2009-10-30 20:15 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2009-04-30 00:47 . 2009-04-30 00:47 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-10-30 20:16 . 2009-10-30 20:16 423784 c:\windows\assembly\GAC\office\12.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-10-30 20:16 . 2009-10-30 20:16 870256 c:\windows\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2009-10-30 20:16 . 2009-10-30 20:16 149352 c:\windows\assembly\GAC\Microsoft.Office.Interop.Graph\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Graph.dll
+ 2009-10-28 02:23 . 2009-09-10 15:10 1418752 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6002.22223_none_b05140d2ecdc475e\setup_wm.exe
+ 2009-10-28 02:23 . 2009-09-10 14:58 1418752 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6002.18111_none_afd0735fd3b858f5\setup_wm.exe
+ 2009-10-28 02:23 . 2009-09-10 15:23 1418752 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6001.22520_none_ae67ce0cefb8a635\setup_wm.exe
+ 2009-10-28 02:23 . 2009-09-10 15:21 1418752 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6001.18330_none_add35f6fd6a32535\setup_wm.exe
+ 2009-10-28 02:23 . 2009-09-10 15:14 1418240 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6000.21125_none_ac866714f28dca12\setup_wm.exe
+ 2009-10-28 02:23 . 2009-09-10 15:29 1418240 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-setup_31bf3856ad364e35_6.0.6000.16926_none_abfdf271d96f105d\setup_wm.exe
+ 2009-10-28 02:23 . 2009-09-10 15:11 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmploc.DLL
+ 2009-10-28 02:23 . 2009-09-10 14:59 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmploc.DLL
+ 2009-10-28 02:23 . 2009-09-10 15:24 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmploc.DLL
+ 2009-10-28 02:23 . 2009-09-10 15:21 8147456 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmploc.DLL
+ 2009-10-28 02:23 . 2009-09-10 15:14 8147968 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmploc.DLL
+ 2009-10-28 02:23 . 2009-09-10 15:29 8147968 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmploc.DLL
- 2006-11-02 10:22 . 2009-10-20 13:51 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2009-10-29 12:45 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 12:47 . 2009-10-15 00:56 2677804 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2006-11-02 12:47 . 2009-10-28 23:16 2677804 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2009-04-04 09:10 . 2009-04-04 09:10 1282560 c:\windows\Installer\5581b.msp
+ 2009-04-04 09:10 . 2009-04-04 09:10 7888384 c:\windows\Installer\55814.msp
+ 2009-04-04 09:10 . 2009-04-04 09:10 9926144 c:\windows\Installer\5580b.msp
+ 2008-08-23 01:24 . 2009-10-30 20:17 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-08-23 01:24 . 2009-10-15 00:35 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-10-30 20:16 . 2009-10-30 20:16 1279848 c:\windows\assembly\GAC\Microsoft.Office.Interop.Excel\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Excel.dll
+ 2009-10-28 02:23 . 2009-09-10 17:10 10627584 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.22223_none_0dc73a70656b2706\wmp.dll
+ 2009-10-28 02:23 . 2009-09-10 16:49 10627584 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6002.18111_none_0d466cfd4c47389d\wmp.dll
+ 2009-10-28 02:23 . 2009-09-10 20:46 10627584 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.22520_none_0bddc7aa684785dd\wmp.dll
+ 2009-10-28 02:23 . 2009-09-10 17:33 10626048 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6001.18330_none_0b49590d4f3204dd\wmp.dll
+ 2009-10-28 02:23 . 2009-09-10 17:31 10622464 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.21125_none_09fc60b26b1ca9ba\wmp.dll
+ 2009-10-28 02:23 . 2009-09-10 17:40 10622464 c:\windows\winsxs\x86_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.0.6000.16926_none_0973ec0f51fdf005\wmp.dll
+ 2009-10-28 02:23 . 2009-09-10 17:33 10626048 c:\windows\System32\wmp.dll
- 2009-09-29 06:13 . 2009-07-14 13:00 10626048 c:\windows\System32\wmp.dll
+ 2009-04-04 03:36 . 2009-04-04 03:36 21390848 c:\windows\Installer\55720.msp
+ 2009-04-04 09:09 . 2009-04-04 09:09 15190016 c:\windows\Installer\55712.msp
+ 2009-09-28 21:00 . 2009-10-28 02:20 310122950 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
+ 2009-04-04 09:08 . 2009-04-04 09:08 343058432 c:\windows\Installer\55801.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Google Update"="c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-10-01 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-11 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-11 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-11 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^User^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
path=c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
backup=c:\windows\pss\ERUNT AutoBackup.lnk.Startup
backupExtension=.Startup
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [29/09/2009 7:35 AM 108289]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [10/10/2009 7:13 AM 1153368]
R3 VMHybrid;VMHybrid service;c:\windows\System32\drivers\VMHybrid.sys [7/05/2008 12:11 AM 1059072]
S3 VST_DPV;VST_DPV;c:\windows\System32\drivers\VSTDPV3.SYS [2/11/2006 6:25 PM 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\System32\drivers\VSTBS23.SYS [2/11/2006 6:25 PM 251904]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-04-06 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 01:20]
2009-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1528258781-958764860-922923996-1000Core.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-01 13:25]
2009-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1528258781-958764860-922923996-1000UA.job
- c:\users\User\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-01 13:25]
2009-11-02 c:\windows\Tasks\User_Feed_Synchronization-{F9FF09AC-153B-4608-B8DC-F5F1858EFF8A}.job
- c:\windows\system32\msfeedssync.exe [2008-07-29 07:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\bjb30s8d.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - plugin: c:\users\User\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-02 14:52
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-11-02 14:54
ComboFix-quarantined-files.txt 2009-11-02 06:54
ComboFix2.txt 2009-10-26 02:56
ComboFix3.txt 2009-10-13 15:59
ComboFix4.txt 2009-10-13 14:26
Pre-Run: 105,990,565,888 bytes free
Post-Run: 105,939,128,320 bytes free
- - End Of File - - FD8AD6E55348C57C03355B6A06DD3B30
Thanks in advance.