Papakid
I did the precleaning as asked
I had Norton installed for about a week and realized what a HEAVY program that was and a resource hog as far as Panda that would have been an online scan
As far as Firewalls the one with Norton there was one in the internet security suite from verizon but that was only active for a week or 2 and discontinued there protection because I bought the etrust internet security suite and have had them for over a year so that is the only firewall running.
here is the combofix log
"Matthew" - 2007-07-18 16:27:05 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\_000005_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\winbl32.dll
((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 )))))))))))))))))))))))))))))))
2007-07-18 05:48 <DIR> d-------- C:\Deckard
2007-07-15 21:05 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-07-12 10:14 630,200 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2007-07-12 10:14 108,392 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2007-07-12 10:12 99,904 --a------ C:\WINDOWS\system32\isafeif.dll
2007-07-12 10:12 75,280 --a------ C:\WINDOWS\system32\isafprod.dll
2007-07-12 10:12 32,528 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-07-12 10:12 26,640 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2007-07-12 10:12 21,648 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-07-12 10:12 21,392 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2007-07-12 10:11 <DIR> d-------- C:\Program Files\CA
2007-07-12 10:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CA
2007-07-12 09:16 <DIR> d-------- C:\Program Files\Add Remove Pro
2007-07-04 08:33 <DIR> d-------- C:\DOCUME~1\Matthew\APPLIC~1\iWin
2007-07-04 07:23 <DIR> d-------- C:\Program Files\Yahoo! Games
2007-06-28 05:01 <DIR> d-------- C:\DOCUME~1\YOURDA~1\APPLIC~1\TrojanHunter
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-16 02:06:00 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k7
2007-07-16 02:06:00 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k6
2007-07-16 02:06:00 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k5
2007-07-16 02:06:00 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k4
2007-07-16 02:06:00 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k3
2007-07-16 02:06:00 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k2
2007-07-16 02:06:00 64 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k1
2007-07-16 02:06:00 51,966 ----a-w C:\WINDOWS\system32\drivers\kmxcfg.u2k0
2007-07-06 00:57:10 -------- d-----w C:\DOCUME~1\Matthew\APPLIC~1\Yahoo!
2007-07-01 18:14:24 -------- d-----w C:\Program Files\Yahoo!
2007-06-17 05:11:58 51,200 ----a-w C:\WINDOWS\nircmd.exe
2007-06-11 17:55:30 -------- d-----w C:\DOCUME~1\Matthew\APPLIC~1\TrojanHunter
2007-06-04 23:19:21 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-05-31 18:47:06 114,448 ----a-w C:\WINDOWS\system32\drivers\KmxFw.sys
2007-05-31 18:47:04 92,432 ----a-w C:\WINDOWS\system32\drivers\KmxStart.sys
2007-05-31 18:47:04 256,784 ----a-w C:\WINDOWS\system32\UmxSbxw.dll
2007-05-31 18:47:04 126,224 ----a-w C:\WINDOWS\system32\drivers\KmxCF.sys
2007-05-31 18:47:02 117,520 ----a-w C:\WINDOWS\system32\UmxSbxExw.dll
2007-05-28 20:36:44 -------- d-----w C:\Program Files\Common Files\Scanner
2007-05-18 19:30:00 89,096 ----a-w C:\WINDOWS\system32\drivers\KmxCfg.sys
2007-05-18 19:30:00 63,496 ----a-w C:\WINDOWS\system32\drivers\KmxSbx.sys
2007-05-18 19:30:00 61,960 ----a-w C:\WINDOWS\system32\drivers\KmxAgent.sys
2007-05-18 19:30:00 45,064 ----a-w C:\WINDOWS\system32\drivers\KmxFile.sys
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-02 23:48:11 95,760 ----a-w C:\avshlext.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 16:36:06 79,424 ----a-w C:\WINDOWS\system32\vetredir.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
2007-05-30 16:18 808472 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B9F5787-88A5-4945-90E7-C4B18563BC5E}]
2006-11-25 20:19 705024 --a------ C:\Program Files\KeyScrambler\KeyScramblerIE.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 00:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-07-12 04:00 501136 --a------ C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"A Verizon App"="C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE" [2005-05-23 16:20]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-06-12 12:18]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-06-12 12:32]
"cafwc"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2007-06-01 14:14]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2007-06-01 14:14]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2007-06-01 14:07]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.17.0\QOELoader.exe" [2007-07-12 14:13]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-07-02 18:40]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
UmxWnp.Dll --a------ 2006-11-17 22:30 79368 C:\WINDOWS\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Monitor.lnk
backup=C:\WINDOWS\pss\Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer4_in_1]
"C:\Program Files\Lexmark 4200 Series\Fax\fm3032.exe" /s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 4200 Series]
"C:\Program Files\Lexmark 4200 Series\lxbmbmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
"C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\type32]
"C:\Program Files\Microsoft IntelliType Pro\type32.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ymetray]
"C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
*Newly Created Service* - AVGARCLN
*Newly Created Service* - AVG_ANTI-ROOTKIT
Contents of the 'Scheduled Tasks' folder
2007-07-12 15:11:57 C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Matthew at 10 11 AM.job
2007-07-18 02:41:21 C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Matthew at 8 39 PM.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-18 16:32:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-18 16:36:36
C:\ComboFix-quarantined-files.txt ... 2007-07-18 16:36
C:\ComboFix2.txt ... 2007-05-11 00:12
C:\ComboFix3.txt ... 2007-05-10 10:31
--- E O F ---
Kaspersky just simply would not work no matter what I did
Here is the RegSearch log
Windows Registry Editor Version 5.00
; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.5.0
; Results at 7/18/2007 5:07:46 PM for strings:
; 'ticldxtw.fjj'
; 'co_mon.sys'
; 'uninstall '
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{60F6E467-4DEF-11d2-B2D9-00C04F8EEC8C}]
@="Uninstall Prop Bag"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67cf8cbd-e5c0-44f7-9de5-e1d599d626d8}]
@="OS Uninstall Disk Cleaner"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Multimedia\Components\Installed\setup_wmsetsdk10]
"DESCRIPTION"="Windows Media Setup provides AutoUpdate, install, and uninstall capabilities for Windows Media Player. This component must be installed for the software to function."
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Multimedia\Components\Installed\setup_WMSETUP10]
"DESCRIPTION"="Windows Media Setup provides AutoUpdate, install, and uninstall capabilities for Windows Media Player. This component must be installed for the software to function."
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\ath:7.0\UninstCall0]
@="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\faus3270.dll\" OnUninstall "
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\Free:6.0\File11]
@="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Real\\RealPlayer\\Uninstall RealPlayer.lnk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\MSG:7.0\UninstCall0]
@="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnms3270.dll\" OnUninstall "
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\PlayerUninstBegin:6.0\DisplayName]
@="RealPlayer Uninstall Component 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\PlayerUninstEnd:6.0\DisplayName]
@="RealPlayer Uninstall Component 2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\recordengine:1.0\UninstCall0]
@="\"C:\\Program Files\\Common Files\\Real\\RCAPlugins\\locd3210.dll\" OnUninstall "
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\rfxinst:7.0\UninstCall0]
@="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\nprfxins.dll\" EX_Uninstall NoParam"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\RNAdmin:0.1\UninstCall0]
@="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\rnad3201.dll\" OnUninstall "
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8E62F83D-3F34-482A-8D51-B695DA69A995}\1.0]
@="VZGUninstall 1.0 Type Library"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IEHomePageInfo]
"BackupFileName"="C:\\Program Files\\Uninstall Information\\IEHomePageInfo\\IEHomePageInfo.DAT"
"BackupPath"="C:\\Program Files\\Uninstall Information\\IEHomePageInfo"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Microsoft .NET Framework 2.0\KB917283]
"UninstallCommand"="C:\\WINDOWS\\system32\\msiexec.exe /promptrestart /uninstall {967B098A-042D-4367-BAC9-8BC11684174F} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Microsoft .NET Framework 2.0\KB922770]
"UninstallCommand"="C:\\WINDOWS\\system32\\msiexec.exe /promptrestart /uninstall {0E92DD42-76F5-4EF2-B381-F9C1D72BE23D} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Microsoft .NET Framework 2.0\KB928365]
"UninstallCommand"="C:\\WINDOWS\\system32\\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Uninstall Backup Image]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches\Uninstall Backup Image]
"Description"="These files are needed if you want to uninstall this version of Windows and return back to your previous operating system."
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB928365.T1_1ToU569_1]
"UninstallString"="C:\\WINDOWS\\system32\\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\2.0.0.4 (en-US)\Uninstall]
"Uninstall Log Folder"="C:\\Program Files\\Mozilla Firefox\\uninstall"
[HKEY_LOCAL_MACHINE\SOFTWARE\Yahoo\MailTo]
"UninstallSuccessMsg"="Yahoo! Mail uninstall was completed successfully."
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CO_Mon]
; Contents of value:
; \??\C:\WINDOWS\system32\Drivers\CO_Mon.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,43,00,4f,00,5f,00,\
4d,00,6f,00,6e,00,2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TICLDXTW]
; Contents of value:
; \??\C:\WINDOWS\system32\ticldxtw.fjj
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,74,00,69,00,63,00,6c,00,64,00,78,00,74,00,77,00,2e,00,66,00,6a,00,\
6a,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\CO_Mon]
; Contents of value:
; \??\C:\WINDOWS\system32\Drivers\CO_Mon.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,43,00,4f,00,5f,00,\
4d,00,6f,00,6e,00,2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TICLDXTW]
; Contents of value:
; \??\C:\WINDOWS\system32\ticldxtw.fjj
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,74,00,69,00,63,00,6c,00,64,00,78,00,74,00,77,00,2e,00,66,00,6a,00,\
6a,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\CO_Mon]
; Contents of value:
; \??\C:\WINDOWS\system32\Drivers\CO_Mon.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,43,00,4f,00,5f,00,\
4d,00,6f,00,6e,00,2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\TICLDXTW]
; Contents of value:
; \??\C:\WINDOWS\system32\ticldxtw.fjj
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,74,00,69,00,63,00,6c,00,64,00,78,00,74,00,77,00,2e,00,66,00,6a,00,\
6a,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CO_Mon]
; Contents of value:
; \??\C:\WINDOWS\system32\Drivers\CO_Mon.sys
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,44,00,72,00,69,00,76,00,65,00,72,00,73,00,5c,00,43,00,4f,00,5f,00,\
4d,00,6f,00,6e,00,2e,00,73,00,79,00,73,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TICLDXTW]
; Contents of value:
; \??\C:\WINDOWS\system32\ticldxtw.fjj
"ImagePath"=hex(2):5c,00,3f,00,3f,00,5c,00,43,00,3a,00,5c,00,57,00,49,00,4e,00,\
44,00,4f,00,57,00,53,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,74,00,69,00,63,00,6c,00,64,00,78,00,74,00,77,00,2e,00,66,00,6a,00,\
6a,00,00,00
; End Of The Log...
Will post back with a new HJT log
D_N_M