Comp been acting weird today. windows live doesn't sign in , calendar had April 25th 2010 as date, firefox wasn't my default browser, my antivirus (avast) appears to have been deleted. I tried using restore point but there is only one and it is for April 25 2010 9 am...
anyways here are my logs. Combofix is huge
ComboFix 10-01-12.02 - Mike 01/12/2010 16:50:21.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.574 [GMT -5:00]
Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
C:\LOG.TXT
c:\windows\system32\SIntf16.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_APPLE_MOBILE_DEVICE
-------\Service_Apple Mobile Device
((((((((((((((((((((((((( Files Created from 2009-12-12 to 2010-01-12 )))))))))))))))))))))))))))))))
.
2010-04-25 17:33 . 2010-04-25 17:33 262144 ----a-w- C:\ntuser.dat
2010-01-12 21:24 . 2010-01-12 21:24 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-10 03:39 . 2010-01-10 03:44 -------- d-----w- c:\program files\Children of the Nile - Enhanced Edition
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-12 21:41 . 2009-11-13 17:13 -------- d-----w- c:\program files\Alwil Software
2010-01-12 21:28 . 2009-07-18 21:18 -------- d-----w- c:\program files\Yahoo!
2010-01-12 21:27 . 2009-07-18 22:20 -------- d-----w- c:\documents and settings\Mike\Application Data\Yahoo!
2010-01-12 21:24 . 2009-07-18 21:19 -------- d-----w- c:\documents and settings\Yosley\Application Data\Yahoo!
2010-01-12 21:24 . 2009-07-18 21:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-12 21:23 . 2008-02-25 19:32 -------- d-----w- c:\program files\Windows Live
2010-01-11 20:34 . 2008-03-29 12:20 -------- d-----w- c:\program files\Google
2010-01-11 18:03 . 2008-06-17 18:51 -------- d-----w- c:\program files\Diablo II
2010-01-11 18:03 . 2008-06-04 02:47 81347 -c--a-w- c:\windows\DIIUnin.dat
2010-01-11 14:35 . 2008-10-18 23:57 -------- d-----w- c:\documents and settings\Mike\Application Data\Winamp
2010-01-10 04:04 . 2009-12-12 19:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Avery
2010-01-09 19:40 . 2008-01-23 21:52 -------- d-----w- c:\documents and settings\Mike\Application Data\U3
2010-01-09 17:18 . 2008-01-23 17:04 135856 ----a-w- c:\documents and settings\Yosley\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-15 22:14 . 2009-12-12 04:43 -------- d-----w- c:\program files\Free Easy Burner
2009-12-15 11:24 . 2008-02-12 00:55 -------- d-----w- c:\documents and settings\Mike\Application Data\uTorrent
2009-12-13 15:54 . 2008-01-23 21:06 135856 ----a-w- c:\documents and settings\Mike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-12 22:00 . 2008-10-20 23:41 -------- d-----w- c:\program files\Activision
2009-12-12 19:25 . 2008-01-23 17:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-12 07:08 . 2009-07-16 17:55 -------- d-----w- c:\program files\Ubisoft
2009-12-12 05:14 . 2009-12-12 05:14 -------- d-----w- c:\program files\Bethesda Softworks
2009-12-12 04:40 . 2008-09-22 19:48 -------- d-----w- c:\program files\Common Files\Nero
2009-12-12 04:39 . 2008-09-22 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-12-09 01:44 . 2009-12-09 02:02 19236 ----a-w- C:\mediamp3.dat
2009-12-02 01:28 . 2009-10-06 23:49 -------- d-----w- c:\documents and settings\Mike\Application Data\gtk-2.0
2009-12-01 02:11 . 2009-12-01 02:11 -------- d-----w- c:\documents and settings\Mike\Application Data\GameRanger
2009-11-27 21:37 . 2008-01-31 21:56 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-11-27 21:37 . 2008-01-31 22:00 138936 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-27 21:37 . 2008-01-31 21:56 214504 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-11-27 20:51 . 2009-11-27 20:51 1207984 ----a-w- c:\documents and settings\Mike\Application Data\GameRanger\GameRanger\GameRanger.exe
2009-11-27 20:50 . 2009-11-27 20:50 155312 ----a-w- c:\documents and settings\Mike\Application Data\GameRanger\GameRanger\Data\GameRanger.dll
2009-11-26 16:47 . 2009-10-23 05:01 -------- d-----w- c:\program files\PokerStars
2009-11-25 18:19 . 2009-11-25 18:19 -------- d-----w- c:\documents and settings\Guest\Application Data\Malwarebytes
2009-11-22 04:56 . 2008-09-22 19:51 -------- d-----w- c:\documents and settings\Mike\Application Data\Nero
2009-11-22 04:14 . 2008-02-05 19:16 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-19 15:54 . 2009-11-19 15:54 48816 ----a-w- c:\documents and settings\Mike\Application Data\GameRanger\GameRanger\Data\GameRangerLaunch.dll
2009-11-15 21:58 . 2009-11-15 21:58 2368 ----a-w- c:\windows\system32\SVKP.sys
2009-11-15 21:53 . 2009-11-15 21:53 -------- d-----w- c:\program files\JoWooD
2009-11-14 15:15 . 2008-03-28 16:53 -------- d-----w- c:\documents and settings\Yosley\Application Data\Apple Computer
2009-11-14 05:39 . 2009-11-14 05:39 138240 ----a-w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll
2009-11-14 05:39 . 2009-11-14 05:39 138240 ----a-w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll
2009-11-14 05:39 . 2009-11-14 05:39 138240 ----a-w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll
2009-11-14 05:39 . 2009-11-14 05:39 138240 ----a-w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll
2009-11-14 05:39 . 2008-02-03 03:35 -------- d-----w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab
2009-11-01 15:01 . 2009-11-01 15:01 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-22 14:29 . 2009-08-12 20:41 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
anyways here are my logs. Combofix is huge
ComboFix 10-01-12.02 - Mike 01/12/2010 16:50:21.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.574 [GMT -5:00]
Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
C:\LOG.TXT
c:\windows\system32\SIntf16.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_APPLE_MOBILE_DEVICE
-------\Service_Apple Mobile Device
((((((((((((((((((((((((( Files Created from 2009-12-12 to 2010-01-12 )))))))))))))))))))))))))))))))
.
2010-04-25 17:33 . 2010-04-25 17:33 262144 ----a-w- C:\ntuser.dat
2010-01-12 21:24 . 2010-01-12 21:24 -------- d-----w- c:\windows\system32\wbem\Repository
2010-01-10 03:39 . 2010-01-10 03:44 -------- d-----w- c:\program files\Children of the Nile - Enhanced Edition
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-12 21:41 . 2009-11-13 17:13 -------- d-----w- c:\program files\Alwil Software
2010-01-12 21:28 . 2009-07-18 21:18 -------- d-----w- c:\program files\Yahoo!
2010-01-12 21:27 . 2009-07-18 22:20 -------- d-----w- c:\documents and settings\Mike\Application Data\Yahoo!
2010-01-12 21:24 . 2009-07-18 21:19 -------- d-----w- c:\documents and settings\Yosley\Application Data\Yahoo!
2010-01-12 21:24 . 2009-07-18 21:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-12 21:23 . 2008-02-25 19:32 -------- d-----w- c:\program files\Windows Live
2010-01-11 20:34 . 2008-03-29 12:20 -------- d-----w- c:\program files\Google
2010-01-11 18:03 . 2008-06-17 18:51 -------- d-----w- c:\program files\Diablo II
2010-01-11 18:03 . 2008-06-04 02:47 81347 -c--a-w- c:\windows\DIIUnin.dat
2010-01-11 14:35 . 2008-10-18 23:57 -------- d-----w- c:\documents and settings\Mike\Application Data\Winamp
2010-01-10 04:04 . 2009-12-12 19:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Avery
2010-01-09 19:40 . 2008-01-23 21:52 -------- d-----w- c:\documents and settings\Mike\Application Data\U3
2010-01-09 17:18 . 2008-01-23 17:04 135856 ----a-w- c:\documents and settings\Yosley\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-15 22:14 . 2009-12-12 04:43 -------- d-----w- c:\program files\Free Easy Burner
2009-12-15 11:24 . 2008-02-12 00:55 -------- d-----w- c:\documents and settings\Mike\Application Data\uTorrent
2009-12-13 15:54 . 2008-01-23 21:06 135856 ----a-w- c:\documents and settings\Mike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-12 22:00 . 2008-10-20 23:41 -------- d-----w- c:\program files\Activision
2009-12-12 19:25 . 2008-01-23 17:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-12 07:08 . 2009-07-16 17:55 -------- d-----w- c:\program files\Ubisoft
2009-12-12 05:14 . 2009-12-12 05:14 -------- d-----w- c:\program files\Bethesda Softworks
2009-12-12 04:40 . 2008-09-22 19:48 -------- d-----w- c:\program files\Common Files\Nero
2009-12-12 04:39 . 2008-09-22 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-12-09 01:44 . 2009-12-09 02:02 19236 ----a-w- C:\mediamp3.dat
2009-12-02 01:28 . 2009-10-06 23:49 -------- d-----w- c:\documents and settings\Mike\Application Data\gtk-2.0
2009-12-01 02:11 . 2009-12-01 02:11 -------- d-----w- c:\documents and settings\Mike\Application Data\GameRanger
2009-11-27 21:37 . 2008-01-31 21:56 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-11-27 21:37 . 2008-01-31 22:00 138936 -c--a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-27 21:37 . 2008-01-31 21:56 214504 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-11-27 20:51 . 2009-11-27 20:51 1207984 ----a-w- c:\documents and settings\Mike\Application Data\GameRanger\GameRanger\GameRanger.exe
2009-11-27 20:50 . 2009-11-27 20:50 155312 ----a-w- c:\documents and settings\Mike\Application Data\GameRanger\GameRanger\Data\GameRanger.dll
2009-11-26 16:47 . 2009-10-23 05:01 -------- d-----w- c:\program files\PokerStars
2009-11-25 18:19 . 2009-11-25 18:19 -------- d-----w- c:\documents and settings\Guest\Application Data\Malwarebytes
2009-11-22 04:56 . 2008-09-22 19:51 -------- d-----w- c:\documents and settings\Mike\Application Data\Nero
2009-11-22 04:14 . 2008-02-05 19:16 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-19 15:54 . 2009-11-19 15:54 48816 ----a-w- c:\documents and settings\Mike\Application Data\GameRanger\GameRanger\Data\GameRangerLaunch.dll
2009-11-15 21:58 . 2009-11-15 21:58 2368 ----a-w- c:\windows\system32\SVKP.sys
2009-11-15 21:53 . 2009-11-15 21:53 -------- d-----w- c:\program files\JoWooD
2009-11-14 15:15 . 2008-03-28 16:53 -------- d-----w- c:\documents and settings\Yosley\Application Data\Apple Computer
2009-11-14 05:39 . 2009-11-14 05:39 138240 ----a-w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll
2009-11-14 05:39 . 2009-11-14 05:39 138240 ----a-w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll
2009-11-14 05:39 . 2009-11-14 05:39 138240 ----a-w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll
2009-11-14 05:39 . 2009-11-14 05:39 138240 ----a-w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll
2009-11-14 05:39 . 2008-02-03 03:35 -------- d-----w- c:\documents and settings\Mike\Application Data\SystemRequirementsLab
2009-11-01 15:01 . 2009-11-01 15:01 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-22 14:29 . 2009-08-12 20:41 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.