Hi,
Managed to use the internet at a hotel today, so I will try your new suggestions later.
I also logged into another user account on the laptop in safe mode and ran MBAM and Comofix...both programs found something....logs below:
MBAM LOG:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 6.0.2900.5512
19/09/2010 04:55:34
mbam-log-2010-09-19 (04-55-34).txt
Scan type: Quick scan
Objects scanned: 126672
Time elapsed: 7 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\com+ manager (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\Web\Local Settings\Temp\hjkr1p.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\jkr2hs7fqw.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\kqt4n6dlkw.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\tpcuqc.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\u3dwyosn.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\zmo0cie0.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
COMBOFIX LOG:
ComboFix 10-09-16.04 - Web 19/09/2010 5:00.1.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.807 [GMT 1:00]
Running from: c:\documents and settings\Web\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Web\.COMMgr
c:\documents and settings\Web\Local Settings\Application Data\bnquqfngg\bsuvbheuqiw.exe
c:\documents and settings\Web\Local Settings\Application Data\edrsqkdmi\bpghquduqiw.exe
c:\windows\atidalosa.dll
c:\windows\eputibof.dll
c:\windows\ulibiyovoxanetix.dll
c:\windows\wimgxft.dll
c:\windows\system32\winlogon.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2010-08-19 to 2010-09-19 )))))))))))))))))))))))))))))))
.
2010-09-17 12:02 . 2010-09-17 12:02 -------- d-----w- c:\documents and settings\Admin\Application Data\vlc
2010-09-17 11:51 . 2010-09-17 11:51 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Google
2010-09-17 11:44 . 2010-09-17 12:12 -------- d-----w- c:\documents and settings\Admin\Application Data\Apple Computer
2010-09-17 02:44 . 2010-09-17 02:53 -------- d-----w- C:\Combo-Fix
2010-09-14 06:34 . 2010-09-14 06:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-09-14 06:34 . 2010-09-14 06:34 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-09-14 04:14 . 2010-09-14 04:14 -------- d-----w- c:\documents and settings\Admin\Application Data\PC Tools
2010-09-14 04:13 . 2010-09-14 06:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-14 02:02 . 2010-09-14 02:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-09-14 02:02 . 2010-09-14 02:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-14 01:56 . 2010-09-14 04:14 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-09-13 00:43 . 2010-09-14 01:48 0 ----a-w- c:\windows\Qtuweqetalaj.bin
2010-09-13 00:43 . 2010-09-14 03:47 2838 ----a-w- c:\windows\Ojefuyag.dat
2010-09-13 00:42 . 2010-09-19 04:08 841216 ----a-w- c:\windows\system32\drivers\lggtctm.sys
2010-09-11 11:14 . 2010-09-11 11:14 -------- d-----w- c:\program files\Convar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-17 12:12 . 2009-02-07 11:28 60464 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-17 02:21 . 2010-09-14 02:00 60464 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-14 02:01 . 2010-09-14 02:00 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2010-09-13 00:11 . 2009-10-17 00:36 -------- d-----w- c:\program files\Telstra Turbo Connection Manager
2010-08-23 01:36 . 2009-04-12 21:51 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2010-08-04 00:11 . 2010-07-21 11:28 27591840 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\msgup1000_1270_us_u2.exe
2010-08-02 07:30 . 2010-08-02 07:30 -------- d-----w- c:\program files\Ableton
2010-08-02 04:46 . 2009-02-18 21:42 -------- d-----w- c:\program files\Google
2010-08-02 00:18 . 2010-07-10 10:47 -------- d-----w- c:\program files\Mediafour
2010-07-25 14:40 . 2010-07-25 14:35 -------- d-----w- c:\documents and settings\All Users\Application Data\WindSolutions
2010-07-25 14:37 . 2010-07-25 14:37 -------- d-----w- c:\program files\Music Rescue
2010-07-25 14:35 . 2010-07-25 14:35 -------- d-----w- c:\program files\WindSolutions
2010-07-10 04:53 . 2010-07-10 04:53 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2008-05-07 08:34 . 2008-07-05 02:55 15523560 ----a-w- c:\program files\U1 Setup.exe
.
------- Sigcheck -------
[-] 2008-04-14 . 858A92ABBFA4395FDEAE9CE8404D0DF5 . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2008-04-14 . ED8230261CDBB41414A152098A5E1293 . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 104984]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 121368]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 100888]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-06-03 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-06-03 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-07-23 335872]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"autodetect"="c:\windows\system32\SupportAppXL\AutoDect.exe" [2008-08-07 91648]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-16 16806400]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"wupdate"="c:\windows\system32\wupdate.exe" [BU]
"utlegodg"="c:\documents and settings\Web\Local Settings\Application Data\bnquqfngg\bsuvbheuqiw.exe" [BU]
"aopgomts"="c:\documents and settings\Web\Local Settings\Application Data\edrsqkdmi\bpghquduqiw.exe" [BU]
"Wmimefameteq"="c:\windows\onuyohuy.dll" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-2-3 113664]
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-7-5 303104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-11 02:51 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 ----a-w- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 08:42 2808832 ----a-w- c:\windows\alcwzrd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 16:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ----a-w- c:\windows\SoundMan.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys --> c:\windows\system32\DRIVERS\epfwtdir.sys [?]
S2 0028831284690044mcinstcleanup;McAfee Application Installer Cleanup (0028831284690044);c:\docume~1\ADMINI~1\LOCALS~1\Temp\002883~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\002883~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate1c9921256115394;Google Update Service (gupdate1c9921256115394);c:\program files\Google\Update\GoogleUpdate.exe [18/02/2009 22:46 133104]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [17/10/2009 01:37 7680]
--- Other Services/Drivers In Memory ---
*Deregistered* - lggtctm
.
Contents of the 'Scheduled Tasks' folder
2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 21:46]
2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 21:46]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global
uInternet Settings,ProxyServer = http=127.0.0.1:6092
uInternet Settings,ProxyOverride =
IE: Save Flash - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
IE: Save YouTube Video - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/217
FF - ProfilePath - c:\documents and settings\Web\Application Data\Mozilla\Firefox\Profiles\zirmi4w0.default\
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: XULRunner: {0FED6A9D-2712-4322-8209-E040FCB5E084} - c:\documents and settings\Web\Local Settings\Application Data\{0FED6A9D-2712-4322-8209-E040FCB5E084}
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKCU-Run-Wcoluj - c:\windows\wimgxft.dll
HKCU-Run-utlegodg - c:\documents and settings\Web\Local Settings\Application Data\bnquqfngg\bsuvbheuqiw.exe
HKCU-Run-aopgomts - c:\documents and settings\Web\Local Settings\Application Data\edrsqkdmi\bpghquduqiw.exe
HKCU-Run-sdsetup_aff - c:\documents and settings\Web\Desktop\sdsetup_aff.exe
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-19 05:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lggtctm]
.
Completion time: 2010-09-19 05:10:25
ComboFix-quarantined-files.txt 2010-09-19 04:10
ComboFix2.txt 2010-09-17 02:53
ComboFix3.txt 2010-09-14 08:17
ComboFix4.txt 2010-09-14 07:46
Pre-Run: 2,011,340,800 bytes free
Post-Run: 2,358,132,736 bytes free
- - End Of File - - F9D228B21C98CAF298F0247ACB869F59
I'll try the OTL thing later and hopefully get online and post the log tomorrow. |Thanks so much for all your help!!
Martin
Managed to use the internet at a hotel today, so I will try your new suggestions later.
I also logged into another user account on the laptop in safe mode and ran MBAM and Comofix...both programs found something....logs below:
MBAM LOG:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 6.0.2900.5512
19/09/2010 04:55:34
mbam-log-2010-09-19 (04-55-34).txt
Scan type: Quick scan
Objects scanned: 126672
Time elapsed: 7 minute(s), 10 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\com+ manager (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\Web\Local Settings\Temp\hjkr1p.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\jkr2hs7fqw.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\kqt4n6dlkw.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\tpcuqc.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\u3dwyosn.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Local Settings\Temp\zmo0cie0.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Web\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
COMBOFIX LOG:
ComboFix 10-09-16.04 - Web 19/09/2010 5:00.1.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.807 [GMT 1:00]
Running from: c:\documents and settings\Web\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Web\.COMMgr
c:\documents and settings\Web\Local Settings\Application Data\bnquqfngg\bsuvbheuqiw.exe
c:\documents and settings\Web\Local Settings\Application Data\edrsqkdmi\bpghquduqiw.exe
c:\windows\atidalosa.dll
c:\windows\eputibof.dll
c:\windows\ulibiyovoxanetix.dll
c:\windows\wimgxft.dll
c:\windows\system32\winlogon.exe . . . is infected!!
c:\windows\explorer.exe . . . is infected!!
.
((((((((((((((((((((((((( Files Created from 2010-08-19 to 2010-09-19 )))))))))))))))))))))))))))))))
.
2010-09-17 12:02 . 2010-09-17 12:02 -------- d-----w- c:\documents and settings\Admin\Application Data\vlc
2010-09-17 11:51 . 2010-09-17 11:51 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Google
2010-09-17 11:44 . 2010-09-17 12:12 -------- d-----w- c:\documents and settings\Admin\Application Data\Apple Computer
2010-09-17 02:44 . 2010-09-17 02:53 -------- d-----w- C:\Combo-Fix
2010-09-14 06:34 . 2010-09-14 06:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-09-14 06:34 . 2010-09-14 06:34 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-09-14 04:14 . 2010-09-14 04:14 -------- d-----w- c:\documents and settings\Admin\Application Data\PC Tools
2010-09-14 04:13 . 2010-09-14 06:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-14 02:02 . 2010-09-14 02:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-09-14 02:02 . 2010-09-14 02:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-14 01:56 . 2010-09-14 04:14 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-09-13 00:43 . 2010-09-14 01:48 0 ----a-w- c:\windows\Qtuweqetalaj.bin
2010-09-13 00:43 . 2010-09-14 03:47 2838 ----a-w- c:\windows\Ojefuyag.dat
2010-09-13 00:42 . 2010-09-19 04:08 841216 ----a-w- c:\windows\system32\drivers\lggtctm.sys
2010-09-11 11:14 . 2010-09-11 11:14 -------- d-----w- c:\program files\Convar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-17 12:12 . 2009-02-07 11:28 60464 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-17 02:21 . 2010-09-14 02:00 60464 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-14 02:01 . 2010-09-14 02:00 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2010-09-13 00:11 . 2009-10-17 00:36 -------- d-----w- c:\program files\Telstra Turbo Connection Manager
2010-08-23 01:36 . 2009-04-12 21:51 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2010-08-04 00:11 . 2010-07-21 11:28 27591840 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\msgup1000_1270_us_u2.exe
2010-08-02 07:30 . 2010-08-02 07:30 -------- d-----w- c:\program files\Ableton
2010-08-02 04:46 . 2009-02-18 21:42 -------- d-----w- c:\program files\Google
2010-08-02 00:18 . 2010-07-10 10:47 -------- d-----w- c:\program files\Mediafour
2010-07-25 14:40 . 2010-07-25 14:35 -------- d-----w- c:\documents and settings\All Users\Application Data\WindSolutions
2010-07-25 14:37 . 2010-07-25 14:37 -------- d-----w- c:\program files\Music Rescue
2010-07-25 14:35 . 2010-07-25 14:35 -------- d-----w- c:\program files\WindSolutions
2010-07-10 04:53 . 2010-07-10 04:53 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2008-05-07 08:34 . 2008-07-05 02:55 15523560 ----a-w- c:\program files\U1 Setup.exe
.
------- Sigcheck -------
[-] 2008-04-14 . 858A92ABBFA4395FDEAE9CE8404D0DF5 . 507904 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2008-04-14 . ED8230261CDBB41414A152098A5E1293 . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 104984]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 121368]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 100888]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-06-03 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-06-03 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-07-23 335872]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"autodetect"="c:\windows\system32\SupportAppXL\AutoDect.exe" [2008-08-07 91648]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-16 16806400]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"wupdate"="c:\windows\system32\wupdate.exe" [BU]
"utlegodg"="c:\documents and settings\Web\Local Settings\Application Data\bnquqfngg\bsuvbheuqiw.exe" [BU]
"aopgomts"="c:\documents and settings\Web\Local Settings\Application Data\edrsqkdmi\bpghquduqiw.exe" [BU]
"Wmimefameteq"="c:\windows\onuyohuy.dll" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-2-3 113664]
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-7-5 303104]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-11 02:51 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 ----a-w- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2008-06-19 08:42 2808832 ----a-w- c:\windows\alcwzrd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 16:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-06-18 10:01 77824 ----a-w- c:\windows\SoundMan.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys --> c:\windows\system32\DRIVERS\epfwtdir.sys [?]
S2 0028831284690044mcinstcleanup;McAfee Application Installer Cleanup (0028831284690044);c:\docume~1\ADMINI~1\LOCALS~1\Temp\002883~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\002883~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate1c9921256115394;Google Update Service (gupdate1c9921256115394);c:\program files\Google\Update\GoogleUpdate.exe [18/02/2009 22:46 133104]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [17/10/2009 01:37 7680]
--- Other Services/Drivers In Memory ---
*Deregistered* - lggtctm
.
Contents of the 'Scheduled Tasks' folder
2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 21:46]
2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-18 21:46]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global
uInternet Settings,ProxyServer = http=127.0.0.1:6092
uInternet Settings,ProxyOverride =
IE: Save Flash - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
IE: Save YouTube Video - c:\program files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/217
FF - ProfilePath - c:\documents and settings\Web\Application Data\Mozilla\Firefox\Profiles\zirmi4w0.default\
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: XULRunner: {0FED6A9D-2712-4322-8209-E040FCB5E084} - c:\documents and settings\Web\Local Settings\Application Data\{0FED6A9D-2712-4322-8209-E040FCB5E084}
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKCU-Run-Wcoluj - c:\windows\wimgxft.dll
HKCU-Run-utlegodg - c:\documents and settings\Web\Local Settings\Application Data\bnquqfngg\bsuvbheuqiw.exe
HKCU-Run-aopgomts - c:\documents and settings\Web\Local Settings\Application Data\edrsqkdmi\bpghquduqiw.exe
HKCU-Run-sdsetup_aff - c:\documents and settings\Web\Desktop\sdsetup_aff.exe
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-19 05:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lggtctm]
.
Completion time: 2010-09-19 05:10:25
ComboFix-quarantined-files.txt 2010-09-19 04:10
ComboFix2.txt 2010-09-17 02:53
ComboFix3.txt 2010-09-14 08:17
ComboFix4.txt 2010-09-14 07:46
Pre-Run: 2,011,340,800 bytes free
Post-Run: 2,358,132,736 bytes free
- - End Of File - - F9D228B21C98CAF298F0247ACB869F59
I'll try the OTL thing later and hopefully get online and post the log tomorrow. |Thanks so much for all your help!!
Martin