Thanks!
Ok, I downloaded ComboFix and when I typed or pasted it on RUN it said it couldnt find it. So I ran it from the desktop icon.
It ran then automatically rebooted my laptop.After this it said it was running the log. I went to bed and left comp on. Woke up and no sign of the log - had rebooted laptop again. But just found it in the C: drive here it is:
ComboFix 08-07-22.4 - Administrator 2008-07-23 22:16:42.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.874.1.1033.18.145 [GMT 7:00] Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe * Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\WINDOWS\BMbb616230.txt C:\WINDOWS\cookies.ini C:\WINDOWS\pskt.ini C:\WINDOWS\system32\acttdpgt.dll C:\WINDOWS\system32\bnbshggn.dll C:\WINDOWS\system32\cxwwwfow.ini C:\WINDOWS\system32\ecdwrucq.ini C:\WINDOWS\system32\fbctufvk.dll C:\WINDOWS\system32\fhpalk.dll C:\WINDOWS\system32\gnqowc.dll C:\WINDOWS\system32\hcnothyl.dll C:\WINDOWS\system32\hNpYaccf.ini C:\WINDOWS\system32\hNpYaccf.ini2 C:\WINDOWS\system32\LTAKnnmp.ini C:\WINDOWS\system32\LTAKnnmp.ini2 C:\WINDOWS\system32\nidojgjr.dll C:\WINDOWS\system32\oodvac.dll C:\WINDOWS\system32\pjnbjqbv.ini C:\WINDOWS\system32\pkgmnrxr.dll C:\WINDOWS\system32\qgyelgkr.ini C:\WINDOWS\system32\qtehft.dll C:\WINDOWS\system32\qviyjpqr.ini C:\WINDOWS\system32\qvsmdx.dll C:\WINDOWS\system32\rkgleygq.dll C:\WINDOWS\system32\rmgamesj.ini C:\WINDOWS\system32\tfnyhjnj.ini C:\WINDOWS\system32\tkgeoajx.dll C:\WINDOWS\system32\tuilnwjj.dll C:\WINDOWS\system32\ujjlmdki.dll C:\WINDOWS\system32\xaaecugu.dll C:\WINDOWS\system32\xnqanugx.dll C:\WINDOWS\system32\ymplvgeo.dll C:\WINDOWS\system32\zobslo.dll
. ((((((((((((((((((((((((( Files Created from 2008-06-23 to 2008-07-23 ))))))))))))))))))))))))))))))) .
2008-07-23 17:48 . 2008-07-23 17:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-07-23 17:47 . 2008-07-23 17:47 <DIR> d-------- C:\Program Files\SUPERAntiSpyware 2008-07-23 17:47 . 2008-07-23 17:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com 2008-07-23 17:45 . 2008-07-23 17:45 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-07-22 21:26 . 2008-07-22 21:28 <DIR> d-------- C:\HJT 2008-07-22 20:20 . 2008-07-23 17:00 1,688 --a------ C:\WINDOWS\system32\TRJ_NTAUTO.TMP 2008-07-22 17:12 . 2008-07-23 17:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trojan Remover 2008-07-22 16:44 . 2008-07-23 19:39 <DIR> d-------- C:\Program Files\Trojan Remover 2008-07-22 15:44 . 2008-07-22 15:44 0 --a------ C:\WINDOWS\system32\mapisvc.inf 2008-07-18 12:10 . 2008-07-18 12:10 0 --a------ C:\WINDOWS\BMbb616230.xml 2008-07-06 21:29 . 2008-07-06 21:29 <DIR> d-------- C:\Program Files\BUFFALO 2008-07-06 21:29 . 2007-05-18 16:04 15,872 --a------ C:\WINDOWS\system32\drivers\bfturboh.sys
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-23 15:26 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype 2008-07-18 12:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995 2008-07-16 10:47 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Apple Computer 2008-07-06 15:26 --------- d-----w C:\Program Files\FinePixViewer 2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys 2006-08-15 05:25 13,824 -c----w C:\Documents and Settings\Administrator\atwbxdet.dll 2005-12-08 01:57 1,689,933 -c--a-w C:\Program Files\WinRAR.zip .
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352] "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-08-25 21:54 23090984] "BBC News alerts"="C:\Program Files\BBC News alerts\skinkers.exe" [2005-04-04 20:35 475136] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 17:44 15360] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 09:25 68856] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 22:32 53248] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-23 09:54 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 17:44 15360]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-12 05:34:48 3746856]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Desktop Manager.lnk - C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe [2006-08-27 11:38:50 1114217] ExifLauncher2.lnk - C:\Program Files\FinePixViewer\QuickDCF2.exe [2007-12-03 21:46:08 303104] Status Monitor.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [2006-11-20 16:49:13 819200]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "SynchronousMachineGroupPolicy"= 0 (0x0) "SynchronousUserGroupPolicy"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring] 2004-09-06 05:29 180290 C:\WINDOWS\system32\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] --a------ 2007-08-15 20:15 271672 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2007-06-29 06:24 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] --a------ 2007-06-22 09:25 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winboot] --a------ 2003-01-14 12:15 110592 C:\WINDOWS\system32\wscript.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\Program Files\BBC News alerts\skinkers.exe"= C:\Program Files\BBC News alerts\skinkers.exe "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\livecall.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\FolderShare\\FolderShare.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 rmedia;Ricoh MediaCard Driver;C:\WINDOWS\system32\DRIVERS\rmedia.sys [2003-10-20 19:09] R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 06:20] R1 GhPciScan;GhostPciScanner;C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys [2003-05-28 19:01] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 06:16] S0 Spssys;Toshiba SPS Service;C:\WINDOWS\system32\drivers\spssys.sys [] S2 MediaAdapters;Network Trafic Monitoring ;c:\windows\system32\nmntrng.exe [] S3 AlcrFilt;Alcor Micro Corp;C:\WINDOWS\System32\Drivers\AlcrFilt.sys [2003-04-28 16:20] S3 bfturboh;BUFFALO TurboUSB for HD Filter;C:\WINDOWS\system32\drivers\bfturboh.sys [2007-05-18 16:04] S3 MMIOPORT;MMIOPORT;C:\WINDOWS\system32\drivers\MMIOPORT.sys [2000-03-03 10:16] S3 Serport;iTegno Modem driver;C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2002-08-08 01:13]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c14fa7c-fef1-11dc-9a42-0012f0d9eb08}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs . Contents of the 'Scheduled Tasks' folder "2008-07-21 01:32:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . - - - - ORPHANS REMOVED - - - -
BHO-{366DA57D-CFF8-481F-85C6-D3A227D1121E} - C:\WINDOWS\system32\fccaYpNh.dll BHO-{F6517692-D51C-4461-9DF4-DD555E9A2AEB} - C:\WINDOWS\system32\pmnnKATL.dll HKLM-Run-b85251ac - C:\WINDOWS\system32\rkgleygq.dll HKLM-Run-BMbb616230 - C:\WINDOWS\system32\xaaecugu.dll Notify-WgaLogon - (no file) MSConfigStartUp-MS32DLL - \.MS32DLL.dll.vbs
. ------- Supplementary Scan ------- . R0 -: HKCU-Main,Start Page = hxxp://www.smh.com.au/ R0 -: HKCU-Main,Search Page = hxxp://www.google.com R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-07-23 22:24:53 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\WINDOWS\system32\S24EvMon.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\ZCfgSvc.exe C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\system32\bgsvcgen.exe C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\RegSrvc.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\1XConfig.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\WINDOWS\SoftwareDistribution\Download\663e7188bbb3d768555f5280d384ddab\update\update.exe . ************************************************************************** . Completion time: 2008-07-23 22:34:13 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-23 15:34:00
Pre-Run: 10,915,905,536 bytes free Post-Run: 11,726,749,696 bytes free
199 --- E O F --- 2008-07-06 14:10:56
|