We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

system tools 2001 help needed

245

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741
    Part of the Furniture Combo Breaker
    Forumite
    hammerboy2 wrote: »
    the rapidshare link you posted

    Well theres nothing wrong with it. Looking at your malwarebytes logs theres a fair chance the hosts file has been changed

    Download HostsXpert (US MIRROR)
    http://www.softpedia.com/progDownload/Hoster-Download-27041.html
    and then follow the below steps.

    * Unzip HostsXpert.zip
    * It will create a folder named HostsXpert in whatever folder you extract it to.
    * Run HostsXpert.exe by pressing the SHIFT key, RIGHT CLICKING on the exe file and selecting 'RUN AS' (admin)
    * click the Make Writeable? button.
    * click Restore Microsoft's Hosts File and then click OK.
    * Click the X to exit the program
    :idea:
  • aliEnRIK
    aliEnRIK Posts: 17,741
    Part of the Furniture Combo Breaker
    Forumite
    Combofix definitely needs running

    Malwarebytes could really do with UPDATING and running first
    :idea:
  • hammerboy2
    hammerboy2 Posts: 58
    Part of the Furniture 10 Posts Combo Breaker
    Forumite
    so
    malware first
    combofix
    then hostsxpert

    thanks
  • hammerboy2
    hammerboy2 Posts: 58
    Part of the Furniture 10 Posts Combo Breaker
    Forumite
    aliEnRIK

    have updated Malwarebytes and run again, done the hostsxpert and ran combofix
    here is log
    ComboFix 11-03-09.05 - Chris 10/03/2011 18:05:43.1.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2046.1141 [GMT 0:00]
    Running from: c:\users\Chris\Desktop\ComboFix.exe
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
    FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
    c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
    .
    BITS: Possible infected sites
    .
    hxxp://sync.broadband.o2.co.uk:8080
    .
    ((((((((((((((((((((((((( Files Created from 2011-02-10 to 2011-03-10 )))))))))))))))))))))))))))))))
    .
    .
    2011-03-10 18:22 . 2011-03-10 18:22
    d
    w- c:\users\Default\AppData\Local\temp
    2011-03-09 19:45 . 2010-12-29 18:28 429056 ----a-w- c:\windows\system32\EncDec.dll
    2011-03-09 19:45 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
    2011-03-09 19:45 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
    2011-03-09 19:45 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
    2011-03-09 19:44 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
    2011-03-09 19:44 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
    2011-03-09 19:39 . 2011-02-23 09:35 5943120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D3367A57-8D92-45AB-BEFB-F8824C38C2A5}\mpengine.dll
    2011-03-09 19:16 . 2011-03-09 19:16
    d
    w- c:\program files\Windows Portable Devices
    2011-03-07 20:00 . 2010-10-13 22:28 164840 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
    2011-03-07 19:58 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
    2011-03-07 19:58 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
    2011-03-07 19:58 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
    2011-03-07 19:57 . 2009-09-25 01:33 369664 ----a-w- c:\windows\system32\WMPhoto.dll
    2011-03-07 19:57 . 2009-09-25 02:07 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
    2011-03-07 19:57 . 2009-09-25 02:10 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
    2011-03-07 19:57 . 2009-09-25 02:04 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
    2011-03-07 19:57 . 2009-09-25 01:33 195584 ----a-w- c:\windows\system32\dxdiagn.dll
    2011-03-07 19:57 . 2009-09-25 01:32 252928 ----a-w- c:\windows\system32\dxdiag.exe
    2011-03-07 19:57 . 2009-09-25 01:31 519680 ----a-w- c:\windows\system32\d3d11.dll
    2011-03-07 19:54 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2011-03-07 19:54 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
    2011-03-07 19:54 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-03-07 19:09 . 2011-03-07 19:09 388096 ----a-r- c:\users\Chris\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2011-03-07 19:09 . 2011-03-07 19:09
    d
    w- c:\program files\Trend Micro
    2011-03-07 19:01 . 2011-03-07 19:01
    d
    w- c:\program files\Microsoft.NET
    2011-03-06 19:32 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-06 19:04 . 2011-03-06 19:06
    d
    w- c:\windows\system32\ca-ES
    2011-03-06 19:04 . 2011-03-06 19:05
    d
    w- c:\windows\system32\eu-ES
    2011-03-06 19:04 . 2011-03-06 19:05
    d
    w- c:\windows\system32\vi-VN
    2011-03-06 18:31 . 2011-03-06 18:31
    d
    w- c:\windows\system32\EventProviders
    2011-03-06 17:21 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
    2011-03-06 17:09 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
    2011-03-06 16:55 . 2009-11-08 10:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2011-03-06 16:55 . 2009-11-08 10:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
    2011-03-06 16:55 . 2009-11-08 10:55 297808 ----a-w- c:\windows\system32\mscoree.dll
    2011-03-06 16:55 . 2009-11-08 10:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
    2011-03-06 16:55 . 2009-11-08 10:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
    2011-03-06 16:49 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
    2011-03-06 16:49 . 2009-10-09 21:56 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
    2011-03-06 16:49 . 2009-10-09 21:56 20480 ----a-w- c:\windows\system32\winrshost.exe
    2011-03-06 16:49 . 2009-10-09 21:56 40448 ----a-w- c:\windows\system32\winrs.exe
    2011-03-06 16:49 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
    2011-03-06 16:49 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\winrssrv.dll
    2011-03-06 16:49 . 2009-10-09 21:55 79872 ----a-w- c:\windows\system32\wecutil.exe
    2011-03-06 16:49 . 2009-10-09 21:55 54272 ----a-w- c:\windows\system32\WsmRes.dll
    2011-03-06 16:49 . 2009-10-09 21:55 146944 ----a-w- c:\windows\system32\wecsvc.dll
    2011-03-06 16:49 . 2009-10-09 21:55 81408 ----a-w- c:\windows\system32\wevtfwd.dll
    2011-03-06 16:49 . 2009-10-09 21:55 56320 ----a-w- c:\windows\system32\wecapi.dll
    2011-03-06 16:49 . 2009-10-09 21:56 41472 ----a-w- c:\windows\system32\pwrshplugin.dll
    2011-03-06 16:48 . 2009-08-01 06:27 201184 ----a-w- c:\windows\system32\winrm.vbs
    2011-03-06 16:48 . 2009-10-09 21:56 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
    2011-03-06 16:48 . 2009-10-09 21:56 241152 ----a-w- c:\windows\system32\winrscmd.dll
    2011-03-06 16:48 . 2009-10-09 21:56 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
    2011-03-06 16:48 . 2009-10-09 21:56 145408 ----a-w- c:\windows\system32\WsmAuto.dll
    2011-03-06 16:48 . 2009-10-09 21:55 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
    2011-03-06 16:48 . 2009-10-09 21:56 1181696 ----a-w- c:\windows\system32\WsmSvc.dll
    2011-03-06 16:06 . 2009-04-11 06:28 1077248 ----a-w- c:\windows\system32\vssapi.dll
    2011-03-06 16:05 . 2009-04-11 06:28 842240 ----a-w- c:\windows\system32\systemcpl.dll
    2011-03-06 15:45 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
    2011-03-06 15:45 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
    2011-03-06 15:43 . 2010-01-29 15:40 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
    2011-03-06 15:42 . 2010-08-20 16:05 867328 ----a-w- c:\windows\system32\wmpmde.dll
    2011-03-06 15:42 . 2010-11-04 18:55 601600 ----a-w- c:\windows\system32\schedsvc.dll
    2011-03-06 15:42 . 2010-11-04 18:56 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
    2011-03-06 15:42 . 2010-11-04 18:55 352768 ----a-w- c:\windows\system32\taskschd.dll
    2011-03-06 15:42 . 2010-11-04 18:55 270336 ----a-w- c:\windows\system32\taskcomp.dll
    2011-03-06 15:42 . 2010-11-04 16:34 171520 ----a-w- c:\windows\system32\taskeng.exe
    2011-03-06 15:42 . 2010-10-18 13:37 81920 ----a-w- c:\windows\system32\consent.exe
    2011-03-06 15:42 . 2010-06-11 16:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
    2011-03-06 15:41 . 2010-10-28 13:20 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-03-06 15:40 . 2011-01-08 08:47 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-03-06 15:40 . 2011-01-08 06:28 292352 ----a-w- c:\windows\system32\atmfd.dll
    2011-03-06 15:40 . 2010-06-16 15:30 72704 ----a-w- c:\windows\system32\fontsub.dll
    2011-03-06 15:40 . 2010-06-16 16:04 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2011-03-06 15:40 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-06 15:34 . 2010-08-31 15:44 531968 ----a-w- c:\windows\system32\comctl32.dll
    2011-03-06 14:20 . 2011-03-06 14:20
    d
    w- C:\PerfLogs
    2011-03-06 13:06 . 2011-03-06 13:06
    d
    w- c:\program files\Common Files\Java
    2011-03-05 20:01 . 2011-03-05 20:01
    d
    w- c:\program files\Common Files\Adobe
    2011-03-05 19:45 . 2011-03-05 19:45
    d
    w- c:\users\Chris\AppData\Local\Secunia PSI
    2011-03-05 19:45 . 2011-03-05 19:45
    d
    w- c:\program files\Secunia
    2011-03-05 13:50 . 2011-03-05 13:50
    d
    w- c:\users\Chris\AppData\Roaming\Malwarebytes
    2011-03-05 13:50 . 2010-12-20 18:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-03-05 13:50 . 2011-03-05 13:50
    d
    w- c:\programdata\Malwarebytes
    2011-03-05 13:50 . 2011-03-05 13:50
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2011-03-05 13:50 . 2010-12-20 18:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-03-03 13:13 . 2011-03-03 13:13
    d
    w- c:\program files\iPod
    2011-03-03 13:13 . 2011-03-03 13:14
    d
    w- c:\program files\iTunes
    2011-03-03 13:12 . 2011-03-05 15:03
    d
    w- c:\programdata\lJnFpKa06300
    2011-02-18 16:36 . 2011-02-18 16:36 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    2011-02-18 16:36 . 2011-02-18 16:36 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
    2011-02-08 19:18 . 2011-02-08 19:18 31 ---ha-w- c:\windows\UKCpInfo.sys
    2011-02-08 19:18 . 2011-02-08 19:18
    d
    w- c:\program files\Coupon Printer
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-06 13:38 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
    2011-03-06 13:38 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
    2011-03-06 12:43 . 2010-08-11 18:36 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-02-02 17:11 . 2009-10-02 21:39 222080
    w- c:\windows\system32\MpSigStub.exe
    2009-02-12 21:24 . 2009-10-10 11:13 6963606 ----a-w- c:\program files\dcloner_V6.0.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-25 39408]
    "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2010-06-24 247144]
    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    "SacReminderHDDV2"="c:\programdata\OfficeGuardianV2\reminder\SacReminder.exe" [2010-12-21 522064]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-11-24 167936]
    "NapsterShell"="c:\program files\Napster\napster.exe" [2006-09-06 323216]
    "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-11-28 46704]
    "EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-07-18 1306624]
    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
    "snp2uvc"="c:\windows\vsnp2uvc.exe" [2008-08-01 675840]
    "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-01 421160]
    "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-07 90191]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-07 7766016]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-07 81920]
    .
    c:\users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
    Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-1-10 291896]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    .
    R2 CFUACProxy_officeguardianv2;CFUACProxy_officeguardianv2;c:\programdata\OfficeGuardianV2\UACProxy.exe [2010-12-21 83792]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate1c9cbe4d998217a;Google Update Service (gupdate1c9cbe4d998217a);c:\program files\Google\Update\GoogleUpdate.exe [2009-05-03 133104]
    R2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [x]
    R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-10-13 84264]
    R3 PavSRK.sys;PavSRK.sys;c:\windows\system32\PavSRK.sys [x]
    R3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys [x]
    R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
    R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
    R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
    R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
    R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
    R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
    R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    R4 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-10-13 84072]
    S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-10-13 64304]
    S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-10-13 164840]
    S2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\printer\center\KodakSvc.exe [2008-07-25 18944]
    S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2010-11-24 88176]
    S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
    S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 271480]
    S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-13 188136]
    S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-10-13 141792]
    S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-01-10 993848]
    S2 sprtsvc_O2;SupportSoft Sprocket Service (O2);c:\program files\O2\bin\sprtsvc.exe [2007-06-07 202280]
    S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
    S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-10-13 55840]
    S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-10-13 313288]
    S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - mfeavfk01
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs REG_MULTI_SZ BthServ
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-03 11:46]
    .
    2011-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-03 11:46]
    .
    2011-03-09 c:\windows\Tasks\User_Feed_Synchronization-{064BF6A4-8A94-485F-916C-4FD6CEF22243}.job
    - c:\windows\system32\msfeedssync.exe [2011-03-06 04:47]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=71&bd=Pavilion&pf=laptop
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=71&bd=Pavilion&pf=laptop
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
    IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    Trusted Zone: o2.co.uk\*.broadband
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM-Run-QlbCtrl - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
    HKLM-Run-WAWifiMessage - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    HKLM-Run-hpWirelessAssistant - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    HKLM-Run-BVRPLiveUpdate - c:\program files\Avanquest update\Engine\Setup.exe
    HKLM-RunOnce-Launcher - (no file)
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-03-10 18:23
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    .
    c:\users\Chris\AppData\Local\Temp\catchme.dll 53248 bytes executable
    .
    scan completed successfully
    hidden files: 1
    .
    **************************************************************************
    .
    LOCKED REGISTRY KEYS
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2011-03-10 18:37:14
    ComboFix-quarantined-files.txt 2011-03-10 18:37
    .
    Pre-Run: 87,755,771,904 bytes free
    Post-Run: 97,202,917,376 bytes free
    .
    - - End Of File - - 27149EEFA154D8F07329CF392E16C12D
  • aliEnRIK
    aliEnRIK Posts: 17,741
    Part of the Furniture Combo Breaker
    Forumite
    Open notepad and copy/paste the text in RED below

    File::
    c:\users\Chris\AppData\Local\Temp\catchme.dll

    Folder::
    c:\programdata\lJnFpKa06300


    Save this as "CFScript" (FULL file will be 'CFScript.txt' EXACTLY as shown)

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

    CFScript.gif


    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply
    (If SNAPSHOT is stupidly large, leave that part out)

    Combofix should never take more that 30 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    :idea:
  • aliEnRIK
    log as requested
    thanks


    ComboFix 11-03-10.01 - Chris 10/03/2011 21:32:37.2.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2046.1087 [GMT 0:00]
    Running from: c:\users\Chris\Desktop\ComboFix.exe
    Command switches used :: c:\users\Chris\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs\CFScript.txt
    AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
    FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
    SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    FILE ::
    "c:\users\Chris\AppData\Local\Temp\catchme.dll"
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\programdata\lJnFpKa06300
    c:\programdata\lJnFpKa06300\lJnFpKa06300
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-02-10 to 2011-03-10 )))))))))))))))))))))))))))))))
    .
    .
    2011-03-10 21:47 . 2011-03-10 21:47
    d
    w- c:\users\Default\AppData\Local\temp
    2011-03-09 19:45 . 2010-12-29 18:28 429056 ----a-w- c:\windows\system32\EncDec.dll
    2011-03-09 19:45 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
    2011-03-09 19:45 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
    2011-03-09 19:45 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
    2011-03-09 19:44 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
    2011-03-09 19:44 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
    2011-03-09 19:39 . 2011-02-23 09:35 5943120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D3367A57-8D92-45AB-BEFB-F8824C38C2A5}\mpengine.dll
    2011-03-09 19:16 . 2011-03-09 19:16
    d
    w- c:\program files\Windows Portable Devices
    2011-03-07 20:00 . 2010-10-13 22:28 164840 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
    2011-03-07 19:58 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
    2011-03-07 19:58 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
    2011-03-07 19:58 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
    2011-03-07 19:57 . 2009-09-25 01:33 369664 ----a-w- c:\windows\system32\WMPhoto.dll
    2011-03-07 19:57 . 2009-09-25 02:07 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
    2011-03-07 19:57 . 2009-09-25 02:10 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
    2011-03-07 19:57 . 2009-09-25 02:04 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
    2011-03-07 19:57 . 2009-09-25 01:33 195584 ----a-w- c:\windows\system32\dxdiagn.dll
    2011-03-07 19:57 . 2009-09-25 01:32 252928 ----a-w- c:\windows\system32\dxdiag.exe
    2011-03-07 19:57 . 2009-09-25 01:31 519680 ----a-w- c:\windows\system32\d3d11.dll
    2011-03-07 19:54 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
    2011-03-07 19:54 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
    2011-03-07 19:54 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-03-07 19:09 . 2011-03-07 19:09 388096 ----a-r- c:\users\Chris\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
    2011-03-07 19:09 . 2011-03-07 19:09
    d
    w- c:\program files\Trend Micro
    2011-03-07 19:01 . 2011-03-07 19:01
    d
    w- c:\program files\Microsoft.NET
    2011-03-06 19:32 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
    2011-03-06 19:04 . 2011-03-06 19:06
    d
    w- c:\windows\system32\ca-ES
    2011-03-06 19:04 . 2011-03-06 19:05
    d
    w- c:\windows\system32\eu-ES
    2011-03-06 19:04 . 2011-03-06 19:05
    d
    w- c:\windows\system32\vi-VN
    2011-03-06 18:31 . 2011-03-06 18:31
    d
    w- c:\windows\system32\EventProviders
    2011-03-06 17:21 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
    2011-03-06 17:09 . 2009-03-08 11:32 72704 ----a-w- c:\windows\system32\admparse.dll
    2011-03-06 16:55 . 2009-11-08 10:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2011-03-06 16:55 . 2009-11-08 10:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
    2011-03-06 16:55 . 2009-11-08 10:55 297808 ----a-w- c:\windows\system32\mscoree.dll
    2011-03-06 16:55 . 2009-11-08 10:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
    2011-03-06 16:55 . 2009-11-08 10:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
    2011-03-06 16:49 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
    2011-03-06 16:49 . 2009-10-09 21:56 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
    2011-03-06 16:49 . 2009-10-09 21:56 20480 ----a-w- c:\windows\system32\winrshost.exe
    2011-03-06 16:49 . 2009-10-09 21:56 40448 ----a-w- c:\windows\system32\winrs.exe
    2011-03-06 16:49 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
    2011-03-06 16:49 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\winrssrv.dll
    2011-03-06 16:49 . 2009-10-09 21:55 79872 ----a-w- c:\windows\system32\wecutil.exe
    2011-03-06 16:49 . 2009-10-09 21:55 54272 ----a-w- c:\windows\system32\WsmRes.dll
    2011-03-06 16:49 . 2009-10-09 21:55 146944 ----a-w- c:\windows\system32\wecsvc.dll
    2011-03-06 16:49 . 2009-10-09 21:55 81408 ----a-w- c:\windows\system32\wevtfwd.dll
    2011-03-06 16:49 . 2009-10-09 21:55 56320 ----a-w- c:\windows\system32\wecapi.dll
    2011-03-06 16:49 . 2009-10-09 21:56 41472 ----a-w- c:\windows\system32\pwrshplugin.dll
    2011-03-06 16:48 . 2009-08-01 06:27 201184 ----a-w- c:\windows\system32\winrm.vbs
    2011-03-06 16:48 . 2009-10-09 21:56 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
    2011-03-06 16:48 . 2009-10-09 21:56 241152 ----a-w- c:\windows\system32\winrscmd.dll
    2011-03-06 16:48 . 2009-10-09 21:56 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
    2011-03-06 16:48 . 2009-10-09 21:56 145408 ----a-w- c:\windows\system32\WsmAuto.dll
    2011-03-06 16:48 . 2009-10-09 21:55 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
    2011-03-06 16:48 . 2009-10-09 21:56 1181696 ----a-w- c:\windows\system32\WsmSvc.dll
    2011-03-06 16:06 . 2009-04-11 06:28 1077248 ----a-w- c:\windows\system32\vssapi.dll
    2011-03-06 16:05 . 2009-04-11 06:28 842240 ----a-w- c:\windows\system32\systemcpl.dll
    2011-03-06 15:45 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
    2011-03-06 15:45 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
    2011-03-06 15:43 . 2010-01-29 15:40 1616384 ----a-w- c:\program files\Windows Mail\msoe.dll
    2011-03-06 15:42 . 2010-08-20 16:05 867328 ----a-w- c:\windows\system32\wmpmde.dll
    2011-03-06 15:42 . 2010-11-04 18:55 601600 ----a-w- c:\windows\system32\schedsvc.dll
    2011-03-06 15:42 . 2010-11-04 18:56 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
    2011-03-06 15:42 . 2010-11-04 18:55 352768 ----a-w- c:\windows\system32\taskschd.dll
    2011-03-06 15:42 . 2010-11-04 18:55 270336 ----a-w- c:\windows\system32\taskcomp.dll
    2011-03-06 15:42 . 2010-11-04 16:34 171520 ----a-w- c:\windows\system32\taskeng.exe
    2011-03-06 15:42 . 2010-10-18 13:37 81920 ----a-w- c:\windows\system32\consent.exe
    2011-03-06 15:42 . 2010-06-11 16:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
    2011-03-06 15:41 . 2010-10-28 13:20 2048 ----a-w- c:\windows\system32\tzres.dll
    2011-03-06 15:40 . 2011-01-08 08:47 34304 ----a-w- c:\windows\system32\atmlib.dll
    2011-03-06 15:40 . 2011-01-08 06:28 292352 ----a-w- c:\windows\system32\atmfd.dll
    2011-03-06 15:40 . 2010-06-16 15:30 72704 ----a-w- c:\windows\system32\fontsub.dll
    2011-03-06 15:40 . 2010-06-16 16:04 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2011-03-06 15:40 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
    2011-03-06 15:34 . 2010-08-31 15:44 531968 ----a-w- c:\windows\system32\comctl32.dll
    2011-03-06 14:20 . 2011-03-06 14:20
    d
    w- C:\PerfLogs
    2011-03-06 13:06 . 2011-03-06 13:06
    d
    w- c:\program files\Common Files\Java
    2011-03-05 20:01 . 2011-03-05 20:01
    d
    w- c:\program files\Common Files\Adobe
    2011-03-05 19:45 . 2011-03-05 19:45
    d
    w- c:\users\Chris\AppData\Local\Secunia PSI
    2011-03-05 19:45 . 2011-03-05 19:45
    d
    w- c:\program files\Secunia
    2011-03-05 13:50 . 2011-03-05 13:50
    d
    w- c:\users\Chris\AppData\Roaming\Malwarebytes
    2011-03-05 13:50 . 2010-12-20 18:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-03-05 13:50 . 2011-03-05 13:50
    d
    w- c:\programdata\Malwarebytes
    2011-03-05 13:50 . 2011-03-05 13:50
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2011-03-05 13:50 . 2010-12-20 18:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-03-03 13:13 . 2011-03-03 13:13
    d
    w- c:\program files\iPod
    2011-03-03 13:13 . 2011-03-03 13:14
    d
    w- c:\program files\iTunes
    2011-02-18 16:36 . 2011-02-18 16:36 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    2011-02-18 16:36 . 2011-02-18 16:36 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-06 13:38 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
    2011-03-06 13:38 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
    2011-03-06 12:43 . 2010-08-11 18:36 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-02-02 17:11 . 2009-10-02 21:39 222080
    w- c:\windows\system32\MpSigStub.exe
    2009-02-12 21:24 . 2009-10-10 11:13 6963606 ----a-w- c:\program files\dcloner_V6.0.exe
    .
    .
    ((((((((((((((((((((((((((((( [EMAIL="SnapShot@2011-03-10_18.23.30"]SnapShot@2011-03-10_18.23.30[/EMAIL] )))))))))))))))))))))))))))))))))))))))))
    .
    + 2006-12-18 21:55 . 2011-03-10 18:56 88484 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2006-11-02 13:05 . 2011-03-10 18:57 87422 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2007-05-20 07:08 . 2011-03-10 18:55 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2007-05-20 07:08 . 2011-03-10 13:44 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2007-05-20 07:08 . 2011-03-10 18:55 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2007-05-20 07:08 . 2011-03-10 13:44 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2007-05-20 07:08 . 2011-03-10 13:44 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2007-05-20 07:08 . 2011-03-10 18:55 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2011-03-10 13:00 . 2011-03-10 13:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2011-03-10 18:54 . 2011-03-10 18:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2011-03-10 13:00 . 2011-03-10 13:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2011-03-10 18:54 . 2011-03-10 18:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2011-03-09 21:32 . 2011-03-10 21:17 157968 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
    - 2006-11-02 10:33 . 2011-03-10 13:05 609196 c:\windows\System32\perfh009.dat
    + 2006-11-02 10:33 . 2011-03-10 19:02 609196 c:\windows\System32\perfh009.dat
    - 2006-11-02 10:33 . 2011-03-10 13:05 108672 c:\windows\System32\perfc009.dat
    + 2006-11-02 10:33 . 2011-03-10 19:02 108672 c:\windows\System32\perfc009.dat
    - 2011-03-06 17:46 . 2011-03-10 13:00 262144 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2011-03-06 17:46 . 2011-03-10 18:54 262144 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2011-03-09 21:55 . 2011-03-10 18:53 329628 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    - 2011-03-09 21:55 . 2011-03-10 11:28 329628 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-25 39408]
    "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2010-06-24 247144]
    "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 393216]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
    "SacReminderHDDV2"="c:\programdata\OfficeGuardianV2\reminder\SacReminder.exe" [2010-12-21 522064]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-11-24 167936]
    "NapsterShell"="c:\program files\Napster\napster.exe" [2006-09-06 323216]
    "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-11-28 46704]
    "EKIJ5000StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2008-07-18 1306624]
    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
    "snp2uvc"="c:\windows\vsnp2uvc.exe" [2008-08-01 675840]
    "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-09-30 1193848]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-01 421160]
    "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-01-22 40368]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-07 90191]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-07 7766016]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-07 81920]
    .
    c:\users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
    Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-1-10 291896]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    .
    R2 CFUACProxy_officeguardianv2;CFUACProxy_officeguardianv2;c:\programdata\OfficeGuardianV2\UACProxy.exe [2010-12-21 83792]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate1c9cbe4d998217a;Google Update Service (gupdate1c9cbe4d998217a);c:\program files\Google\Update\GoogleUpdate.exe [2009-05-03 133104]
    R2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [x]
    R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-10-13 84264]
    R3 PavSRK.sys;PavSRK.sys;c:\windows\system32\PavSRK.sys [x]
    R3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys [x]
    R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
    R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
    R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
    R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
    R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
    R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
    R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    R4 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-10-13 84072]
    S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-10-13 64304]
    S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-10-13 164840]
    S2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\printer\center\KodakSvc.exe [2008-07-25 18944]
    S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2010-11-24 88176]
    S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
    S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 271480]
    S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-13 188136]
    S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-10-13 141792]
    S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-01-10 993848]
    S2 sprtsvc_O2;SupportSoft Sprocket Service (O2);c:\program files\O2\bin\sprtsvc.exe [2007-06-07 202280]
    S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-06-24 92008]
    S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-10-13 55840]
    S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-10-13 313288]
    S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - mfeavfk01
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs REG_MULTI_SZ BthServ
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-03 11:46]
    .
    2011-03-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-03 11:46]
    .
    2011-03-10 c:\windows\Tasks\User_Feed_Synchronization-{064BF6A4-8A94-485F-916C-4FD6CEF22243}.job
    - c:\windows\system32\msfeedssync.exe [2011-03-06 04:47]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=71&bd=Pavilion&pf=laptop
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=71&bd=Pavilion&pf=laptop
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
    IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    Trusted Zone: o2.co.uk\*.broadband
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-03-10 21:48
    Windows 6.0.6002 Service Pack 2 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    .
    c:\users\Chris\AppData\Local\Temp\catchme.dll 53248 bytes executable
    .
    scan completed successfully
    hidden files: 1
    .
    **************************************************************************
    .
    LOCKED REGISTRY KEYS
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2011-03-10 22:00:28
    ComboFix-quarantined-files.txt 2011-03-10 22:00
    ComboFix2.txt 2011-03-10 18:37
    .
    Pre-Run: 97,008,386,048 bytes free
    Post-Run: 96,965,459,968 bytes free
    .
    - - End Of File - - A4A8374C85F22727087E70BE6964D361
  • aliEnRIK
    aliEnRIK Posts: 17,741
    Part of the Furniture Combo Breaker
    Forumite
    Youve got a stubborn file, found by combofix in a part ive never seen before

    try this -

    Show hidden files/folders -
    http://www.bleepingcomputer.com/tutorials/tutorial130.html

    Open malwarebytes
    Goto MORE TOOLS
    then RUN TOOL
    Use it to destroy this file -
    c:\users\Chris\AppData\Local\Temp\catchme.dll
    :idea:
  • sorry aliEnRIK if i seem a bit dim this morning
    after i click on the run tools i type c:\users\Chris\AppData\Local\Temp\catchme.dll
    click on open
    it then says catchme.dll file does not exist
    create file
    do i just click yes?
  • aliEnRIK
    aliEnRIK Posts: 17,741
    Part of the Furniture Combo Breaker
    Forumite
    No

    Clearly theres something there. I just dunno how to remove it

    Manually clear the temp folder -
    http://www.vistax64.com/tutorials/104637-temporary-files-temp-folder.html

    Then let me know what folders/files are left (Making sure 'hidden files/folders' is still on)
    :idea:
  • hammerboy2
    hammerboy2 Posts: 58
    Part of the Furniture 10 Posts Combo Breaker
    Forumite
    this is what is left after maually deleting

    ehmsas.txt

    low
This discussion has been closed.
★ ★ ★ Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 355.7K Banking & Borrowing
  • 254.9K Reduce Debt & Boost Income
  • 456.1K Spending & Discounts
  • 248.3K Work, Benefits & Business
  • 605.8K Mortgages, Homes & Bills
  • 179K Life & Family
  • 263.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.