Have run in this order
1. rkill
2. tdskiller
3. Malawarebytes
4. Combofix
Nothing has removed it yet.
Have the following log.
ComboFix 11-08-21.01 - 5961 20/08/2011 21:46:09.5.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.1013.608 [GMT -7:00]
Running from: c:\users\5961\Desktop\virus removers\ComboFix.exe
AV: Emsisoft Anti-Malware *Disabled/Outdated* {0ADC9F7D-20C1-240F-01E2-43466EBA893A}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: Emsisoft Anti-Malware *Disabled/Outdated* {B1BD7E99-06FB-2B81-3B52-7834153DC387}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-07-21 to 2011-08-21 )))))))))))))))))))))))))))))))
.
.
2011-08-21 04:53 . 2011-08-21 04:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-20 07:31 . 2011-08-21 04:53 -------- d-----w- c:\users\5961\AppData\Local\temp
2011-08-19 15:30 . 2011-08-19 15:30 24416 ----a-w- c:\windows\system32\drivers\regguard.sys
2011-08-19 07:06 . 2011-08-20 15:49 -------- d-----w- c:\programdata\PCPitstop
2011-08-19 07:06 . 2011-08-19 07:07 -------- d-----w- c:\program files\PCPitstop
2011-08-19 06:11 . 2011-08-19 06:11 39192 ----a-w- c:\windows\system32\Partizan.exe
2011-08-19 06:11 . 2011-08-19 06:11 35816 ----a-w- c:\windows\system32\drivers\Partizan.sys
2011-08-19 06:10 . 2011-07-27 20:59 11040 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
2011-08-19 06:10 . 2011-08-19 06:12 -------- d-----w- c:\program files\UnHackMe
2011-08-16 17:41 . 2011-08-16 17:54 -------- d-----w- c:\program files\Trojan Guarder Gold Version
2011-08-16 06:08 . 2011-08-16 17:14 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2011-08-16 05:47 . 2006-05-25 21:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2011-08-16 05:47 . 2005-08-26 07:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2011-08-16 05:47 . 2006-06-19 19:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2011-08-16 05:47 . 2002-03-06 07:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2011-08-16 05:47 . 2003-02-03 02:06 153088 ----a-w- c:\windows\system32\unrar3.dll
2011-08-16 05:46 . 2011-08-16 05:48 -------- d-----w- c:\users\5961\AppData\Roaming\Simply Super Software
2011-08-16 05:46 . 2011-08-16 05:46 -------- d-----w- c:\programdata\Simply Super Software
2011-08-16 04:53 . 2011-08-16 04:53 -------- d-----w- c:\program files\Lavasoft
2011-08-16 04:35 . 2011-08-16 04:35 10752 ----a-w- c:\windows\system32\drivers\ZeroAccess.sys
2011-08-14 23:03 . 2011-08-15 04:02 -------- d-----w- C:\Emsisoft Anti-Malware
2011-08-13 14:41 . 2011-08-13 14:41 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2011-08-13 03:31 . 2011-08-16 09:27 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2011-08-12 16:08 . 2011-08-19 16:49 -------- d-----w- c:\programdata\AVAST Software
2011-08-12 16:08 . 2011-08-12 16:08 -------- d-----w- c:\program files\AVAST Software
2011-08-12 07:59 . 2011-08-14 01:38 -------- d-----w- c:\programdata\STOPzilla!
2011-08-12 06:36 . 2011-08-12 06:53 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-08-12 06:35 . 2011-08-12 06:35 -------- d-----w- c:\program files\Hitman Pro 3.5
2011-08-10 11:16 . 2011-06-17 16:03 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-08-10 11:16 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 11:16 . 2011-06-06 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-10 11:16 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-10 11:16 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-10 11:14 . 2011-06-17 20:13 905104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-07 07:23 . 2011-08-07 07:23 75776 ----a-w- c:\windows\system32\dfrgifpsu.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-19 06:11 . 2011-02-10 01:12 26 ----a-w- c:\windows\winstart.bat
2011-08-16 05:02 . 2009-10-30 17:30 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-07-02 16:19 . 2011-05-31 15:30 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-22 19:17 . 2011-06-24 05:22 17280 ----a-w- c:\windows\system32\roboot.exe
2011-06-07 05:18 . 2003-03-19 05:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-06-07 05:18 . 2003-02-21 11:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-06-02 13:34 . 2011-07-13 20:52 2043392 ----a-w- c:\windows\system32\win32k.sys
2006-09-29 23:06 . 2008-01-05 23:43 11205817 ----a-w- c:\program files\Common Files\fcc32.exe
2005-08-03 19:50 . 2008-01-05 23:43 393216 ----a-w- c:\program files\Common Files\fcsmapi.dll
2001-08-23 13:00 . 2008-01-05 23:43 486400 ----a-w- c:\program files\Common Files\dbghelp.dll
2011-06-26 21:14 . 2011-05-01 06:55 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\users\5961\AppData\Roaming\mjusbsp\cdloader2.exe" [2011-05-16 50592]
"Magellan CmTray"="c:\program files\Content Manager\CmTray.exe" [2010-08-24 439296]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-08 39408]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-05-28 412560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-13 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-13 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-13 133912]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2007-01-09 191552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Info Center"="c:\program files\PCPitstop\Info Center\InfoCenter.exe" [2011-08-03 24216]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-05-27 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2007-01-09 191552]
.
c:\users\5961\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\5961\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan\0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-05-27 21:52 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-15 23:19 136176 ----atw- c:\users\5961\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 23:08 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-05-27 04:06 4351216 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-06-15 22:02 15141768 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 23:07 2260480 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 12:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
R1 a2injectiondriver;a2injectiondriver;c:\program files\Emsisoft Anti-Malware\a2dix86.sys [2010-09-05 41928]
R1 a2util;a-squared Malware-IDS utility driver;c:\program files\Emsisoft Anti-Malware\a2util32.sys [2010-05-05 11776]
R2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-06-30 3029208]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-05-28 353168]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-02-21 73728]
R3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys [2011-07-11 18768]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 63364179
*NewlyCreated* - ECACHE
*Deregistered* - 63364179
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
getPlusHelper REG_MULTI_SZ getPlusHelper
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-01-21 06:08]
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:08]
.
2011-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:08]
.
2011-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-141718280-3075198056-734452945-1000Core.job
- c:\users\5961\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 23:19]
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-141718280-3075198056-734452945-1000UA.job
- c:\users\5961\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 23:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254 192.168.1.254
FF - ProfilePath - c:\users\5961\AppData\Roaming\Mozilla\Firefox\Profiles\qm24sn1t.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=402&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-20 21:53
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-141718280-3075198056-734452945-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{793B5EB5-F2AA-3C9E-D10F-FAB4D52CD73E}*]
"halcedjlbcmnddec"=hex:6a,61,61,6d,67,64,6e,68,69,6e,69,67,6f,63,62,66,69,70,
61,6f,00,fa
"iancokodlbmfbikdbi"=hex:6a,61,61,6d,67,64,6e,68,69,6e,69,67,6f,63,62,66,69,70,
61,6f,00,70
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(1464)
c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\igfxsrvc.dll
.
Completion time: 2011-08-20 21:58:42
ComboFix-quarantined-files.txt 2011-08-21 04:58
ComboFix2.txt 2011-08-20 07:31
ComboFix3.txt 2011-08-19 20:04
ComboFix4.txt 2011-08-14 22:55
ComboFix5.txt 2011-08-21 04:43
.
Pre-Run: 9,169,559,552 bytes free
Post-Run: 9,146,372,096 bytes free
.
- - End Of File - - EC9288206B488BDA40EBA09648A5CFD7
1. rkill
2. tdskiller
3. Malawarebytes
4. Combofix
Nothing has removed it yet.
Have the following log.
ComboFix 11-08-21.01 - 5961 20/08/2011 21:46:09.5.2 - x86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.1013.608 [GMT -7:00]
Running from: c:\users\5961\Desktop\virus removers\ComboFix.exe
AV: Emsisoft Anti-Malware *Disabled/Outdated* {0ADC9F7D-20C1-240F-01E2-43466EBA893A}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: Emsisoft Anti-Malware *Disabled/Outdated* {B1BD7E99-06FB-2B81-3B52-7834153DC387}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-07-21 to 2011-08-21 )))))))))))))))))))))))))))))))
.
.
2011-08-21 04:53 . 2011-08-21 04:53 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-20 07:31 . 2011-08-21 04:53 -------- d-----w- c:\users\5961\AppData\Local\temp
2011-08-19 15:30 . 2011-08-19 15:30 24416 ----a-w- c:\windows\system32\drivers\regguard.sys
2011-08-19 07:06 . 2011-08-20 15:49 -------- d-----w- c:\programdata\PCPitstop
2011-08-19 07:06 . 2011-08-19 07:07 -------- d-----w- c:\program files\PCPitstop
2011-08-19 06:11 . 2011-08-19 06:11 39192 ----a-w- c:\windows\system32\Partizan.exe
2011-08-19 06:11 . 2011-08-19 06:11 35816 ----a-w- c:\windows\system32\drivers\Partizan.sys
2011-08-19 06:10 . 2011-07-27 20:59 11040 ----a-w- c:\windows\system32\drivers\UnHackMeDrv.sys
2011-08-19 06:10 . 2011-08-19 06:12 -------- d-----w- c:\program files\UnHackMe
2011-08-16 17:41 . 2011-08-16 17:54 -------- d-----w- c:\program files\Trojan Guarder Gold Version
2011-08-16 06:08 . 2011-08-16 17:14 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2011-08-16 05:47 . 2006-05-25 21:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2011-08-16 05:47 . 2005-08-26 07:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2011-08-16 05:47 . 2006-06-19 19:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2011-08-16 05:47 . 2002-03-06 07:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2011-08-16 05:47 . 2003-02-03 02:06 153088 ----a-w- c:\windows\system32\unrar3.dll
2011-08-16 05:46 . 2011-08-16 05:48 -------- d-----w- c:\users\5961\AppData\Roaming\Simply Super Software
2011-08-16 05:46 . 2011-08-16 05:46 -------- d-----w- c:\programdata\Simply Super Software
2011-08-16 04:53 . 2011-08-16 04:53 -------- d-----w- c:\program files\Lavasoft
2011-08-16 04:35 . 2011-08-16 04:35 10752 ----a-w- c:\windows\system32\drivers\ZeroAccess.sys
2011-08-14 23:03 . 2011-08-15 04:02 -------- d-----w- C:\Emsisoft Anti-Malware
2011-08-13 14:41 . 2011-08-13 14:41 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2011-08-13 03:31 . 2011-08-16 09:27 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2011-08-12 16:08 . 2011-08-19 16:49 -------- d-----w- c:\programdata\AVAST Software
2011-08-12 16:08 . 2011-08-12 16:08 -------- d-----w- c:\program files\AVAST Software
2011-08-12 07:59 . 2011-08-14 01:38 -------- d-----w- c:\programdata\STOPzilla!
2011-08-12 06:36 . 2011-08-12 06:53 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-08-12 06:35 . 2011-08-12 06:35 -------- d-----w- c:\program files\Hitman Pro 3.5
2011-08-10 11:16 . 2011-06-17 16:03 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-08-10 11:16 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 11:16 . 2011-06-06 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-10 11:16 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-10 11:16 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-10 11:14 . 2011-06-17 20:13 905104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-08-07 07:23 . 2011-08-07 07:23 75776 ----a-w- c:\windows\system32\dfrgifpsu.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-19 06:11 . 2011-02-10 01:12 26 ----a-w- c:\windows\winstart.bat
2011-08-16 05:02 . 2009-10-30 17:30 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-07-02 16:19 . 2011-05-31 15:30 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-22 19:17 . 2011-06-24 05:22 17280 ----a-w- c:\windows\system32\roboot.exe
2011-06-07 05:18 . 2003-03-19 05:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-06-07 05:18 . 2003-02-21 11:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-06-02 13:34 . 2011-07-13 20:52 2043392 ----a-w- c:\windows\system32\win32k.sys
2006-09-29 23:06 . 2008-01-05 23:43 11205817 ----a-w- c:\program files\Common Files\fcc32.exe
2005-08-03 19:50 . 2008-01-05 23:43 393216 ----a-w- c:\program files\Common Files\fcsmapi.dll
2001-08-23 13:00 . 2008-01-05 23:43 486400 ----a-w- c:\program files\Common Files\dbghelp.dll
2011-06-26 21:14 . 2011-05-01 06:55 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\users\5961\AppData\Roaming\mjusbsp\cdloader2.exe" [2011-05-16 50592]
"Magellan CmTray"="c:\program files\Content Manager\CmTray.exe" [2010-08-24 439296]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-08 39408]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-05-28 412560]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 4390912]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-13 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-13 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-13 133912]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2007-01-09 191552]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"Info Center"="c:\program files\PCPitstop\Info Center\InfoCenter.exe" [2011-08-03 24216]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-05-27 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2007-01-09 191552]
.
c:\users\5961\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\5961\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0Partizan\0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-05-27 21:52 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-06-15 23:19 136176 ----atw- c:\users\5961\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-01-25 23:08 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-05-27 04:06 4351216 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-06-15 22:02 15141768 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 23:07 2260480 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 12:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
.
R1 a2injectiondriver;a2injectiondriver;c:\program files\Emsisoft Anti-Malware\a2dix86.sys [2010-09-05 41928]
R1 a2util;a-squared Malware-IDS utility driver;c:\program files\Emsisoft Anti-Malware\a2util32.sys [2010-05-05 11776]
R2 a2AntiMalware;Emsisoft Anti-Malware 5.1 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [2011-06-30 3029208]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-05-28 353168]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 a2acc;a2acc;c:\program files\EMSISOFT ANTI-MALWARE\a2accx86.sys [2011-02-21 73728]
R3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\wlh_x86\FileMonitor.sys [2011-07-11 18768]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 63364179
*NewlyCreated* - ECACHE
*Deregistered* - 63364179
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
getPlusHelper REG_MULTI_SZ getPlusHelper
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-01-21 06:08]
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:08]
.
2011-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-26 06:08]
.
2011-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-141718280-3075198056-734452945-1000Core.job
- c:\users\5961\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 23:19]
.
2011-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-141718280-3075198056-734452945-1000UA.job
- c:\users\5961\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-27 23:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254 192.168.1.254
FF - ProfilePath - c:\users\5961\AppData\Roaming\Mozilla\Firefox\Profiles\qm24sn1t.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&systemid=402&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-20 21:53
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-141718280-3075198056-734452945-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{793B5EB5-F2AA-3C9E-D10F-FAB4D52CD73E}*]
"halcedjlbcmnddec"=hex:6a,61,61,6d,67,64,6e,68,69,6e,69,67,6f,63,62,66,69,70,
61,6f,00,fa
"iancokodlbmfbikdbi"=hex:6a,61,61,6d,67,64,6e,68,69,6e,69,67,6f,63,62,66,69,70,
61,6f,00,70
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(1464)
c:\users\5961\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\igfxsrvc.dll
.
Completion time: 2011-08-20 21:58:42
ComboFix-quarantined-files.txt 2011-08-21 04:58
ComboFix2.txt 2011-08-20 07:31
ComboFix3.txt 2011-08-19 20:04
ComboFix4.txt 2011-08-14 22:55
ComboFix5.txt 2011-08-21 04:43
.
Pre-Run: 9,169,559,552 bytes free
Post-Run: 9,146,372,096 bytes free
.
- - End Of File - - EC9288206B488BDA40EBA09648A5CFD7