Thankyou for your reply J SntgRvr.
Here is the log from Malwarebyte's Anti-Malware.
--- File Start ---Malwarebytes' Anti-Malware 1.39
Database version: 2468
Windows 6.0.6001 Service Pack 1
21/07/2009 3:58:30 PM
mbam-log-2009-07-21 (15-58-30).txt
Scan type: Quick Scan
Objects scanned: 85825
Time elapsed: 2 minute(s), 53 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
--- End of File ---After following the Combofix instructions I do not recall being prompted to 'Install the Recovery Console'.
Combofix detected the following:
C:\Windows\system32\drivers\SKYNETbjbqetep.sys
C:\Windows\system32\SKYNETfrmcurhd.dll
C:\Windows\system32\SKYNETdceqiqsx.dat
C:\Windows\system32\SKYNETxtkvddxp.dll
C:\Windows\system32\SKYNETtbplqoxx.dat
Here is the ComboFix.txt log file:
--- Start of File ---ComboFix 09-07-20.04 - tommy 21/07/2009 16:11.1.4 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.61.1033.18.3326.2449 [GMT 9.5:30]
Running from: c:\users\tommy\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3719346066-1755772926-2078216697-1001
c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500
c:\windows\system32\dc.exe
c:\windows\system32\drivers\SKYNETbjbqetep.sys
c:\windows\system32\SKYNETdceqiqsx.dat
c:\windows\system32\SKYNETfrmcurhd.dll
c:\windows\system32\SKYNETtbplqoxx.dat
c:\windows\system32\SKYNETxtkvddxp.dll
c:\windows\system32\wordpad.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETdpvcfxgi
((((((((((((((((((((((((( Files Created from 2009-06-21 to 2009-07-21 )))))))))))))))))))))))))))))))
.
2009-07-21 06:48 . 2009-07-21 06:49 -------- d-----w- c:\users\tommy\AppData\Local\temp
2009-07-21 06:48 . 2009-07-21 06:48 -------- d-----w- c:\users\Guest\AppData\Local\temp
2009-07-21 06:24 . 2009-07-13 04:06 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-21 06:24 . 2009-07-21 06:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-21 06:24 . 2009-07-13 04:06 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-15 07:57 . 2009-07-15 07:57 -------- d-----w- c:\programdata\id Software
2009-07-15 03:13 . 2009-06-15 15:24 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-15 03:13 . 2009-06-15 15:20 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-15 03:13 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-15 03:13 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-13 03:31 . 2009-07-13 03:31 625728 ----a-w- c:\programdata\id Software\QuakeLive\npquakezero.dll
2009-07-07 08:24 . 2009-07-07 08:24 -------- d-----w- c:\users\tommy\AppData\Roaming\SplashupLight.8F84E54D18819F0C71CA15FE192C56A89F17989F.1
2009-07-07 08:24 . 2009-07-07 08:24 -------- d-----w- c:\program files\Splashup Light
2009-07-07 03:37 . 2009-07-07 03:37 -------- d-----w- c:\programdata\WindowsSearch
2009-07-06 04:31 . 2009-07-06 04:31 2373712 ----a-w- c:\programdata\id Software\QuakeLive\pbsvc.exe
2009-07-05 07:51 . 2009-07-05 08:01 -------- d-----w- C:\Fraps
2009-07-04 07:43 . 2009-07-04 07:43 107196 ---ha-w- c:\windows\system32\mlfcache.dat
2009-06-27 04:20 . 2009-06-27 04:24 -------- d-----w- C:\Python25
2009-06-26 13:17 . 2009-06-27 04:30 -------- d-----w- c:\program files\Bethesda Softworks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-21 06:41 . 2008-12-03 07:36 16608 ----a-w- c:\windows\gdrv.sys
2009-07-21 06:40 . 2008-12-05 08:00 -------- d-----w- c:\users\tommy\AppData\Roaming\uTorrent
2009-07-21 06:05 . 2008-12-03 11:33 -------- d-----w- c:\program files\Steam
2009-07-20 14:21 . 2008-12-04 11:50 -------- d-----w- c:\users\tommy\AppData\Roaming\mIRC
2009-07-20 11:42 . 2008-12-04 12:11 -------- d-----w- c:\program files\mIRC
2009-07-19 14:47 . 2008-12-05 10:43 -------- d-----w- c:\program files\1
2009-07-19 10:43 . 2009-04-12 12:40 138944 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-19 10:43 . 2009-01-14 10:26 189784 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-07-15 16:37 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-15 07:57 . 2009-01-14 10:26 2373712 ----a-w- c:\windows\system32\pbsvc.exe
2009-07-06 08:44 . 2009-05-23 14:38 -------- d-----w- c:\users\tommy\AppData\Roaming\Mumble
2009-07-03 05:00 . 2008-12-03 11:33 -------- d-----w- c:\program files\Common Files\Steam
2009-06-20 10:01 . 2008-12-03 07:36 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-15 12:01 . 2009-05-03 03:53 -------- d-----w- c:\programdata\Microsoft Help
2009-06-10 14:04 . 2008-12-04 13:14 -------- d-----w- c:\users\tommy\AppData\Roaming\Hamachi
2009-05-26 22:36 . 2008-12-03 07:35 59288 ----a-w- c:\users\tommy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-23 14:38 . 2009-05-23 14:38 -------- d-----w- c:\program files\Mumble
2009-05-19 12:23 . 2009-01-14 10:26 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-05-19 12:21 . 2009-01-14 10:26 22328 ----a-w- c:\users\tommy\AppData\Roaming\PnkBstrK.sys
2009-05-19 12:21 . 2009-01-14 10:26 22328 ----a-w- c:\users\tommy\AppData\Roaming\PnkBstrK.sys
2009-04-30 12:37 . 2009-06-14 19:25 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-14 19:25 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-04-24 16:05 . 2009-06-10 22:29 827904 ----a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-06-10 22:29 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-06-10 22:29 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-04-23 12:43 . 2009-06-10 22:29 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 22:29 636928 ----a-w- c:\windows\system32\localspl.dll
2009-06-13 04:27 . 2008-12-03 08:11 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2006-11-22 14:58 . 2006-11-22 14:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-06-11 1217784]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"InternodeUsage"="c:\progra~1\INTERN~2\mum.exe" [2008-11-30 1340416]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"uTorrent"="c:\users\tommy\Downloads\utorrent.exe" [2009-03-21 270128]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2008-06-10 1442888]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"DeathAdder"="c:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-21 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-03-19 2029640]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-07 6139904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^tommy^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hamachi.lnk]
path=c:\users\tommy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hamachi.lnk
backup=c:\windows\pss\hamachi.lnk.Startup
backupExtension=.Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BD359CA7-0513-415B-BAA0-6C4A8DBD5438}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{C9B8A0EA-23FF-4819-B287-2798EB87F421}"= UDP:c:\program files\RealVNC\VNC4\winvnc4.exe:VNC Server
"{D7C3DD93-4C97-4F4B-8D3C-506009328BD6}"= TCP:c:\program files\RealVNC\VNC4\winvnc4.exe:VNC Server
"{CA4B433C-C642-4CA9-A730-33D09EE3A8B4}"= UDP:c:\users\tommy\Downloads\utorrent.exe:µTorrent (TCP-In)
"{CA34896D-544B-4401-843D-D1BE7BB14952}"= TCP:c:\users\tommy\Downloads\utorrent.exe:µTorrent (UDP-In)
"{2566EF2B-ACD0-49B9-A9DE-9E3D70BFBE43}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{B9ECEB68-1BA6-4414-B4BC-CF31EEAF9099}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{BC752B89-86FA-425B-9B5B-C67DA3C1E8E0}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{286D9B7B-E398-456B-BCD9-C879824DA81A}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{76838CDA-0F0A-4C36-9C50-6163A501936B}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E8665250-A262-462D-9898-A53587D75481}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4F2570D6-5E91-4849-8BD6-A3692E9E1033}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9CF6E3CE-714E-4291-B5C0-4F3E056FFE30}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{1AB3A555-E924-4C80-9744-92F40B49C43C}"= UDP:c:\program files\Steam\steamapps\common\world of goo demo\WorldOfGoo.exe:World of Goo Demo
"{52D73351-3464-40EB-B84B-E89146A704FA}"= TCP:c:\program files\Steam\steamapps\common\world of goo demo\WorldOfGoo.exe:World of Goo Demo
"{555F0E30-98D4-4525-A3A8-E28C84145075}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{42E5294B-2D97-4343-9961-91D2A8E16DE5}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{080E8B60-3938-4514-B5A4-EB9A1C30E555}"= UDP:c:\program files\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
"{6B9E27F1-504C-4B22-A5F6-BB9979AC18EC}"= TCP:c:\program files\Steam\steamapps\common\left 4 dead\left4dead.exe:Left 4 Dead
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Users\\tommy\\AppData\\Local\\Temp\\nscBFCE.tmp\\srchost.exe"= c:\users\tommy\AppData\Local\Temp\nscBFCE.tmp\srchost.exe:*:Enabled:@xpsp2res.dll,-22019
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [19/03/2009 11:44 AM 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [19/03/2009 11:44 AM 731840]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [19/03/2009 11:45 AM 38240]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [3/12/2008 5:06 PM 80392]
R3 DAdderFltr;DeathAdder Mouse;c:\windows\System32\drivers\dadder.sys [10/12/2008 4:08 PM 22784]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
TCP: {DBADD39B-2862-4D52-BC64-8DE643601EE9} = 192.168.1.254
FF - ProfilePath - c:\users\tommy\AppData\Roaming\Mozilla\Firefox\Profiles\g8lllwj0.default\
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - component: c:\users\tommy\AppData\Roaming\Mozilla\Firefox\Profiles\g8lllwj0.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - plugin: c:\programdata\id Software\QuakeLive\npquakezero.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-21 16:19
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-07-21 16:21
ComboFix-quarantined-files.txt 2009-07-21 06:50
Pre-Run: 82,460,524,544 bytes free
Post-Run: 82,413,404,160 bytes free
Current=4 Default=4 Failed=3 LastKnownGood=6 Sets=1,3,4,6
176 --- E O F --- 2009-07-18 02:24
--- End of File ---Thankyou for all your help so far,
Kind Regards,
Tom.