Thomas
Full Member
  

Gender: 
Posts: 233
|
 |
help please
« on: Aug 22nd, 2009, 5:02pm » |
|
hey tom i can not reformat my pc it says it can not find mup.sys but i have it in my driver folder ComboFix 09-08-22.06 - Compaq_Owner 08/22/2009 17:27.1.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.222.102 [GMT -4:00] Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . ((((((((((((((((((((((((( Files Created from 2009-07-22 to 2009-08-22 ))))))))))))))))))))))))))))))) . 2009-08-22 15:04 . 2009-08-22 21:17117760----a-w-c:\documents and settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-08-22 15:03 . 2009-08-22 15:03--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-08-22 15:02 . 2009-08-22 15:22--------d-----w-c:\program files\SUPERAntiSpyware 2009-08-22 15:02 . 2009-08-22 15:02--------d-----w-c:\documents and settings\Compaq_Owner\Application Data\SUPERAntiSpyware.com 2009-08-22 15:01 . 2009-08-22 15:01--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-08-20 08:22 . 2009-08-20 08:2273216----a-w-c:\windows\system32\dllcache\setup50.exe 2009-08-19 04:46 . 2009-08-19 04:46--------d-----w-c:\documents and settings\All Users\Application Data\IObit 2009-08-19 03:44 . 2009-08-19 03:44--------d-----w-c:\documents and settings\Compaq_Owner\Application Data\Yahoo! 2009-08-19 03:42 . 2009-08-22 08:15--------d-----w-c:\documents and settings\Compaq_Owner\Application Data\IObit 2009-08-19 03:42 . 2009-08-19 04:46--------d-----w-c:\program files\IObit 2009-08-18 01:47 . 2009-08-18 01:47--------d-----w-c:\windows\speech 2009-08-15 01:47 . 2009-08-15 01:47--------d-----w-c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Yahoo 2009-08-15 01:30 . 2009-08-15 01:47--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo! 2009-08-15 01:30 . 2009-05-26 23:50607472----a-w-c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe 2009-08-15 01:30 . 2009-08-19 05:29--------d-----w-c:\program files\Yahoo! 2009-08-09 00:42 . 2009-08-09 00:51--------d-----w-c:\documents and settings\Compaq_Owner\Application Data\TeamViewer 2009-08-09 00:41 . 2009-08-09 00:41--------d-----w-c:\program files\TeamViewer 2009-08-09 00:40 . 2009-08-09 00:40--------d-----w-c:\documents and settings\Compaq_Owner\temp 2009-08-04 19:16 . 2009-08-04 19:16152576----a-w-c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_15\lzma.dll 2009-08-03 06:18 . 2009-08-06 19:24--------d-----w-c:\documents and settings\Compaq_Owner\Application Data\YTK Enhanced 2009-08-03 06:18 . 2009-08-06 19:24987994----a-w-c:\documents and settings\Compaq_Owner\Application Data\YTK Enhanced\unins000.exe 2009-08-03 06:17 . 2009-08-03 06:35--------d-----w-c:\program files\YTK Enhanced 2009-07-31 16:17 . 2009-07-31 16:1747360----a-w-c:\windows\system32\drivers\pcouffin.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-22 21:17 . 2009-04-11 01:09--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP 2009-08-22 15:13 . 2009-04-10 23:57--------d-----w-c:\documents and settings\Compaq_Owner\Application Data\uTorrent 2009-08-21 09:42 . 2009-04-25 08:57300680----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-08-19 21:15 . 2009-04-11 00:58--------d-----w-c:\program files\TrojanHunter 5.1 2009-08-10 22:20 . 2009-04-15 23:53--------d-----w-c:\program files\Microsoft Silverlight 2009-08-10 00:37 . 2009-04-11 00:2955656----a-w-c:\windows\system32\drivers\avgntflt.sys 2009-08-04 19:17 . 2005-08-08 22:19--------d-----w-c:\program files\Java 2009-07-25 09:23 . 2009-04-11 00:06411368----a-w-c:\windows\system32\deploytk.dll 2009-07-14 00:35 . 2009-07-14 00:35--------d-----w-c:\documents and settings\Compaq_Owner\Application Data\Windows Search 2009-07-03 17:09 . 2004-08-04 12:00915456----a-w-c:\windows\system32\wininet.dll 2009-07-02 13:59 . 2009-07-02 11:59--------d-----w-c:\documents and settings\Compaq_Owner\Application Data\Wireshark 2009-07-02 11:55 . 2009-07-02 11:54--------d-----w-c:\program files\Wireshark 2009-07-02 11:55 . 2009-07-02 11:55--------d-----w-c:\program files\WinPcap 2009-07-01 19:40 . 2009-04-11 16:02--------d-----w-c:\program files\Winamp 2009-06-29 16:09 . 2009-06-29 16:09--------d-----w-c:\documents and settings\All Users\Application Data\Tarma Installer 2009-06-29 16:08 . 2009-06-29 16:0981920--s---r-c:\documents and settings\All Users\Application Data\Tarma Installer\{D6B25B8D-0566-42B1-A23D-7576138435D6}\Setup.exe 2009-06-27 00:46 . 2009-06-27 00:462112----a-w-c:\windows\system32\drivers\kxrmsghookdrv.sys 2009-06-24 06:42 . 2009-06-24 06:42--------d-----w-c:\program files\Digital Asphyxia 2009-06-16 14:36 . 2004-08-04 12:0081920----a-w-c:\windows\system32\fontsub.dll 2009-06-16 14:36 . 2004-08-04 12:00119808----a-w-c:\windows\system32\t2embed.dll 2009-06-10 00:35 . 2009-06-10 00:35152576----a-w-c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-06-08 22:34 . 2009-06-08 22:34321536----atw-c:\documents and settings\Compaq_Owner\Application Data\Microsoft\engine_vx.dll 2009-06-08 22:34 . 2009-06-08 22:3418724----atw-c:\documents and settings\Compaq_Owner\Application Data\Microsoft\bass.dll 2009-06-08 22:34 . 2009-06-08 22:3426200----atw-c:\documents and settings\Compaq_Owner\Application Data\Microsoft\qwadjb.dll 2009-06-08 22:34 . 2009-06-08 22:3416952----atw-c:\documents and settings\Compaq_Owner\Application Data\Microsoft\1eaadjc.dll 2009-06-08 22:34 . 2009-06-08 22:3415416----atw-c:\documents and settings\Compaq_Owner\Application Data\Microsoft\rsaadjd.dll 2009-06-08 22:34 . 2009-06-08 22:3414392----atw-c:\documents and settings\Compaq_Owner\Application Data\Microsoft\kfgresk.dll 2009-06-08 22:34 . 2009-06-08 22:3413984----atw-c:\documents and settings\Compaq_Owner\Application Data\Microsoft\mjcriu.dll 2009-06-08 22:34 . 2009-06-08 22:3410808----atw-c:\documents and settings\Compaq_Owner\Application Data\Microsoft\peaadje.dll 2009-06-03 19:09 . 2004-08-04 12:001291264----a-w-c:\windows\system32\quartz.dll 2009-05-28 11:03 . 2009-04-11 00:0032800----a-w-c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-25 04:24 . 2008-05-27 02:18350208----a-w-c:\windows\system32\mssph.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-22 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "THGuard"="c:\program files\TrojanHunter 5.1\THGuard.exe" [2009-04-11 1056928] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280] "IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-08-20 943888] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 16:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Digital Asphyxia\\Y!TunnelPro 2.5\\YTPro.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\VC Sync\\VCSync.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"= "c:\\Program Files\\YTK Enhanced\\YTKE.exe"= R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [4/10/2009 8:29 PM 108289] R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [8/21/2009 12:28 AM 305936] R3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\drivers\ubVeo532.sys [7/1/2002 6:30 PM 95232] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408] S0 gzsrgbl;gzsrgbl;c:\windows\system32\drivers\ifrcr.sys --> c:\windows\system32\drivers\ifrcr.sys [?] S3 devkxrmsghookdrv;kX-Ray Msg Hook Enum Drv;c:\windows\system32\drivers\kxrmsghookdrv.sys [6/26/2009 8:46 PM 2112] S3 KMD;ProcInspect;\??\c:\documents and settings\Compaq_Owner\Desktop\kX-Ray\KMD.sys --> c:\documents and settings\Compaq_Owner\Desktop\kX-Ray\KMD.sys [?] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [12/23/2008 11:35 AM 50704] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-08-22 c:\windows\Tasks\AWC AutoCare.job - c:\program files\IObit\Advanced SystemCare 3\AutoCare.exe [2009-08-19 19:11] 2009-08-22 c:\windows\Tasks\AWC AutoSweep.job - c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2009-08-19 19:35] 2009-08-22 c:\windows\Tasks\AWC Update.job - c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2009-08-19 14:15] 2009-08-22 c:\windows\Tasks\User_Feed_Synchronization-{31D4BDED-654E-4816-B55F-1833 525DC237}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser uSearchURL,(Default) = hxxp://www.google.com/keyword/%s DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab . ************************************************************************ ** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-08-22 17:35 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df ,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,df,f1,87,4c,a8,d5,47,47,b7,57, a4,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df ,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,df,f1,87,4c,a8,d5,47,47,b7,57, a4,\ [HKEY_LOCAL_MACHINE\software\Classes\{80b8c23c-16e0-4cd8-bbc3-cecec9a78b79}] @DACL=(02 0000) @SACL=(02 0000) [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*] "AB141C35E9F4BF344B9FC010BB17F68A"="" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(740) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2620) c:\windows\system32\WININET.dll c:\windows\system32\webcheck.dll c:\windows\system32\IEFRAME.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-08-22 17:38 ComboFix-quarantined-files.txt 2009-08-22 21:38 Pre-Run: 51,558,359,040 bytes free Post-Run: 51,567,017,984 bytes free 173--- E O F ---2009-06-10 01:22
|