combofixlog2
ComboFix 10-12-04.06 - Terry 12/09/2010 16:11:14.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.688 [GMT -5:00]
Running from: c:\documents and settings\Terry\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Terry\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\TDSSKiller_Quarantine
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\mbr0000\object.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\mbr0000\tsk0000.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\mbr0000\tsk0000.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\object.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\object.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0000.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0000.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0001.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0001.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0002.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0002.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0003.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0003.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0004.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0004.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0005.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0006.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0006.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0007.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0007.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0008.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0000\tdlfs0000\tsk0009.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\mbr0000\object.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\mbr0000\tsk0000.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\mbr0000\tsk0000.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\object.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\object.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0000.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0000.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0001.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0001.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0002.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0002.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0003.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0003.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0004.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0004.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0005.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0005.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0006.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0006.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0007.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0007.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0008.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0008.ini
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0009.dta
c:\tdsskiller_quarantine\04.12.2010_19.55.40\boot0001\tdlfs0000\tsk0009.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\mbr0000\object.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\mbr0000\tsk0000.dta
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\mbr0000\tsk0000.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\object.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\object.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0000.dta
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0000.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0001.dta
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0001.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0002.dta
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0002.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0003.dta
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0003.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0004.dta
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0004.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0005.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0006.dta
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0006.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0007.dta
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0007.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0008.ini
c:\tdsskiller_quarantine\04.12.2010_20.01.22\boot0000\tdlfs0000\tsk0009.ini
.
--------------- FCopy ---------------
c:\windows\ServicePackFiles\i386\spoolsv.exe --> c:\windows\System32\spoolsv.exe
.
((((((((((((((((((((((((( Files Created from 2010-11-09 to 2010-12-09 )))))))))))))))))))))))))))))))
.
2010-12-09 21:11 . 2008-04-14 00:12 57856 -c--a-w- c:\windows\system32\dllcache\spoolsv.exe
2010-12-09 21:11 . 2008-04-14 00:12 57856 ----a-w- c:\windows\system32\spoolsv.exe
2010-12-09 21:01 . 2010-12-09 21:01 -------- d-----w- C:\HijackThis
2010-12-09 02:42 . 2010-12-09 02:42 -------- d-----w- c:\windows\LastGood
2010-12-06 00:50 . 2010-12-06 00:50 -------- d-----w- c:\program files\ESET
2010-12-02 21:24 . 2010-12-02 21:25 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-12-01 03:17 . 2010-12-01 03:17 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-11-29 11:20 . 2010-11-29 11:20 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2010-11-28 05:41 . 2010-11-28 05:41 -------- d-s---w- c:\documents and settings\LocalService\UserData
2010-11-28 04:22 . 2010-11-28 04:22 -------- d-----w- c:\documents and settings\LocalService\Application Data\Talkback
2010-11-27 15:29 . 2010-11-28 04:22 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Thunderbird
2010-11-27 15:29 . 2010-11-27 15:29 -------- d-----w- c:\documents and settings\LocalService\Application Data\Thunderbird
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 22:42 . 2008-12-18 00:13 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 22:42 . 2008-12-18 00:13 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-12 19:17 . 2010-10-06 20:18 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-11-12 19:17 . 2010-10-06 20:18 88544 ----a-w- c:\windows\system32\drivers\mfendisk.sys
2010-11-12 19:17 . 2010-10-06 20:18 84072 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
2010-11-12 19:17 . 2010-10-06 20:18 95600 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-11-12 19:17 . 2010-10-06 20:18 84264 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-11-12 19:17 . 2010-10-06 20:18 55840 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-11-12 19:17 . 2010-10-06 20:18 52104 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-11-12 19:17 . 2010-10-06 20:18 386840 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-11-12 19:17 . 2010-10-06 20:18 313288 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-11-12 19:17 . 2010-10-06 20:18 152960 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-09-18 16:23 . 2002-08-29 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-09-20 19:42 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-09-20 19:42 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-18 06:53 . 2002-08-29 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-11-12 19:17 . 2010-10-11 00:53 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-13 1195920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2010-11-27 01:36 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf D:\System Mechanic Professional 6
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DVD@ccess.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DVD@ccess.lnk
backup=c:\windows\pss\DVD@ccess.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Terry^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Terry\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Terry^Start Menu^Programs^Startup^V CAST Media Monitor.lnk]
path=c:\documents and settings\Terry\Start Menu\Programs\Startup\V CAST Media Monitor.lnk
backup=c:\windows\pss\V CAST Media Monitor.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A Verizon App]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2008-04-23 07:08 483328 -c--a-w- d:\adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
2005-04-04 22:58 856064 -c--a-w- d:\adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
2007-01-19 15:49 49152 ----a-w- c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link Wireless G WDA-1320]
2007-06-11 23:57 1654784 ----a-w- c:\program files\D-Link\Wireless G WDA-1320\AirGCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gene USB Monitor]
2002-12-17 17:58 40960 ----a-r- c:\windows\system32\UMonit2K.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 06:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
2006-11-21 21:08 813912 ----a-w- c:\program files\Microsoft IntelliType Pro\itype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-11-29 22:42 963976 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 15:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-06-23 20:49 7626752 ----a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-06-23 20:49 86016 ----a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2007-12-05 06:41 1626112 ----a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 15:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer]
2006-12-20 22:47 557056 -c--a-w- d:\system mechanic professional 6\SMSystemAnalyzer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-07-27 21:01 68096 ----a-w- c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
2006-03-30 21:45 313472 -c--a-w- d:\adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
2010-03-16 20:28 4281584 ----a-w- c:\program files\verizon\VSP\VerizonServicepoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ServicepointService"=2 (0x2)
"rpcapd"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"d:\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\verizon\\VSP\\ServicepointService.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 JAHCI;JAHCI;c:\windows\system32\drivers\JAHCI.sys [10/3/2006 3:56 PM 33280]
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [12/6/2006 5:59 PM 45056]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [10/6/2010 3:18 PM 84072]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [12/4/2008 1:50 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 1:50 PM 67656]
R2 DVDAccss;DVDAccss;c:\windows\system32\drivers\DVDAccss.sys [1/12/2007 6:30 PM 29156]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [10/6/2010 3:18 PM 271480]
R2 McMPFSvc;McAfee Personal Firewall;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [10/6/2010 3:18 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [10/6/2010 3:18 PM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [10/6/2010 3:18 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\Mcafee\SystemCore\mfevtps.exe [10/6/2010 3:18 PM 141792]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [8/25/2005 3:00 PM 472832]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [10/6/2010 3:18 PM 55840]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [10/6/2010 3:18 PM 313288]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [10/6/2010 3:18 PM 88544]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;c:\windows\system32\drivers\ULILAN51.SYS [12/6/2006 5:59 PM 28672]
S2 0289111291862548mcinstcleanup;McAfee Application Installer Cleanup (0289111291862548);c:\windows\TEMP\028911~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\028911~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [10/6/2010 3:18 PM 88544]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [10/6/2010 3:18 PM 84264]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [9/20/2008 2:42 PM 14336]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 1:50 PM 12872]
S4 gupdate1c99438adfd775e;Google Update Service (gupdate1c99438adfd775e);c:\program files\Google\Update\GoogleUpdate.exe [2/21/2009 10:25 AM 133104]
S4 McOobeSv;McAfee OOBE Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [10/6/2010 3:18 PM 271480]
S4 ServicepointService;ServicepointService;c:\program files\verizon\VSP\ServicepointService.exe [10/6/2010 2:43 PM 689392]
--- Other Services/Drivers In Memory ---
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-12-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-28 22:53]
2010-12-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-21 15:25]
2010-12-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-21 15:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www2.verizon.net/welcome/?version=dsl
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
IE: Convert link target to Adobe PDF - d:\adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - d:\adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Terry\Application Data\Mozilla\Firefox\Profiles\nyr4ezyg.default\
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - component: c:\program files\Mozilla Firefox\components\Scriptff.dll
FF - plugin: c:\documents and settings\Terry\Application Data\Mozilla\Firefox\Profiles\nyr4ezyg.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLM32.DLL
FF - plugin: c:\program files\Verizon\VSP\nprpspa.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Extension: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Extension: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\McAfee\SiteAdvisor
FF - Extension: Personas:
personas@christopher.beard - c:\documents and settings\Terry\Application Data\Mozilla\Firefox\Profiles\nyr4ezyg.default\extensions\personas@christopher.beard
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\documents and settings\Terry\Application Data\Mozilla\Firefox\Profiles\nyr4ezyg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: Adobe DLM (powered by getPlus(R)): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - c:\documents and settings\Terry\Application Data\Mozilla\Firefox\Profiles\nyr4ezyg.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-09 16:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1424)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2010-12-09 16:21:03
ComboFix-quarantined-files.txt 2010-12-09 21:20
ComboFix2.txt 2010-12-07 03:16
Pre-Run: 20,995,051,520 bytes free
Post-Run: 20,974,338,048 bytes free
- - End Of File - - 34B86DCDF052180035A68931D7A2267E