Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Browser Hijacked?


  • Please log in to reply
7 replies to this topic

#1 bug1965

bug1965

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 09 February 2008 - 12:16 PM

I think i may have what is called browser hijacked - when i click on search results i get redirected to other sites. plus when i reboot, pop ups from spybot 'registry change denied' come up like crazy. i temp. disabled teatimer in spybot - not sure if that is safe or not.

log file below from HJT, first time posting so let me know if I did it right.

appreciate any help...thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:52:40 AM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\PurgeIE\PurgeIE_Service.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\Crusty.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O21 - SSODL: zip - {34ebdc45-8189-499a-b9cc-85ce7fd95910} - C:\WINDOWS\Installer\{34ebdc45-8189-499a-b9cc-85ce7fd95910}\zip.dll
O21 - SSODL: CDSetup - {93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa} - C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll
O21 - SSODL: UnknownSetup - {efc58e03-b427-4330-9406-518f8b398e81} - C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll
O21 - SSODL: RamKernel - {41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96} - C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll
O21 - SSODL: CheckAlrt - {8bf4d422-89d5-40d6-b85a-3629ec8333b6} - C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll
O21 - SSODL: ??p - {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll
O21 - SSODL: AvpUnknown - {366109dd-9da1-4683-891a-c58352d62fc6} - C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PurgeIE XP Service (PurgeIEservice) - Assistance & Resources for Computing, Inc. - C:\Program Files\PurgeIE\PurgeIE_Service.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 8695 bytes

BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:10:25 PM

Posted 09 February 2008 - 12:24 PM

Hello bug1965,

Welcome to Bleeping Computer :blink: Yes, please leave Tea Timer off for now. When we're done you can turn it back on and it should be all right. :thumbsup:

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 bug1965

bug1965
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 09 February 2008 - 12:40 PM

thanks tea, i hope you can help, been at this for 2 days on my own!

below are the logs..fyi, i have downloaded and run: ad-aware2007, combofix, purgeie, ccleaner, smitfraud, spybot, avg anti-spyware and vundofix (i think thats all) but to no avail...let me know if i did this right...

ComboFix 08-02.05.3 - REM 2008-02-09 12:29:17.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.571 [GMT -5:00]
Running from: C:\Documents and Settings\REM\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.

2008-02-08 16:37 . 2004-08-10 05:00 388,608 --a------ C:\kmd.exe
2008-02-08 11:23 . 2008-02-08 11:23 <DIR> d-------- C:\VundoFix Backups
2008-02-08 10:57 . 2008-02-08 11:04 2,806 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-08 10:46 . 2008-02-08 10:46 46,080 --a------ C:\Program Files\tmp39928203.exe
2008-02-08 10:46 . 2008-02-08 10:46 11,776 --a------ C:\Program Files\tmp39928046.exe
2008-02-08 10:46 . 2008-02-08 10:46 11,776 --a------ C:\Program Files\tmp39928015.exe
2008-02-08 10:46 . 2008-02-08 10:46 10,240 --a------ C:\Program Files\tmp39928187.exe
2008-02-08 10:46 . 2008-02-08 10:46 10,240 --a------ C:\Program Files\tmp39928078.exe
2008-02-08 08:51 . 2008-02-08 08:51 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-08 08:51 . 2008-02-08 08:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-08 08:37 . 2008-02-08 08:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-08 00:00 . 2008-02-08 08:34 <DIR> d-------- C:\Documents and Settings\REM\.housecall6.6
2008-02-07 23:51 . 2008-02-07 23:51 <DIR> d-------- C:\Program Files\CCleaner
2008-02-07 22:02 . 2008-02-07 22:02 <DIR> d-------- C:\Documents and Settings\REM\Application Data\Grisoft
2008-02-07 22:02 . 2008-02-07 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-07 22:02 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-07 20:18 . 2008-02-07 20:12 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-07 20:18 . 2008-02-07 20:18 3,442 --a------ C:\WINDOWS\unins000.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 21:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-08 15:55 --------- d-----w C:\Program Files\PurgeIE
2008-02-08 13:51 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-08 01:22 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-23 21:03 --------- d-----w C:\Documents and Settings\REM\Application Data\AdobeUM
2008-01-07 21:43 66,360 ----a-w C:\Documents and Settings\REM\Application Data\GDIPFONTCACHEV1.DAT
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-11-14 07:26 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-23 12:25 2,017,091 ----a-w C:\Program Files\aresregular209_installer.exe
2006-10-03 07:43 2,402,550 ----a-w C:\WINDOWS\inf\SET9F.tmp
2007-10-11 11:30 88 --sh--r C:\WINDOWS\system32\ED1FE13856.sys
2007-10-11 11:30 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 17:18 151552]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 17:29 303104]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 11:05 212992]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 14:49 1121280]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 09:26 110592]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49 163840]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 16:00 1005096]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 11:48 761947]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2005-03-07 23:42 176128]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"zip"= {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll [2008-02-08 00:42 39462]
"CDSetup"= {93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa} - C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll [2008-01-30 00:10 12838]
"UnknownSetup"= {efc58e03-b427-4330-9406-518f8b398e81} - C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll [2008-02-07 19:45 14374]
"RamKernel"= {41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96} - C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll [2008-02-07 22:52 14374]
"CheckAlrt"= {8bf4d422-89d5-40d6-b85a-3629ec8333b6} - C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll [2008-02-07 21:20 14374]
"??p"= {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll [2008-02-08 00:42 39462]
"AvpUnknown"= {366109dd-9da1-4683-891a-c58352d62fc6} - C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll [2008-02-08 07:19 14374]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 2003-05-29 10:00 8704 C:\WINDOWS\system32\PCANotify.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=C:\WINDOWS\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^REM^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=C:\Documents and Settings\REM\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=C:\WINDOWS\pss\Microsoft Find Fast.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^REM^Start Menu^Programs^Startup^Office Startup.lnk]
path=C:\Documents and Settings\REM\Start Menu\Programs\Startup\Office Startup.lnk
backup=C:\WINDOWS\pss\Office Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 2006-04-06 14:58 1032192 C:\Program Files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2005-05-15 02:04 332800 C:\Program Files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2004-12-06 01:05 127035 C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-12-09 20:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-09-29 14:01 67584 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmergencyAutoRun]
--a------ 2005-06-21 01:11 65644 C:\i3DVR_Remote\EmergencyMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2006-07-29 11:08 169984 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1173721191\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-11 22:12 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2005-03-07 23:42 176128 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-12-13 16:41 77824 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-12-13 16:45 118784 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-12-13 16:44 98304 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2005-12-28 11:56 602182 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 2005-12-28 11:55 667718 C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-06-10 10:44 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-06-10 10:44 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-10-30 09:36 256576 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechGalleryRepair]
--a------ 2002-12-10 17:32 155648 C:\Program Files\Logitech\ImageStudio\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
--a------ 2002-12-10 17:31 61440 C:\Program Files\Logitech\ImageStudio\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
--a------ 2002-12-10 16:54 127022 C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra------ 2006-01-30 11:00 98304 C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-10-25 18:58 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-10-24 16:10 4662776 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
S3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys [2002-12-10 16:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-09 16:48:51 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (REM-LAP-REM).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-09 12:31:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll
-> C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll
-> C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll
-> C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll
-> C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll
.
Completion time: 2008-02-09 12:31:47
ComboFix-quarantined-files.txt 2008-02-08 04:28:43
ComboFix2.txt 2008-02-08 21:41:13
ComboFix3.txt 2008-02-08 16:56:51
ComboFix4.txt 2008-02-08 04:28:52
ComboFix5.txt 2008-02-08 02:04:47
.
2008-01-10 14:37:30 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:38:08 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\PurgeIE\PurgeIE_Service.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\Crusty.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O21 - SSODL: zip - {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll
O21 - SSODL: CDSetup - {93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa} - C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll
O21 - SSODL: UnknownSetup - {efc58e03-b427-4330-9406-518f8b398e81} - C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll
O21 - SSODL: RamKernel - {41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96} - C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll
O21 - SSODL: CheckAlrt - {8bf4d422-89d5-40d6-b85a-3629ec8333b6} - C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll
O21 - SSODL: ??p - {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll
O21 - SSODL: AvpUnknown - {366109dd-9da1-4683-891a-c58352d62fc6} - C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PurgeIE XP Service (PurgeIEservice) - Assistance & Resources for Computing, Inc. - C:\Program Files\PurgeIE\PurgeIE_Service.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 8662 bytes

#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:10:25 PM

Posted 09 February 2008 - 02:55 PM

Hello,

Yes, you did it right.....but.....do you happen to have any of the other logs from ComboFix? It would help me immensely to be able to see what was originally deleted. :thumbsup:

Do you know what any of those 021 entries are? If not, I'd like to have them analyzed, please.

Navigate to the following files, one by one:
C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll
C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll
C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll
C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll
C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll
C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll

Please go to VirusTotal and submit the files for a scan, one by one, and post the results in your next reply.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 bug1965

bug1965
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 09 February 2008 - 04:19 PM

i don't know what those files are, results are below from virus total. attached 1 other combofix file i had saved as well. also have 5 tmp.exe files in my program files folder which i think are related, i delete them but they come back....thanks

ComboFix 08-02.05.3 - REM 2008-02-07 23:25:53.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.568 [GMT -5:00]
Running from: C:\Documents and Settings\REM\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.

2008-02-07 22:52 . 2008-02-07 22:52 10,240 --a------ C:\Program Files\tmp70734.exe
2008-02-07 22:52 . 2008-02-07 22:52 10,240 --a------ C:\Program Files\tmp70718.exe
2008-02-07 22:02 . 2008-02-07 22:02 <DIR> d-------- C:\Documents and Settings\REM\Application Data\Grisoft
2008-02-07 22:02 . 2008-02-07 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-07 22:02 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-07 21:02 . 2004-08-10 05:00 388,608 --a------ C:\kmd.exe
2008-02-07 20:18 . 2008-02-07 20:12 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-07 20:18 . 2008-02-07 20:18 3,442 --a------ C:\WINDOWS\unins000.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 02:56 --------- d-----w C:\Program Files\PurgeIE
2008-02-08 01:22 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-08 01:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-23 21:03 --------- d-----w C:\Documents and Settings\REM\Application Data\AdobeUM
2008-01-07 21:43 66,360 ----a-w C:\Documents and Settings\REM\Application Data\GDIPFONTCACHEV1.DAT
2007-11-14 07:26 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-23 12:25 2,017,091 ----a-w C:\Program Files\aresregular209_installer.exe
2006-10-03 07:43 2,402,550 ----a-w C:\WINDOWS\inf\SET9F.tmp
2007-10-11 11:30 88 --sh--r C:\WINDOWS\system32\ED1FE13856.sys
2007-10-11 11:30 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 17:18 151552]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 17:29 303104]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 11:05 212992]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 14:49 1121280]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 09:26 110592]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49 163840]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 16:00 1005096]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 11:48 761947]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2005-03-07 23:42 176128]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"zip"= {d76a3980-b185-4019-a28d-31d3ec857b34} - C:\WINDOWS\Installer\{d76a3980-b185-4019-a28d-31d3ec857b34}\zip.dll [2008-02-07 21:20 39462]
"CDSetup"= {93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa} - C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll [2008-01-30 00:10 12838]
"UnknownSetup"= {efc58e03-b427-4330-9406-518f8b398e81} - C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll [2008-02-07 19:45 14374]
"RamKernel"= {41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96} - C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll [2008-02-07 22:52 14374]
"CheckAlrt"= {8bf4d422-89d5-40d6-b85a-3629ec8333b6} - C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll [2008-02-07 21:20 14374]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 2003-05-29 10:00 8704 C:\WINDOWS\system32\PCANotify.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=C:\WINDOWS\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^REM^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=C:\Documents and Settings\REM\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=C:\WINDOWS\pss\Microsoft Find Fast.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^REM^Start Menu^Programs^Startup^Office Startup.lnk]
path=C:\Documents and Settings\REM\Start Menu\Programs\Startup\Office Startup.lnk
backup=C:\WINDOWS\pss\Office Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 2006-04-06 14:58 1032192 C:\Program Files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2005-05-15 02:04 332800 C:\Program Files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2004-12-06 01:05 127035 C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-12-09 20:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-09-29 14:01 67584 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmergencyAutoRun]
--a------ 2005-06-21 01:11 65644 C:\i3DVR_Remote\EmergencyMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2006-07-29 11:08 169984 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1173721191\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-11 22:12 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2005-03-07 23:42 176128 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-12-13 16:41 77824 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-12-13 16:45 118784 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-12-13 16:44 98304 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2005-12-28 11:56 602182 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 2005-12-28 11:55 667718 C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-06-10 10:44 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-06-10 10:44 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-10-30 09:36 256576 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechGalleryRepair]
--a------ 2002-12-10 17:32 155648 C:\Program Files\Logitech\ImageStudio\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
--a------ 2002-12-10 17:31 61440 C:\Program Files\Logitech\ImageStudio\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
--a------ 2002-12-10 16:54 127022 C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra------ 2006-01-30 11:00 98304 C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-10-25 18:58 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-10-24 16:10 4662776 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
S3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys [2002-12-10 16:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

*Newly Created Service* - AVGASCLN
.
Contents of the 'Scheduled Tasks' folder
"2008-02-08 03:52:18 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (REM-LAP-REM).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 23:28:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll
-> C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll
-> C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll
-> C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll
.
Completion time: 2008-02-07 23:28:51
ComboFix-quarantined-files.txt 2008-02-08 04:28:43
ComboFix2.txt 2008-02-08 02:04:47
ComboFix3.txt 2007-11-10 13:14:19
ComboFix4.txt 2007-10-19 23:15:14
.
2008-01-10 14:37:30 --- E O F ---


File zip.dll received on 02.09.2008 21:13:08 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.2.6.10 2008.02.05 -
AntiVir 7.6.0.62 2008.02.08 TR/Dldr.BHO.CM.1
Authentium 4.93.8 2008.02.08 -
Avast 4.7.1098.0 2008.02.09 -
AVG 7.5.0.516 2008.02.09 BHO.DCJ
BitDefender 7.2 2008.02.09 Trojan.Agent.AGUF
CAT-QuickHeal None 2008.02.08 -
ClamAV 0.92 2008.02.09 -
DrWeb 4.44.0.09170 2008.02.09 Trojan.Click.16450
eSafe 7.0.15.0 2008.01.28 Suspicious File
eTrust-Vet 31.3.5522 2008.02.08 Win32/VMalum.BVKA
Ewido 4.0 2008.02.09 -
FileAdvisor 1 2008.02.09 -
Fortinet 3.14.0.0 2008.02.09 -
F-Prot 4.4.2.54 2008.02.08 W32/Agent.Z.gen!Eldorado
F-Secure 6.70.13260.0 2008.02.09 W32/DLoader.dam
Ikarus T3.1.1.20 2008.02.09 Trojan-Clicker.Win32.Small.BG
Kaspersky 7.0.0.125 2008.02.09 Trojan-Downloader.Win32.BHO.cm
McAfee 5226 2008.02.08 Downloader.gen.a
Microsoft 1.3204 2008.02.09 Trojan:Win32/Agent.ZA
NOD32v2 2861 2008.02.09 -
Norman 5.80.02 2008.02.08 W32/DLoader.dam
Panda 9.0.0.4 2008.02.09 Trj/DNSChanger.AHD
Prevx1 V2 2008.02.09 E404Bho:Adware-b
Rising 20.29.22.00 2008.01.30 -
Sophos 4.26.0 2008.02.09 -
Sunbelt 2.2.907.0 2008.02.09 VIPRE.Suspicious
Symantec 10 2008.02.09 -
TheHacker 6.2.9.214 2008.02.09 Trojan/Downloader.BHO.cm
VBA32 3.12.6.0 2008.02.09 Trojan-Downloader.Win32.BHO.cm
VirusBuster 4.3.26:9 2008.02.09 Trojan.DL.BHO.GES
Webwasher-Gateway 6.6.2 2008.02.09 Trojan.Dldr.BHO.CM.1

Additional information
File size: 39462 bytes
MD5: c14ca97911c4e64f1b978695455e6e51
SHA1: 82e93a1757215fd7da0b84ae6021ad2aced239d3
PEiD: PECompact 2.xx --&gt; BitSum Technologies
packers: PecBundle, PECompact
packers: PE_Patch.PECompact, PecBundle, PECompact
Prevx info: http://info.prevx.com/aboutprogramtext.asp...254B600F764249B
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.

File CDSetup.dll received on 02.09.2008 21:26:56 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.2.6.10 2008.02.05 -
AntiVir 7.6.0.62 2008.02.08 TR/Agent.eld.1
Authentium 4.93.8 2008.02.08 -
Avast 4.7.1098.0 2008.02.09 -
AVG 7.5.0.516 2008.02.09 Agent.NLL
BitDefender 7.2 2008.02.09 Trojan.Downloader.Agent.ZAN
CAT-QuickHeal None 2008.02.08 Trojan.Agent.eld
ClamAV 0.92 2008.02.09 Trojan.Agent-12452
DrWeb 4.44.0.09170 2008.02.09 Trojan.Click.16772
eSafe 7.0.15.0 2008.01.28 Suspicious File
eTrust-Vet 31.3.5522 2008.02.08 -
Ewido 4.0 2008.02.09 -
FileAdvisor 1 2008.02.09 -
Fortinet 3.14.0.0 2008.02.09 -
F-Prot 4.4.2.54 2008.02.08 W32/Agent.Z.gen!Eldorado
F-Secure 6.70.13260.0 2008.02.09 W32/Agent.dam
Ikarus T3.1.1.20 2008.02.09 Trojan-Clicker.Win32.Small.BG
Kaspersky 7.0.0.125 2008.02.09 Trojan.Win32.Agent.eld
McAfee 5226 2008.02.08 Generic.dx
Microsoft 1.3204 2008.02.09 TrojanClicker:Win32/Zirit.A
NOD32v2 2861 2008.02.09 Win32/Agent.ELD
Norman 5.80.02 2008.02.08 W32/Agent.dam
Panda 9.0.0.4 2008.02.09 Suspicious file
Prevx1 V2 2008.02.09 Trojan.DoS.Win32.Opdos
Rising 20.29.22.00 2008.01.30 -
Sophos 4.26.0 2008.02.09 Mal/Heuri-E
Sunbelt 2.2.907.0 2008.02.09 VIPRE.Suspicious
Symantec 10 2008.02.09 -
TheHacker 6.2.9.214 2008.02.09 Trojan/Agent.eld
VBA32 3.12.6.0 2008.02.09 Trojan.Win32.Agent.eld
VirusBuster 4.3.26:9 2008.02.09 Trojan.CL.Zirit.A
Webwasher-Gateway 6.6.2 2008.02.09 Trojan.Agent.eld.1

Additional information
File size: 12838 bytes
MD5: 118dfe6879355ed116d278b87d469fba
SHA1: c26d84c0bcc12635cf5dcc31f4d9496fac7aa7d8
PEiD: PECompact 2.xx --&gt; BitSum Technologies
packers: PecBundle, PECompact
packers: PE_Patch.PECompact, PecBundle, PECompact
Prevx info: http://info.prevx.com/aboutprogramtext.asp...E9C790000CA3901
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.

File UnknownSetup.dll received on 02.09.2008 21:39:45 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.2.6.10 2008.02.05 -
AntiVir 7.6.0.62 2008.02.08 TR/Agent.evy
Authentium 4.93.8 2008.02.08 -
Avast 4.7.1098.0 2008.02.09 -
AVG 7.5.0.516 2008.02.09 Agent.NWL
BitDefender 7.2 2008.02.09 Trojan.Clicker.Small.YI
CAT-QuickHeal None 2008.02.08 -
ClamAV 0.92 2008.02.09 -
DrWeb 4.44.0.09170 2008.02.09 Trojan.Click.16987
eSafe 7.0.15.0 2008.01.28 Suspicious File
eTrust-Vet 31.3.5522 2008.02.08 -
Ewido 4.0 2008.02.09 -
FileAdvisor 1 2008.02.09 -
Fortinet 3.14.0.0 2008.02.09 -
F-Prot 4.4.2.54 2008.02.08 W32/Agent.Z.gen!Eldorado
F-Secure 6.70.13260.0 2008.02.09 W32/Agent.dam
Ikarus T3.1.1.20 2008.02.09 Trojan-Clicker.Win32.Small.BG
Kaspersky 7.0.0.125 2008.02.09 Trojan.Win32.Agent.evy
McAfee 5226 2008.02.08 Generic.dx
Microsoft 1.3204 2008.02.09 Trojan:Win32/Agent
NOD32v2 2861 2008.02.09 -
Norman 5.80.02 2008.02.08 W32/Agent.dam
Panda 9.0.0.4 2008.02.09 Trj/Agent.HYM
Prevx1 V2 2008.02.09 Backdoor.Trojan
Rising 20.29.22.00 2008.01.30 -
Sophos 4.26.0 2008.02.09 Mal/Heuri-E
Sunbelt 2.2.907.0 2008.02.09 VIPRE.Suspicious
Symantec 10 2008.02.09 Backdoor.Trojan
TheHacker 6.2.9.214 2008.02.09 Trojan/Agent.evy
VBA32 3.12.6.0 2008.02.09 Trojan.Win32.Agent.evy
VirusBuster 4.3.26:9 2008.02.09 -
Webwasher-Gateway 6.6.2 2008.02.09 Trojan.Agent.evy

Additional information
File size: 14374 bytes
MD5: e978da6959c26ede508e7ac494f8b7a2
SHA1: 412fc897439eced8b855447af164480ff885595d
PEiD: PECompact 2.xx --&gt; BitSum Technologies
packers: PecBundle, PECompact
packers: PE_Patch.PECompact, PecBundle, PECompact
Prevx info: http://info.prevx.com/aboutprogramtext.asp...7279200EB5F2946
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.

File RamKernel.dll received on 02.09.2008 21:51:49 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.2.6.10 2008.02.05 -
AntiVir 7.6.0.62 2008.02.08 TR/Agent.evy
Authentium 4.93.8 2008.02.08 -
Avast 4.7.1098.0 2008.02.09 -
AVG 7.5.0.516 2008.02.09 Agent.NWL
BitDefender 7.2 2008.02.09 Trojan.Clicker.Small.YI
CAT-QuickHeal None 2008.02.08 -
ClamAV 0.92 2008.02.09 -
DrWeb 4.44.0.09170 2008.02.09 Trojan.Click.16987
eSafe 7.0.15.0 2008.01.28 Suspicious File
eTrust-Vet 31.3.5522 2008.02.08 -
Ewido 4.0 2008.02.09 -
FileAdvisor 1 2008.02.09 -
Fortinet 3.14.0.0 2008.02.09 -
F-Prot 4.4.2.54 2008.02.08 W32/Agent.Z.gen!Eldorado
F-Secure 6.70.13260.0 2008.02.09 W32/Agent.dam
Ikarus T3.1.1.20 2008.02.09 Trojan-Clicker.Win32.Small.BG
Kaspersky 7.0.0.125 2008.02.09 Trojan.Win32.Agent.evy
McAfee 5226 2008.02.08 Generic.dx
Microsoft 1.3204 2008.02.09 Trojan:Win32/Agent
NOD32v2 2861 2008.02.09 -
Norman 5.80.02 2008.02.08 W32/Agent.dam
Panda 9.0.0.4 2008.02.09 Trj/Agent.HYM
Prevx1 V2 2008.02.09 Backdoor.Trojan
Rising 20.29.22.00 2008.01.30 -
Sophos 4.26.0 2008.02.09 Mal/Heuri-E
Sunbelt 2.2.907.0 2008.02.09 VIPRE.Suspicious
Symantec 10 2008.02.09 Backdoor.Trojan
TheHacker 6.2.9.214 2008.02.09 Trojan/Agent.evy
VBA32 3.12.6.0 2008.02.09 Trojan.Win32.Agent.evy
VirusBuster 4.3.26:9 2008.02.09 -
Webwasher-Gateway 6.6.2 2008.02.09 Trojan.Agent.evy

Additional information
File size: 14374 bytes
MD5: c41d17e14a000e5adf36e8452d07e0db
SHA1: 2d4af7949c70a871ae15e39772bea36bda19e8d0
PEiD: PECompact 2.xx --&gt; BitSum Technologies
packers: PecBundle, PECompact
packers: PE_Patch.PECompact, PecBundle, PECompact
Prevx info: http://info.prevx.com/aboutprogramtext.asp...8BCCA009BF0B21E
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.


File CheckAlrt.dll received on 02.09.2008 22:01:03 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.2.6.10 2008.02.05 -
AntiVir 7.6.0.62 2008.02.08 TR/Agent.evy
Authentium 4.93.8 2008.02.08 -
Avast 4.7.1098.0 2008.02.09 -
AVG 7.5.0.516 2008.02.09 Agent.NWL
BitDefender 7.2 2008.02.09 Trojan.Clicker.Small.YI
CAT-QuickHeal None 2008.02.08 -
ClamAV 0.92 2008.02.09 -
DrWeb 4.44.0.09170 2008.02.09 Trojan.Click.16987
eSafe 7.0.15.0 2008.01.28 Suspicious File
eTrust-Vet 31.3.5522 2008.02.08 -
Ewido 4.0 2008.02.09 -
FileAdvisor 1 2008.02.09 -
Fortinet 3.14.0.0 2008.02.09 -
F-Prot 4.4.2.54 2008.02.08 W32/Agent.Z.gen!Eldorado
F-Secure 6.70.13260.0 2008.02.09 W32/Agent.dam
Ikarus T3.1.1.20 2008.02.09 Trojan-Clicker.Win32.Small.BG
Kaspersky 7.0.0.125 2008.02.09 Trojan.Win32.Agent.evy
McAfee 5226 2008.02.08 Generic.dx
Microsoft 1.3204 2008.02.09 Trojan:Win32/Agent
NOD32v2 2861 2008.02.09 -
Norman 5.80.02 2008.02.08 W32/Agent.dam
Panda 9.0.0.4 2008.02.09 Trj/Agent.HYM
Prevx1 V2 2008.02.09 Backdoor.Trojan
Rising 20.29.22.00 2008.01.30 -
Sophos 4.26.0 2008.02.09 Mal/Heuri-E
Sunbelt 2.2.907.0 2008.02.09 VIPRE.Suspicious
Symantec 10 2008.02.09 Backdoor.Trojan
TheHacker 6.2.9.214 2008.02.09 Trojan/Agent.evy
VBA32 3.12.6.0 2008.02.09 Trojan.Win32.Agent.evy
VirusBuster 4.3.26:9 2008.02.09 -
Webwasher-Gateway 6.6.2 2008.02.09 Trojan.Agent.evy

Additional information
File size: 14374 bytes
MD5: 74a815d17de5b1957f75f049de7d1c4a
SHA1: 7c1c66b1edd4a660ded3d0b9dbc080edb799b9d0
PEiD: PECompact 2.xx --&gt; BitSum Technologies
packers: PecBundle, PECompact
packers: PE_Patch.PECompact, PecBundle, PECompact
Prevx info: http://info.prevx.com/aboutprogramtext.asp...C1364007AC41DB0
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.

File AvpUnknown.dll received on 02.09.2008 22:08:55 (CET)Antivirus Version Last Update Result
AhnLab-V3 2008.2.6.10 2008.02.05 -
AntiVir 7.6.0.62 2008.02.08 TR/Agent.evy
Authentium 4.93.8 2008.02.08 -
Avast 4.7.1098.0 2008.02.09 -
AVG 7.5.0.516 2008.02.09 Agent.NWL
BitDefender 7.2 2008.02.09 Trojan.Clicker.Small.YI
CAT-QuickHeal None 2008.02.08 -
ClamAV 0.92 2008.02.09 -
DrWeb 4.44.0.09170 2008.02.09 Trojan.Click.16987
eSafe 7.0.15.0 2008.01.28 Suspicious File
eTrust-Vet 31.3.5522 2008.02.08 -
Ewido 4.0 2008.02.09 -
FileAdvisor 1 2008.02.09 -
Fortinet 3.14.0.0 2008.02.09 -
F-Prot 4.4.2.54 2008.02.08 W32/Agent.Z.gen!Eldorado
F-Secure 6.70.13260.0 2008.02.09 W32/Agent.dam
Ikarus T3.1.1.20 2008.02.09 Trojan-Clicker.Win32.Small.BG
Kaspersky 7.0.0.125 2008.02.09 Trojan.Win32.Agent.evy
McAfee 5226 2008.02.08 Generic.dx
Microsoft 1.3204 2008.02.09 Trojan:Win32/Agent
NOD32v2 2861 2008.02.09 -
Norman 5.80.02 2008.02.08 W32/Agent.dam
Panda 9.0.0.4 2008.02.09 Trj/Agent.HYM
Prevx1 V2 2008.02.09 Backdoor.Trojan
Rising 20.29.22.00 2008.01.30 -
Sophos 4.26.0 2008.02.09 Mal/Heuri-E
Sunbelt 2.2.907.0 2008.02.09 VIPRE.Suspicious
Symantec 10 2008.02.09 Backdoor.Trojan
TheHacker 6.2.9.214 2008.02.09 Trojan/Agent.evy
VBA32 3.12.6.0 2008.02.09 Trojan.Win32.Agent.evy
VirusBuster 4.3.26:9 2008.02.09 -
Webwasher-Gateway 6.6.2 2008.02.09 Trojan.Agent.evy

Additional information
File size: 14374 bytes
MD5: 7c82cb32d4b8b9723dc8251eb4a77a73
SHA1: d3f59eb916cd9ba2c4ad5a6ed59eaf6cb8cdb394
PEiD: PECompact 2.xx --&gt; BitSum Technologies
packers: PecBundle, PECompact
packers: PE_Patch.PECompact, PecBundle, PECompact
Prevx info: http://info.prevx.com/aboutprogramtext.asp...FC79500A227C941
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.

#6 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:10:25 PM

Posted 09 February 2008 - 05:40 PM

Hello,

Thank you very much for that....indeed those are very nasty, so away with them!!

* Open notepad - don't use any other text editor than notepad or the script will fail.
Copy/paste the text in the quote box below into notepad:

Folder::
C:\WINDOWS\Installer


Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again.

After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Thanks
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#7 bug1965

bug1965
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 09 February 2008 - 06:12 PM

here u go...

ComboFix 08-02.05.3 - REM 2008-02-09 17:55:26.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.382 [GMT -5:00]
Running from: C:\Documents and Settings\REM\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\REM\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Installer
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_00C13C7C67114FA9BA82279FC250D0AB
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_054261CBD8C94C6D8817D656CC1A033D
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_055CC35A33A54307B9E34233F6AA8FDE
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_05FD48E7D048497F8FA3DACBBA8F2E94
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_09AADA6A9C9C4D2DA5929E3DE93F8BC0
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_0CC53324FD8443ECB1124A95E47804C1
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_0FEB4E46D0B44242BCDA6AC742F48298
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_1467C91E743347009F419C1BD8AB8B20
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_1622E18DC25D4179B222636610C86DA9
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_1C9BA74BA8D94CF59492BC9B18E49076
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_21F756BD14D64449A7EA94A0E6D041A9
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_226DD5FE8D164008B3C38FFFC5807E61
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_282A312589114655B587454816638481
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_321A67A25EE6450F9914577B2AF12F0C
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_327659160E1D4AE5848A638DABFD66BA
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_3B690D4FE21F435EA11220392FC1DAEC
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_3C7EADE98C834720A4C580BF31CDE1CE
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_3D65530D315E4A76B7C3CE8A1A5E23FC
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_4B878F4DC65D4C72AAFAE0D3E33008A5
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_4D43F3EB9AE148A983A2D0F016C4BAD9
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_5093DAD313334B3498E91B98E06E13CE
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_55CC1B27AFEC4745A1FCB0E6CA58EB93
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_55F309F4EEB448C4A4D22DC3D099F9FF
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_5BC0D38AA94044EF92C3E94FCEAE5835
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_5C1C817FE9BF4BE192C5AE25C376BFF0
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_662ED7947F73408F9E2224E5F866A782
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_68283BC2EEF740CDB71675829EE73FB0
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_6C1B50C6B9624EF8B93F3A88CF9DA9FF
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_6CA1A513F3F846159016B308F3E641F6
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_6ECA508392414D72BDEDECD4E33A3657
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_790506C5C97A49D59F013E6FB5A0E407
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_7A0AF66CB33E466C851FBDAD219CD85D
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_7A3E9B15D3DD480B954F5E9533F10B41
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_7DEC773A86AE4D339CC1A5A99E663F98
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_828277CF302F4820A8A3004862209C88
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_85651684E8A24E9AB919E3FA4C0AA112
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_878CA147D88944B98066DA33E2ED63D6
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_9063516667C34F18B9BB2A5D15B40C2D
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_91AD4895F9584B3FA096511C17427738
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_93674861B5754C14A1A520B03DF8B4E6
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_99418C89F31C42018C22205B4DFBEA17
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_9BEC69E88EC14425BB164001EC568290
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_9C0DD5B2974B42FCBC1C66069F59E010
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_A19CDD3475C6443FA262803F3007817E
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_A4C5D62BF31C4B19860E6F761D3A1B12
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_A72AB81453E94BEA94588D40D2B29CBB
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_A896F43ED9344361B157C440EC26CAD5
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_A99669BE65C04184AC4D033CCE4FC929
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_AA7EAD5F684C453B91B0D1AF3BDF0660
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_B22B0951255F4434880A48D12FB033BE
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_B3CBE0B21F7C4CF9BE8A469B3783846F
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_BA393A838FEB4A29BC6C826FE51EC85F
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_C27222CAE0614295BA6CE64266BD998B
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_C3E37940E13A4A49B39554EAEC124111
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_CCEEB3983DFC4892B119592C77FD590F
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_CE4A70BBD5D247D584404433615207B8
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_CEDCD8CC731643C19D7D2BA4916FA149
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_CEF71506CD9542A28EC0A877A4FE6631
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_D305DB00FCC943C19C9F26CCA98E91E9
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_D7E543274D44466DA9D464247C80A12B
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_D94839D142884D8BBDB9AC7F9D9F363D
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_DCFB381FF19D4548B922F672EDA3C89A
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_E2E467414C8445FD874064D33FF3B548
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_E50B58F36C064A31A54661B4F1AC898C
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_EE5983EFF76946D2897FFEC8415C78E7
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_F6AF488A2A404F62A5A3E94A860AA6C8
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\_FBC6E63921EE4BD8ABAF9E296A76D026
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\albumreleasenotes.htm
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\apprc.dll7
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\comm32.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\commsti.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\convertrc.dll7
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\corel_photo_album_6.scr
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\cpascrrc6.dll7
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\fpxig.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\igcore14d.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\igfpx14d.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\igjpeg2k14d.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\iglzw14d.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\jpegacc.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\kodakgallery.com.url
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\license.rtf
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\mediadetect.exe
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\mediadetectrc.dll7
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\movieprojector.exe
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\movprojrc.dll7
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\ofoto.photoservice1
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\photo_album_6.exe
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\player.exe
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\playerrc.dll7
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\psikey.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\pspa.exe
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\qt.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\readme.html
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\reg.exe
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\scandrv.exe
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\scandrvrc.dll7
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\splithtml.exe
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\6.0.0\stitch.dll
C:\WINDOWS\Installer\$PatchCache$\Managed\8418B9A87DDDF844DBC65338683D3245\CacheSize.txt
C:\WINDOWS\Installer\{075473F5-846A-448B-BCB3-104AA1760205}\1033.MST
C:\WINDOWS\Installer\{075473F5-846A-448B-BCB3-104AA1760205}\MediaHub.exe
C:\WINDOWS\Installer\{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}\PS2Trial.Exe
C:\WINDOWS\Installer\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}\1033.MST
C:\WINDOWS\Installer\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}\ARPIcon.exe
C:\WINDOWS\Installer\{15EE79F4-4ED1-4267-9B0F-351009325D7D}\1033.mst
C:\WINDOWS\Installer\{15EE79F4-4ED1-4267-9B0F-351009325D7D}\HPSUShortcut2_936C42D08CEE4BDFB8CEC4BDC93C6CF8_1.exe
C:\WINDOWS\Installer\{21657574-BD54-48A2-9450-EB03B2C7FC29}\1033.MST
C:\WINDOWS\Installer\{21657574-BD54-48A2-9450-EB03B2C7FC29}\MediaHub.exe
C:\WINDOWS\Installer\{21657574-BD54-48A2-9450-EB03B2C7FC29}\MyDVDRel60.exe
C:\WINDOWS\Installer\{26E1BFB0-E87E-4696-9F89-B467F01F81E5}\1033.MST
C:\WINDOWS\Installer\{26E1BFB0-E87E-4696-9F89-B467F01F81E5}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{26E1BFB0-E87E-4696-9F89-B467F01F81E5}\NewShortcut1_058B32E263104359B2D41988390C3B83.exe
C:\WINDOWS\Installer\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}\1033.MST
C:\WINDOWS\Installer\{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}\NewShortcut1.A6CC6977_F7B4_4C0B_9510_BCD847D4BDB2.exe
C:\WINDOWS\Installer\{34ebdc45-8189-499a-b9cc-85ce7fd95910}\zip.dll
C:\WINDOWS\Installer\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe
C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll
C:\WINDOWS\Installer\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}\icon.exe
C:\WINDOWS\Installer\{3F4EC965-28EF-45C3-B063-04B25D4E9679}\1033.MST
C:\WINDOWS\Installer\{3F4EC965-28EF-45C3-B063-04B25D4E9679}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll
C:\WINDOWS\Installer\{446DBFFA-4088-48E3-8932-74316BA4CAE4}\Installer.ico
C:\WINDOWS\Installer\{446DBFFA-4088-48E3-8932-74316BA4CAE4}\iTunesIco.exe
C:\WINDOWS\Installer\{446DBFFA-4088-48E3-8932-74316BA4CAE4}\RichText.ico
C:\WINDOWS\Installer\{4667B940-BB01-428B-986E-A0CC46497BF7}\NewShortcut1.exe
C:\WINDOWS\Installer\{4781569D-5404-1F26-4B2B-6DF444441031}\1033.mst
C:\WINDOWS\Installer\{4781569D-5404-1F26-4B2B-6DF444441031}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{50D8FFDD-90CD-4859-841F-AA1961C7767A}\Installer.ico
C:\WINDOWS\Installer\{50D8FFDD-90CD-4859-841F-AA1961C7767A}\PictureViewer.ico
C:\WINDOWS\Installer\{50D8FFDD-90CD-4859-841F-AA1961C7767A}\QTPlayer.ico
C:\WINDOWS\Installer\{50D8FFDD-90CD-4859-841F-AA1961C7767A}\QTUninstaller.ico
C:\WINDOWS\Installer\{50D8FFDD-90CD-4859-841F-AA1961C7767A}\RichText.ico
C:\WINDOWS\Installer\{52D56C42-8C69-4882-A661-39695537C9CF}\1033.MST
C:\WINDOWS\Installer\{52D56C42-8C69-4882-A661-39695537C9CF}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{52D56C42-8C69-4882-A661-39695537C9CF}\StartProgramAppSC_B017CB0539454256B841A052DAF77A8F.exe
C:\WINDOWS\Installer\{548EEA8E-8299-497F-8057-811D2D7097DC}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{548EEA8E-8299-497F-8057-811D2D7097DC}\NewShortcut4_4CBB1976C0944FA38ACF3C143BEB09D5.exe
C:\WINDOWS\Installer\{548EEA8E-8299-497F-8057-811D2D7097DC}\NewShortcut6_5FF0011DF81244E5B74356CDA2D3FA3D_1.exe
C:\WINDOWS\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
C:\WINDOWS\Installer\{5A24DD7E-7B01-41AC-ADA8-F1776177A3BA}\MainApp.exe
C:\WINDOWS\Installer\{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}\NewShortcut1.exe
C:\WINDOWS\Installer\{664b82b3-2c47-454b-9644-3a8f6e0a39ef}\zip.dll
C:\WINDOWS\Installer\{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}\NewShortcut1.exe
C:\WINDOWS\Installer\{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}\PlusIcon
C:\WINDOWS\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142030}\1033.MST
C:\WINDOWS\Installer\{74F7662C-B1DB-489E-A8AC-07A06B24978B}\1033.MST
C:\WINDOWS\Installer\{89135fdd-b931-486e-9ad2-c39e9b5f8bc6}\zip.dll
C:\WINDOWS\Installer\{8A9B8148-DDD7-448F-BD6C-358386D32354}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{8A9B8148-DDD7-448F-BD6C-358386D32354}\NewShortcut1_8A9B8148DDD7448FBD6C358386D32354.exe
C:\WINDOWS\Installer\{8A9B8148-DDD7-448F-BD6C-358386D32354}\NewShortcut2_8A9B8148DDD7448FBD6C358386D32354.exe
C:\WINDOWS\Installer\{8A9B8148-DDD7-448F-BD6C-358386D32354}\NewShortcut3_928F762215294C13AD31D1888867DB93.exe
C:\WINDOWS\Installer\{8A9B8148-DDD7-448F-BD6C-358386D32354}\NewShortcut7_8A9B8148DDD7448FBD6C358386D32354.exe
C:\WINDOWS\Installer\{8A9B8148-DDD7-448F-BD6C-358386D32354}\Shortcut0.C3A146F5_4B48_11D5_A819_00B0D0428C0C.exe
C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll
C:\WINDOWS\Installer\{8f0c5e3e-450d-4ae5-aa13-76e89d14da0b}\zip.dll
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\graph.ico
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\misc.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\outicon.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\pptico.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
C:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll
C:\WINDOWS\Installer\{A683A2C0-821C-486F-858C-FA634DB5E864}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{A683A2C0-821C-486F-858C-FA634DB5E864}\NewShortcut1.html
C:\WINDOWS\Installer\{A683A2C0-821C-486F-858C-FA634DB5E864}\NewShortcut2.html
C:\WINDOWS\Installer\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}\1033.MST
C:\WINDOWS\Installer\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}\MediaHub.exe
C:\WINDOWS\Installer\{AC76BA86-0000-0000-0000-6028747ADE01}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\FDFFile.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\PDFFile.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\PDXFile.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\PRINTME_DOWNLOAD.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\Rdr60.mst
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\Rdr60ENU.mst
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\RMFFile.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\SC_Reader_DT.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\SC_Reader_DTX.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\SC_Reader_PM.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\SC_Reader_PMX.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\XDPFile.ico
C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A00000000001}\XFDFile.ico
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\CARMOrganizer.exe
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\ClipBkShortcut.exe
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\CompatibilityHelp.ICO
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\Help.ICO
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\PRShortcut.exe
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\QPWShortcut.exe
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\RegisterShortcutHomeEdition.exe
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\TechSuppShortcut.ico
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\UAShortcut.exe
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\UserGuide.ico
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\UserGuideHomeEdition.ico
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\WPShortcut.exe
C:\WINDOWS\Installer\{AF19F291-F22F-4798-9662-525305AE9E48}\WPShortcutDesktop_AF19F291F22F47989662525305AE9E48.hta
C:\WINDOWS\Installer\{B0DF58A2-40DF-4465-AA56-38623EC9938C}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{B0DF58A2-40DF-4465-AA56-38623EC9938C}\NewShortcut1_B0DF58A240DF4465AA5638623EC9938C.exe
C:\WINDOWS\Installer\{B0DF58A2-40DF-4465-AA56-38623EC9938C}\NewShortcut11_759E0B26521F4666BEAF33B31123216E.exe
C:\WINDOWS\Installer\{B12665F4-4E93-4AB4-B7FC-37053B524629}\1033.MST
C:\WINDOWS\Installer\{B12665F4-4E93-4AB4-B7FC-37053B524629}\MediaHub.exe
C:\WINDOWS\Installer\{B6884A07-0305-47AE-9969-8F26FADC17DE}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{B6884A07-0305-47AE-9969-8F26FADC17DE}\NewShortcut1_B6884A07030547AE99698F26FADC17DE.exe
C:\WINDOWS\Installer\{B6884A07-0305-47AE-9969-8F26FADC17DE}\NewShortcut11_B6884A07030547AE99698F26FADC17DE.exe
C:\WINDOWS\Installer\{C04E32E0-0416-434D-AFB9-6969D703A9EF}\icon.exe
C:\WINDOWS\Installer\{d76a3980-b185-4019-a28d-31d3ec857b34}\zip.dll
C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\_251AC6AA_CBAD_43F2_B583_EB7A23989C72
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\ARPPRODUCTICON.exe
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\BeHostFile.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\CallerFile.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\HostAdminSnapIn.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\pcACommandQueFile.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\pcAScreenFile.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\pcASidFile.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\pcAThinHostConfigFile.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\RAPSDataFile.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\RAPSStartMenuShortcut.ico
C:\WINDOWS\Installer\{E05E8183-866A-11D3-97DF-0000F8D8F2E9}\RemoteCtrlFile.ico
C:\WINDOWS\Installer\{EA103B64-C0E4-4C0E-A506-751590E1653D}\Shortcut_start.9FAB98ED_2143_4534_9750_7CD4ECEB9596.exe
C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll
C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll
C:\WINDOWS\Installer\11adc.msi
C:\WINDOWS\Installer\11ae2.msi
C:\WINDOWS\Installer\11ae8.msi
C:\WINDOWS\Installer\11aee.msi
C:\WINDOWS\Installer\11af4.msi
C:\WINDOWS\Installer\11afa.msi
C:\WINDOWS\Installer\11b00.msi
C:\WINDOWS\Installer\11b06.msi
C:\WINDOWS\Installer\11b0c.msi
C:\WINDOWS\Installer\11b12.msi
C:\WINDOWS\Installer\11b18.msi
C:\WINDOWS\Installer\11b1e.msi
C:\WINDOWS\Installer\11b24.msi
C:\WINDOWS\Installer\11b2a.msi
C:\WINDOWS\Installer\11b30.msi
C:\WINDOWS\Installer\11b37.msi
C:\WINDOWS\Installer\11b3d.msi
C:\WINDOWS\Installer\141df00.msi
C:\WINDOWS\Installer\152e9d.msi
C:\WINDOWS\Installer\152ea2.msi
C:\WINDOWS\Installer\17d221de.msi
C:\WINDOWS\Installer\1a5ea.msi
C:\WINDOWS\Installer\1a5fb.msi
C:\WINDOWS\Installer\1a605.msi
C:\WINDOWS\Installer\1b536.msi
C:\WINDOWS\Installer\1b542.msi
C:\WINDOWS\Installer\1b54b.msi
C:\WINDOWS\Installer\1b551.msi
C:\WINDOWS\Installer\1b556.msi
C:\WINDOWS\Installer\1b55b.msi
C:\WINDOWS\Installer\1b560.msi
C:\WINDOWS\Installer\1b565.msi
C:\WINDOWS\Installer\1b56b.msi
C:\WINDOWS\Installer\1b576.msi
C:\WINDOWS\Installer\1b57c.msi
C:\WINDOWS\Installer\1b582.msi
C:\WINDOWS\Installer\1b588.msi
C:\WINDOWS\Installer\1b58e.msi
C:\WINDOWS\Installer\1b59e.msi
C:\WINDOWS\Installer\1b5a9.msi
C:\WINDOWS\Installer\1b5ae.msi
C:\WINDOWS\Installer\1b5d8.msi
C:\WINDOWS\Installer\1b5dd.msi
C:\WINDOWS\Installer\1b5e6.msi
C:\WINDOWS\Installer\1b686.msp
C:\WINDOWS\Installer\1b718.msp
C:\WINDOWS\Installer\1b71d.msi
C:\WINDOWS\Installer\1b727.msi
C:\WINDOWS\Installer\1cf7b115.msp
C:\WINDOWS\Installer\1f7a983.msi
C:\WINDOWS\Installer\29ef52a.msi
C:\WINDOWS\Installer\376b0b4.msi
C:\WINDOWS\Installer\377d2ef.msp
C:\WINDOWS\Installer\377d333.msp
C:\WINDOWS\Installer\39ec9b.msi
C:\WINDOWS\Installer\3bc065b.msi
C:\WINDOWS\Installer\42e8eb.msi
C:\WINDOWS\Installer\5234f250.msi
C:\WINDOWS\Installer\759dc.msi
C:\WINDOWS\Installer\8bab.msi
C:\WINDOWS\Installer\97527f2.msp
C:\WINDOWS\Installer\c68ab.msi
C:\WINDOWS\Installer\e321.msi
C:\WINDOWS\Installer\f1bbc1e.msi
C:\WINDOWS\Installer\f1bbc24.msi
C:\WINDOWS\Installer\f1bbc2b.msi
C:\WINDOWS\Installer\f1bbc31.msi
C:\WINDOWS\Installer\f1bbc37.msi
C:\WINDOWS\Installer\f1bbc3e.msi
C:\WINDOWS\Installer\f1bbc44.msi
C:\WINDOWS\Installer\f1bbc4a.msi
C:\WINDOWS\Installer\f1bbc50.msi
C:\WINDOWS\Installer\f1bbc56.msi
C:\WINDOWS\Installer\f1bbc5c.msi
C:\WINDOWS\Installer\f1bbc63.msi
C:\WINDOWS\Installer\f1bbc69.msi
C:\WINDOWS\Installer\f1bbc6f.msi
C:\WINDOWS\Installer\f1bbc76.msi
C:\WINDOWS\Installer\f1bbc7c.msi
C:\WINDOWS\Installer\f1bbc8a.msi
C:\WINDOWS\Installer\f1bbc91.msi
C:\WINDOWS\Installer\f1bbc98.msi
C:\WINDOWS\Installer\f1bbc9e.msi
C:\WINDOWS\Installer\f1bbca4.msi
C:\WINDOWS\Installer\f1bbcaa.msi
C:\WINDOWS\Installer\f1bbcb1.msi
C:\WINDOWS\Installer\f1bbcb7.msi
C:\WINDOWS\Installer\f1bbcbe.msi
C:\WINDOWS\Installer\f1bbcc4.msi
C:\WINDOWS\Installer\f1bbcca.msi
C:\WINDOWS\Installer\iProData\iconvrtr.exe
C:\WINDOWS\Installer\iProData\mCore.msi
C:\WINDOWS\Installer\iProData\mDriver.msi
C:\WINDOWS\Installer\iProData\mDrWiFi.msi
C:\WINDOWS\Installer\iProData\mEOU.msi
C:\WINDOWS\Installer\iProData\mGina.msi
C:\WINDOWS\Installer\iProData\mHlpDell.msi
C:\WINDOWS\Installer\iProData\mIWA.msi
C:\WINDOWS\Installer\iProData\mLogView.msi
C:\WINDOWS\Installer\iProData\mMHouse.msi
C:\WINDOWS\Installer\iProData\mPfMgr.msi
C:\WINDOWS\Installer\iProData\mPfWiz.msi
C:\WINDOWS\Installer\iProData\mProSafe.msi
C:\WINDOWS\Installer\iProData\mSDK.msi
C:\WINDOWS\Installer\iProData\mSSO.msi
C:\WINDOWS\Installer\iProData\mToolkit.msi
C:\WINDOWS\Installer\iProData\mTrace.msi
C:\WINDOWS\Installer\iProData\mWlsSafe.msi
C:\WINDOWS\Installer\iProData\mWMI.msi
C:\WINDOWS\Installer\iProData\mXML.msi
C:\WINDOWS\Installer\iProData\mZConfig.msi
C:\WINDOWS\Installer\iProData\verfile.tic
C:\WINDOWS\Installer\iProInst.bmp
C:\WINDOWS\Installer\iProInst.exe
C:\WINDOWS\Installer\MSN Messenger 8.1.0178\MsnMsgs.Msi

.
((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.

2008-02-09 12:28 . 2004-08-10 05:00 388,608 --a------ C:\kmd.exe
2008-02-08 11:23 . 2008-02-08 11:23 <DIR> d-------- C:\VundoFix Backups
2008-02-08 10:57 . 2008-02-08 11:04 2,806 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-08 08:51 . 2008-02-08 08:51 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-08 08:51 . 2008-02-08 08:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-08 08:37 . 2008-02-08 08:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-08 00:00 . 2008-02-08 08:34 <DIR> d-------- C:\Documents and Settings\REM\.housecall6.6
2008-02-07 23:51 . 2008-02-07 23:51 <DIR> d-------- C:\Program Files\CCleaner
2008-02-07 22:02 . 2008-02-07 22:02 <DIR> d-------- C:\Documents and Settings\REM\Application Data\Grisoft
2008-02-07 22:02 . 2008-02-07 22:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-07 22:02 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-07 20:18 . 2008-02-07 20:12 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-07 20:18 . 2008-02-07 20:18 3,442 --a------ C:\WINDOWS\unins000.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 21:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-08 15:55 --------- d-----w C:\Program Files\PurgeIE
2008-02-08 13:51 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-08 01:22 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-23 21:03 --------- d-----w C:\Documents and Settings\REM\Application Data\AdobeUM
2008-01-07 21:43 66,360 ----a-w C:\Documents and Settings\REM\Application Data\GDIPFONTCACHEV1.DAT
2007-12-14 16:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-11-14 07:26 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-23 12:25 2,017,091 ----a-w C:\Program Files\aresregular209_installer.exe
2006-10-03 07:43 2,402,550 ----a-w C:\WINDOWS\inf\SET9F.tmp
2007-10-11 11:30 88 --sh--r C:\WINDOWS\system32\ED1FE13856.sys
2007-10-11 11:30 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 17:18 151552]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 17:29 303104]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 11:05 212992]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 14:49 1121280]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 09:26 110592]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49 163840]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 16:00 1005096]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 11:48 761947]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2005-03-07 23:42 176128]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"zip"= {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll [ ]
"CDSetup"= {93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa} - C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll [ ]
"UnknownSetup"= {efc58e03-b427-4330-9406-518f8b398e81} - C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll [ ]
"RamKernel"= {41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96} - C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll [ ]
"CheckAlrt"= {8bf4d422-89d5-40d6-b85a-3629ec8333b6} - C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll [ ]
"??p"= {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll [ ]
"AvpUnknown"= {366109dd-9da1-4683-891a-c58352d62fc6} - C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll 2003-05-29 10:00 8704 C:\WINDOWS\system32\PCANotify.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=C:\WINDOWS\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^REM^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=C:\Documents and Settings\REM\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=C:\WINDOWS\pss\Microsoft Find Fast.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^REM^Start Menu^Programs^Startup^Office Startup.lnk]
path=C:\Documents and Settings\REM\Start Menu\Programs\Startup\Office Startup.lnk
backup=C:\WINDOWS\pss\Office Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 2006-04-06 14:58 1032192 C:\Program Files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2005-05-15 02:04 332800 C:\Program Files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2004-12-06 01:05 127035 C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-12-09 20:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-09-29 14:01 67584 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmergencyAutoRun]
--a------ 2005-06-21 01:11 65644 C:\i3DVR_Remote\EmergencyMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2006-07-29 11:08 169984 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1173721191\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-11 22:12 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2005-03-07 23:42 176128 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-12-13 16:41 77824 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-12-13 16:45 118784 C:\WINDOWS\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-12-13 16:44 98304 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2005-12-28 11:56 602182 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 2005-12-28 11:55 667718 C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-06-10 10:44 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-06-10 10:44 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-10-30 09:36 256576 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechGalleryRepair]
--a------ 2002-12-10 17:32 155648 C:\Program Files\Logitech\ImageStudio\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
--a------ 2002-12-10 17:31 61440 C:\Program Files\Logitech\ImageStudio\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMS]
--a------ 2002-12-10 16:54 127022 C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra------ 2006-01-30 11:00 98304 C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-10-25 18:58 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-10-24 16:10 4662776 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
S3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys [2002-12-10 16:53]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-09 16:48:51 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (REM-LAP-REM).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-09 17:58:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-09 17:59:06
ComboFix-quarantined-files.txt 2008-02-09 22:58:58
ComboFix2.txt 2008-02-09 17:31:48
ComboFix3.txt 2008-02-08 21:41:13
ComboFix4.txt 2008-02-08 16:56:51
ComboFix5.txt 2008-02-08 04:28:52
.
2008-01-10 14:37:30 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:06:04 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\PurgeIE\PurgeIE_Service.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\REM\LOCALS~1\Temp\sysserver.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\Crusty.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O21 - SSODL: zip - {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll (file missing)
O21 - SSODL: CDSetup - {93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa} - C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll (file missing)
O21 - SSODL: UnknownSetup - {efc58e03-b427-4330-9406-518f8b398e81} - C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll (file missing)
O21 - SSODL: RamKernel - {41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96} - C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll (file missing)
O21 - SSODL: CheckAlrt - {8bf4d422-89d5-40d6-b85a-3629ec8333b6} - C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll (file missing)
O21 - SSODL: ??p - {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll (file missing)
O21 - SSODL: AvpUnknown - {366109dd-9da1-4683-891a-c58352d62fc6} - C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PurgeIE XP Service (PurgeIEservice) - Assistance & Resources for Computing, Inc. - C:\Program Files\PurgeIE\PurgeIE_Service.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 8729 bytes

#8 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:10:25 PM

Posted 11 February 2008 - 03:31 PM

Hello,

Hope you had a great weekend. :blink:

Please run HijackThis! and click "Scan." Place checks next to the following entries, if present:

O21 - SSODL: zip - {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll (file missing)
O21 - SSODL: CDSetup - {93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa} - C:\WINDOWS\Installer\{93f12e8d-e6f4-4e2e-94aa-51f8f84e90fa}\CDSetup.dll (file missing)
O21 - SSODL: UnknownSetup - {efc58e03-b427-4330-9406-518f8b398e81} - C:\WINDOWS\Installer\{efc58e03-b427-4330-9406-518f8b398e81}\UnknownSetup.dll (file missing)
O21 - SSODL: RamKernel - {41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96} - C:\WINDOWS\Installer\{41d00c2c-82c7-4f2e-bdfa-a7c2d301ed96}\RamKernel.dll (file missing)
O21 - SSODL: CheckAlrt - {8bf4d422-89d5-40d6-b85a-3629ec8333b6} - C:\WINDOWS\Installer\{8bf4d422-89d5-40d6-b85a-3629ec8333b6}\CheckAlrt.dll (file missing)
O21 - SSODL: ??p - {f0389420-d173-432b-9098-6ab9d20f1ab8} - C:\WINDOWS\Installer\{f0389420-d173-432b-9098-6ab9d20f1ab8}\zip.dll (file missing)
O21 - SSODL: AvpUnknown - {366109dd-9da1-4683-891a-c58352d62fc6} - C:\WINDOWS\Installer\{366109dd-9da1-4683-891a-c58352d62fc6}\AvpUnknown.dll (file missing)


Close all browsers and other windows except for HijackThis!, and click "Fix checked".

Reboot your computer.

Your Java is way out of date, which leaves your computer vulnerable.

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 6u4.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.
In your reply, please let me know how your computer is running now and post a new HijackThis log. :thumbsup:

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users