CF log:
ComboFix 12-03-02.01 - Adriana 03/03/2012 9:09.1.4 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.2046.1167 [GMT -5:00]
Running from: c:\users\Adriana\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\oobe\audit.exe
c:\windows\system32\oobe\msoobe.exe
c:\windows\system32\oobe\oobeldr.exe
c:\windows\system32\oobe\Setup.exe
c:\windows\system32\oobe\windeploy.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-02-03 to 2012-03-03 )))))))))))))))))))))))))))))))
.
.
2012-03-03 01:26 . 2012-03-03 01:26 -------- d-----w- c:\program files\ESET
2012-03-02 12:41 . 2012-03-02 12:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-03-02 12:41 . 2012-03-02 12:41 -------- d-----w- c:\programdata\Malwarebytes
2012-03-02 12:41 . 2011-12-10 20:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-02 03:15 . 2012-03-02 03:15 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-02 03:15 . 2012-03-02 03:15 -------- d-----w- c:\windows\system32\Macromed
2012-03-02 03:14 . 2012-03-02 03:14 -------- d-----w- c:\program files\Common Files\WebM Project
2012-03-02 03:14 . 2012-03-02 03:14 -------- d-----w- c:\program files\Google
2012-03-02 02:49 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2012-03-01 01:17 . 2012-03-01 01:17 -------- d-----w- c:\program files\Windows Portable Devices
2012-03-01 01:12 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2012-03-01 01:12 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2012-03-01 01:12 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2012-03-01 00:51 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-01 00:50 . 2011-12-14 16:17 680448 ----a-w- c:\windows\system32\msvcrt.dll
2012-03-01 00:47 . 2010-05-04 19:13 231424 ----a-w- c:\windows\system32\msshsq.dll
2012-03-01 00:42 . 2012-03-01 01:18 -------- d-----w- c:\program files\Microsoft Silverlight
2012-03-01 00:41 . 2009-06-03 23:56 675152 ----a-w- c:\windows\system32\gpprefcl.dll
2012-02-29 13:43 . 2012-02-29 13:43 -------- d-----w- c:\windows\system32\ca-ES
2012-02-29 13:43 . 2012-02-29 13:43 -------- d-----w- c:\windows\system32\eu-ES
2012-02-29 13:43 . 2012-02-29 13:43 -------- d-----w- c:\windows\system32\vi-VN
2012-02-29 13:40 . 2012-02-29 13:40 -------- d-----w- c:\windows\system32\SPReview
2012-02-29 13:28 . 2009-04-11 04:28 97792 ----a-w- c:\windows\system32\oleprn.dll
2012-02-29 13:27 . 2009-04-11 04:28 507904 ----a-w- c:\windows\system32\vdsdyn.dll
2012-02-29 13:25 . 2012-02-29 13:25 -------- d-----w- c:\windows\system32\EventProviders
2012-02-29 04:05 . 2012-02-08 03:03 6552120 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-02-29 03:53 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2012-02-29 03:53 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2012-02-27 13:21 . 2012-02-27 13:21 -------- d-----w- c:\program files\Microsoft.NET
2012-02-27 13:20 . 2009-11-08 15:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-02-27 13:20 . 2009-11-08 15:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-02-27 13:20 . 2009-11-08 15:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-02-27 13:20 . 2009-11-08 15:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-02-27 13:20 . 2009-11-08 15:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-02-27 09:06 . 2012-02-27 08:17 -------- d-----w- c:\windows\Debug
2012-02-27 08:52 . 2012-02-27 09:02 -------- d-----w- c:\windows\Panther
2012-02-27 08:51 . 2012-02-27 08:51 -------- d-----w- c:\windows\system32\OEM
2012-02-27 08:32 . 2012-02-27 08:32 -------- d-----w- C:\Windows.old
2012-02-27 08:03 . 2008-05-27 04:59 18904 ----a-w- c:\windows\system32\StructuredQuerySchemaTrivial.bin
2012-02-27 07:35 . 2010-02-20 23:06 24064 ----a-w- c:\windows\system32\nshhttp.dll
2012-02-27 07:35 . 2010-02-20 23:05 30720 ----a-w- c:\windows\system32\httpapi.dll
2012-02-27 07:35 . 2010-02-20 20:53 411648 ----a-w- c:\windows\system32\drivers\http.sys
2012-02-27 07:30 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
2012-02-27 07:28 . 2008-02-29 06:35 6656 ----a-w- c:\windows\system32\kbd106n.dll
2012-02-27 07:26 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2012-02-27 07:25 . 2011-02-12 08:39 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2012-02-27 07:25 . 2009-04-11 06:28 840704 ----a-w- c:\windows\system32\WFS.exe
2012-02-27 07:25 . 2011-02-22 13:23 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-02-27 07:25 . 2010-12-29 18:28 322560 ----a-w- c:\windows\system32\sbe.dll
2012-02-27 07:25 . 2010-12-29 18:28 153088 ----a-w- c:\windows\system32\sbeio.dll
2012-02-27 07:25 . 2010-12-29 18:26 177664 ----a-w- c:\windows\system32\mpg2splt.ax
2012-02-27 07:25 . 2010-10-18 13:37 81920 ----a-w- c:\windows\system32\consent.exe
2012-02-27 07:25 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2012-02-27 07:25 . 2011-04-21 13:58 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-27 07:17 . 2009-09-10 14:58 1418752 ----a-w- c:\program files\Windows Media Player\setup_wm.exe
2012-02-27 07:17 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe
2012-02-27 07:15 . 2009-12-04 18:30 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2012-02-27 07:15 . 2009-12-04 18:28 22528 ----a-w- c:\windows\system32\msyuv.dll
2012-02-27 07:15 . 2009-12-04 18:28 31744 ----a-w- c:\windows\system32\msvidc32.dll
2012-02-27 07:15 . 2009-12-04 18:28 123904 ----a-w- c:\windows\system32\msvfw32.dll
2012-02-27 07:15 . 2009-12-04 18:28 13312 ----a-w- c:\windows\system32\msrle32.dll
2012-02-27 07:15 . 2009-12-04 18:28 82944 ----a-w- c:\windows\system32\mciavi32.dll
2012-02-27 07:15 . 2009-12-04 18:28 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2012-02-27 07:15 . 2009-12-04 18:27 91136 ----a-w- c:\windows\system32\avifil32.dll
2012-02-27 07:12 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2012-02-27 07:06 . 2012-02-27 07:06 0 ----a-w- c:\windows\ativpsrm.bin
2012-02-27 07:00 . 2009-12-23 11:33 172032 ----a-w- c:\windows\system32\wintrust.dll
2012-02-27 07:00 . 2010-01-13 17:34 98304 ----a-w- c:\windows\system32\cabview.dll
2012-02-27 07:00 . 2012-02-27 07:00 -------- d-----w- c:\programdata\Office Genuine Advantage
2012-02-27 06:56 . 2012-02-27 06:56 713784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E8E6DE80-694A-4F49-A466-90DDA6D7384B}\gapaengine.dll
2012-02-27 06:56 . 2012-01-31 12:44 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-02-27 06:52 . 2012-02-27 06:52 -------- d-----w- c:\program files\Microsoft Security Client
2012-02-27 06:51 . 2010-04-05 20:00 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2012-02-27 06:50 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2012-02-27 06:50 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2012-02-27 06:50 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2012-02-27 06:50 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2012-02-27 06:50 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2012-02-27 06:50 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2012-02-27 06:50 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2012-02-27 06:50 . 2009-08-07 00:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2012-02-27 06:50 . 2009-08-06 23:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-02-27 06:37 . 2012-03-01 01:27 -------- d-----w- c:\program files\installshield installation information
2012-02-27 06:37 . 2012-02-27 06:37 -------- d-----w- c:\program files\NETGEAR
2012-02-27 06:37 . 2012-02-27 06:37 -------- d-----w- c:\programdata\NETGEAR
2012-02-27 06:37 . 2012-03-02 03:14 -------- d-sh--w- c:\windows\Installer
2012-02-27 06:37 . 2012-02-27 06:37 -------- d-----w- c:\windows\Downloaded Installations
2012-02-27 06:18 . 2012-03-01 00:43 -------- d-----w- c:\users\Adriana
2012-02-27 06:15 . 2012-02-27 06:15 -------- d-----w- c:\users\ashleyxoxjoshua
2012-02-25 00:36 . 2012-02-27 23:45 -------- d-----w- C:\MGADiagToolOutput
2012-02-19 13:07 . 2012-02-20 01:44 -------- d-----w- C:\notepad
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 55775525
*Deregistered* - 55775525
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-02 06:56]
.
2012-03-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-03-02 06:56]
.
2012-03-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-959352362-581761041-2300734415-1001Core.job
- c:\users\Adriana\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-27 06:56]
.
2012-03-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-959352362-581761041-2300734415-1001UA.job
- c:\users\Adriana\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-27 06:56]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
TCP: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-03-03 09:14
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-03-03 09:16:23
ComboFix-quarantined-files.txt 2012-03-03 14:16
.
Pre-Run: 168,524,013,568 bytes free
Post-Run: 167,816,663,040 bytes free
.
- - End Of File - - BCE4B49585C33EAFE5EFCB1AD2DEAA6F