Here's the Systemlook log:
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 22:35 on 31/07/2010 by Administrator (Administrator - Elevation successful)
========== filefind ==========
Searching for "wscntfy.*"
No files found.
Searching for "tcpip.*"
C:\Qoobox\Quarantine\Registry_backups\tcpip.reg --a--- 17241 bytes [04:20 29/07/2010] [00:05 01/08/2010] C2628F948D440133CF42DE87A33E0D13
C:\WINDOWS\Help\tcpip.chm --a--c 50586 bytes [10:00 14/04/2008] [10:00 14/04/2008] 24FC18A9ED0AA561C5F5DC295F9AA9F2
C:\WINDOWS\system32\drivers\tcpip.sys --a--c 361600 bytes [04:52 30/12/2008] [04:52 30/12/2008] 5AE1C2695F6523AD98B948F2887D8C5E
-=End Of File=-
Here's the ComboFix log:
ComboFix 10-07-31.02 - Administrator 07/31/2010 22:58:38.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1406 [GMT -4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2010-07-01 to 2010-08-01 )))))))))))))))))))))))))))))))
.
2010-07-29 17:45 . 2010-07-29 17:46 -------- d-----w- c:\program files\Zards software
2010-07-29 13:28 . 2010-07-29 13:28 -------- d-----w- c:\windows\system32\wbem\snmp
2010-07-29 13:28 . 2010-07-29 13:28 -------- d-----w- c:\windows\system32\xircom
2010-07-29 13:28 . 2010-07-29 13:28 -------- d-----w- c:\program files\microsoft frontpage
2010-07-29 03:58 . 2010-07-29 03:58 -------- d-----w- c:\program files\Trend Micro
2010-07-29 00:08 . 2010-07-29 00:08 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-07-28 21:34 . 2010-07-28 21:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-07-28 21:34 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-28 21:34 . 2010-07-28 21:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-28 21:34 . 2010-07-28 21:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-28 21:34 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-24 00:18 . 2010-07-24 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-07-24 00:18 . 2010-07-24 00:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\Office Genuine Advantage
2010-07-14 14:11 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-05 14:26 . 2010-07-29 20:00 -------- d-----w- c:\program files\Garena
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-31 23:37 . 2009-07-08 02:44 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2010-07-31 03:44 . 2009-04-25 01:35 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2010-07-28 21:18 . 2009-05-10 05:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-15 04:03 . 2009-04-25 01:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-05 02:44 . 2010-03-14 23:13 253241 ----a-w- c:\documents and settings\Administrator\Application Data\Sony Online Entertainment\npsoeact.dll
2010-07-05 02:44 . 2010-03-14 23:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Sony Online Entertainment
2010-06-28 19:49 . 2010-06-17 00:34 21361 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-06-28 19:46 . 2010-06-28 19:38 -------- d-----w- c:\program files\NETGEAR
2010-06-28 19:38 . 2009-04-23 18:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-27 03:10 . 2010-06-27 03:10 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-17 00:34 . 2009-06-03 19:32 -------- d-----w- c:\program files\RALINK
2010-06-14 14:31 . 2009-04-23 17:28 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
.
(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
------- Sigcheck -------
[-] 2008-12-30 . 5AE1C2695F6523AD98B948F2887D8C5E . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
c:\windows\System32\wscntfy.exe ... is missing !!
.
((((((((((((((((((((((((((((( SnapShot@2010-07-29_04.21.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-01 02:39 . 2010-08-01 02:39 16384 c:\windows\Temp\Perflib_Perfdata_258.dat
+ 2008-04-14 10:00 . 2010-07-31 23:10 91010 c:\windows\system32\perfc009.dat
+ 2010-07-28 17:20 . 2010-07-31 23:59 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-07-28 17:20 . 2010-07-29 04:16 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-14 10:00 . 2010-07-31 23:10 488522 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:03 1230080 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-04-10 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-07-09 2048352]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2008-04-14 99840]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Startup Defender.lnk - c:\program files\Zards software\Startup Defender\Startup Defender.exe [2009-1-25 1045504]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-4-23 24576]
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2009-12-23 2330624]
Pharos Notify.lnk - c:\program files\Pharos\bin\PSNotify.exe [2009-4-28 405504]
Smart Wizard Wireless Settings.lnk - c:\program files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe [2010-6-28 1044577]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-31 12:55 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
2009-04-27 14:51 49968 ----a-w- c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2008-05-02 04:15 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"DAUpdaterSvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Pharos\\bin\\PSNotify.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/10/2009 1:24 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/10/2009 1:24 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/31/2009 8:55 AM 297752]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [10/9/2007 1:13 PM 38144]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [4/28/2009 12:04 PM 24652]
R3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [7/31/2009 3:12 PM 341504]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [4/24/2009 9:32 PM 721904]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\NQZ63.tmp --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\NQZ63.tmp [?]
S4 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [11/21/2009 4:16 AM 25832]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ASPI32
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2010-07-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-2139871995-1417001333-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-10 03:54]
2010-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-2139871995-1417001333-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-10 03:54]
2010-08-01 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\i8vginbr.default\
FF - prefs.js: browser.startup.homepage - about
:blank
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-31 23:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\NQZ63.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc21.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-861567501-2139871995-1417001333-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:96,b3,57,10,40,db,db,94,e0,4e,fd,26,52,b0,7d,ab,77,75,01,63,b1,e3,0d,
e8,03,0e,6f,a1,ee,7e,2d,8d,60,b6,32,66,3b,01,cb,b7,75,bc,81,88,af,2f,26,a3,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-861567501-2139871995-1417001333-500\Software\SecuROM\License information*]
"datasecu"=hex:aa,25,97,c8,51,62,f6,bf,c0,49,e1,24,89,e1,c8,96,f4,4f,e5,6c,10,
b1,ff,1d,88,d2,53,ac,96,be,4f,5d,14,bb,7d,6b,79,ab,3e,14,7d,2b,98,50,82,f1,\
"rkeysecu"=hex:26,50,c2,0d,f2,e2,67,4c,ee,08,ee,0f,e2,b3,93,6f
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2960)
c:\windows\system32\msi.dll
.
Completion time: 2010-07-31 23:01:15
ComboFix-quarantined-files.txt 2010-08-01 03:01
ComboFix2.txt 2010-08-01 02:45
ComboFix3.txt 2010-08-01 00:08
ComboFix4.txt 2010-07-29 04:22
Pre-Run: 22,445,989,888 bytes free
Post-Run: 22,430,212,096 bytes free
- - End Of File - - 23AACCB0C24185CCB717AE8678BD8C4D