trouble
Went to get the next copy of the combofix and it was gone so had to run the scan again, at which time my computer froze. Had to turn the computer off and then run the scan again.
ComboFix 08-05-21.2 - Betty Heller 2008-05-21 22:24:09.5 -
FAT32x86
Running from: C:\Documents and Settings\Betty Heller\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-22 to 2008-05-22 )))))))))))))))))))))))))))))))
.
2008-05-21 20:34 . 2008-05-21 20:34 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-21 20:34 . 2008-05-21 20:34 <DIR> d-------- C:\Documents and Settings\Betty Heller\Application Data\Malwarebytes
2008-05-21 20:34 . 2008-05-21 20:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-21 20:34 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-21 20:34 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-21 20:33 . 2008-05-21 20:33 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-21 19:40 . 2008-05-21 19:40 <DIR> d-------- C:\Documents and Settings\Betty Heller\Application Data\Uniblue
2008-05-20 22:32 . 2008-05-20 22:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-16 21:37 . 2008-05-16 21:37 <DIR> d-------- C:\Program Files\ieSpell
2008-05-15 21:49 . 2008-05-15 21:49 <DIR> d-------- C:\kav
2008-05-07 00:12 . 2008-05-07 00:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-07 00:12 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-05-07 00:12 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-04-28 22:03 . 2008-04-28 22:00 691,545 --a------ C:\WINDOWS\unins000.exe
2008-04-28 22:03 . 2008-04-28 22:03 2,557 --a------ C:\WINDOWS\unins000.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-12 02:46 12,296,547 ------w C:\avg7qt.dat
2008-03-25 17:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-03-25 17:56 --------- d-----w C:\Program Files\NCH Swift Sound
2008-03-25 17:56 --------- d-----w C:\Documents and Settings\Betty Heller\Application Data\NCH Swift Sound
2008-03-25 08:11 --------- d-----w C:\Program Files\Reference Assemblies
2008-03-25 08:11 --------- d-----w C:\Program Files\MSBuild
2008-03-25 07:57 --------- d-----w C:\Program Files\MSXML 6.0
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 23:36 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-11-04 16:33 8,459 ----a-w C:\Program Files\install.log
2007-08-08 12:47 1 ----a-w C:\Documents and Settings\Betty Heller\controls.dat
2007-07-18 14:38 65,536 ----a-w C:\Documents and Settings\Betty Heller\jbfmod.dll
2007-07-18 14:38 127,488 ----a-w C:\Documents and Settings\Betty Heller\fmod.dll
.
((((((((((((((((((((((((((((( snapshot@2008-05-14_21.22.44.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-15 02:19:42 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-22 03:19:26 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2000-08-31 13:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 13:00:00 89,504 ----a-w C:\WINDOWS\fdsv.exe
+ 2008-03-25 02:32:44 218,496 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
- 2007-12-24 14:10:14 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-05-17 17:01:46 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6868D8FB-A831-4D25-866F-F53B1FD4EC1E}]
C:\WINDOWS\system32\vturr.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04 1415824]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-08-10 03:29 57344 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2004-06-21 10:57 143360 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-07-27 01:01 68096 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"v4AAefJrq8"= rundll32.exe "C:\WINDOWS\system32\ndaTqsVqrX.dll",DllCleanServer
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdawx]
iifdawx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwim32]
winwim32.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\City of Heroes\\CityOfHeroes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-05-17 01:00:04 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Betty Heller.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2008-05-22 03:20:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-21 22:25:50
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
C:\WINDOWS\EXPLORER.EXE [1536] 0x84335878
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-21 22:26:16
ComboFix-quarantined-files.txt 2008-05-22 03:26:14
ComboFix3.txt 2008-05-15 02:56:16
ComboFix2.txt 2008-05-22 01:57:24
Pre-Run: 1,137,115,136 bytes free
Post-Run: 1,127,833,600 bytes free
106 --- E O F --- 2008-05-17 00:26:55