Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Trojan.win32.vapsup.eie And Trojan-downloaderwin32


  • Please log in to reply
11 replies to this topic

#1 kuebd

kuebd

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:01 AM

Posted 03 May 2008 - 07:53 AM

Hi,
Seems to be a common thread and one that I thank you in advance for helping me to resolve.
Inundated with pop ups that are not detected or able to be deleted by Trend micro PCcillin .

My system is sluggish no make that down right slow, particularly when connect to the internet and I recieve all of the following:
Generic pop ups and system warnings
System integrity scan wizard pop up
Security warning WormWin32.Netbooster pop up
Desktop shotcuts to error cleaner, privacy protector and spyware malware protection all pointing to URL //viruswebprotect.com.shandler.php?
Task manager is disabled
Internet explorer home page changed to www.softwarereferral.com as well as trying to download other pages which Trend designate as bad web pages.
i.e. www. safenavweb.com and //209.9.170.172/jump....

Please find below DSS and Kaspersky scans.

I appreciate you time and efforts to help someone that is not that great with computers but can follow instructions.
Many thanks
Kuebd

Deckard's System Scanner v20071014.68
Run by Ken on 2008-05-03 13:16:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 2 Restore Point(s) --
2: 2008-05-03 03:16:56 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-05-03 03:09:55 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 78% (more than 75%).


-- HijackThis (run as Ken.exe) -------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:19:30 PM, on 3/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Documents and Settings\All Users\Application Data\bqrsvarw\lmxovqzk.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Telstra\Cable Login\bpcable.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\mjcringd.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\Program Files\Telstra\Cable Login\bpcService.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Documents and Settings\Ken\Desktop\dss.exe
C:\Program Files\Java\jre1.6.0_04\bin\jucheck.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Ken.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=Explorer.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: DVA Gate - {DDFF8B71-EF58-4922-ACF2-2003FE2B7481} - C:\WINDOWS\gndarmblvpg.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: wxdbpfvo - {DDA28099-DACF-415D-A5A8-BB134FCA3D6A} - C:\WINDOWS\wxdbpfvo.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [cxjxjw] c:\windows\system32\cxjxjw.exe
O4 - HKLM\..\Run: [BigPondCable] "C:\Program Files\Telstra\Cable Login\bpcable.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [mdgcdqte] C:\WINDOWS\system32\mjcringd.exe
O4 - HKLM\..\Policies\Explorer\Run: [jdMqsGvcMM] C:\Documents and Settings\All Users\Application Data\bqrsvarw\lmxovqzk.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178534350187
O18 - Filter hijack: text/html - {47828676-D1BF-451C-932B-7C476901E98E} - (no file)
O21 - SSODL: bdkpfxqw - {CE23FA0F-A6BC-4E40-BA27-E56A4697815D} - C:\WINDOWS\bdkpfxqw.dll
O21 - SSODL: qadovnel - {1C800429-D278-4123-A771-71B437C9EFFD} - C:\WINDOWS\qadovnel.dll
O23 - Service: BigPond Broadband Cable Login (bpcService) - Unknown owner - C:\Program Files\Telstra\Cable Login\bpcService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O24 - Desktop Component 0: (no name) - http://cybernet.m7z.net/www.cybernetentert.../i/h/200//9.jpg
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/Ken/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 10964 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080430-234111-747 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD7>
R3 asapiW2k - c:\windows\system32\drivers\asapiw2k.sys <Not Verified; VOB Computersysteme GmbH; asapi>
R3 dvd43llh - c:\windows\system32\drivers\dvd43llh.sys <Not Verified; RIF; DVD For Free>
R3 Pcouffin (Low level access layer for CD devices) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; PadusŪ ASPI Shell>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 bpcService (BigPond Broadband Cable Login) - "c:\program files\telstra\cable login\bpcservice.exe"


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-05-03 12:35:01 256 --a------ C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
2008-05-03 12:34:11 302 --a------ C:\WINDOWS\Tasks\WebReg Photosmart 3300 series.job


-- Files created between 2008-04-03 and 2008-05-03 -----------------------------

2008-04-28 10:48:50 0 d-------- C:\WINDOWS\Sun
2008-04-28 10:48:50 0 d-------- C:\Documents and Settings\Anita\Application Data\Sun
2008-04-28 10:32:14 0 d-------- C:\Program Files\PC-Cleaner
2008-04-27 21:44:41 98304 --a------ C:\WINDOWS\system32\mjcringd.exe
2008-04-27 21:44:28 0 d-------- C:\Documents and Settings\Ken\Application Data\TmpRecentIcons
2008-04-27 21:26:02 0 d-------- C:\Program Files\Trend Micro
2008-04-27 20:19:04 0 d-------- C:\Documents and Settings\Anita\Application Data\TmpRecentIcons
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\winsystem.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\userconfig9x.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\WINWGPX.EXE
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\winsystem.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\winlogonpc.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\vcatchpi.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\vbsys2.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\thun32.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\thun.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\temp#01.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\taack.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\taack.dat
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\sysreq.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\ssvchost.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\ssvchost.com
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\ssurf022.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\sncntr.exe
2008-04-27 12:14:05 0 d-------- C:\WINDOWS\system32\smp
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\Rundl1.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\regm64.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\regc64.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\psoft1.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\psof1.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\ps1.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\newsd32.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\netode.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\mwin32.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\mtr2.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\msvchost.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\mssecu.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\msnbho.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\msgp.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\medup020.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\medup012.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\hxiwlgpm.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\hxiwlgpm.dat
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\hoproxy.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\h@tkeysh@@k.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\emesx.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\dpcproxy.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\bsva-egihsg52.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\bdn.com
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\awtoolb.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\anticipator.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\akttzn.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\mssecu.exe
2008-04-27 12:14:05 0 d-------- C:\WINDOWS\mslagent
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\iTunesMusic.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\FVProtect.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\bdn.com
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\a.bat
2008-04-27 12:14:05 0 d-------- C:\Program Files\akl
2008-04-27 12:13:53 94208 --a------ C:\WINDOWS\system32\tqbqbgxu.exe
2008-04-27 12:13:53 0 d-------- C:\Documents and Settings\All Users\Application Data\bqrsvarw
2008-04-27 12:13:44 98304 --a------ C:\WINDOWS\xbaqktfv.exe
2008-04-27 12:13:44 188416 --a------ C:\WINDOWS\wxdbpfvo.dll
2008-04-27 12:13:44 102400 --a------ C:\WINDOWS\spwoqbmv.exe
2008-04-27 12:13:44 229376 --a------ C:\WINDOWS\qadovnel.dll
2008-04-27 12:13:44 274432 --a------ C:\WINDOWS\bdkpfxqw.dll


-- Find3M Report ---------------------------------------------------------------

2008-03-22 18:12:04 0 d-------- C:\Documents and Settings\Ken\Application Data\Real
2008-03-08 15:36:30 0 d-------- C:\Documents and Settings\Ken\Application Data\LimeWire
2008-03-03 19:02:29 0 d-------- C:\Program Files\Windows Live
2008-03-03 18:58:47 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-03 18:58:35 0 d-------- C:\Program Files\Common Files


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDFF8B71-EF58-4922-ACF2-2003FE2B7481}]
C:\WINDOWS\gndarmblvpg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="C:\WINDOWS\htpatch.exe" [31/10/2002 02:40 AM]
"SoundMan"="SOUNDMAN.EXE" [28/10/2002 04:38 PM C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/07/2003 01:19 PM]
"nwiz"="nwiz.exe" [28/07/2003 01:19 PM C:\WINDOWS\system32\nwiz.exe]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [09/07/2001 08:50 PM]
"Dit"="Dit.exe" [29/08/2002 07:43 AM C:\WINDOWS\Dit.exe]
"VOBRegCheck"="C:\WINDOWS\System32\VOBREGCheck.exe" [09/01/2003 09:55 AM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [24/07/2002 05:20 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07/12/2003 12:30 PM]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [20/08/2002 09:29 AM]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []
"cxjxjw"="c:\windows\system32\cxjxjw.exe" []
"BigPondCable"="C:\Program Files\Telstra\Cable Login\bpcable.exe" [03/07/2006 12:21 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [24/11/2005 08:44 AM]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [28/06/2004 08:29 PM]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [10/06/2005 07:24 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [10/06/2005 07:21 PM]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [22/05/2006 01:26 PM]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [11/05/2005 11:12 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [14/12/2007 02:42 AM]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [30/12/2006 12:52 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 05:56 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [14/10/2004 02:24 AM]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [18/07/2002 05:00 AM]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [19/08/2005 06:34 PM]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" []
"mdgcdqte"="C:\WINDOWS\system32\mjcringd.exe" [27/04/2008 09:44 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [11/05/2005 11:23:26 PM]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1/08/1997]
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{f04aff5e-362e-11d3-81ab-00c04fb932ba}\4AA756BB.exe [30/04/2003 7:35:14 PM]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1/08/1997]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"jdMqsGvcMM"=C:\Documents and Settings\All Users\Application Data\bqrsvarw\lmxovqzk.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdkpfxqw"= {CE23FA0F-A6BC-4E40-BA27-E56A4697815D} - C:\WINDOWS\bdkpfxqw.dll [26/04/2008 11:17 PM 274432]
"qadovnel"= {1C800429-D278-4123-A771-71B437C9EFFD} - C:\WINDOWS\qadovnel.dll [26/04/2008 11:17 PM 229376]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe "
"Userinit"="C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-05-03 13:27:28 ------------


Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: IntelŪ PentiumŪ 4 CPU 2.60GHz
Percentage of Memory in Use: 75%
Physical Memory (total/avail): 511.49 MiB / 123.84 MiB
Pagefile Memory (total/avail): 1250.01 MiB / 808.78 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1935.43 MiB

C: is Fixed (NTFS) - 74.52 GiB total, 35.85 GiB free.
D: is Fixed (NTFS) - 65.73 GiB total, 60.75 GiB free.
E: is Fixed (FAT32) - 8.78 GiB total, 5.74 GiB free.
F: is CDROM (No Media)
G: is CDROM (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
J: is Removable (No Media)
K: is Removable (No Media)
M: is Removable (No Media)

\\.\PHYSICALDRIVE0 - ST3160021A - 149.03 GiB - 3 partitions
\PARTITION0 (bootable) - Installable File System - 74.52 GiB - C:
\PARTITION1 - Extended w/Extended Int 13 - 74.51 GiB - D: - E:

\\.\PHYSICALDRIVE5 - HP Photosmart 3310 USB Device

\\.\PHYSICALDRIVE3 - Medion Flash XL MMC/SD USB Device

\\.\PHYSICALDRIVE1 - Medion Flash XL CF USB Device

\\.\PHYSICALDRIVE2 - Medion Flash XL MS USB Device

\\.\PHYSICALDRIVE4 - Medion Flash XL SM USB Device



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FW: Trend Micro PC-cillin Internet Security (Firewall) v15 (Trend Micro, Inc.)
AV: Trend Micro PC-cillin Internet Security 2007 v15.30.1132 (Trend Micro, Inc.)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe:*:Enabled:backWeb-8876480"
"F:\\setup\\HPZnet01.exe"="F:\\setup\\HPZnet01.exe:*:Enabled:hpznet01.exe"
"F:\\setup\\HPONICIFS01.EXE"="F:\\setup\\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Telstra\\Cable Login\\bpcable.exe"="C:\\Program Files\\Telstra\\Cable Login\\bpcable.exe:*:Enabled:BigPond Cable Client"
"C:\\Program Files\\Telstra\\Cable Login\\bpcService.exe"="C:\\Program Files\\Telstra\\Cable Login\\bpcService.exe:*:Enabled:BigPond Cable Client (running as a service)"
"G:\\setup\\HPZnet01.exe"="G:\\setup\\HPZnet01.exe:*:Enabled:hpznet01.exe"
"G:\\setup\\HPONICIFS01.EXE"="G:\\setup\\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Ken\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MAIN
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Ken
LOGONSERVER=\\MAIN
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Ulead Systems\MPEG;;C:\PROGRA~1\COMMON~1\MUVEET~1\030625
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 7, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0207
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Ken\LOCALS~1\Temp
TMP=C:\DOCUME~1\Ken\LOCALS~1\Temp
USERDOMAIN=MAIN
USERNAME=Ken
USERPROFILE=C:\Documents and Settings\Ken
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Ken (admin)
Anita (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
1Click DVD Copy 4.2.9.2 --> "C:\Documents and Settings\Ken\My Documents\DVD Copy\1Click DVD Copy 4.2\unins000.exe"
Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe MPEG Encoder --> MsiExec.exe /I{9811A185-3D3D-11D6-9E14-00036D172B00}
Adobe Premiere 6.5 --> C:\WINDOWS\UNINST.EXE -f"C:\Program Files\Adobe\Premiere 6.5\DeIsL1.isu" -c"C:\Program Files\Adobe\Premiere 6.5\Uninst.dll"
BigPond Broadband Cable --> MsiExec.exe /X{6DE9C4EE-086C-443E-B75E-429751261B05}
BigPond Broadband Cable Login --> MsiExec.exe /I{BCE5A33D-A808-492A-9B5C-DCAFCFF24D27}
DesignExpress CD Labelmaker 32 bit --> C:\WINDOWS\MVUNINST\App1\unwise.exe C:\WINDOWS\MVUNINST\APP1\INSTALL.LOG "DesignExpress CD Labelmaker Uninstall"
Digital Photo Navigator 1.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7EF4BD8-CA13-11D5-AE3D-005004B8E30C}\Setup.exe" -l0x9
DVD Solution --> "C:\Program Files\Uninstall_CDS.exe"
DVD43 v3.9.0 --> "C:\Program Files\dvd43\unins000.exe"
GdiplusUpgrade --> MsiExec.exe /I{5421155F-B033-49DB-9B33-8F80F233D4D5}
HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HP Image Zone Express --> MsiExec.exe /X{FE64AE29-0883-4C70-8388-DC026019C900}
HP Imaging Device Functions 5.3 --> C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
HP PSC & OfficeJet 5.3.A --> "C:\Program Files\HP\Digital Imaging\{3E386744-10FA-44b2-98C9-DF7A270DECB3}\setup\hpzscr01.exe" -datfile hposcr06.dat
HP Software Update --> MsiExec.exe /X{15EE79F4-4ED1-4267-9B0F-351009325D7D}
HP Solution Center & Imaging Support Tools 5.3 --> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
Informations about your PC --> MsiExec.exe /I{0AB149EB-2AE0-466C-9BA4-3A718CF06432}
InstantCopy --> MsiExec.exe /I{A2B3D1A5-82CA-4876-AFFA-DB304A3A4FE1}
Java™ 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
LimeWire 4.16.6 --> "C:\Program Files\LimeWire\uninstall.exe"
Macromedia Flash Player --> MsiExec.exe /X{0456ebd7-5f67-4ab6-852e-63781e3f389c}
Medi@Show --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Medion\MediaShow\Uninst.isu"
Medion Flash XL --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA1CB7AC-E221-4822-A789-0ADB051DC498}\Setup.exe" -l0x9
Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Home Publishing 2000 --> MsiExec.exe /I{f04aff5e-362e-11d3-81ab-00c04fb932ba}
Microsoft Money --> MsiExec.exe /I{01A2E33A-8ADA-42D1-9173-8F65149E952F}
Microsoft Money System Pack --> MsiExec.exe /I{02CA7E66-1AD1-4DE9-BA9E-86A0EEB019C7}
Microsoft Office 97, Professional Edition --> C:\Program Files\Microsoft Office\Office\Setup\Acme.exe /w Off97Pro.STF
Microsoft Picture It! Photo 7.0 --> MsiExec.exe /I{369B36BE-3D64-4641-9AEA-808D436FE132}
Microsoft Windows Journal Viewer --> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA7}
Microsoft Word 2002 --> MsiExec.exe /I{911B0409-6000-11D3-8CFE-0050048383C9}
Nero - Burning Rom --> MsiExec.exe /X{A4D7B764-4140-11D4-88EB-0050DA3579C0}
Network Play System (Patching) --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Electronic Arts\Network Play System\NPSPatch.isu"
NVIDIA Windows 2000/XP Display Drivers --> rundll32.exe C:\WINDOWS\system32\nvinstnt.dll,NvUninstallNT4 nv4_disp.inf
OneCare Advisor (Windows Live Toolbar) --> MsiExec.exe /X{53B2CFE9-A508-4457-B2CA-5D253536BFB7}
Popup Blocker (Windows Live Toolbar) --> MsiExec.exe /X{66A7A386-6F35-41A7-A731-101F0C0153C8}
Power Cinema --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6B103F43-069C-11D6-9EA2-0050BAE317E1}\Setup.exe" -uninst
PowerDirector Express --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EDE721EC-870A-11D8-9D75-000129760D75}\setup.exe" -uninstall
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
PowerProducer --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\setup.exe" -uninstall
PowerVCR II --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0BA5720-E189-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime --> C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek AC'97 Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
SiS 900 PCI Fast Ethernet Adapter Driver --> C:\Progra~1\SiSLan\Uninst.exe
Smart Menus (Windows Live Toolbar) --> MsiExec.exe /X{F084395C-40FB-4DB3-981C-B51E74E1E83D}
Trend Micro PC-cillin Internet Security 2007 --> C:\PROGRA~1\TRENDM~1\INTERN~1\remove.exe
Trend Micro PC-cillin Internet Security 2007 --> MsiExec.exe /X{BB4B6355-D38A-492C-873B-A1B2CF6C3832}
Ulead VideoStudio 7 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{757AD3D4-036B-42FA-B0A4-96BD6F4605A0}\setup.exe" -l0x9
WebVideo Support --> C:\WINDOWS\spwoqbmv.exe
Windows Backup Utility --> MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
Windows Live Favorites for Windows Live Toolbar --> MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live installer --> MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger --> MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Outlook Toolbar (Windows Live Toolbar) --> MsiExec.exe /X{35E1A8C8-6646-4101-B0AA-42D1EB2AB3AE}
Windows Live Sign-in Assistant --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Live Toolbar --> "C:\Program Files\Windows Live Toolbar\UnInstall.exe" {D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Toolbar --> MsiExec.exe /X{D5A145FC-D00C-4F1A-9119-EB4D9D659750}
Windows Live Toolbar Extension (Windows Live Toolbar) --> MsiExec.exe /X{341201D4-4F61-4ADB-987E-9CCE4D83A58D}
Windows Live Toolbar Feed Detector (Windows Live Toolbar) --> MsiExec.exe /X{68108E66-D13A-4EE8-A6F4-40E4B90C2A26}
Windows Media Encoder 9 Series --> msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Encoder 9 Series --> MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Windows Media Format 9 Series SDK --> MsiExec.exe /X{EEE0F0A7-6B7D-4D1E-9498-43D9D012DDF7}
Windows Media Format SDK Hotfix - KB891122 --> "C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
Yahoo! Address AutoComplete --> C:\WINDOWS\System32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\yaddbook.dll
Yahoo! extras --> C:\PROGRA~1\Yahoo!\Common\unyext.exe
Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI~1.DLL
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type2509 / Success
Event Submitted/Written: 04/28/2008 04:35:54 PM
Event ID/Source: 12001 / usnjsvc
Event Description:
The Messenger Sharing USN Journal Reader service started successfully.

Event Record #/Type2505 / Error
Event Submitted/Written: 04/28/2008 00:35:26 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16640, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type2503 / Error
Event Submitted/Written: 04/28/2008 11:26:57 AM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application explorer.exe, version 6.0.2900.3156, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type2502 / Error
Event Submitted/Written: 04/28/2008 10:57:23 AM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16640, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type2499 / Error
Event Submitted/Written: 04/28/2008 01:07:59 AM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16640, hang module hungapp, version 0.0.0.0, hang address 0x00000000.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type132448 / Warning
Event Submitted/Written: 04/30/2008 02:07:47 PM
Event ID/Source: 36 / W32Time
Event Description:
The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Event Record #/Type132424 / Error
Event Submitted/Written: 04/29/2008 03:55:49 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {00BF57EF-C57F-47D4-9119-1F31FAD912C8} did not register with DCOM within the required timeout.

Event Record #/Type132422 / Error
Event Submitted/Written: 04/29/2008 03:55:17 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {00BF57EF-C57F-47D4-9119-1F31FAD912C8} did not register with DCOM within the required timeout.

Event Record #/Type132421 / Error
Event Submitted/Written: 04/29/2008 03:54:46 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {00BF57EF-C57F-47D4-9119-1F31FAD912C8} did not register with DCOM within the required timeout.

Event Record #/Type132420 / Error
Event Submitted/Written: 04/29/2008 03:54:16 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {00BF57EF-C57F-47D4-9119-1F31FAD912C8} did not register with DCOM within the required timeout.



-- End of Deckard's System Scanner: finished at 2008-05-03 13:27:28 ------------


-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 03, 2008 5:39:22 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/05/2008
Kaspersky Anti-Virus database records: 736403
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - Critical Areas:
C:\WINDOWS
C:\DOCUME~1\Ken\LOCALS~1\Temp\

Scan Statistics:
Total number of scanned objects: 28501
Number of viruses found: 4
Number of infected objects: 8
Number of suspicious objects: 0
Duration of the scan process: 01:42:51

Infected Object Name / Virus Name / Last Action
C:\WINDOWS\bdkpfxqw.dll Infected: Trojan.Win32.Vapsup.eie skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\qadovnel.dll Infected: Trojan.Win32.Vapsup.eie skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\spwoqbmv.exe Infected: Trojan.Win32.Vapsup.eie skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\mjcringd.exe Infected: Trojan-Downloader.Win32.Obfuscated.vb skipped
C:\WINDOWS\system32\tqbqbgxu.exe Infected: Trojan-Downloader.Win32.Obfuscated.uy skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Web\def.htm Infected: not-virus:Hoax.HTML.Secureinvites.c skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\wxdbpfvo.dll Infected: Trojan.Win32.Vapsup.eie skipped
C:\WINDOWS\xbaqktfv.exe Infected: Trojan.Win32.Vapsup.eie skipped

Scan process completed.

Edited by KoanYorel, 03 May 2008 - 10:39 AM.
to disable hot link URLs above


BC AdBot (Login to Remove)

 


#2 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:01 AM

Posted 04 May 2008 - 09:49 AM

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. :thumbsup:

Please download ComboFix and save it to your desktop.

Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.

Double click combofix.exe and follow the prompts.
When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#3 kuebd

kuebd
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:01 AM

Posted 05 May 2008 - 12:29 AM

Hi Sam,
Appreciate your help and thanks for the prompt reply. :thumbsup:

Combofix log as requested.

Just a quick question while you looking at this.
I need to renew my Trend Micro PC-cillin Subscription......is this security software ok or should I be look at something else.
Would be great to find out what you recommend.

Regards
Ken

ComboFix 08-05-01.3 - Ken 2008-05-05 14:52:57.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.114 [GMT 10:00]
Running from: C:\Documents and Settings\Ken\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Anita\Desktop\Error Cleaner.url
C:\Documents and Settings\Anita\Desktop\Privacy Protector.url
C:\Documents and Settings\Anita\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Anita\Favorites\Error Cleaner.url
C:\Documents and Settings\Anita\Favorites\Privacy Protector.url
C:\Documents and Settings\Anita\Favorites\Spyware&Malware Protection.url
C:\Documents and Settings\Anita\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Ken\Desktop\Error Cleaner.url
C:\Documents and Settings\Ken\Desktop\Privacy Protector.url
C:\Documents and Settings\Ken\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Ken\Favorites\Error Cleaner.url
C:\Documents and Settings\Ken\Favorites\Privacy Protector.url
C:\Documents and Settings\Ken\Favorites\Spyware&Malware Protection.url
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.exe
C:\Program Files\PC-Cleaner
C:\WINDOWS\a.bat
C:\WINDOWS\base64.tmp
C:\WINDOWS\bdkpfxqw.dll
C:\WINDOWS\bdn.com
C:\WINDOWS\FVProtect.exe
C:\WINDOWS\iTunesMusic.exe
C:\WINDOWS\mslagent
C:\WINDOWS\mslagent\2_mslagent.dll
C:\WINDOWS\mslagent\mslagent.exe
C:\WINDOWS\mslagent\uninstall.exe
C:\WINDOWS\mssecu.exe
C:\WINDOWS\qadovnel.dll
C:\WINDOWS\spwoqbmv.exe
C:\WINDOWS\system32\bsva-egihsg52.exe
C:\WINDOWS\system32\emesx.dll
C:\WINDOWS\system32\smp
C:\WINDOWS\system32\smp\msrc.exe
C:\WINDOWS\system32\wintsu.exe
C:\WINDOWS\userconfig9x.dll
C:\WINDOWS\Web\def.htm
C:\WINDOWS\winsystem.exe
C:\WINDOWS\wxdbpfvo.dll
C:\WINDOWS\xbaqktfv.exe
C:\WINDOWS\zip1.tmp
C:\WINDOWS\zip2.tmp
C:\WINDOWS\zip3.tmp
C:\WINDOWS\zipped.tmp

.
((((((((((((((((((((((((( Files Created from 2008-04-05 to 2008-05-05 )))))))))))))))))))))))))))))))
.

2008-05-03 14:00 . 2008-05-03 14:00 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 14:00 . 2008-05-03 14:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-03 13:05 . 2008-05-03 13:05 <DIR> d-------- C:\Deckard
2008-04-28 10:48 . 2008-04-28 10:48 <DIR> d-------- C:\WINDOWS\Sun
2008-04-27 21:44 . 2008-05-03 11:15 <DIR> d-------- C:\Documents and Settings\Ken\Application Data\TmpRecentIcons
2008-04-27 21:28 . 2008-03-30 18:50 1,169,240 --a------ C:\WINDOWS\system32\drivers\vsapint.sys
2008-04-27 21:28 . 2006-12-30 00:53 288,848 --a------ C:\WINDOWS\system32\drivers\TM_CFW.sys
2008-04-27 21:28 . 2008-03-30 19:07 204,816 --a------ C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-04-27 21:28 . 2006-12-30 00:53 111,888 --a------ C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2008-04-27 21:28 . 2006-12-30 00:53 75,088 --a------ C:\WINDOWS\system32\drivers\tmtdi.sys
2008-04-27 21:28 . 2008-03-30 19:07 36,368 --a------ C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-04-27 21:26 . 2008-04-30 23:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-27 20:19 . 2008-04-27 20:19 <DIR> d-------- C:\Documents and Settings\Anita\Application Data\TmpRecentIcons
2008-04-27 12:13 . 2008-04-27 12:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\bqrsvarw
2008-04-27 12:13 . 2008-04-27 12:13 94,208 --a------ C:\WINDOWS\system32\tqbqbgxu.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 11:45 4,096 ----a-w C:\WINDOWS\system32\WINWGPX.EXE
2008-04-27 11:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-08 05:36 --------- d-----w C:\Documents and Settings\Ken\Application Data\LimeWire
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-29 10:17 4,506,256 ----a-w C:\Documents and Settings\Anita\LimeWireWin.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2007-07-24 11:09 80,056 ----a-w C:\Documents and Settings\Anita\Application Data\GDIPFONTCACHEV1.DAT
2006-01-31 06:33 5,180,760 -c--a-w C:\Documents and Settings\Ken\CONFIGW.EXE
2004-08-09 12:30 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDFF8B71-EF58-4922-ACF2-2003FE2B7481}]
C:\WINDOWS\gndarmblvpg.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 17:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24 1694208]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2002-07-18 05:00 200767]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-08-19 18:34 3084288]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" [ ]
"mdgcdqte"="C:\WINDOWS\system32\mjcringd.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="C:\WINDOWS\htpatch.exe" [2002-10-31 02:40 28672]
"SoundMan"="SOUNDMAN.EXE" [2002-10-28 16:38 47104 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 13:19 4841472]
"nwiz"="nwiz.exe" [2003-07-28 13:19 323584 C:\WINDOWS\system32\nwiz.exe]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 20:50 155648]
"Dit"="Dit.exe" [2002-08-29 07:43 73728 C:\WINDOWS\Dit.exe]
"VOBRegCheck"="C:\WINDOWS\System32\VOBREGCheck.exe" [2003-01-09 09:55 153088]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-24 17:20 28672]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-12-07 12:30 77824]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 09:29 40960]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [ ]
"cxjxjw"="c:\windows\system32\cxjxjw.exe" [ ]
"BigPondCable"="C:\Program Files\Telstra\Cable Login\bpcable.exe" [2006-07-03 00:21 258048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-24 08:44 180269]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-06-28 20:29 32768]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-06-10 19:24 196608]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 19:21 217088]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2006-05-22 13:26 694272]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 02:42 144784]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-12-30 00:52 3429904]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-01 111376]
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{f04aff5e-362e-11d3-81ab-00c04fb932ba}\4AA756BB.exe [2003-04-30 19:35:14 30720]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-01 51984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"jdMqsGvcMM"= C:\Documents and Settings\All Users\Application Data\bqrsvarw\lmxovqzk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Telstra\\Cable Login\\bpcable.exe"=
"C:\\Program Files\\Telstra\\Cable Login\\bpcService.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=


*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-05 04:35:03 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-03 02:34:11 C:\WINDOWS\Tasks\WebReg Photosmart 3300 series.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-05 14:56:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HTpatch = C:\WINDOWS\htpatch.exe?ows\CurrentVersion\Run???\??????Z????`??Z???Z`??Z???????????????Z???Z???Z???Z$??????Z???????????????Z???????????Z???w????(????3?w???w?????3?w ??w???Z:???????d???r??Z1??Z???Zd??????Z?-?Z????z??w8h?Z\2?Z?1?Zhtinst.INI?Z?u?Z????d????????F?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-05 15:00:01
ComboFix-quarantined-files.txt 2008-05-05 04:59:50

Pre-Run: 38,363,389,952 bytes free
Post-Run: 38,475,304,960 bytes free

187 --- E O F --- 2008-04-12 13:26:45

#4 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:01 AM

Posted 05 May 2008 - 08:47 AM

I'm alright with Trendmicro. It's much better than what most of the people posting in this board are running. :thumbsup:

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

Folder::
C:\Documents and Settings\All Users\Application Data\bqrsvarw

File::
C:\WINDOWS\system32\tqbqbgxu.exe
C:\WINDOWS\system32\WINWGPX.EXE

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDFF8B71-EF58-4922-ACF2-2003FE2B7481}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mdgcdqte"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cxjxjw"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply along with a new HijackThis log.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#5 kuebd

kuebd
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:01 AM

Posted 06 May 2008 - 07:34 AM

Sam,
Thanks for that will stick with Trendmicro.
How are things going with this.....seems the internet has gotten better and lost most of the annoying pop ups.
One or two still seem to appear but don't seem connected to web use.

Logs attached as requested.

Enjoy your day
Regards
Ken

ComboFix 08-05-01.3 - Ken 2008-05-06 22:10:35.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.129 [GMT 10:00]
Running from: C:\Documents and Settings\Ken\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ken\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\tqbqbgxu.exe
C:\WINDOWS\system32\WINWGPX.EXE
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\bqrsvarw
C:\Documents and Settings\All Users\Application Data\bqrsvarw\lmxovqzk.exe
C:\Program Files\PC-Cleaner
C:\WINDOWS\system32\tqbqbgxu.exe
C:\WINDOWS\system32\WINWGPX.EXE

.
((((((((((((((((((((((((( Files Created from 2008-04-06 to 2008-05-06 )))))))))))))))))))))))))))))))
.

2008-05-05 16:17 . 2008-05-06 20:56 <DIR> d-------- C:\Program Files\Google
2008-05-05 16:08 . 2008-05-05 16:08 114,688 --a------ C:\WINDOWS\system32\bqnglobk.exe
2008-05-03 14:00 . 2008-05-03 14:00 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 14:00 . 2008-05-03 14:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-03 13:05 . 2008-05-03 13:05 <DIR> d-------- C:\Deckard
2008-04-28 10:48 . 2008-04-28 10:48 <DIR> d-------- C:\WINDOWS\Sun
2008-04-27 21:44 . 2008-05-03 11:15 <DIR> d-------- C:\Documents and Settings\Ken\Application Data\TmpRecentIcons
2008-04-27 21:28 . 2008-03-30 18:50 1,169,240 --a------ C:\WINDOWS\system32\drivers\vsapint.sys
2008-04-27 21:28 . 2006-12-30 00:53 288,848 --a------ C:\WINDOWS\system32\drivers\TM_CFW.sys
2008-04-27 21:28 . 2008-03-30 19:07 204,816 --a------ C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-04-27 21:28 . 2006-12-30 00:53 111,888 --a------ C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2008-04-27 21:28 . 2006-12-30 00:53 75,088 --a------ C:\WINDOWS\system32\drivers\tmtdi.sys
2008-04-27 21:28 . 2008-03-30 19:07 36,368 --a------ C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-04-27 21:26 . 2008-05-06 21:26 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-27 20:19 . 2008-04-27 20:19 <DIR> d-------- C:\Documents and Settings\Anita\Application Data\TmpRecentIcons

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-05 06:17 --------- d-----w C:\Program Files\Java
2008-04-27 11:45 4,096 ----a-w C:\WINDOWS\system32\winsystem.exe
2008-04-27 11:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-08 05:36 --------- d-----w C:\Documents and Settings\Ken\Application Data\LimeWire
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-29 10:17 4,506,256 ----a-w C:\Documents and Settings\Anita\LimeWireWin.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2007-07-24 11:09 80,056 ----a-w C:\Documents and Settings\Anita\Application Data\GDIPFONTCACHEV1.DAT
2006-01-31 06:33 5,180,760 -c--a-w C:\Documents and Settings\Ken\CONFIGW.EXE
2004-08-09 12:30 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((( snapshot@2008-05-05_14.59.18.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-05 04:32:02 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-06 10:56:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-04-11 05:24:04 2,560 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2008-05-05 05:43:09 2,560 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2008-04-11 05:24:04 34,304 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2008-05-05 05:43:09 34,304 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2008-04-11 05:24:04 8,192 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2008-05-05 05:43:09 8,192 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2008-04-11 05:24:04 3,584 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2008-05-05 05:43:09 3,584 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2008-04-11 05:24:04 16,384 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2008-05-05 05:43:09 16,384 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2008-04-11 05:24:04 22,528 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2008-05-05 05:43:09 22,528 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2008-04-11 05:24:04 45,056 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2008-05-05 05:43:09 45,056 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2007-12-13 13:57:22 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-02-21 15:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2007-12-13 13:57:24 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-02-21 15:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2007-12-13 14:59:16 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-02-21 16:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 17:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24 1694208]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2002-07-18 05:00 200767]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-08-19 18:34 3084288]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" [ ]
"cpztgijd"="C:\WINDOWS\system32\bqnglobk.exe" [2008-05-05 16:08 114688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="C:\WINDOWS\htpatch.exe" [2002-10-31 02:40 28672]
"SoundMan"="SOUNDMAN.EXE" [2002-10-28 16:38 47104 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 13:19 4841472]
"nwiz"="nwiz.exe" [2003-07-28 13:19 323584 C:\WINDOWS\system32\nwiz.exe]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 20:50 155648]
"Dit"="Dit.exe" [2002-08-29 07:43 73728 C:\WINDOWS\Dit.exe]
"VOBRegCheck"="C:\WINDOWS\System32\VOBREGCheck.exe" [2003-01-09 09:55 153088]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-24 17:20 28672]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-12-07 12:30 77824]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 09:29 40960]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [ ]
"BigPondCable"="C:\Program Files\Telstra\Cable Login\bpcable.exe" [2006-07-03 00:21 258048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-24 08:44 180269]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-06-28 20:29 32768]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-06-10 19:24 196608]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 19:21 217088]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2006-05-22 13:26 694272]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-12-30 00:52 3429904]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-01 111376]
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{f04aff5e-362e-11d3-81ab-00c04fb932ba}\4AA756BB.exe [2003-04-30 19:35:14 30720]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-01 51984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Telstra\\Cable Login\\bpcable.exe"=
"C:\\Program Files\\Telstra\\Cable Login\\bpcService.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=


.
Contents of the 'Scheduled Tasks' folder
"2008-05-06 11:35:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-03 02:34:11 C:\WINDOWS\Tasks\WebReg Photosmart 3300 series.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-06 22:13:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HTpatch = C:\WINDOWS\htpatch.exe?ows\CurrentVersion\Run???\??????Z????`??Z???Z`??Z???????????????Z???Z???Z???Z$??????Z???????????????Z???????????Z???w????(????3?w???w?????3?w ??w???Z:???????d???r??Z1??Z???Zd??????Z?-?Z????z??w8h?Z\2?Z?1?Zhtinst.INI?Z?u?Z????d????????F?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-06 22:16:52
ComboFix-quarantined-files.txt 2008-05-06 12:16:38
ComboFix2.txt 2008-05-05 05:00:02

Pre-Run: 38,124,122,112 bytes free
Post-Run: 38,176,497,664 bytes free

172 --- E O F --- 2008-04-12 13:26:45




Deckard's System Scanner v20071014.68
Run by Ken on 2008-05-06 22:24:45
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Percentage of Memory in Use: 77% (more than 75%).


-- HijackThis (run as Ken.exe) -------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:55 PM, on 6/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Telstra\Cable Login\bpcService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\Dit.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Telstra\Cable Login\bpcable.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\bqnglobk.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Ken\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Ken.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [BigPondCable] "C:\Program Files\Telstra\Cable Login\bpcable.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [cpztgijd] C:\WINDOWS\system32\bqnglobk.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178534350187
O23 - Service: BigPond Broadband Cable Login (bpcService) - Unknown owner - C:\Program Files\Telstra\Cable Login\bpcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O24 - Desktop Component 0: (no name) - http://cybernet.m7z.net/www.cybernetentert.../i/h/200//9.jpg
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/Ken/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 10220 bytes

-- Files created between 2008-04-06 and 2008-05-06 -----------------------------

2008-05-05 16:17:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-05-05 16:17:52 0 d-------- C:\Program Files\Google
2008-05-05 16:08:13 114688 --a------ C:\WINDOWS\system32\bqnglobk.exe
2008-05-05 14:49:09 68096 --a------ C:\WINDOWS\zip.exe
2008-05-05 14:49:09 49152 --a------ C:\WINDOWS\VFind.exe
2008-05-05 14:49:09 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-05-05 14:49:09 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-05-05 14:49:09 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-05-05 14:49:09 98816 --a------ C:\WINDOWS\sed.exe
2008-05-05 14:49:09 80412 --a------ C:\WINDOWS\grep.exe
2008-05-05 14:49:09 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-05-03 14:00:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-03 14:00:19 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 10:48:50 0 d-------- C:\WINDOWS\Sun
2008-04-28 10:48:50 0 d-------- C:\Documents and Settings\Anita\Application Data\Sun
2008-04-27 21:44:28 0 d-------- C:\Documents and Settings\Ken\Application Data\TmpRecentIcons
2008-04-27 21:26:02 0 d-------- C:\Program Files\Trend Micro
2008-04-27 20:19:04 0 d-------- C:\Documents and Settings\Anita\Application Data\TmpRecentIcons
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\winsystem.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\winlogonpc.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\vcatchpi.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\vbsys2.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\thun32.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\thun.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\temp#01.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\taack.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\taack.dat
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\sysreq.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\ssvchost.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\ssvchost.com
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\ssurf022.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\sncntr.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\Rundl1.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\regm64.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\regc64.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\psoft1.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\psof1.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\ps1.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\newsd32.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\netode.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\mwin32.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\mtr2.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\msvchost.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\mssecu.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\msnbho.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\msgp.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\medup020.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\medup012.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\hxiwlgpm.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\hxiwlgpm.dat
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\hoproxy.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\h@tkeysh@@k.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\dpcproxy.exe
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\bdn.com
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\awtoolb.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\anticipator.dll
2008-04-27 12:14:05 4096 --a------ C:\WINDOWS\system32\akttzn.exe


-- Find3M Report ---------------------------------------------------------------

2008-05-05 16:19:41 0 d-------- C:\Documents and Settings\Ken\Application Data\Google
2008-05-05 16:17:23 0 d-------- C:\Program Files\Java
2008-03-22 18:12:04 0 d-------- C:\Documents and Settings\Ken\Application Data\Real
2008-03-08 15:36:30 0 d-------- C:\Documents and Settings\Ken\Application Data\LimeWire


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="C:\WINDOWS\htpatch.exe" [31/10/2002 02:40 AM]
"SoundMan"="SOUNDMAN.EXE" [28/10/2002 04:38 PM C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/07/2003 01:19 PM]
"nwiz"="nwiz.exe" [28/07/2003 01:19 PM C:\WINDOWS\system32\nwiz.exe]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [09/07/2001 08:50 PM]
"Dit"="Dit.exe" [29/08/2002 07:43 AM C:\WINDOWS\Dit.exe]
"VOBRegCheck"="C:\WINDOWS\System32\VOBREGCheck.exe" [09/01/2003 09:55 AM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [24/07/2002 05:20 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07/12/2003 12:30 PM]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [20/08/2002 09:29 AM]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []
"BigPondCable"="C:\Program Files\Telstra\Cable Login\bpcable.exe" [03/07/2006 12:21 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [24/11/2005 08:44 AM]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [28/06/2004 08:29 PM]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [10/06/2005 07:24 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [10/06/2005 07:21 PM]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [22/05/2006 01:26 PM]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [11/05/2005 11:12 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 04:25 AM]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [30/12/2006 12:52 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 05:56 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [14/10/2004 02:24 AM]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [18/07/2002 05:00 AM]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [19/08/2005 06:34 PM]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" []
"cpztgijd"="C:\WINDOWS\system32\bqnglobk.exe" [05/05/2008 04:08 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [11/05/2005 11:23:26 PM]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1/08/1997]
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{f04aff5e-362e-11d3-81ab-00c04fb932ba}\4AA756BB.exe [30/04/2003 7:35:14 PM]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1/08/1997]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-05-06 22:25:16 ------------

#6 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:01 AM

Posted 06 May 2008 - 10:18 AM

Not quite done yet.

Copy and paste ALL the following text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: CFScript to your desktop.

File::
C:\WINDOWS\system32\bqnglobk.exe

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cpztgijd"=-
Prior to running Combofix.exe you should disable your antivirus program and disconnect from the internet.

Now drag then drop the CFScript file onto ComboFix.exe as seen in the image below.

Posted Image

This will start ComboFix again.
After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.


=================



Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
  • Under "Configuration and Preferences", click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.

Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#7 kuebd

kuebd
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:01 AM

Posted 07 May 2008 - 06:55 AM

Thanks Sam,
Here you go some more light reading....enjoy

ComboFix 08-05-01.3 - Ken 2008-05-07 20:03:03.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.123 [GMT 10:00]
Running from: C:\Documents and Settings\Ken\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ken\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\bqnglobk.exe
.

((((((((((((((((((((((((( Files Created from 2008-04-07 to 2008-05-07 )))))))))))))))))))))))))))))))
.

2008-05-07 17:32 . 2008-05-07 17:32 <DIR> d-------- C:\WINDOWS\LastGood
2008-05-07 17:32 . 2008-02-15 23:39 138,384 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-05-07 17:32 . 2008-02-15 23:39 52,496 --a------ C:\WINDOWS\system32\drivers\tmactmon.sys
2008-05-07 17:32 . 2008-02-15 23:39 52,240 --a------ C:\WINDOWS\system32\drivers\tmevtmgr.sys
2008-05-05 16:17 . 2008-05-06 20:56 <DIR> d-------- C:\Program Files\Google
2008-05-03 14:00 . 2008-05-03 14:00 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-03 14:00 . 2008-05-03 14:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-03 13:05 . 2008-05-03 13:05 <DIR> d-------- C:\Deckard
2008-04-28 10:48 . 2008-04-28 10:48 <DIR> d-------- C:\WINDOWS\Sun
2008-04-27 21:44 . 2008-05-03 11:15 <DIR> d-------- C:\Documents and Settings\Ken\Application Data\TmpRecentIcons
2008-04-27 21:26 . 2008-05-07 17:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-27 20:19 . 2008-04-27 20:19 <DIR> d-------- C:\Documents and Settings\Anita\Application Data\TmpRecentIcons

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 12:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-05-05 06:17 --------- d-----w C:\Program Files\Java
2008-04-27 11:45 4,096 ----a-w C:\WINDOWS\system32\winsystem.exe
2008-03-30 09:07 36,368 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2008-03-30 09:07 204,816 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2008-03-30 08:50 1,169,240 ----a-w C:\WINDOWS\system32\drivers\vsapint.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-08 05:36 --------- d-----w C:\Documents and Settings\Ken\Application Data\LimeWire
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-29 10:17 4,506,256 ----a-w C:\Documents and Settings\Anita\LimeWireWin.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2007-07-24 11:09 80,056 ----a-w C:\Documents and Settings\Anita\Application Data\GDIPFONTCACHEV1.DAT
2006-01-31 06:33 5,180,760 -c--a-w C:\Documents and Settings\Ken\CONFIGW.EXE
2004-08-09 12:30 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((( snapshot@2008-05-05_14.59.18.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-05 04:32:02 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-07 07:29:37 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-04-11 05:24:04 2,560 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2008-05-05 05:43:09 2,560 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2008-04-11 05:24:04 34,304 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2008-05-05 05:43:09 34,304 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2008-04-11 05:24:04 8,192 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2008-05-05 05:43:09 8,192 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2008-04-11 05:24:04 3,584 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2008-05-05 05:43:09 3,584 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2008-04-11 05:24:04 16,384 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2008-05-05 05:43:09 16,384 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2008-04-11 05:24:04 22,528 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2008-05-05 05:43:09 22,528 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2008-04-11 05:24:04 45,056 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2008-05-05 05:43:09 45,056 ----a-r C:\WINDOWS\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2008-02-15 13:39:32 96,256 ----a-w C:\WINDOWS\Installer\atl80.dll
+ 2008-02-15 13:39:32 156,936 ----a-w C:\WINDOWS\Installer\libexpat.dll
+ 2008-02-15 13:39:32 1,101,824 ----a-w C:\WINDOWS\Installer\mfc80.dll
+ 2008-02-15 13:39:32 1,093,120 ----a-w C:\WINDOWS\Installer\mfc80u.dll
+ 2008-02-15 13:39:32 69,632 ----a-w C:\WINDOWS\Installer\mfcm80.dll
+ 2008-02-15 13:39:32 57,856 ----a-w C:\WINDOWS\Installer\mfcm80u.dll
+ 2008-02-15 13:39:32 479,232 ----a-w C:\WINDOWS\Installer\msvcm80.dll
+ 2008-02-15 13:39:32 548,864 ----a-w C:\WINDOWS\Installer\msvcp80.dll
+ 2008-02-15 13:39:32 626,688 ----a-w C:\WINDOWS\Installer\msvcr80.dll
+ 2008-02-15 13:39:32 124,168 ----a-w C:\WINDOWS\Installer\TmDbg32.dll
- 2006-12-29 14:53:52 288,848 ----a-w C:\WINDOWS\system32\drivers\TM_CFW.sys
+ 2008-02-15 13:39:32 333,328 ----a-w C:\WINDOWS\system32\drivers\TM_CFW.sys
- 2006-12-29 14:53:52 75,088 ----a-w C:\WINDOWS\system32\drivers\tmtdi.sys
+ 2008-02-15 13:39:32 65,936 ----a-w C:\WINDOWS\system32\drivers\tmtdi.sys
- 2007-12-13 13:57:22 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-02-21 15:23:35 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2007-12-13 13:57:24 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-02-21 15:23:39 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2007-12-13 14:59:16 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-02-21 16:33:32 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 17:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24 1694208]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2002-07-18 05:00 200767]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-08-19 18:34 3084288]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="C:\WINDOWS\htpatch.exe" [2002-10-31 02:40 28672]
"SoundMan"="SOUNDMAN.EXE" [2002-10-28 16:38 47104 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 13:19 4841472]
"nwiz"="nwiz.exe" [2003-07-28 13:19 323584 C:\WINDOWS\system32\nwiz.exe]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 20:50 155648]
"Dit"="Dit.exe" [2002-08-29 07:43 73728 C:\WINDOWS\Dit.exe]
"VOBRegCheck"="C:\WINDOWS\System32\VOBREGCheck.exe" [2003-01-09 09:55 153088]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-24 17:20 28672]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-12-07 12:30 77824]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 09:29 40960]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [ ]
"BigPondCable"="C:\Program Files\Telstra\Cable Login\bpcable.exe" [2006-07-03 00:21 258048]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-24 08:44 180269]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-06-28 20:29 32768]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-06-10 19:24 196608]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 19:21 217088]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2006-05-22 13:26 694272]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-02-16 00:56 1398024]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-01 111376]
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{f04aff5e-362e-11d3-81ab-00c04fb932ba}\4AA756BB.exe [2003-04-30 19:35:14 30720]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-01 51984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Telstra\\Cable Login\\bpcable.exe"=
"C:\\Program Files\\Telstra\\Cable Login\\bpcService.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R2 bpcService;BigPond Broadband Cable Login;"C:\Program Files\Telstra\Cable Login\bpcService.exe" [2006-07-03 00:21]

*Newly Created Service* - SFCTLCOM
*Newly Created Service* - TMACTMON
*Newly Created Service* - TMBMSERVER
*Newly Created Service* - TMEVTMGR
*Newly Created Service* - TMPFW
*Newly Created Service* - TMPROXY
*Newly Created Service* - TMXPFLT
*Newly Created Service* - VSAPINT
.
Contents of the 'Scheduled Tasks' folder
"2008-05-07 09:35:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-03 02:34:11 C:\WINDOWS\Tasks\WebReg Photosmart 3300 series.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-07 20:10:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HTpatch = C:\WINDOWS\htpatch.exe?ows\CurrentVersion\Run???\??????Z????`??Z???Z`??Z???????????????Z???Z???Z???Z$??????Z???????????????Z???????????Z???w????(????3?w???w?????3?w ??w???Z:???????d???r??Z1??Z???Zd??????Z?-?Z????z??w8h?Z\2?Z?1?Zhtinst.INI?Z?u?Z????d????????F?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-07 20:17:52
ComboFix-quarantined-files.txt 2008-05-07 10:17:21
ComboFix2.txt 2008-05-06 12:16:53
ComboFix3.txt 2008-05-05 05:00:02

Pre-Run: 37,759,221,760 bytes free
Post-Run: 37,771,796,480 bytes free

188 --- E O F --- 2008-04-12 13:26:45




SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/07/2008 at 09:36 PM

Application Version : 4.0.1154

Core Rules Database Version : 3454
Trace Rules Database Version: 1446

Scan type : Complete Scan
Total Scan Time : 01:01:09

Memory items scanned : 511
Memory threats detected : 0
Registry items scanned : 5974
Registry threats detected : 9
File items scanned : 78953
File threats detected : 253

Adware.Tracking Cookie
C:\Documents and Settings\Ken\Cookies\ken@statse.webtrendslive[2].txt
C:\Documents and Settings\Ken\Cookies\ken@www.sexandsubmission[1].txt
C:\Documents and Settings\Ken\Cookies\ken@atdmt[2].txt
C:\Documents and Settings\Ken\Cookies\ken@doubleclick[1].txt
C:\Documents and Settings\Ken\Cookies\ken@tribalfusion[2].txt
C:\Documents and Settings\Ken\Cookies\ken@fastclick[1].txt
C:\Documents and Settings\Ken\Cookies\ken@bs.serving-sys[2].txt
C:\Documents and Settings\Ken\Cookies\ken@apmebf[1].txt
C:\Documents and Settings\Ken\Cookies\ken@ads.bleepingcomputer[1].txt
C:\Documents and Settings\Ken\Cookies\ken@mediaplex[1].txt
C:\Documents and Settings\Ken\Cookies\ken@www.mynortonaccount[1].txt
C:\Documents and Settings\Ken\Cookies\ken@adopt.euroclick[1].txt
C:\Documents and Settings\Ken\Cookies\ken@www.findmyorder[2].txt
C:\Documents and Settings\Ken\Cookies\ken@serving-sys[2].txt
C:\Documents and Settings\Ken\Cookies\ken@findmyorder[1].txt
C:\Documents and Settings\Ken\Cookies\ken@2o7[2].txt
C:\Documents and Settings\Anita\Cookies\anita@112.2o7[2].txt
C:\Documents and Settings\Anita\Cookies\anita@247realmedia[1].txt
C:\Documents and Settings\Anita\Cookies\anita@3.adbrite[2].txt
C:\Documents and Settings\Anita\Cookies\anita@4.adbrite[2].txt
C:\Documents and Settings\Anita\Cookies\anita@a.websponsors[2].txt
C:\Documents and Settings\Anita\Cookies\anita@account.live[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ad.accelerator-media[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ad.ifrance[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ad.uk.tangozebra[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ad.zanox[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ad1.emediate[2].txt
C:\Documents and Settings\Anita\Cookies\anita@adbrite[2].txt
C:\Documents and Settings\Anita\Cookies\anita@adecn[1].txt
C:\Documents and Settings\Anita\Cookies\anita@adinterax[2].txt
C:\Documents and Settings\Anita\Cookies\anita@adlegend[2].txt
C:\Documents and Settings\Anita\Cookies\anita@adnetserver[1].txt
C:\Documents and Settings\Anita\Cookies\anita@adopt.euroclick[2].txt
C:\Documents and Settings\Anita\Cookies\anita@adopt.specificclick[2].txt
C:\Documents and Settings\Anita\Cookies\anita@adrevolver[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.1001skins[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.adbrite[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.addynamix[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.adgoto[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.emaginet[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.gamesbannernet[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.glispa[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.labpixies[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.pointroll[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.realtechnetwork[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.revsci[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.stardoll[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.str8up[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ads.surfnetkids[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads3.blastro[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ads4.blastro[2].txt
C:\Documents and Settings\Anita\Cookies\anita@adserv01[1].txt
C:\Documents and Settings\Anita\Cookies\anita@adserver.adreactor[1].txt
C:\Documents and Settings\Anita\Cookies\anita@adultadworld[2].txt
C:\Documents and Settings\Anita\Cookies\anita@adv.webmd[1].txt
C:\Documents and Settings\Anita\Cookies\anita@adviva[2].txt
C:\Documents and Settings\Anita\Cookies\anita@aotgroup.122.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@as-eu.falkag[2].txt
C:\Documents and Settings\Anita\Cookies\anita@atdmt[2].txt
C:\Documents and Settings\Anita\Cookies\anita@au.adserver.yahoo[1].txt
C:\Documents and Settings\Anita\Cookies\anita@azjmp[2].txt
C:\Documents and Settings\Anita\Cookies\anita@b5media.us.intellitxt[1].txt
C:\Documents and Settings\Anita\Cookies\anita@banners2.battleon[1].txt
C:\Documents and Settings\Anita\Cookies\anita@bestsexworld[1].txt
C:\Documents and Settings\Anita\Cookies\anita@bfast[1].txt
C:\Documents and Settings\Anita\Cookies\anita@brightcove.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@bs.serving-sys[1].txt
C:\Documents and Settings\Anita\Cookies\anita@burstnet[2].txt
C:\Documents and Settings\Anita\Cookies\anita@checkmystats.com[1].txt
C:\Documents and Settings\Anita\Cookies\anita@clicksor[1].txt
C:\Documents and Settings\Anita\Cookies\anita@cnetaustralia.122.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@collective-media[2].txt
C:\Documents and Settings\Anita\Cookies\anita@collegeteencreamers[1].txt
C:\Documents and Settings\Anita\Cookies\anita@counter.hitslink[1].txt
C:\Documents and Settings\Anita\Cookies\anita@counter4.sextracker[1].txt
C:\Documents and Settings\Anita\Cookies\anita@cz4.clickzs[2].txt
C:\Documents and Settings\Anita\Cookies\anita@dealtime[1].txt
C:\Documents and Settings\Anita\Cookies\anita@doubleclick[1].txt
C:\Documents and Settings\Anita\Cookies\anita@eas.apm.emediate[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-accuweather.hitbox[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-alkemi.hitbox[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-austar.hitbox[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-clubmedasia.hitbox[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-ctv.hitbox[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-dig.hitbox[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-foxmovies.hitbox[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-ifilm.hitbox[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-jetstarairways.hitbox[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-meevee.hitbox[2].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-newsinteractive.hitbox[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-tourismqueensland.hitbox[1].txt
C:\Documents and Settings\Anita\Cookies\anita@ehg-warnerbrothers.hitbox[2].txt
C:\Documents and Settings\Anita\Cookies\anita@focalex[2].txt
C:\Documents and Settings\Anita\Cookies\anita@bleeparoo[2].txt
C:\Documents and Settings\Anita\Cookies\anita@h.starware[1].txt
C:\Documents and Settings\Anita\Cookies\anita@harpo.122.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@hitbox[2].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[10].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[1].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[2].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[3].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[5].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[6].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[7].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[8].txt
C:\Documents and Settings\Anita\Cookies\anita@humornsex[9].txt
C:\Documents and Settings\Anita\Cookies\anita@image.checkmystats.com[2].txt
C:\Documents and Settings\Anita\Cookies\anita@imrworldwide[2].txt
C:\Documents and Settings\Anita\Cookies\anita@incentaclick[2].txt
C:\Documents and Settings\Anita\Cookies\anita@interclick[2].txt
C:\Documents and Settings\Anita\Cookies\anita@kaboose.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@kontera[1].txt
C:\Documents and Settings\Anita\Cookies\anita@m1.webstats.motigo[2].txt
C:\Documents and Settings\Anita\Cookies\anita@maxim.122.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@media.adrevolver[1].txt
C:\Documents and Settings\Anita\Cookies\anita@media.adrevolver[3].txt
C:\Documents and Settings\Anita\Cookies\anita@media.sandlab[1].txt
C:\Documents and Settings\Anita\Cookies\anita@media.sensis.com[1].txt
C:\Documents and Settings\Anita\Cookies\anita@media303[2].txt
C:\Documents and Settings\Anita\Cookies\anita@mediaonenetwork[1].txt
C:\Documents and Settings\Anita\Cookies\anita@metacafe.122.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@microsoftwlmessengermkt.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@microsoftwlsearchcrm.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@momsteachingteens[1].txt
C:\Documents and Settings\Anita\Cookies\anita@msnaccountservices.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@msnportal.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@mswlsrccrmgame5aucom.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@mystats[2].txt
C:\Documents and Settings\Anita\Cookies\anita@network.alluremedia.com[2].txt
C:\Documents and Settings\Anita\Cookies\anita@optimize.indieclick[2].txt
C:\Documents and Settings\Anita\Cookies\anita@optimost[1].txt
C:\Documents and Settings\Anita\Cookies\anita@optus.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@overture[2].txt
C:\Documents and Settings\Anita\Cookies\anita@pamedia.com[2].txt
C:\Documents and Settings\Anita\Cookies\anita@partypoker[2].txt
C:\Documents and Settings\Anita\Cookies\anita@paycounter[1].txt
C:\Documents and Settings\Anita\Cookies\anita@paypal.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@perf.overture[1].txt
C:\Documents and Settings\Anita\Cookies\anita@podtrac.advertserve[1].txt
C:\Documents and Settings\Anita\Cookies\anita@pornaccess[2].txt
C:\Documents and Settings\Anita\Cookies\anita@pornguidenetwork[1].txt
C:\Documents and Settings\Anita\Cookies\anita@pornoinside[2].txt
C:\Documents and Settings\Anita\Cookies\anita@pornokinki[2].txt
C:\Documents and Settings\Anita\Cookies\anita@precisionclick[1].txt
C:\Documents and Settings\Anita\Cookies\anita@pro-market[2].txt
C:\Documents and Settings\Anita\Cookies\anita@realmedia[1].txt
C:\Documents and Settings\Anita\Cookies\anita@roiservice[1].txt
C:\Documents and Settings\Anita\Cookies\anita@scanner.spyshredder-scanner[2].txt
C:\Documents and Settings\Anita\Cookies\anita@scanner.spyshredderscanner[2].txt
C:\Documents and Settings\Anita\Cookies\anita@scanner.xspy-shredder[1].txt
C:\Documents and Settings\Anita\Cookies\anita@sensismediasmart.com[1].txt
C:\Documents and Settings\Anita\Cookies\anita@server.cpmstar[2].txt
C:\Documents and Settings\Anita\Cookies\anita@server.koadserver[2].txt
C:\Documents and Settings\Anita\Cookies\anita@sexsearchcom[1].txt
C:\Documents and Settings\Anita\Cookies\anita@sextracker[1].txt
C:\Documents and Settings\Anita\Cookies\anita@smartadserver[2].txt
C:\Documents and Settings\Anita\Cookies\anita@stat.dealtime[2].txt
C:\Documents and Settings\Anita\Cookies\anita@stat.onestat[2].txt
C:\Documents and Settings\Anita\Cookies\anita@statse.webtrendslive[1].txt
C:\Documents and Settings\Anita\Cookies\anita@toplist[1].txt
C:\Documents and Settings\Anita\Cookies\anita@tour.sexsearchcom[2].txt
C:\Documents and Settings\Anita\Cookies\anita@tracking.battleon[2].txt
C:\Documents and Settings\Anita\Cookies\anita@tracking.hearthstoneonline[2].txt
C:\Documents and Settings\Anita\Cookies\anita@tradedoubler[1].txt
C:\Documents and Settings\Anita\Cookies\anita@trafficmp[2].txt
C:\Documents and Settings\Anita\Cookies\anita@travelcomau.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@tripod[2].txt
C:\Documents and Settings\Anita\Cookies\anita@try.starware[1].txt
C:\Documents and Settings\Anita\Cookies\anita@valueclick[1].txt
C:\Documents and Settings\Anita\Cookies\anita@vhost.oddcast[2].txt
C:\Documents and Settings\Anita\Cookies\anita@videoegg.adbureau[2].txt
C:\Documents and Settings\Anita\Cookies\anita@web4.realtracker[1].txt
C:\Documents and Settings\Anita\Cookies\anita@weborama[1].txt
C:\Documents and Settings\Anita\Cookies\anita@wotifcom.112.2o7[1].txt
C:\Documents and Settings\Anita\Cookies\anita@wt.sexsearch[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.3dstats[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.burstbeacon[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.burstnet[2].txt
C:\Documents and Settings\Anita\Cookies\anita@www.checkmystats.com[2].txt
C:\Documents and Settings\Anita\Cookies\anita@www.countrylink[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.discountnewcars.com[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.fatpenguinmedia[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.bleeparoo[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.googleadservices[10].txt
C:\Documents and Settings\Anita\Cookies\anita@www.googleadservices[11].txt
C:\Documents and Settings\Anita\Cookies\anita@www.googleadservices[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.googleadservices[2].txt
C:\Documents and Settings\Anita\Cookies\anita@www.googleadservices[3].txt
C:\Documents and Settings\Anita\Cookies\anita@www.googleadservices[4].txt
C:\Documents and Settings\Anita\Cookies\anita@www.googleadservices[5].txt
C:\Documents and Settings\Anita\Cookies\anita@www.incentaclick[2].txt
C:\Documents and Settings\Anita\Cookies\anita@www.bleepbot[2].txt
C:\Documents and Settings\Anita\Cookies\anita@www.porn-sex-pussy[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.ppctracking[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.pstats[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www.w3counter[2].txt
C:\Documents and Settings\Anita\Cookies\anita@www.xxx69[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www2.addfreestats[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www3.addfreestats[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www5.addfreestats[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www6.addfreestats[1].txt
C:\Documents and Settings\Anita\Cookies\anita@www7.addfreestats[2].txt
C:\Documents and Settings\Anita\Cookies\anita@xiti[1].txt
C:\Documents and Settings\Anita\Cookies\anita@xxxcounter[1].txt
C:\Documents and Settings\Anita\Cookies\anita@yadro[2].txt

Browser Hijacker.Internet Explorer Settings Hijack
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\Microsoft\Internet Explorer\Main#Start Page [ http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2 ]

Trojan.DNSChanger-Codec
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\uninstall

Rogue.PC-Cleaner
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\dpcproxy
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\fwbd
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\HolLol
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\Inet Delivery
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\Invictus
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\mwc
HKU\S-1-5-21-1449742115-3956808350-3667102658-1013\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad#SystemCheck2

Trojan.Unclassified/Multi-Dropper (Packed)
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\BQRSVARW\LMXOVQZK.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E8C9669E-7F4A-4B7A-8A5C-506AFCDDCC43}\RP6\A0001242.EXE

Trojan.Unknown Origin
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\WINTSU.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E8C9669E-7F4A-4B7A-8A5C-506AFCDDCC43}\RP3\A0001083.EXE

Trojan.Unclassified/GTS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E8C9669E-7F4A-4B7A-8A5C-506AFCDDCC43}\RP3\A0001093.DLL

Adware.Vundo-Variant/J
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E8C9669E-7F4A-4B7A-8A5C-506AFCDDCC43}\RP3\A0001094.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E8C9669E-7F4A-4B7A-8A5C-506AFCDDCC43}\RP3\A0001095.DLL

Trojan.Fake-Drop/Gen
C:\WINDOWS\SYSTEM32\AKTTZN.EXE
C:\WINDOWS\SYSTEM32\ANTICIPATOR.DLL
C:\WINDOWS\SYSTEM32\AWTOOLB.DLL
C:\WINDOWS\SYSTEM32\BDN.COM
C:\WINDOWS\SYSTEM32\H@TKEYSH@@K.DLL
C:\WINDOWS\SYSTEM32\HOPROXY.DLL
C:\WINDOWS\SYSTEM32\HXIWLGPM.DAT
C:\WINDOWS\SYSTEM32\HXIWLGPM.EXE
C:\WINDOWS\SYSTEM32\MEDUP012.DLL
C:\WINDOWS\SYSTEM32\MEDUP020.DLL
C:\WINDOWS\SYSTEM32\MSGP.EXE
C:\WINDOWS\SYSTEM32\MSNBHO.DLL
C:\WINDOWS\SYSTEM32\MSSECU.EXE
C:\WINDOWS\SYSTEM32\MSVCHOST.EXE
C:\WINDOWS\SYSTEM32\MTR2.EXE
C:\WINDOWS\SYSTEM32\MWIN32.EXE
C:\WINDOWS\SYSTEM32\NETODE.EXE
C:\WINDOWS\SYSTEM32\NEWSD32.EXE
C:\WINDOWS\SYSTEM32\PS1.EXE
C:\WINDOWS\SYSTEM32\REGC64.DLL
C:\WINDOWS\SYSTEM32\REGM64.DLL
C:\WINDOWS\SYSTEM32\RUNDL1.EXE
C:\WINDOWS\SYSTEM32\SSURF022.DLL
C:\WINDOWS\SYSTEM32\SSVCHOST.COM
C:\WINDOWS\SYSTEM32\SSVCHOST.EXE
C:\WINDOWS\SYSTEM32\SYSREQ.EXE
C:\WINDOWS\SYSTEM32\TAACK.DAT
C:\WINDOWS\SYSTEM32\TAACK.EXE
C:\WINDOWS\SYSTEM32\TEMP#01.EXE
C:\WINDOWS\SYSTEM32\THUN.DLL
C:\WINDOWS\SYSTEM32\THUN32.DLL
C:\WINDOWS\SYSTEM32\VBIEWER.OCX
C:\WINDOWS\SYSTEM32\VBSYS2.DLL
C:\WINDOWS\SYSTEM32\VCATCHPI.DLL
C:\WINDOWS\SYSTEM32\WINLOGONPC.EXE
C:\WINDOWS\SYSTEM32\WINSYSTEM.EXE

Dpcproxy
C:\WINDOWS\SYSTEM32\DPCPROXY.EXE

Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\PSOF1.EXE

Adware.Pacer D
C:\WINDOWS\SYSTEM32\PSOFT1.EXE

Trojan.Dluca-I
C:\WINDOWS\SYSTEM32\SNCNTR.EXE

#8 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:01 AM

Posted 07 May 2008 - 04:16 PM

Please post a new log from DSS.
How is your computer behaving now?
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#9 kuebd

kuebd
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:01 AM

Posted 11 May 2008 - 07:02 PM

Hi Sam,
My apologies for not be able to reply for a few days.....

Computer is running really well thanks to you......all pop ups seem to have gone, start up is quick and all programs seem to be running well.
I only get two issues both on boot up.

Of the two issues on start up one seems to hold up things until cancelled and I get the following message.
Windows - No disk
Exception processing message
C0000013 Parameters 75b6bf9c 75b6bf9c 75b6bf9c
I may need to cancel this 2-3 times and start up continues

The other is the message Bigpond Cable Broadband Login connection failed but this does not hold start up and internet connection is available.
I close this message with a click on Ok and all is good.

The first one is a little annoying as it seems to hold up the loading of a few processes but doesn't seem to be a real big problem.

Again many thanks for getting my computer back on track.

Regards
Ken




Deckard's System Scanner v20071014.68
Run by Ken on 2008-05-12 09:39:19
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Percentage of Memory in Use: 85% (more than 75%).


-- HijackThis (run as Ken.exe) -------------------------------------------------

logfile has no content; running clone.
-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-05-12 09:39:30
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Telstra\Cable Login\bpcService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\Dit.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Telstra\Cable Login\bpcable.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Ken\Desktop\dss.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar2.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [BigPondCable] "C:\Program Files\Telstra\Cable Login\bpcable.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1178534350187
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/flash...ent/swflash.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: BigPond Broadband Cable Login (bpcService) - Unknown owner - C:\Program Files\Telstra\Cable Login\bpcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O24 - Desktop Component 0: - http://cybernet.m7z.net/www.cybernetentert...h/200//9.jpgO24 - Desktop Component 1: - file:///C:/DOCUME~1/Ken/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 11093 bytes

-- Files created between 2008-04-12 and 2008-05-12 -----------------------------

2008-05-07 20:28:17 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-07 20:27:09 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-05-07 20:27:09 0 d-------- C:\Documents and Settings\Ken\Application Data\SUPERAntiSpyware.com
2008-05-07 17:34:54 0 d-------- C:\Documents and Settings\Anita\Application Data\Google
2008-05-05 16:17:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Google
2008-05-05 16:17:52 0 d-------- C:\Program Files\Google
2008-05-05 14:49:09 68096 --a------ C:\WINDOWS\zip.exe
2008-05-05 14:49:09 49152 --a------ C:\WINDOWS\VFind.exe
2008-05-05 14:49:09 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-05-05 14:49:09 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-05-05 14:49:09 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-05-05 14:49:09 98816 --a------ C:\WINDOWS\sed.exe
2008-05-05 14:49:09 80412 --a------ C:\WINDOWS\grep.exe
2008-05-05 14:49:09 73728 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-05-03 14:00:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-03 14:00:19 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 10:48:50 0 d-------- C:\WINDOWS\Sun
2008-04-28 10:48:50 0 d-------- C:\Documents and Settings\Anita\Application Data\Sun
2008-04-27 21:44:28 0 d-------- C:\Documents and Settings\Ken\Application Data\TmpRecentIcons
2008-04-27 21:26:02 0 d-------- C:\Program Files\Trend Micro
2008-04-27 20:19:04 0 d-------- C:\Documents and Settings\Anita\Application Data\TmpRecentIcons


-- Find3M Report ---------------------------------------------------------------

2008-05-07 20:26:24 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-05 16:19:41 0 d-------- C:\Documents and Settings\Ken\Application Data\Google
2008-05-05 16:17:23 0 d-------- C:\Program Files\Java
2008-03-22 18:12:04 0 d-------- C:\Documents and Settings\Ken\Application Data\Real


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="C:\WINDOWS\htpatch.exe" [31/10/2002 02:40 AM]
"SoundMan"="SOUNDMAN.EXE" [28/10/2002 04:38 PM C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [28/07/2003 01:19 PM]
"nwiz"="nwiz.exe" [28/07/2003 01:19 PM C:\WINDOWS\system32\nwiz.exe]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [09/07/2001 08:50 PM]
"Dit"="Dit.exe" [29/08/2002 07:43 AM C:\WINDOWS\Dit.exe]
"VOBRegCheck"="C:\WINDOWS\System32\VOBREGCheck.exe" [09/01/2003 09:55 AM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [24/07/2002 05:20 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07/12/2003 12:30 PM]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [20/08/2002 09:29 AM]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []
"BigPondCable"="C:\Program Files\Telstra\Cable Login\bpcable.exe" [03/07/2006 12:21 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [24/11/2005 08:44 AM]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [28/06/2004 08:29 PM]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [10/06/2005 07:24 PM]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [10/06/2005 07:21 PM]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [22/05/2006 01:26 PM]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [11/05/2005 11:12 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 04:25 AM]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [16/02/2008 12:56 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 05:56 PM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [14/10/2004 02:24 AM]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [18/07/2002 05:00 AM]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [19/08/2005 06:34 PM]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" []
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [29/02/2008 04:03 PM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [11/05/2005 11:23:26 PM]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1/08/1997]
Microsoft Works Calendar Reminders.lnk - C:\WINDOWS\Installer\{f04aff5e-362e-11d3-81ab-00c04fb932ba}\4AA756BB.exe [30/04/2003 7:35:14 PM]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1/08/1997]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=1 (0x1)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-05-12 09:40:25 ------------

#10 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:01 AM

Posted 12 May 2008 - 09:00 AM

Run Hijackthis again, click scan, and Put a checkmark next to the line listed below. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

O4 - HKLM\..\Run: [Dit] Dit.exe


Reboot your computer and let me know if you still get that first error message.


For that other message, check this link for a possible fix.

http://users.bigpond.net.au/bigpond_help/t...k_fix/2033e.htm


Let me know how it goes.
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================

#11 kuebd

kuebd
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:01 AM

Posted 13 May 2008 - 05:57 PM

Sam,
Hats off to you.....
Me thinks you are a wizard....message gone

Really appreciate your time and effort...thanks

Should I uninstall any of the items we downloaded or is it all good.

Regards
Ken

#12 Buckeye_Sam

Buckeye_Sam

    Malware Expert


  • Members
  • 17,382 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pickerington, Ohio
  • Local time:08:01 AM

Posted 13 May 2008 - 10:52 PM

All good! :blink:

Just a few last things and you should be good to go! :wacko:


First, your log shows that you don't have the recovery console installed.
Check this link for more info on the recovery console and how to get it installed.

How to install and use the Windows XP Recovery Console



===================



Next, let's remove Combofix now that we're done with it and clean up a few other things.
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK

    • Posted Image
  • When shown the disclaimer, Select "2"



==================



Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point left over from what we have just cleaned.

    You can find instructions on how to enable and reenable system restore here:

    Windows XP System Restore Guide

    Renable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

:thumbsup: :)
Posted Image If I have helped you in any way, please consider a donation to help me continue the fight against malware.


Failing to respond back to the person that is giving up their own time to help you not only is insensitive and disrespectful, but it guarantees that you will never receive help from me again. Please thank your helpers and there will always be help here when you need it!


========================================================




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users