Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.
MalwareByte's Anti-Malware Download

> Forum Guidelines

Read this topic before posting a log.


DO NOT post a ComboFix log unless requested to.


Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.

2 Pages V   1 2 >  
Closed TopicStart new topic
> Vundo Removal
ccoia
post Feb 12 2008, 07:04 AM
Post #1


Member
**

Group: Members
Posts: 21
Joined: 7-February 08
Member No.: 188,831



Hi, I am running XP sp2 and have tried to remove a Vundo infection. Now I constantly get a notice that I have a vats infection and upon booting I get the error that:
windows cannot find c:\windows\system32\vtstq.exe. Make sure you typed the name correctly and try again.
cannot load or run c:\windows\system32\vtstq.exe specified in the registry. make sure the file exists on your computer.


Previous to contacting this forum I have run Adaware, Spybot and Stinger380.
Thanks for your help.

This is the log of the scan when the system is not in safe mode:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:42:45 AM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rnews.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtstq.exe
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [McRegWiz] /autorun
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

--
End of file - 3601 bytes
Go to the top of the page
 
+Quote Post
SifuMike
post Feb 14 2008, 02:45 PM
Post #2


malware expert
******

Group: HJT Team
Posts: 10,743
Joined: 8-January 05
From: Vancouver (not BC) WA (Not DC) USA
Member No.: 9,026



Hello ccoia,

QUOTE
I am running XP sp2 and have tried to remove a Vundo infection.


How did you try to remove it?


Your hijackthis log is missing all the running processes. blink.gif
I need to see the running processes to find the infections.


The top portion of your log should look something like this:
QUOTE
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:00:29, on 10/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe



Please reboot your computer to the Normal Mode, then post a fresh Hijackthis log. Make sure the running processes are there.

This post has been edited by SifuMike: Feb 14 2008, 02:46 PM


--------------------
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!





Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.
Go to the top of the page
 
+Quote Post
ccoia
post Feb 14 2008, 03:13 PM
Post #3


Member
**

Group: Members
Posts: 21
Joined: 7-February 08
Member No.: 188,831



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:11:43 PM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
I ran vundofix and vundobegone.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rnews.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtstq.exe
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [McRegWiz] /autorun
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

--
End of file - 4939 bytes

This post has been edited by ccoia: Feb 14 2008, 03:15 PM
Go to the top of the page
 
+Quote Post
SifuMike
post Feb 14 2008, 05:41 PM
Post #4


malware expert
******

Group: HJT Team
Posts: 10,743
Joined: 8-January 05
From: Vancouver (not BC) WA (Not DC) USA
Member No.: 9,026



Hi ccoia,

We will run ComboFix.

You need to disable your McAfee Antivirus before running ComboFix, as it will prevent it from running.

To disable McAfee Virusscan:
Please navigate to the system tray on the bottom right hand corner and look for a sign.
  • right-click it -> chose "Exit."
  • a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.
You succesfully disabled the McAfee Guard.




Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Be sure to install the Windows XP Recovery Console in case you have not installed it yet. <== IMPORTANT

Post the ComboFix log.


--------------------
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!





Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.
Go to the top of the page
 
+Quote Post
ccoia
post Feb 15 2008, 07:26 AM
Post #5


Member
**

Group: Members
Posts: 21
Joined: 7-February 08
Member No.: 188,831



Had a hard time getting Mcafee to shut off. Exit was not an option when right clicking.


ComboFix 08-02-15.2 - Owner 2008-02-15 7:16:18.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.260 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\Vundo Fix\ComboFix.exe
* Created a new restore point

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\gffatpet.dll
C:\WINDOWS\system32\qtstv.ini
C:\WINDOWS\system32\qtstv.ini2
C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\vymtndgg.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.

2008-02-07 11:54 . 2008-02-07 11:57 <DIR> d-------- C:\HijackThis
2008-02-07 11:48 . 2008-02-07 11:48 20,328 --a------ C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
2008-02-07 11:36 . 2008-02-07 11:36 376 --a------ C:\WINDOWS\ODBC.INI
2008-02-07 11:32 . 2008-02-07 11:32 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-02-07 11:29 . 2008-02-07 11:31 <DIR> d-------- C:\WINDOWS\ShellNew
2008-02-07 11:29 . 2008-02-07 11:29 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-02-07 07:30 . 2008-02-07 07:38 827 --a------ C:\reg.rtf
2008-02-06 12:44 . 2008-02-06 12:44 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-06 12:44 . 2008-02-06 12:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-06 12:44 . 2008-02-06 12:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-06 10:46 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-05 16:14 . 2008-02-14 14:58 1,968 --a------ C:\WINDOWS\system32\Config.MPF
2008-02-05 16:10 . 2008-02-05 16:10 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-02-05 16:10 . 2008-02-05 16:10 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SiteAdvisor
2008-02-05 16:10 . 2008-02-05 16:10 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-02-05 16:09 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-02-05 16:07 . 2007-06-25 10:57 171,240 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-05 16:07 . 2007-06-25 10:57 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-05 16:07 . 2007-06-25 10:57 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-05 16:07 . 2007-06-25 10:57 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-05 16:06 . 2007-03-02 14:16 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-05 16:06 . 2007-06-25 14:54 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-05 16:05 . 2008-02-05 16:09 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-02-05 15:52 . 2008-02-05 15:52 <DIR> d-------- C:\Program Files\RcvSystem
2008-02-05 13:32 . 2008-02-07 06:54 774 --ahs---- C:\WINDOWS\system32\yegauytq.ini
2008-02-05 13:31 . 2008-02-05 13:31 90,688 --a------ C:\WINDOWS\system32\qtyuagey.dll
2008-02-04 15:18 . 2008-02-04 15:18 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Walgreens
2008-02-01 03:21 . 2008-02-01 03:21 245,408 --a------ C:\WINDOWS\system32\unicows.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 18:15 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe
2008-02-07 16:26 158,208 ----a-w C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
2008-02-07 14:41 --------- d-----w C:\Program Files\Yahoo!
2008-02-07 14:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Yahoo!
2008-02-07 14:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-06 18:42 --------- d-----w C:\Program Files\QuickTime
2008-02-06 00:12 --------- d-----w C:\Program Files\McAfee
2008-02-06 00:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-06 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-02-05 23:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-01-14 13:50 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-14 03:00 --------- d-----w C:\Program Files\McAfee.com
2008-01-14 02:59 --------- d-----w C:\Documents and Settings\Owner\Application Data\McAfee.com Personal Firewall
2008-01-14 02:45 --------- d-----w C:\Program Files\MySpace
2008-01-14 01:11 --------- d-----w C:\Program Files\Kodak
2008-01-14 01:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-01-14 01:10 --------- d-----w C:\Program Files\Common Files\Kodak
2008-01-14 01:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-05 03:03 --------- d-----w C:\Documents and Settings\Owner\Application Data\MySpace
2008-01-04 02:47 --------- d-----w C:\Program Files\Google
2008-01-04 02:20 --------- d-----w C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2008-01-04 01:18 --------- d-----w C:\Documents and Settings\Owner\Application Data\McAfee
2008-01-03 02:33 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-03 02:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-03 02:30 --------- d-----w C:\Program Files\Analog Devices
2008-01-03 02:29 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-03 02:24 --------- d-----w C:\Program Files\Citrix
2008-01-03 02:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Citrix
.
CODE
<pre>
----a-w         1,404,928 2008-02-06 20:39:47  C:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w           152,144 2008-02-06 20:39:47  C:\Program Files\McAfee\MSK\MskAgent .exe
----a-w            98,304 2008-02-05 21:25:33  C:\Program Files\McAfee\SpamKiller\MskAgent .exe
----a-w           139,264 2008-02-06 21:00:22  C:\Program Files\McAfee.com\Agent\MC01A1~1 .EXE
----a-w           139,264 2008-02-06 21:00:22  C:\Program Files\McAfee.com\Agent\MC01A1~2 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC01A1~3 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC01A1~4 .EXE
----a-w           184,320 2008-02-04 17:50:31  C:\Program Files\McAfee.com\Agent\MC01FF~1 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC069F~1 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~2 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~3 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~4 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC099F~1 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~2 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~3 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~4 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC1E26~1 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~2 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~3 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~4 .EXE
----a-w           184,320 2008-01-23 20:43:03  C:\Program Files\McAfee.com\Agent\MC2398~1      .EXE
----a-w           184,320 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC2398~1     .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1    .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1   .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1  .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1 .EXE
----a-w           184,320 2008-01-21 20:59:07  C:\Program Files\McAfee.com\Agent\MC2398~2 .EXE
----a-w           184,320 2008-01-21 21:08:22  C:\Program Files\McAfee.com\Agent\MC2398~4 .EXE
----a-w           184,320 2008-01-30 20:53:09  C:\Program Files\McAfee.com\Agent\MC3211~1 .EXE
----a-w           184,320 2008-02-06 21:00:28  C:\Program Files\McAfee.com\Agent\MC3882~1 .EXE
----a-w           184,320 2008-02-06 21:00:28  C:\Program Files\McAfee.com\Agent\MC3882~2 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3882~3 .EXE
----a-w           184,320 2008-01-23 00:21:31  C:\Program Files\McAfee.com\Agent\MC3882~4 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3993~1 .EXE
----a-w           184,320 2008-02-05 23:51:47  C:\Program Files\McAfee.com\Agent\MC3993~2 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3D5C~1 .EXE
----a-w           184,320 2008-01-17 01:49:25  C:\Program Files\McAfee.com\Agent\MC3D5C~2 .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~1  .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~1 .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~2    .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~2   .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~2  .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~2 .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~3 .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~4 .EXE
----a-w           184,320 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC54C0~1 .EXE
----a-w           184,320 2008-01-25 18:10:45  C:\Program Files\McAfee.com\Agent\MC5EA7~1 .EXE
----a-w           139,264 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC74AE~1 .EXE
----a-w           139,264 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC74AE~2 .EXE
----a-w           184,320 2008-01-30 00:17:40  C:\Program Files\McAfee.com\Agent\MC88A6~1 .EXE
----a-w           184,320 2008-01-30 02:23:19  C:\Program Files\McAfee.com\Agent\MC88A8~1 .EXE
----a-w           139,264 2008-02-06 21:00:33  C:\Program Files\McAfee.com\Agent\MC9C17~1 .EXE
----a-w           139,264 2008-02-06 21:00:33  C:\Program Files\McAfee.com\Agent\MC9C17~2 .EXE
----a-w           139,264 2008-02-06 21:00:34  C:\Program Files\McAfee.com\Agent\MC9C17~3 .EXE
----a-w           139,264 2008-02-06 21:00:34  C:\Program Files\McAfee.com\Agent\MC9C17~4 .EXE
----a-w           139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~1 .EXE
----a-w           139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~2 .EXE
----a-w           139,264 2008-02-06 21:00:35  C:\Program Files\McAfee.com\Agent\MC9C99~3 .EXE
----a-w           139,264 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MC9C99~4 .EXE
----a-w           184,320 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MCA519~1 .EXE
----a-w           184,320 2008-01-17 23:43:32  C:\Program Files\McAfee.com\Agent\MCA519~2 .EXE
----a-w           139,264 2008-02-06 21:00:36  C:\Program Files\McAfee.com\Agent\MCABBE~1 .EXE
----a-w           139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~2 .EXE
----a-w           139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~3 .EXE
----a-w           139,264 2008-02-06 21:00:37  C:\Program Files\McAfee.com\Agent\MCABBE~4 .EXE
----a-w           245,760 2008-02-05 23:51:48  C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w           184,320 2008-02-06 21:00:38  C:\Program Files\McAfee.com\Agent\MCBD81~1           .EXE
----a-w           184,320 2008-02-06 21:00:38  C:\Program Files\McAfee.com\Agent\MCBD81~1          .EXE
----a-w           184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1         .EXE
----a-w           184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1        .EXE
----a-w           184,320 2008-02-06 21:00:39  C:\Program Files\McAfee.com\Agent\MCBD81~1       .EXE
----a-w           184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1      .EXE
----a-w           184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1     .EXE
----a-w           184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1    .EXE
----a-w           184,320 2008-02-06 21:00:40  C:\Program Files\McAfee.com\Agent\MCBD81~1   .EXE
----a-w           184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~1  .EXE
----a-w           184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~1 .EXE
----a-w           184,320 2008-02-06 21:00:41  C:\Program Files\McAfee.com\Agent\MCBD81~2 .EXE
----a-w           184,320 2008-02-01 21:10:09  C:\Program Files\McAfee.com\Agent\MCBD81~4 .EXE
----a-w           184,320 2008-02-06 21:00:42  C:\Program Files\McAfee.com\Agent\MCC645~1 .EXE
----a-w           184,320 2008-01-17 20:46:22  C:\Program Files\McAfee.com\Agent\MCDB2F~1 .EXE
----a-w           184,320 2008-01-30 18:37:34  C:\Program Files\McAfee.com\Agent\MCF323~1 .EXE
----a-w           139,264 2008-02-06 21:00:42  C:\Program Files\McAfee.com\Agent\mcregwiz .exe
----a-w           139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~1 .EXE
----a-w           139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~2 .EXE
----a-w           139,264 2008-02-06 21:00:43  C:\Program Files\McAfee.com\Agent\MCREGW~3 .EXE
----a-w           139,264 2008-02-06 21:00:44  C:\Program Files\McAfee.com\Agent\MCREGW~4 .EXE
----a-w           184,320 2008-02-06 21:00:44  C:\Program Files\McAfee.com\Agent\mcupdate        .exe
----a-w           184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate       .exe
----a-w           184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate      .exe
----a-w           184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate     .exe
----a-w           184,320 2008-02-06 21:00:45  C:\Program Files\McAfee.com\Agent\mcupdate    .exe
----a-w           184,320 2008-02-06 21:00:46  C:\Program Files\McAfee.com\Agent\mcupdate   .exe
----a-w           184,320 2008-02-06 21:00:46  C:\Program Files\McAfee.com\Agent\mcupdate  .exe
----a-w           184,320 2008-01-30 22:05:03  C:\Program Files\McAfee.com\Agent\mcupdate .exe
----a-w           184,320 2008-01-15 00:39:00  C:\Program Files\McAfee.com\Agent\MCUPDA~1  .EXE
----a-w           184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
----a-w           184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~2 .EXE
----a-w           184,320 2008-02-06 21:00:47  C:\Program Files\McAfee.com\Agent\MCUPDA~3 .EXE
----a-w           225,280 2008-02-05 21:25:54  C:\Program Files\McAfee.com\MPS\mscifapp .exe
----a-w         1,327,104 2008-02-05 21:25:54  C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
----a-w           122,880 2008-02-05 23:45:11  C:\Program Files\McAfee.com\Shared\mcappins .exe
----a-w           139,264 2008-02-05 23:45:39  C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
----a-w           180,224 2008-02-05 23:45:32  C:\Program Files\McAfee.com\VSO\mcvsshld .exe
----a-w         1,694,208 2008-02-06 20:39:56  C:\Program Files\Messenger\msmsgs .exe
----a-w            77,824 2008-02-06 18:48:46  C:\Program Files\QuickTime\qttask                                                           .exe
----a-w            77,824 2008-02-06 00:04:55  C:\Program Files\QuickTime\qttask                                                          .exe
----a-w            77,824 2008-02-06 21:00:57  C:\Program Files\QuickTime\qttask                                                         .exe
----a-w            77,824 2008-02-06 21:00:57  C:\Program Files\QuickTime\qttask                                                        .exe
----a-w            77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask                                                       .exe
----a-w            77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask                                                      .exe
----a-w            77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask                                                     .exe
----a-w            77,824 2008-02-06 21:00:58  C:\Program Files\QuickTime\qttask                                                    .exe
----a-w            77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask                                                   .exe
----a-w            77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask                                                  .exe
----a-w            77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask                                                 .exe
----a-w            77,824 2008-02-06 21:00:59  C:\Program Files\QuickTime\qttask                                                .exe
----a-w            77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask                                               .exe
----a-w            77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask                                              .exe
----a-w            77,824 2008-02-06 21:01:00  C:\Program Files\QuickTime\qttask                                             .exe
----a-w            77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask                                            .exe
----a-w            77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask                                           .exe
----a-w            77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask                                          .exe
----a-w            77,824 2008-02-06 21:01:01  C:\Program Files\QuickTime\qttask                                         .exe
----a-w            77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask                                        .exe
----a-w            77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask                                       .exe
----a-w            77,824 2008-02-06 21:01:02  C:\Program Files\QuickTime\qttask                                      .exe
----a-w            77,824 2008-02-06 21:01:03  C:\Program Files\QuickTime\qttask                                     .exe
----a-w            77,824 2008-02-06 21:01:04  C:\Program Files\QuickTime\qttask                                    .exe
----a-w            77,824 2008-02-06 21:01:04  C:\Program Files\QuickTime\qttask                                   .exe
----a-w            77,824 2008-02-06 21:01:05  C:\Program Files\QuickTime\qttask                                  .exe
----a-w            77,824 2008-02-06 21:01:05  C:\Program Files\QuickTime\qttask                                 .exe
----a-w            77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask                                .exe
----a-w            77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask                               .exe
----a-w            77,824 2008-02-06 21:01:06  C:\Program Files\QuickTime\qttask                              .exe
----a-w            77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask                             .exe
----a-w            77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask                            .exe
----a-w            77,824 2008-02-06 21:01:07  C:\Program Files\QuickTime\qttask                           .exe
----a-w            77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask                          .exe
----a-w            77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask                         .exe
----a-w            77,824 2008-02-06 21:01:08  C:\Program Files\QuickTime\qttask                        .exe
----a-w            77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask                       .exe
----a-w            77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask                      .exe
----a-w            77,824 2008-02-06 21:01:09  C:\Program Files\QuickTime\qttask                     .exe
----a-w            77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask                    .exe
----a-w            77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask                   .exe
----a-w            77,824 2008-02-06 21:01:10  C:\Program Files\QuickTime\qttask                  .exe
----a-w            77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask                 .exe
----a-w            77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask                .exe
----a-w            77,824 2008-02-06 21:01:11  C:\Program Files\QuickTime\qttask               .exe
----a-w            77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask              .exe
----a-w            77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask             .exe
----a-w            77,824 2008-02-06 21:01:12  C:\Program Files\QuickTime\qttask            .exe
----a-w            77,824 2008-02-06 21:01:13  C:\Program Files\QuickTime\qttask           .exe
----a-w            77,824 2008-02-06 21:01:13  C:\Program Files\QuickTime\qttask          .exe
----a-w            77,824 2008-02-06 21:01:14  C:\Program Files\QuickTime\qttask         .exe
----a-w            77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask        .exe
----a-w            77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask       .exe
----a-w            77,824 2008-02-06 21:01:15  C:\Program Files\QuickTime\qttask      .exe
----a-w            77,824 2008-02-06 21:01:16  C:\Program Files\QuickTime\qttask     .exe
----a-w            77,824 2008-02-06 21:01:16  C:\Program Files\QuickTime\qttask    .exe
----a-w            77,824 2008-02-06 21:01:17  C:\Program Files\QuickTime\qttask   .exe
----a-w            77,824 2008-02-06 21:01:17  C:\Program Files\QuickTime\qttask  .exe
----a-w            77,824 2008-02-06 21:01:18  C:\Program Files\QuickTime\qttask .exe
----a-w         4,670,704 2008-01-14 02:33:45  C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
----a-w           158,208 2008-02-07 16:26:39  C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
----a-w            77,824 2008-02-06 20:39:43  C:\WINDOWS\system32\hkcmd .exe
----a-w           114,688 2008-02-06 20:39:43  C:\WINDOWS\system32\igfxpers .exe
----a-w            94,208 2008-02-06 20:39:39  C:\WINDOWS\system32\igfxtray .exe
</pre>



-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C44579A-F22C-4F41-891F-2D605391C1A1}]
C:\WINDOWS\system32\vtstq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e04e704f-02a3-4888-a8f4-a5f050134138}]
C:\WINDOWS\system32\gffatpet.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-11 10:16 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [ ]
"McRegWiz"=" /autorun" []
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"combofix"="C:\WINDOWS\system32\kmd.exe" [2004-08-04 02:00 388608]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnnkj]
pmnnnkj.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\80b61ec1]
--a------ 2008-02-05 13:31 90688 C:\WINDOWS\system32\qtyuagey.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
--a------ 2008-02-07 08:26 158208 C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MskAgentexe]
C:\Program Files\McAfee\MSK\MskAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule11]
C:\Program Files\QdrModule\QdrModule11.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-06 10:48 77824 C:\Program Files\QuickTime\qttask .exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
--a------ 2008-02-06 10:56 36640 C:\Program Files\SiteAdvisor\6172\SiteAdv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)


.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 09:22:39 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-02-06 00:06:12 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-15 07:21:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-02-15 7:23:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-15 15:22:57
.
2008-01-16 23:50:30 --- E O F ---
Go to the top of the page
 
+Quote Post
SifuMike
post Feb 15 2008, 01:20 PM
Post #6


malware expert
******

Group: HJT Team
Posts: 10,743
Joined: 8-January 05
From: Vancouver (not BC) WA (Not DC) USA
Member No.: 9,026



Hi ccoia,

You win the prize for the most infections this week. smile.gif



Click Start, then Run and type Notepad and click OK.
Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the code box below into notepad:

CODE
File::
C:\WINDOWS\system32\yegauytq.ini
C:\WINDOWS\system32\qtyuagey.dll
C:\WINDOWS\system32\pmnnnkj.dll
C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\gffatpet.dll
C:\WINDOWS\system32\qtyuagey.dll
C:\Program Files\QdrModule\QdrModule11.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C44579A-F22C-4F41-891F-2D605391C1A1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e04e704f-02a3-4888-a8f4-a5f050134138}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnnnkj]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\80b61ec1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule11]

RenV::
----a-w         1,404,928 2008-02-06 20:39:47  C:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w           152,144 2008-02-06 20:39:47  C:\Program Files\McAfee\MSK\MskAgent .exe
----a-w            98,304 2008-02-05 21:25:33  C:\Program Files\McAfee\SpamKiller\MskAgent .exe
----a-w           139,264 2008-02-06 21:00:22  C:\Program Files\McAfee.com\Agent\MC01A1~1 .EXE
----a-w           139,264 2008-02-06 21:00:22  C:\Program Files\McAfee.com\Agent\MC01A1~2 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC01A1~3 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC01A1~4 .EXE
----a-w           184,320 2008-02-04 17:50:31  C:\Program Files\McAfee.com\Agent\MC01FF~1 .EXE
----a-w           139,264 2008-02-06 21:00:23  C:\Program Files\McAfee.com\Agent\MC069F~1 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~2 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~3 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC069F~4 .EXE
----a-w           139,264 2008-02-06 21:00:24  C:\Program Files\McAfee.com\Agent\MC099F~1 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~2 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~3 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC099F~4 .EXE
----a-w           139,264 2008-02-06 21:00:25  C:\Program Files\McAfee.com\Agent\MC1E26~1 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~2 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~3 .EXE
----a-w           139,264 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC1E26~4 .EXE
----a-w           184,320 2008-01-23 20:43:03  C:\Program Files\McAfee.com\Agent\MC2398~1      .EXE
----a-w           184,320 2008-02-06 21:00:26  C:\Program Files\McAfee.com\Agent\MC2398~1     .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1    .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1   .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1  .EXE
----a-w           184,320 2008-02-06 21:00:27  C:\Program Files\McAfee.com\Agent\MC2398~1 .EXE
----a-w           184,320 2008-01-21 20:59:07  C:\Program Files\McAfee.com\Agent\MC2398~2 .EXE
----a-w           184,320 2008-01-21 21:08:22  C:\Program Files\McAfee.com\Agent\MC2398~4 .EXE
----a-w           184,320 2008-01-30 20:53:09  C:\Program Files\McAfee.com\Agent\MC3211~1 .EXE
----a-w           184,320 2008-02-06 21:00:28  C:\Program Files\McAfee.com\Agent\MC3882~1 .EXE
----a-w           184,320 2008-02-06 21:00:28  C:\Program Files\McAfee.com\Agent\MC3882~2 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3882~3 .EXE
----a-w           184,320 2008-01-23 00:21:31  C:\Program Files\McAfee.com\Agent\MC3882~4 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3993~1 .EXE
----a-w           184,320 2008-02-05 23:51:47  C:\Program Files\McAfee.com\Agent\MC3993~2 .EXE
----a-w           184,320 2008-02-06 21:00:29  C:\Program Files\McAfee.com\Agent\MC3D5C~1 .EXE
----a-w           184,320 2008-01-17 01:49:25  C:\Program Files\McAfee.com\Agent\MC3D5C~2 .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~1  .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~1 .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~2    .EXE
----a-w           184,320 2008-02-06 21:00:30  C:\Program Files\McAfee.com\Agent\MC49C5~2   .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~2  .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~2 .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~3 .EXE
----a-w           184,320 2008-02-06 21:00:31  C:\Program Files\McAfee.com\Agent\MC49C5~4 .EXE
----a-w           184,320 2008-02-06 21:00:32  C:\Program Files\McAfee.com\Agent\MC54C0~1 .EXE
----a-w           184,320 2008-01-25 18:10:45  C:\Program Files\McAfee.com\Agent\MC5EA7~1 .EXE
----a-w           139,264