WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptioninternet connection/trojans/log file from combofix Emptyinternet connection/trojans/log file from combofix

more_horiz
I have run Combofix on your advice and the internet now seems to work okay again. Thank you!!! Smile...
Does that mean my computer is clear now or just part of iy is fixed???

Here is the log file from the combofix scan:

ComboFix 10-01-27.03 - Eddie Howley 27/01/2010 22:50:55.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.612 [GMT 0:00]
Running from: c:\documents and settings\Eddie Howley\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Internet Explorer\msimg32.dll
c:\recycler\S-1-5-21-546286046-1483979584-599923875-1003
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\twain_32.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Created from 2009-12-27 to 2010-01-27 )))))))))))))))))))))))))))))))
.

2010-01-25 21:18 . 2010-01-25 21:18 -------- d-----w- C:\MGTools
2010-01-25 20:33 . 2010-01-25 20:33 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Malwarebytes
2010-01-25 20:32 . 2010-01-25 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-25 17:44 . 2010-01-25 17:44 -------- d-----w- c:\program files\CCleaner
2010-01-25 15:44 . 2010-01-25 17:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-25 12:45 . 2010-01-25 12:45 -------- d-----w- c:\program files\AVG
2010-01-25 12:45 . 2010-01-25 17:24 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-25 00:45 . 2010-01-25 00:45 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2010-01-25 00:45 . 2010-01-25 00:45 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\TuneUp Software
2010-01-25 00:43 . 2010-01-25 00:43 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-25 00:43 . 2010-01-25 17:06 -------- d-----w- c:\program files\TuneUp Utilities 2009
2010-01-25 00:43 . 2010-01-25 00:43 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2010-01-25 00:01 . 2009-09-20 02:19 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVENG.SYS
2010-01-25 00:01 . 2009-09-20 02:19 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVENG32.DLL
2010-01-25 00:01 . 2009-09-20 02:19 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVEX32A.DLL
2010-01-25 00:01 . 2009-09-20 02:19 1323568 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVEX15.SYS
2010-01-25 00:01 . 2009-09-20 02:19 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\ERASER.SYS
2010-01-25 00:01 . 2009-12-10 09:00 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\CCERASER.DLL
2010-01-25 00:01 . 2009-09-25 08:00 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\ECMSVR32.DLL
2010-01-25 00:01 . 2009-09-20 02:19 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\EECTRL.SYS
2010-01-24 23:40 . 2010-01-24 23:40 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-01-24 23:40 . 2010-01-24 23:40 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-24 14:57 . 2010-01-24 16:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-24 13:39 . 2010-01-24 15:59 -------- d-----w- c:\documents and settings\Eddie Howley\Local Settings\Application Data\nqxvht
2010-01-24 11:42 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\Scxpx86.dll
2010-01-24 11:41 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSXpx86.sys
2010-01-24 11:41 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSxpx86.dll
2010-01-24 11:41 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSvix86.sys
2010-01-24 11:41 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSviA64.sys
2010-01-18 22:49 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSXpx86.sys
2010-01-18 22:49 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\Scxpx86.dll
2010-01-18 22:49 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSxpx86.dll
2010-01-18 22:49 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSvix86.sys
2010-01-18 22:49 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 18:18 . 2009-11-06 22:13 65024 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2010-01-25 18:18 . 2009-11-06 22:13 5120 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
2010-01-25 18:18 . 2009-11-06 22:13 18944 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2010-01-25 18:05 . 2007-03-13 18:30 -------- d-----w- c:\program files\Common Files\Real
2010-01-25 18:05 . 2007-03-13 18:30 -------- d-----w- c:\program files\Real
2010-01-25 17:59 . 2006-11-24 21:38 -------- d-----w- c:\program files\MSN Messenger
2010-01-25 17:58 . 2007-01-07 22:20 -------- d-----w- c:\program files\Yahoo!
2010-01-25 17:58 . 2007-01-07 22:22 -------- d--h--r- c:\documents and settings\Eddie Howley\Application Data\yahoo!
2010-01-25 17:57 . 2008-01-12 16:41 -------- d-----w- c:\program files\Logitech
2010-01-25 17:56 . 2006-10-08 10:44 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-24 15:07 . 2009-11-06 22:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-20 20:24 . 2008-02-18 19:26 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-21 22:20 . 2006-11-24 21:22 -------- d-----w- c:\program files\Google
2009-12-21 19:14 . 2006-10-08 03:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-14 20:56 . 2006-11-24 21:26 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Skype
2009-12-14 20:53 . 2009-08-03 20:27 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\skypePM
2009-12-08 20:05 . 2009-11-06 22:14 117760 ----a-w- c:\documents and settings\Eddie Howley\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\PC Suite
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Nokia
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-12-05 17:24 . 2009-12-05 17:24 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-12-05 17:24 . 2009-12-05 17:24 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\Common Files\PCSuite
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-05 17:20 . 2009-12-05 17:19 -------- d-----w- c:\program files\Nokia
2009-12-05 17:20 . 2009-06-29 20:18 -------- d-----w- c:\program files\DIFX
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-05 17:18 . 2009-12-05 17:18 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-12-05 17:18 . 2009-12-05 17:18 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-12-05 17:18 . 2009-12-05 17:18 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-12-05 17:18 . 2009-12-05 17:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-11-21 15:51 . 2006-10-08 03:21 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-05 21:37 . 2009-11-05 21:37 452104 ----a-w- c:\documents and settings\Eddie Howley\Application Data\Real\RealPlayer\setup\AU_setup9.exe
2009-10-30 01:51 . 2009-10-30 01:51 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-14 2001648]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"SMSERIAL"="sm56hlpr.exe" [2004-12-29 544768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 15:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0305020.00B\SymEFA.sys [19/09/2009 12:51 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0305020.00B\BHDrvx86.sys [19/09/2009 12:51 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0305020.00B\cchpx86.sys [19/09/2009 12:51 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSXpx86.sys [24/01/2010 11:41 329592]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/10/2009 21:24 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/10/2009 21:24 74480]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe [19/09/2009 12:51 117640]
R3 EKBfltr;ENE Keyboard Controller;c:\windows\system32\drivers\EKBfltr.sys [08/10/2006 03:24 5504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [25/01/2010 00:01 102448]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/10/2009 21:24 7408]
S2 gupdate1c9c69527525f0a;Google Update Service (gupdate1c9c69527525f0a);c:\program files\Google\Update\GoogleUpdate.exe [26/04/2009 17:33 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-01-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:34]

2010-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:33]

2010-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
AddRemove-HijackThis - e:\mgtools\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-27 22:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1008)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2010-01-27 22:57:31
ComboFix-quarantined-files.txt 2010-01-27 22:57

Pre-Run: 35,129,360,384 bytes free
Post-Run: 35,364,876,288 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 59303A907BBF4287881F078E08E6C12D

descriptioninternet connection/trojans/log file from combofix EmptyRe: internet connection/trojans/log file from combofix

more_horiz
Hello.

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    uInternet Settings,ProxyOverride =

    RegLock::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]


  4. Save this as CFScript.txt, in the same location as ComboFix.exe

    internet connection/trojans/log file from combofix Cfscriptb4i

  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
internet connection/trojans/log file from combofix DXwU4
internet connection/trojans/log file from combofix VvYDg

descriptioninternet connection/trojans/log file from combofix EmptyRe: internet connection/trojans/log file from combofix

more_horiz
Here is the log file from the second scan from Combofix. Are you able to tell me whats wrong with my computer and what is being fixed plz:

ComboFix 10-01-28.05 - Eddie Howley 29/01/2010 13:53:16.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.615 [GMT 0:00]
Running from: c:\documents and settings\Eddie Howley\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Eddie Howley\Desktop\CFScript.txt
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.

2010-01-25 21:18 . 2010-01-25 21:18 -------- d-----w- C:\MGTools
2010-01-25 20:33 . 2010-01-25 20:33 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Malwarebytes
2010-01-25 20:32 . 2010-01-25 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-25 17:44 . 2010-01-25 17:44 -------- d-----w- c:\program files\CCleaner
2010-01-25 15:44 . 2010-01-25 17:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-25 12:45 . 2010-01-25 12:45 -------- d-----w- c:\program files\AVG
2010-01-25 12:45 . 2010-01-25 17:24 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-25 00:45 . 2010-01-25 00:45 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2010-01-25 00:45 . 2010-01-25 00:45 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\TuneUp Software
2010-01-25 00:43 . 2010-01-25 00:43 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-25 00:43 . 2010-01-25 17:06 -------- d-----w- c:\program files\TuneUp Utilities 2009
2010-01-25 00:43 . 2010-01-25 00:43 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2010-01-25 00:01 . 2009-09-20 02:19 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVENG.SYS
2010-01-25 00:01 . 2009-09-20 02:19 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVENG32.DLL
2010-01-25 00:01 . 2009-09-20 02:19 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVEX32A.DLL
2010-01-25 00:01 . 2009-09-20 02:19 1323568 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVEX15.SYS
2010-01-25 00:01 . 2009-09-20 02:19 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\ERASER.SYS
2010-01-25 00:01 . 2009-12-10 09:00 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\CCERASER.DLL
2010-01-25 00:01 . 2009-09-25 08:00 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\ECMSVR32.DLL
2010-01-25 00:01 . 2009-09-20 02:19 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\EECTRL.SYS
2010-01-24 23:40 . 2010-01-24 23:40 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-01-24 23:40 . 2010-01-24 23:40 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-24 14:57 . 2010-01-24 16:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-24 13:39 . 2010-01-24 15:59 -------- d-----w- c:\documents and settings\Eddie Howley\Local Settings\Application Data\nqxvht
2010-01-24 11:42 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\Scxpx86.dll
2010-01-24 11:41 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSXpx86.sys
2010-01-24 11:41 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSxpx86.dll
2010-01-24 11:41 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSvix86.sys
2010-01-24 11:41 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSviA64.sys
2010-01-18 22:49 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSXpx86.sys
2010-01-18 22:49 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\Scxpx86.dll
2010-01-18 22:49 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSxpx86.dll
2010-01-18 22:49 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSvix86.sys
2010-01-18 22:49 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 18:18 . 2009-11-06 22:13 65024 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2010-01-25 18:18 . 2009-11-06 22:13 5120 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
2010-01-25 18:18 . 2009-11-06 22:13 18944 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2010-01-25 18:05 . 2007-03-13 18:30 -------- d-----w- c:\program files\Common Files\Real
2010-01-25 18:05 . 2007-03-13 18:30 -------- d-----w- c:\program files\Real
2010-01-25 17:59 . 2006-11-24 21:38 -------- d-----w- c:\program files\MSN Messenger
2010-01-25 17:58 . 2007-01-07 22:20 -------- d-----w- c:\program files\Yahoo!
2010-01-25 17:58 . 2007-01-07 22:22 -------- d--h--r- c:\documents and settings\Eddie Howley\Application Data\yahoo!
2010-01-25 17:57 . 2008-01-12 16:41 -------- d-----w- c:\program files\Logitech
2010-01-25 17:56 . 2006-10-08 10:44 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-24 15:07 . 2009-11-06 22:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-20 20:24 . 2008-02-18 19:26 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-21 22:20 . 2006-11-24 21:22 -------- d-----w- c:\program files\Google
2009-12-21 19:14 . 2006-10-08 03:21 916480 ------w- c:\windows\system32\wininet.dll
2009-12-14 20:56 . 2006-11-24 21:26 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Skype
2009-12-14 20:53 . 2009-08-03 20:27 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\skypePM
2009-12-08 20:05 . 2009-11-06 22:14 117760 ----a-w- c:\documents and settings\Eddie Howley\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\PC Suite
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Nokia
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-12-05 17:24 . 2009-12-05 17:24 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-12-05 17:24 . 2009-12-05 17:24 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\Common Files\PCSuite
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-05 17:20 . 2009-12-05 17:19 -------- d-----w- c:\program files\Nokia
2009-12-05 17:20 . 2009-06-29 20:18 -------- d-----w- c:\program files\DIFX
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-05 17:18 . 2009-12-05 17:18 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-12-05 17:18 . 2009-12-05 17:18 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-12-05 17:18 . 2009-12-05 17:18 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-12-05 17:18 . 2009-12-05 17:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-11-21 15:51 . 2006-10-08 03:21 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-05 21:37 . 2009-11-05 21:37 452104 ----a-w- c:\documents and settings\Eddie Howley\Application Data\Real\RealPlayer\setup\AU_setup9.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-01-27_22.55.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-29 13:44 . 2010-01-29 13:44 16384 c:\windows\Temp\Perflib_Perfdata_7c.dat
+ 2010-01-29 13:43 . 2010-01-29 13:43 16384 c:\windows\Temp\Perflib_Perfdata_7b8.dat
- 2010-01-27 22:39 . 2010-01-27 22:39 16384 c:\windows\Temp\Perflib_Perfdata_7b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-14 2001648]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"SMSERIAL"="sm56hlpr.exe" [2004-12-29 544768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 15:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0305020.00B\SymEFA.sys [19/09/2009 12:51 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0305020.00B\BHDrvx86.sys [19/09/2009 12:51 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0305020.00B\cchpx86.sys [19/09/2009 12:51 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSXpx86.sys [24/01/2010 11:41 329592]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/10/2009 21:24 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/10/2009 21:24 74480]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe [19/09/2009 12:51 117640]
R3 EKBfltr;ENE Keyboard Controller;c:\windows\system32\drivers\EKBfltr.sys [08/10/2006 03:24 5504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [25/01/2010 00:01 102448]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/10/2009 21:24 7408]
S2 gupdate1c9c69527525f0a;Google Update Service (gupdate1c9c69527525f0a);c:\program files\Google\Update\GoogleUpdate.exe [26/04/2009 17:33 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-01-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:34]

2010-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:33]

2010-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-29 13:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1012)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(320)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-29 14:02:10
ComboFix-quarantined-files.txt 2010-01-29 14:01
ComboFix2.txt 2010-01-27 22:57

Pre-Run: 35,386,466,304 bytes free
Post-Run: 35,346,968,576 bytes free

- - End Of File - - 044A051B2DE9B09D19FA3C480AB4B0AE

descriptioninternet connection/trojans/log file from combofix EmptyRe: internet connection/trojans/log file from combofix

more_horiz
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

How is the machine running now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
internet connection/trojans/log file from combofix DXwU4
internet connection/trojans/log file from combofix VvYDg

descriptioninternet connection/trojans/log file from combofix EmptyRe: internet connection/trojans/log file from combofix

more_horiz
Seems to be running okay now. Thanks again for all the help:)

descriptioninternet connection/trojans/log file from combofix EmptyRe: internet connection/trojans/log file from combofix

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum