Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Zbog


  • Please log in to reply
6 replies to this topic

#1 vicdog

vicdog

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:05 AM

Posted 23 October 2007 - 06:07 PM

Here is my hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:55:33 PM, on 10/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxsrvc.exe
F:\HiJackThis.exe

F2 - REG:system.ini: Shell=
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0F364119-6074-4100-C354-03895BC6483C} - (no file)
O2 - BHO: (no name) - {480598DD-AE28-48B7-82F7-6ADDA1AA6B66} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.19\QOELoader.exe"
O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [CaPPcl] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe /scan /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [Staples Easy Button] "C:\Program Files\Staples Easy Button\EasyButton.exe" /BOOT
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707...ex/qtplugin.cab
O21 - SSODL: hstsys - {E23209C3-D901-4DF2-B619-972175CB8C28} - C:\WINDOWS\hstsys.dll
O21 - SSODL: hostctrl - {D7A91E46-0933-4B69-A034-1C2C00AD250D} - C:\WINDOWS\hostctrl.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: WinSock Svchost Manager (WinSvchostManager) - Unknown owner - C:\WINDOWS\SYSTEM32\svcprs32.exe

--
End of file - 8272 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 24 October 2007 - 04:56 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum vicdog :thumbsup:
My name is Richie and i'll be helping you to fix your problems.

Please disable Spybot S&Dís protection,or it will interfere.
You can enable it after you're clean.
Open Spybot and click on 'Mode' and check 'Advanced Mode'.
Click on 'Tools' in bottom left hand corner.
Click on the 'System Startup' icon.
Uncheck 'Teatimer' box and/or uncheck 'Resident'.
Click the 'Allow Change' box.
Then, check next to the computer clock to see if the icon for Spybot is still there.
If it is, right click it and choose 'exit Spybot-S&D Resident'.
Restart the computer.
If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:
http://www.russelltexas.com/malware/teatimer.htm


Copy and paste the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.bat to your desktop.
Then double click on the fix.bat file on your desktopPosted Image
You'll see a black screen flash,thats normal.

@echo off
sc stop WinSvchostManager
sc delete WinSvchostManager

Restart your pc.


Download SDFix.exe and save it to your desktop:
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

* Double click on SDFix on your desktop,and install the fix to C:\

Please then reboot your computer into Safe Mode by doing the following:

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.

* In Safe Mode,go to and open the C:\SDFix folder,then double click on RunThis.bat to start the script.
* Type Y to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt into your next reply.


If you have previously downloaded ComboFix,please delete that version now.
Now download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#3 vicdog

vicdog
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:05 AM

Posted 24 October 2007 - 06:46 PM

Here are the logs. Thanks for the help. I had to remove the startup entries for CA because it was stuck in some crazy loop to install the firewall.


SDFix: Version 1.111

Run by lgraybill on Wed 10/24/2007 at 05:37 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\nmcuninstall.exe - Deleted
C:\WINDOWS\ntspkmxl.dll - Deleted
C:\WINDOWS\rs.txt - Deleted
C:\WINDOWS\search_res.txt - Deleted



Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE:*:Enabled:Connection Manager"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Hewlett-Packard\\HP DeskJet 1220C Toolbox\\HPW8TBX.exe"="C:\\Program Files\\Hewlett-Packard\\HP DeskJet 1220C Toolbox\\HPW8TBX.exe:*:Enabled:Toolbox for HP Printing System for Windows"
"C:\\Program Files\\Hewlett-Packard\\hp deskjet 9600 series\\Toolbox\\HPWITBX.exe"="C:\\Program Files\\Hewlett-Packard\\hp deskjet 9600 series\\Toolbox\\HPWITBX.exe:*:Enabled:Toolbox for HP Printing System for Windows"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE:*:Enabled:ActiveSync Application"
"C:\\Program Files\\Sharp\\Sharpdesk\\FTPServer.exe"="C:\\Program Files\\Sharp\\Sharpdesk\\FTPServer.exe:*:Enabled:Network Scanner Tool"
"C:\\Program Files\\Common Files\\News 10 NewsCentral\\TrueWeather.exe"="C:\\Program Files\\Common Files\\News 10 NewsCentral\\TrueWeather.exe:*:Enabled:TrueWeather"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\ICQ\\Icq.exe"="C:\\Program Files\\ICQ\\Icq.exe:*:Enabled:ICQ"
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"="C:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe:*:Enabled:TrueVector Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Thu 29 Aug 2002 77,824 ...H. --- "C:\Program Files\MSN\msnupdate!@#@.exe"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc100.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc101.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc102.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc103.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc104.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc105.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc106.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc107.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc108.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc109.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc110.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc111.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc112.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc113.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc114.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc115.tmp"
Tue 23 Oct 2007 85,946 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc116.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc117.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc118.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc119.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc120.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc121.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc122.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc123.tmp"
Tue 23 Oct 2007 85,946 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc124.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc125.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc126.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc127.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc128.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc129.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc130.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc131.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc132.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc133.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc21.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc22.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc23.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc24.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc25.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc26.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc27.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc28.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc29.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc30.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc31.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc32.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc33.tmp"
Tue 23 Oct 2007 85,946 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc34.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc35.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc36.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc37.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc38.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc39.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc40.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc41.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc42.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc43.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc44.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc45.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc46.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc47.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc48.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc49.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc50.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc51.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc52.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc53.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc54.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc55.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc56.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc57.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc58.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc59.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc60.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc61.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc62.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc63.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc64.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc65.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc66.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc67.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc68.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc69.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc70.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc71.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc72.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc73.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc74.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc75.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc76.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc77.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc78.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc79.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc80.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc81.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc82.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc83.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc84.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc85.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc86.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc87.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc88.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc89.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc90.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc91.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc92.tmp"
Tue 23 Oct 2007 388,090 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc93.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc94.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc95.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc96.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc97.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc98.tmp"
Tue 23 Oct 2007 0 A..H. --- "C:\RECYCLER\S-1-5-21-722463289-3423219296-3871846941-1007\Dc99.tmp"
Fri 28 Oct 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 20 Oct 2003 73,688 ..SHR --- "C:\Program Files\Autodesk\Autodesk DWF Viewer\Setup.exe"
Sat 24 Jan 2004 5,120 A.SHR --- "C:\Program Files\Autodesk\Autodesk DWF Viewer\_Setupx.dll"
Wed 10 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 10 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"

Finished!


now combofix
ComboFix 07-10-25.1 - lgraybill 2007-10-24 17:54:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2050 [GMT -5:00]
Running from: C:\Documents and Settings\lgraybill\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\lgraybill\Application Data\installer_en[1].exe
C:\WINDOWS\system32\LMIinit.dll
C:\WINDOWS\system32\UmxWnp.Dll

.
((((((((((((((((((((((((( Files Created from 2007-09-25 to 2007-10-25 )))))))))))))))))))))))))))))))
.

2007-10-24 17:52 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-24 17:35 <DIR> d-------- C:\WINDOWS\ERUNT
2007-10-23 21:34 <DIR> d-------- C:\Program Files\Lavasoft
2007-10-23 21:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-23 21:33 <DIR> d-------- C:\WINDOWS\CAVTemp
2007-10-23 16:36 289,144 --a------ C:\WINDOWS\SYSTEM32\VCCLSID.exe
2007-10-23 16:36 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-10-23 16:36 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2007-10-23 16:36 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2007-10-23 16:36 25,600 --a------ C:\WINDOWS\SYSTEM32\WS2Fix.exe
2007-10-23 15:14 <DIR> d-------- C:\Program Files\ToniArts
2007-10-23 14:08 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgArCln.sys
2007-10-23 09:22 <DIR> d-------- C:\Documents and Settings\lgraybill\Application Data\CallingID
2007-10-23 09:22 6 --a------ C:\WINDOWS\SYSTEM32\mkghj.dll
2007-10-23 09:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-23 09:21 <DIR> d-------- C:\Program Files\Common Files\Scanner
2007-10-23 09:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CA
2007-10-23 09:18 <DIR> d-------- C:\Program Files\CA
2007-10-23 09:09 <DIR> d-------- C:\Documents and Settings\lgraybill\Application Data\GetRightToGo
2007-10-22 14:28 <DIR> d-------- C:\Documents and Settings\lgraybill\Application Data\MailFrontier
2007-10-22 14:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-10-22 14:19 11,264 --a------ C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-10-22 14:19 4,212 ---h----- C:\WINDOWS\SYSTEM32\zllictbl.dat
2007-10-22 13:38 <DIR> d-------- C:\Smitfraud
2007-10-22 13:35 2,516 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-10-22 12:37 <DIR> d-------- C:\WINDOWS\SYSTEM32\ZoneLabs
2007-10-22 11:47 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-22 09:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-22 08:44 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-10-18 15:54 <DIR> d-------- C:\Documents and Settings\lgraybill\Application Data\YourPrivacyGuard
2007-10-18 09:26 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-18 09:25 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-10-11 13:33 <DIR> d-------- C:\music
2007-10-10 14:22 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\UMDF
2007-10-10 04:20 582,656 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-25 22:54 --------- d-----w C:\Program Files\LogMeIn
2007-10-23 23:54 --------- d-----w C:\Program Files\QuickTime
2007-10-23 21:53 --------- d-----w C:\Program Files\Azureus
2007-10-23 20:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-23 16:36 --------- d-----w C:\Program Files\Caterpillar
2007-10-23 16:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-23 16:11 --------- d-----w C:\Program Files\Shutterfly
2007-10-23 16:10 --------- d-----w C:\Program Files\MUSICMATCH
2007-10-23 16:04 --------- d-----w C:\Program Files\Jasc Software Inc
2007-10-23 15:58 --------- d-----w C:\Program Files\Winamp
2007-10-23 15:56 --------- d-----w C:\Program Files\Cummins Power Suite
2007-10-23 14:22 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-23 14:20 2,732,032 ----a-w C:\WINDOWS\SYSTEM32\win32cpr.dll
2007-10-23 14:20 1,556,575 ----a-w C:\WINDOWS\SYSTEM32\winsflt.dll
2007-10-22 21:22 --------- d-----w C:\Program Files\MySpace
2007-10-22 21:21 --------- d-----w C:\Program Files\Common Files\Real
2007-10-22 21:19 --------- d-----w C:\Program Files\AIM
2007-10-22 21:18 --------- d-----w C:\Documents and Settings\lgraybill\Application Data\Aim
2007-09-24 17:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-09-24 17:44 --------- d-----w C:\Program Files\Common Files\aol
2007-09-24 17:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-09-24 17:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-09-15 02:05 99,592 ----a-w C:\WINDOWS\SYSTEM32\isafeif.dll
2007-09-15 02:05 879,784 ----a-w C:\WINDOWS\system32\drivers\vetefile.sys
2007-09-15 02:05 79,424 ----a-w C:\WINDOWS\SYSTEM32\vetredir.dll
2007-09-15 02:05 75,016 ----a-w C:\WINDOWS\SYSTEM32\isafprod.dll
2007-09-15 02:05 32,264 ----a-w C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-09-15 02:05 26,376 ----a-w C:\WINDOWS\system32\drivers\vet-filt.sys
2007-09-15 02:05 21,512 ----a-w C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-09-15 02:05 21,128 ----a-w C:\WINDOWS\system32\drivers\vet-rec.sys
2007-09-15 02:05 108,312 ----a-w C:\WINDOWS\system32\drivers\veteboot.sys
2007-09-05 16:50 93,712 ----a-w C:\WINDOWS\system32\drivers\KmxStart.sys
2007-09-05 16:50 133,136 ----a-w C:\WINDOWS\system32\drivers\KmxCF.sys
2007-09-05 16:50 114,704 ----a-w C:\WINDOWS\system32\drivers\KmxFw.sys
2007-09-03 18:01 823,296 ----a-w C:\WINDOWS\SYSTEM32\svcprs32.exe
2007-09-03 18:01 1,212,416 ----a-w C:\WINDOWS\SYSTEM32\mdmcls32.exe
2007-09-03 18:00 11,333,632 ----a-w C:\WINDOWS\cfgmng32.exe
2007-09-03 17:52 1,830,912 ----a-w C:\WINDOWS\SYSTEM32\winsflte.dll
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\SYSTEM32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\inetcomm.dll
2007-08-20 10:04 824,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-08-20 10:04 671,232 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-08-20 10:04 477,696 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-08-20 10:04 44,544 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-08-20 10:04 3,584,512 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-08-20 10:04 27,648 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
2007-08-20 10:04 230,400 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
2007-08-20 10:04 214,528 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-08-20 10:04 193,024 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-08-20 10:04 153,088 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
2007-08-20 10:04 132,608 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
2007-08-20 10:04 1,152,000 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-08-17 07:34 161,792 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2007-08-02 15:09 256,528 ----a-w C:\WINDOWS\SYSTEM32\UmxSbxw.dll
2007-08-02 15:09 117,264 ----a-w C:\WINDOWS\SYSTEM32\UmxSbxExw.dll
2007-07-31 00:19 92,504 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
2007-07-31 00:19 92,504 ----a-w C:\WINDOWS\SYSTEM32\cdm.dll
2007-07-31 00:19 549,720 ----a-w C:\WINDOWS\SYSTEM32\wuapi.dll
2007-07-31 00:19 549,720 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
2007-07-31 00:19 53,080 ----a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
2007-07-31 00:19 53,080 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
2007-07-31 00:19 43,352 ----a-w C:\WINDOWS\SYSTEM32\wups2.dll
2007-07-31 00:19 325,976 ----a-w C:\WINDOWS\SYSTEM32\wucltui.dll
2007-07-31 00:19 325,976 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
2007-07-31 00:19 203,096 ----a-w C:\WINDOWS\SYSTEM32\wuweb.dll
2007-07-31 00:19 203,096 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
2007-07-31 00:19 1,712,984 ----a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
2007-07-31 00:19 1,712,984 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
2007-07-31 00:18 33,624 ----a-w C:\WINDOWS\SYSTEM32\wups.dll
2007-07-31 00:18 33,624 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
2005-07-21 17:51 457 -c--a-w C:\Program Files\INSTALL.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F364119-6074-4100-C354-03895BC6483C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-09-19 14:40]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-09-14 21:05]
"QOELOADER"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.19\QOELoader.exe" [2007-10-23 09:21]
"cafw"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2007-09-12 22:01]
"capfasem"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2007-09-12 22:01]
"capfupgrade"="C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2007-09-12 22:01]
"CaPPcl"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe" [2007-09-17 21:35]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\LinkAdvisor\CIDLinkAdvisor.dll [2007-09-03 23:04 1373624]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1

R0 KmxStart;KmxStart;C:\WINDOWS\system32\DRIVERS\kmxstart.sys
R1 KmxAgent;KmxAgent;C:\WINDOWS\system32\DRIVERS\kmxagent.sys
R1 KmxFile;KmxFile;C:\WINDOWS\system32\DRIVERS\KmxFile.sys
R1 KmxFw;KmxFw;C:\WINDOWS\system32\DRIVERS\kmxfw.sys
R2 KmxCF;KmxCF;C:\WINDOWS\system32\DRIVERS\KmxCF.sys
R2 KmxSbx;KmxSbx;C:\WINDOWS\system32\DRIVERS\KmxSbx.sys
R2 LMIInfo;LogMeIn Kernel Information Provider;\??\C:\Program Files\LogMeIn\x86\RaInfo.sys
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
R2 UmxAgent;HIPS Event Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe"
R2 UmxCfg;HIPS Configuration Interpreter;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe"
R2 UmxPol;HIPS Policy Manager;"C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe"
R3 KmxCfg;KmxCfg;C:\WINDOWS\system32\DRIVERS\kmxcfg.sys
R3 LMImirr;LMImirr;C:\WINDOWS\system32\DRIVERS\LMImirr.sys
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43754740-b0c5-11da-838d-000cf1a5b050}]
AutoRun\command - F:\JDSecure\Windows\JDSecure20.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43754741-b0c5-11da-838d-000cf1a5b050}]
AutoRun\command - F:\JDSecure\Windows\JDSecure20.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{49a9ae96-c340-11da-8393-000cf1a5b050}]
AutoRun\command - F:\JDSecure\Windows\JDSecure20.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6bcd9836-4723-11db-83c5-000cf1a5b050}]
AutoRun\command - F:\JDSecure\Windows\JDSecure20.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f279bc18-06b8-11db-83b4-000cf1a5b050}]
AutoRun\command - F:\JDSecure\Windows\JDSecure20.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-10-23 17:18:05 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as lgraybill at 12 00 PM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
"2007-10-01 21:41:26 C:\WINDOWS\Tasks\Disk Cleanup.job"
"2007-10-12 21:00:00 C:\WINDOWS\Tasks\{3EF54D71-BDF8-4E1F-A2BA-E1B4B7C8A4CB}_DJT6QF41_lgraybill.job"
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-25 18:08:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-25 18:19:55 - machine was rebooted
.
--- E O F ---

Now hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:40:50 PM, on 10/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Documents and Settings\lgraybill\Desktop\HiJackThis.exe

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0F364119-6074-4100-C354-03895BC6483C} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\WebsiteInspector\Toolbar\CallingIDIE.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

--
End of file - 6555 bytes

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 24 October 2007 - 07:47 PM

You have a Backdoor Trojan present on your pc
A Backdoor is a software program that gives an attacker unauthorized access to a machine and the means for remotely controlling the machine without the user's knowledge. A Backdoor compromises system integrity by making changes to the system that allow it to be used by the attacker for malicious purposes unknown to the user.

They are typically installed without user interaction through security exploits, and may allow an attacker to remotely control the infected machine. Such risks may allow the attacker to install additional malware and use the compromised machine to participate in denial of service attacks, spamming, and bot nets, or to transmit sensitive data to a remote server. The malware may be cloaked and not visible to the user. These risks severely compromise the system by lowering security settings, installing 'backdoors,' infecting system files, or spreading to other networked machines.

If your computer was used for online banking or has credit card information on it, all passwords should be changed immediately to include those used for email, eBay and forums.
You should consider them to be compromised.
They should be changed by using a different computer and not the infected one,if not an attacker may get the new passwords and transaction information.
Banking and credit card institutions should be notified of the possible security breech.

Since your computer was compromised read:
How to report ID theft, fraud, drive-by installs, hijacking and malware:
http://www.dslreports.com/faq/10451

When Should I Format, How Should I Reinstall:
http://www.dslreports.com/faq/10063

Let me know how you wish to proceed,but i must warn you now that even if you wish to continue disinfecting your system, i cannot guarantee it to be 100% safe after we've finished.
Posted Image
Posted Image

#5 vicdog

vicdog
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:05 AM

Posted 24 October 2007 - 09:02 PM

Okay, i'm going to do the format re-install. I can handle that unless there is something special I need to do to be sure it is wiped. I will most likely remove all partions, create new then re-install. Can you tell me what in the logs tells you it is still infected?

Thanks for all the help.

#6 vicdog

vicdog
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:09:05 AM

Posted 24 October 2007 - 09:12 PM

Can you tell me if this one looks okay?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:08:53 PM, on 10/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Money Plus\MNYCoreFiles\mnyinsit.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Documents and Settings\Dad\My Documents\Downloads\HiJackThis.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MoneyInsights] "C:\Program Files\Microsoft Money Plus\MNYCoreFiles\mnyinsit.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1188008849765
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1188666812890
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6612 bytes

#7 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:03:05 PM

Posted 25 October 2007 - 03:56 AM

Can you tell me what in the logs tells you it is still infected?

Mdmcls32.exe is present in the Combofix.txt and is a Backdoor Trojan.

Can you tell me if this one looks okay?

That log looks clean,but your system itself is'nt forced to be so,further investigations would have to be taken.

That version of Sun Java is outdated:
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6 update 3'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java version.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users