Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Virtumonde


  • This topic is locked This topic is locked
6 replies to this topic

#1 Brent824

Brent824

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:42 PM

Posted 27 May 2008 - 05:34 PM

I have tried Spybot, Adaware, PC Doctor, etc. and cannot remove Virtumonde. My system cannot connect to many websites, and I constantly get popup ads.

Deckard's System Scanner v20071014.68
Run by Brent Adair on 2008-05-27 17:12:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
9: 2008-05-27 03:50:46 UTC - RP123 - Removed Ad-Aware
8: 2008-05-26 20:57:22 UTC - RP122 - Windows Backup
7: 2008-05-26 20:54:37 UTC - RP121 - Scheduled Checkpoint
6: 2008-05-24 23:44:27 UTC - RP120 - Ad-Aware Restore Point 2008-05-24 18:44:25
5: 2008-05-24 02:36:51 UTC - RP118 - Installed Ad-Aware


-- First Restore Point --
1: 2008-05-23 03:28:17 UTC - RP112 - Windows Update


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Brent Adair.exe) -----------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:16:11 PM, on 5/27/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\Brent Adair\Desktop\dss.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Brent Adair.exe
c:\PROGRA~1\mcafee\msc\mcupdui.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8053AF4F-F35D-4EC6-A411-039EFB515CD8} - C:\Windows\system32\pmnkhFVO.dll
O2 - BHO: (no name) - {8C5DDD78-F0EE-4F03-A02C-9CA3BCE7B075} - C:\Windows\system32\ljJbXnoO.dll
O2 - BHO: {a6dd39aa-c5d7-15eb-46f4-053d368298ef} - {fe892863-d350-4f64-be51-7d5caa93dd6a} - C:\Windows\system32\qmcoxpkl.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\urQkkjJy.dll,#1
O4 - HKLM\..\Run: [38ab5838] rundll32.exe "C:\Windows\system32\hsxlsnyy.dll",b
O4 - HKLM\..\Run: [BM3b986ba4] Rundll32.exe "C:\Windows\system32\swugenco.dll",s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.beatport.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/...S/wlscctrl2.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Sprint Con App Svc (CASprint) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - PCTEL - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10771 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080523-154018-428 O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
backup-20080523-154018-699 O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\ssqOFxWq.dll,#1
backup-20080523-154018-920 O4 - HKLM\..\Run: [BM3b986ba4] Rundll32.exe "C:\Windows\system32\khqkcmcl.dll",s
backup-20080523-154018-963 O2 - BHO: (no name) - {BFBB8732-BAB2-462C-B794-9AE7505895B0} - C:\Windows\system32\ljJbXnoO.dll
backup-20080523-154127-610 O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\ssqOFxWq.dll,#1
backup-20080523-154127-739 O4 - HKLM\..\Run: [BM3b986ba4] Rundll32.exe "C:\Windows\system32\khqkcmcl.dll",s
backup-20080523-154127-927 O2 - BHO: (no name) - {BFBB8732-BAB2-462C-B794-9AE7505895B0} - C:\Windows\system32\ljJbXnoO.dll

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

All drivers whitelisted.


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 PLFlash DeviceIoControl Service - c:\windows\system32\ioctlsvc.exe <Not Verified; Prolific Technology Inc.; IoctlSvc Application>

S3 Com4Qlb - "c:\program files\hewlett-packard\hp quick launch buttons\com4qlb.exe" <Not Verified; Hewlett-Packard Development Company, L.P.; HP Quick Launch Buttons>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-05-27 17:10:32 430 --ah----- C:\Windows\Tasks\User_Feed_Synchronization-{1848469F-3F60-461B-828A-5CE68295DE70}.job
2008-05-15 01:42:53 352 --a------ C:\Windows\Tasks\McDefragTask.job
2008-05-01 01:00:04 344 --a------ C:\Windows\Tasks\McQcTask.job


-- Files created between 2008-04-27 and 2008-05-27 -----------------------------

2008-05-27 15:53:40 0 d-------- C:\Users\All Users\Kaspersky Lab
2008-05-27 15:53:38 0 d-------- C:\Windows\system32\Kaspersky Lab
2008-05-27 09:53:53 0 d-------- C:\Windows\pss
2008-05-27 09:34:17 0 d-------- C:\VundoFix Backups
2008-05-26 22:53:04 2560 --a------ C:\Windows\system32\hchjncdj.exe
2008-05-26 22:52:07 0 d-------- C:\Windows\system32\appmgmt
2008-05-26 22:50:47 124928 --a------ C:\Windows\system32\bltbcyda.dll
2008-05-26 22:37:10 124928 --a------ C:\Windows\system32\esvviapu.dll
2008-05-26 22:31:15 57344 --a------ C:\Windows\system32\pmnkhFVO.dll
2008-05-26 15:02:05 345 --ahs---- C:\Windows\system32\rtCccccf.ini2
2008-05-26 15:01:56 371200 --a------ C:\Windows\system32\fccccCtr.dll
2008-05-24 13:03:49 2560 --a------ C:\Windows\system32\hsjiaekv.exe
2008-05-24 12:58:27 126464 --a------ C:\Windows\system32\tlybtwxe.dll
2008-05-24 12:57:46 888134 --ahs---- C:\Windows\system32\vFiQWwEg.ini2
2008-05-24 12:57:39 371712 --a------ C:\Windows\system32\gEwWQiFv.dll
2008-05-23 21:37:31 0 d-------- C:\Users\All Users\Lavasoft
2008-05-23 21:24:59 0 d-------- C:\Program Files\Windows Live Safety Center
2008-05-23 19:30:53 133632 --a------ C:\Windows\system32\qmcoxpkl.dll
2008-05-23 19:25:36 126464 --a------ C:\Windows\system32\orykhkei.dll
2008-05-23 19:20:59 126464 --a------ C:\Windows\system32\owamewwc.dll
2008-05-23 19:10:13 0 d-------- C:\Program Files\Enigma Software Group
2008-05-23 19:00:29 2560 --a------ C:\Windows\system32\myquungh.exe
2008-05-23 18:58:10 126464 --a------ C:\Windows\system32\jmbuklut.dll
2008-05-23 16:11:11 126464 --a------ C:\Windows\system32\ueuhhhxp.dll
2008-05-23 16:00:56 0 d-------- C:\Program Files\PCPitstop
2008-05-23 15:35:09 2560 --a------ C:\Windows\system32\uarbihlh.exe
2008-05-23 15:32:11 0 d-------- C:\Program Files\Trend Micro
2008-05-23 15:10:44 126464 --a------ C:\Windows\system32\khqkcmcl.dll
2008-05-23 15:08:40 126464 --a------ C:\Windows\system32\gyjeolml.dll
2008-05-23 11:16:37 0 d-------- C:\Program Files\Sierra Wireless
2008-05-23 11:16:00 0 d-------- C:\Program Files\Common Files\PctelEapPeer Authentication
2008-05-23 11:15:54 0 d-------- C:\Program Files\Sprint
2008-05-23 11:15:54 0 d-------- C:\Program Files\Novatel Wireless
2008-05-23 10:36:22 0 -rahs---- C:\MSDOS.SYS
2008-05-23 10:36:22 0 -rahs---- C:\IO.SYS
2008-05-22 22:32:11 126464 --a------ C:\Windows\system32\swugenco.dll
2008-05-22 22:26:54 897776 --ahs---- C:\Windows\system32\rBaHPXyb.ini2
2008-05-22 19:42:03 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-21 22:11:52 345 --ahs---- C:\Windows\system32\PWDMmnpo.ini2
2008-05-21 10:41:09 0 d-------- C:\Program Files\ImTOO(0)
2008-05-21 10:14:51 0 d-------- C:\Program Files\Yahoo!
2008-05-21 09:47:33 0 d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-05-20 22:29:47 806995 --ahs---- C:\Windows\system32\OonXbJjl.ini2
2008-05-20 22:29:42 370176 -----n--- C:\Windows\system32\ljJbXnoO.dll
2008-05-20 22:25:00 0 d-------- C:\Program Files\ImTOO
2008-05-09 11:17:33 0 d-------- C:\Program Files\MixMeister Fusion 7.2.2
2008-05-05 21:12:41 0 d-------- C:\Users\All Users\Logitech
2008-05-05 21:12:36 0 d-------- C:\Program Files\Common Files\Logishrd
2008-05-05 21:12:30 0 d-------- C:\Program Files\Logitech
2008-05-05 21:12:03 0 d-------- C:\Users\All Users\LogiShrd
2008-04-29 16:22:36 0 d-------- C:\Program Files\Trillian
2008-04-28 22:03:08 0 d-------- C:\Users\Default\Roaming
2008-04-28 22:03:08 0 d-------- C:\Users\Brent Adair\Roaming
2008-04-28 22:03:02 0 d-------- C:\Program Files\MySpace


-- Find3M Report ---------------------------------------------------------------

2008-05-26 22:52:06 0 d-------- C:\Program Files\Common Files
2008-05-23 21:38:14 0 d-------- C:\Program Files\chatClient
2008-05-23 11:29:19 0 d-------- C:\Users\Brent Adair\AppData\Roaming\LimeWire
2008-05-21 21:02:00 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Winamp
2008-05-21 10:15:12 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Yahoo!
2008-05-20 22:11:35 0 d-------- C:\Users\Brent Adair\AppData\Roaming\dvdcss
2008-05-19 16:10:27 0 d-------- C:\Program Files\Microsoft Silverlight
2008-05-18 03:04:24 0 d-------- C:\Program Files\Easy CD-DA Extractor 11
2008-05-16 20:01:03 0 d-------- C:\Users\Brent Adair\AppData\Roaming\NeroDCTemplates
2008-05-14 03:03:59 0 d-------- C:\Program Files\Windows Mail
2008-05-13 17:15:37 256 --a------ C:\Windows\system32\pool.bin
2008-05-09 11:18:09 0 d-------- C:\Users\Brent Adair\AppData\Roaming\MixMeister Technology
2008-05-05 21:16:51 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Logitech
2008-05-05 21:16:02 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-30 18:09:40 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Skype
2008-04-30 18:07:51 0 d-------- C:\Users\Brent Adair\AppData\Roaming\skypePM
2008-04-29 16:24:07 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Trillian
2008-04-29 13:49:28 0 d-------- C:\Users\Brent Adair\AppData\Roaming\FileZilla
2008-04-28 22:03:07 0 d-------- C:\Users\Brent Adair\AppData\Roaming\MySpace
2008-04-25 10:30:17 0 d-------- C:\Program Files\SureThing CD Labeler 5
2008-04-25 10:26:19 0 d-------- C:\Program Files\Common Files\SureThing Shared
2008-04-24 17:14:53 0 d-------- C:\Program Files\LimeWire
2008-04-23 16:03:10 0 d-------- C:\Program Files\Skype
2008-04-23 16:03:07 0 d-------- C:\Program Files\Common Files\Skype
2008-04-21 22:20:35 0 d-------- C:\Program Files\Apple Software Update
2008-04-19 20:56:21 0 d-------- C:\Program Files\Common Files\LightScribe
2008-04-19 20:33:17 0 d-------- C:\Program Files\FileZilla FTP Client
2008-04-19 13:23:32 0 d-------- C:\Program Files\Picasa2
2008-04-19 13:23:22 0 d-------- C:\Program Files\Google
2008-04-19 13:21:35 0 d-------- C:\Program Files\Java
2008-04-18 11:21:58 61440 --a------ C:\Windows\system32\pxfhwmcp.dll <Not Verified; DEVGURU; Application Interface DLL>
2008-04-17 21:37:18 0 d-------- C:\Program Files\Common Files\Java
2008-04-17 21:19:13 0 d-------- C:\Program Files\Filetopia3
2008-04-16 22:49:48 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-16 21:35:25 0 d-------- C:\Program Files\HPQ
2008-04-16 21:32:03 0 d-------- C:\Program Files\Hewlett-Packard
2008-04-16 21:31:42 0 d-------- C:\Users\Brent Adair\AppData\Roaming\InstallShield
2008-04-16 21:29:58 0 d-------- C:\Program Files\TIVistadriver
2008-04-15 23:07:33 0 d-------- C:\Program Files\QuickTime
2008-04-14 22:36:28 0 d-------- C:\Program Files\Common Files\AnswerWorks 5.0
2008-04-14 22:09:47 0 d-------- C:\Program Files\Common Files\Motorola Shared
2008-04-14 21:51:26 0 d-------- C:\Program Files\BitComet
2008-04-14 21:48:32 2560 --a------ C:\Windows\system32\bitcometres.dll <Not Verified; BitComet; BitComet BCTP Helper>
2008-04-14 21:43:49 0 d-------- C:\Program Files\Winamp
2008-04-14 21:32:25 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Blackberry Desktop
2008-04-14 21:30:57 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Research In Motion
2008-04-14 10:26:46 0 d-------- C:\Program Files\Common Files\PX Storage Engine
2008-04-14 10:26:45 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-04-14 10:26:14 0 d-------- C:\Program Files\Roxio
2008-04-14 10:24:18 0 d-------- C:\Program Files\Common Files\Roxio Shared
2008-04-14 10:16:36 0 d-------- C:\Program Files\Common Files\Research In Motion
2008-04-14 10:16:11 0 d-------- C:\Program Files\Research In Motion
2008-04-14 03:12:19 0 d-------- C:\Program Files\McAfee
2008-04-14 03:01:11 0 d-------- C:\Program Files\MSXML 4.0
2008-04-13 19:30:29 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Adobe
2008-04-13 19:27:42 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-13 19:03:52 0 d-------- C:\Program Files\Microsoft Works
2008-04-13 19:03:28 0 d-------- C:\Program Files\MSBuild
2008-04-13 19:01:15 0 d-------- C:\Program Files\Microsoft.NET
2008-04-13 18:57:38 0 d-------- C:\Program Files\Microsoft Visual Studio 8
2008-04-13 18:38:01 0 d-------- C:\Program Files\TagRename
2008-04-13 18:30:11 0 d-------- C:\Program Files\Common Files\McAfee
2008-04-13 18:29:49 0 d-------- C:\Program Files\McAfee.com
2008-04-13 18:20:35 0 d-------- C:\Program Files\Deejaysystem
2008-04-13 18:10:09 0 d-------- C:\Program Files\NeroInstall.bak
2008-04-13 18:07:54 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Nero
2008-04-13 18:06:50 0 d-------- C:\Program Files\Common Files\Nero
2008-04-13 18:05:37 0 d-------- C:\Program Files\Nero
2008-04-13 17:55:56 0 d-------- C:\Users\Brent Adair\AppData\Roaming\WinRAR
2008-04-13 17:44:16 0 d-------- C:\Program Files\Quicken
2008-04-13 17:40:07 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Intuit
2008-04-13 17:39:35 0 d-------- C:\Program Files\Common Files\Palo Alto Software
2008-04-13 17:39:31 0 d-------- C:\Program Files\Common Files\Intuit
2008-04-13 17:37:42 0 d-------- C:\Program Files\DAEMON Tools Lite
2008-04-13 17:37:28 0 d-------- C:\Users\Brent Adair\AppData\Roaming\DAEMON Tools
2008-04-13 15:26:47 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Macromedia
2008-04-13 15:09:24 0 d-------- C:\Program Files\Synaptics
2008-04-13 15:08:41 0 d-------- C:\Program Files\CONEXANT
2008-04-13 15:01:20 174 --ahs---- C:\Program Files\desktop.ini
2008-04-13 14:56:41 0 d-------- C:\Program Files\Windows Calendar
2008-04-13 14:56:39 0 d-------- C:\Program Files\Windows Defender
2008-04-13 14:56:36 0 d-------- C:\Program Files\BitLocker
2008-04-13 14:56:34 0 d-------- C:\Program Files\Windows Sidebar
2008-04-13 14:56:34 0 d-------- C:\Program Files\Microsoft Games
2008-04-13 13:40:06 0 d-------- C:\Users\Brent Adair\AppData\Roaming\Identities
2008-04-11 17:23:54 38400 --a------ C:\Windows\system32\SoundSchemes.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8053AF4F-F35D-4EC6-A411-039EFB515CD8}]
05/20/2008 10:24 PM 57344 --a------ C:\Windows\system32\pmnkhFVO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C5DDD78-F0EE-4F03-A02C-9CA3BCE7B075}]
05/20/2008 10:29 PM 370176 --------- C:\Windows\system32\ljJbXnoO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fe892863-d350-4f64-be51-7d5caa93dd6a}]
05/23/2008 07:30 PM 133632 --a------ C:\Windows\system32\qmcoxpkl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [04/13/2008 02:39 PM]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [02/11/2008 08:13 PM]
"Persistence"="C:\Windows\system32\igfxpers.exe" [02/11/2008 08:13 PM]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [09/15/2007 02:29 AM]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [02/18/2008 04:29 PM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 07:12 PM]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [08/24/2007 07:00 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"@"="" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"QlbCtrl.exe"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [10/19/2007 01:28 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [09/21/2007 03:10 AM C:\Windows\KHALMNPR.Exe]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [05/20/2008 10:55 AM]
"MSServer"="C:\Windows\system32\urQkkjJy.dll" []
"38ab5838"="C:\Windows\system32\hsxlsnyy.dll" []
"BM3b986ba4"="C:\Windows\system32\swugenco.dll" [05/22/2008 10:32 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [04/13/2008 02:19 PM]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [04/01/2008 04:39 AM]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [02/28/2008 05:07 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 07:33 AM]

C:\Users\Brent Adair\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [8/24/2007 4:45:42 AM]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [5/7/2008 7:30:44 PM]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [5/5/2008 9:13:00 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8053AF4F-F35D-4EC6-A411-039EFB515CD8}"= C:\Windows\system32\pmnkhFVO.dll [05/20/2008 10:24 PM 57344]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\Windows\system32\ljJbXnoO

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BM3b986ba4"=Rundll32.exe "C:\Windows\system32\swugenco.dll",s
"IgfxTray"=C:\Windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
GPSvcGroup GPSvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f1e8e7c-09a9-11dd-bf1f-0016d40d32bc}]
AutoRun\command- E:\AUTORUN.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration



-- Hosts -----------------------------------------------------------------------

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

8520 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-05-27 17:18:25 ------------

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft® Windows Vista™ Ultimate (build 6000)
Architecture: X86; Language: English

CPU 0: Genuine Intel® CPU T2050 @ 1.60GHz
Percentage of Memory in Use: 45%
Physical Memory (total/avail): 2037.5 MiB / 1103.13 MiB
Pagefile Memory (total/avail): 4294.3 MiB / 3258.04 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1904.57 MiB

C: is Fixed (NTFS) - 111.79 GiB total, 34.34 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
L: is Network (NTFS)
Q: is Network (NTFS)

\\.\PHYSICALDRIVE0 - FUJITSU MHY2120BH ATA Device - 111.79 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 111.79 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

AV: McAfee VirusScan v (McAfee)
AS: McAfee VirusScan v (McAfee) Disabled
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Brent Adair\AppData\Roaming
CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=BRENT-LAPTOP
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Brent Adair
LOCALAPPDATA=C:\Users\Brent Adair\AppData\Local
LOGONSERVER=\\BRENT-LAPTOP
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 14 Stepping 8, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0e08
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip
RoxioCentral=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\BRENTA~1\AppData\Local\Temp
TMP=C:\Users\BRENTA~1\AppData\Local\Temp
USERDOMAIN=Brent-Laptop
USERNAME=Brent Adair
USERPROFILE=C:\Users\Brent Adair
windir=C:\Windows


-- User Profiles ---------------------------------------------------------------

Brent Adair (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\Windows\UNNeroBackItUp.exe /UNINSTALL
--> C:\Windows\UNNeroMediaHome.exe /UNINSTALL
--> C:\Windows\UNNeroShowTime.exe /UNINSTALL
--> C:\Windows\UNNeroVision.exe /UNINSTALL
--> C:\Windows\UNRecode.exe /UNINSTALL
--> MsiExec.exe /I{2BE0C605-9BEC-434D-9FAE-931194E72414}
--> MsiExec.exe /I{48A669A9-76FA-4CA8-BFD5-00C125AC4166}
--> MsiExec.exe /I{726A362E-EBFD-4C3F-8664-6593C2B08386}
--> MsiExec.exe /I{943CB81D-11B9-401E-8305-752528D00AA1}
--> MsiExec.exe /I{E75F019D-98A0-4B39-B1A8-3A01400D2A18}
--> MsiExec.exe /X{F664EDB9-59DF-452A-A3D7-085ED1B8D374}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
Adobe Flash Player ActiveX --> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player 11 --> C:\Windows\system32\adobe\SHOCKW~1\UNWISE.EXE C:\Windows\system32\Adobe\SHOCKW~1\Install.log
Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
BitComet 1.00 --> C:\Program Files\BitComet\uninst.exe
BlackBerry Desktop Software 4.3 --> MsiExec.exe /I{D793A12F-E362-48BB-B332-1DA5E936B52D}
BlackBerry Desktop Software 4.3 --> MsiExec.exe /i{D793A12F-E362-48BB-B332-1DA5E936B52D}
BlackBerry Device Software v4.3.0 for the BlackBerry 8130 smartphone --> MsiExec.exe /X{0FCBD242-1076-4D71-BF36-B7267F6A7032}
CDDRV_Installer --> MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
Chat Client --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1D71A696-7CCD-4E11-A0DA-618282F1AD7C}\Setup.exe" -l0x9
CleanUp! --> C:\Program Files\CleanUp!\uninstall.exe
Deejaysystem™ Mk-I release 5a --> "C:\Program Files\Deejaysystem\Djs Mk-I\unins000.exe"
erLT --> MsiExec.exe /I{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}
Filetopia Client v3.04d --> C:\PROGRA~1\FILETO~1\UNWISE.EXE C:\PROGRA~1\FILETO~1\INSTALL.LOG
FileZilla Client 3.0.9.2 --> C:\Program Files\FileZilla FTP Client\uninstall.exe
GEAR 32bit Driver Installer --> MsiExec.exe /X{E89B484C-B913-49A0-959B-89E836001658}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HP Quick Launch Buttons 6.30 J1 --> C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\Setup.exe -runfromtemp -l0x0009 -removeonly uninst
ImTOO DVD Ripper Ultimate --> C:\Program Files\ImTOO\DVD Ripper Ultimate 5\Uninstall.exe
Intel® Graphics Media Accelerator Driver --> C:\Windows\system32\igxpun.exe -uninstall
Intel® Network Connections Drivers --> Prounstl.exe
Java™ 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Kaspersky Online Scanner --> C:\Windows\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
KhalInstallWrapper --> MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
LimeWire 4.16.7 --> "C:\Program Files\LimeWire\uninstall.exe"
Logitech Desktop Messenger --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\SETUP.EXE" -l0x9 UNINSTALL
Logitech SetPoint --> C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x0009 -removeonly
McAfee SecurityCenter --> C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISER /dll OSETUP.DLL
Microsoft Office Enterprise 2007 --> MsiExec.exe /X{91120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Silverlight --> MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
MixMeister Fusion 7.2.2 --> "C:\Program Files\MixMeister Fusion 7.2.2\unins000.exe"
MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833) --> MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
Nero 8 --> MsiExec.exe /X{BE282C23-5484-47FF-B2C1-EBEA5C891033}
neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
Picasa 2 --> "C:\Program Files\Picasa2\Uninstall.exe"
Quicken 2008 --> MsiExec.exe /X{3B0F52AC-EF5C-4831-B221-06C782E41280}
QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
Roxio Media Manager --> MsiExec.exe /X{303379C9-8610-4CCF-AF37-C4BF8998C591}
Security Update for Excel 2007 (KB946974) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
Security Update for Microsoft Office Publisher 2007 (KB950114) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {F9C3CDBA-1F00-4D4D-959D-75C9D3ACDD85}
Security Update for Microsoft Office system 2007 (KB951808) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00}
Security Update for Microsoft Office Word 2007 (KB950113) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9}
Security Update for Office 2007 (KB947801) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
Security Update for Outlook 2007 (KB946983) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}
Security Update for Visio 2007 (KB947590) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Skype™ 3.6 --> MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Soft Data Fax Modem with SmartCP --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_5045_wis30A5z\UIU32m.exe -U -Iwis30A5z.inf
Sprint SmartView --> MsiExec.exe /X{C5BE83A5-3355-4E64-B8A0-FD41ABFB4C8B}
SureThing CD Labeler Deluxe 5.0.593.0 --> "C:\Program Files\SureThing CD Labeler 5\unins000.exe"
Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Tag&Rename 3.4.6 --> "C:\Program Files\TagRename\unins000.exe"
Texas Instruments PCIxx21/x515/xx12 drivers. --> C:\Program Files\InstallShield Installation Information\{DB780B85-B4B5-4864-A49C-9B706B169C93}\setup.exe -runfromtemp -l0x0409
Trillian --> C:\Program Files\Trillian\Trillian.exe /uninstall
Update for Office 2007 (KB946691) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb950378) --> msiexec /package {91120000-0030-0000-0000-0000000FF1CE} /uninstall {F6296086-AED5-4EC0-938B-08EA0254F20E}
VCRedistSetup --> MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
Winamp --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Live OneCare safety scanner --> "C:\Program Files\Windows Live Safety Center\UnInstall.exe"
Windows Live OneCare safety scanner --> MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type12277 / Error
Event Submitted/Written: 05/27/2008 05:17:38 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application cscript.exe, version 5.7.0.6000, time stamp 0x4549b118, faulting module SHLWAPI.dll, version 6.0.6000.16386, time stamp 0x4549bdb9, exception code 0xc0000005, fault offset 0x0001d856,
process id 0x1764, application start time 0xcscript.exe0.

Event Record #/Type12271 / Error
Event Submitted/Written: 05/27/2008 05:16:11 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application Brent Adair.exe, version 2.0.0.2, time stamp 0x466838c1, faulting module SHLWAPI.dll, version 6.0.6000.16386, time stamp 0x4549bdb9, exception code 0xc0000005, fault offset 0x0001d856,
process id 0x14b8, application start time 0xBrent Adair.exe0.

Event Record #/Type12261 / Success
Event Submitted/Written: 05/27/2008 05:09:29 PM
Event ID/Source: 5617 / WinMgmt
Event Description:


Event Record #/Type12260 / Success
Event Submitted/Written: 05/27/2008 05:09:28 PM
Event ID/Source: 5615 / WinMgmt
Event Description:


Event Record #/Type12251 / Success
Event Submitted/Written: 05/27/2008 05:09:21 PM
Event ID/Source: 902 / Software Licensing Service
Event Description:
The Software Licensing service has started.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type47693 / Warning
Event Submitted/Written: 05/27/2008 05:10:41 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%Brent-Laptop27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %Brent-Laptop27 can't undo changes that you allow.

For more information please see the following:
%Brent-Laptop275

Scan ID: {2C03D60A-61DB-44AA-B046-E27EE84F511C}

User: Brent-Laptop\Brent Adair

Name: %Brent-Laptop271

ID: %Brent-Laptop272

Severity ID: %Brent-Laptop273

Category ID: %Brent-Laptop274

Path Found: %Brent-Laptop276

Alert Type: %Brent-Laptop278

Detection Type: 1.1.1505.02

Event Record #/Type47594 / Warning
Event Submitted/Written: 05/27/2008 05:08:33 PM
Event ID/Source: 4001 / Microsoft-Windows-WLAN-AutoConfig
Event Description:


Event Record #/Type47592 / Error
Event Submitted/Written: 05/27/2008 05:08:30 PM
Event ID/Source: 10005 / DCOM
Event Description:
1068fdPHost{145B4335-FE2A-4927-A040-7C35AD3180EF}

Event Record #/Type47590 / Error
Event Submitted/Written: 05/27/2008 05:08:09 PM
Event ID/Source: 10005 / DCOM
Event Description:
1084MDM{0C0A3666-30C9-11D0-8F20-00805F2CD064}

Event Record #/Type47589 / Error
Event Submitted/Written: 05/27/2008 05:08:06 PM
Event ID/Source: 10005 / DCOM
Event Description:
1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}



-- End of Deckard's System Scanner: finished at 2008-05-27 17:18:25 ------------

KASPERSKY ONLINE SCANNER REPORTKASPERSKY ONLINE SCANNER REPORT
Tuesday, May 27, 2008 5:03:59 PM
Operating System: Microsoft Windows Vista Professional, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/05/2008
Kaspersky Anti-Virus database records: 802914


Scan Settings
Scan using the following antivirus databaseextended
Scan Archivestrue
Scan Mail Basestrue

Scan TargetCritical Areas
C:\Windows
C:\Users\BRENTA~1\AppData\Local\Temp\

Scan Statistics
Total number of scanned objects53912
Number of viruses found6
Number of infected objects19
Number of suspicious objects0
Duration of the scan process00:35:32

Infected Object NameVirus NameLast Action
C:\Windows\CSC\v2.0.6\pq Object is locked skipped

C:\Windows\Debug\PASSWD.LOG Object is locked skipped

C:\Windows\Debug\sam.log Object is locked skipped

C:\Windows\Prefetch\ReadyBoot\ReadyBoot.etl Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked
skipped

C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked
skipped

C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked
skipped

C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{0f694465-6a70-11db-8eb3-985e31beb686}.TM.blf
Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{0f694465-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms
Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{0f694465-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000002.regtrans-ms
Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked
skipped

C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked
skipped

C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked
skipped

C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{01fcd409-2870-11dd-baf4-0016d40d32bc}.TM.blf
Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{01fcd409-2870-11dd-baf4-0016d40d32bc}.TMContainer00000000000000000001.regtrans-ms
Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{01fcd409-2870-11dd-baf4-0016d40d32bc}.TMContainer00000000000000000002.regtrans-ms
Object is locked skipped

C:\Windows\System32\bltbcyda.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.tsz skipped

C:\Windows\System32\catroot2\edb.log Object is locked skipped

C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
Object is locked skipped

C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
Object is locked skipped

C:\Windows\System32\config\COMPONENTS Object is locked skipped

C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped

C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped

C:\Windows\System32\config\DEFAULT Object is locked skipped

C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped

C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped

C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped

C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped

C:\Windows\System32\config\RegBack\SAM Object is locked skipped

C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped

C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped

C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped

C:\Windows\System32\config\SAM Object is locked skipped

C:\Windows\System32\config\SAM.LOG1 Object is locked skipped

C:\Windows\System32\config\SAM.LOG2 Object is locked skipped

C:\Windows\System32\config\SECURITY Object is locked skipped

C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped

C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped

C:\Windows\System32\config\SOFTWARE Object is locked skipped

C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped

C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped

C:\Windows\System32\config\SYSTEM Object is locked skipped

C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped

C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf
Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms
Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms
Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms
Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms
Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000005.regtrans-ms
Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000006.regtrans-ms
Object is locked skipped

C:\Windows\System32\drivers\sptd.sys Object is locked skipped

C:\Windows\System32\esvviapu.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.tsz skipped

C:\Windows\System32\gEwWQiFv.dll Infected: Trojan.Win32.Pakes.cym skipped

C:\Windows\System32\gyjeolml.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.trv skipped

C:\Windows\System32\jmbuklut.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.trv skipped

C:\Windows\System32\khqkcmcl.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.trv skipped

C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped

C:\Windows\System32\orykhkei.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.trv skipped

C:\Windows\System32\owamewwc.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.trv skipped

C:\Windows\System32\pmnkhFVO.dll Infected:
Trojan-Downloader.Win32.Agent.pqh skipped

C:\Windows\System32\swugenco.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.trd skipped

C:\Windows\System32\tlybtwxe.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.tro skipped

C:\Windows\System32\ueuhhhxp.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.trv skipped

C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped

C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped

C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped

C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped

C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped

C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002 Object is locked
skipped

C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped

C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked
skipped

C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked
skipped

C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked
skipped

C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is
locked skipped

C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped


C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx
Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx
Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object
is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx
Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx
Object is locked skipped

C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped

C:\Windows\Temp\mcmsc_yIYXXGW0XqaqOBq Object is locked skipped

C:\Users\BRENTA~1\AppData\Local\Temp\FXSAPIDebugLogFile.txt Object is
locked skipped

C:\Users\BRENTA~1\AppData\Local\Temp\tmp00011c65 Infected:
Trojan-Downloader.Win32.Agent.pqh skipped

C:\Users\BRENTA~1\AppData\Local\Temp\tmp0001420e Infected:
Trojan-Downloader.Win32.Agent.pqh skipped

C:\Users\BRENTA~1\AppData\Local\Temp\tmp0001975e Infected:
Trojan-Downloader.Win32.Agent.pqh skipped

C:\Users\BRENTA~1\AppData\Local\Temp\tmp00026d81 Infected:
Trojan-Downloader.Win32.Agent.pqh skipped

C:\Users\BRENTA~1\AppData\Local\Temp\tmp00032319 Infected:
Trojan-Downloader.Win32.Agent.pqh skipped

C:\Users\BRENTA~1\AppData\Local\Temp\tmp00233f22 Infected:
Trojan-Downloader.Win32.Agent.pqh skipped

C:\Users\BRENTA~1\AppData\Local\Temp\tmp030dbc6b Infected:
Trojan-Downloader.Win32.Agent.pqh skipped

C:\Users\BRENTA~1\AppData\Local\Temp\~DF64D8.tmp Object is locked skipped

C:\Users\BRENTA~1\AppData\Local\Temp\~DF6539.tmp Object is locked skipped

C:\Users\BRENTA~1\AppData\Local\Temp\~DF846E.tmp Object is locked skipped

Scan process completed.

BC AdBot (Login to Remove)

 


#2 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:42 PM

Posted 28 May 2008 - 07:31 AM

Hello Brent824 and welcome to BleepingComputer,

1. * Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Under Browsing History, click Delete.
  • Click Delete Files, Delete cookies and Delete history
  • Click Close below.
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu..
  • Click the Clear now button below.. A new window will popup what to clear.
  • Select all and click the Clear button again.
  • Click OK to close the Options window
* Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.
2. Please download Malwarebytes' Anti-Malware from Here or Here

Doubleclick mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply along with a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

3. Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.
The Windows Recovery Console will allow you to boot up into a special recovery mode, in case your computer has a problem after an attempted removal of malware. This allows us to help you .

In the event you already have Combofix, delete your current version and download the latest version as described in the tutorial.
It must be saved directly to your desktop.


Note: Make sure not to click ComboFix's window while it's running. That may cause it to stall or freeze.

Please post the log from ComboFix (can also be found as C:\ComboFix.txt) in your next reply. :thumbsup:

If you have any questions along the way, STOP and ask them before proceeding !!

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#3 Brent824

Brent824
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:42 PM

Posted 28 May 2008 - 10:29 AM

I'm not sure if Anti-Malware and/or ComboFix successfully removed the infected items, however I greatly appreciate all the help!

Malwarebytes' Anti-Malware 1.12
Database version: 793

Scan type: Quick Scan
Objects scanned: 35265
Time elapsed: 5 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 11
Registry Values Infected: 4
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 11

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Windows\System32\ljJbXnoO.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\Windows\System32\pmnkhFVO.dll (Trojan.Vundo) -> Unloaded module successfully.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8c5ddd78-f0ee-4f03-a02c-9ca3bce7b075} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{8c5ddd78-f0ee-4f03-a02c-9ca3bce7b075} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8053af4f-f35d-4ec6-a411-039efb515cd8} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8053af4f-f35d-4ec6-a411-039efb515cd8} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\38ab5838 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM3b986ba4 (Trojan.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{8053af4f-f35d-4ec6-a411-039efb515cd8} (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ljjbxnoo -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ljjbxnoo -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\fccccCtr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\rtCccccf.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\rtCccccf.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\gEwWQiFv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\vFiQWwEg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\vFiQWwEg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\ljJbXnoO.dll (Trojan.Vundo) -> Delete on reboot.
C:\Windows\System32\OonXbJjl.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\OonXbJjl.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\srlfroai.dll (Trojan.Agent) -> Delete on reboot.
C:\Windows\System32\pmnkhFVO.dll (Trojan.Vundo) -> Delete on reboot.

ComboFix 08-05-27.4 - Brent Adair 2008-05-28 9:51:46.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1033.18.1084 [GMT -5:00]
Running from: C:\Users\Brent Adair\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\bltbcyda.dll
C:\Windows\system32\esvviapu.dll
C:\Windows\system32\gyjeolml.dll
C:\Windows\system32\hchjncdj.exe
C:\Windows\system32\hsjiaekv.exe
C:\Windows\System32\ivwuftnu.ini
C:\Windows\system32\jmbuklut.dll
C:\Windows\system32\khqkcmcl.dll
C:\Windows\system32\ljJbXnoO.dll
C:\Windows\system32\mcrh.tmp
C:\Windows\system32\myquungh.exe
C:\Windows\system32\orykhkei.dll
C:\Windows\system32\owamewwc.dll
C:\Windows\system32\pmnkhFVO.dll
C:\Windows\System32\PWDMmnpo.ini
C:\Windows\System32\PWDMmnpo.ini2
C:\Windows\system32\qmcoxpkl.dll
C:\Windows\System32\rBaHPXyb.ini
C:\Windows\System32\rBaHPXyb.ini2
C:\Windows\system32\srlfroai.dll
C:\Windows\system32\swugenco.dll
C:\Windows\system32\tlybtwxe.dll
C:\Windows\system32\uarbihlh.exe
C:\Windows\system32\ueuhhhxp.dll
C:\Windows\system32\x64
C:\Windows\System32\yynslxsh.ini

.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.

2008-05-28 09:24 . 2008-05-28 09:24 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\Malwarebytes
2008-05-28 09:24 . 2008-05-28 09:24 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-05-28 09:24 . 2008-05-28 09:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-28 09:24 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-28 09:24 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-27 17:04 . 2008-05-27 17:04 <DIR> d-------- C:\Deckard
2008-05-27 15:53 . 2008-05-27 15:53 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-05-27 15:53 . 2008-05-27 15:53 <DIR> d-------- C:\Users\All Users\Kaspersky Lab
2008-05-27 09:34 . 2008-05-27 09:34 <DIR> d-------- C:\VundoFix Backups
2008-05-23 21:37 . 2008-05-26 22:51 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-05-23 21:24 . 2008-05-23 21:27 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-05-23 19:10 . 2008-05-27 15:49 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-23 16:00 . 2008-05-23 16:00 <DIR> d-------- C:\Program Files\PCPitstop
2008-05-23 15:32 . 2008-05-23 15:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-23 11:16 . 2008-05-23 11:16 <DIR> d-------- C:\Program Files\Sierra Wireless
2008-05-23 11:16 . 2008-05-23 11:16 <DIR> d-------- C:\Program Files\Common Files\PctelEapPeer Authentication
2008-05-23 11:15 . 2008-05-23 11:15 <DIR> d-------- C:\Program Files\Sprint
2008-05-23 11:15 . 2008-05-23 11:15 <DIR> d-------- C:\Program Files\Novatel Wireless
2008-05-23 08:29 . 2008-05-23 14:23 261 --a------ C:\Windows\wininit.ini
2008-05-22 19:42 . 2008-05-23 15:33 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-22 19:42 . 2008-05-23 15:33 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-21 10:41 . 2008-05-21 10:41 <DIR> d-------- C:\Program Files\ImTOO(0)
2008-05-21 10:15 . 2008-05-21 10:15 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\Yahoo!
2008-05-21 10:14 . 2008-05-21 19:17 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-21 09:47 . 2008-05-21 09:47 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-05-20 22:25 . 2008-05-21 21:01 <DIR> d-------- C:\Program Files\ImTOO
2008-05-20 22:11 . 2008-05-20 22:11 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\dvdcss
2008-05-16 20:01 . 2008-05-16 20:01 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\NeroDCTemplates
2008-05-09 11:18 . 2008-05-09 11:18 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\MixMeister Technology
2008-05-09 11:17 . 2008-05-09 11:18 <DIR> d-------- C:\Program Files\MixMeister Fusion 7.2.2
2008-05-07 19:30 . 2008-05-07 19:30 130,208 -r------- C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
2008-05-05 21:58 . 2008-05-05 21:58 2,643 --a------ C:\Windows\System32\NMMediaServer.cfg
2008-05-05 21:17 . 2008-05-05 21:17 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-05-05 21:16 . 2008-05-05 21:16 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\Logitech
2008-05-05 21:16 . 2008-05-05 21:16 127,034 -r------- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2008-05-05 21:13 . 2007-11-15 10:06 301,656 --a------ C:\Windows\System32\BtCoreIf.dll
2008-05-05 21:13 . 2007-11-15 10:07 170,512 --a------ C:\Windows\System32\kemutb.dll
2008-05-05 21:13 . 2007-11-15 10:07 141,840 --a------ C:\Windows\System32\KemUtil.dll
2008-05-05 21:13 . 2007-11-15 10:07 117,264 --a------ C:\Windows\System32\KemWnd.dll
2008-05-05 21:13 . 2007-11-15 10:07 76,304 --a------ C:\Windows\System32\KemXML.dll
2008-05-05 21:12 . 2008-05-05 21:17 <DIR> d-------- C:\Users\All Users\Logitech
2008-05-05 21:12 . 2008-05-05 21:12 <DIR> d-------- C:\Users\All Users\LogiShrd
2008-05-05 21:12 . 2008-05-05 21:16 <DIR> d-------- C:\Program Files\Logitech
2008-05-05 21:12 . 2008-05-05 21:16 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2008-04-30 18:34 . 2008-05-16 19:36 99 --a------ C:\Windows\(null)toolkit.ini
2008-04-29 16:24 . 2008-04-29 16:24 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\Trillian
2008-04-29 16:22 . 2008-05-27 17:06 <DIR> d-------- C:\Program Files\Trillian
2008-04-28 22:03 . 2008-04-28 22:03 <DIR> d-------- C:\Users\Default\Roaming
2008-04-28 22:03 . 2008-04-28 22:03 <DIR> d-------- C:\Users\Brent Adair\Roaming
2008-04-28 22:03 . 2008-04-28 22:03 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\MySpace
2008-04-28 22:03 . 2008-04-30 20:56 <DIR> d-------- C:\Program Files\MySpace

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-24 02:38 --------- d-----w C:\Program Files\chatClient
2008-05-23 16:29 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\LimeWire
2008-05-22 02:02 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Winamp
2008-05-19 21:10 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-18 08:04 --------- d-----w C:\Program Files\Easy CD-DA Extractor 11
2008-05-14 08:03 --------- d-----w C:\Program Files\Windows Mail
2008-05-06 02:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-30 23:09 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Skype
2008-04-30 23:07 32 ----a-w C:\Users\All Users\ezsid.dat
2008-04-30 23:07 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\skypePM
2008-04-29 18:49 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\FileZilla
2008-04-25 15:30 --------- d-----w C:\Program Files\SureThing CD Labeler 5
2008-04-25 15:26 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-04-24 22:14 --------- d-----w C:\Program Files\LimeWire
2008-04-23 21:03 --------- d-----w C:\Program Files\Skype
2008-04-23 21:03 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-22 03:20 --------- d-----w C:\Program Files\Apple Software Update
2008-04-20 01:56 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-04-20 01:33 --------- d-----w C:\Program Files\FileZilla FTP Client
2008-04-19 18:23 --------- d-----w C:\Program Files\Picasa2
2008-04-19 18:23 --------- d-----w C:\Program Files\Google
2008-04-19 18:21 --------- d-----w C:\Program Files\Java
2008-04-18 16:21 61,440 ----a-w C:\Windows\System32\pxfhwmcp.dll
2008-04-18 16:21 32,408 ----a-w C:\Windows\System32\PCTINDIS5.sys
2008-04-18 16:21 138,016 ----a-w C:\Windows\System32\PCTIN50.dll
2008-04-18 15:45 38,680 ----a-w C:\Windows\system32\drivers\pctnullport.sys
2008-04-18 02:37 --------- d-----w C:\Program Files\Common Files\Java
2008-04-18 02:19 --------- d-----w C:\Program Files\Filetopia3
2008-04-17 03:49 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-17 02:35 --------- d-----w C:\Program Files\HPQ
2008-04-17 02:32 --------- d-----w C:\Program Files\Hewlett-Packard
2008-04-17 02:31 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\InstallShield
2008-04-17 02:29 --------- d-----w C:\Program Files\TIVistadriver
2008-04-16 04:15 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-04-16 04:07 --------- d-----w C:\Program Files\QuickTime
2008-04-15 03:36 --------- d-----w C:\Program Files\Common Files\AnswerWorks 5.0
2008-04-15 03:09 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2008-04-15 02:51 --------- d-----w C:\Program Files\BitComet
2008-04-15 02:48 2,560 ----a-w C:\Windows\System32\bitcometres.dll
2008-04-15 02:46 --------- d-----w C:\Program Files\CleanUp!
2008-04-15 02:43 --------- d-----w C:\Program Files\Winamp
2008-04-15 02:32 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Blackberry Desktop
2008-04-15 02:30 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Research In Motion
2008-04-14 15:26 --------- d-----w C:\Program Files\Roxio
2008-04-14 15:26 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-04-14 15:26 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-04-14 15:24 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-04-14 15:16 --------- d-----w C:\Program Files\Research In Motion
2008-04-14 15:16 --------- d-----w C:\Program Files\Common Files\Research In Motion
2008-04-14 08:12 --------- d-----w C:\Program Files\McAfee
2008-04-14 08:01 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-14 00:27 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-14 00:03 --------- d-----w C:\Program Files\MSBuild
2008-04-14 00:03 --------- d-----w C:\Program Files\Microsoft Works
2008-04-14 00:01 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-13 23:57 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-04-13 23:38 --------- d-----w C:\Program Files\TagRename
2008-04-13 23:30 --------- d-----w C:\Program Files\Common Files\McAfee
2008-04-13 23:29 --------- d-----w C:\Program Files\McAfee.com
2008-04-13 23:20 --------- d-----w C:\Program Files\Deejaysystem
2008-04-13 23:10 --------- d-----w C:\Program Files\NeroInstall.bak
2008-04-13 23:07 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Nero
2008-04-13 23:06 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-13 23:05 --------- d-----w C:\Program Files\Nero
2008-04-13 22:44 --------- d-----w C:\Program Files\Quicken
2008-04-13 22:40 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Intuit
2008-04-13 22:39 --------- d-----w C:\Program Files\Common Files\Palo Alto Software
2008-04-13 22:39 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-13 22:37 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\DAEMON Tools
2008-04-13 22:37 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-04-13 22:31 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-04-13 20:42 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
2008-04-13 20:09 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2008-04-13 20:09 --------- d-----w C:\Program Files\Synaptics
2008-04-13 20:08 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2008-04-13 20:08 8,704 ----a-w C:\Windows\System32\hccoin.dll
2008-04-13 20:08 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2008-04-13 20:08 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2008-04-13 20:08 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2008-04-13 20:08 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2008-04-13 20:08 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2008-04-13 20:08 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2008-04-13 20:08 19,456 ----a-w C:\Windows\system32\drivers\usbohci.sys
2008-04-13 20:08 --------- d-----w C:\Program Files\CONEXANT
2008-04-13 20:06 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-04-13 20:01 174 --sha-w C:\Program Files\desktop.ini
2008-04-13 19:56 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-13 19:56 --------- d-----w C:\Program Files\Windows Defender
2008-04-13 19:56 --------- d-----w C:\Program Files\Windows Calendar
2008-04-13 19:56 --------- d-----w C:\Program Files\Microsoft Games
2008-04-13 19:56 --------- d-----w C:\Program Files\BitLocker
2008-04-13 19:43 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-04-13 19:43 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-04-13 19:43 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2008-04-13 19:43 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2008-04-13 19:43 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-04-13 19:43 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-04-13 19:43 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2008-04-13 19:43 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2008-04-13 19:43 2,923,520 ----a-w C:\Windows\explorer.exe
.

------- Sigcheck -------

2008-04-15 23:15 803328 82c4070707d100febc3d25cf00b77a4c C:\Windows\System32\drivers\tcpip.sys
2006-11-02 03:58 802816 d944522b048a5feb7700b5170d3d9423 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16386_none_5f4ed3e0926e99e4\tcpip.sys
2008-04-15 23:15 803328 82c4070707d100febc3d25cf00b77a4c C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16627_none_5f90b964923d030a\tcpip.sys
2008-04-13 14:29 806400 52a8bd6294f7d1443c6184c67ae13af4 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20752_none_5ff4e4f9ab7777f4\tcpip.sys

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fe892863-d350-4f64-be51-7d5caa93dd6a}]
C:\Windows\system32\qmcoxpkl.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-04-13 14:19 1232896]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 04:39 486856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 17:07 1828136]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:33 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-04-13 14:39 1006264]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 20:13 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 20:13 133656]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 02:29 102400]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 16:29 2221352]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"@"="" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"QlbCtrl.exe"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-10-19 13:28 202032]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 03:10 55824 C:\Windows\KHALMNPR.Exe]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [2008-05-20 10:55 17672]
"combofix"="C:\Windows\system32\CF19570.exe" [2006-11-02 04:44 320000]

C:\Users\Brent Adair\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-05-07 19:30:44 91440]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-05-05 21:13:00 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BM3b986ba4"=Rundll32.exe "C:\Windows\system32\swugenco.dll",s
"IgfxTray"=C:\Windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4106310787-4105588417-3853101615-1000]
"EnableNotificationsRef"=dword:00000002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{A89DD40B-38AF-4DE1-9978-4FE403E51169}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{17844623-24AE-4277-A0D0-21A4B4916C04}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"{AFC18A5C-EF31-4311-92AB-5BF41FA7E5E6}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{D6A2876B-C731-4A30-9647-924178F351BD}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{1D3897D3-BA0A-4B81-BE5D-7D1937049C8C}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{80A00D36-EA40-481D-A69F-6BBE247951B7}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A3EF82C9-6F83-45FB-8C1F-E3DA92C2B40E}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DA62F69B-8450-482A-BE74-E822953BC454}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{FE1BDEF2-F101-4BB1-B035-A157E22E1ABB}"= UDP:11734:BitComet 11734 TCP
"{4C0B4BC0-499E-4617-B97A-6E8A482A8816}"= TCP:11734:BitComet 11734 UDP
"TCP Query User{BD233961-787F-4CF9-A92F-E74E30E3C49A}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{B7E1A75D-4A35-476C-9918-C2975446B544}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{6FBF635B-79F3-4771-BDB8-BCD41A5616D6}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A435836A-4CE5-466D-8D4A-F04BD39AA8CB}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{34D3119A-91C3-4A34-9D5B-EA8C23D26358}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EE2C7C1A-3B1A-48BC-8137-FD320ABA8F1C}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DE90938A-2FFA-418C-A4F0-7D95D040443E}"= UDP:11734:BitComet 11734 TCP
"{3EBA42EA-C867-4BC3-B5AC-ADFB30B759E1}"= TCP:11734:BitComet 11734 UDP
"TCP Query User{8127C9AB-3261-4F20-9ECD-1F7F1477F62C}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{B4C4BED2-8AB2-4667-B696-6CE342DE3B60}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{A3FC0F6B-2FDF-4FE8-B2B1-7D24DBCBAF9B}C:\\program files\\filetopia3\\filetopia.exe"= UDP:C:\program files\filetopia3\filetopia.exe:Filetopia
"UDP Query User{1DBBC6A3-5A71-47F2-8A6D-7E19913AE49A}C:\\program files\\filetopia3\\filetopia.exe"= TCP:C:\program files\filetopia3\filetopia.exe:Filetopia
"{6E563230-5257-4451-847F-227938191460}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{2D2CB1CA-2D95-4260-8432-B67A511CA0C9}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{DA5F1E66-9E9B-45B3-B467-A23B27F5F345}"= C:\Program Files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{E4188E2F-0844-4EB8-B71E-BFC3C2B5C55A}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{AB0D34F2-19C6-42C4-932D-8FBEA3E8AD98}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{EE1BE405-5C67-4986-9030-A77B96AFB0CB}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{C3B9A247-969C-4710-9EEA-1104ED41BC43}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{469972AD-BABE-404E-8047-75426D10656C}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{5C215470-7258-4900-B0C5-9D38CF23D2C7}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-01-30 05:23]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 19:36]
R3 Nmea;Sprint Connection Manager - emulates the NMEA ports;C:\Windows\system32\DRIVERS\pctnullport.sys [2008-04-18 10:45]
R3 NWADI;NWADI Bus Enumerator;C:\Windows\system32\DRIVERS\NWADIenum.sys [2007-09-06 15:30]
R3 swmsflt;swmsflt;C:\Windows\system32\drivers\swmsflt.sys [2008-03-05 15:41]
S3 CASprint;Sprint Con App Svc;"C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe" /n "CASprint" []
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;C:\Windows\system32\DRIVERS\nwusbser2.sys [2007-10-12 17:04]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys [2007-10-12 17:04]
S3 SprintRcAppSvc;Sprint RcAppSvc;"C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe" /n "SprintRcAppSvc" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
GPSvcGroup REG_MULTI_SZ GPSvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f1e8e7c-09a9-11dd-bf1f-0016d40d32bc}]
\shell\AutoRun\command - E:\AUTORUN.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
"2008-05-15 06:42:53 C:\Windows\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-05-01 06:00:04 C:\Windows\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-05-27 22:38:10 C:\Windows\Tasks\User_Feed_Synchronization-{1848469F-3F60-461B-828A-5CE68295DE70}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-28 10:09:40
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\Users\Brent Adair\AppData\Local\Temp\lucene-498870ad5c2a31c74319eba6e0754ce5-commit.lock 0 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\LogonUI.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\System32\IoctlSvc.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\rdpclip.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\Windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2008-05-28 10:12:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-28 15:12:36

Pre-Run: 35,155,779,584 bytes free
Post-Run: 34,657,714,176 bytes free

346 --- E O F --- 2008-05-23 03:29:41

#4 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:42 PM

Posted 28 May 2008 - 11:34 AM

Hello Brent,

Could you upload some files please ?
Can you zip the folder C:\Qoobox using WinZip (or a similar program) to Qoobox.zip and upload the zipped file to :

http://www.bleepingcomputer.com/submit-malware.php?channel=9

How ? : 1. In the first window (Link to topic where this file was requested:) copy and past this link :http://www.bleepingcomputer.com/forums/t/149157/infected-with-virtumonde/
2. In the second window (Browse to the file you want to submit: ) browse to the Qoobox.zip file

3. Click the Send file button :thumbsup:
[/list]
Then, let's clean up some more :

Open Notepad - don't use any other texteditor than Notepad or the script will fail !
Copy/paste the bold, blue text below into an empty notepad window:Folder::
C:\VundoFix Backups
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fe892863-d350-4f64-be51-7d5caa93dd6a}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"BM3b986ba4"=-

Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again. Upon reboot, (in case it asks to reboot), post the contents of the Combofix log in your next reply, as well as a fresh HijackThislog.

Are you still having problems ?

Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#5 Brent824

Brent824
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:03:42 PM

Posted 28 May 2008 - 01:00 PM

I uploaded the zip file requested as well as ran a new ComboFix with the CFScript as instructed. Below is the new ComboFix log. I don't seem to be having any more problems; no more popups and I can now navigate to websites I previously could not with IE. THANK YOU for the help!

ComboFix 08-05-27.4 - Brent Adair 2008-05-28 12:43:39.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1033.18.1122 [GMT -5:00]
Running from: C:\Users\Brent Adair\Desktop\ComboFix.exe
Command switches used :: C:\Users\Brent Adair\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\VundoFix Backups

.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.

2008-05-28 12:16 . 2008-05-28 12:16 3,193,206 --a------ C:\QooBox.zip
2008-05-28 12:00 . 2008-05-28 12:23 96,966 --a------ C:\Windows\System32\drivers\klin.dat
2008-05-28 12:00 . 2008-05-28 12:23 88,262 --a------ C:\Windows\System32\drivers\klick.dat
2008-05-28 11:59 . 2008-05-28 11:59 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-05-28 11:59 . 2008-05-28 12:47 2,519,584 --ahs---- C:\Windows\System32\drivers\fidbox.dat
2008-05-28 11:59 . 2008-05-28 12:29 28,388 --ahs---- C:\Windows\System32\drivers\fidbox.idx
2008-05-28 11:52 . 2008-05-28 11:52 <DIR> d-------- C:\Users\All Users\Kaspersky Lab Setup Files
2008-05-28 09:24 . 2008-05-28 09:24 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\Malwarebytes
2008-05-28 09:24 . 2008-05-28 09:24 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-05-28 09:24 . 2008-05-28 09:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-28 09:24 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-28 09:24 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-27 17:04 . 2008-05-27 17:04 <DIR> d-------- C:\Deckard
2008-05-27 15:53 . 2008-05-27 15:53 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-05-27 15:53 . 2008-05-28 12:37 <DIR> d-------- C:\Users\All Users\Kaspersky Lab
2008-05-23 21:37 . 2008-05-26 22:51 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-05-23 21:24 . 2008-05-23 21:27 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-05-23 19:10 . 2008-05-27 15:49 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-23 16:00 . 2008-05-23 16:00 <DIR> d-------- C:\Program Files\PCPitstop
2008-05-23 15:32 . 2008-05-23 15:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-23 11:16 . 2008-05-23 11:16 <DIR> d-------- C:\Program Files\Sierra Wireless
2008-05-23 11:16 . 2008-05-23 11:16 <DIR> d-------- C:\Program Files\Common Files\PctelEapPeer Authentication
2008-05-23 11:15 . 2008-05-23 11:15 <DIR> d-------- C:\Program Files\Sprint
2008-05-23 11:15 . 2008-05-23 11:15 <DIR> d-------- C:\Program Files\Novatel Wireless
2008-05-23 08:29 . 2008-05-23 14:23 261 --a------ C:\Windows\wininit.ini
2008-05-22 19:42 . 2008-05-23 15:33 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-22 19:42 . 2008-05-23 15:33 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-21 10:41 . 2008-05-21 10:41 <DIR> d-------- C:\Program Files\ImTOO(0)
2008-05-21 10:15 . 2008-05-21 10:15 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\Yahoo!
2008-05-21 10:14 . 2008-05-21 19:17 <DIR> d-------- C:\Program Files\Yahoo!
2008-05-21 09:47 . 2008-05-21 09:47 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-05-20 22:25 . 2008-05-21 21:01 <DIR> d-------- C:\Program Files\ImTOO
2008-05-20 22:11 . 2008-05-20 22:11 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\dvdcss
2008-05-16 20:01 . 2008-05-16 20:01 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\NeroDCTemplates
2008-05-09 11:18 . 2008-05-09 11:18 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\MixMeister Technology
2008-05-09 11:17 . 2008-05-09 11:18 <DIR> d-------- C:\Program Files\MixMeister Fusion 7.2.2
2008-05-07 19:30 . 2008-05-07 19:30 130,208 -r------- C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
2008-05-05 21:58 . 2008-05-05 21:58 2,643 --a------ C:\Windows\System32\NMMediaServer.cfg
2008-05-05 21:17 . 2008-05-05 21:17 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-05-05 21:16 . 2008-05-05 21:16 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\Logitech
2008-05-05 21:16 . 2008-05-05 21:16 127,034 -r------- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe
2008-05-05 21:13 . 2007-11-15 10:06 301,656 --a------ C:\Windows\System32\BtCoreIf.dll
2008-05-05 21:13 . 2007-11-15 10:07 170,512 --a------ C:\Windows\System32\kemutb.dll
2008-05-05 21:13 . 2007-11-15 10:07 141,840 --a------ C:\Windows\System32\KemUtil.dll
2008-05-05 21:13 . 2007-11-15 10:07 117,264 --a------ C:\Windows\System32\KemWnd.dll
2008-05-05 21:13 . 2007-11-15 10:07 76,304 --a------ C:\Windows\System32\KemXML.dll
2008-05-05 21:12 . 2008-05-05 21:17 <DIR> d-------- C:\Users\All Users\Logitech
2008-05-05 21:12 . 2008-05-05 21:12 <DIR> d-------- C:\Users\All Users\LogiShrd
2008-05-05 21:12 . 2008-05-05 21:16 <DIR> d-------- C:\Program Files\Logitech
2008-05-05 21:12 . 2008-05-05 21:16 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2008-04-30 18:34 . 2008-05-16 19:36 99 --a------ C:\Windows\(null)toolkit.ini
2008-04-29 16:24 . 2008-04-29 16:24 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\Trillian
2008-04-29 16:22 . 2008-05-27 17:06 <DIR> d-------- C:\Program Files\Trillian
2008-04-28 22:03 . 2008-04-28 22:03 <DIR> d-------- C:\Users\Default\Roaming
2008-04-28 22:03 . 2008-04-28 22:03 <DIR> d-------- C:\Users\Brent Adair\Roaming
2008-04-28 22:03 . 2008-04-28 22:03 <DIR> d-------- C:\Users\Brent Adair\AppData\Roaming\MySpace
2008-04-28 22:03 . 2008-04-30 20:56 <DIR> d-------- C:\Program Files\MySpace

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 17:23 112,144 ----a-w C:\Windows\system32\drivers\kl1.sys
2008-05-24 02:38 --------- d-----w C:\Program Files\chatClient
2008-05-23 16:29 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\LimeWire
2008-05-22 02:02 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Winamp
2008-05-19 21:10 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-18 08:04 --------- d-----w C:\Program Files\Easy CD-DA Extractor 11
2008-05-14 08:03 --------- d-----w C:\Program Files\Windows Mail
2008-05-06 02:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-30 23:09 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Skype
2008-04-30 23:07 32 ----a-w C:\Users\All Users\ezsid.dat
2008-04-30 23:07 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\skypePM
2008-04-29 18:49 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\FileZilla
2008-04-25 15:30 --------- d-----w C:\Program Files\SureThing CD Labeler 5
2008-04-25 15:26 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-04-24 22:14 --------- d-----w C:\Program Files\LimeWire
2008-04-23 21:03 --------- d-----w C:\Program Files\Skype
2008-04-23 21:03 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-22 03:20 --------- d-----w C:\Program Files\Apple Software Update
2008-04-20 01:56 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-04-20 01:33 --------- d-----w C:\Program Files\FileZilla FTP Client
2008-04-19 18:23 --------- d-----w C:\Program Files\Picasa2
2008-04-19 18:23 --------- d-----w C:\Program Files\Google
2008-04-19 18:21 --------- d-----w C:\Program Files\Java
2008-04-18 16:21 61,440 ----a-w C:\Windows\System32\pxfhwmcp.dll
2008-04-18 16:21 32,408 ----a-w C:\Windows\System32\PCTINDIS5.sys
2008-04-18 16:21 138,016 ----a-w C:\Windows\System32\PCTIN50.dll
2008-04-18 15:45 38,680 ----a-w C:\Windows\system32\drivers\pctnullport.sys
2008-04-18 02:37 --------- d-----w C:\Program Files\Common Files\Java
2008-04-18 02:19 --------- d-----w C:\Program Files\Filetopia3
2008-04-17 03:49 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-17 02:35 --------- d-----w C:\Program Files\HPQ
2008-04-17 02:32 --------- d-----w C:\Program Files\Hewlett-Packard
2008-04-17 02:31 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\InstallShield
2008-04-17 02:29 --------- d-----w C:\Program Files\TIVistadriver
2008-04-16 04:15 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-04-16 04:07 --------- d-----w C:\Program Files\QuickTime
2008-04-15 03:36 --------- d-----w C:\Program Files\Common Files\AnswerWorks 5.0
2008-04-15 03:09 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2008-04-15 02:51 --------- d-----w C:\Program Files\BitComet
2008-04-15 02:48 2,560 ----a-w C:\Windows\System32\bitcometres.dll
2008-04-15 02:46 --------- d-----w C:\Program Files\CleanUp!
2008-04-15 02:43 --------- d-----w C:\Program Files\Winamp
2008-04-15 02:32 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Blackberry Desktop
2008-04-15 02:30 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Research In Motion
2008-04-14 15:26 --------- d-----w C:\Program Files\Roxio
2008-04-14 15:26 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-04-14 15:26 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-04-14 15:24 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-04-14 15:16 --------- d-----w C:\Program Files\Research In Motion
2008-04-14 15:16 --------- d-----w C:\Program Files\Common Files\Research In Motion
2008-04-14 08:01 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-14 00:27 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-14 00:03 --------- d-----w C:\Program Files\MSBuild
2008-04-14 00:03 --------- d-----w C:\Program Files\Microsoft Works
2008-04-14 00:01 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-13 23:57 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-04-13 23:38 --------- d-----w C:\Program Files\TagRename
2008-04-13 23:20 --------- d-----w C:\Program Files\Deejaysystem
2008-04-13 23:10 --------- d-----w C:\Program Files\NeroInstall.bak
2008-04-13 23:07 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Nero
2008-04-13 23:06 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-13 23:05 --------- d-----w C:\Program Files\Nero
2008-04-13 22:44 --------- d-----w C:\Program Files\Quicken
2008-04-13 22:40 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\Intuit
2008-04-13 22:39 --------- d-----w C:\Program Files\Common Files\Palo Alto Software
2008-04-13 22:39 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-13 22:37 --------- d-----w C:\Users\Brent Adair\AppData\Roaming\DAEMON Tools
2008-04-13 22:37 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-04-13 22:31 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-04-13 20:42 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
2008-04-13 20:09 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2008-04-13 20:09 --------- d-----w C:\Program Files\Synaptics
2008-04-13 20:08 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2008-04-13 20:08 8,704 ----a-w C:\Windows\System32\hccoin.dll
2008-04-13 20:08 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2008-04-13 20:08 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2008-04-13 20:08 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2008-04-13 20:08 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2008-04-13 20:08 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2008-04-13 20:08 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2008-04-13 20:08 19,456 ----a-w C:\Windows\system32\drivers\usbohci.sys
2008-04-13 20:08 --------- d-----w C:\Program Files\CONEXANT
2008-04-13 20:06 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-04-13 20:01 174 --sha-w C:\Program Files\desktop.ini
2008-04-13 19:56 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-13 19:56 --------- d-----w C:\Program Files\Windows Defender
2008-04-13 19:56 --------- d-----w C:\Program Files\Windows Calendar
2008-04-13 19:56 --------- d-----w C:\Program Files\Microsoft Games
2008-04-13 19:56 --------- d-----w C:\Program Files\BitLocker
2008-04-13 19:43 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-04-13 19:43 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-04-13 19:43 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2008-04-13 19:43 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2008-04-13 19:43 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-04-13 19:43 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-04-13 19:43 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2008-04-13 19:43 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2008-04-13 19:43 2,923,520 ----a-w C:\Windows\explorer.exe
2008-04-13 19:43 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2008-04-13 19:43 11,264 ----a-w C:\Windows\system32\drivers\wmiacpi.sys
.

------- Sigcheck -------

2008-04-15 23:15 803328 82c4070707d100febc3d25cf00b77a4c C:\Windows\System32\drivers\tcpip.sys
2006-11-02 03:58 802816 d944522b048a5feb7700b5170d3d9423 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16386_none_5f4ed3e0926e99e4\tcpip.sys
2008-04-15 23:15 803328 82c4070707d100febc3d25cf00b77a4c C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.16627_none_5f90b964923d030a\tcpip.sys
2008-04-13 14:29 806400 52a8bd6294f7d1443c6184c67ae13af4 C:\Windows\winsxs\x86_microsoft-windows-tcpip_31bf3856ad364e35_6.0.6000.20752_none_5ff4e4f9ab7777f4\tcpip.sys

.
((((((((((((((((((((((((((((( snapshot@2008-05-28_10.11.56.77 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-28 14:56:35 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-05-28 17:30:10 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-05-23 16:27:40 51,200 ----a-w C:\Windows\inf\infpub.dat
+ 2008-05-28 16:59:49 51,200 ----a-w C:\Windows\inf\infpub.dat
- 2008-05-23 16:27:40 86,016 ----a-w C:\Windows\inf\infstor.dat
+ 2008-05-28 16:59:48 86,016 ----a-w C:\Windows\inf\infstor.dat
- 2008-05-23 16:27:40 143,360 ----a-w C:\Windows\inf\infstrng.dat
+ 2008-05-28 16:59:48 143,360 ----a-w C:\Windows\inf\infstrng.dat
- 2008-05-28 14:56:36 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-05-28 17:30:11 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-05-28 14:56:36 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-05-28 17:30:11 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-05-28 15:07:12 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-05-28 17:45:06 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-05-28 15:09:48 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-05-28 17:47:06 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-05-28 17:47:06 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-05-28 11:32:26 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-28 15:58:59 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-05-28 11:32:26 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-28 15:58:59 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-28 11:32:26 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-28 15:58:59 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-28 16:58:42 147,984 ----a-w C:\Windows\System32\drivers\klif.sys
+ 2007-10-16 16:05:28 20,496 ----a-w C:\Windows\System32\drivers\klim6.sys
+ 2008-02-08 23:35:42 23,604 ----a-w C:\Windows\System32\drivers\klopp.dat
+ 2007-10-16 16:05:28 20,496 ----a-w C:\Windows\System32\DriverStore\FileRepository\klim6.inf_bb6bc382\klim6.sys
+ 2008-02-08 23:37:44 219,664 ----a-w C:\Windows\System32\klogon.dll
- 2008-05-28 15:01:34 104,868 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-05-28 17:36:07 104,868 ----a-w C:\Windows\System32\perfc009.dat
- 2008-05-28 15:01:34 621,552 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-05-28 17:36:07 621,552 ----a-w C:\Windows\System32\perfh009.dat
- 2008-05-23 13:30:47 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
+ 2008-05-28 16:39:54 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
- 2008-05-28 14:41:05 35,834 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-05-28 17:36:52 36,332 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-05-23 03:48:08 103,830,536 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-05-28 15:36:18 105,926,505 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-04-13 14:19 1232896]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 04:39 486856]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 17:07 1828136]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:33 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 20:13 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 20:13 133656]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 02:29 102400]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 16:29 2221352]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"QlbCtrl.exe"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-10-19 13:28 202032]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 03:10 55824 C:\Windows\KHALMNPR.Exe]
"Sprint SmartView"="C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" [2008-05-20 10:55 17672]

C:\Users\Brent Adair\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-05-07 19:30:44 91440]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-05-05 21:13:00 784912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"IgfxTray"=C:\Windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4106310787-4105588417-3853101615-1000]
"EnableNotificationsRef"=dword:00000002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{A89DD40B-38AF-4DE1-9978-4FE403E51169}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{17844623-24AE-4277-A0D0-21A4B4916C04}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"{D6A2876B-C731-4A30-9647-924178F351BD}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{1D3897D3-BA0A-4B81-BE5D-7D1937049C8C}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{80A00D36-EA40-481D-A69F-6BBE247951B7}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A3EF82C9-6F83-45FB-8C1F-E3DA92C2B40E}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DA62F69B-8450-482A-BE74-E822953BC454}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{FE1BDEF2-F101-4BB1-B035-A157E22E1ABB}"= UDP:11734:BitComet 11734 TCP
"{4C0B4BC0-499E-4617-B97A-6E8A482A8816}"= TCP:11734:BitComet 11734 UDP
"TCP Query User{BD233961-787F-4CF9-A92F-E74E30E3C49A}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{B7E1A75D-4A35-476C-9918-C2975446B544}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{6FBF635B-79F3-4771-BDB8-BCD41A5616D6}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A435836A-4CE5-466D-8D4A-F04BD39AA8CB}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{34D3119A-91C3-4A34-9D5B-EA8C23D26358}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EE2C7C1A-3B1A-48BC-8137-FD320ABA8F1C}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DE90938A-2FFA-418C-A4F0-7D95D040443E}"= UDP:11734:BitComet 11734 TCP
"{3EBA42EA-C867-4BC3-B5AC-ADFB30B759E1}"= TCP:11734:BitComet 11734 UDP
"TCP Query User{8127C9AB-3261-4F20-9ECD-1F7F1477F62C}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{B4C4BED2-8AB2-4667-B696-6CE342DE3B60}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{A3FC0F6B-2FDF-4FE8-B2B1-7D24DBCBAF9B}C:\\program files\\filetopia3\\filetopia.exe"= UDP:C:\program files\filetopia3\filetopia.exe:Filetopia
"UDP Query User{1DBBC6A3-5A71-47F2-8A6D-7E19913AE49A}C:\\program files\\filetopia3\\filetopia.exe"= TCP:C:\program files\filetopia3\filetopia.exe:Filetopia
"{6E563230-5257-4451-847F-227938191460}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{2D2CB1CA-2D95-4260-8432-B67A511CA0C9}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{DA5F1E66-9E9B-45B3-B467-A23B27F5F345}"= C:\Program Files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{E4188E2F-0844-4EB8-B71E-BFC3C2B5C55A}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{AB0D34F2-19C6-42C4-932D-8FBEA3E8AD98}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{EE1BE405-5C67-4986-9030-A77B96AFB0CB}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{C3B9A247-969C-4710-9EEA-1104ED41BC43}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{469972AD-BABE-404E-8047-75426D10656C}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{5C215470-7258-4900-B0C5-9D38CF23D2C7}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"TCP Query User{218C076C-8A36-4870-9498-E12CDF605895}C:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 7.0.1.325\\english\\setup.exe"= UDP:C:\programdata\kaspersky lab setup files\kaspersky anti-virus 7.0.1.325\english\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"UDP Query User{8988724F-EFFB-4779-AA56-7BF4090AFAB2}C:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 7.0.1.325\\english\\setup.exe"= TCP:C:\programdata\kaspersky lab setup files\kaspersky anti-virus 7.0.1.325\english\setup.exe:Kaspersky Anti-Virus 7.0 Setup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2007-10-16 11:05]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-01-30 05:23]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 19:36]
R3 Nmea;Sprint Connection Manager - emulates the NMEA ports;C:\Windows\system32\DRIVERS\pctnullport.sys [2008-04-18 10:45]
R3 NWADI;NWADI Bus Enumerator;C:\Windows\system32\DRIVERS\NWADIenum.sys [2007-09-06 15:30]
R3 swmsflt;swmsflt;C:\Windows\system32\drivers\swmsflt.sys [2008-03-05 15:41]
S3 CASprint;Sprint Con App Svc;"C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe" /n "CASprint" []
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;C:\Windows\system32\DRIVERS\nwusbser2.sys [2007-10-12 17:04]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys [2007-10-12 17:04]
S3 SprintRcAppSvc;Sprint RcAppSvc;"C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe" /n "SprintRcAppSvc" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
GPSvcGroup REG_MULTI_SZ GPSvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f1e8e7c-09a9-11dd-bf1f-0016d40d32bc}]
\shell\AutoRun\command - E:\AUTORUN.EXE

*Newly Created Service* - KL1

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
Contents of the 'Scheduled Tasks' folder
"2008-05-27 22:38:10 C:\Windows\Tasks\User_Feed_Synchronization-{1848469F-3F60-461B-828A-5CE68295DE70}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-28 12:47:24
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-28 12:49:47
ComboFix-quarantined-files.txt 2008-05-28 17:49:39
ComboFix2.txt 2008-05-28 15:12:52

Pre-Run: 34,279,297,024 bytes free
Post-Run: 35,959,414,784 bytes free

336 --- E O F --- 2008-05-23 03:29:41

#6 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:42 PM

Posted 28 May 2008 - 04:07 PM

Pleased to hear that, Brent :thumbsup:

You can remove all used tools and folders created in the process.
To remove ComboFix :
Go to Start > Run, and copy and paste next command in the field:ComboFix /u
Make sure there's a space between Combofix and /u
Then press Enter.
This will uninstall Combofix, delete its related folders and files, restore your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Your JavaVM is also out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u6.
  • Scroll down to where it says The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the Download button to the right.
  • Check the box that says: Accept License Agreement
  • The page will refresh.
  • Click on the link to download Windows Offline Installation (jre-6u6-windows-i586-p.exe) and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.
Greetings,
Thunder
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference

#7 Thunder

Thunder

  • Members
  • 3,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Belgium
  • Local time:10:42 PM

Posted 26 June 2008 - 08:08 AM

Since there is no feedback anymore, I assume this issue is resolved ... so, this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Whatever happens, make believe it was intended to ...
-----------------------------------------------------------------------
Posted Image - If I have helped you in any way, please consider a donation to help me continue the fight against malware.
-----------------------------------------------------------------------
Stand Up & Be Counted --> Posted Image <-- And make a difference




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users