wolfblitz
Posts: 82 +0
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo-over.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo-separator.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\mail.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\maps.bmp
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\menuseparatorback.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modify-save.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modify.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modifyhot.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\music.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\news.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-main.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-search.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-weather.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-weather.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-widgets.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\orange.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\pixsy.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\protect-id.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-buffering.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-connecting.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-playing.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-stopped.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta.ico
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\relatedlinks.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-collapse.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-delete.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-expand.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-feed.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder-remove.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder-rename.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-found.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-reload.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-subscribe.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rssback.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rsstopback.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search-over.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search_button_over_png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search_button_png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-left.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-middle.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-right.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\settings.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\shopping.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\siteinfo.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-bluelite.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-bluesky.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-grey.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-lichen.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-orange.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-yellow.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin.xml
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\technorati.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\throbber.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\toolbarsplitter.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\translate.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\video.bmp
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\vmn.css
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\vmn.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\weather.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\web.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\widgets-square-16px.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\wikipedia.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\yahoosearch.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\yellow.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\youtube.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\zoom.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\components\windowmediator.js
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\manifest.xml
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\searchquband.dll
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\uninstall.exe
c:\program files\Searchqu Toolbar\sysid.ini
c:\program files\Searchqu Toolbar\uninstall.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-06-10 to 2012-07-10 )))))))))))))))))))))))))))))))
.
.
2012-07-08 11:07 . 2012-07-08 11:07 -------- d-sh--w- c:\documents and settings\bon\IECompatCache
2012-07-01 10:13 . 2012-07-01 10:13 -------- d-----w- c:\documents and settings\bon\Application Data\Friday's games
2012-07-01 10:00 . 2012-07-01 10:16 -------- d-----w- C:\Zylom Games
2012-07-01 09:12 . 2012-07-01 10:17 -------- d-----w- c:\program files\Zylom Games
2012-07-01 09:12 . 2012-07-01 09:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom
2012-06-23 16:12 . 2012-06-23 16:12 -------- d-----w- C:\Doctor Who - The Gunpowder Plot
2012-06-22 01:05 . 2012-06-22 01:05 -------- d-----w- c:\documents and settings\bon\AppData
2012-06-16 17:40 . 2012-05-11 14:42 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-17 08:41 . 2012-04-06 19:06 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-17 08:41 . 2011-08-01 05:22 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-02 14:19 . 2010-09-03 11:48 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2010-09-03 11:48 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2010-09-03 09:44 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2010-09-03 09:44 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2010-09-03 09:44 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2010-09-03 11:48 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2010-09-03 11:48 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2010-09-03 09:44 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2010-09-03 09:44 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2006-02-28 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2010-09-03 11:48 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2010-09-03 09:44 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2010-09-03 09:44 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2006-02-28 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2006-02-28 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 13:20 . 2006-02-28 12:00 1863168 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 14:42 . 2006-02-28 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2006-02-28 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2006-02-28 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-05-04 13:12 . 2006-02-28 12:00 2192640 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 22:59 2069120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2010-09-03 09:42 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-14 22:20 . 2012-05-06 07:41 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-07-07_04.27.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-10 19:26 . 2012-07-10 19:26 16384 c:\windows\Temp\Perflib_Perfdata_80.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-08-01 20880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-01-31 258512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=c:\windows\pss\VIA RAID TOOL.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-02 10:07 843712 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-03-27 12:41 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2004-05-12 14:18 241664 ----a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-08-01 03:32 958352 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-08-01 03:32 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-08-01 03:32 3507088 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-08-30 05:48 69632 ----a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 14:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2004-01-15 12:33 49152 ----a-r- c:\windows\system32\VTTimer.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"45323:TCP"= 45323:TCP:*
isabled:utorrent
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [03-06-2012 06:00 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [03-06-2012 06:00 86224]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27-10-2010 19:52 136176]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [13-08-2011 10:06 66112]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27-10-2010 19:52 136176]
S3 iadusb;MT882;c:\windows\system32\drivers\glauiad.sys [03-09-2010 11:00 30336]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [06-05-2012 08:41 113120]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [13-08-2011 10:06 180672]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [13-08-2011 10:06 180672]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc544efd4614b4.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 18:52]
.
2012-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cc544efd998702.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 18:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\bon\Application Data\Mozilla\Firefox\Profiles\mslqpcww.default\
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=394&systemid=406&sr=0&q=
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-DATAMNGR - c:\progra~1\SEARCH~1\Datamngr\DATAMN~1.EXE
AddRemove-Searchqu Toolbar - c:\program files\Searchqu Toolbar\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-10 20:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3760)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
.
**************************************************************************
.
Completion time: 2012-07-10 20:35:41 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-10 19:35
ComboFix2.txt 2012-07-07 04:39
ComboFix3.txt 2011-04-11 17:34
ComboFix4.txt 2011-03-22 20:54
.
Pre-Run: 44,429,430,784 bytes free
Post-Run: 44,405,309,440 bytes free
.
- - End Of File - - 9E943F27AC2EDEA0C38C8409DACA8E42
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo-separator.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\logo.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\mail.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\maps.bmp
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\menuseparatorback.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modify-save.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modify.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\modifyhot.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\music.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\news.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-main.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-search.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-weather.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-weather.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\options\options-widgets.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\orange.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\pixsy.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\protect-id.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-buffering.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-connecting.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-playing.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta-stopped.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\radiobeta.ico
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\relatedlinks.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-collapse.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-delete.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-expand.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-feed.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder-remove.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder-rename.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-folder.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-found.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-reload.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss-subscribe.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rss.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rssback.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\rsstopback.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search-over.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search_button_over_png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\search_button_png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-left.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-middle.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\searchbar\searchbar-background-right.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\settings.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\shopping.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\siteinfo.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-bluelite.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-bluesky.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-grey.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-lichen.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-orange.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin-yellow.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\skin.xml
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\technorati.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\throbber.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\toolbarsplitter.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\translate.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\video.bmp
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\vmn.css
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\vmn.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\weather.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\web.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\widgets-square-16px.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\wikipedia.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\yahoosearch.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\yellow.gif
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\youtube.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\chrome\skin\zoom.png
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\components\windowmediator.js
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\dtUser.exe
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\manifest.xml
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\searchquband.dll
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\searchqudtx.dll
c:\program files\Searchqu Toolbar\Datamngr\ToolBar\uninstall.exe
c:\program files\Searchqu Toolbar\sysid.ini
c:\program files\Searchqu Toolbar\uninstall.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-06-10 to 2012-07-10 )))))))))))))))))))))))))))))))
.
.
2012-07-08 11:07 . 2012-07-08 11:07 -------- d-sh--w- c:\documents and settings\bon\IECompatCache
2012-07-01 10:13 . 2012-07-01 10:13 -------- d-----w- c:\documents and settings\bon\Application Data\Friday's games
2012-07-01 10:00 . 2012-07-01 10:16 -------- d-----w- C:\Zylom Games
2012-07-01 09:12 . 2012-07-01 10:17 -------- d-----w- c:\program files\Zylom Games
2012-07-01 09:12 . 2012-07-01 09:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom
2012-06-23 16:12 . 2012-06-23 16:12 -------- d-----w- C:\Doctor Who - The Gunpowder Plot
2012-06-22 01:05 . 2012-06-22 01:05 -------- d-----w- c:\documents and settings\bon\AppData
2012-06-16 17:40 . 2012-05-11 14:42 521728 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-17 08:41 . 2012-04-06 19:06 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-17 08:41 . 2011-08-01 05:22 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-02 14:19 . 2010-09-03 11:48 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 14:19 . 2010-09-03 11:48 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 14:19 . 2010-09-03 09:44 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 14:19 . 2010-09-03 09:44 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 14:19 . 2010-09-03 09:44 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 14:19 . 2010-09-03 11:48 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 14:19 . 2010-09-03 11:48 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 14:19 . 2010-09-03 09:44 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 14:19 . 2010-09-03 09:44 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 14:19 . 2006-02-28 12:00 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 14:19 . 2010-09-03 11:48 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 14:19 . 2010-09-03 09:44 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 14:19 . 2010-09-03 09:44 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2006-02-28 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2006-02-28 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 13:20 . 2006-02-28 12:00 1863168 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 14:42 . 2006-02-28 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2006-02-28 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2006-02-28 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-05-04 13:12 . 2006-02-28 12:00 2192640 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-03 22:59 2069120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2010-09-03 09:42 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-14 22:20 . 2012-05-06 07:41 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2012-07-07_04.27.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-07-10 19:26 . 2012-07-10 19:26 16384 c:\windows\Temp\Perflib_Perfdata_80.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2011-08-01 20880]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-01-31 258512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=c:\windows\pss\VIA RAID TOOL.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-02 10:07 843712 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-03-27 12:41 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2004-05-12 14:18 241664 ----a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-08-01 03:32 958352 ----a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-08-01 03:32 20880 ----a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-08-01 03:32 3507088 ----a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-08-30 05:48 69632 ----a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 14:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2004-01-15 12:33 49152 ----a-r- c:\windows\system32\VTTimer.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\WINDOWS\\system32\\muzapp.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"45323:TCP"= 45323:TCP:*
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [03-06-2012 06:00 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [03-06-2012 06:00 86224]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27-10-2010 19:52 136176]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [13-08-2011 10:06 66112]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [27-10-2010 19:52 136176]
S3 iadusb;MT882;c:\windows\system32\drivers\glauiad.sys [03-09-2010 11:00 30336]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [06-05-2012 08:41 113120]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [13-08-2011 10:06 180672]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [13-08-2011 10:06 180672]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cc544efd4614b4.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 18:52]
.
2012-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA1cc544efd998702.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 18:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\bon\Application Data\Mozilla\Firefox\Profiles\mslqpcww.default\
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=394&systemid=406&sr=0&q=
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-DATAMNGR - c:\progra~1\SEARCH~1\Datamngr\DATAMN~1.EXE
AddRemove-Searchqu Toolbar - c:\program files\Searchqu Toolbar\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-10 20:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3760)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
.
**************************************************************************
.
Completion time: 2012-07-10 20:35:41 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-10 19:35
ComboFix2.txt 2012-07-07 04:39
ComboFix3.txt 2011-04-11 17:34
ComboFix4.txt 2011-03-22 20:54
.
Pre-Run: 44,429,430,784 bytes free
Post-Run: 44,405,309,440 bytes free
.
- - End Of File - - 9E943F27AC2EDEA0C38C8409DACA8E42