Hello.
you didnt understandme what I meant by the comments was that the combofix programme was very time consuming and that it had completed 50 stages and it was supposed to restart where it was kind of stuck at the shutting down screen but anyway its past that now, the log is pasted below BUT there is a issue every time I click internet explorer or any other software and even conrol panel it comes up with the error message with "Illegal operation attempted on a registry key that has been marked for deletion". I am yet to restart my computer myself after running the combofix programme.
Thanks
ComboFix - Hussains 18/02/2010 19:35:02.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2045.1026 [GMT 0:00]
Running from: c:\users\Hussains\Desktop\COMBOFIX.EXE
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-2072669260-3456327829-1688835100-1002
c:\$recycle.bin\S-1-5-21-2072669260-3456327829-1688835100-1003
c:\$recycle.bin\S-1-5-21-2072669260-3456327829-1688835100-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\users\Hussains\AppData\Roaming\inst.exe
c:\windows\system32\twain_32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))
.
2010-02-18 19:47 . 2010-02-18 22:08 -------- d-----w- c:\users\Hussains\AppData\Local\temp
2010-02-18 19:47 . 2010-02-18 19:47 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp
2010-02-18 19:47 . 2010-02-18 19:47 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-02-18 19:47 . 2010-02-18 19:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-18 18:42 . 2010-02-18 18:42 -------- d-----w- c:\program files\Trend Micro
2010-02-18 18:40 . 2010-02-18 18:52 -------- d-----w- c:\program files\SpywareGuard
2010-02-18 18:28 . 2010-02-18 18:28 -------- d-----w- c:\program files\CleanUp!
2010-02-18 18:17 . 2009-11-15 22:48 17408 ----a-w- c:\windows\system32\drivers\DiagnosticScan.SYS
2010-02-18 18:17 . 2009-10-19 10:21 5120 ----a-w- c:\windows\system32\drivers\Start1Driver.SYS
2010-02-18 18:17 . 2010-02-18 19:18 -------- d-----w- c:\program files\AA
2010-02-18 15:39 . 2010-02-18 15:58 2560 ----a-w- c:\windows\system32\drivers\MCHINJDRV.SYS
2010-02-18 00:12 . 2010-02-18 02:57 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-02-18 00:12 . 2010-02-18 01:31 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-17 23:16 . 2010-02-17 23:16 -------- d-----w- c:\program files\CCleaner
2010-02-17 00:21 . 2010-02-17 00:21 -------- d-----w- c:\windows\Sun
2010-02-16 22:20 . 2010-02-16 22:20 -------- d-----w- c:\users\Hussains\DoctorWeb
2010-02-16 21:52 . 2010-02-18 17:29 -------- d-----w- C:\$AVG
2010-02-16 21:52 . 2010-02-16 21:52 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-16 21:52 . 2010-02-16 21:52 25608 ----a-w- c:\windows\system32\drivers\AVGIDSvx.sys
2010-02-16 21:52 . 2010-02-16 21:52 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-02-16 21:52 . 2010-02-16 21:52 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-16 21:51 . 2010-02-16 21:51 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-16 21:51 . 2010-02-16 21:51 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-16 21:51 . 2010-02-18 03:18 -------- d-----w- c:\windows\system32\drivers\Avg
2010-02-16 21:44 . 2010-02-16 21:44 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2010-02-16 21:44 . 2010-02-16 21:44 -------- d-----w- c:\programdata\avg9
2010-02-16 21:40 . 2010-02-16 21:44 -------- d-----w- c:\program files\AVG
2010-02-16 21:01 . 2010-02-18 03:30 -------- d-----w- c:\program files\Windows Live Safety Center
2010-01-28 20:21 . 2010-01-28 20:21 -------- d-----w- c:\users\Default\AppData\Roaming\Trusteer
2010-01-28 16:34 . 2008-08-26 09:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-01-28 16:34 . 2010-01-28 16:34 -------- d-----w- c:\program files\PC Connectivity Solution
2010-01-28 16:26 . 2010-01-28 16:26 -------- d-----w- c:\programdata\OviInstallerCache
2010-01-28 16:04 . 2010-01-28 16:04 -------- d-----w- c:\program files\Common Files\Java
2010-01-21 16:12 . 2010-01-21 16:12 552 ----a-w- c:\users\Hussains\AppData\Local\d3d8caps.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-18 22:05 . 2009-06-26 17:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-18 17:58 . 2008-02-24 18:43 1356 ----a-w- c:\users\Hussains\AppData\Local\d3d9caps.dat
2010-02-18 03:59 . 2009-12-16 16:30 -------- d-----w- c:\users\Hussains\AppData\Roaming\vlc
2010-02-17 23:35 . 2009-05-22 19:50 -------- d-----w- c:\program files\ExpressVids
2010-02-17 14:25 . 2009-12-31 00:53 -------- d-----w- c:\program files\Yahoo!
2010-02-17 14:25 . 2009-12-31 00:54 -------- d-----w- c:\programdata\Yahoo!
2010-02-17 04:14 . 2009-05-24 16:25 -------- d--h--w- c:\programdata\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2010-02-17 04:14 . 2009-05-24 16:21 -------- d--h--w- c:\programdata\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
2010-02-17 04:14 . 2009-05-24 16:01 -------- d--h--w- c:\programdata\{2840BBCB-9BEC-47F6-BA0F-10D3C34BF151}
2010-02-16 19:03 . 2009-05-24 16:01 -------- dc-h--w- c:\programdata\~4
2010-02-16 19:03 . 2009-05-24 15:33 -------- d-----w- c:\program files\Uniblue
2010-02-16 19:03 . 2009-05-24 16:21 -------- dc-h--w- c:\programdata\~3
2010-02-16 19:02 . 2009-05-24 16:27 -------- d-----w- c:\programdata\DriverScanner
2010-02-16 19:02 . 2009-05-24 16:25 -------- dc-h--w- c:\programdata\~2
2010-02-16 19:02 . 2008-09-09 16:50 -------- d-----w- c:\users\Hussains\AppData\Roaming\Uniblue
2010-02-15 13:16 . 2009-10-03 20:37 -------- d-----w- c:\users\Hussains\AppData\Roaming\U3
2010-02-14 17:15 . 2008-02-09 21:03 -------- d-----w- c:\users\Hussains\AppData\Roaming\uTorrent
2010-02-11 20:57 . 2009-02-17 16:22 -------- d-----w- c:\users\Hussains\AppData\Roaming\Zoom Player
2010-02-10 16:50 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-10 13:39 . 2007-08-29 12:41 -------- d-----w- c:\programdata\Microsoft Help
2010-02-01 07:41 . 2008-10-25 16:25 -------- d-----w- c:\program files\uTorrent
2010-01-28 16:36 . 2008-02-11 19:24 -------- d-----w- c:\program files\Common Files\Nokia
2010-01-28 16:35 . 2008-02-11 19:18 -------- d-----w- c:\program files\Nokia
2010-01-28 16:03 . 2008-01-27 17:32 -------- d-----w- c:\program files\Java
2010-01-21 21:59 . 2007-08-23 15:57 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-21 19:51 . 2007-08-29 21:00 -------- d-----w- c:\programdata\Messenger Plus!
2010-01-21 19:48 . 2007-08-29 20:16 -------- d-----w- c:\program files\Messenger Plus! Live
2010-01-21 19:18 . 2007-08-23 15:49 -------- d-----w- c:\programdata\Roxio
2010-01-20 19:00 . 2008-03-26 16:01 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-14 11:12 . 2009-10-02 17:29 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-11 16:20 . 2010-01-10 20:54 -------- d-----w- c:\programdata\boost_interprocess
2010-01-10 20:55 . 2010-01-10 20:54 -------- d-----w- c:\users\Hussains\AppData\Roaming\Multi File Downloader
2010-01-08 03:07 . 2008-02-11 19:20 -------- d-----w- c:\users\Hussains\AppData\Roaming\Nokia
2010-01-08 03:01 . 2010-01-08 03:01 -------- d-----w- c:\program files\Common Files\PCSuite
2010-01-08 02:54 . 2009-04-08 15:19 -------- d-----w- c:\programdata\Installations
2010-01-04 00:12 . 2007-08-29 10:46 117192 ----a-w- c:\users\Hussains\AppData\Local\GDIPFONTCACHEV1.DAT
2010-01-04 00:04 . 2007-08-23 15:57 -------- d-----w- c:\program files\Microsoft Works
2010-01-02 06:38 . 2010-01-22 16:27 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 16:27 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 16:27 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 16:27 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-31 00:57 . 2008-12-10 17:27 -------- d-----w- c:\users\Hussains\AppData\Roaming\Yahoo!
2009-12-17 17:14 . 2008-10-25 19:51 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-11 11:43 . 2010-02-10 13:21 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-11 11:43 . 2010-02-10 13:21 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-12-08 20:01 . 2010-02-10 13:21 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-12-08 20:01 . 2010-02-10 13:21 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 20:01 . 2010-02-10 13:21 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 17:26 . 2010-02-10 13:21 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-12-04 18:30 . 2010-02-10 13:21 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-04 18:29 . 2010-02-10 13:21 1314816 ----a-w- c:\windows\system32\quartz.dll
2009-12-04 18:28 . 2010-02-10 13:21 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-04 18:28 . 2010-02-10 13:21 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-04 18:28 . 2010-02-10 13:21 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-04 18:28 . 2010-02-10 13:21 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-04 18:28 . 2010-02-10 13:21 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-04 18:28 . 2010-02-10 13:21 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-04 18:27 . 2010-02-10 13:21 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-12-04 15:56 . 2010-02-10 13:21 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 15:56 . 2010-02-10 13:21 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 22:50 . 2007-09-21 20:39 117192 ----a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-30 11:52 . 2006-07-11 17:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
2007-08-23 23:24 . 2007-08-23 23:24 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-27 1830128]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe" [2008-08-14 240112]
"CPMonitor"="c:\program files\Roxio Creator 2009\5.0\CPMonitor.exe" [2008-08-10 80368]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-07 1176808]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-11-30 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"DelayShred"="c:\program files\mcafee\mshr\ShrCL.EXE" [2009-09-25 113168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
path=
backup=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 16:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
2009-07-22 18:16 2331936 ----a-w- c:\program files\Nokia\Nokia Music\NokiaMusic.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 23:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd3]
2006-09-19 08:07 827392 ----a-w- c:\windows\vsnpstd3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 16:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):3d,dc,ef,97,d9,df,c9,01
R0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\System32\drivers\AVGIDSvx.sys [16/02/2010 21:52 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [16/02/2010 21:52 161800]
R0 DiagnosticScan;DiagnosticScan;c:\windows\System32\drivers\DiagnosticScan.SYS [18/02/2010 18:17 17408]
R1 Avgfwfd;AVG network filter service;c:\windows\System32\drivers\avgfwd6x.sys [16/02/2010 21:44 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [16/02/2010 21:51 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\System32\drivers\avgtdix.sys [16/02/2010 21:52 360584]
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [11/01/2010 18:05 58984]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [11/01/2010 18:05 345832]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [26/05/2009 09:05 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [26/05/2009 09:05 72944]
R1 Start1Driver;Start1Driver;c:\windows\System32\drivers\Start1Driver.SYS [18/02/2010 18:17 5120]
R2 AERTFilters;Andrea RT Filters Service;c:\windows\System32\AERTSrv.exe [05/12/2007 06:17 77824]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [16/02/2010 21:49 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [16/02/2010 21:50 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [16/02/2010 21:48 5832712]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [08/09/2008 17:45 93320]
R2 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [18/02/2007 19:34 5376]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [11/01/2010 18:05 972008]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [18/02/2010 00:12 1153368]
R3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSDriver.sys [16/02/2010 21:49 122376]
R3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSFilter.sys [16/02/2010 21:49 30216]
R3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys [16/02/2010 21:48 27800]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [23/08/2007 15:54 5504]
S2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [06/04/2007 13:08 36312]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [14/08/2008 00:25 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [14/08/2008 00:24 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [14/08/2008 00:24 170480]
S2 TwonkyMedia;TwonkyMedia;c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 --> c:\program files\Nokia\Nokia Home Media Server\Media Server\TwonkyMedia.exe -serviceversion 0 [?]
S3 BPAO;BPAO;c:\users\Hussains\AppData\Local\Temp\BPAO.exe --> c:\users\Hussains\AppData\Local\Temp\BPAO.exe [?]
S3 DHTRACE;Intel(R) DHTrace Controller;c:\program files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [06/04/2007 13:08 39896]
S3 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [12/02/2007 09:46 208896]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [05/10/2009 19:15 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21:48 704864]
S3 NMSCore;Intel(R) NMSCore;c:\program files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe [06/04/2007 13:07 313816]
S3 QualityManager;Intel(R) Quality Manager;c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\QualityManager.exe [06/04/2007 13:10 272856]
S3 RBFV;RBFV;c:\users\Hussains\AppData\Local\Temp\RBFV.exe --> c:\users\Hussains\AppData\Local\Temp\RBFV.exe [?]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [14/08/2008 00:25 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [14/08/2008 00:23 1124848]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [26/05/2009 09:05 7408]
S3 WNGWEVFJ;WNGWEVFJ;c:\users\Hussains\AppData\Local\Temp\WNGWEVFJ.exe --> c:\users\Hussains\AppData\Local\Temp\WNGWEVFJ.exe [?]
S3 XTLUTZSHDTGFWL;XTLUTZSHDTGFWL;c:\users\Hussains\AppData\Local\Temp\XTLUTZSHDTGFWL.exe --> c:\users\Hussains\AppData\Local\Temp\XTLUTZSHDTGFWL.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2009-07-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2009-10-15 11:22]
2010-02-18 c:\windows\Tasks\User_Feed_Synchronization-{F6BA0F74-53E3-453D-B482-36B19CBCE83A}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Supplementary Scan -------
.
uStart Page = www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Hussains\AppData\Roaming\Mozilla\Firefox\Profiles\eyqfb1f3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true.
- - - - ORPHANS REMOVED - - - -
Notify-!SASWinLogon - c:\program files\SUPERAntiSpyware\SASWINLO.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-18 22:06
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x86A1E1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x84baad24
\Driver\ACPI -> acpi.sys @ 0x805bcd68
\Driver\atapi -> 0x86a1e1f8
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->Warning: possible MBR rootkit infection !
user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(6644)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\WUDFHost.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\windows\system32\Taskmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
.
**************************************************************************
.
Completion time: 2010-02-18 22:19:58 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-18 22:19
Pre-Run: 129,868,914,688 bytes free
Post-Run: 129,384,226,816 bytes free
- - End Of File - - 03720C8D4BAA4813BE0D116443AC73E1