toggle151
asked on
Avira antivirus giving me fake alerts?
My Avira detected this when i just boot my comp.
Virus or unwanted program 'TR/TDss.yux [trojan]'
detected in file 'E:\Windows\System32\hjgru iqmlrbdqp. dll.
Action performed: Allow access.
and this when i opened Windows Live! mail
Virus or unwanted program 'TR/TDss.yux [trojan]'
detected in file 'E:\Windows\Temp\hjgruiryr qxojkeg.tm p.
Action performed: Delete file.
The thing is i cant find these files on the system...but the alert keeps poping up...what files could these be?
Virus or unwanted program 'TR/TDss.yux [trojan]'
detected in file 'E:\Windows\System32\hjgru
Action performed: Allow access.
and this when i opened Windows Live! mail
Virus or unwanted program 'TR/TDss.yux [trojan]'
detected in file 'E:\Windows\Temp\hjgruiryr
Action performed: Delete file.
The thing is i cant find these files on the system...but the alert keeps poping up...what files could these be?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
You might want to try scanning with Dr. Web Anti-Virus as well.
http://www.freedrweb.com/
http://www.freedrweb.com/
Those are not fake alerts...
Have those quarantine or deleted by your resident antivirus.
Or use MalwareBytes or Combofix as already suggested which both take care of TDSS rootkits, Combofix is the best tool for this as it removes all relevant registry entries as well.
You need to rename MalwareBytes or Combofix before saving the file to your desktop as these nasties often block these tools from running.
Run MalwareBytes and or Combofix in normal mode not safe mode.
Have those quarantine or deleted by your resident antivirus.
Or use MalwareBytes or Combofix as already suggested which both take care of TDSS rootkits, Combofix is the best tool for this as it removes all relevant registry entries as well.
You need to rename MalwareBytes or Combofix before saving the file to your desktop as these nasties often block these tools from running.
Run MalwareBytes and or Combofix in normal mode not safe mode.
Yep...rpggamergirl is correct...these are not fake alerts...after doing some more research...Combofix can detect it...but won't delete it...I don't know if any other Expert(s) experienced or knew of this before...but I just wanted to let the other Experts know...In case if they didn't.
Combofix removes TDSS* rootkits and for other variants not in its database Combofix has a script function that can delete anything you input into the script,
that's why we ask to look at a Combofix log because any bad files, services, reg entries not removed in its first run can be removed in the second run.
that's why we ask to look at a Combofix log because any bad files, services, reg entries not removed in its first run can be removed in the second run.
Better, use the Avira RescueCD. It will work most of the times as these files will not be in use.
Some help about the Avira RescueCD can be found here: http://forum.avira.com/wbb/index.php?page=Thread&threadID=82163
Some help about the Avira RescueCD can be found here: http://forum.avira.com/wbb/index.php?page=Thread&threadID=82163
Oops!...I should of been more clear in my last comment...I knew already that Combofix doesn't remove all of the infections on the first scan...and I understand that's why the Experts want to look at the Combofix log for any missed files that should be removed...my comment is meant to state that...Combofix as far as I know will detect it...but won't delete it...on the first run.
ASKER
This is the log that i got from combofix...according to this it should have solved the problem...and i figure the problem came from a WGA crack i used for vista...could any of these be false positives or are they realy rootkits? btw thanx for all the help so far guys
ComboFix 09-07-01.01 - Spike 02/07/2009 9:44.1 - NTFSx86
Microsoft® Windows Vista" Ultimate 6.0.6001.1.1252.65.1033.18 .2046.1177 [GMT 8:00]
Running from: e:\users\Spike\Desktop\Com boFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-D A132C1ACF4 6}
.
(((((((((((((((((((((((((( (((((((((( ((( Other Deletions )))))))))))))))))))))))))) )))))))))) )))))))))) )))
.
e:\windows\system32\ammppg .dll
e:\windows\system32\driver s\hjgruitb rpxprn.sys
e:\windows\system32\hjgrui iwxskief.d at
e:\windows\system32\hjgrui jwqvdmpn.d ll
e:\windows\system32\hjgrui qmlrbdqp.d ll
e:\windows\system32\hjgrui rpibiihx.d at
e:\windows\system32\mlfcac he.dat
e:\windows\system32\WgaLog on.dll
.
(((((((((((((((((((((((((( (((((((((( ((( Drivers/Services )))))))))))))))))))))))))) )))))))))) )))))))))) )))
.
-------\Service_hjgruifpbw ydtm
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 )))))))))))))))))))))))))) )))))
.
2009-07-02 01:53 . 2009-07-02 01:53 -------- d-----w- e:\users\Administrator\App Data\Local \temp
2009-07-01 12:04 . 2009-07-01 12:04 198064 ----a-w- e:\users\Administrator\App Data\Roami ng\IDM\idm mzcc3\comp onents\idm mzcc.dll
2009-07-01 12:04 . 2009-07-01 12:04 -------- d-----w- e:\users\Administrator\App Data\Roami ng\IDM
2009-07-01 12:04 . 2009-07-01 12:04 -------- d-----w- e:\users\Administrator\App Data\Roami ng\DMCache
2009-06-30 02:21 . 2009-06-30 12:46 -------- d-----w- e:\users\Spike\AppData\Roa ming\tor
2009-06-29 13:10 . 2004-08-03 23:00 506368 ----a-w- e:\windows\system32\msxml. dll
2009-06-29 12:33 . 2009-06-29 12:33 -------- d-----w- e:\program files\MKVtoolnix
2009-06-29 12:33 . 2009-06-29 12:33 -------- d-----w- e:\program files\DirectVobSub
2009-06-29 11:20 . 2009-06-29 11:30 -------- d-----w- e:\program files\Nero
2009-06-29 11:20 . 2009-06-29 11:31 -------- d-----w- e:\program files\Common Files\Nero
2009-06-29 11:20 . 2009-06-29 11:23 -------- d-----w- e:\programdata\Nero
2009-06-29 11:20 . 2008-08-20 03:33 1315328 ----a-w- e:\windows\system32\ole32. dll
2009-06-29 10:33 . 2009-06-29 10:33 -------- d-----w- e:\program files\MainConcept
2009-06-29 10:27 . 2009-06-29 10:33 -------- d-----w- e:\program files\megui
2009-06-29 10:26 . 2009-06-29 10:26 -------- d-----w- e:\program files\Xvid
2009-06-29 10:26 . 2009-06-07 08:24 180224 ----a-w- e:\windows\system32\xvidvf w.dll
2009-06-29 10:26 . 2009-06-07 08:16 819200 ----a-w- e:\windows\system32\xvidco re.dll
2009-06-29 10:26 . 2009-06-29 10:26 -------- d-----w- e:\program files\AC3Filter
2009-06-29 10:23 . 2009-05-15 11:36 85504 ----a-w- e:\windows\system32\ff_vfw .dll
2009-06-29 10:23 . 2009-06-29 10:23 -------- d-----w- e:\program files\ffdshow
2009-06-29 10:23 . 2009-05-15 11:36 60273 ----a-w- e:\windows\system32\pthrea dGC2.dll
2009-06-29 10:23 . 2009-06-29 10:23 -------- d-----w- e:\program files\Common Files\Sonic Shared
2009-06-29 10:23 . 2009-06-29 10:23 -------- d-----w- e:\program files\Sonic
2009-06-29 10:22 . 2009-06-29 10:22 -------- d-----w- e:\program files\CoreCodec
2009-06-29 10:21 . 2009-06-29 10:21 -------- d-----w- e:\program files\Haali
2009-06-29 10:14 . 2009-06-30 12:56 -------- d-----w- e:\program files\a-squared Anti-Malware
2009-06-29 10:13 . 2009-06-29 10:13 -------- d-----w- e:\program files\Wireshark
2009-06-29 10:12 . 2009-06-29 10:12 -------- d-----w- e:\program files\VideoLAN
2009-06-29 10:11 . 2009-06-30 12:46 -------- d-----w- e:\users\Spike\AppData\Roa ming\Vidal ia
2009-06-29 10:11 . 2009-06-29 10:11 -------- d-----w- e:\program files\Vidalia Bundle
2009-06-29 10:11 . 2009-06-29 10:11 -------- d-----w- e:\program files\Real Alternative
2009-06-29 10:07 . 2009-06-29 10:07 -------- d-----w- e:\program files\Apple Software Update
2009-06-29 10:04 . 2009-06-29 10:04 -------- d-----w- e:\program files\LimeWire
2009-06-26 16:01 . 2009-04-20 14:28 57016 ----a-w- e:\windows\system32\imsys. dll
2009-06-26 16:01 . 2009-04-20 14:28 233144 ----a-w- e:\windows\system32\IMImag e.dll
2009-06-26 16:01 . 2009-04-20 14:28 367800 ----a-w- e:\windows\system32\iimds. dll
2009-06-26 16:01 . 2009-02-10 16:02 14848 ----a-w- e:\windows\system32\iimir. dll
2009-06-26 15:52 . 2009-06-26 16:02 -------- d-----w- e:\program files\iMacros
2009-06-26 12:41 . 2009-06-23 05:52 57344 ----a-w- e:\users\Spike\AppData\Roa ming\Mozil la\Firefox \Profiles\ m5pizx7x.d efault\ext ensions\{F CAB6FDD-55 85-425b-95 C1-5ED856F 3FD08}\com ponents\ns Catcher.dl l
2009-06-26 12:41 . 2009-06-08 06:00 110592 ----a-w- e:\users\Spike\AppData\Roa ming\Mozil la\Firefox \Profiles\ m5pizx7x.d efault\ext ensions\{8 1BF1D23-5F 17-408D-AC 6B-BD6DF7C AF670}\com ponents\Xp comOpusCon nector.dll
2009-06-14 13:23 . 2009-04-30 12:37 293376 ----a-w- e:\windows\system32\psisde cd.dll
2009-06-14 13:23 . 2009-04-30 12:37 428544 ----a-w- e:\windows\system32\EncDec .dll
2009-06-11 05:26 . 2009-04-21 11:55 2033152 ----a-w- e:\windows\system32\win32k .sys
2009-06-11 05:26 . 2009-04-23 12:42 636928 ----a-w- e:\windows\system32\locals pl.dll
2009-06-11 05:25 . 2009-05-09 05:50 915456 ----a-w- e:\windows\system32\winine t.dll
2009-06-11 05:25 . 2009-05-09 05:34 71680 ----a-w- e:\windows\system32\iesetu p.dll
2009-06-11 05:25 . 2009-04-23 12:43 784896 ----a-w- e:\windows\system32\rpcrt4 .dll
2009-06-09 10:43 . 2009-06-09 10:45 -------- d-----w- e:\users\Spike\AppData\Roa ming\CopyT rans
2009-06-05 10:42 . 2009-07-02 01:32 4096 ----a-w- e:\windows\system32\detour ed.dll
.
(((((((((((((((((((((((((( (((((((((( (((( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) ))))))
.
2009-07-02 01:44 . 2009-05-08 11:29 65327 ----a-w- e:\programdata\nvModes.dat
2009-07-01 16:57 . 2009-03-18 06:23 -------- d-----w- e:\program files\Warcraft III
2009-06-30 14:56 . 2008-07-31 04:27 -------- d-----w- e:\users\Spike\AppData\Roa ming\DMCac he
2009-06-30 14:20 . 2009-01-17 06:23 -------- d-----w- e:\program files\Left 4 Dead
2009-06-29 12:32 . 2008-11-15 10:06 -------- d-----w- e:\users\Spike\AppData\Roa ming\Nero
2009-06-29 10:23 . 2008-11-01 16:01 -------- d-----w- e:\program files\Common Files\Roxio Shared
2009-06-29 10:13 . 2009-02-14 02:48 -------- d-----w- e:\program files\WinPcap
2009-06-29 10:10 . 2008-07-31 09:34 -------- d-----w- e:\program files\FLV Player
2009-06-29 10:09 . 2009-06-29 10:08 -------- d-----w- e:\program files\QuickTime
2009-06-29 10:08 . 2009-06-29 10:08 -------- d-----w- e:\program files\AviSynth 2.5
2009-06-29 10:08 . 2009-06-29 10:08 -------- d-----w- e:\program files\AnMing
2009-06-29 10:06 . 2009-01-04 14:27 -------- d-----w- e:\programdata\WinZip
2009-06-29 09:13 . 2008-11-01 07:19 -------- d-----w- e:\users\Spike\AppData\Roa ming\IDM
2009-06-29 09:11 . 2008-11-15 10:04 -------- d-----w- e:\program files\Nero 9
2009-06-21 15:42 . 2008-09-09 14:49 -------- d-----w- e:\users\Spike\AppData\Roa ming\UseNe XT
2009-06-13 05:50 . 2008-07-31 05:22 -------- d-----w- e:\programdata\Microsoft Help
2009-06-09 12:14 . 2009-03-20 12:29 97608 ----a-w- e:\windows\system32\driver s\avfwot.s ys
2009-06-06 16:35 . 2008-08-05 13:09 -------- d-----w- e:\users\Spike\AppData\Roa ming\LimeW ire
2009-05-30 13:57 . 2008-08-16 04:25 -------- d-----w- e:\users\Spike\AppData\Roa ming\MyPho neExplorer
2009-05-30 11:00 . 2008-08-23 09:37 -------- d-----w- e:\program files\MyPhoneExplorer
2009-05-30 02:38 . 2009-05-30 02:23 -------- d-----w- e:\programdata\DriverScann er
2009-05-30 02:38 . 2009-05-30 02:22 -------- dc-h--w- e:\programdata\{66E2F539-1 2B6-4870-A 500-7689CD E75C5E}
2009-05-30 02:38 . 2008-12-21 12:26 -------- d-----w- e:\users\Spike\AppData\Roa ming\Unibl ue
2009-05-29 10:49 . 2008-09-09 14:49 -------- d-----w- e:\program files\UseNeXT
2009-05-23 13:21 . 2009-05-23 13:06 -------- d-----w- e:\program files\Your Uninstaller 2008
2009-05-23 13:17 . 2008-07-31 03:38 -------- d--h--w- e:\program files\InstallShield Installation Information
2009-05-23 13:16 . 2009-05-20 10:54 -------- d-----w- e:\programdata\CyberLink
2009-05-23 13:13 . 2009-05-20 10:50 53319 ----a-w- e:\programdata\TEMP\{A8516 AC9-AAF1-4 7F9-9766-0 3E2D4CDBCF 8}\PostBui ld.exe
2009-05-23 13:06 . 2009-05-23 13:06 -------- d-----w- e:\users\Spike\AppData\Roa ming\URSof t
2009-05-23 12:18 . 2008-09-06 05:40 -------- d-----w- e:\program files\Replay Music 3
2009-05-23 11:01 . 2008-11-01 07:19 -------- d-----w- e:\program files\Internet Download Manager
2009-05-22 11:19 . 2009-05-22 11:19 -------- d-----w- e:\users\Spike\AppData\Roa ming\Sunbe lt
2009-05-22 11:18 . 2009-05-22 11:18 -------- d-----w- e:\programdata\Sunbelt
2009-05-21 11:08 . 2008-12-21 14:27 -------- d-----w- e:\program files\Cheat Engine
2009-05-20 11:07 . 2009-05-20 10:54 -------- d-----w- e:\users\Spike\AppData\Roa ming\Cyber Link
2009-05-20 10:56 . 2009-05-20 10:50 29480 ----a-w- e:\windows\system32\msxml3 a.dll
2009-05-20 10:56 . 2008-07-31 09:07 353576 ----a-w- e:\windows\system32\msvcr7 1.dll
2009-05-20 10:56 . 2009-05-20 10:56 53319 ----a-w- e:\programdata\TEMP\{2B55A F83-017A-4 C81-9324-D 9D3255642A 6}\PostBui ld.exe
2009-05-20 10:56 . 2008-07-31 09:07 505128 ----a-w- e:\windows\system32\msvcp7 1.dll
2009-05-20 10:53 . 2009-05-20 10:53 -------- d-----w- e:\program files\Common Files\CyberLink
2009-05-17 06:03 . 2009-05-17 06:03 198064 ----a-w- e:\users\Spike\AppData\Roa ming\IDM\i dmmzcc3\co mponents\i dmmzcc.dll
2009-05-17 05:21 . 2008-07-31 09:34 -------- d-----w- e:\program files\Common Files\DVDVideoSoft
2009-05-17 05:19 . 2008-12-21 08:28 -------- d-----w- e:\program files\Common Files\Common Share
2009-05-16 05:01 . 2009-05-16 05:01 -------- d-----w- e:\program files\hiro's tool
2009-05-15 00:02 . 2009-05-15 00:02 2373416 ----a-w- e:\programdata\Nero\Nero\D rWeb\DrWeb 32.dll
2009-05-14 23:50 . 2009-05-14 23:50 2373416 ----a-w- e:\programdata\Nero\Nero 9\DrWeb\DrWeb32.dll
2009-05-14 10:57 . 2008-07-31 09:18 -------- d-----w- e:\program files\Microsoft Works
2009-05-14 10:47 . 2006-11-02 11:18 -------- d-----w- e:\program files\Windows Mail
2009-05-11 10:58 . 2009-05-11 10:58 -------- d-----w- e:\users\Spike\AppData\Roa ming\JAM Software
2009-05-08 11:29 . 2008-07-31 03:51 -------- d-----w- e:\programdata\NVIDIA
2009-05-08 11:25 . 2009-03-18 09:42 -------- d-----w- e:\program files\Common Files\Wise Installation Wizard
2009-05-08 11:22 . 2009-04-10 04:23 -------- d-----w- e:\users\Spike\AppData\Roa ming\Orbit
2009-04-30 16:08 . 2009-04-30 16:08 1194528 ----a-w- e:\windows\system32\nvcplu i.exe
2009-04-30 16:08 . 2009-04-30 16:08 1292832 ----a-w- e:\windows\system32\nvsvs. dll
2009-04-30 16:07 . 2009-04-30 16:07 92704 ----a-w- e:\windows\system32\nvmctr ay.dll
2009-04-30 16:07 . 2009-04-30 16:07 768544 ----a-w- e:\windows\system32\nvsvc. dll
2009-04-30 16:07 . 2009-04-30 16:07 4045344 ----a-w- e:\windows\system32\nvvitv s.dll
2009-04-30 16:07 . 2009-04-30 16:07 4020768 ----a-w- e:\windows\system32\nvdisp s.dll
2009-04-30 16:07 . 2009-04-30 16:07 3516960 ----a-w- e:\windows\system32\nvgame s.dll
2009-04-30 16:07 . 2009-04-30 16:07 3123744 ----a-w- e:\windows\system32\nvwss. dll
2009-04-30 16:07 . 2009-04-30 16:07 211488 ----a-w- e:\windows\system32\nvvsvc .exe
2009-04-30 16:07 . 2009-04-30 16:07 195104 ----a-w- e:\windows\system32\nvmccs s.dll
2009-04-30 16:07 . 2009-04-30 16:07 143360 ----a-w- e:\windows\system32\nvshex t.dll
2009-04-30 16:07 . 2009-04-30 16:07 13781536 ----a-w- e:\windows\system32\nvcpl. dll
2009-04-30 16:07 . 2009-04-30 16:07 1288736 ----a-w- e:\windows\system32\nvmobl s.dll
2009-04-30 14:02 . 2009-04-30 14:02 9850016 ----a-w- e:\windows\system32\driver s\nvlddmkm .sys
2009-04-30 14:02 . 2009-04-30 14:02 7593472 ----a-w- e:\windows\system32\nvd3du m.dll
2009-04-30 14:02 . 2009-04-30 14:02 663552 ----a-w- e:\windows\system32\nvcuvi d.dll
2009-04-30 14:02 . 2009-04-30 14:02 457248 ----a-w- e:\windows\system32\nvudis p.exe
2009-04-30 14:02 . 2009-04-30 14:02 3128320 ----a-w- e:\windows\system32\nvwgf2 um.dll
2009-04-30 14:02 . 2009-04-30 14:02 1704960 ----a-w- e:\windows\system32\nvcuda .dll
2009-04-30 14:02 . 2009-04-30 14:02 143360 ----a-w- e:\windows\system32\nvcod1 46.dll
2009-04-30 14:02 . 2009-04-30 14:02 143360 ----a-w- e:\windows\system32\nvcod. dll
2009-04-30 14:02 . 2009-04-30 14:02 1314816 ----a-w- e:\windows\system32\nvcuve nc.dll
2009-04-30 14:02 . 2009-04-30 14:02 10366976 ----a-w- e:\windows\system32\nvoglv 32.dll
2009-04-30 14:02 . 2007-12-11 09:06 983552 ----a-w- e:\windows\system32\nvapi. dll
2009-04-27 11:21 . 2009-03-20 10:27 96104 ----a-w- e:\windows\system32\driver s\avipbb.s ys
2009-04-27 11:21 . 2009-03-20 10:27 55640 ----a-w- e:\windows\system32\driver s\avgntflt .sys
2009-04-26 16:42 . 2008-07-31 03:47 457248 ----a-w- e:\windows\system32\NVUNIN ST.EXE
2009-04-16 02:48 . 2009-04-16 02:48 23 --sha-w- e:\windows\system32\fbdaab b3_x.dat
2009-04-04 05:04 . 2008-07-31 03:48 882232 ----a-w- e:\windows\system32\driver s\tcpip.sy s
2009-04-03 14:15 . 2009-04-03 14:16 102664 ----a-w- e:\windows\system32\driver s\tmcomm.s ys
.
(((((((((((((((((((((((((( (((((((((( ( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) ))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR E\Microsof t\Windows\ CurrentVer sion\Run]
"msnmsgr"="e:\program files\Windows Live\Messenger\msnmsgr.exe " [2009-02-06 3885408]
"WMPNSCFG"="e:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"RtHDVCpl"="e:\windows\RtH DVCpl.exe" [2007-08-09 4702208]
"Thumbs"="e:\users\Spike\D esktop\DXW nd\ThumbWi n\ThumbWin .exe" [2007-08-29 119808]
"avgnt"="e:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-20 209153]
"mxomssmenu"="e:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312]
"NvCplDaemon"="e:\windows\ system32\N vCpl.dll" [2009-04-30 13781536]
"QuickTime Task"="e:\program files\QuickTime\QTTask.exe " [2009-05-26 413696]
"a-squared"="e:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-06-07 3207824]
e:\users\Administrator\App Data\Roami ng\Microso ft\Windows \Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - e:\program files\Microsoft Office\Office12\ONENOTEM.E XE [2008-10-25 98696]
e:\programdata\Microsoft\W indows\Sta rt Menu\Programs\Startup\
Privoxy.lnk - e:\program files\Vidalia Bundle\Privoxy\privoxy.exe [2006-11-20 250368]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\poli cies\syste m]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\softwar e\microsof t\windows\ currentver sion\polic ies\explor er]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows nt\currentversion\drivers3 2]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM \CurrentCo ntrolSet\C ontrol\Saf eBoot\Mini mal\WinDef end]
@="Service"
[HKEY_LOCAL_MACHINE\softwa re\microso ft\securit y center\Svc\S-1-5-21-140739 5325-22594 14566-1186 877101-100 0]
"EnableNotificationsRef"=d word:00000 001
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ FirewallRu les]
"{5C79436D-F158-47F6-BE30- 1197CB2926 6F}"= e:\program files\Windows Live\Messenger\livecall.ex e:Windows Live Messenger (Phone)
"{E50BA9EB-C37A-4DB1-A3CA- 854085EA20 2A}"= TCP:6004|e:\program files\Microsoft Office\Office12\outlook.ex e:Microsof t Office Outlook
"{0B9C2E98-B9F9-43CE-98AB- 8BBF49CF13 05}"= UDP:e:\program files\Microsoft Office\Office12\GROOVE.EXE :Microsoft Office Groove
"{C55416D3-B718-4233-ADCB- 16BE1ACC17 46}"= TCP:e:\program files\Microsoft Office\Office12\GROOVE.EXE :Microsoft Office Groove
"{54536ABF-F7CF-4976-9356- 97EF31EEA8 E0}"= UDP:e:\program files\Microsoft Office\Office12\ONENOTE.EX E:Microsof t Office OneNote
"{79E46E6D-684E-42D6-9365- E41F107108 07}"= TCP:e:\program files\Microsoft Office\Office12\ONENOTE.EX E:Microsof t Office OneNote
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ StandardPr ofile]
"EnableFirewall"= 0 (0x0)
R2 AntiVirSchedulerService;Av ira AntiVir Scheduler;e:\program files\Avira\AntiVir Desktop\sched.exe [20/3/2009 6:27 PM 108289]
S2 .webroot_reset;Webroot Reset; [x]
S3 NPF;NetGroup Packet Filter Driver;e:\windows\System32 \drivers\n pf.sys [23/12/2008 11:35 PM 50704]
S3 zteusbser;ZTE USB Device for Legacy Serial Communication;e:\windows\S ystem32\dr ivers\CT_Z TEMT_U_USB SER.sys [1/9/2008 4:41 PM 104320]
S4 AntiVirMailService;Avira AntiVir MailGuard;e:\program files\Avira\AntiVir Desktop\avmailc.exe [20/3/2009 6:27 PM 194817]
S4 AntiVirWebService;Avira AntiVir WebGuard;e:\program files\Avira\AntiVir Desktop\avwebgrd.exe [20/3/2009 6:27 PM 434945]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\active setup\installed components\>{60B49E34-C7CC -11D0-8953 -00A0C9034 7FF}]
"e:\windows\System32\rundl l32.exe" "e:\windows\System32\iedkc s32.dll",B randIEActi veSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
IE: Download all links with IDM - e:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - e:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - e:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~2\Offic e12\EXCEL. EXE/3000
LSP: e:\windows\system32\idmmbc .dll
FF - ProfilePath - e:\users\Spike\AppData\Roa ming\Mozil la\Firefox \Profiles\ m5pizx7x.d efault\
FF - prefs.js: browser.search.selectedEng ine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/se arch?ei=ut f-8&fr=meg aup&p=
FF - prefs.js: network.proxy.http - 81.219.46.218
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 2
FF - component: e:\users\Spike\AppData\Roa ming\IDM\i dmmzcc3\co mponents\i dmmzcc.dll
FF - component: e:\users\Spike\AppData\Roa ming\Mozil la\Firefox \Profiles\ m5pizx7x.d efault\ext ensions\{8 1BF1D23-5F 17-408D-AC 6B-BD6DF7C AF670}\com ponents\Xp comOpusCon nector.dll
FF - component: e:\users\Spike\AppData\Roa ming\Mozil la\Firefox \Profiles\ m5pizx7x.d efault\ext ensions\{F CAB6FDD-55 85-425b-95 C1-5ED856F 3FD08}\com ponents\ns Catcher.dl l
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEF AC-0016-00 00-0007-AB CDEFFEDCBA }
.
************************** ********** ********** ********** ********** ********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-02 09:53
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************** ********** ********** ********** ********** ********
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-14073 95325-2259 414566-118 6877101-10 00_Classes \CLSID\{6a afe09b-dc3 3-4682-b33 2-8643f99e 58be}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000115
"Therad"=dword:0000001b
"MData"=hex(0):cb,9b,ad,ef ,27,7d,29, 69,f5,02,f 0,76,aa,4a ,f1,7c,d3, d9,67,7f,6 a,
4b,7b,ad,4d,51,c8,2e,97,6b ,20,ae,9f, a5,91,2f,4 7,1f,5f,13 ,d7,34,45, 07,bf,10,\
[HKEY_USERS\S-1-5-21-14073 95325-2259 414566-118 6877101-10 00_Classes \CLSID\{7B 8E9164-324 D-4A2E-A46 D-0165FB20 00EC}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):48,41,4a,c 5,da,f8,d2 ,23,da,28, 0c,80,d0,f e,40,ab,c0 ,46,3d,17, 71,
34,cc,67,f0,c4,9a,b0,63,38 ,f5,b0,49, b5,3f,ce,6 4,18,6a,23 ,00,00,00, 00,00,00,\
[HKEY_LOCAL_MACHINE\SYSTEM \ControlSe t001\Contr ol\Class\{ 4D36E96D-E 325-11CE-B FC1-08002B E10318}\00 00\AllUser Settings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM \ControlSe t001\Contr ol\Class\{ 4D36E96D-E 325-11CE-B FC1-08002B E10318}\00 01\AllUser Settings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-07-02 9:55
ComboFix-quarantined-files .txt 2009-07-02 01:55
Pre-Run: 40,556,527,616 bytes free
Post-Run: 42,309,668,864 bytes free
266 --- E O F --- 2009-06-27 14:38
ComboFix 09-07-01.01 - Spike 02/07/2009 9:44.1 - NTFSx86
Microsoft® Windows Vista" Ultimate 6.0.6001.1.1252.65.1033.18
Running from: e:\users\Spike\Desktop\Com
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-D
.
((((((((((((((((((((((((((
.
e:\windows\system32\ammppg
e:\windows\system32\driver
e:\windows\system32\hjgrui
e:\windows\system32\hjgrui
e:\windows\system32\hjgrui
e:\windows\system32\hjgrui
e:\windows\system32\mlfcac
e:\windows\system32\WgaLog
.
((((((((((((((((((((((((((
.
-------\Service_hjgruifpbw
((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 ))))))))))))))))))))))))))
.
2009-07-02 01:53 . 2009-07-02 01:53 -------- d-----w- e:\users\Administrator\App
2009-07-01 12:04 . 2009-07-01 12:04 198064 ----a-w- e:\users\Administrator\App
2009-07-01 12:04 . 2009-07-01 12:04 -------- d-----w- e:\users\Administrator\App
2009-07-01 12:04 . 2009-07-01 12:04 -------- d-----w- e:\users\Administrator\App
2009-06-30 02:21 . 2009-06-30 12:46 -------- d-----w- e:\users\Spike\AppData\Roa
2009-06-29 13:10 . 2004-08-03 23:00 506368 ----a-w- e:\windows\system32\msxml.
2009-06-29 12:33 . 2009-06-29 12:33 -------- d-----w- e:\program files\MKVtoolnix
2009-06-29 12:33 . 2009-06-29 12:33 -------- d-----w- e:\program files\DirectVobSub
2009-06-29 11:20 . 2009-06-29 11:30 -------- d-----w- e:\program files\Nero
2009-06-29 11:20 . 2009-06-29 11:31 -------- d-----w- e:\program files\Common Files\Nero
2009-06-29 11:20 . 2009-06-29 11:23 -------- d-----w- e:\programdata\Nero
2009-06-29 11:20 . 2008-08-20 03:33 1315328 ----a-w- e:\windows\system32\ole32.
2009-06-29 10:33 . 2009-06-29 10:33 -------- d-----w- e:\program files\MainConcept
2009-06-29 10:27 . 2009-06-29 10:33 -------- d-----w- e:\program files\megui
2009-06-29 10:26 . 2009-06-29 10:26 -------- d-----w- e:\program files\Xvid
2009-06-29 10:26 . 2009-06-07 08:24 180224 ----a-w- e:\windows\system32\xvidvf
2009-06-29 10:26 . 2009-06-07 08:16 819200 ----a-w- e:\windows\system32\xvidco
2009-06-29 10:26 . 2009-06-29 10:26 -------- d-----w- e:\program files\AC3Filter
2009-06-29 10:23 . 2009-05-15 11:36 85504 ----a-w- e:\windows\system32\ff_vfw
2009-06-29 10:23 . 2009-06-29 10:23 -------- d-----w- e:\program files\ffdshow
2009-06-29 10:23 . 2009-05-15 11:36 60273 ----a-w- e:\windows\system32\pthrea
2009-06-29 10:23 . 2009-06-29 10:23 -------- d-----w- e:\program files\Common Files\Sonic Shared
2009-06-29 10:23 . 2009-06-29 10:23 -------- d-----w- e:\program files\Sonic
2009-06-29 10:22 . 2009-06-29 10:22 -------- d-----w- e:\program files\CoreCodec
2009-06-29 10:21 . 2009-06-29 10:21 -------- d-----w- e:\program files\Haali
2009-06-29 10:14 . 2009-06-30 12:56 -------- d-----w- e:\program files\a-squared Anti-Malware
2009-06-29 10:13 . 2009-06-29 10:13 -------- d-----w- e:\program files\Wireshark
2009-06-29 10:12 . 2009-06-29 10:12 -------- d-----w- e:\program files\VideoLAN
2009-06-29 10:11 . 2009-06-30 12:46 -------- d-----w- e:\users\Spike\AppData\Roa
2009-06-29 10:11 . 2009-06-29 10:11 -------- d-----w- e:\program files\Vidalia Bundle
2009-06-29 10:11 . 2009-06-29 10:11 -------- d-----w- e:\program files\Real Alternative
2009-06-29 10:07 . 2009-06-29 10:07 -------- d-----w- e:\program files\Apple Software Update
2009-06-29 10:04 . 2009-06-29 10:04 -------- d-----w- e:\program files\LimeWire
2009-06-26 16:01 . 2009-04-20 14:28 57016 ----a-w- e:\windows\system32\imsys.
2009-06-26 16:01 . 2009-04-20 14:28 233144 ----a-w- e:\windows\system32\IMImag
2009-06-26 16:01 . 2009-04-20 14:28 367800 ----a-w- e:\windows\system32\iimds.
2009-06-26 16:01 . 2009-02-10 16:02 14848 ----a-w- e:\windows\system32\iimir.
2009-06-26 15:52 . 2009-06-26 16:02 -------- d-----w- e:\program files\iMacros
2009-06-26 12:41 . 2009-06-23 05:52 57344 ----a-w- e:\users\Spike\AppData\Roa
2009-06-26 12:41 . 2009-06-08 06:00 110592 ----a-w- e:\users\Spike\AppData\Roa
2009-06-14 13:23 . 2009-04-30 12:37 293376 ----a-w- e:\windows\system32\psisde
2009-06-14 13:23 . 2009-04-30 12:37 428544 ----a-w- e:\windows\system32\EncDec
2009-06-11 05:26 . 2009-04-21 11:55 2033152 ----a-w- e:\windows\system32\win32k
2009-06-11 05:26 . 2009-04-23 12:42 636928 ----a-w- e:\windows\system32\locals
2009-06-11 05:25 . 2009-05-09 05:50 915456 ----a-w- e:\windows\system32\winine
2009-06-11 05:25 . 2009-05-09 05:34 71680 ----a-w- e:\windows\system32\iesetu
2009-06-11 05:25 . 2009-04-23 12:43 784896 ----a-w- e:\windows\system32\rpcrt4
2009-06-09 10:43 . 2009-06-09 10:45 -------- d-----w- e:\users\Spike\AppData\Roa
2009-06-05 10:42 . 2009-07-02 01:32 4096 ----a-w- e:\windows\system32\detour
.
((((((((((((((((((((((((((
.
2009-07-02 01:44 . 2009-05-08 11:29 65327 ----a-w- e:\programdata\nvModes.dat
2009-07-01 16:57 . 2009-03-18 06:23 -------- d-----w- e:\program files\Warcraft III
2009-06-30 14:56 . 2008-07-31 04:27 -------- d-----w- e:\users\Spike\AppData\Roa
2009-06-30 14:20 . 2009-01-17 06:23 -------- d-----w- e:\program files\Left 4 Dead
2009-06-29 12:32 . 2008-11-15 10:06 -------- d-----w- e:\users\Spike\AppData\Roa
2009-06-29 10:23 . 2008-11-01 16:01 -------- d-----w- e:\program files\Common Files\Roxio Shared
2009-06-29 10:13 . 2009-02-14 02:48 -------- d-----w- e:\program files\WinPcap
2009-06-29 10:10 . 2008-07-31 09:34 -------- d-----w- e:\program files\FLV Player
2009-06-29 10:09 . 2009-06-29 10:08 -------- d-----w- e:\program files\QuickTime
2009-06-29 10:08 . 2009-06-29 10:08 -------- d-----w- e:\program files\AviSynth 2.5
2009-06-29 10:08 . 2009-06-29 10:08 -------- d-----w- e:\program files\AnMing
2009-06-29 10:06 . 2009-01-04 14:27 -------- d-----w- e:\programdata\WinZip
2009-06-29 09:13 . 2008-11-01 07:19 -------- d-----w- e:\users\Spike\AppData\Roa
2009-06-29 09:11 . 2008-11-15 10:04 -------- d-----w- e:\program files\Nero 9
2009-06-21 15:42 . 2008-09-09 14:49 -------- d-----w- e:\users\Spike\AppData\Roa
2009-06-13 05:50 . 2008-07-31 05:22 -------- d-----w- e:\programdata\Microsoft Help
2009-06-09 12:14 . 2009-03-20 12:29 97608 ----a-w- e:\windows\system32\driver
2009-06-06 16:35 . 2008-08-05 13:09 -------- d-----w- e:\users\Spike\AppData\Roa
2009-05-30 13:57 . 2008-08-16 04:25 -------- d-----w- e:\users\Spike\AppData\Roa
2009-05-30 11:00 . 2008-08-23 09:37 -------- d-----w- e:\program files\MyPhoneExplorer
2009-05-30 02:38 . 2009-05-30 02:23 -------- d-----w- e:\programdata\DriverScann
2009-05-30 02:38 . 2009-05-30 02:22 -------- dc-h--w- e:\programdata\{66E2F539-1
2009-05-30 02:38 . 2008-12-21 12:26 -------- d-----w- e:\users\Spike\AppData\Roa
2009-05-29 10:49 . 2008-09-09 14:49 -------- d-----w- e:\program files\UseNeXT
2009-05-23 13:21 . 2009-05-23 13:06 -------- d-----w- e:\program files\Your Uninstaller 2008
2009-05-23 13:17 . 2008-07-31 03:38 -------- d--h--w- e:\program files\InstallShield Installation Information
2009-05-23 13:16 . 2009-05-20 10:54 -------- d-----w- e:\programdata\CyberLink
2009-05-23 13:13 . 2009-05-20 10:50 53319 ----a-w- e:\programdata\TEMP\{A8516
2009-05-23 13:06 . 2009-05-23 13:06 -------- d-----w- e:\users\Spike\AppData\Roa
2009-05-23 12:18 . 2008-09-06 05:40 -------- d-----w- e:\program files\Replay Music 3
2009-05-23 11:01 . 2008-11-01 07:19 -------- d-----w- e:\program files\Internet Download Manager
2009-05-22 11:19 . 2009-05-22 11:19 -------- d-----w- e:\users\Spike\AppData\Roa
2009-05-22 11:18 . 2009-05-22 11:18 -------- d-----w- e:\programdata\Sunbelt
2009-05-21 11:08 . 2008-12-21 14:27 -------- d-----w- e:\program files\Cheat Engine
2009-05-20 11:07 . 2009-05-20 10:54 -------- d-----w- e:\users\Spike\AppData\Roa
2009-05-20 10:56 . 2009-05-20 10:50 29480 ----a-w- e:\windows\system32\msxml3
2009-05-20 10:56 . 2008-07-31 09:07 353576 ----a-w- e:\windows\system32\msvcr7
2009-05-20 10:56 . 2009-05-20 10:56 53319 ----a-w- e:\programdata\TEMP\{2B55A
2009-05-20 10:56 . 2008-07-31 09:07 505128 ----a-w- e:\windows\system32\msvcp7
2009-05-20 10:53 . 2009-05-20 10:53 -------- d-----w- e:\program files\Common Files\CyberLink
2009-05-17 06:03 . 2009-05-17 06:03 198064 ----a-w- e:\users\Spike\AppData\Roa
2009-05-17 05:21 . 2008-07-31 09:34 -------- d-----w- e:\program files\Common Files\DVDVideoSoft
2009-05-17 05:19 . 2008-12-21 08:28 -------- d-----w- e:\program files\Common Files\Common Share
2009-05-16 05:01 . 2009-05-16 05:01 -------- d-----w- e:\program files\hiro's tool
2009-05-15 00:02 . 2009-05-15 00:02 2373416 ----a-w- e:\programdata\Nero\Nero\D
2009-05-14 23:50 . 2009-05-14 23:50 2373416 ----a-w- e:\programdata\Nero\Nero 9\DrWeb\DrWeb32.dll
2009-05-14 10:57 . 2008-07-31 09:18 -------- d-----w- e:\program files\Microsoft Works
2009-05-14 10:47 . 2006-11-02 11:18 -------- d-----w- e:\program files\Windows Mail
2009-05-11 10:58 . 2009-05-11 10:58 -------- d-----w- e:\users\Spike\AppData\Roa
2009-05-08 11:29 . 2008-07-31 03:51 -------- d-----w- e:\programdata\NVIDIA
2009-05-08 11:25 . 2009-03-18 09:42 -------- d-----w- e:\program files\Common Files\Wise Installation Wizard
2009-05-08 11:22 . 2009-04-10 04:23 -------- d-----w- e:\users\Spike\AppData\Roa
2009-04-30 16:08 . 2009-04-30 16:08 1194528 ----a-w- e:\windows\system32\nvcplu
2009-04-30 16:08 . 2009-04-30 16:08 1292832 ----a-w- e:\windows\system32\nvsvs.
2009-04-30 16:07 . 2009-04-30 16:07 92704 ----a-w- e:\windows\system32\nvmctr
2009-04-30 16:07 . 2009-04-30 16:07 768544 ----a-w- e:\windows\system32\nvsvc.
2009-04-30 16:07 . 2009-04-30 16:07 4045344 ----a-w- e:\windows\system32\nvvitv
2009-04-30 16:07 . 2009-04-30 16:07 4020768 ----a-w- e:\windows\system32\nvdisp
2009-04-30 16:07 . 2009-04-30 16:07 3516960 ----a-w- e:\windows\system32\nvgame
2009-04-30 16:07 . 2009-04-30 16:07 3123744 ----a-w- e:\windows\system32\nvwss.
2009-04-30 16:07 . 2009-04-30 16:07 211488 ----a-w- e:\windows\system32\nvvsvc
2009-04-30 16:07 . 2009-04-30 16:07 195104 ----a-w- e:\windows\system32\nvmccs
2009-04-30 16:07 . 2009-04-30 16:07 143360 ----a-w- e:\windows\system32\nvshex
2009-04-30 16:07 . 2009-04-30 16:07 13781536 ----a-w- e:\windows\system32\nvcpl.
2009-04-30 16:07 . 2009-04-30 16:07 1288736 ----a-w- e:\windows\system32\nvmobl
2009-04-30 14:02 . 2009-04-30 14:02 9850016 ----a-w- e:\windows\system32\driver
2009-04-30 14:02 . 2009-04-30 14:02 7593472 ----a-w- e:\windows\system32\nvd3du
2009-04-30 14:02 . 2009-04-30 14:02 663552 ----a-w- e:\windows\system32\nvcuvi
2009-04-30 14:02 . 2009-04-30 14:02 457248 ----a-w- e:\windows\system32\nvudis
2009-04-30 14:02 . 2009-04-30 14:02 3128320 ----a-w- e:\windows\system32\nvwgf2
2009-04-30 14:02 . 2009-04-30 14:02 1704960 ----a-w- e:\windows\system32\nvcuda
2009-04-30 14:02 . 2009-04-30 14:02 143360 ----a-w- e:\windows\system32\nvcod1
2009-04-30 14:02 . 2009-04-30 14:02 143360 ----a-w- e:\windows\system32\nvcod.
2009-04-30 14:02 . 2009-04-30 14:02 1314816 ----a-w- e:\windows\system32\nvcuve
2009-04-30 14:02 . 2009-04-30 14:02 10366976 ----a-w- e:\windows\system32\nvoglv
2009-04-30 14:02 . 2007-12-11 09:06 983552 ----a-w- e:\windows\system32\nvapi.
2009-04-27 11:21 . 2009-03-20 10:27 96104 ----a-w- e:\windows\system32\driver
2009-04-27 11:21 . 2009-03-20 10:27 55640 ----a-w- e:\windows\system32\driver
2009-04-26 16:42 . 2008-07-31 03:47 457248 ----a-w- e:\windows\system32\NVUNIN
2009-04-16 02:48 . 2009-04-16 02:48 23 --sha-w- e:\windows\system32\fbdaab
2009-04-04 05:04 . 2008-07-31 03:48 882232 ----a-w- e:\windows\system32\driver
2009-04-03 14:15 . 2009-04-03 14:16 102664 ----a-w- e:\windows\system32\driver
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"msnmsgr"="e:\program files\Windows Live\Messenger\msnmsgr.exe
"WMPNSCFG"="e:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWA
"RtHDVCpl"="e:\windows\RtH
"Thumbs"="e:\users\Spike\D
"avgnt"="e:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-20 209153]
"mxomssmenu"="e:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312]
"NvCplDaemon"="e:\windows\
"QuickTime Task"="e:\program files\QuickTime\QTTask.exe
"a-squared"="e:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-06-07 3207824]
e:\users\Administrator\App
OneNote 2007 Screen Clipper and Launcher.lnk - e:\program files\Microsoft Office\Office12\ONENOTEM.E
e:\programdata\Microsoft\W
Privoxy.lnk - e:\program files\Vidalia Bundle\Privoxy\privoxy.exe
[HKEY_LOCAL_MACHINE\softwa
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\softwar
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\softwa
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\softwa
"EnableNotificationsRef"=d
[HKLM\~\services\sharedacc
"{5C79436D-F158-47F6-BE30-
"{E50BA9EB-C37A-4DB1-A3CA-
"{0B9C2E98-B9F9-43CE-98AB-
"{C55416D3-B718-4233-ADCB-
"{54536ABF-F7CF-4976-9356-
"{79E46E6D-684E-42D6-9365-
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
R2 AntiVirSchedulerService;Av
S2 .webroot_reset;Webroot Reset; [x]
S3 NPF;NetGroup Packet Filter Driver;e:\windows\System32
S3 zteusbser;ZTE USB Device for Legacy Serial Communication;e:\windows\S
S4 AntiVirMailService;Avira AntiVir MailGuard;e:\program files\Avira\AntiVir Desktop\avmailc.exe [20/3/2009 6:27 PM 194817]
S4 AntiVirWebService;Avira AntiVir WebGuard;e:\program files\Avira\AntiVir Desktop\avwebgrd.exe [20/3/2009 6:27 PM 434945]
[HKEY_LOCAL_MACHINE\softwa
"e:\windows\System32\rundl
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
IE: Download all links with IDM - e:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - e:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - e:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~2\Offic
LSP: e:\windows\system32\idmmbc
FF - ProfilePath - e:\users\Spike\AppData\Roa
FF - prefs.js: browser.search.selectedEng
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/se
FF - prefs.js: network.proxy.http - 81.219.46.218
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.type - 2
FF - component: e:\users\Spike\AppData\Roa
FF - component: e:\users\Spike\AppData\Roa
FF - component: e:\users\Spike\AppData\Roa
FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEF
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-02 09:53
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-14073
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000115
"Therad"=dword:0000001b
"MData"=hex(0):cb,9b,ad,ef
4b,7b,ad,4d,51,c8,2e,97,6b
[HKEY_USERS\S-1-5-21-14073
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):48,41,4a,c
34,cc,67,f0,c4,9a,b0,63,38
[HKEY_LOCAL_MACHINE\SYSTEM
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-07-02 9:55
ComboFix-quarantined-files
Pre-Run: 40,556,527,616 bytes free
Post-Run: 42,309,668,864 bytes free
266 --- E O F --- 2009-06-27 14:38
ASKER
BTW avira no longer detects the viruses on boot...i guess its solved! case closed :) THANKS ALOT GUYS for everyting :)
ASKER
Spot on..thanx
The files are probably hidden...if you go to my computer...then select tools...then select folder options...select the view tab. Make sure that show hidden files and folder is selected. Make sure that you don't delete any files from here...there hidden for a reason and might corrupt your OS if deleted. Try scanning with another antivirus...and see if it detects these files...it's possible that Avira might detecting false alerts.