My sick laptop runs Windows vista Business and Macafee Anti virus and spyware.
Two days ago after I did a restart to my system I got this problem.
Now all drivers do not working.
I run a Combofix and I got the below log report.
Please, I need your help.
Thank you.
ComboFix 12-08-13.01 - Robles 08/15/2012 8:42.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3066.2581 [GMT -5:00]
Running from: c:\users\Robles\Desktop\New\ComboFix03.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-07-15 to 2012-08-15 )))))))))))))))))))))))))))))))
.
.
2012-08-15 13:48 . 2012-08-15 13:48 -------- d-----w- c:\users\Srice\AppData\Local\temp
2012-08-15 13:48 . 2012-08-15 13:48 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-08-15 13:48 . 2012-08-15 13:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-14 22:33 . 2012-08-15 13:48 -------- d-----w- c:\users\Robles\AppData\Local\temp
2012-08-14 22:23 . 2012-08-14 22:33 -------- d-----w- C:\ComboFix03
2012-08-14 22:17 . 2012-08-14 22:17 -------- d-----w- c:\users\Robles\AppData\Local\Adobe
2012-08-14 22:00 . 2009-07-23 06:13 306 ----a-w- c:\windows\myClean.bat
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\users\Robles\AppData\Roaming\PC Utility Kit
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\users\Robles\AppData\Roaming\DriverCure
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\programdata\PC Utility Kit
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\program files\PC Utility Kit
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\program files\Common Files\PC Utility Kit
2012-08-14 21:31 . 2012-08-14 21:31 -------- d-----w- c:\programdata\ErrorEND
2012-08-14 21:31 . 2012-08-14 21:31 -------- d-----w- c:\program files\ErrorEND
2012-08-13 15:49 . 2012-08-13 15:49 -------- d-----w- C:\~ROXTMP
2012-08-13 15:42 . 2012-08-13 15:42 -------- d-----w- c:\users\Robles\AppData\Local\Roxio
2012-08-09 21:04 . 2012-08-09 21:04 -------- d--h--w- c:\programdata\CanonIJEGV
2012-08-09 21:03 . 2012-08-09 21:03 -------- d-----w- c:\program files\Canon
2012-08-09 13:32 . 2012-08-09 13:32 -------- d-----w- c:\users\Srice\AppData\Roaming\PeerNetworking
2012-08-09 13:13 . 2012-06-13 13:40 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-08-09 13:10 . 2012-06-02 08:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-07-25 17:41 . 2012-06-05 16:47 708608 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-25 17:41 . 2012-06-05 16:47 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-25 17:41 . 2012-06-05 16:47 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-25 17:41 . 2012-06-04 15:26 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-25 17:41 . 2012-06-02 00:03 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-25 17:41 . 2012-06-02 00:04 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-25 17:30 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-07-25 17:30 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-07-25 17:30 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-07-25 17:30 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-07-25 17:29 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-07-25 17:29 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-07-25 17:29 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-07-25 17:29 . 2012-06-02 20:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-07-25 17:29 . 2012-06-02 20:12 33792 ----a-w- c:\windows\system32\wuapp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-14 22:14 . 2011-11-19 01:16 17920 ----a-w- c:\windows\system32\rpcnetp.exe
2012-08-14 22:14 . 2011-11-19 00:01 58288 ----a-w- c:\windows\system32\rpcnet.dll
2012-08-09 20:09 . 2011-11-19 01:18 17920 ----a-w- c:\windows\system32\rpcnetp.dll
2012-08-09 19:51 . 2012-05-15 17:28 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-09 19:51 . 2011-11-19 00:24 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-25 21:04 . 2012-06-25 21:04 1394248 ----a-w- c:\windows\system32\msxml4.dll
2011-11-21 04:04 . 2011-12-06 04:30 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\Robles\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\Robles\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\Robles\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-18 13597216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-18 92704]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2008-10-18 96800]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-16 483420]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-07 36864]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-04-30 3888640]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"Monitor.exe"="c:\program files\LinksysOne\LinksysOne Surveillance Utility\Monitor.exe" [2008-02-05 2080768]
"Recorder.exe"="c:\program files\LinksysOne\LinksysOne Surveillance Utility\Recorder.exe" [2008-09-11 409600]
"IndexSearch"="c:\program files\Dell Printers\paperport\PaperPort\IndexSearch.exe" [2010-03-17 46368]
"PaperPort PTD"="c:\program files\Dell Printers\paperport\PaperPort\pptd40nt.exe" [2010-03-17 29984]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"RunMVSMyClean"="c:\windows\myclean.bat" [2009-07-23 306]
"AppRemover2"="wscript.exe" [2009-04-11 155648]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Robles^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\Robles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-21 02:28 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLPSP]
2010-06-01 17:03 886152 ----a-w- c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpsp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLQLU]
2010-06-01 17:03 1127744 ----a-w- c:\program files\Dell Printers\Additional Color Laser Software\Launcher\DLQLU.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLUPDR]
2010-06-01 17:03 566680 ----a-w- c:\program files\Dell Printers\Additional Color Laser Software\Updater\dlupdr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2010-03-17 06:30 46368 ----a-w- c:\program files\Dell Printers\paperport\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-03-27 10:09 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2010-03-17 06:33 29984 ----a-w- c:\program files\Dell Printers\paperport\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF5 Registry Controller]
2010-03-06 01:11 62752 ----a-w- c:\program files\Dell Printers\paperport\PDFViewer\RegistryController.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFHook]
2010-03-06 01:11 636192 ----a-w- c:\program files\Dell Printers\paperport\PDFViewer\pdfPro5Hook.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 20:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rohos]
2011-11-23 18:45 809272 ----a-w- c:\program files\Rohos\agent.exe
.
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ec3a90dd\aestsrv.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-15 19:51]
.
2012-08-14 c:\windows\Tasks\ErrorEND.job
- c:\program files\ErrorEND\ErrorEND.exe [2011-03-09 12:23]
.
2012-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-19 22:58]
.
2012-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-19 22:58]
.
2012-08-14 c:\windows\Tasks\PC Utility Kit Registration3.job
- c:\program files\Common Files\PC Utility Kit\UUS3\UUS3.dll [2012-03-27 19:30]
.
2012-08-14 c:\windows\Tasks\PC Utility Kit Update3.job
- c:\program files\Common Files\PC Utility Kit\UUS3\Update3.exe [2012-03-27 19:30]
.
2012-08-14 c:\windows\Tasks\PC Utility Kit.job
- c:\program files\PC Utility Kit\PC Utility Kit\pcutilitykit.exe [2012-04-10 21:55]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{605E5D27-BFA0-471F-87ED-98A2623D633C} - c:\program files\CADE Pro 2.20.3\Web\new.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 68.94.156.1
FF - ProfilePath - c:\users\Robles\AppData\Roaming\Mozilla\Firefox\Profiles\330f1inw.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-15 08:48
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(1620)
c:\users\Robles\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\BCMWLCPL.CPL
.
Completion time: 2012-08-15 08:49:58
ComboFix-quarantined-files.txt 2012-08-15 13:49
ComboFix2.txt 2012-08-14 22:33
.
Pre-Run: 53,475,725,312 bytes free
Post-Run: 53,435,576,320 bytes free
.
- - End Of File - - 966D5A0B35E410A2DF8A26221BA60D1C
Two days ago after I did a restart to my system I got this problem.
Now all drivers do not working.
I run a Combofix and I got the below log report.
Please, I need your help.
Thank you.
ComboFix 12-08-13.01 - Robles 08/15/2012 8:42.1.2 - x86 NETWORK
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3066.2581 [GMT -5:00]
Running from: c:\users\Robles\Desktop\New\ComboFix03.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-07-15 to 2012-08-15 )))))))))))))))))))))))))))))))
.
.
2012-08-15 13:48 . 2012-08-15 13:48 -------- d-----w- c:\users\Srice\AppData\Local\temp
2012-08-15 13:48 . 2012-08-15 13:48 -------- d-----w- c:\users\Guest\AppData\Local\temp
2012-08-15 13:48 . 2012-08-15 13:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-14 22:33 . 2012-08-15 13:48 -------- d-----w- c:\users\Robles\AppData\Local\temp
2012-08-14 22:23 . 2012-08-14 22:33 -------- d-----w- C:\ComboFix03
2012-08-14 22:17 . 2012-08-14 22:17 -------- d-----w- c:\users\Robles\AppData\Local\Adobe
2012-08-14 22:00 . 2009-07-23 06:13 306 ----a-w- c:\windows\myClean.bat
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\users\Robles\AppData\Roaming\PC Utility Kit
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\users\Robles\AppData\Roaming\DriverCure
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\programdata\PC Utility Kit
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\program files\PC Utility Kit
2012-08-14 21:37 . 2012-08-14 21:37 -------- d-----w- c:\program files\Common Files\PC Utility Kit
2012-08-14 21:31 . 2012-08-14 21:31 -------- d-----w- c:\programdata\ErrorEND
2012-08-14 21:31 . 2012-08-14 21:31 -------- d-----w- c:\program files\ErrorEND
2012-08-13 15:49 . 2012-08-13 15:49 -------- d-----w- C:\~ROXTMP
2012-08-13 15:42 . 2012-08-13 15:42 -------- d-----w- c:\users\Robles\AppData\Local\Roxio
2012-08-09 21:04 . 2012-08-09 21:04 -------- d--h--w- c:\programdata\CanonIJEGV
2012-08-09 21:03 . 2012-08-09 21:03 -------- d-----w- c:\program files\Canon
2012-08-09 13:32 . 2012-08-09 13:32 -------- d-----w- c:\users\Srice\AppData\Roaming\PeerNetworking
2012-08-09 13:13 . 2012-06-13 13:40 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-08-09 13:10 . 2012-06-02 08:16 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-07-25 17:41 . 2012-06-05 16:47 708608 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-07-25 17:41 . 2012-06-05 16:47 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-25 17:41 . 2012-06-05 16:47 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-25 17:41 . 2012-06-04 15:26 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-25 17:41 . 2012-06-02 00:03 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-25 17:41 . 2012-06-02 00:04 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-25 17:30 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-07-25 17:30 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2012-07-25 17:30 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-07-25 17:30 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-07-25 17:29 . 2012-06-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-07-25 17:29 . 2012-06-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-07-25 17:29 . 2012-06-02 22:12 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-07-25 17:29 . 2012-06-02 20:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-07-25 17:29 . 2012-06-02 20:12 33792 ----a-w- c:\windows\system32\wuapp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-14 22:14 . 2011-11-19 01:16 17920 ----a-w- c:\windows\system32\rpcnetp.exe
2012-08-14 22:14 . 2011-11-19 00:01 58288 ----a-w- c:\windows\system32\rpcnet.dll
2012-08-09 20:09 . 2011-11-19 01:18 17920 ----a-w- c:\windows\system32\rpcnetp.dll
2012-08-09 19:51 . 2012-05-15 17:28 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-09 19:51 . 2011-11-19 00:24 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-25 21:04 . 2012-06-25 21:04 1394248 ----a-w- c:\windows\system32\msxml4.dll
2011-11-21 04:04 . 2011-12-06 04:30 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\Robles\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\Robles\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-12-05 19:17 94208 ----a-w- c:\users\Robles\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\ISUSPM.exe" [2009-05-05 222496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-18 13597216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-18 92704]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2008-10-18 96800]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-16 483420]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-07 36864]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-04-30 3888640]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"Monitor.exe"="c:\program files\LinksysOne\LinksysOne Surveillance Utility\Monitor.exe" [2008-02-05 2080768]
"Recorder.exe"="c:\program files\LinksysOne\LinksysOne Surveillance Utility\Recorder.exe" [2008-09-11 409600]
"IndexSearch"="c:\program files\Dell Printers\paperport\PaperPort\IndexSearch.exe" [2010-03-17 46368]
"PaperPort PTD"="c:\program files\Dell Printers\paperport\PaperPort\pptd40nt.exe" [2010-03-17 29984]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"RunMVSMyClean"="c:\windows\myclean.bat" [2009-07-23 306]
"AppRemover2"="wscript.exe" [2009-04-11 155648]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^Users^Robles^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\Robles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-21 02:28 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLPSP]
2010-06-01 17:03 886152 ----a-w- c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpsp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLQLU]
2010-06-01 17:03 1127744 ----a-w- c:\program files\Dell Printers\Additional Color Laser Software\Launcher\DLQLU.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLUPDR]
2010-06-01 17:03 566680 ----a-w- c:\program files\Dell Printers\Additional Color Laser Software\Updater\dlupdr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2010-03-17 06:30 46368 ----a-w- c:\program files\Dell Printers\paperport\PaperPort\IndexSearch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-03-27 10:09 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2010-03-17 06:33 29984 ----a-w- c:\program files\Dell Printers\paperport\PaperPort\pptd40nt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF5 Registry Controller]
2010-03-06 01:11 62752 ----a-w- c:\program files\Dell Printers\paperport\PDFViewer\RegistryController.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFHook]
2010-03-06 01:11 636192 ----a-w- c:\program files\Dell Printers\paperport\PDFViewer\pdfPro5Hook.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 20:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rohos]
2011-11-23 18:45 809272 ----a-w- c:\program files\Rohos\agent.exe
.
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ec3a90dd\aestsrv.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-15 19:51]
.
2012-08-14 c:\windows\Tasks\ErrorEND.job
- c:\program files\ErrorEND\ErrorEND.exe [2011-03-09 12:23]
.
2012-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-19 22:58]
.
2012-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-19 22:58]
.
2012-08-14 c:\windows\Tasks\PC Utility Kit Registration3.job
- c:\program files\Common Files\PC Utility Kit\UUS3\UUS3.dll [2012-03-27 19:30]
.
2012-08-14 c:\windows\Tasks\PC Utility Kit Update3.job
- c:\program files\Common Files\PC Utility Kit\UUS3\Update3.exe [2012-03-27 19:30]
.
2012-08-14 c:\windows\Tasks\PC Utility Kit.job
- c:\program files\PC Utility Kit\PC Utility Kit\pcutilitykit.exe [2012-04-10 21:55]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{605E5D27-BFA0-471F-87ED-98A2623D633C} - c:\program files\CADE Pro 2.20.3\Web\new.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 68.94.156.1
FF - ProfilePath - c:\users\Robles\AppData\Roaming\Mozilla\Firefox\Profiles\330f1inw.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-15 08:48
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(1620)
c:\users\Robles\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\BCMWLCPL.CPL
.
Completion time: 2012-08-15 08:49:58
ComboFix-quarantined-files.txt 2012-08-15 13:49
ComboFix2.txt 2012-08-14 22:33
.
Pre-Run: 53,475,725,312 bytes free
Post-Run: 53,435,576,320 bytes free
.
- - End Of File - - 966D5A0B35E410A2DF8A26221BA60D1C