Rorschach112,
Thanks for the quick response!
Here are the things that I did and could not do.
Since I cannot connect to the internet, I had to install the Recovery Console from the CD. It was installed successfully.
-- I was able to disable the Spybot resident program, but not McAfee (I have the AOL version). So ComboFix ran with McAfee active
-- When I ran ComboFix, it rebooted my PC. Not sure if that was supposed to happen.
-- After ComboFix ran, I first tried to open a browser, could not connect.
-- I tried to do a 'ipconfig /renew' but received the same message: "An error occurred while renewing interface Local Area Connection : The RPC server is unavailable"
-- In Control Panel -> Network Connections, there are no connections to show. I could not create a new one or do a Network Toubleshoot. I get a window with the message, "Windows cannot open Help and Support because a system service is not running. To fix this problem, start the service named 'Help and Support'."
ComboFix log is below.
Looking forward to next steps.
-------------------
ComboFix 08-12-07.01 - Mario 2008-12-08 13:26:52.1 - NTFSx86
Running from: c:\documents and settings\Mario\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TCPSR
((((((((((((((((((((((((( Files Created from 2008-11-08 to 2008-12-08 )))))))))))))))))))))))))))))))
.
2008-12-07 22:35 . 2008-12-07 22:35 <DIR> d-------- c:\program files\Trend Micro
2008-12-07 22:33 . 2008-12-07 22:34 <DIR> d-------- c:\program files\ERUNT
2008-12-07 22:31 . 2008-12-07 19:58 791,393 --a------ c:\documents and settings\Mario\erunt_setup.exe
2008-12-07 22:28 . 2008-12-07 22:16 812,344 --a------ C:\HJTInstall.exe
2008-12-07 22:28 . 2008-12-07 19:57 9,334 --a------ C:\SysRestorePoint_v13.zip
2008-12-05 20:19 . 2008-12-07 23:04 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-05 20:19 . 2008-12-05 20:19 <DIR> d-------- c:\documents and settings\Mario\Application Data\Malwarebytes
2008-12-05 20:19 . 2008-12-05 20:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-05 20:19 . 2008-12-03 19:58 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-05 20:19 . 2008-12-03 19:58 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-05 18:28 . 2008-12-05 18:19 150,104 --a------ C:\documentsandsettings
2008-12-02 23:37 . 2008-12-02 23:37 <DIR> d-------- c:\program files\Linksys
2008-12-02 23:37 . 2008-12-02 23:37 <DIR> d-------- c:\program files\Funk Software
2008-12-02 23:37 . 2008-12-02 23:37 <DIR> d-------- c:\program files\Common Files\Funk Software
2008-12-02 23:37 . 2004-12-17 13:52 17,992 --a------ c:\windows\system32\drivers\bcm42rly.sys
2008-12-02 23:37 . 2004-12-17 13:52 17,992 --a------ c:\windows\system32\bcm42rly.sys
2008-12-02 23:32 . 2003-07-16 22:43 94,208 --a------ c:\windows\system32\W32N50CT.dll
2008-12-02 23:32 . 2003-07-16 22:28 17,142 --a------ c:\windows\system32\CBTNDIS5.sys
2008-12-02 23:32 . 1998-05-13 00:00 4,716 --a------ c:\windows\system32\VERSION.LIB
2008-12-02 23:32 . 2008-12-02 23:37 64 --a------ c:\windows\init.ini
2008-12-02 23:10 . 2005-02-12 00:46 371,712 -ra------ c:\windows\system32\drivers\BCMWL5.SYS
2008-12-02 22:26 . 2008-12-02 22:26 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\SACore
2008-12-01 21:43 . 2008-12-01 21:43 <DIR> d-------- c:\windows\system32\CatRoot_bak
2008-11-24 12:04 . 2008-11-24 12:04 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-11-24 10:38 . 2008-11-24 10:39 <DIR> d-------- c:\program files\iTunes
2008-11-24 10:38 . 2008-11-24 10:38 <DIR> d-------- c:\program files\iPod
2008-11-24 10:38 . 2008-11-24 10:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-24 10:35 . 2008-11-24 10:36 <DIR> d-------- c:\program files\QuickTime
2008-11-24 10:29 . 2008-11-24 10:29 <DIR> d-------- c:\program files\Bonjour
2008-11-24 09:33 . 2008-11-24 09:33 <DIR> d-------- c:\program files\PC Drivers HeadQuarters
2008-11-24 09:33 . 2008-11-24 09:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-11-20 21:47 . 2008-11-20 21:47 207 --a------ c:\windows\wininit.ini
2008-11-19 22:47 . 2008-11-19 22:47 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-11-19 22:47 . 2008-11-19 22:51 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
2008-11-19 22:47 . 2008-11-19 22:47 <DIR> d-------- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-11-19 22:47 . 2008-11-19 22:47 <DIR> d-------- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-11-19 20:09 . 2004-08-04 05:00 4,224 --a------ c:\windows\system32\drivers\beep.sys
2008-11-19 20:09 . 2004-08-04 05:00 4,224 --a--c--- c:\windows\system32\dllcache\beep.sys
2008-11-18 19:10 . 2004-08-04 05:00 1,875,968 --a--c--- c:\windows\system32\dllcache\msir3jp.lex
2008-11-18 19:09 . 2004-08-04 05:00 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2008-11-18 19:08 . 2004-08-04 05:00 1,677,824 --a--c--- c:\windows\system32\dllcache\chsbrkr.dll
2008-11-18 19:06 . 2008-11-18 19:06 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-11-18 19:05 . 2004-08-04 05:00 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
2008-11-18 19:05 . 2008-11-18 19:05 749 -rah----- c:\windows\WindowsShell.Manifest
2008-11-18 19:05 . 2008-11-18 19:05 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-11-18 19:05 . 2008-11-18 19:05 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-11-18 19:05 . 2008-11-18 19:05 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-11-18 18:57 . 2004-08-04 05:00 24,661 --a------ c:\windows\system32\spxcoins.dll
2008-11-18 18:57 . 2004-08-04 05:00 24,661 --a--c--- c:\windows\system32\dllcache\spxcoins.dll
2008-11-18 18:57 . 2004-08-04 05:00 13,312 --a------ c:\windows\system32\irclass.dll
2008-11-18 18:57 . 2004-08-04 05:00 13,312 --a--c--- c:\windows\system32\dllcache\irclass.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-07 23:50 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-03 04:37 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-02 02:58 14,336 ----a-w c:\windows\system32\svchost.exe
2008-11-24 15:42 --------- d-----w c:\program files\Apple Software Update
2008-11-24 13:44 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-22 22:17 --------- d-----w c:\program files\AOL Toolbar
2008-11-21 03:47 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-31 21:02 --------- d-----w c:\documents and settings\Mario\Application Data\GARMIN
2008-10-31 21:02 --------- d-----w c:\documents and settings\All Users\Application Data\GARMIN
2008-10-31 20:26 --------- d-----w c:\program files\Google
2008-10-31 13:48 --------- d-----w c:\program files\McAfee
2008-10-28 23:43 --------- d-----w c:\documents and settings\Mario\Application Data\Apple Computer
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
.
------- Sigcheck -------
2008-12-01 21:58 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\svchost.exe
2008-11-19 22:34 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\dllcache\svchost.exe
2005-03-02 13:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 10:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-04 05:00 577024 c72661f8552ace7c5c85e16a3cf505c4 c:\windows\$NtUninstallKB890859$\user32.dll
2005-03-02 13:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
2004-08-04 05:00 577024 c72661f8552ace7c5c85e16a3cf505c4 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\user32.dll
2004-08-04 05:00 577024 c72661f8552ace7c5c85e16a3cf505c4 c:\windows\system32\user32.dll
2004-08-04 05:00 577024 c72661f8552ace7c5c85e16a3cf505c4 c:\windows\system32\dllcache\user32.dll
2004-08-04 05:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\ws2_32.dll
2004-08-04 05:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2004-08-04 05:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\dllcache\ws2_32.dll
2006-03-03 22:58 663552 c0845ecbf4f9164e618ee381b79c9032 c:\windows\$hf_mig$\KB912812\SP2QFE\wininet.dll
2007-02-20 04:52 665600 b258c922d22deec880b60720531d7627 c:\windows\$hf_mig$\KB931768\SP2QFE\wininet.dll
2007-04-18 07:46 665600 4261ba03afd659de04f0a17dfbdd454d c:\windows\$hf_mig$\KB933566\SP2QFE\wininet.dll
2007-06-26 09:35 665600 e1a3dd68b5380b360a7310a64d9bb188 c:\windows\$hf_mig$\KB937143\SP2QFE\wininet.dll
2007-08-22 07:55 665600 a1bc17eb3758d73c3938b2318820f5b4 c:\windows\$hf_mig$\KB939653\SP2QFE\wininet.dll
2007-10-11 00:57 666112 80d660a49e0d118144423099b2a9f5da c:\windows\$hf_mig$\KB942615\SP2QFE\wininet.dll
2007-10-10 18:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-06 21:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 08:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-22 22:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 11:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-08-26 04:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2006-03-03 22:33 658432 1c0979c7a489bee573cd0bf4ad94bb06 c:\windows\$NtUninstallKB931768$\wininet.dll
2007-02-20 04:48 658944 30d1c47e40efbb792ff8d3c3b51ce507 c:\windows\$NtUninstallKB933566$\wininet.dll
2007-04-18 07:31 658944 b7156cd97e739f3014bc4d61758f868a c:\windows\$NtUninstallKB937143$\wininet.dll
2007-06-26 09:09 658944 184e47c8f7b331025e6dc92740db188f c:\windows\$NtUninstallKB939653$\wininet.dll
2007-08-22 08:12 658944 1901ad51da8be9f8b38d5d526e5d1788 c:\windows\$NtUninstallKB942615$\wininet.dll
2007-10-11 01:13 659456 2005ad86a22aee68e21ee59f9ccb77f2 c:\windows\ie7\wininet.dll
2007-08-13 18:54 818688 a4a0fc92358f39538a6494c42ef99fe9 c:\windows\ie7updates\KB942615-IE7\wininet.dll
2007-10-10 18:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll
2007-12-06 21:21 824832 806d274c9a6c3aaea5eae8e4af841e04 c:\windows\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 08:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll
2008-04-22 23:16 826368 f6589be784647cfdbc22ea51ccb1a57a c:\windows\ie7updates\KB953838-IE7\wininet.dll
2008-06-23 11:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
2008-08-20 00:38 659456 87e694d09893978f22024feeedf35342 c:\windows\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp2gdr\wininet.dll
2008-08-20 00:33 667648 c91e3a6ef094202f6b5ca8960dfcf243 c:\windows\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp2qfe\wininet.dll
2008-08-20 00:30 666112 9af5f25124fbdc36e2b510729cba2674 c:\windows\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3gdr\wininet.dll
2008-08-19 23:58 666624 94418f53d2612c26dbadc04dafbc197c c:\windows\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3qfe\wininet.dll
2006-03-03 22:33 658432 1c0979c7a489bee573cd0bf4ad94bb06 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\wininet.dll
2006-03-03 22:33 658432 1c0979c7a489bee573cd0bf4ad94bb06 c:\windows\system32\wininet.dll
2006-03-03 22:33 658432 1c0979c7a489bee573cd0bf4ad94bb06 c:\windows\system32\dllcache\wininet.dll
2006-04-20 07:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 11:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 05:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 06:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 06:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2004-08-04 05:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
2007-10-30 12:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\tcpip.sys
2004-08-04 05:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\system32\dllcache\tcpip.sys
2004-08-04 05:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\system32\drivers\tcpip.sys
2004-08-04 05:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\winlogon.exe
2004-08-04 05:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\winlogon.exe
2004-08-04 05:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\system32\dllcache\winlogon.exe
2004-08-04 05:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\ndis.sys
2004-08-04 05:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\dllcache\ndis.sys
2004-08-04 05:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2004-08-04 05:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\ip6fw.sys
2004-08-04 05:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\dllcache\ip6fw.sys
2004-08-04 05:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2005-03-01 19:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2005-03-29 20:01 2056832 9a06915a29434202e8d39456822b3a12 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
2005-03-29 20:01 2056832 9a06915a29434202e8d39456822b3a12 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2004-08-03 22:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\ntkrnlpa.exe
2008-08-14 04:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntkrnlpa.exe
2008-08-14 04:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntkrnlpa.exe
2008-08-14 04:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntkrnlpa.exe
2008-08-14 15:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntkrnlpa.exe
2005-03-29 20:01 2056832 9a06915a29434202e8d39456822b3a12 c:\windows\system32\ntkrnlpa.exe
2005-03-01 20:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2005-03-29 20:23 2179584 255449e7f00e23d9b10ae8cdd5f73e56 c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
2005-03-29 20:23 2179584 255449e7f00e23d9b10ae8cdd5f73e56 c:\windows\Driver Cache\i386\ntoskrnl.exe
2004-08-03 23:20 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\ntoskrnl.exe
2008-08-14 05:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2GDR\ntoskrnl.exe
2008-08-14 04:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP2QFE\ntoskrnl.exe
2008-08-14 05:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3GDR\ntoskrnl.exe
2008-08-14 16:11 2189184 31914172342bff330063f343ac6958fe c:\windows\SoftwareDistribution\Download\e76b316b6389286fbb342d033e63f1ba\SP3QFE\ntoskrnl.exe
2005-03-29 20:23 2179584 255449e7f00e23d9b10ae8cdd5f73e56 c:\windows\system32\ntoskrnl.exe
2004-08-04 05:00 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
2007-06-13 06:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-04 05:00 1032192 a0732187050030ae399b241436565e64 c:\windows\$NtUninstallKB938828$\explorer.exe
2004-08-04 05:00 1032192 a0732187050030ae399b241436565e64 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\explorer.exe
2004-08-04 05:00 1032192 a0732187050030ae399b241436565e64 c:\windows\system32\dllcache\explorer.exe
2004-08-04 05:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\services.exe
2004-08-04 05:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\services.exe
2004-08-04 05:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\dllcache\services.exe
2004-08-04 05:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\lsass.exe
2004-08-04 05:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe
2004-08-04 05:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\dllcache\lsass.exe
2004-08-04 05:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\ctfmon.exe
2004-08-04 05:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe
2004-08-04 05:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\dllcache\ctfmon.exe
2005-06-10 19:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2004-08-04 05:00 57856 7435b108b935e42ea92ca94f59c8e717 c:\windows\$NtUninstallKB896423$\spoolsv.exe
2004-08-04 05:00 57856 7435b108b935e42ea92ca94f59c8e717 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\spoolsv.exe
2004-08-04 05:00 57856 7435b108b935e42ea92ca94f59c8e717 c:\windows\system32\spoolsv.exe
2004-08-04 05:00 57856 7435b108b935e42ea92ca94f59c8e717 c:\windows\system32\dllcache\spoolsv.exe
2004-08-04 05:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\userinit.exe
2004-08-04 05:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2004-08-04 05:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\dllcache\userinit.exe
2004-08-04 05:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\SoftwareDistribution\Download\7684fcdc5c1747eb53ef3c2d202add11\backup\termsrv.dll
2004-08-04 05:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\termsrv.dll
2004-08-04 05:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"gStart"="c:\garmin\gStart.exe" [2008-08-13 1891416]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="c:\program files\Common Files\AOL\1178819297\ee\AOLSoftware.exe" [2006-09-25 50736]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2007-05-10 26112]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"Pure Networks Port Magic"="c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-04-05 99480]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 c:\windows\BCMSMMSG.exe]
"nwiz"="nwiz.exe" [2004-10-26 c:\windows\system32\nwiz.exe]
c:\documents and settings\Mario\Start Menu\Programs\Startup\
MotionBased Agent.lnk - c:\program files\MotionBased\Agent\MBAgent.exe [2006-12-30 909312]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
Wireless-G Notebook Adapter.lnk - c:\program files\Linksys\Wireless-G Notebook Adapter\Gcc.exe [2008-12-02 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
*Newly Created Service* - HELPSVC
.
Contents of the 'Scheduled Tasks' folder
2008-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-11-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
HKLM-Run-rs32net - c:\windows\System32\rs32net.exe
HKLM-Run-brastk - brastk.exe
HKU-Default-Run-brastk - c:\windows\system32\brastk.exe
Notify-jdpwomrr - jdpwomrr.dll
SafeBoot-ati0ptxx.sys
SafeBoot-ati5inxx.sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
- c:\windows\Downloaded Program Files\WscWlanScannerCtrl_cab.inf
FireFox -: Profile - c:\documents and settings\Mario\Application Data\Mozilla\Firefox\Profiles\5b5a5iup.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.cnn.com
FF -: plugin - c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-08 13:32:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(908)
c:\program files\Funk Software\Funk Client\odLogin.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\McAfee\SiteAdvisor\McSACore.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
c:\windows\system32\nvsvc32.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\program files\Common Files\AOL\1178819297\EE\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
c:\program files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
.
**************************************************************************
.
Completion time: 2008-12-08 13:37:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-08 18:37:01
Pre-Run: 45,129,916,416 bytes free
Post-Run: 46,623,010,816 bytes free
307 --- E O F --- 2008-11-13 04:37:55