| thanks again for the help.
ComboFix 08-10-09.06 - jon eubanks 2008-10-10 11:11:38.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1832 [GMT -4:00] Running from: C:\Users\jon eubanks\Downloads\ComboFix.exe * Created a new restore point * Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\Windows\system32\x64
. ((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 ))))))))))))))))))))))))))))))) .
2008-10-10 11:00 . 2008-10-10 11:00 <DIR> d-------- C:\Program Files\Yahoo! 2008-10-10 10:59 . 2008-10-10 11:00 <DIR> d-------- C:\Program Files\CCleaner 2008-10-10 10:50 . 2008-10-10 10:50 <DIR> d-------- C:\Program Files\RegCure 2008-10-09 14:48 . 2008-10-09 14:48 <DIR> d-------- C:\Users\jon eubanks\AppData\Roaming\Malwarebytes 2008-10-09 14:48 . 2008-10-09 14:48 <DIR> d-------- C:\Users\All Users\Malwarebytes 2008-10-09 14:48 . 2008-10-09 14:48 <DIR> d-------- C:\ProgramData\Malwarebytes 2008-10-09 14:48 . 2008-10-09 14:48 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-10-09 14:48 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys 2008-10-09 14:48 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys 2008-10-08 21:27 . 2008-10-10 11:05 <DIR> d-a------ C:\Users\All Users\TEMP 2008-10-08 21:27 . 2008-10-10 11:05 <DIR> d-a------ C:\ProgramData\TEMP 2008-10-08 21:27 . 2004-08-04 07:00 506,368 --a------ C:\Windows\System32\msxml.dll 2008-10-08 15:12 . 2008-10-08 15:12 <DIR> d-------- C:\Users\jon eubanks\New Folder 2008-10-08 15:11 . 2008-10-08 15:17 <DIR> d-------- C:\Users\jon eubanks\major geek 2008-10-08 09:53 . 2008-10-08 09:53 <DIR> d-------- C:\Program Files\Trend Micro 2008-10-06 17:27 . 2008-10-08 15:34 <DIR> d-------- C:\Users\jon eubanks\AppData\Roaming\Apple Computer 2008-10-06 17:06 . 2008-10-06 17:06 <DIR> dr------- C:\Users\jon eubanks\Searches 2008-10-06 17:05 . 2008-10-06 17:06 <DIR> dr------- C:\Users\jon eubanks\Videos 2008-10-06 17:05 . 2008-10-06 17:06 <DIR> dr------- C:\Users\jon eubanks\Saved Games 2008-10-06 17:05 . 2008-10-06 17:06 <DIR> dr------- C:\Users\jon eubanks\Pictures 2008-10-06 17:05 . 2008-10-08 15:35 <DIR> dr------- C:\Users\jon eubanks\Music 2008-10-06 17:05 . 2008-10-08 15:15 <DIR> dr------- C:\Users\jon eubanks\Links 2008-10-06 17:05 . 2008-10-10 11:09 <DIR> dr------- C:\Users\jon eubanks\Downloads 2008-10-06 17:05 . 2008-10-06 17:06 <DIR> dr------- C:\Users\jon eubanks\Documents 2008-10-06 17:05 . 2008-10-06 17:05 <DIR> dr------- C:\Users\jon eubanks\Contacts 2008-10-06 17:05 . 2008-10-07 12:08 <DIR> d-------- C:\Users\jon eubanks\AppData\Roaming\Sony Corporation 2008-10-06 17:05 . 2006-11-02 08:37 <DIR> d-------- C:\Users\jon eubanks\AppData\Roaming\Media Center Programs 2008-10-06 17:05 . 2008-10-06 17:06 <DIR> d--h----- C:\Users\jon eubanks\AppData 2008-10-06 17:05 . 2008-10-08 15:12 <DIR> d-------- C:\Users\jon eubanks 2008-10-06 16:59 . 2008-10-06 16:59 <DIR> d-------- C:\Program Files\Microsoft Silverlight 2008-10-06 13:30 . 2008-10-08 17:54 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy 2008-10-06 13:30 . 2008-10-08 17:54 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy 2008-10-06 13:30 . 2008-10-07 12:01 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy 2008-10-06 11:18 . 2008-10-06 17:25 <DIR> d-------- C:\Program Files\Windows Live Safety Center 2008-10-05 09:24 . 2008-10-06 14:13 <DIR> d-------- C:\Users\jonathan\AppData\Roaming\uTorrent 2008-10-04 17:53 . 2008-10-05 21:42 <DIR> d--h----- C:\$AVG8.VAULT$ 2008-10-04 15:10 . 2008-10-04 15:10 <DIR> d-------- C:\Users\All Users\Google 2008-10-04 15:10 . 2008-10-04 15:47 <DIR> d-------- C:\Program Files\Google 2008-10-04 15:02 . 2008-10-10 11:07 <DIR> d-------- C:\Windows\System32\drivers\Avg 2008-10-04 15:02 . 2008-10-04 15:02 <DIR> d-------- C:\Users\All Users\avg8 2008-10-04 15:02 . 2008-10-04 15:02 <DIR> d-------- C:\ProgramData\avg8 2008-10-04 15:02 . 2008-10-04 15:02 <DIR> d-------- C:\Program Files\AVG 2008-10-04 15:02 . 2008-10-04 15:02 97,928 --a------ C:\Windows\System32\drivers\avgldx86.sys 2008-10-04 15:02 . 2008-10-04 15:02 69,128 --a------ C:\Windows\System32\drivers\avgwfpx.sys 2008-10-04 15:02 . 2008-10-04 15:02 10,520 --a------ C:\Windows\System32\avgrsstx.dll 2008-10-04 12:26 . 2008-10-04 12:26 <DIR> d-------- C:\Users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-10-04 12:26 . 2008-10-04 12:26 <DIR> d-------- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-10-04 12:26 . 2008-10-04 12:26 <DIR> d-------- C:\Program Files\iTunes 2008-10-04 12:26 . 2008-10-04 12:26 <DIR> d-------- C:\Program Files\iPod 2008-10-04 12:26 . 2008-04-17 13:12 107,368 --a------ C:\Windows\System32\GEARAspi.dll 2008-10-04 12:26 . 2008-04-17 13:12 15,464 --a------ C:\Windows\System32\drivers\GEARAspiWDM.sys 2008-10-01 13:01 . 2008-10-01 13:01 32,000 --a------ C:\Windows\System32\drivers\usbaapl.sys 2008-09-11 15:34 . 2008-07-30 21:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll 2008-09-11 15:34 . 2008-07-30 23:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll 2008-09-11 15:27 . 2008-08-01 21:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys 2008-09-11 15:27 . 2008-06-25 23:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll 2008-09-11 15:27 . 2008-06-25 23:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll 2008-09-11 15:27 . 2008-05-08 15:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys 2008-09-11 15:27 . 2008-05-19 22:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys 2008-09-11 15:27 . 2008-06-25 23:29 45,056 --a------ C:\Windows\System32\dataclen.dll 2008-09-11 15:27 . 2008-08-01 23:26 36,864 --a------ C:\Windows\System32\cdd.dll
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-06 02:11 --------- d-----w C:\Users\jonathan\AppData\Roaming\Apple Computer 2008-10-04 19:09 --------- d-----w C:\Program Files\Java 2008-10-04 16:26 --------- d-----w C:\ProgramData\Apple Computer 2008-10-04 16:24 --------- d-----w C:\Program Files\QuickTime 2008-10-04 16:24 --------- d-----w C:\Program Files\Common Files\Apple 2008-10-04 16:18 --------- d-----w C:\Program Files\Bonjour 2008-09-21 22:34 --------- d-----w C:\Users\jonathan\AppData\Roaming\Sony Corporation 2008-09-12 16:16 --------- d-----w C:\ProgramData\Microsoft Help 2008-08-29 14:18 87,336 ----a-w C:\Windows\System32\dns-sd.exe 2008-08-29 13:53 61,440 ----a-w C:\Windows\System32\dnssd.dll 2008-08-28 01:09 --------- d-----w C:\Program Files\Apple Software Update 2008-08-27 22:09 --------- d-----w C:\Program Files\Safari 2008-08-27 14:37 --------- d-----w C:\Program Files\Windows Mail 2008-07-31 04:24 3,452 --sha-w C:\Windows\System32\KGyGaAvL.sys 2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll 2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll 2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll 2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe 2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll 2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll 2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll 2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll 2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll 2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll 2008-07-19 02:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll 2008-07-19 00:44 31,232 ----a-w C:\Windows\System32\wuapp.exe 2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll 2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini .
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AOLOverlayIcon] @="{AB0C8BE3-041C-47d6-8195-E089D32B38DD}" [HKEY_CLASSES_ROOT\CLSID\{AB0C8BE3-041C-47d6-8195-E089D32B38DD}] 2008-02-02 20:27 303104 --------- C:\DDI\overicon.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920] "RegistryMechanic"="C:\Program Files\Registry Mechanic\RMTray.exe" [2008-07-03 812952] "WindowsWelcomeCenter"="oobefldr.dll" [2008-01-20 C:\Windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-04 141848] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-04 154136] "Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-04 137752] "Apoint"="C:\Program Files\Apoint\Apoint.exe" [2008-02-22 122880] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792] "ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-11-21 311296] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "VAIOMyMemCenter"="C:\Program Files\Sony\VAIO My Memory Center\VAIO MyMemCenter.exe" [2008-02-29 679936] "VWLASU"="C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe" [2008-02-19 24576] "VAIO Help and Support Demo"="C:\Program Files\Sony\VAIO Help and Support Demo\LaunchVHSD.exe" [2007-08-27 290816] "VAIORegistration"="C:\Program Files\Sony\First Experience\WelcomeLauncher.exe" [2007-10-17 20480] "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 624248] "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160] "TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" [2006-10-30 3576512] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696] "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-04 1234712] "RtHDVCpl"="RtHDVCpl.exe" [2008-01-22 C:\Windows\RtHDVCpl.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-11-13 972064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2007-08-14 23:05 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{716F4DA6-7120-4796-8FB3-9DE89E939A78}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{4451C8BB-5F7B-4E0B-BC88-AFC72E97E929}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{0A0B8C11-98E6-4ED5-9B29-A584EDFC1789}"= UDP:3703:Adobe Version Cue CS3 Server "{7B0A84A7-3F19-490E-8F75-B1661C41E421}"= UDP:3704:Adobe Version Cue CS3 Server "{327A4C24-09FB-4794-9A60-E186580F1726}"= UDP:50900:Adobe Version Cue CS3 Server "{B99F514C-7A41-4942-BF98-8AA1F2F7A128}"= UDP:50901:Adobe Version Cue CS3 Server "{0D3DF764-70A3-453B-AABE-5AB391585C28}"= UDP:C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server "{C47ECD57-B810-4218-B7E6-B8CC49836EBB}"= TCP:C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe:Adobe Version Cue CS3 Server "{4C8049CD-FA0E-4B48-BCB8-B9A21A4036EF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{471DB945-DF75-4839-848B-7E7FBEC2AD78}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "{AAF0264C-5E3A-427F-B0F1-58C6C518525B}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour "{0D5272AA-5C58-463A-8161-AF2A188AEAD1}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour "{BA649E71-1E6B-4FD9-8A61-4FE39CC2CAD1}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe "{D4A20B57-08DC-41BD-95FC-2D93B4D21341}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe "{42187B64-F3C1-4882-902F-DCB7EC85CD64}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{8591073E-9239-49B0-B293-39CD81AC1DE5}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-10-04 97928] R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-04 875288] R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-04 231704] R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-17 11032] R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296] R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2008-03-03 333088] R3 AvgWfpX;AVG Free8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-10-04 69128] R3 SFEP;Sony Firmware Extension Parser;C:\Windows\system32\DRIVERS\SFEP.sys [2007-12-16 9344] R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-06-05 812544] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2008-02-05 246784] S3 SOHCImp;VAIO Media plus Content Importer;C:\Program Files\Sony\VAIO Media plus\SOHCImp.exe [2008-03-04 104288] S3 SOHDms;VAIO Media plus Digital Media Server;C:\Program Files\Sony\VAIO Media plus\SOHDms.exe [2008-03-04 350048] S3 SOHDs;VAIO Media plus Device Searcher;C:\Program Files\Sony\VAIO Media plus\SOHDs.exe [2008-03-04 63328] S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2008-03-03 87328] S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656] S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]
*Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder
2008-10-10 C:\Windows\Tasks\RegCure Program Check.job - C:\Program Files\RegCure\RegCure.exe [2008-04-21 17:21]
2008-10-10 C:\Windows\Tasks\RegCure.job - C:\Program Files\RegCure\RegCure.exe [2008-04-21 17:21] . . ------- Supplementary Scan ------- . FireFox -: Profile - C:\Users\jon eubanks\AppData\Roaming\Mozilla\Firefox\Profiles\ux2tngqx.default\ FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll .
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-10-10 11:14:31 Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . Completion time: 2008-10-10 11:15:57 ComboFix-quarantined-files.txt 2008-10-10 15:15:54
Pre-Run: 19,216,654,336 bytes free Post-Run: 19,201,593,344 bytes free
214 --- E O F --- 2008-10-09 18:43:17
|