ComboFix 11-11-02.03 - brand0 11/02/2011 13:07:32.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.534 [GMT -4:00]
Running from: c:\documents and settings\brand0\Desktop\ComboFix1.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\brand0\aeemtcbqwh.tmp
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{44d22856-fc7a-4312-841c-a09660b41d71}
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{44d22856-fc7a-4312-841c-a09660b41d71}\chrome.manifest
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{44d22856-fc7a-4312-841c-a09660b41d71}\chrome\xulcache.jar
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{44d22856-fc7a-4312-841c-a09660b41d71}\defaults\preferences\xulcache.js
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{44d22856-fc7a-4312-841c-a09660b41d71}\install.rdf
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{e46d740e-2905-41d2-9c2e-0cad0c06da75}
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{e46d740e-2905-41d2-9c2e-0cad0c06da75}\chrome.manifest
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{e46d740e-2905-41d2-9c2e-0cad0c06da75}\chrome\xulcache.jar
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{e46d740e-2905-41d2-9c2e-0cad0c06da75}\defaults\preferences\xulcache.js
c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\extensions\{e46d740e-2905-41d2-9c2e-0cad0c06da75}\install.rdf
c:\documents and settings\brand0\Local Settings\Application Data\NetworkUser.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-10-02 to 2011-11-02 )))))))))))))))))))))))))))))))
.
.
2011-11-01 18:28 . 2011-11-01 18:28 388096 ----a-r- c:\documents and settings\brand0\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-01 18:28 . 2011-11-01 18:28 -------- d-----w- c:\program files\Trend Micro
2011-10-31 21:40 . 2011-10-31 21:40 -------- d-----w- c:\program files\IObit
2011-10-31 21:40 . 2011-10-31 21:40 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\IObit
2011-10-27 18:18 . 2008-04-13 18:40 62976 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2011-10-27 18:18 . 2008-04-13 18:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-10-20 01:15 . 2011-08-31 21:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-20 01:03 . 2011-05-12 18:05 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
2011-10-20 00:36 . 2011-10-20 00:36 -------- d-----w- c:\program files\Sophos
2011-10-19 18:59 . 2011-10-19 18:59 -------- d-sh--w- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2011-10-19 18:52 . 2011-10-19 23:17 -------- d-sh--w- c:\documents and settings\brand0\Local Settings\Application Data\4bfcd315
2011-10-12 21:00 . 2011-10-12 21:00 -------- d-----w- c:\windows\.jagex_cache_32
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-26 15:41 . 2008-07-29 23:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 12:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-20 17:37 . 2011-09-20 17:37 14744 ----a-w- c:\documents and settings\brand0\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
2011-09-09 09:12 . 2004-08-04 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-18 19:03 . 2011-08-18 19:03 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-17 13:49 . 2004-08-04 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-01-27 16:58 . 2011-04-21 20:05 2959376 ----a-w- c:\program files\dotnetfx35setup.exe
2010-11-27 17:20 . 2010-11-27 17:20 1478773 ----a-w- c:\program files\CNTsetup.exe
2002-06-28 15:19 . 2010-07-23 08:28 723456 ----a-w- c:\program files\HLSS 3.00.exe
2011-09-30 20:06 . 2011-05-12 14:58 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-10-27_18.23.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-07-28 23:22 . 2011-10-30 01:53 735984 c:\windows\Installer\SandboxieInstall32.exe
- 2011-07-28 23:22 . 2011-09-08 00:27 735984 c:\windows\Installer\SandboxieInstall32.exe
+ 2011-05-20 20:23 . 2011-10-29 17:09 152748 c:\windows\DIIUnin.dat
+ 2011-11-01 18:28 . 2011-11-01 18:28 1094656 c:\windows\Installer\dedf9df.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2010-07-04 398568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoWelcomeScreen"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 04:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 09:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
2002-06-10 07:15 309760 ----a-w- c:\program files\AIM+\AIM+.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HanPurple Update]
2011-10-30 00:33 223744 ----a-w- c:\documents and settings\brand0\Local Settings\Application Data\Adobe\AdobeUpdate\Adobeup.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intel AppUp(SM) center]
2011-04-21 20:11 943 ----a-w- c:\program files\Intel\IntelAppStore\bin\serviceManager.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-06-07 21:51 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 21:00 449608 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-07-06 23:52 1047656 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamjojo.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-17 02:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-06-07 21:34 13902440 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-06-07 21:34 110696 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVMixerTray]
2004-12-20 21:12 131072 ----a-w- c:\program files\NVIDIA Corporation\NvMixer\NvMixerTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2010-06-03 04:48 1753192 ----a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 21:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2010-07-04 09:49 398568 ----a-w- c:\program files\Sandboxie\SbieCtrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2007-04-16 19:28 577536 ----a-w- c:\windows\soundman.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2011-09-08 02:04 1242448 ----a-w- d:\program files\Steam\Steam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 15:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Kaiba Corp VDS\\KCVDS.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Steam\\steamapps\\brand0nist00nice\\counter-strike source\\hl2.exe"=
"d:\\Program Files\\Steam\\steamapps\\common\\borderlands\\Binaries\\Borderlands.exe"=
.
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [2/11/2005 6:11 PM 16640]
R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [10/19/2011 9:03 PM 18816]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/19/2011 9:15 PM 366152]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/19/2011 9:15 PM 22216]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\7.tmp --> c:\windows\system32\7.tmp [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 21:57]
.
.
------- Supplementary Scan -------
.
uLocal Page =
uStart Page =
uInternet Settings,ProxyOverride = *.local
TCP: Interfaces\{4B36EEE5-ECBA-4115-B578-7D5B74A45AD9}: NameServer = 209.18.47.61,209.18.47.62
FF - ProfilePath - c:\documents and settings\brand0\Application Data\Mozilla\Firefox\Profiles\1esc2iio.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-MicrosoftTrayOnline - c:\documents and settings\All Users.WINDOWS\Application Data\MicrosoftTrayOnline.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-02 13:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\7.tmp"
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
Completion time: 2011-11-02 13:14:58
ComboFix-quarantined-files.txt 2011-11-02 17:14
ComboFix2.txt 2011-10-27 18:27
ComboFix3.txt 2011-09-07 00:39
ComboFix4.txt 2010-09-27 22:58
.
Pre-Run: 10,157,367,296 bytes free
Post-Run: 10,338,672,640 bytes free
.
- - End Of File - - 675BF741067805D1B3A77515F36090CD
Thank you for replying to me Gringo,
The issues I am still having at the moment are:
- When I click links in search engines, they get redirected and I have to go back then try again to make it work.
- My security access must have been altered or something because I cannot delete or open any .exe files that I already had on my computer. If I download a new .exe then it works fine. I checked my access and it says Administrator and I am the only user of this pc.
So because I cannot delete .exe files I already had, and I already had ComboFix.exe on my Desktop, I had to rename the install to ComboFix1.exe. I hope the name change won't matter. And the computer right now other than those issues seems to be alright. I can still do other things without too many issues/lag.