I have the antivirus soft on my computer. Then, I used ComboFix and i think the virus is almost gone. The pop-ups are gone, and I'm able to download things and open Microsoft WOrd (which I wasnt able to do before). however, the virus is still preventing a connection from my printer to the computer so i cant print anything. Besides for that, everything is normal. what can i do to re-connect my printer to the comp? Here is the log:
ComboFix 10-02-03.04 - stuffx3 02/03/2010 19:48:27.1.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.530 [GMT -8:00]
Running from: c:\documents and settings\stuffx3\My Documents\Downloads\ComboFix.exe
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\stuffx3\LOCALS~1\Temp\7zS2C.tmp\nonlocalized\xpcom.dll
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}\chrome.manifest
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}\chrome\content\_cfg.js
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}\chrome\content\overlay.xul
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}\install.rdf
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}\chrome.manifest
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}\chrome\content\_cfg.js
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}\chrome\content\overlay.xul
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}\install.rdf
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}\chrome.manifest
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}\chrome\content\_cfg.js
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}\chrome\content\overlay.xul
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}\install.rdf
c:\documents and settings\stuffx3\Local Settings\Temp\7zS2C.tmp\nonlocalized\xpcom.dll
c:\documents and settings\stuffx3\Start Menu\Programs\Startup\scandisk.lnk
C:\s
c:\windows\EventSystem.log
c:\windows\ihiyovox.dll
c:\windows\system32\11323.exe
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11840.exe
c:\windows\system32\11942.exe
c:\windows\system32\12316.exe
c:\windows\system32\12382.exe
c:\windows\system32\12623.exe
c:\windows\system32\12859.exe
c:\windows\system32\13931.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\15141.exe
c:\windows\system32\153.exe
c:\windows\system32\15350.exe
c:\windows\system32\15724.exe
c:\windows\system32\15890.exe
c:\windows\system32\16827.exe
c:\windows\system32\16944.exe
c:\windows\system32\17035.exe
c:\windows\system32\17421.exe
c:\windows\system32\17673.exe
c:\windows\system32\1842.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\18756.exe
c:\windows\system32\19169.exe
c:\windows\system32\19264.exe
c:\windows\system32\19629.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\19954.exe
c:\windows\system32\20037.exe
c:\windows\system32\21538.exe
c:\windows\system32\21726.exe
c:\windows\system32\22190.exe
c:\windows\system32\22648.exe
c:\windows\system32\23281.exe
c:\windows\system32\23805.exe
c:\windows\system32\23811.exe
c:\windows\system32\24084.exe
c:\windows\system32\24370.exe
c:\windows\system32\24393.exe
c:\windows\system32\24464.exe
c:\windows\system32\24626.exe
c:\windows\system32\25547.exe
c:\windows\system32\25667.exe
c:\windows\system32\26299.exe
c:\windows\system32\26308.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\27446.exe
c:\windows\system32\27529.exe
c:\windows\system32\27644.exe
c:\windows\system32\28145.exe
c:\windows\system32\28253.exe
c:\windows\system32\28703.exe
c:\windows\system32\288.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\30106.exe
c:\windows\system32\30333.exe
c:\windows\system32\3035.exe
c:\windows\system32\31101.exe
c:\windows\system32\31322.exe
c:\windows\system32\32391.exe
c:\windows\system32\32439.exe
c:\windows\system32\32662.exe
c:\windows\system32\32757.exe
c:\windows\system32\3548.exe
c:\windows\system32\3902.exe
c:\windows\system32\4664.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\4966.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5537.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\6729.exe
c:\windows\system32\6868.exe
c:\windows\system32\7376.exe
c:\windows\system32\7711.exe
c:\windows\system32\778.exe
c:\windows\system32\8723.exe
c:\windows\system32\8942.exe
c:\windows\system32\9040.exe
c:\windows\system32\9741.exe
c:\windows\system32\9894.exe
c:\windows\system32\9961.exe
c:\windows\system32\warning.html
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3550P
((((((((((((((((((((((((( Files Created from 2010-01-04 to 2010-02-04 )))))))))))))))))))))))))))))))
.
2010-02-04 02:11 . 2010-02-04 02:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-02-04 02:11 . 2010-02-04 02:11 -------- d-----w- c:\program files\Alwil Software
2010-02-04 02:01 . 2010-02-04 02:05 -------- d-----w- c:\documents and settings\stuffx3\.SunDownloadManager
2010-02-03 05:06 . 2009-10-30 19:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-03 05:06 . 2009-11-09 19:20 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-02-03 05:06 . 2009-10-07 00:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-03 05:06 . 2009-09-03 17:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-03 05:06 . 2010-02-03 05:06 -------- d-----w- c:\program files\Common Files\PC Tools
2010-02-03 05:06 . 2010-02-03 05:11 -------- d-----w- c:\program files\Spyware Doctor
2010-02-03 05:06 . 2010-02-03 05:06 -------- d-----w- c:\documents and settings\stuffx3\Application Data\PC Tools
2010-02-03 05:06 . 2010-02-03 05:06 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-01-31 02:14 . 2010-01-31 02:14 -------- d-----w- c:\documents and settings\stuffx3\Application Data\CyberLink
2010-01-31 02:14 . 2010-01-31 02:25 -------- d-----w- c:\documents and settings\stuffx3\Local Settings\Application Data\PowerDVD
2010-01-26 04:13 . 2010-01-26 04:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Yahoo!
2010-01-26 02:39 . 2010-01-26 03:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-01-26 02:39 . 2010-01-26 02:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-25 23:56 . 2010-01-25 23:56 444 ----a-w- c:\windows\system32\d3d8caps.dat
2010-01-25 23:50 . 2010-02-04 03:12 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-25 23:41 . 2010-02-02 08:02 0 ----a-w- c:\windows\Usuwoyadomipu.bin
2010-01-25 23:41 . 2010-02-03 06:07 120 ----a-w- c:\windows\Kbobuyi.dat
2010-01-13 00:13 . 2009-11-21 16:36 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-08 05:09 . 2010-01-08 05:09 -------- d-----w- c:\program files\Common Files\Software Update Utility
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-04 04:14 . 2009-01-18 05:07 -------- d-----w- c:\program files\WinClamAVShield
2010-02-04 04:13 . 2009-03-04 02:19 66032 ----a-w- c:\documents and settings\stuffx3\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-03 06:20 . 2007-05-11 20:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-03 06:14 . 2009-03-04 00:33 -------- d-----w- c:\documents and settings\stuffx3\Application Data\uTorrent
2010-02-03 04:30 . 2009-10-01 05:45 -------- d-----w- c:\program files\uTorrent
2010-02-02 23:33 . 2009-01-17 21:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-02-02 23:32 . 2009-03-04 00:21 -------- d-----w- c:\documents and settings\stuffx3\Application Data\Spyware Terminator
2010-02-02 23:32 . 2009-01-17 21:33 -------- d-----w- c:\program files\Spyware Terminator
2010-01-28 05:28 . 2009-01-22 23:39 -------- d-----w- c:\documents and settings\ASHLEY DOMINIC\Application Data\Spyware Terminator
2010-01-26 06:02 . 2009-01-18 15:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-26 06:02 . 2010-01-26 06:02 5115823 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-26 02:55 . 2006-02-17 12:44 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-26 02:39 . 2006-02-17 12:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-23 03:30 . 2009-11-24 04:42 79488 ----a-w- c:\documents and settings\stuffx3\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-21 05:48 . 2009-11-24 06:53 143512 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-10 05:13 . 2006-03-06 01:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-08 05:09 . 2009-10-26 05:39 -------- d-----w- c:\program files\AIM
2010-01-08 00:07 . 2009-01-18 15:48 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2009-01-18 15:48 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 19:19 . 2008-11-02 18:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-02 19:07 . 2010-01-02 19:07 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-02 19:06 . 2010-01-02 19:06 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-21 16:36 . 2009-09-16 23:50 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-17 01:18 . 2009-11-17 01:13 63 ----a-w- c:\documents and settings\stuffx3\jagex_runescape_preferences2.dat
2009-11-17 01:16 . 2009-11-17 01:12 38 ----a-w- c:\documents and settings\stuffx3\jagex_runescape_preferences.dat
2009-11-09 08:33 . 2009-11-09 08:33 45056 ----a-r- c:\documents and settings\stuffx3\Application Data\Microsoft\Installer\{08C2044E-9E98-4005-8E3C-E438A10501EC}\MapleStory.exe1_08C2044E9E9840058E3CE438A10501EC.exe
2009-11-09 08:33 . 2009-11-09 08:33 45056 ----a-r- c:\documents and settings\stuffx3\Application Data\Microsoft\Installer\{08C2044E-9E98-4005-8E3C-E438A10501EC}\MapleStory.exe_08C2044E9E9840058E3CE438A10501EC.exe
2009-11-09 08:33 . 2009-11-09 08:33 10134 ----a-r- c:\documents and settings\stuffx3\Application Data\Microsoft\Installer\{08C2044E-9E98-4005-8E3C-E438A10501EC}\ARPPRODUCTICON.exe
2009-11-06 17:20 . 2009-11-21 17:48 34112 ----a-w- c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-06 17:20 . 2009-11-21 17:48 32448 ----a-w- c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-06 17:20 . 2009-11-21 17:48 22352 ----a-w- c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-09-27 19:31 . 2006-04-22 02:52 104 --sh--r- c:\windows\system32\7C5853413C.sys
2009-09-27 19:31 . 2006-04-22 02:52 5226 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-10-01 289072]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellTransferAgent"="c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-01-17 1783808]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"VerizonServicepoint.exe"="c:\program files\Verizon\Servicepoint\VerizonServicepoint.exe" [2006-02-01 1880064]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-02-17 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-06 114688]
"MPTBox"="c:\progra~1\Canon\MULTIP~1\MPTBox.exe" [2001-10-20 159744]
"monitr32"="c:\program files\Canon\MultiPASS4\monitr32.exe" [2001-10-20 323584]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-06 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-06 77824]
"fxredir"="c:\windows\system32\fxredir.exe" [2001-10-20 77824]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-2-5 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\browser\\ybrowser.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2/2/2010 9:06 PM 207792]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [1/17/2009 1:33 PM 141312]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/22/2009 3:44 PM 24652]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/18/2009 7:48 AM 38224]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-01-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://verizon.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\ASHLEY DOMINIC\Start Menu\Programs\Accessories\IMVU\Run IMVU.lnk
DPF: {03A99563-4F42-4DCF-A069-C728A71164A3} - hxxp://apps.vivaty.com/downloads/player/install.cab
FF - ProfilePath - c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npdeploytk.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\nppdf32.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin7.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Djonole - c:\windows\ihiyovox.dll
HKLM-Run-WMC_AutoUpdate - (no file)
HKU-Default-Run-notepad - c:\docume~1\LOCALS~1\ntload.dll
MSConfigStartUp-Internet Security 2010 - c:\program files\InternetSecurity2010\IS2010.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-03 20:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore.sys >>UNKNOWN [0x872F3856]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf77fdfc3
\Driver\ACPI -> ACPI.sys @ 0xf7770cb8
\Driver\atapi -> atapi.sys @ 0xf77087b4
IoDeviceObjectType -> ParseProcedure -> ntoskrnl.exe @ 0x8056d56b
\Device\Harddisk0\DR0 -> ParseProcedure -> ntoskrnl.exe @ 0x8056d56b
NDIS: Intel(R) PRO/100 VE Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf75fdba0
PacketIndicateHandler -> NDIS.sys @ 0xf760ab21
SendHandler -> NDIS.sys @ 0xf75e887b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(4028)
c:\windows\system32\WININET.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\progra~1\Yahoo!\browser\ycommon.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2010-02-03 20:24:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-04 04:24
Pre-Run: 25,620,893,696 bytes free
Post-Run: 35,216,691,200 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 5159921EFFC2DAF94E5743ED4893073F
ComboFix 10-02-03.04 - stuffx3 02/03/2010 19:48:27.1.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.530 [GMT -8:00]
Running from: c:\documents and settings\stuffx3\My Documents\Downloads\ComboFix.exe
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\stuffx3\LOCALS~1\Temp\7zS2C.tmp\nonlocalized\xpcom.dll
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}\chrome.manifest
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}\chrome\content\_cfg.js
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}\chrome\content\overlay.xul
c:\documents and settings\Administrator\Local Settings\Application Data\{05D11120-42B1-4C03-9DEB-781B408931E0}\install.rdf
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}\chrome.manifest
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}\chrome\content\_cfg.js
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}\chrome\content\overlay.xul
c:\documents and settings\ASHLEY DOMINIC\Local Settings\Application Data\{99AA70C0-02F3-425F-A29E-39CD6BC0209F}\install.rdf
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}\chrome.manifest
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}\chrome\content\_cfg.js
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}\chrome\content\overlay.xul
c:\documents and settings\stuffx3\Local Settings\Application Data\{481110DC-90EE-497C-8D2F-857A3E37A296}\install.rdf
c:\documents and settings\stuffx3\Local Settings\Temp\7zS2C.tmp\nonlocalized\xpcom.dll
c:\documents and settings\stuffx3\Start Menu\Programs\Startup\scandisk.lnk
C:\s
c:\windows\EventSystem.log
c:\windows\ihiyovox.dll
c:\windows\system32\11323.exe
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11840.exe
c:\windows\system32\11942.exe
c:\windows\system32\12316.exe
c:\windows\system32\12382.exe
c:\windows\system32\12623.exe
c:\windows\system32\12859.exe
c:\windows\system32\13931.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\15141.exe
c:\windows\system32\153.exe
c:\windows\system32\15350.exe
c:\windows\system32\15724.exe
c:\windows\system32\15890.exe
c:\windows\system32\16827.exe
c:\windows\system32\16944.exe
c:\windows\system32\17035.exe
c:\windows\system32\17421.exe
c:\windows\system32\17673.exe
c:\windows\system32\1842.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\18756.exe
c:\windows\system32\19169.exe
c:\windows\system32\19264.exe
c:\windows\system32\19629.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\19954.exe
c:\windows\system32\20037.exe
c:\windows\system32\21538.exe
c:\windows\system32\21726.exe
c:\windows\system32\22190.exe
c:\windows\system32\22648.exe
c:\windows\system32\23281.exe
c:\windows\system32\23805.exe
c:\windows\system32\23811.exe
c:\windows\system32\24084.exe
c:\windows\system32\24370.exe
c:\windows\system32\24393.exe
c:\windows\system32\24464.exe
c:\windows\system32\24626.exe
c:\windows\system32\25547.exe
c:\windows\system32\25667.exe
c:\windows\system32\26299.exe
c:\windows\system32\26308.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\27446.exe
c:\windows\system32\27529.exe
c:\windows\system32\27644.exe
c:\windows\system32\28145.exe
c:\windows\system32\28253.exe
c:\windows\system32\28703.exe
c:\windows\system32\288.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\30106.exe
c:\windows\system32\30333.exe
c:\windows\system32\3035.exe
c:\windows\system32\31101.exe
c:\windows\system32\31322.exe
c:\windows\system32\32391.exe
c:\windows\system32\32439.exe
c:\windows\system32\32662.exe
c:\windows\system32\32757.exe
c:\windows\system32\3548.exe
c:\windows\system32\3902.exe
c:\windows\system32\4664.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\4966.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5537.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\6729.exe
c:\windows\system32\6868.exe
c:\windows\system32\7376.exe
c:\windows\system32\7711.exe
c:\windows\system32\778.exe
c:\windows\system32\8723.exe
c:\windows\system32\8942.exe
c:\windows\system32\9040.exe
c:\windows\system32\9741.exe
c:\windows\system32\9894.exe
c:\windows\system32\9961.exe
c:\windows\system32\warning.html
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3550P
((((((((((((((((((((((((( Files Created from 2010-01-04 to 2010-02-04 )))))))))))))))))))))))))))))))
.
2010-02-04 02:11 . 2010-02-04 02:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-02-04 02:11 . 2010-02-04 02:11 -------- d-----w- c:\program files\Alwil Software
2010-02-04 02:01 . 2010-02-04 02:05 -------- d-----w- c:\documents and settings\stuffx3\.SunDownloadManager
2010-02-03 05:06 . 2009-10-30 19:11 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-02-03 05:06 . 2009-11-09 19:20 207792 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-02-03 05:06 . 2009-10-07 00:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-02-03 05:06 . 2009-09-03 17:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-02-03 05:06 . 2010-02-03 05:06 -------- d-----w- c:\program files\Common Files\PC Tools
2010-02-03 05:06 . 2010-02-03 05:11 -------- d-----w- c:\program files\Spyware Doctor
2010-02-03 05:06 . 2010-02-03 05:06 -------- d-----w- c:\documents and settings\stuffx3\Application Data\PC Tools
2010-02-03 05:06 . 2010-02-03 05:06 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-01-31 02:14 . 2010-01-31 02:14 -------- d-----w- c:\documents and settings\stuffx3\Application Data\CyberLink
2010-01-31 02:14 . 2010-01-31 02:25 -------- d-----w- c:\documents and settings\stuffx3\Local Settings\Application Data\PowerDVD
2010-01-26 04:13 . 2010-01-26 04:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Yahoo!
2010-01-26 02:39 . 2010-01-26 03:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-01-26 02:39 . 2010-01-26 02:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-25 23:56 . 2010-01-25 23:56 444 ----a-w- c:\windows\system32\d3d8caps.dat
2010-01-25 23:50 . 2010-02-04 03:12 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-25 23:41 . 2010-02-02 08:02 0 ----a-w- c:\windows\Usuwoyadomipu.bin
2010-01-25 23:41 . 2010-02-03 06:07 120 ----a-w- c:\windows\Kbobuyi.dat
2010-01-13 00:13 . 2009-11-21 16:36 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-08 05:09 . 2010-01-08 05:09 -------- d-----w- c:\program files\Common Files\Software Update Utility
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-04 04:14 . 2009-01-18 05:07 -------- d-----w- c:\program files\WinClamAVShield
2010-02-04 04:13 . 2009-03-04 02:19 66032 ----a-w- c:\documents and settings\stuffx3\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-03 06:20 . 2007-05-11 20:15 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-03 06:14 . 2009-03-04 00:33 -------- d-----w- c:\documents and settings\stuffx3\Application Data\uTorrent
2010-02-03 04:30 . 2009-10-01 05:45 -------- d-----w- c:\program files\uTorrent
2010-02-02 23:33 . 2009-01-17 21:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
2010-02-02 23:32 . 2009-03-04 00:21 -------- d-----w- c:\documents and settings\stuffx3\Application Data\Spyware Terminator
2010-02-02 23:32 . 2009-01-17 21:33 -------- d-----w- c:\program files\Spyware Terminator
2010-01-28 05:28 . 2009-01-22 23:39 -------- d-----w- c:\documents and settings\ASHLEY DOMINIC\Application Data\Spyware Terminator
2010-01-26 06:02 . 2009-01-18 15:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-26 06:02 . 2010-01-26 06:02 5115823 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-26 02:55 . 2006-02-17 12:44 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-26 02:39 . 2006-02-17 12:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-23 03:30 . 2009-11-24 04:42 79488 ----a-w- c:\documents and settings\stuffx3\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-21 05:48 . 2009-11-24 06:53 143512 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-10 05:13 . 2006-03-06 01:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-08 05:09 . 2009-10-26 05:39 -------- d-----w- c:\program files\AIM
2010-01-08 00:07 . 2009-01-18 15:48 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2009-01-18 15:48 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 19:19 . 2008-11-02 18:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-02 19:07 . 2010-01-02 19:07 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-02 19:06 . 2010-01-02 19:06 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-21 16:36 . 2009-09-16 23:50 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-17 01:18 . 2009-11-17 01:13 63 ----a-w- c:\documents and settings\stuffx3\jagex_runescape_preferences2.dat
2009-11-17 01:16 . 2009-11-17 01:12 38 ----a-w- c:\documents and settings\stuffx3\jagex_runescape_preferences.dat
2009-11-09 08:33 . 2009-11-09 08:33 45056 ----a-r- c:\documents and settings\stuffx3\Application Data\Microsoft\Installer\{08C2044E-9E98-4005-8E3C-E438A10501EC}\MapleStory.exe1_08C2044E9E9840058E3CE438A10501EC.exe
2009-11-09 08:33 . 2009-11-09 08:33 45056 ----a-r- c:\documents and settings\stuffx3\Application Data\Microsoft\Installer\{08C2044E-9E98-4005-8E3C-E438A10501EC}\MapleStory.exe_08C2044E9E9840058E3CE438A10501EC.exe
2009-11-09 08:33 . 2009-11-09 08:33 10134 ----a-r- c:\documents and settings\stuffx3\Application Data\Microsoft\Installer\{08C2044E-9E98-4005-8E3C-E438A10501EC}\ARPPRODUCTICON.exe
2009-11-06 17:20 . 2009-11-21 17:48 34112 ----a-w- c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-06 17:20 . 2009-11-21 17:48 32448 ----a-w- c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-06 17:20 . 2009-11-21 17:48 22352 ----a-w- c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-09-27 19:31 . 2006-04-22 02:52 104 --sh--r- c:\windows\system32\7C5853413C.sys
2009-09-27 19:31 . 2006-04-22 02:52 5226 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-27 3883856]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-10-01 289072]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellTransferAgent"="c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-01-17 1783808]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"VerizonServicepoint.exe"="c:\program files\Verizon\Servicepoint\VerizonServicepoint.exe" [2006-02-01 1880064]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-02-17 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-06 114688]
"MPTBox"="c:\progra~1\Canon\MULTIP~1\MPTBox.exe" [2001-10-20 159744]
"monitr32"="c:\program files\Canon\MultiPASS4\monitr32.exe" [2001-10-20 323584]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-06 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-06 77824]
"fxredir"="c:\windows\system32\fxredir.exe" [2001-10-20 77824]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-2-5 54512]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\browser\\ybrowser.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2/2/2010 9:06 PM 207792]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [1/17/2009 1:33 PM 141312]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/22/2009 3:44 PM 24652]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/18/2009 7:48 AM 38224]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-01-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://verizon.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\ASHLEY DOMINIC\Start Menu\Programs\Accessories\IMVU\Run IMVU.lnk
DPF: {03A99563-4F42-4DCF-A069-C728A71164A3} - hxxp://apps.vivaty.com/downloads/player/install.cab
FF - ProfilePath - c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\documents and settings\stuffx3\Application Data\Mozilla\Firefox\Profiles\nijr47ee.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npdeploytk.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\nppdf32.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin7.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Djonole - c:\windows\ihiyovox.dll
HKLM-Run-WMC_AutoUpdate - (no file)
HKU-Default-Run-notepad - c:\docume~1\LOCALS~1\ntload.dll
MSConfigStartUp-Internet Security 2010 - c:\program files\InternetSecurity2010\IS2010.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-03 20:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys PCTCore.sys >>UNKNOWN [0x872F3856]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf77fdfc3
\Driver\ACPI -> ACPI.sys @ 0xf7770cb8
\Driver\atapi -> atapi.sys @ 0xf77087b4
IoDeviceObjectType -> ParseProcedure -> ntoskrnl.exe @ 0x8056d56b
\Device\Harddisk0\DR0 -> ParseProcedure -> ntoskrnl.exe @ 0x8056d56b
NDIS: Intel(R) PRO/100 VE Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xf75fdba0
PacketIndicateHandler -> NDIS.sys @ 0xf760ab21
SendHandler -> NDIS.sys @ 0xf75e887b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(4028)
c:\windows\system32\WININET.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\progra~1\Yahoo!\browser\ycommon.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2010-02-03 20:24:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-04 04:24
Pre-Run: 25,620,893,696 bytes free
Post-Run: 35,216,691,200 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 5159921EFFC2DAF94E5743ED4893073F