Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Horrible Internet Browser Problem


  • This topic is locked This topic is locked
11 replies to this topic

#1 pirajacinto

pirajacinto

  • Members
  • 98 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 16 September 2007 - 04:47 PM

I'm having several problems with my computer for the last few days (or even a whole week now). When I start the computer, after putting in the password it would take a long time to load and eventaully it would, however it only shows the desktop wallpaper and even then maybe 3-4mins of wait until everyhing pops up and starts to completely load. Then, my "Ad-Watch SE Professional" would load and while i do get some usual errors, lastly I've been getting about 20 Mal-ware aler that are harmful to my computer.

To make matters worse, whenever I would open a new link in my INternet Explorer the broswer would often freeze for 30secs and then a "Windows Explorer has encountered a problem and needs to close". After forcing to go thought that, that started to happen in my folders of my computer too. In fact, at one point it was so bad that when I opened one folder and stayed there for at least a min, it would freeze up like the Internet Explorer error and then get the problem error again. Each time I get those errors the whole desktop reloads. Please, I would really like some help with this horrible problem.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:47:00 PM, on 9/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ps2.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\HP_Administrator\Local Settings\Temp\thinksnet.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173486144703
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\bonfqfgo.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 9496 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:29 AM

Posted 17 September 2007 - 05:01 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum pirajacinto :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.


*NOTE*
If you have previously downloaded ComboFix,please delete that version and download it again from below.

Download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 pirajacinto

pirajacinto
  • Topic Starter

  • Members
  • 98 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 17 September 2007 - 06:11 PM

Hello Richie! I'm glad to have you helping me! I hope we can fix my computer together.

ComboFix 07-09-18 - "HP_Administrator" 2007-09-17 15:07:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.556 [GMT -7:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Avenger
C:\DOCUME~1\HP_ADM~1\APPLIC~1\macromedia\Flash Player\#SharedObjects\AQ49PGH7\www.broadcaster.com
C:\DOCUME~1\HP_ADM~1\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\HP_ADM~1\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\DOCUME~1\HP_ADM~1\APPLIC~1\PPPATC~1
C:\DOCUME~1\HP_ADM~1\APPLIC~1\PPPATC~1\j?vaw.exe
C:\DOCUME~1\HP_ADM~1\STARTM~1\Programs\Outerinfo
C:\DOCUME~1\HP_ADM~1\STARTM~1\Programs\Outerinfo\Terms.lnk
C:\DOCUME~1\HP_ADM~1\STARTM~1\Programs\Outerinfo\Uninstall.lnk
C:\DOCUME~1\HP_ADM~1\STARTM~1\Programs\Startup.\TA_Start.lnk
C:\DOCUME~1\HP_ADM~1\STARTM~1\Programs\Startup\ta_start.lnk
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\svhost
C:\Program Files\ymbols~1
C:\Program Files\ymbols~1\?ymbols\
C:\Program Files\ymbols~1\spoolsv.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\cookies.ini
C:\WINDOWS\DOWNLO~1\UWA7P_0001_N91M0809NetInstaller.exe
C:\WINDOWS\regedit.com
C:\WINDOWS\svhost.exe
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\acjfbfvb.dll
C:\WINDOWS\system32\aecxwaqr.dll
C:\WINDOWS\system32\afrjkxbf.exe
C:\WINDOWS\system32\agvfbxfo.ini
C:\WINDOWS\system32\ahpptcmw.ini
C:\WINDOWS\system32\ahrnhimu.exe
C:\WINDOWS\system32\ahycdvvw.dll
C:\WINDOWS\system32\akcmyrcn.exe
C:\WINDOWS\system32\aqqgsmbf.dll
C:\WINDOWS\system32\asvwpuss.dll
C:\WINDOWS\system32\atofhbux.exe
C:\WINDOWS\system32\auwbbuhx.exe
C:\WINDOWS\system32\avxkdqdr.dll
C:\WINDOWS\system32\axadmikb.ini
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\bblgwqil.dll
C:\WINDOWS\system32\bbxjlxld.ini
C:\WINDOWS\system32\bhmullje.ini
C:\WINDOWS\system32\bkimdaxa.dll
C:\WINDOWS\system32\blckvwli.ini
C:\WINDOWS\system32\bobkmcxa.exe
C:\WINDOWS\system32\bodjqini.exe
C:\WINDOWS\system32\boghynfb.exe
C:\WINDOWS\system32\bonfqfgo.exe
C:\WINDOWS\system32\bqdrpsvr.dll
C:\WINDOWS\system32\bqmyevtj.dll
C:\WINDOWS\system32\bslwphyh.ini
C:\WINDOWS\system32\bvfbfjca.ini
C:\WINDOWS\system32\bwxcpcfe.exe
C:\WINDOWS\system32\bxlfgyyq.exe
C:\WINDOWS\system32\cbdqvcxs.dll
C:\WINDOWS\system32\cbkayudv.dll
C:\WINDOWS\system32\ccklxqua.dll
C:\WINDOWS\system32\cjffxnqh.exe
C:\WINDOWS\system32\ckvhivtq.dll
C:\WINDOWS\system32\cmvosnjy.ini
C:\WINDOWS\system32\cnlpkcbl.exe
C:\WINDOWS\system32\cntqavpr.exe
C:\WINDOWS\system32\cpqgeosv.dll
C:\WINDOWS\system32\cqyyugpb.exe
C:\WINDOWS\system32\ctyawnjo.ini
C:\WINDOWS\system32\cusjgabi.ini
C:\WINDOWS\system32\cvbnmovc.exe
C:\WINDOWS\system32\cxponeqo.ini
C:\WINDOWS\system32\cygpxpuh.ini
C:\WINDOWS\system32\dbctwffs.exe
C:\WINDOWS\system32\ddcbyvw.dll
C:\WINDOWS\system32\dejdmjmk.ini
C:\WINDOWS\system32\dhjcveth.exe
C:\WINDOWS\system32\djuswunw.dll
C:\WINDOWS\system32\dleojwgd.exe
C:\WINDOWS\system32\dlxljxbb.dll
C:\WINDOWS\system32\dmqmaesy.exe
C:\WINDOWS\system32\dnlecosj.dll
C:\WINDOWS\system32\dpchggjp.ini
C:\WINDOWS\system32\dsaisydk.exe
C:\WINDOWS\system32\dstrtfep.dll
C:\WINDOWS\system32\dtgwsnqf.ini
C:\WINDOWS\system32\duesxnrm.exe
C:\WINDOWS\system32\dvepobvx.exe
C:\WINDOWS\system32\dvwnrydu.exe
C:\WINDOWS\system32\dwdgwxeh.exe
C:\WINDOWS\system32\dylspuik.ini
C:\WINDOWS\system32\dynrgitg.dll
C:\WINDOWS\system32\edxsvjnh.dll
C:\WINDOWS\system32\efhkj.bak1
C:\WINDOWS\system32\efhkj.bak2
C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.ini2
C:\WINDOWS\system32\efhkj.tmp
C:\WINDOWS\system32\ehoqrnkf.ini
C:\WINDOWS\system32\ehtgdkxl.ini
C:\WINDOWS\system32\ejllumhb.dll
C:\WINDOWS\system32\ekthtomq.ini
C:\WINDOWS\system32\elhnrksd.exe
C:\WINDOWS\system32\eliqcmys.ini
C:\WINDOWS\system32\emaojqth.dll
C:\WINDOWS\system32\emlhljbv.dll
C:\WINDOWS\system32\epeaqhhx.exe
C:\WINDOWS\system32\epiddhmm.dll
C:\WINDOWS\system32\epvkqlpq.exe
C:\WINDOWS\system32\estsouuy.exe
C:\WINDOWS\system32\eunylvjd.exe
C:\WINDOWS\system32\evxaoenp.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\f10WtR\f10WtR1099.exe
C:\WINDOWS\system32\fbmsgqqa.ini
C:\WINDOWS\system32\fbvkyprx.exe
C:\WINDOWS\system32\fchuqjaq.exe
C:\WINDOWS\system32\fcqhkdwm.ini
C:\WINDOWS\system32\fikwykif.exe
C:\WINDOWS\system32\fjragkmq.dll
C:\WINDOWS\system32\fknrqohe.dll
C:\WINDOWS\system32\fmyfbiov.ini
C:\WINDOWS\system32\fnlnpnhq.dll
C:\WINDOWS\system32\foycjypw.exe
C:\WINDOWS\system32\fqmeynmo.dll
C:\WINDOWS\system32\fqnswgtd.dll
C:\WINDOWS\system32\geadhsln.exe
C:\WINDOWS\system32\gfdhrfsl.exe
C:\WINDOWS\system32\ghcvajtw.ini
C:\WINDOWS\system32\ghsuhcbx.dll
C:\WINDOWS\system32\ghyhqprw.exe
C:\WINDOWS\system32\gifcfxam.exe
C:\WINDOWS\system32\giwdbhsv.dll
C:\WINDOWS\system32\gklbqmum.exe
C:\WINDOWS\system32\glemcdvv.exe
C:\WINDOWS\system32\gmprgcxe.exe
C:\WINDOWS\system32\gmxmutnn.ini
C:\WINDOWS\system32\goigcctx.exe
C:\WINDOWS\system32\gopcgltq.ini
C:\WINDOWS\system32\gtigrnyd.ini
C:\WINDOWS\system32\guhxfuui.dll
C:\WINDOWS\system32\gvtyobnt.dll
C:\WINDOWS\system32\hcxecxje.exe
C:\WINDOWS\system32\hdmwbbhk.exe
C:\WINDOWS\system32\hggdday.dll
C:\WINDOWS\system32\hjudufus.exe
C:\WINDOWS\system32\hjunhpmw.exe
C:\WINDOWS\system32\hkvcuvpc.exe
C:\WINDOWS\system32\hmokpgxl.exe
C:\WINDOWS\system32\hmyktrbh.exe
C:\WINDOWS\system32\hnjvsxde.ini
C:\WINDOWS\system32\hoilxibm.dll
C:\WINDOWS\system32\hppccjei.exe
C:\WINDOWS\system32\hpxyivks.dll
C:\WINDOWS\system32\hssexecv.dll
C:\WINDOWS\system32\htorhamq.dll
C:\WINDOWS\system32\htqjoame.ini
C:\WINDOWS\system32\htrvisjm.dll
C:\WINDOWS\system32\hupxpgyc.dll
C:\WINDOWS\system32\hvlmnylq.exe
C:\WINDOWS\system32\hvmmukdw.exe
C:\WINDOWS\system32\hyhpwlsb.dll
C:\WINDOWS\system32\hyrgrebx.dll
C:\WINDOWS\system32\ibagjsuc.dll
C:\WINDOWS\system32\iboyvggp.exe
C:\WINDOWS\system32\ihbdegqd.exe
C:\WINDOWS\system32\iiwrfktm.exe
C:\WINDOWS\system32\iixjohjt.exe
C:\WINDOWS\system32\ildivliy.dll
C:\WINDOWS\system32\ilgwplaw.dll
C:\WINDOWS\system32\ilwvkclb.dll
C:\WINDOWS\system32\imgijlcp.exe
C:\WINDOWS\system32\iotvmyst.exe
C:\WINDOWS\system32\iqnhmqcv.exe
C:\WINDOWS\system32\itlaosid.exe
C:\WINDOWS\system32\iuufxhug.ini
C:\WINDOWS\system32\ixwoduaf.exe
C:\WINDOWS\system32\jelfhpht.ini
C:\WINDOWS\system32\jflxjghw.dll
C:\WINDOWS\system32\jgmcdeqw.dll
C:\WINDOWS\system32\jhnxxfxl.exe
C:\WINDOWS\system32\jjgujsve.dll
C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\jlekvmdf.exe
C:\WINDOWS\system32\jlkacfxs.exe
C:\WINDOWS\system32\joapaiyw.dll
C:\WINDOWS\system32\joufjesr.exe
C:\WINDOWS\system32\jpujahjd.exe
C:\WINDOWS\system32\jrfqjfiu.ini
C:\WINDOWS\system32\jsocelnd.ini
C:\WINDOWS\system32\jtveymqb.ini
C:\WINDOWS\system32\jvfxxhnp.exe
C:\WINDOWS\system32\kafkbngt.ini
C:\WINDOWS\system32\kbkfhbvr.dll
C:\WINDOWS\system32\kcktstae.exe
C:\WINDOWS\system32\kdafjnns.exe
C:\WINDOWS\system32\kdaniahe.exe
C:\WINDOWS\system32\kfgxyvkt.ini
C:\WINDOWS\system32\kiupslyd.dll
C:\WINDOWS\system32\kjxmstus.exe
C:\WINDOWS\system32\kmjmdjed.dll
C:\WINDOWS\system32\knopqarx.exe
C:\WINDOWS\system32\krtwaesk.dll
C:\WINDOWS\system32\kxfmugva.dll
C:\WINDOWS\system32\kyxnixcv.ini
C:\WINDOWS\system32\legyunix.dll
C:\WINDOWS\system32\lejedwib.exe
C:\WINDOWS\system32\lgliqvpx.exe
C:\WINDOWS\system32\lhpyuadu.exe
C:\WINDOWS\system32\liavpeks.dll
C:\WINDOWS\system32\lihyuhhi.exe
C:\WINDOWS\system32\liqhqsml.ini
C:\WINDOWS\system32\liqwglbb.ini
C:\WINDOWS\system32\llikopvr.ini
C:\WINDOWS\system32\llnmp.ini
C:\WINDOWS\system32\llwmbqpk.exe
C:\WINDOWS\system32\lmsqhqil.dll
C:\WINDOWS\system32\lnewlbky.dll
C:\WINDOWS\system32\lngcnolb.exe
C:\WINDOWS\system32\lpcdlmtu.dll
C:\WINDOWS\system32\lpekdpbx.dll
C:\WINDOWS\system32\lqpdjtme.exe
C:\WINDOWS\system32\lrowgvkt.exe
C:\WINDOWS\system32\lsqmqdip.dll
C:\WINDOWS\system32\ltoccqwe.dll
C:\WINDOWS\system32\lvvoglml.exe
C:\WINDOWS\system32\lxkdgthe.dll
C:\WINDOWS\system32\mabudjib.exe
C:\WINDOWS\system32\mbixlioh.ini
C:\WINDOWS\system32\mhxlxsei.dll
C:\WINDOWS\system32\mjfutebi.exe
C:\WINDOWS\system32\mlilcuek.exe
C:\WINDOWS\system32\mllwbcfy.dll
C:\WINDOWS\system32\mmhddipe.ini
C:\WINDOWS\system32\mnyicbsi.exe
C:\WINDOWS\system32\mpgyhuow.ini
C:\WINDOWS\system32\mrnefpmt.ini
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\msylelap.dll
C:\WINDOWS\system32\mtpiuvax.exe
C:\WINDOWS\system32\mtxatfmr.dll
C:\WINDOWS\system32\mwdkhqcf.dll
C:\WINDOWS\system32\mxnqdyka.exe
C:\WINDOWS\system32\nbgsjmdm.exe
C:\WINDOWS\system32\ncpkovpn.exe
C:\WINDOWS\system32\ncuimagu.exe
C:\WINDOWS\system32\ndfarxhf.dll
C:\WINDOWS\system32\ndttsixa.exe
C:\WINDOWS\system32\nemfxqih.exe
C:\WINDOWS\system32\nglfqnxt.exe
C:\WINDOWS\system32\nhbdpkfi.exe
C:\WINDOWS\system32\njsbnrdb.exe
C:\WINDOWS\system32\nlmkfhtl.exe
C:\WINDOWS\system32\nntumxmg.dll
C:\WINDOWS\system32\nofrratw.exe
C:\WINDOWS\system32\npshpvrr.exe
C:\WINDOWS\system32\nqqoygcu.exe
C:\WINDOWS\system32\nqwvcrrw.dll
C:\WINDOWS\system32\nroqbdal.exe
C:\WINDOWS\system32\nsvmyihu.exe
C:\WINDOWS\system32\nuuxnkyo.dll
C:\WINDOWS\system32\obshmqkg.exe
C:\WINDOWS\system32\oexcefng.exe
C:\WINDOWS\system32\ofktrbua.dll
C:\WINDOWS\system32\ofxbfvga.dll
C:\WINDOWS\system32\oiuogwxw.dll
C:\WINDOWS\system32\ojhkigbf.exe
C:\WINDOWS\system32\ojnwaytc.dll
C:\WINDOWS\system32\olocudtq.exe
C:\WINDOWS\system32\omhqdpts.dll
C:\WINDOWS\system32\oofkoufa.dll
C:\WINDOWS\system32\oqenopxc.dll
C:\WINDOWS\system32\oqigdmhm.exe
C:\WINDOWS\system32\osvyiqlh.exe
C:\WINDOWS\system32\ovbiksxn.exe
C:\WINDOWS\system32\owbypkmj.exe
C:\WINDOWS\system32\oxayjegt.dll
C:\WINDOWS\system32\oyknxuun.ini
C:\WINDOWS\system32\pabuphos.exe
C:\WINDOWS\system32\pcjedngy.exe
C:\WINDOWS\system32\peftrtsd.ini
C:\WINDOWS\system32\pegwiwvx.ini
C:\WINDOWS\system32\pftcptgm.dll
C:\WINDOWS\system32\pinvbntx.exe
C:\WINDOWS\system32\pitjapmu.ini
C:\WINDOWS\system32\pivuqiiq.ini
C:\WINDOWS\system32\pjgghcpd.dll
C:\WINDOWS\system32\pjirujvt.ini
C:\WINDOWS\system32\popatcup.dll
C:\WINDOWS\system32\puctapop.ini
C:\WINDOWS\system32\qagdjtil.exe
C:\WINDOWS\system32\qaigiywu.ini
C:\WINDOWS\system32\qaokmurv.ini
C:\WINDOWS\system32\qdeoskoq.dll
C:\WINDOWS\system32\qepvthiy.ini
C:\WINDOWS\system32\qfeqifef.exe
C:\WINDOWS\system32\qfnuenro.dll
C:\WINDOWS\system32\qfwbdfwf.exe
C:\WINDOWS\system32\qhcakkpc.exe
C:\WINDOWS\system32\qhiodves.exe
C:\WINDOWS\system32\qhnpnlnf.ini
C:\WINDOWS\system32\qiiquvip.dll
C:\WINDOWS\system32\qimtwwos.exe
C:\WINDOWS\system32\qkncfawh.dll
C:\WINDOWS\system32\qmahroth.ini
C:\WINDOWS\system32\qmkgarjf.ini
C:\WINDOWS\system32\qmothtke.dll
C:\WINDOWS\system32\qncyvsnu.exe
C:\WINDOWS\system32\qojccrbh.dll
C:\WINDOWS\system32\qoksoedq.ini
C:\WINDOWS\system32\qpcftswx.dll
C:\WINDOWS\system32\qqrsjpam.exe
C:\WINDOWS\system32\qqwiajwb.exe
C:\WINDOWS\system32\qtlgcpog.dll
C:\WINDOWS\system32\qvaycnbw.ini
C:\WINDOWS\system32\rbrbrtxw.exe
C:\WINDOWS\system32\rcrgptbr.exe
C:\WINDOWS\system32\rdgninjx.exe
C:\WINDOWS\system32\rdowkjyc.exe
C:\WINDOWS\system32\rdqdkxva.ini
C:\WINDOWS\system32\rgknevvw.ini
C:\WINDOWS\system32\rglefpqp.dll
C:\WINDOWS\system32\rhswrkhh.exe
C:\WINDOWS\system32\riilgsft.exe
C:\WINDOWS\system32\rklxawxv.exe
C:\WINDOWS\system32\rmftaxtm.ini
C:\WINDOWS\system32\rpexvulb.exe
C:\WINDOWS\system32\rpqvpfwy.exe
C:\WINDOWS\system32\rptmuqui.exe
C:\WINDOWS\system32\rqawxcea.ini
C:\WINDOWS\system32\rrtvjkqd.dll
C:\WINDOWS\system32\rsstwbsu.ini
C:\WINDOWS\system32\rvpokill.dll
C:\WINDOWS\system32\rvsprdqb.ini
C:\WINDOWS\system32\ryqwrvbs.dll
C:\WINDOWS\system32\sampfhaq.exe
C:\WINDOWS\system32\sbvrwqyr.ini
C:\WINDOWS\system32\seecqyqs.dll
C:\WINDOWS\system32\seqmkrru.dll
C:\WINDOWS\system32\sigphuuy.dll
C:\WINDOWS\system32\sjpyqbvv.exe
C:\WINDOWS\system32\skepvail.ini
C:\WINDOWS\system32\skkfygvx.exe
C:\WINDOWS\system32\sktfdqee.dll
C:\WINDOWS\system32\skviyxph.ini
C:\WINDOWS\system32\skviyxph.tmp
C:\WINDOWS\system32\slmkggqk.exe
C:\WINDOWS\system32\slvwjrbt.dll
C:\WINDOWS\system32\smfyanjy.dll
C:\WINDOWS\system32\sqiahsrq.exe
C:\WINDOWS\system32\sqyqcees.ini
C:\WINDOWS\system32\srrxhxcd.exe
C:\WINDOWS\system32\ssupwvsa.ini
C:\WINDOWS\system32\stpdqhmo.ini
C:\WINDOWS\system32\svfqxqiv.dll
C:\WINDOWS\system32\swhpfuwf.exe
C:\WINDOWS\system32\swoocvbs.exe
C:\WINDOWS\system32\sxvqqjvw.ini
C:\WINDOWS\system32\symcqile.dll
C:\WINDOWS\system32\sypkxndh.exe
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\tbrjwvls.ini
C:\WINDOWS\system32\tgejyaxo.ini
C:\WINDOWS\system32\tgnbkfak.dll
C:\WINDOWS\system32\thphflej.dll
C:\WINDOWS\system32\tibjnnfv.exe
C:\WINDOWS\system32\tkdijvmw.exe
C:\WINDOWS\system32\tkricuia.exe
C:\WINDOWS\system32\tkvhrery.exe
C:\WINDOWS\system32\tkvyxgfk.dll
C:\WINDOWS\system32\tlhlyssy.ini
C:\WINDOWS\system32\tmpfenrm.dll
C:\WINDOWS\system32\tpxcergp.exe
C:\WINDOWS\system32\tvegkknc.exe
C:\WINDOWS\system32\tvjurijp.dll
C:\WINDOWS\system32\tvthcpqk.exe
C:\WINDOWS\system32\ualkeivm.exe
C:\WINDOWS\system32\ubqnjfjm.exe
C:\WINDOWS\system32\uhgqyjkf.dll
C:\WINDOWS\system32\uhjdrfqu.exe
C:\WINDOWS\system32\uifjqfrj.dll
C:\WINDOWS\system32\uijgfqwr.exe
C:\WINDOWS\system32\umpajtip.dll
C:\WINDOWS\system32\uqudarfn.exe
C:\WINDOWS\system32\urdcowim.exe
C:\WINDOWS\system32\urrkmqes.ini
C:\WINDOWS\system32\usbwtssr.dll
C:\WINDOWS\system32\utmldcpl.ini
C:\WINDOWS\system32\utmldcpl.tmp
C:\WINDOWS\system32\utoslqfv.ini
C:\WINDOWS\system32\uwyigiaq.dll
C:\WINDOWS\system32\vajoaeyh.exe
C:\WINDOWS\system32\vamvivtw.exe
C:\WINDOWS\system32\vcexessh.ini
C:\WINDOWS\system32\vcxinxyk.dll
C:\WINDOWS\system32\vduyakbc.ini
C:\WINDOWS\system32\vebryqbo.exe
C:\WINDOWS\system32\vesaxnbi.exe
C:\WINDOWS\system32\vfqlsotu.dll
C:\WINDOWS\system32\vgpbhkqt.exe
C:\WINDOWS\system32\vinaulku.exe
C:\WINDOWS\system32\viqxqfvs.ini
C:\WINDOWS\system32\voibfymf.dll
C:\WINDOWS\system32\vpybjdfy.dll
C:\WINDOWS\system32\vrqnmtte.dll
C:\WINDOWS\system32\vrueqcyb.dll
C:\WINDOWS\system32\vrumkoaq.dll
C:\WINDOWS\system32\vrwcidxl.exe
C:\WINDOWS\system32\vshbdwig.ini
C:\WINDOWS\system32\vsoegqpc.ini
C:\WINDOWS\system32\wbncyavq.dll
C:\WINDOWS\system32\wbsmuseu.exe
C:\WINDOWS\system32\wbubykwy.exe
C:\WINDOWS\system32\wejlyndr.exe
C:\WINDOWS\system32\wgntpvym.dll
C:\WINDOWS\system32\whgjxlfj.ini
C:\WINDOWS\system32\whjfcwts.exe
C:\WINDOWS\system32\wmctppha.dll
C:\WINDOWS\system32\wnuwsujd.ini
C:\WINDOWS\system32\wouhygpm.dll
C:\WINDOWS\system32\wpejpwkv.exe
C:\WINDOWS\system32\wqedcmgj.ini
C:\WINDOWS\system32\wrrcvwqn.ini
C:\WINDOWS\system32\wtjavchg.dll
C:\WINDOWS\system32\wuyuggto.exe
C:\WINDOWS\system32\wvjqqvxs.dll
C:\WINDOWS\system32\wvuusqq.dll
C:\WINDOWS\system32\wvvdcyha.ini
C:\WINDOWS\system32\wvvenkgr.dll
C:\WINDOWS\system32\X1
C:\WINDOWS\system32\X1\x22011.exe
C:\WINDOWS\system32\xaguciiw.exe
C:\WINDOWS\system32\xbchushg.ini
C:\WINDOWS\system32\xbergryh.ini
C:\WINDOWS\system32\xhftqaeg.dll
C:\WINDOWS\system32\xinuygel.ini
C:\WINDOWS\system32\xkbhculy.dll
C:\WINDOWS\system32\xmiihxcg.exe
C:\WINDOWS\system32\xnlpjjxh.exe
C:\WINDOWS\system32\xnwyergf.exe
C:\WINDOWS\system32\xtbgkcse.exe
C:\WINDOWS\system32\xtdvbjae.exe
C:\WINDOWS\system32\xunlarch.exe
C:\WINDOWS\system32\xvwiwgep.dll
C:\WINDOWS\system32\xwgsrfli.exe
C:\WINDOWS\system32\xwstfcpq.ini
C:\WINDOWS\system32\yakgucna.exe
C:\WINDOWS\system32\yfcbwllm.ini
C:\WINDOWS\system32\yfowhrqv.exe
C:\WINDOWS\system32\ygnmnr.dll
C:\WINDOWS\system32\ygyocpav.exe
C:\WINDOWS\system32\yihtvpeq.dll
C:\WINDOWS\system32\yjnayfms.ini
C:\WINDOWS\system32\yjnsovmc.dll
C:\WINDOWS\system32\ykblwenl.ini
C:\WINDOWS\system32\yluchbkx.ini
C:\WINDOWS\system32\ysavlhck.exe
C:\WINDOWS\system32\yssylhlt.dll
C:\WINDOWS\system32\yuuhpgis.ini
C:\WINDOWS\system32\yvmnwujb.exe
C:\WINDOWS\system32\ywagdmqh.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-08-18 to 2007-09-18 )))))))))))))))))))))))))))))))
.

2007-09-02 11:53 1,885,368 --ahsc--- C:\WINDOWS\system32\jjjlm.bak1
2007-09-01 10:43 1,885,066 --ahsc--- C:\WINDOWS\system32\mpqss.bak1
2007-08-30 11:29 1,912,232 --ahsc--- C:\WINDOWS\system32\llnmp.bak1
2007-08-29 16:57 6,448 --ahsc--- C:\WINDOWS\system32\cbadd.bak1
2007-08-28 20:47 1,688,843 --ahsc--- C:\WINDOWS\system32\rstwa.bak1
2007-08-26 10:49 1,611,427 --ahsc--- C:\WINDOWS\system32\vvvwa.bak1
2007-08-26 03:41 6,473 --ahsc--- C:\WINDOWS\system32\jjkmp.bak1
2007-08-25 11:14 1,600,553 --ahsc--- C:\WINDOWS\system32\oqtss.bak1
2007-08-24 19:48 6,513 --ahsc--- C:\WINDOWS\system32\ghkmp.bak1
2007-08-23 19:10 1,601,026 --ahsc--- C:\WINDOWS\system32\ghhkj.bak1
2007-08-23 11:19 6,473 --ahsc--- C:\WINDOWS\system32\ihkmp.bak1
2007-08-22 23:34 1,505,525 --ahsc--- C:\WINDOWS\system32\orqss.bak2
2007-08-22 18:28 <DIR> d----c--- C:\Program Files\Autodesk
2007-08-22 18:12 6,513 --ahsc--- C:\WINDOWS\system32\qpqss.bak1
2007-08-22 17:00 6,473 --ahsc--- C:\WINDOWS\system32\cbeeg.bak1
2007-08-21 22:42 1,590,154 --ahsc--- C:\WINDOWS\system32\fgjlm.bak1
2007-08-20 22:59 6,473 --ahsc--- C:\WINDOWS\system32\xbeeg.bak1
2007-08-20 10:40 6,473 --ahsc--- C:\WINDOWS\system32\pstwa.bak1
2007-08-20 00:54 1,607,549 --ahsc--- C:\WINDOWS\system32\aybeg.bak1
2007-08-19 12:54 1,503,133 --ahsc--- C:\WINDOWS\system32\aybeg.bak2
2007-08-19 10:51 1,501,370 --ahsc--- C:\WINDOWS\system32\kjjlm.bak2
2007-08-18 22:59 6,473 --ahsc--- C:\WINDOWS\system32\dfhkj.bak1

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-18 15:49 --------- d----c--- C:\Program Files\PeerGuardian2
2007-09-09 01:27 --------- d----c--- C:\Program Files\StepMania
2007-09-06 15:38 --------- d----c--- C:\Program Files\microsoft frontpage
2007-08-16 02:56 --------- d----c--- C:\Program Files\TRINITRON CG
2007-08-14 23:16 --------- d----c--- C:\Program Files\Common Files\Symantec Shared
2007-08-14 23:16 --------- d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-08-11 12:35 --------- d----c--- C:\Program Files\Norton Internet Security
2007-08-11 12:33 --------- d----c--- C:\Program Files\Symantec
2007-08-11 12:32 10344 --a--c--- C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-08-01 22:12 --------- d----c--- C:\Program Files\OGplanet
2007-07-19 21:14 --------- d----c--- C:\Program Files\Common Files\Autodesk Shared
2007-07-19 21:14 --------- d----c--- C:\Program Files\Common Files\Alias Shared
2005-06-29 19:04 251 --a--c--- C:\Program Files\wt3d.ini
2005-07-15 22:07:18 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 02:04]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 17:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-12-01 03:55]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 C:\WINDOWS\AGRSMMSG.exe]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 06:43]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-09-16 08:27]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-25 07:17]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" []
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 07:54]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 11:25]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2007-04-19 22:21]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 16:14 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2006-05-04 16:26 C:\WINDOWS\alcwzrd.exe]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" []
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" []
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" []
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" []
"SSC_UserPrompt"="c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-02 00:59]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 21:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"RealPlayer"="C:\Program Files\Real\RealPlayer\realplay.exe" [2006-05-29 20:15]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 12:12]
"Aim6"="" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 20:28:24]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-03-15 12:47:06]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\SpySub.exe [2005-03-15 12:17:32]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-03-15 12:18:42]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"= C:\Program Files\InterMute\SpySubtract\sshook.dll [2005-08-25 12:06 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll

R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys
R3 pgfilter;pgfilter;\??\C:\Program Files\PeerGuardian2\pgfilter.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
AutoRun\command- G:\RAIDY2RT.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
AutoRun\command- K:\RAIDY_R.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\M]
AutoRun\command- M:\menu.exe

*Newly Created Service* - COMHOST
*Newly Created Service* - PGFILTER
.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 03:00:01 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - HP_Administrator.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
"2007-09-07 07:31:31 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-18 16:03:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-18 16:05:48 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-18 16:05
C:\ComboFix2.txt ... 2007-05-24 11:04
C:\ComboFix3.txt ... 2007-05-03 11:23
.
--- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:11:31 PM, on 9/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173486144703
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 9367 bytes

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:29 AM

Posted 17 September 2007 - 06:58 PM

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\system32\jjjlm.bak1
C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\llnmp.bak1
C:\WINDOWS\system32\cbadd.bak1
C:\WINDOWS\system32\rstwa.bak1
C:\WINDOWS\system32\vvvwa.bak1
C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\oqtss.bak1
C:\WINDOWS\system32\ghkmp.bak1
C:\WINDOWS\system32\ghhkj.bak1
C:\WINDOWS\system32\ihkmp.bak1
C:\WINDOWS\system32\orqss.bak2
C:\WINDOWS\system32\qpqss.bak1
C:\WINDOWS\system32\cbeeg.bak1
C:\WINDOWS\system32\fgjlm.bak1
C:\WINDOWS\system32\xbeeg.bak1
C:\WINDOWS\system32\pstwa.bak1
C:\WINDOWS\system32\aybeg.bak1
C:\WINDOWS\system32\aybeg.bak2
C:\WINDOWS\system32\kjjlm.bak2
C:\WINDOWS\system32\dfhkj.bak1

Registry::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image
Posted Image

#5 pirajacinto

pirajacinto
  • Topic Starter

  • Members
  • 98 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 19 September 2007 - 12:30 AM

ComboFix 07-09-18 - "HP_Administrator" 2007-09-19 22:09:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.541 [GMT -7:00]
* Created a new restore point

FILE::
C:\WINDOWS\system32\jjjlm.bak1
C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\llnmp.bak1
C:\WINDOWS\system32\cbadd.bak1
C:\WINDOWS\system32\rstwa.bak1
C:\WINDOWS\system32\vvvwa.bak1
C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\oqtss.bak1
C:\WINDOWS\system32\ghkmp.bak1
C:\WINDOWS\system32\ghhkj.bak1
C:\WINDOWS\system32\ihkmp.bak1
C:\WINDOWS\system32\orqss.bak2
C:\WINDOWS\system32\qpqss.bak1
C:\WINDOWS\system32\cbeeg.bak1
C:\WINDOWS\system32\fgjlm.bak1
C:\WINDOWS\system32\xbeeg.bak1
C:\WINDOWS\system32\pstwa.bak1
C:\WINDOWS\system32\aybeg.bak1
C:\WINDOWS\system32\aybeg.bak2
C:\WINDOWS\system32\kjjlm.bak2
C:\WINDOWS\system32\dfhkj.bak1
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\aybeg.bak1
C:\WINDOWS\system32\aybeg.bak2
C:\WINDOWS\system32\cbadd.bak1
C:\WINDOWS\system32\cbeeg.bak1
C:\WINDOWS\system32\dfhkj.bak1
C:\WINDOWS\system32\fgjlm.bak1
C:\WINDOWS\system32\ghhkj.bak1
C:\WINDOWS\system32\ghkmp.bak1
C:\WINDOWS\system32\ihkmp.bak1
C:\WINDOWS\system32\jjjlm.bak1
C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\kjjlm.bak2
C:\WINDOWS\system32\llnmp.bak1
C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\oqtss.bak1
C:\WINDOWS\system32\orqss.bak2
C:\WINDOWS\system32\pstwa.bak1
C:\WINDOWS\system32\qpqss.bak1
C:\WINDOWS\system32\rstwa.bak1
C:\WINDOWS\system32\vvvwa.bak1
C:\WINDOWS\system32\xbeeg.bak1

.
((((((((((((((((((((((((( Files Created from 2007-08-20 to 2007-09-20 )))))))))))))))))))))))))))))))
.

2007-09-19 00:43 <DIR> d----c--- C:\DOCUME~1\HP_ADM~1\APPLIC~1\ZOO Digital Publishing
2007-09-19 00:28 <DIR> d----c--- C:\Program Files\ZOO Digital Publishing
2007-08-22 18:28 <DIR> d----c--- C:\Program Files\Autodesk

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-19 22:15 --------- d----c--- C:\Program Files\PeerGuardian2
2007-09-09 01:27 --------- d----c--- C:\Program Files\StepMania
2007-09-06 15:38 --------- d----c--- C:\Program Files\microsoft frontpage
2007-08-18 04:06 1598957 --ahsc--- C:\WINDOWS\system32\bbadd.bak1
2007-08-16 22:29 6473 --ahsc--- C:\WINDOWS\system32\bbeeg.bak1
2007-08-16 02:56 --------- d----c--- C:\Program Files\TRINITRON CG
2007-08-15 23:06 1686008 --ahsc--- C:\WINDOWS\system32\npqss.bak1
2007-08-14 23:23 6461 --ahsc--- C:\WINDOWS\system32\nnnmp.bak1
2007-08-14 23:16 --------- d----c--- C:\Program Files\Common Files\Symantec Shared
2007-08-14 23:16 --------- d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-08-13 23:52 1685657 --ahsc--- C:\WINDOWS\system32\tttss.bak1
2007-08-11 12:35 --------- d----c--- C:\Program Files\Norton Internet Security
2007-08-11 12:33 --------- d----c--- C:\Program Files\Symantec
2007-08-11 12:32 10344 --a--c--- C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-08-01 22:12 --------- d----c--- C:\Program Files\OGplanet
2007-07-30 19:19 92504 --a--c--- C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a--c--- C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a--c--- C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a--c--- C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a--c--- C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a--c--- C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a--c--- C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a--c--- C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a--c--- C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-19 21:14 --------- d----c--- C:\Program Files\Common Files\Autodesk Shared
2007-07-19 21:14 --------- d----c--- C:\Program Files\Common Files\Alias Shared
2007-06-25 23:08 1104896 --a--c--- C:\WINDOWS\system32\msxml3.dll
2007-06-19 06:31 282112 --a--c--- C:\WINDOWS\system32\gdi32.dll
2007-04-19 23:45 1375085 ---hsc--- C:\WINDOWS\inf\nwitca.ini2
2007-04-19 16:35 1370966 ---hsc--- C:\WINDOWS\inf\nwitca.bak2
2007-04-09 13:56 1217168 ---hsc--- C:\WINDOWS\inf\nwitca.bak1
2005-06-29 19:04 251 --a--c--- C:\Program Files\wt3d.ini
2005-07-15 22:07:18 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 02:04]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 17:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-12-01 03:55]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 C:\WINDOWS\AGRSMMSG.exe]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 06:43]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-09-16 08:27]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-25 07:17]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" []
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 07:54]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 11:25]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2007-04-19 22:21]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 16:14 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2006-05-04 16:26 C:\WINDOWS\alcwzrd.exe]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" []
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" []
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" []
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" []
"SSC_UserPrompt"="c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-02 00:59]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 21:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"RealPlayer"="C:\Program Files\Real\RealPlayer\realplay.exe" [2006-05-29 20:15]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 12:12]
"Aim6"="" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 20:28:24]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-03-15 12:47:06]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\SpySub.exe [2005-03-15 12:17:32]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-03-15 12:18:42]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"= C:\Program Files\InterMute\SpySubtract\sshook.dll [2005-08-25 12:06 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll

R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys
R3 pgfilter;pgfilter;\??\C:\Program Files\PeerGuardian2\pgfilter.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
AutoRun\command- K:\RAIDY_R.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\M]
AutoRun\command- M:\menu.exe

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 03:00:01 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - HP_Administrator.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
"2007-09-07 07:31:31 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-19 22:16:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-19 22:18:31
C:\ComboFix-quarantined-files.txt ... 2007-09-19 22:18
C:\ComboFix2.txt ... 2007-09-18 16:05
C:\ComboFix3.txt ... 2007-05-24 11:04
.
--- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:30:40 PM, on 9/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ps2.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1173486144703
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 9534 bytes

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:29 AM

Posted 19 September 2007 - 05:55 AM

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktopPosted Imageand agree to merge the imformation into the registry,then restart your pc.

REGEDIT4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00


Please download OTMoveIt by OldTimer:
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

Save it to your desktop.
Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose 'Copy'):

C:\WINDOWS\system32\bbadd.bak1
C:\WINDOWS\system32\bbeeg.bak1
C:\WINDOWS\system32\npqss.bak1
C:\WINDOWS\system32\nnnmp.bak1
C:\WINDOWS\system32\tttss.bak1
C:\WINDOWS\inf\nwitca.ini2
C:\WINDOWS\inf\nwitca.bak2
C:\WINDOWS\inf\nwitca.bak1


Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button Posted Image

Copy everything on the 'Results' window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose 'Copy'), and paste it into your next reply.
Close OTMoveIt

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.
If you are asked to reboot the machine choose Yes.

Please run this online virus scan:Activescan using Internet Explorer.
Once you are on the Panda site click the Scan your PC button
A new window will open...click the Check Now button
Enter your Country
Enter your State/Province
Enter your e-mail address and click send
Select either Home User or Company
Click the big Scan Now button
If it wants to install an ActiveX component allow it
It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
When download is complete, click on Local Disks to start the scan
When the scan completes,click the See Report button, then Save Report, and save it to your desktop.
Post the Activescan report into your next reply.

Also post a new Hijackthis log.
Posted Image
Posted Image

#7 pirajacinto

pirajacinto
  • Topic Starter

  • Members
  • 98 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 24 September 2007 - 11:43 PM

Sorry for the delay, but I'm having problems with doing the 2nd part. But here's MoveIt! first.

C:\WINDOWS\system32\bbadd.bak1 moved successfully.
C:\WINDOWS\system32\bbeeg.bak1 moved successfully.
C:\WINDOWS\system32\npqss.bak1 moved successfully.
C:\WINDOWS\system32\nnnmp.bak1 moved successfully.
C:\WINDOWS\system32\tttss.bak1 moved successfully.
C:\WINDOWS\inf\nwitca.ini2 moved successfully.
C:\WINDOWS\inf\nwitca.bak2 moved successfully.
C:\WINDOWS\inf\nwitca.bak1 moved successfully.

Created on 09/25/2007 21:41:02


I can't seem to do the online virus scan as as soon as the pop up for the "Scan My PC" button I push pops up, it instandly closes. This happens alot to Javascript type of pop ups.

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:29 AM

Posted 25 September 2007 - 05:16 AM

Restart your pc.

Double click on Combofix.exe again and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.

Also post a new Hijackthis log.
Let me know how your pc is running now please.
Posted Image
Posted Image

#9 pirajacinto

pirajacinto
  • Topic Starter

  • Members
  • 98 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 25 September 2007 - 09:45 PM

ComboFix 07-09-18 - "HP_Administrator" 2007-09-26 19:27:07.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.554 [GMT -7:00]
.

((((((((((((((((((((((((( Files Created from 2007-08-27 to 2007-09-27 )))))))))))))))))))))))))))))))
.

2007-09-19 00:43 <DIR> d----c--- C:\DOCUME~1\HP_ADM~1\APPLIC~1\ZOO Digital Publishing
2007-09-19 00:28 <DIR> d----c--- C:\Program Files\ZOO Digital Publishing

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-26 19:34 --------- d----c--- C:\Program Files\PeerGuardian2
2007-09-22 22:42 --------- d----c--- C:\Program Files\StepMania
2007-09-06 15:38 --------- d----c--- C:\Program Files\microsoft frontpage
2007-08-22 18:28 --------- d----c--- C:\Program Files\Autodesk
2007-08-16 02:56 --------- d----c--- C:\Program Files\TRINITRON CG
2007-08-14 23:16 --------- d----c--- C:\Program Files\Common Files\Symantec Shared
2007-08-14 23:16 --------- d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-08-11 12:35 --------- d----c--- C:\Program Files\Norton Internet Security
2007-08-11 12:33 --------- d----c--- C:\Program Files\Symantec
2007-08-11 12:32 10344 --a--c--- C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-08-01 22:12 --------- d----c--- C:\Program Files\OGplanet
2007-07-30 19:19 92504 --a--c--- C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a--c--- C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a--c--- C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a--c--- C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a--c--- C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a--c--- C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a--c--- C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a--c--- C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a--c--- C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-06-25 23:08 1104896 --a--c--- C:\WINDOWS\system32\msxml3.dll
2005-06-29 19:04 251 --a--c--- C:\Program Files\wt3d.ini
2005-07-15 22:07:18 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((( snapshot_2007-09-18_160509.90 )))))))))))))))))))))))))))))))))))))))))
.
-c--a-r 593,920 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
-c--a-r 12,288 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
-c--a-r 86,016 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
-c--a-r 135,168 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
-c--a-r 11,264 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
-c--a-r 27,136 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
-c--a-r 4,096 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
-c--a-r 794,624 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
-c--a-r 249,856 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
-c--a-r 61,440 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
-c--a-r 23,040 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
-c--a-r 286,720 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
-c--a-r 409,600 2007-09-20 10:01:42 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
.
-c--a-r 593,920 2007-08-15 10:14:55 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
-c--a-r 12,288 2007-08-15 10:14:55 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
-c--a-r 86,016 2007-08-15 10:14:55 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
-c--a-r 135,168 2007-08-15 10:14:55 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
-c--a-r 11,264 2007-08-15 10:14:55 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
-c--a-r 27,136 2007-08-15 10:14:56 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
-c--a-r 4,096 2007-08-15 10:14:56 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
-c--a-r 794,624 2007-08-15 10:14:56 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
-c--a-r 249,856 2007-08-15 10:14:55 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
-c--a-r 61,440 2007-08-15 10:14:55 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
-c--a-r 23,040 2007-08-15 10:14:56 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
-c--a-r 286,720 2007-08-15 10:14:55 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
-c--a-r 409,600 2007-08-15 10:14:54 C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 02:04]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 17:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-12-01 03:55]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 C:\WINDOWS\AGRSMMSG.exe]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 06:43]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-09-16 08:27]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-25 07:17]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" []
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 07:54]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 11:25]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2007-04-19 22:21]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 16:14 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2006-05-04 16:26 C:\WINDOWS\alcwzrd.exe]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" []
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" []
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" []
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" []
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" []
"SSC_UserPrompt"="c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-02 00:59]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-09 21:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24]
"RealPlayer"="C:\Program Files\Real\RealPlayer\realplay.exe" [2006-05-29 20:15]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2005-05-25 12:12]
"Aim6"="" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 20:28:24]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-03-15 12:47:06]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\SpySub.exe [2005-03-15 12:17:32]
Updates from HP.lnk - C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe [2005-03-15 12:18:42]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FA010552-4A27-4cb1-A1BB-3E2D697F1639}"= C:\Program Files\InterMute\SpySubtract\sshook.dll [2005-08-25 12:06 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll

R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys
R3 pgfilter;pgfilter;\??\C:\Program Files\PeerGuardian2\pgfilter.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
AutoRun\command- K:\RAIDY_R.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
AutoRun\command- L:\Setup.exe
readme\command- notepad readme.txt

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\M]
AutoRun\command- M:\menu.exe

*Newly Created Service* - COMHOST
*Newly Created Service* - PGFILTER
.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 03:00:01 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - HP_Administrator.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
"2007-09-07 07:31:31 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-26 19:34:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-26 19:36:43
C:\ComboFix-quarantined-files.txt ... 2007-09-26 19:36
C:\ComboFix2.txt ... 2007-09-19 22:18
C:\ComboFix3.txt ... 2007-09-18 16:05
.
--- E O F ---

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:29 AM

Posted 26 September 2007 - 10:31 AM

Your log is clean :thumbsup:
If all's ok,please do the following:

Please double-click OTMoveIt.exe to run it.
Click on the 'Cleanup' button Posted Image
When the 'Confirm' box appears click 'Yes'.
Restart your pc when prompted.

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
How to prevent Malware by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image

#11 pirajacinto

pirajacinto
  • Topic Starter

  • Members
  • 98 posts
  • OFFLINE
  •  
  • Local time:09:29 PM

Posted 29 September 2007 - 04:04 AM

Wow, is that really all there is to the problem? I've seen stuff where it goes on for at least a month...

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:29 AM

Posted 29 September 2007 - 09:06 AM

Yes thats it :thumbsup:

This thread will now be closed.
If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you.
Include the address of this thread in your request.
If you should have a new issue, please start a new topic.
This applies only to the original topic starter.
Everyone else please begin a New Topic.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users