Uninstalled BitTorrent as instructed (thanks for the info post!). ComboFix log below, new DDS log is in the next post:
ComboFix 09-11-08.03 - Cal85 11/08/2009 16:38.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1014.461 [GMT -8:00]
Running from: c:\users\Cal85\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2876608432-483462828-314405990-500
c:\users\Cal85\Documents\registry1030.reg
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-10-09 to 2009-11-09 )))))))))))))))))))))))))))))))
.
2009-11-09 00:50 . 2009-11-09 00:55 4096 d-----w- c:\users\Cal85\AppData\Local\temp
2009-11-09 00:50 . 2009-11-09 00:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-30 23:16 . 2009-10-30 23:16 8192 d-----w- C:\SpybotSD
2009-10-30 22:44 . 2009-10-30 22:46 8192 d-----w- c:\program files\SpybotSD
2009-10-30 21:50 . 2009-10-30 21:50 -------- d-----w- c:\users\Cal85\AppData\Local\Threat Expert
2009-10-30 21:43 . 2009-11-07 07:48 0 ----a-w- c:\windows\win32k.sys
2009-10-30 10:02 . 2009-10-30 21:50 -------- d-----w- c:\programdata\SITEguard
2009-10-30 10:01 . 2009-10-30 10:01 -------- d-----w- c:\program files\Common Files\iS3
2009-10-30 10:01 . 2009-10-30 22:12 -------- d-----w- c:\programdata\STOPzilla!
2009-10-30 08:09 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-30 08:09 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-30 08:09 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-30 08:08 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-30 08:08 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-30 08:08 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-30 08:08 . 2009-08-07 02:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-30 08:08 . 2009-08-07 01:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-29 22:21 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-29 22:21 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2(167).dll
2009-10-28 04:54 . 2009-09-10 15:29 311296 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-28 04:54 . 2009-09-10 17:40 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-10-28 04:54 . 2009-09-10 17:39 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-10-28 04:53 . 2009-09-10 15:29 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-23 23:56 . 2009-10-26 07:40 -------- d-----w- c:\users\Cal85\MarioKart
2009-10-21 21:26 . 2009-10-21 21:26 -------- d-----w- c:\users\Cal85\AppData\Local\Yahoo
2009-10-21 21:23 . 2009-10-21 21:26 -------- d-----w- c:\programdata\Yahoo!
2009-10-21 21:23 . 2009-05-27 02:50 607472 ----a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-10-21 21:23 . 2009-10-21 21:23 -------- d-----w- c:\program files\Yahoo!
2009-10-14 03:12 . 2009-08-05 14:28 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 03:12 . 2009-08-05 14:28 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-14 03:08 . 2009-08-31 15:16 428032 ----a-w- c:\windows\system32\EncDec.dll
2009-10-14 03:07 . 2009-08-31 15:21 292352 ----a-w- c:\windows\system32\psisdecd.dll
2009-10-14 03:07 . 2009-08-31 15:17 1244672 ----a-w- c:\windows\system32\mcmde.dll
2009-10-14 02:53 . 2009-09-04 12:38 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-14 02:52 . 2009-09-14 09:50 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-14 02:52 . 2009-04-02 11:50 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-12 08:17 . 2009-10-12 08:17 -------- d-----w- c:\users\Cal85\AppData\Roaming\Template
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-06 00:14 . 2009-10-12 08:17 108 ----a-w- c:\users\Cal85\AppData\Roaming\wklnhst.dat
2009-11-03 04:42 . 2009-10-03 04:10 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-31 00:01 . 2009-09-30 22:52 4096 d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-30 22:35 . 2009-09-30 22:52 8192 d-----w- c:\program files\Spybot - Search & Destroy
2009-10-30 22:00 . 2009-10-30 22:00 528 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-10-30 22:00 . 2009-10-30 21:58 1544 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-10-30 07:47 . 2007-05-31 17:57 -------- d-----w- c:\program files\NetZero
2009-10-30 07:47 . 2006-06-12 00:01 -------- d-----w- c:\program files\SIFXINST
2009-10-19 09:12 . 2009-09-30 09:11 3695616 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-10-19 09:12 . 2009-09-30 09:11 2353992 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-10-14 10:24 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-09-30 09:11 . 2009-09-30 09:11 525792 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\64\DIFxAPI.dll
2009-09-30 09:11 . 2009-09-30 09:11 303976 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
2009-09-30 09:11 . 2009-09-30 09:11 664936 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-09-30 09:11 . 2009-09-30 09:11 562552 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-09-30 09:11 . 2009-09-30 09:11 566632 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-09-30 09:11 . 2009-09-30 09:11 640760 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-09-30 09:11 . 2009-09-30 09:11 520024 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-09-30 09:11 . 2009-09-30 09:11 1028432 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-09-30 09:09 . 2009-09-30 09:09 4096 dc-h--w- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-30 09:08 . 2009-09-30 09:08 -------- d-----w- c:\program files\Lavasoft
2009-09-29 23:38 . 2009-07-31 05:55 4096 d-----w- c:\program files\Digsby
2009-09-29 05:23 . 2007-10-19 04:42 74168 ----a-w- c:\users\Cal85\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-26 05:10 . 2009-07-31 06:07 130280 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-23 22:02 . 2009-09-23 22:00 4096 d-----w- c:\program files\iTunes
2009-09-23 22:00 . 2009-09-23 22:00 -------- d-----w- c:\program files\iPod
2009-09-23 22:00 . 2007-10-20 03:44 -------- d-----w- c:\program files\Common Files\Apple
2009-09-23 21:51 . 2009-09-23 21:51 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2009-09-23 11:22 . 2007-10-20 06:40 8192 d-----w- c:\program files\Trillian
2009-09-14 06:56 . 2007-05-31 17:46 8192 d-----w- c:\programdata\Microsoft Help
2009-09-12 02:55 . 2007-10-20 03:49 -------- d-----w- c:\users\Cal85\AppData\Roaming\Apple Computer
2009-09-11 07:37 . 2009-09-11 07:35 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-11 07:33 . 2009-09-11 07:32 4096 d-----w- c:\program files\QuickTime
2009-09-10 17:38 . 2009-10-14 03:13 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 11:13 . 2009-09-10 10:55 4096 d-----w- c:\programdata\RapidSolution
2009-09-10 11:02 . 2009-09-10 11:02 8192 d-----w- c:\program files\PixiePack Codec Pack
2009-09-10 10:59 . 2009-09-10 10:59 566552 ----a-w- c:\programdata\RapidSolution\Tunebite\WebRipDLLs\MusicLoad.dll
2009-09-10 10:59 . 2009-09-10 10:59 242968 ----a-w- c:\programdata\RapidSolution\Tunebite\WebRipDLLs\PlgSoundclick.dll
2009-09-10 10:59 . 2009-09-10 10:59 156952 ----a-w- c:\programdata\RapidSolution\Tunebite\WebRipDLLs\PlgIJigg.dll
2009-09-10 10:59 . 2009-09-10 10:59 156952 ----a-w- c:\programdata\RapidSolution\Tunebite\WebRipDLLs\PlgPandora.dll
2009-09-10 10:59 . 2009-09-10 10:59 136472 ----a-w- c:\programdata\RapidSolution\Tunebite\WebRipDLLs\PlgLastfm.dll
2009-09-10 10:55 . 2009-09-10 10:55 -------- d-----w- c:\program files\RapidSolution
2009-09-03 17:37 . 2009-09-10 09:40 16640 ----a-w- c:\windows\system32\drivers\WsAudio_DeviceS(1).sys
2009-08-29 03:41 . 2009-09-05 06:23 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-08-29 03:40 . 2009-09-05 06:23 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-29 02:42 . 2009-08-29 02:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-29 02:42 . 2009-08-29 02:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 23:31 . 2009-09-05 06:23 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 22:45 . 2009-09-10 09:59 23096 ----a-w- c:\windows\system32\drivers\DrmRAudio.sys
2009-08-27 14:02 . 2009-10-14 03:13 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:57 . 2009-10-14 03:13 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 13:57 . 2009-10-14 03:13 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 13:56 . 2009-10-14 03:13 72704 ----a-w- c:\windows\system32\admparse.dll
2009-08-27 11:24 . 2009-10-14 03:13 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-27 09:51 . 2009-10-14 03:13 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-08-14 17:16 . 2009-09-09 05:08 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-14 16:42 . 2009-09-09 05:08 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40 . 2009-09-09 05:08 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-09 05:08 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-09 05:08 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-09 05:08 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-09 05:08 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-09 05:08 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-09 05:08 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-09 05:08 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-09 05:08 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 14:24 . 2009-09-09 05:08 813568 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 14:23 . 2009-09-09 05:08 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-07-14 00:16 . 2009-07-14 00:16 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-07-14 00:16 . 2009-07-14 00:16 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\spybotsd\TeaTimer.exe" [2009-01-26 2144088]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-04 133912]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-04 138008]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-04 154392]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-03 638976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-01-30 303104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-05-04 40072]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [9/30/2009 1:12 AM 64160]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\SpybotSD\SDWinSec.exe [10/30/2009 2:44 PM 1153368]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 6:49 AM 1028432]
S3 DrmRAudio;DrmRAudio;c:\windows\System32\drivers\DrmRAudio.sys [9/10/2009 1:59 AM 23096]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [11/2/2006 2:25 AM 2589184]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\System32\drivers\WsAudio_DeviceS(1).sys [9/10/2009 1:40 AM 16640]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
2009-11-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 09:11]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig?hl=en
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=T-6815
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Cal85\AppData\Roaming\Mozilla\Firefox\Profiles\trwel9xe.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
WebBrowser-{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)
AddRemove-Disney's Toontown Online - c:\progra~1\Disney\DISNEY~1\Toontown\UNWISE.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-08 16:54
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8BAABE07]<<
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 31 !
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\SigmaTel\C-Major Audio\WDM\STacSV.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-11-09 17:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-09 01:05
Pre-Run: 46,688,362,496 bytes free
Post-Run: 46,369,546,240 bytes free
- - End Of File - - 0D1F0924419DF0D646816E2FFE06556B