Okay, well to start off I can run Windows in normal mode and I tried to run ComboFix in normal mode but it wouldn't let me, it would reboot my computer and it wouldn't continue the process. ComboFix did run though in safe mode and I was able to do the complete scan. I do not have the CD for the operating system on my computer because I downgraded to XP I have the CD for Vista. There is no message when I log on to Normal Mode and I do have internet access but it still redirects me when I search for something in Google.
Here is the log.
ComboFix 10-11-21.01 - Administrator 11/25/2010 11:46:09.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.859 [GMT -5:00]
Running from: c:\documents and settings\Administrator.JAY-BB4D1EF4B91\Desktop\jaynori.exe
Command switches used :: I:\CFScript.txt
FILE ::
"c:\windows\system32\drivers\vewji.sys"
"c:\windows\system32\SETUPAPI.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}\chrome.manifest
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}\chrome\content\_cfg.js
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}\chrome\content\overlay.xul
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}\install.rdf
c:\windows\system32\winlogon.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
c:\windows\system32\midimap.dll . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_eixqcdue
((((((((((((((((((((((((( Files Created from 2010-10-25 to 2010-11-25 )))))))))))))))))))))))))))))))
.
2010-11-22 02:59 . 2010-11-22 03:08 -------- d-----w- C:\jaynori
2010-11-22 02:54 . 2010-11-22 02:54 -------- d-----w- C:\$AVG
2010-11-21 06:13 . 2010-11-21 06:13 -------- d-----w- C:\_OTM
2010-11-05 03:28 . 2010-11-05 03:28 -------- d-----w- C:\extensions
2010-11-05 03:12 . 2010-11-05 03:12 -------- d-----r- C:\MSOCache
2010-11-05 03:10 . 2010-11-05 03:10 -------- d-----w- C:\Intel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 16:23 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:57 . 2009-06-13 17:58 1016320 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:57 . 2009-06-13 17:51 1598464 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-10 05:57 . 2009-06-13 17:35 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 16:17 . 2010-09-08 16:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17 . 2010-09-08 16:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-01 11:51 . 2008-04-14 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:38 . 2009-06-13 17:30 1861888 ----a-w- c:\windows\system32\win32k.sys
.
------- Sigcheck -------
[-] 2009-06-13 . 038CA45522FE9B756EFB90DBFA9141EA . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
[-] 2009-06-13 . EC4D66049FCFE818C1D1738DB9A6E5C8 . 568832 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2009-08-06 . F7B2E1B864661A543338AF598F5B9115 . 79072 . . [7.4.7600.226] . . c:\windows\7SP_Files\wuauclt.exe
[7] 2009-08-06 . 62BB79160F86CD962F312C68C6239BFD . 53472 . . [7.4.7600.226] . . c:\windows\7SP_Files\backup\wuauclt.exe
[-] 2009-08-06 . F7B2E1B864661A543338AF598F5B9115 . 79072 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[-] 2010-08-23 . 54223CA7190149BE59E1D10413AB88F5 . 724992 . . [5.82] . . c:\windows\7SP_Files\comctl32.dll
[7] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\7SP_Files\backup\comctl32.dll
[-] 2010-08-23 . 54223CA7190149BE59E1D10413AB88F5 . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2010-08-23 . 54223CA7190149BE59E1D10413AB88F5 . 724992 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll
[7] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
[-] 2009-05-17 . 45B909FB560A7BED67B3457945999013 . 653312 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll
[-] 2009-05-17 . C6CC0229FA60F9E5A2F9E6FD52878665 . 1064448 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
[-] 2009-05-17 . 303673E56D0524AF50B339BD8618E5AC . 931840 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[-] 2010-09-10 . 4FADACE7BA753F74F23F34E0EB275BD0 . 6182400 . . [8.00.6001.23067] . . c:\windows\7SP_Files\mshtml.dll
[7] 2010-09-10 . 8A03CC037E6B7D1796192815231B0C3F . 5958656 . . [8.00.6001.23067] . . c:\windows\7SP_Files\backup\mshtml.dll
[-] 2010-09-10 . 4FADACE7BA753F74F23F34E0EB275BD0 . 6182400 . . [8.00.6001.23067] . . c:\windows\system32\mshtml.dll
[-] 2010-09-10 . 4FADACE7BA753F74F23F34E0EB275BD0 . 6182400 . . [8.00.6001.23067] . . c:\windows\system32\dllcache\mshtml.dll
[-] 2009-06-13 . C94EE53BB0A926279C4C67522031FB7A . 6077440 . . [8.00.6001.22873] . . c:\windows\ie8updates\KB2360131-IE8\mshtml.dll
[-] 2009-06-13 . 05F5164AC40A1D5DE2188B58DD82101F . 648704 . . [5.1.2600.5512] . . c:\windows\7SP_Files\user32.dll
[-] 2009-06-13 . 99C1ACB1B8F0F2CECC56515E502B5120 . 575488 . . [5.1.2600.5512] . . c:\windows\7SP_Files\backup\user32.dll
[-] 2009-06-13 . 05F5164AC40A1D5DE2188B58DD82101F . 648704 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2010-09-10 . 9B374EFDAD4930CB67C57869E12FCBBF . 1016320 . . [8.00.6001.23060] . . c:\windows\7SP_Files\wininet.dll
[7] 2010-09-10 . 0555E190DCD06B8998E6DDCA42DAEB82 . 919552 . . [8.00.6001.23060] . . c:\windows\7SP_Files\backup\wininet.dll
[-] 2010-09-10 . 9B374EFDAD4930CB67C57869E12FCBBF . 1016320 . . [8.00.6001.23060] . . c:\windows\system32\wininet.dll
[-] 2010-09-10 . 9B374EFDAD4930CB67C57869E12FCBBF . 1016320 . . [8.00.6001.23060] . . c:\windows\system32\dllcache\wininet.dll
[-] 2009-06-13 . A09FCA16773A52C6CB0756D84A5509E4 . 971776 . . [8.00.6001.22873] . . c:\windows\ie8updates\KB2360131-IE8\wininet.dll
[-] 2009-06-13 . C64877ED8A2092D28D5119C8270117EC . 1512448 . . [6.00.2900.5634] . . c:\windows\explorer.exe
[-] 2009-06-13 . 6B29E8DCF44B1E2434C4F6F903AE41C8 . 1512448 . . [6.00.2900.5634] . . c:\windows\7SP_Files\explorer.exe
[-] 2009-06-13 . 7C20A150945965CC47E8289636BF4346 . 2117632 . . [6.00.2900.5634] . . c:\windows\7SP_Files\backup\explorer.exe
[-] 2010-07-16 . 149217B62C933505058C8FC4BBE5FD37 . 1341440 . . [5.1.2600.6010] . . c:\windows\7SP_Files\ole32.dll
[7] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\7SP_Files\backup\ole32.dll
[-] 2010-07-16 . 149217B62C933505058C8FC4BBE5FD37 . 1341440 . . [5.1.2600.6010] . . c:\windows\system32\ole32.dll
[-] 2010-07-16 . 149217B62C933505058C8FC4BBE5FD37 . 1341440 . . [5.1.2600.6010] . . c:\windows\system32\dllcache\ole32.dll
[7] 2009-06-13 . 0A80305BFB7346ACB49FD5611B675EC5 . 1288192 . . [5.1.2600.5685] . . c:\windows\$NtUninstallKB979687$\ole32.dll
[-] 2009-06-13 . CBF5945651C96E471B3A004BBDC36864 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[-] 2009-06-13 . D440FD3EA29AEB8AC99F22986A87D345 . 727904 . . [8.00.6001.18702] . . c:\windows\7SP_Files\IEXPLORE.EXE
[-] 2009-06-13 . 56A2008025323B8D2B49184CC6F3FAA1 . 535904 . . [8.00.6001.18702] . . c:\windows\7SP_Files\backup\IEXPLORE.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-06 280779]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [BU]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-02 16851456]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 138008]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"DigidesignMMERefresh"="c:\program files\Digidesign\Drivers\MMERefresh.exe" [2010-06-16 77824]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"CIAxxxxxxx.exe"="c:\ciaxxxxxxx.exe\CIAxxxxxxx.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-06-13 128512]
c:\documents and settings\Jay Jay\Start Menu\Programs\Startup\
Refresh Icon Cache.lnk - c:\windows\7SP_Files\Refresh Icon Cache\Refresh Icon Cache.exe [2010-11-5 203139]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-11-05 03:22 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [11/4/2010 9:46 PM 12552]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/4/2010 9:46 PM 108552]
R3 MBX2DFU;Digidesign Mbox 2 Firmware Updater;c:\windows\system32\drivers\dgmbx2fu.sys [11/13/2010 10:14 AM 21648]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/4/2010 9:46 PM 335240]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/22/2010 11:20 PM 135336]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe --> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [11/9/2010 7:32 PM 16400]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/4/2010 10:18 PM 236368]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [4/19/2010 12:45 PM 1050440]
S3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [11/9/2010 7:32 PM 85008]
S3 DGUSBAP;Service for Digidesign Mbox2 (WDM);c:\windows\system32\drivers\dgmbx2.sys [11/13/2010 10:14 AM 129040]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/4/2010 10:18 PM 19160]
S3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;c:\windows\system32\drivers\mbx2midk.sys [11/9/2010 7:32 PM 21904]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2/25/2010 10:18 AM 10064]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
2010-11-14 c:\windows\Tasks\Automatic maintenance.job
- c:\program files\TuneUp Utilities 2010\OneClickStarter.exe [2010-04-19 17:51]
2010-11-23 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Jay Jay.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-11-05 20:07]
2010-11-23 c:\windows\Tasks\Malwarebytes' Scheduled Update for Jay Jay.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-11-05 20:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {757ACDF3-519A-40D4-A448-B7C20F55602E} = 4.2.2.1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-25 11:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1957994488-1500820517-1606980848-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,17,3f,4b,0f,7b,e6,e2,47,8f,fd,d4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,17,3f,4b,0f,7b,e6,e2,47,8f,fd,d4,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(784)
c:\windows\system32\SETUPAPI.dll
.
Completion time: 2010-11-25 11:54:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-25 16:54
ComboFix2.txt 2010-11-22 03:18
ComboFix3.txt 2010-11-22 03:08
Pre-Run: 473,249,062,912 bytes free
Post-Run: 473,339,666,432 bytes free
- - End Of File - - 9AFCDCFDD3D78E973F8ACB5BBFDC0268
Here is the log.
ComboFix 10-11-21.01 - Administrator 11/25/2010 11:46:09.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.859 [GMT -5:00]
Running from: c:\documents and settings\Administrator.JAY-BB4D1EF4B91\Desktop\jaynori.exe
Command switches used :: I:\CFScript.txt
FILE ::
"c:\windows\system32\drivers\vewji.sys"
"c:\windows\system32\SETUPAPI.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}\chrome.manifest
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}\chrome\content\_cfg.js
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}\chrome\content\overlay.xul
c:\documents and settings\Jay Jay\Local Settings\Application Data\{30D1A54D-FC50-43F6-8173-0D2E7FAFD035}\install.rdf
c:\windows\system32\winlogon.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
c:\windows\system32\midimap.dll . . . is infected!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_eixqcdue
((((((((((((((((((((((((( Files Created from 2010-10-25 to 2010-11-25 )))))))))))))))))))))))))))))))
.
2010-11-22 02:59 . 2010-11-22 03:08 -------- d-----w- C:\jaynori
2010-11-22 02:54 . 2010-11-22 02:54 -------- d-----w- C:\$AVG
2010-11-21 06:13 . 2010-11-21 06:13 -------- d-----w- C:\_OTM
2010-11-05 03:28 . 2010-11-05 03:28 -------- d-----w- C:\extensions
2010-11-05 03:12 . 2010-11-05 03:12 -------- d-----r- C:\MSOCache
2010-11-05 03:10 . 2010-11-05 03:10 -------- d-----w- C:\Intel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 16:23 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-04-14 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-04-14 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-04-14 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:57 . 2009-06-13 17:58 1016320 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:57 . 2009-06-13 17:51 1598464 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-10 05:57 . 2009-06-13 17:35 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 16:17 . 2010-09-08 16:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 16:17 . 2010-09-08 16:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-01 11:51 . 2008-04-14 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:38 . 2009-06-13 17:30 1861888 ----a-w- c:\windows\system32\win32k.sys
.
------- Sigcheck -------
[-] 2009-06-13 . 038CA45522FE9B756EFB90DBFA9141EA . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
[-] 2009-06-13 . EC4D66049FCFE818C1D1738DB9A6E5C8 . 568832 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2009-08-06 . F7B2E1B864661A543338AF598F5B9115 . 79072 . . [7.4.7600.226] . . c:\windows\7SP_Files\wuauclt.exe
[7] 2009-08-06 . 62BB79160F86CD962F312C68C6239BFD . 53472 . . [7.4.7600.226] . . c:\windows\7SP_Files\backup\wuauclt.exe
[-] 2009-08-06 . F7B2E1B864661A543338AF598F5B9115 . 79072 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[-] 2010-08-23 . 54223CA7190149BE59E1D10413AB88F5 . 724992 . . [5.82] . . c:\windows\7SP_Files\comctl32.dll
[7] 2010-08-23 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82] . . c:\windows\7SP_Files\backup\comctl32.dll
[-] 2010-08-23 . 54223CA7190149BE59E1D10413AB88F5 . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2010-08-23 . 54223CA7190149BE59E1D10413AB88F5 . 724992 . . [5.82] . . c:\windows\system32\dllcache\comctl32.dll
[7] 2010-08-23 . 736B12B725AEB2B07F0241A9F680CB10 . 1054208 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
[-] 2009-05-17 . 45B909FB560A7BED67B3457945999013 . 653312 . . [5.82] . . c:\windows\$NtUninstallKB2296011$\comctl32.dll
[-] 2009-05-17 . C6CC0229FA60F9E5A2F9E6FD52878665 . 1064448 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
[-] 2009-05-17 . 303673E56D0524AF50B339BD8618E5AC . 931840 . . [6.0] . . c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[-] 2010-09-10 . 4FADACE7BA753F74F23F34E0EB275BD0 . 6182400 . . [8.00.6001.23067] . . c:\windows\7SP_Files\mshtml.dll
[7] 2010-09-10 . 8A03CC037E6B7D1796192815231B0C3F . 5958656 . . [8.00.6001.23067] . . c:\windows\7SP_Files\backup\mshtml.dll
[-] 2010-09-10 . 4FADACE7BA753F74F23F34E0EB275BD0 . 6182400 . . [8.00.6001.23067] . . c:\windows\system32\mshtml.dll
[-] 2010-09-10 . 4FADACE7BA753F74F23F34E0EB275BD0 . 6182400 . . [8.00.6001.23067] . . c:\windows\system32\dllcache\mshtml.dll
[-] 2009-06-13 . C94EE53BB0A926279C4C67522031FB7A . 6077440 . . [8.00.6001.22873] . . c:\windows\ie8updates\KB2360131-IE8\mshtml.dll
[-] 2009-06-13 . 05F5164AC40A1D5DE2188B58DD82101F . 648704 . . [5.1.2600.5512] . . c:\windows\7SP_Files\user32.dll
[-] 2009-06-13 . 99C1ACB1B8F0F2CECC56515E502B5120 . 575488 . . [5.1.2600.5512] . . c:\windows\7SP_Files\backup\user32.dll
[-] 2009-06-13 . 05F5164AC40A1D5DE2188B58DD82101F . 648704 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2010-09-10 . 9B374EFDAD4930CB67C57869E12FCBBF . 1016320 . . [8.00.6001.23060] . . c:\windows\7SP_Files\wininet.dll
[7] 2010-09-10 . 0555E190DCD06B8998E6DDCA42DAEB82 . 919552 . . [8.00.6001.23060] . . c:\windows\7SP_Files\backup\wininet.dll
[-] 2010-09-10 . 9B374EFDAD4930CB67C57869E12FCBBF . 1016320 . . [8.00.6001.23060] . . c:\windows\system32\wininet.dll
[-] 2010-09-10 . 9B374EFDAD4930CB67C57869E12FCBBF . 1016320 . . [8.00.6001.23060] . . c:\windows\system32\dllcache\wininet.dll
[-] 2009-06-13 . A09FCA16773A52C6CB0756D84A5509E4 . 971776 . . [8.00.6001.22873] . . c:\windows\ie8updates\KB2360131-IE8\wininet.dll
[-] 2009-06-13 . C64877ED8A2092D28D5119C8270117EC . 1512448 . . [6.00.2900.5634] . . c:\windows\explorer.exe
[-] 2009-06-13 . 6B29E8DCF44B1E2434C4F6F903AE41C8 . 1512448 . . [6.00.2900.5634] . . c:\windows\7SP_Files\explorer.exe
[-] 2009-06-13 . 7C20A150945965CC47E8289636BF4346 . 2117632 . . [6.00.2900.5634] . . c:\windows\7SP_Files\backup\explorer.exe
[-] 2010-07-16 . 149217B62C933505058C8FC4BBE5FD37 . 1341440 . . [5.1.2600.6010] . . c:\windows\7SP_Files\ole32.dll
[7] 2010-07-16 . 8D51FB47062F2A1A9EFECCEF338A4C46 . 1289216 . . [5.1.2600.6010] . . c:\windows\7SP_Files\backup\ole32.dll
[-] 2010-07-16 . 149217B62C933505058C8FC4BBE5FD37 . 1341440 . . [5.1.2600.6010] . . c:\windows\system32\ole32.dll
[-] 2010-07-16 . 149217B62C933505058C8FC4BBE5FD37 . 1341440 . . [5.1.2600.6010] . . c:\windows\system32\dllcache\ole32.dll
[7] 2009-06-13 . 0A80305BFB7346ACB49FD5611B675EC5 . 1288192 . . [5.1.2600.5685] . . c:\windows\$NtUninstallKB979687$\ole32.dll
[-] 2009-06-13 . CBF5945651C96E471B3A004BBDC36864 . 37376 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[-] 2009-06-13 . D440FD3EA29AEB8AC99F22986A87D345 . 727904 . . [8.00.6001.18702] . . c:\windows\7SP_Files\IEXPLORE.EXE
[-] 2009-06-13 . 56A2008025323B8D2B49184CC6F3FAA1 . 535904 . . [8.00.6001.18702] . . c:\windows\7SP_Files\backup\IEXPLORE.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-06 280779]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [BU]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-01-07 429392]
"RTHDCPL"="RTHDCPL.EXE" [2008-09-02 16851456]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-16 138008]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"DigidesignMMERefresh"="c:\program files\Digidesign\Drivers\MMERefresh.exe" [2010-06-16 77824]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-02 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"CIAxxxxxxx.exe"="c:\ciaxxxxxxx.exe\CIAxxxxxxx.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-06-13 128512]
c:\documents and settings\Jay Jay\Start Menu\Programs\Startup\
Refresh Icon Cache.lnk - c:\windows\7SP_Files\Refresh Icon Cache\Refresh Icon Cache.exe [2010-11-5 203139]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-11-05 03:22 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [11/4/2010 9:46 PM 12552]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/4/2010 9:46 PM 108552]
R3 MBX2DFU;Digidesign Mbox 2 Firmware Updater;c:\windows\system32\drivers\dgmbx2fu.sys [11/13/2010 10:14 AM 21648]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/4/2010 9:46 PM 335240]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/22/2010 11:20 PM 135336]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe --> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [11/9/2010 7:32 PM 16400]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/4/2010 10:18 PM 236368]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [4/19/2010 12:45 PM 1050440]
S3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [11/9/2010 7:32 PM 85008]
S3 DGUSBAP;Service for Digidesign Mbox2 (WDM);c:\windows\system32\drivers\dgmbx2.sys [11/13/2010 10:14 AM 129040]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/4/2010 10:18 PM 19160]
S3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;c:\windows\system32\drivers\mbx2midk.sys [11/9/2010 7:32 PM 21904]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2/25/2010 10:18 AM 10064]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
2010-11-14 c:\windows\Tasks\Automatic maintenance.job
- c:\program files\TuneUp Utilities 2010\OneClickStarter.exe [2010-04-19 17:51]
2010-11-23 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Jay Jay.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-11-05 20:07]
2010-11-23 c:\windows\Tasks\Malwarebytes' Scheduled Update for Jay Jay.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2010-11-05 20:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {757ACDF3-519A-40D4-A448-B7C20F55602E} = 4.2.2.1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-25 11:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1957994488-1500820517-1606980848-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,17,3f,4b,0f,7b,e6,e2,47,8f,fd,d4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,17,3f,4b,0f,7b,e6,e2,47,8f,fd,d4,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(784)
c:\windows\system32\SETUPAPI.dll
.
Completion time: 2010-11-25 11:54:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-25 16:54
ComboFix2.txt 2010-11-22 03:18
ComboFix3.txt 2010-11-22 03:08
Pre-Run: 473,249,062,912 bytes free
Post-Run: 473,339,666,432 bytes free
- - End Of File - - 9AFCDCFDD3D78E973F8ACB5BBFDC0268