Hi Gringo.
Thanks for the further instructions. As I cannot connect to the internet, I downloaded the combofix on an alternative machine and transferred by usb drive. I disabled Mcafee (it said it was 'off') but forgot I had also installed MS Securty Essentials. Ran combofix and it alerted me to the fact that both Mcafee and MSE were still running which surprised me as I had definitely turned Mcafee off. I couldn't switch off MSE and assume that the virus was affecting this. Anyway, combofix opened a further C:\ window and alerted me that combofix needed to be updated and I would need to have an active internet connection. I don't have that so was just about to post a reply to you when it continued to run ( with a warning that it was at my risk - which was slightly worrying) and soon after advised that I had a particularly difficult to remove 'zero rootkit'? (I think that was what it said as soon after, a further window opened and it advised me that the computer needed to be rebooted and that I should let combofix do this for me. Before I knew it, it had started to shut down and has just restarted and eventually produced the below log.
As for pc now, it seems better. The start menu is more populated than it was and the whole pc is not su sluggish. I have checked network conections and it advises that it is connected, but on trying IE, it cannot connect. Seems there may still be an issue in that department? Perhaps the below log will tell all to your trained eyes.
Thanks again.
ComboFix 12-01-23.02 - Home 27/01/2012 14:07:26.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1023.753 [GMT 0:00]
Running from: c:\documents and settings\Home\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Enabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
.
ADS - WINDOWS: deleted 128 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\~O2ogAy2iYqvsjL
c:\documents and settings\All Users\Application Data\~O2ogAy2iYqvsjLr
c:\documents and settings\All Users\Application Data\O2ogAy2iYqvsjL
c:\documents and settings\All Users\Application Data\O2ogAy2iYqvsjL.exe
c:\documents and settings\All Users\Application Data\RobIKtbrUE.exe
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\xf9poa4vaz.exe
c:\documents and settings\Home\Application Data\D4E39
c:\documents and settings\Home\Application Data\D4E39\5CB93.exe
c:\documents and settings\Home\Application Data\D4E39\991B.4E3
c:\documents and settings\Home\Application Data\desktop.ini
c:\documents and settings\Home\Application Data\xssend2
c:\documents and settings\Home\Local Settings\Application Data\{1CAB38A7-9BC6-41BD-A002-86564E94130F}
c:\documents and settings\Home\Local Settings\Application Data\{1CAB38A7-9BC6-41BD-A002-86564E94130F}\chrome.manifest
c:\documents and settings\Home\Local Settings\Application Data\{1CAB38A7-9BC6-41BD-A002-86564E94130F}\chrome\content\overlay.xul
c:\documents and settings\Home\Local Settings\Application Data\{1CAB38A7-9BC6-41BD-A002-86564E94130F}\install.rdf
c:\documents and settings\Home\Start Menu\Programs\System Check
c:\documents and settings\Home\Start Menu\Programs\System Check\System Check.lnk
c:\documents and settings\Home\Start Menu\Programs\System Check\Uninstall System Check.lnk
c:\documents and settings\Home\WINDOWS
c:\documents and settings\Home\xf9poa4vaz.exe
c:\program files\LP
c:\program files\LP\93BD\1.tmp
c:\program files\LP\93BD\17DF.tmp
c:\program files\LP\93BD\17E0.tmp
c:\program files\LP\93BD\2.tmp
c:\program files\LP\93BD\255.tmp
c:\program files\LP\93BD\256.tmp
c:\program files\LP\93BD\259.tmp
c:\program files\LP\93BD\25A.tmp
c:\program files\LP\93BD\3.tmp
c:\program files\LP\93BD\5.tmp
c:\program files\LP\93BD\65B.exe
c:\windows\$NtUninstallKB38322$
c:\windows\$NtUninstallKB38322$\2393381658\@
c:\windows\$NtUninstallKB38322$\2393381658\bckfg.tmp
c:\windows\$NtUninstallKB38322$\2393381658\cfg.ini
c:\windows\$NtUninstallKB38322$\2393381658\Desktop.ini
c:\windows\$NtUninstallKB38322$\2393381658\keywords
c:\windows\$NtUninstallKB38322$\2393381658\kwrd.dll
c:\windows\$NtUninstallKB38322$\2393381658\L\xgniolat
c:\windows\$NtUninstallKB38322$\2393381658\U\00000001.@
c:\windows\$NtUninstallKB38322$\2393381658\U\00000002.@
c:\windows\$NtUninstallKB38322$\2393381658\U\00000004.@
c:\windows\$NtUninstallKB38322$\2393381658\U\80000000.@
c:\windows\$NtUninstallKB38322$\2393381658\U\80000004.@
c:\windows\$NtUninstallKB38322$\2393381658\U\80000032.@
c:\windows\$NtUninstallKB38322$\266745636
c:\windows\Downloaded Program Files\formcache
c:\windows\Downloaded Program Files\formcache\1.fca
c:\windows\Downloaded Program Files\formcache\2.fca
c:\windows\Downloaded Program Files\formcache\index.fci
c:\windows\system32\370181562.dat
c:\windows\system32\ctfmon(2).exe
c:\windows\system32\drivers\557e35f5afdf0c59.sys
c:\windows\XSxS
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_6TO4
-------\Legacy_ALGREMOTEACCESS
-------\Legacy_ASPNET_STATETUNEUP.DEFRAG
-------\Legacy_SHAREDACCESSFONTCACHE3.0.0.0
-------\Legacy_WMIAPSRVCOMSYSAPP
-------\Service_6to4
-------\Service_ALGRemoteAccess
-------\Service_aspnet_stateTuneUp.Defrag
-------\Service_SharedAccessFontCache3.0.0.0
-------\Service_WmiApSrvCOMSysApp
-------\Legacy_557e35f5afdf0c59
-------\Service_557e35f5afdf0c59
.
.
((((((((((((((((((((((((( Files Created from 2011-12-27 to 2012-01-27 )))))))))))))))))))))))))))))))
.
.
2012-01-26 12:08 . 2012-01-26 12:08 -------- d-----w- c:\program files\Microsoft Security Client
2012-01-25 10:19 . 2012-01-25 10:19 -------- d-----w- c:\program files\Xenocode
2012-01-25 10:19 . 2012-01-25 10:19 -------- d-----w- c:\documents and settings\Home\Local Settings\Application Data\Xenocode
2012-01-24 15:57 . 2012-01-24 15:57 -------- d-----w- C:\b7e1a371c2a2c81df298cb6c32f91a9b
2012-01-23 11:27 . 2012-01-23 11:27 556958 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2012-01-23 10:48 . 2012-01-24 15:57 -------- d-----w- c:\program files\3991B
2012-01-20 08:17 . 2001-08-17 22:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2012-01-20 08:17 . 2008-04-14 05:42 159232 ----a-w- c:\windows\system32\ptpusd.dll
2012-01-20 08:17 . 2008-04-14 00:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2012-01-20 08:17 . 2008-04-14 00:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2012-01-17 13:49 . 2012-01-17 14:11 -------- d-----w- c:\documents and settings\Home\Application Data\vlc
2012-01-17 13:35 . 2012-01-17 13:35 -------- d-----w- c:\program files\VideoLAN
2012-01-16 09:54 . 2012-01-16 09:54 -------- d-----w- c:\program files\uTorrent
2012-01-09 15:05 . 2012-01-09 15:23 -------- d-----w- c:\documents and settings\Home\Local Settings\Application Data\DuplicateCleaner
2012-01-09 15:05 . 2012-01-09 15:05 -------- d-----w- c:\program files\Duplicate Cleaner
2012-01-09 14:50 . 2012-01-09 14:50 -------- d-----w- c:\documents and settings\Home\Local Settings\Application Data\Ilivid Player
2012-01-09 14:50 . 2012-01-09 14:50 -------- dc----w- c:\documents and settings\All Users\Application Data\{B49A644A-1076-4A3D-B124-DAA7862F2318}
2012-01-09 14:49 . 2012-01-09 14:50 -------- d-----w- c:\program files\iLivid
2012-01-09 14:48 . 2012-01-09 14:48 -------- d-----w- c:\documents and settings\Home\Local Settings\Application Data\PackageAware
2012-01-06 08:52 . 2012-01-06 08:52 -------- d-----r- C:\Sandbox
2012-01-02 17:23 . 2012-01-02 17:32 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2012-01-02 17:20 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2012-01-02 17:19 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2012-01-02 17:16 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2012-01-02 17:14 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2012-01-02 17:14 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2012-01-02 17:11 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2012-01-02 17:10 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2012-01-02 11:35 . 2008-04-14 00:09 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
2012-01-02 11:35 . 2008-04-14 00:09 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2012-01-02 01:06 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2012-01-02 01:05 . 2011-02-17 13:18 357888 -c----w- c:\windows\system32\dllcache\srv.sys
2012-01-02 01:05 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2012-01-02 01:05 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2012-01-02 01:03 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2012-01-02 01:01 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2012-01-02 00:39 . 2012-01-02 00:39 -------- d-----w- c:\windows\system32\en
2012-01-02 00:39 . 2012-01-02 00:39 -------- d-----w- c:\windows\system32\bits
2012-01-02 00:12 . 2012-01-02 00:12 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\IObit
2012-01-01 23:31 . 2012-01-01 23:31 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
2012-01-01 21:31 . 2008-04-14 00:12 20992 ------w- c:\windows\system32\spupdwxp.exe
2012-01-01 21:30 . 2008-05-02 14:01 83968 ------w- c:\program files\Messenger\msgsc.dll
2012-01-01 21:29 . 2008-04-14 00:11 81920 ------w- c:\windows\system32\ieencode.dll
2012-01-01 20:53 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2012-01-01 20:52 . 2011-11-04 19:20 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-12-28 21:12 . 2011-12-28 22:19 -------- d-----w- C:\$AVG8.VAULT$
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-25 10:06 . 2010-11-09 16:03 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-23 13:59 . 2006-06-07 14:29 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2011-11-25 21:57 . 2004-08-04 12:00 293376 ----a-w- c:\windows\system32\winsrv(2).dll
2011-11-23 13:25 . 2004-08-04 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-18 12:35 . 2004-08-04 12:00 60416 ----a-w- c:\windows\system32\packager.exe
2011-11-16 09:14 . 2011-11-16 09:14 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-04 19:20 . 2004-08-04 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-04 12:00 1288704 ----a-w- c:\windows\system32\ole32.dll
2010-09-09 13:13 . 2010-09-09 13:13 74796 ----a-w- c:\program files\Uninstal.exe
2006-03-08 19:05 . 2006-01-24 21:27 4882944 ----a-w- c:\program files\Invoice.exe
2005-11-27 16:43 . 2006-01-24 21:27 1734656 ----a-w- c:\program files\Upgrade.exe
2006-10-16 03:24 . 2006-11-06 09:08 135680 -c--a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ipsec.sys
[-] 2008-04-13 19:19 . CD057E33BCFE1899F892AD8AA46793B8 . 75264 . . [9 Alpha217 RC34187 10.2298] . . c:\windows\system32\drivers\ipsec.sys
[7] 2004-08-04 . 64537AA5C003A6AFEEE1DF819062D0D1 . 74752 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ipsec.sys
.
[7] 2008-04-13 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ipsec.sys
[-] 2008-04-13 19:19 . CD057E33BCFE1899F892AD8AA46793B8 . 75264 . . [9 Alpha217 RC34187 10.2298] . . c:\windows\system32\drivers\ipsec.sys
[7] 2004-08-04 . 64537AA5C003A6AFEEE1DF819062D0D1 . 74752 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ipsec.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 14:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Home\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Home\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Home\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Home\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WizMouse"="c:\program files\WizMouse\WizMouse.exe" [2010-03-12 696568]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2011-06-15 1200128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-06-24 1193848]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Home\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Home\Application Data\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DSLMON.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DSLMON.lnk
backup=c:\windows\pss\DSLMON.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Home^Start Menu^Programs^Startup^ntuser_mssec.exe]
path=c:\documents and settings\Home\Start Menu\Programs\Startup\ntuser_mssec.exe
backup=c:\windows\pss\ntuser_mssec.exeStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-02-16 17:57 1945960 ------w- c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSSelectorReinstall]
2007-02-22 18:53 2209224 ----a-w- c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rap]
2011-01-05 14:57 173568 ----a-w- c:\program files\ert\3.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 11:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-02-16 17:45 1169776 ------w- c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UleadBurningHelper"=2 (0x2)
"NTService1"=2 (0x2)
"MaxBackServiceInt"=2 (0x2)
"InCDsrv"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
"WmiApSrvCOMSysApp"=2 (0x2)
"WinDefend"=2 (0x2)
"TuneUp.ProgramStatisticsSvc"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"SharedAccessFontCache3.0.0.0"=2 (0x2)
"RapportMgmtService"=2 (0x2)
"nlsX86cc"=2 (0x2)
"mfevtp"=2 (0x2)
"mfefire"=2 (0x2)
"MDM"=2 (0x2)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"McNaiAnn"=2 (0x2)
"mcmscsvc"=2 (0x2)
"McMPFSvc"=2 (0x2)
"McAfee SiteAdvisor Service"=2 (0x2)
"LiveUpdate"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"cbVSCService"=2 (0x2)
"bepldr"=3 (0x3)
"awhost32"=3 (0x3)
"aspnet_stateTuneUp.Defrag"=2 (0x2)
"ALGRemoteAccess"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MSConfig"=c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"flockbox"=c:\program files\My Lockbox\flockbox.exe /a
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"c:\\Documents and Settings\\Home\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Home\\Desktop\\New Folder\\utorrent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"8000:UDP"= 8000:UDP:Axon RTP Incoming Audio (UDP)
"81:TCP"= 81:TCP:Axon Web Server
.
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [05/02/2009 13:26 17264]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [06/08/2010 10:05 82952]
R1 RapportBuka;RapportBuka;c:\windows\system32\drivers\RapportBuka.sys [01/03/2010 09:18 390528]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [06/08/2010 10:05 312616]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [06/08/2010 10:05 88480]
S0 gqxx;gqxx;c:\windows\system32\drivers\vqjlrhk.sys --> c:\windows\system32\drivers\vqjlrhk.sys [?]
S1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [07/06/2010 17:07 0]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [07/06/2010 17:07 0]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\Home\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS --> c:\docume~1\Home\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\Home\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS --> c:\docume~1\Home\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [06/08/2010 10:05 55456]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys --> c:\windows\system32\Drivers\ANDROIDUSB.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [09/11/2010 16:03 40776]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [06/08/2010 10:05 88480]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [06/08/2010 10:05 83496]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [30/12/2008 10:40 47360]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - IPSEC
*NewlyCreated* - MPFILTER
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-27 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 15:28]
.
2012-01-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 15:39]
.
2012-01-26 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-12-18 14:31]
.
2012-01-26 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-12-18 14:31]
.
2012-01-27 c:\windows\Tasks\User_Feed_Synchronization-{03D4C59F-A6FE-40E7-9E53-5E441EF7C63F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = www.google.co.uk/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.1
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {13510606-30FA-11D2-B383-444553540000} - hxxps://tradezone.pws.co.uk/downloads/webclientV4/win32/omwebie.cab
.
.
------- File Associations -------
.
.scr=AutoCADLTScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-xf9poa4vaz - c:\documents and settings\Home\xf9poa4vaz.exe
HKLM-Run-xf9poa4vaz - c:\documents and settings\All Users\xf9poa4vaz.exe
SafeBoot-WinDefend
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-Jkewa - c:\windows\akozapow.dll
MSConfigStartUp-nonep - c:\docume~1\Home\LOCALS~1\Temp\tmp2aa42431\kkil.exe
MSConfigStartUp-Qburomukimupewu - c:\windows\cemsgole.dll
MSConfigStartUp-U36VRSFLG6 - c:\docume~1\Home\LOCALS~1\Temp\Xqd.exe
MSConfigStartUp-{083029C8-CE7A-82F4-F55C-F76A25C28629} - c:\documents and settings\Home\Application Data\Agnayf\coon.exe
AddRemove-Malwarebytes' Anti-Malware_is1 - g:\malwarebytes' anti-malware\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-01-27 14:31
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-725345543-1229272821-2147133589-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-725345543-1229272821-2147133589-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1B6AF4D0-6D2E-DCC1-3B68-3444D9A87159}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\InProcServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\System32\\msimtf.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'explorer.exe'(7424)
c:\windows\system32\WININET.dll
c:\documents and settings\Home\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\msdtc.exe
.
**************************************************************************
.
Completion time: 2012-01-27 14:43:36 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-27 14:43
.
Pre-Run: 127,285,747,712 bytes free
Post-Run: 128,010,223,616 bytes free
.
- - End Of File - - 2EB179F84C84A2D3D7EF1681D9418EAB