Process:
1) Limewire did not have an uninstall file / Add/Remove item so I just deleted the Limewire folder.
2) Ran JavaRa & removed all Java;
3) Attempted To Install Latest Version Of Java From Site -
Internal Error 2753. regutils.dll
This error occured with the online & offline installer, ended up giving up.
4) Set hidden files / folders to not show (Operating system files hidden already selected);
5) Ran CFScript.txt with ComboFix;
--
Are you aware that it is perfectly normal for IE8 to run multiple versions of iexplore.ese?
--
Rather than running multiple instances IE is starting when I start the laptop up (not anymore but was before) and also trying to connect to the net (Connect / Stay Offline Messages) & also was redirecting URL's so you could never get to the site you enter in the address bar.
ComboFix Log File:
ComboFix 11-06-06.02 - sara cordery 11/06/2011 13:00:26.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.446.148 [GMT 1:00]
Running from: c:\documents and settings\sara cordery\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\sara cordery\Desktop\CFScript.txt
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\all users\application data\Kaspersky Lab Setup Files
c:\documents and settings\all users\application data\Kaspersky Lab Setup Files\Kaspersky PURE 9.1.0.124\English\doc\pure9.1_en.pdf
c:\documents and settings\all users\application data\Kaspersky Lab Setup Files\Kaspersky PURE 9.1.0.124\English\KasperskyPURE.en.msi
c:\documents and settings\all users\application data\Kaspersky Lab Setup Files\Kaspersky PURE 9.1.0.124\English\release_notes_pure9.1_en.doc
c:\documents and settings\all users\application data\Kaspersky Lab Setup Files\Kaspersky PURE 9.1.0.124\English\setup.exe
c:\documents and settings\all users\application data\Kaspersky Lab Setup Files\Kaspersky PURE 9.1.0.124\English\setup.ini
c:\documents and settings\all users\application data\Kaspersky Lab Setup Files\Kaspersky PURE 9.1.0.124\English\setup.reg
c:\program files\CleanMyPC
c:\program files\CleanMyPC\Registry Cleaner\fixlog.ini
c:\program files\CleanMyPC\Registry Cleaner\master.ini
c:\program files\CleanMyPC\Registry Cleaner\RCHelper.exe
c:\program files\CleanMyPC\Registry Cleaner\RCleaner.exe
c:\program files\CleanMyPC\Registry Cleaner\UndoCenter\20110606172434A.cab
c:\program files\CleanMyPC\Registry Cleaner\UndoCenter\20110607151145A.cab
c:\program files\CleanMyPC\Registry Cleaner\UndoCenter\20110607155025A.cab
c:\program files\CleanMyPC\Registry Cleaner\UndoCenter\20110607195402A.cab
c:\program files\CleanMyPC\Registry Cleaner\UnFD.exe
c:\program files\CleanMyPC\Registry Cleaner\unins000.dat
c:\program files\CleanMyPC\Registry Cleaner\unins000.exe
c:\program files\CleanMyPC\Registry Cleaner\update.exe
c:\program files\CleanMyPC\Registry Cleaner\update.urs
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_BLACKBOX
-------\Service_BlackBox
.
.
((((((((((((((((((((((((( Files Created from 2011-05-11 to 2011-06-11 )))))))))))))))))))))))))))))))
.
.
2011-06-08 17:24 . 2011-06-08 17:24 -------- d-----w- c:\documents and settings\sara cordery\Application Data\Avira
2011-06-08 17:14 . 2011-04-01 16:07 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-08 17:14 . 2011-04-01 16:07 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-06-08 17:14 . 2010-06-17 14:27 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2011-06-08 17:14 . 2010-06-17 14:27 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2011-06-08 17:14 . 2011-06-08 17:14 -------- d-----w- c:\program files\Avira
2011-06-08 17:14 . 2011-06-08 17:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2011-06-08 16:03 . 2011-06-08 16:03 194 ---ha-w- C:\aaw7boot.cmd
2011-06-07 23:37 . 2011-05-25 01:00 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-06-07 23:37 . 2011-06-07 23:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2011-06-07 23:37 . 2011-06-07 23:37 -------- d-----w- c:\program files\Lavasoft
2011-06-07 19:40 . 2011-06-07 19:40 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-06-06 16:34 . 2011-06-06 16:34 711728 ----a-w- c:\windows\is-RKVPU.exe
2011-06-04 07:30 . 2011-06-04 07:30 -------- d-----w- C:\$AVG
2011-06-04 03:34 . 2011-06-04 03:34 -------- d-----w- c:\documents and settings\sara cordery\Application Data\AVG10
2011-06-03 21:37 . 2011-06-03 21:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Common Files
2011-06-03 21:11 . 2011-06-08 16:27 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2011-06-03 20:53 . 2011-06-03 20:53 -------- d-----w- c:\documents and settings\sara cordery\Local Settings\Application Data\PackageAware
2011-06-03 20:53 . 2011-06-08 16:23 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2011-06-03 18:56 . 2011-06-03 18:56 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-06-03 18:55 . 2011-06-07 16:43 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-03 18:55 . 2011-06-03 18:55 -------- d-----w- c:\documents and settings\sara cordery\Application Data\SUPERAntiSpyware.com
2011-06-03 18:43 . 2011-06-03 18:44 -------- d-----w- c:\documents and settings\Administrator
2011-06-02 21:38 . 2011-06-02 21:38 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-29 08:11 . 2009-12-15 19:47 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--- c:\windows\is-RKVPU.exe ---
Company:
File Description: Setup/Uninstall
File Version: 51.52.0.0
Product Name:
Copyright:
Original Filename:
File size: 711728
Created time: 2011-06-06 16:34
Modified time: 2011-06-06 16:34
MD5: C8DE25FEFB17627E2237B320CCF30EE1
SHA1: 1EB76F645E9A74E9E45B33FDF4793C889C5A6744
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^sara cordery^Start Menu^Programs^Startup^desktop.ini]
path=c:\documents and settings\sara cordery\Start Menu\Programs\Startup\desktop.ini
backup=c:\windows\pss\desktop.iniStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^sara cordery^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=c:\documents and settings\sara cordery\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=c:\windows\pss\Microsoft Office OneNote 2003 Quick Launch.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
\Program\ [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\%FP%Friendly fts.exe]
2003-05-06 09:28 72192 ----a-w- c:\program files\VoyagerTest\fts.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 22:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 23:46 57344 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-06-28 20:05 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-01 06:39 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DSLAGENTEXE]
2003-08-19 13:47 16384 ------w- c:\program files\BT Voyager 105 ADSL Modem\dslagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DSLSTATEXE]
2003-06-28 16:10 1658965 ------w- c:\program files\BT Voyager 105 ADSL Modem\dslstat.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2008-02-29 02:12 76304 ----a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
2008-02-29 02:12 76304 ----a-w- c:\windows\KHALMNPR.Exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileConnect]
2008-10-09 15:33 2086912 ----a-w- c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
2004-11-17 09:56 1077327 ----a-w- c:\program files\Toshiba\Touch and Launch\PadExe.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 23:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-03-21 14:20 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2005-05-12 09:31 118784 ----a-w- c:\program files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 10:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2004-10-08 21:43 688218 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2004-10-08 21:44 98394 ----a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
2005-04-11 10:26 65536 ----a-w- c:\program files\Toshiba\TOSCDSPD\TOSCDSPD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Hotkey Utility]
2005-08-01 21:25 1093632 ----a-w- c:\program files\Toshiba\Windows Utilities\Hotkey.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [08/06/2011 00:37 64512]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [08/06/2011 18:15 136360]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [25/05/2011 02:00 2151128]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [09/10/2008 16:32 14336]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [04/08/2005 22:09 211200]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\SARACO~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS --> c:\docume~1\SARACO~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\SARACO~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS --> c:\docume~1\SARACO~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/01/2010 14:24 135664]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [03/01/2010 14:24 135664]
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-05-25 01:00]
.
2011-03-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
2011-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-03 13:23]
.
2011-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-03 13:23]
.
2011-06-11 c:\windows\Tasks\User_Feed_Synchronization-{DD5C83BF-206E-4485-BE82-9D7C1B5CFD49}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.nixat.com/
uInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.254
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-CleanMyPC - Registry Cleaner_is1 - c:\program files\CleanMyPC\Registry Cleaner\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-11 13:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(552)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(2268)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\acs.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\snmp.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2011-06-11 13:23:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-11 12:23
ComboFix2.txt 2011-06-08 16:59
.
Pre-Run: 16,076,775,424 bytes free
Post-Run: 15,867,355,136 bytes free
.
- - End Of File - - E530195FC96A81F5A0897B46D0C91A62