Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help Me Please


  • Please log in to reply
15 replies to this topic

#1 Ant84

Ant84

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:26 PM

Posted 30 July 2008 - 08:42 PM

Hello,
I have an XP system that is infected with spyware and viruses. It has improved with the help of some removal tools, however there are still problems. When I start up I get an error message that reads like this, <:WINDOWS/system32/khxcdvvy.dll I also have noticed prompts to update programs on my system by installing the correct cd when I have used the same programs for the past three years without ever seeing this. Lastly I have my Hijack This log, it is long so I have attached it to my post. Please let me know what to do. I thank you for your time and understanding.

Attached Files



BC AdBot (Login to Remove)

 


m

#2 SNOWHITE

SNOWHITE

    missy malware magnet


  • Members
  • 2,676 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Bitola, Macedonia
  • Local time:11:26 PM

Posted 10 August 2008 - 10:44 PM

Hello and welcome to BC

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. We aim to provide the valuable service known to come from BC to every member we can, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

Thanks and again sorry for the delay.

NOTE: Please post the reports back into the topic, do not attach them.

Please download Deckard's System Scanner (DSS) and save to your Desktop.
alternate download site

DSS will do the following:
  • Create a new System Restore point in Windows XP and Vista.
  • Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.
  • Check some important areas of your system and produce a report for an analyst to review.
  • Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.
You must be logged onto an account with administrator privileges when using.
  • Close all applications and windows.
  • Double-click on dss.exe to run it and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not
    malicious.
  • When the scan is complete, two text files will open in Notepad:
    • main.txt <- this one will be maximized
    • extra.txt <- this one will be minimized
  • If not, they both can be found in the C:\Deckard\System Scanner folder.
  • Please copy (Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your next reply.
-- When running DSS, some firewalls may warn that it is trying to access the Internet especially if your asked to download the most current version of HijackThis. Please ensure that you allow it permission to do so.
-- If you get a warning from your anti-virus while DSS is scanning, please allow DSS to continue as the scan is not harmful.


If you already preformed the steps above We still need to see the current state of the machine fresh scan and logs are still necessary

click on Start, click on Run
copy and paste the following in bold in the open window and then click OK
"%userprofile%\desktop\dss.exe" /config
This will open up DSS configuration
click on Check All
click Scan
DSS will now run again when finished
Please post back both logs that open in notepad
Main txt and extra txt



Next
Please do a scan with Kaspersky Online Scanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Please post back with dss reports main.txt, extra.txt and Kaspersky report.

Regards
SNOWHITE
Posted Image

#3 Ant84

Ant84
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:26 PM

Posted 12 August 2008 - 04:07 PM

I was able to run run the dss scan, however when I tryed to run the online kasberry scan I was unable to select Accept as it was not accessable. I do have another version of kasberry on my computer I was able to run and here are the results from the log. I will also attach the four logs from dss

detected: Trojan program Trojan-Downloader.Win32.VB.eyc File: C:\Deckard\System Scanner\20080811200916\backup\DOCUME~1\a\LOCALS~1\Temp\snpp.exe//data0006
detected: Trojan program Trojan-Downloader.WMA.Wimad.k File: C:\Documents and Settings\a\Shared\03 Track 3 (come).wma
detected: Trojan program Trojan-Downloader.WMA.Wimad.k File: C:\Documents and Settings\a\Shared\Top of Charts - 2004 (straight).wma
detected: Trojan program Trojan-Downloader.WMA.Wimad.k File: C:\Documents and Settings\a\Shared\Wicked Remix (straight).wma
detected: riskware not-a-virus:RemoteAdmin.Win32.WinVNC.4 File: D:\I386\SYSTEM32\WM_HOOKS.DLL
detected: riskware not-a-virus:NetTool.Win32.Portscan.c File: D:\PROGRAMS\IPScan\ipscan.exe//UPX
detected: riskware not-a-virus:RemoteAdmin.Win32.WinVNC.c File: D:\PROGRAMS\ultravnc\vnchooks.dll
detected: riskware not-a-virus:RemoteAdmin.Win32.WinVNC.1102 File: D:\PROGRAMS\ultravnc\vncviewer.exe
detected: riskware not-a-virus:RemoteAdmin.Win32.WinVNC.c File: D:\PROGRAMS\ultravnc\winvnc.exe
detected: riskware not-a-virus:RemoteAdmin.Win32.WinVNC.4 File: D:\PROGRAMS\vncserver\vncconfig.exe
detected: riskware not-a-virus:RemoteAdmin.Win32.WinVNC.4 File: D:\PROGRAMS\vncserver\winvnc4.exe

Attached Files



#4 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,693 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:05:26 PM

Posted 12 August 2008 - 06:29 PM

Hello Ant84,

I have merged your latest topic with your previously existing topic. Please keep all posts regarding this issue to this thread by using the Add Reply button at the bottom of the topic. Starting new topics confuses things and delays the assistance you receive.

Back to you SNOWHITE,

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#5 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:05:26 PM

Posted 15 August 2008 - 06:23 PM

Hello and welcome Ant84

Sorry for the delay,

Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall


#6 Ant84

Ant84
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:26 PM

Posted 16 August 2008 - 03:13 PM

This is the latest Hijack this log and Combo fix log

Please let me know what to do next, Thanks

HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:08:02 PM, on 8/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\DOCUME~1\a\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/a/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [is-U85SF] "C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-U85SF\is-U85SF.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - DefaultPrefix:
O15 - Trusted Zone: *.fnismls.com
O15 - Trusted Zone: *.getmedianow.com
O15 - Trusted Zone: *.live.com
O15 - Trusted Zone: *.virtualearth.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: McAfee Application Installer Cleanup (0124351215957598) (0124351215957598mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\012435~1.EXE (file missing)
O23 - Service: a-squared Free Service (a2free) - Unknown owner - C:\DOCUME~1\A\LOCALS~1\TEMP\A2FREE\a2service.exe (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: is-74P1D - Unknown owner - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-74P1D\is-74P1D.exe (file missing)
O23 - Service: is-B98LM - Unknown owner - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-B98LM\is-B98LM.exe (file missing)
O23 - Service: is-QTKTP - Unknown owner - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-QTKTP\is-QTKTP.exe (file missing)
O23 - Service: is-U85SF - Kaspersky Lab - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-U85SF\is-U85SF.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

--
End of file - 10406 bytes






Combo Fix

ComboFix 08-08-15.04 - a 2008-08-16 15:45:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.139 [GMT -4:00]
Running from: C:\Documents and Settings\a\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\a\Application Data\Microsoft\dtsc
C:\Documents and Settings\a\Application Data\Microsoft\dtsc\s
C:\Documents and Settings\a\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiSpyCheck 2.1.lnk
C:\Documents and Settings\a\Application Data\rhcgn3j0en3p
C:\Documents and Settings\a\Application Data\shcjn3j0en3p
C:\Documents and Settings\a\Cookies\a@ad.yieldmanager[2].txt
C:\Documents and Settings\a\Cookies\a@adserver[1].txt
C:\Documents and Settings\a\Cookies\a@advertising[2].txt
C:\Documents and Settings\a\Cookies\a@citi.bridgetrack[2].txt
C:\Documents and Settings\a\Cookies\a@comcast[1].txt
C:\Documents and Settings\a\Cookies\a@my.clearchannelradio[1].txt
C:\Documents and Settings\a\Cookies\a@revsci[2].txt
C:\Documents and Settings\a\Cookies\a@vendorweb.citibank[2].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[10].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[11].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[12].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[13].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[14].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[6].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[7].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[8].txt
C:\Documents and Settings\a\Cookies\a@vsweb.kaspersky[9].txt
C:\Documents and Settings\a\My Documents\FNTS~1
C:\Documents and Settings\a\My Documents\My Documents.url
C:\Documents and Settings\a\My Documents\My Music\My Music.url
C:\Documents and Settings\a\My Documents\My Pictures\My Pictures.url
C:\Documents and Settings\a\Start Menu\AntiSpyCheck 2.1.lnk
C:\Documents and Settings\a\Start Menu\Programs\AntiSpyCheck 2.1
C:\Documents and Settings\a\Start Menu\Programs\AntiSpyCheck 2.1\AntiSpyCheck 2.1.lnk
C:\Program Files\ASpyC
C:\Program Files\ASpyC\ASpyC.exe
C:\Program Files\ASpyC\SpyWarning.dll
C:\Program Files\ASpyC\uninst.exe
C:\Program Files\Common Files\ystem3~1
C:\Program Files\RcvSystem
C:\Program Files\rhcgn3j0en3p
C:\Program Files\shcjn3j0en3p
C:\Program Files\ystem~1
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\Temp\tpBe12
C:\Temp\tpBe12\etFr.log
C:\WINDOWS\BM3318b658.txt
C:\WINDOWS\BM3318b658.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\804031
C:\WINDOWS\system32\804031\804031.dll
C:\WINDOWS\system32\aalpdl.dll
C:\WINDOWS\system32\abc2
C:\WINDOWS\system32\axwlhkel.ini
C:\WINDOWS\system32\bpchmjgj.ini
C:\WINDOWS\system32\dcmnima.ini
C:\WINDOWS\system32\dcmnima.ini2
C:\WINDOWS\system32\eqdnbkwv.ini
C:\WINDOWS\system32\ex1
C:\WINDOWS\system32\eybicptn.ini
C:\WINDOWS\system32\hkohkpws.ini
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\hnnqdjcs.dll
C:\WINDOWS\system32\ineWc01
C:\WINDOWS\system32\ipd1
C:\WINDOWS\system32\ixlfqjrm.ini
C:\WINDOWS\system32\jbaepfib.dll
C:\WINDOWS\system32\jkqvjzl.dll
C:\WINDOWS\system32\jvrosxgm.ini
C:\WINDOWS\system32\kmsavqwj.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\nllxaryq.ini
C:\WINDOWS\system32\oc9
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qrqss.ini
C:\WINDOWS\system32\qrqss.ini2
C:\WINDOWS\system32\qvctqorq.ini
C:\WINDOWS\system32\scurit~1
C:\WINDOWS\system32\shel9
C:\WINDOWS\system32\swpkhokh.dll
C:\WINDOWS\system32\tkghkpeu.ini
C:\WINDOWS\system32\udqjlfqg.ini
C:\WINDOWS\system32\vwkbndqe.dll
C:\WINDOWS\system32\wnsxs~1

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CORE
-------\Legacy_SYSREST.SYS
-------\Service_core


((((((((((((((((((((((((( Files Created from 2008-07-16 to 2008-08-16 )))))))))))))))))))))))))))))))
.

2008-08-15 17:12 . 2008-08-15 17:12 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-15 17:12 . 2008-08-15 17:12 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-13 12:42 . 2008-06-24 12:23 74,240 --------- C:\WINDOWS\system32\dllcache\mscms.dll
2008-08-12 16:36 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-11 20:18 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\15496916.sys
2008-08-11 19:46 . 2008-08-11 19:46 <DIR> d-------- C:\Deckard
2008-08-03 08:53 . 2008-08-03 08:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comcast
2008-08-01 23:05 . 2008-08-01 23:05 <DIR> d-------- C:\Program Files\Unity
2008-08-01 18:17 . 2008-08-01 18:17 <DIR> d-------- C:\Program Files\Applications
2008-08-01 18:17 . 2008-08-01 18:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-01 18:17 . 2008-08-01 18:17 26,624 --a------ C:\WINDOWS\system32\ubpr01.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-16 19:57 152,543,264 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-16 19:53 1,786,868 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-16 14:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-09 15:43 --------- d-----w C:\Program Files\Google
2008-07-16 00:04 --------- d-----w C:\Program Files\Java
2008-07-13 13:49 7,168 ----a-w C:\WINDOWS\system32\drivers\utm1mzm5.sys
2008-07-13 01:06 5,018 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-07-13 00:45 --------- d-----w C:\Program Files\Dell Support Center
2008-07-13 00:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-07-13 00:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-07-13 00:42 --------- d-----w C:\Program Files\Picasa2
2008-07-12 22:13 12,464 ----a-w C:\WINDOWS\system32\drivers\CDAC15BA.SYS
2008-07-12 21:24 --------- d-----w C:\Documents and Settings\a\Application Data\Lavasoft
2008-07-10 01:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-10 00:17 --------- d-----w C:\Program Files\Trend Micro
2008-07-09 01:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-09 01:56 --------- d-----w C:\Documents and Settings\a\Application Data\SUPERAntiSpyware.com
2008-07-08 22:31 114,240 ----a-w C:\WINDOWS\system32\sywwtw.dll
2008-07-08 22:31 114,240 ----a-w C:\WINDOWS\system32\hvakfeux.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:49 --------- d-----w C:\Program Files\Dell
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:12 667,136 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-23 16:12 667,136 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2008-06-23 16:12 618,496 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2008-06-23 16:12 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2008-06-23 16:12 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-06-23 16:12 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2008-06-23 16:12 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-06-23 16:12 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2008-06-23 16:12 1,499,136 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-06-23 16:11 96,256 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2008-06-23 16:11 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2008-06-23 16:11 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2008-06-23 16:11 3,067,392 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 16:11 251,904 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2008-06-23 16:11 205,312 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2008-06-23 16:11 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2008-06-23 16:11 151,040 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2008-06-23 16:11 1,054,208 ------w C:\WINDOWS\system32\dllcache\danim.dll
2008-06-23 16:11 1,024,000 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2008-06-23 09:53 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-04-01 13:53 514 ----a-w C:\Documents and Settings\a\Application Data\wklnhst.dat
2007-02-02 03:17 74,656 ----a-w C:\Documents and Settings\a\Application Data\GDIPFONTCACHEV1.DAT
.

------- Sigcheck -------

2004-08-10 07:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe

2005-03-02 14:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 11:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-10 07:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 14:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\dllcache\user32.dll

2004-08-10 07:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll

2004-08-10 07:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe

2004-08-10 07:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys

2004-08-10 07:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys

2005-03-01 20:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 12:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 05:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2004-08-04 00:59 2015232 fb142b7007ca2eea76966c6c5cc12150 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 20:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 08:55 2015744 bbb2322eb14ad9ad55b1024ffd4d88bf C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2007-02-28 04:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe

2005-03-01 21:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 12:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 05:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2004-08-04 01:18 2148352 626309040459c3915997ef98ec1c8d40 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 20:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 10:15 2136064 8318ed54797f3e513fd5817a1d4bbd18 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2007-02-28 05:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\dllcache\ntoskrnl.exe

2004-08-10 07:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe

2004-08-10 07:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe

2004-08-10 07:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe

2005-06-10 20:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 19:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe

2004-08-10 07:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 20:23 102400]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 19:40 24576 C:\WINDOWS\MIDIDEF.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01 67584]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-20 01:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-20 01:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-20 01:10 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 22:12 221184]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19 53248]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 18:10 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 03:00 90112]
"VoiceCenter"="C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" [2005-02-23 13:08 1159168]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-28 11:24 98304]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 03:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44 81920]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 21:20 8192]
"MMTray"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe" [2005-09-08 21:20 110592]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-25 07:39 1836544]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-12 22:29 185632]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 15:21 198184]
"is-U85SF"="C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-U85SF\is-U85SF.exe" [2008-06-07 15:26 217088]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]
"MBMon"="CTMBHA.DLL" [2005-05-19 18:54 1345520 C:\WINDOWS\system32\CTMBHA.DLL]

C:\Documents and Settings\a\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
dlbcserv.lnk - C:\Program Files\Dell Photo Printer 720\dlbcserv.exe [2006-07-10 11:27:13 315392]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2006-10-25 22:38:45 124912]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-05-15 11:10:00 394856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=

R1 is-74P1Ddrv;is-74P1Ddrv;C:\WINDOWS\system32\drivers\98442555.sys [2008-03-05 11:41]
R1 is-QTKTPdrv;is-QTKTPdrv;C:\WINDOWS\system32\drivers\95151642.sys [2008-03-05 11:41]
R1 is-SPSHUdrv;is-SPSHUdrv;C:\WINDOWS\system32\drivers\22422312.sys [2008-03-05 11:41]
R1 is-U85SFdrv;is-U85SFdrv;C:\WINDOWS\system32\drivers\31914939.sys [2008-03-05 11:41]
R2 is-U85SF;is-U85SF;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-U85SF\is-U85SF.exe [2008-06-07 15:26]
S1 is-B98LMdrv;is-B98LMdrv;C:\WINDOWS\system32\drivers\15496916.sys [2008-03-05 11:41]
S2 0124351215957598mcinstcleanup;McAfee Application Installer Cleanup (0124351215957598);C:\WINDOWS\TEMP\012435~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S2 is-74P1D;is-74P1D;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-74P1D\is-74P1D.exe []
S2 is-B98LM;is-B98LM;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-B98LM\is-B98LM.exe []
S2 is-QTKTP;is-QTKTP;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-QTKTP\is-QTKTP.exe []
S3 utm1mzm5;AVZ Kernel Driver;C:\WINDOWS\system32\Drivers\utm1mzm5.sys [2008-07-13 09:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2007-12-15 C:\WINDOWS\Tasks\McDefragTask.job
- C:\WINDOWS\system32\defrag.exe [2004-08-10 07:00]

2007-12-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -

BHO-{eba7af1c-3b08-4c61-aca9-187b9edc6c90} - C:\WINDOWS\system32\zytaow.dll
HKLM-Run-302b85c4 - C:\WINDOWS\system32\swpkhokh.dll
HKLM-Run-SMrhcgn3j0en3p - C:\Program Files\rhcgn3j0en3p\rhcgn3j0en3p.exe
HKLM-Run-SMshcjn3j0en3p - C:\Program Files\shcjn3j0en3p\shcjn3j0en3p.exe
HKLM-Run-is-74P1D - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-74P1D\is-74P1D.exe
HKLM-Run-BM3318b658 - C:\WINDOWS\system32\khxcdvvy.dll
HKLM-Run-is-QTKTP - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-QTKTP\is-QTKTP.exe
HKLM-Run-is-B98LM - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-B98LM\is-B98LM.exe
Notify-jkkkkhi - jkkkkhi.dll


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\a\Application Data\Mozilla\Firefox\Profiles\0q4p38bg.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-16 15:55:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\a\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-08-16 16:00:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-16 19:59:55

Pre-Run: 133,264,470,016 bytes free
Post-Run: 133,471,543,296 bytes free

340 --- E O F --- 2008-08-14 00:28:10

#7 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:05:26 PM

Posted 16 August 2008 - 05:17 PM

Nicely done,,, getting there




Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\system32\sywwtw.dll
    C:\WINDOWS\system32\hvakfeux.dll

  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.

  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


Could you please scan with Kaspersky as well

Please do a scan with Kaspersky Online Scanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


#8 Ant84

Ant84
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:26 PM

Posted 18 August 2008 - 11:31 AM

Step Three...Here are the latest scans

OT scan

DllUnregisterServer procedure not found in C:\WINDOWS\system32\sywwtw.dll
C:\WINDOWS\system32\sywwtw.dll NOT unregistered.
C:\WINDOWS\system32\sywwtw.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\hvakfeux.dll
C:\WINDOWS\system32\hvakfeux.dll NOT unregistered.
C:\WINDOWS\system32\hvakfeux.dll moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 0817




Kaspersky Online scan

KASPERSKY ONLINE SCANNER 7 REPORT
Monday, August 18, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, August 17, 2008 21:46:47
Records in database: 1102962


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area My Computer
A:\
C:\
D:\

Scan statistics
Files scanned 68843
Threat name 11
Infected objects 16
Suspicious objects 0
Duration of the scan 06:29:01

File name Threat name Threats count
C:\Deckard\System Scanner\20080811200916\backup\DOCUME~1\a\LOCALS~1\Temp\lla1.exe Infected: Hoax.Win32.Renos.vaua 1

C:\Deckard\System Scanner\20080811200916\backup\DOCUME~1\a\LOCALS~1\Temp\lla2.exe Infected: not-a-virus:AdWare.Win32.E404.gc 1

C:\Deckard\System Scanner\20080811200916\backup\DOCUME~1\a\LOCALS~1\Temp\snpp.exe Infected: Trojan-Downloader.Win32.VB.eyc 1

C:\Documents and Settings\a\Shared\03 Track 3 (come).wma Infected: Trojan-Downloader.WMA.Wimad.k 1

C:\Documents and Settings\a\Shared\Top of Charts - 2004 (straight).wma Infected: Trojan-Downloader.WMA.Wimad.k 1

C:\Documents and Settings\a\Shared\Wicked Remix (straight).wma Infected: Trojan-Downloader.WMA.Wimad.k 1

C:\Program Files\Applications\iebr.dll Infected: Trojan-Downloader.Win32.Zlob.twx 1

C:\Program Files\Applications\iebt.dll Infected: Trojan-Downloader.Win32.Zlob.twx 1

C:\Program Files\Applications\iebtm.exe Infected: Trojan-Downloader.Win32.Zlob.twy 1

C:\Program Files\Applications\wcs.exe Infected: Trojan-Downloader.Win32.Zlob.twy 1

C:\QooBox\Quarantine\C\Program Files\ASpyC\SpyWarning.dll.vir Infected: not-a-virus:FraudTool.Win32.AntiSpyCheck.m 1

C:\QooBox\Quarantine\C\WINDOWS\system32\804031\804031.dll.vir Infected: not-a-virus:AdWare.Win32.E404.gd 1

C:\QooBox\Quarantine\C\WINDOWS\system32\jkqvjzl.dll.vir Infected: Hoax.Win32.Agent.ee 1

C:\QooBox\Quarantine\C\WINDOWS\system32\swpkhokh.dll.vir Infected: Trojan.Win32.Monder.bxy 1

C:\QooBox\Quarantine\C\WINDOWS\system32\vwkbndqe.dll.vir Infected: Trojan.Win32.Monder.brk 1

C:\WINDOWS\system32\ubpr01.exe Infected: not-a-virus:AdWare.Win32.E404.gc 1

The selected area was scanned.

#9 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:05:26 PM

Posted 19 August 2008 - 07:21 PM

Need to be very careful of what your downloading and from where,,, you will want to manually delete these

C:\Documents and Settings\a\Shared\03 Track 3 (come).wma Infected: Trojan-Downloader.WMA.Wimad.k 1

C:\Documents and Settings\a\Shared\Top of Charts - 2004 (straight).wma Infected: Trojan-Downloader.WMA.Wimad.k 1

C:\Documents and Settings\a\Shared\Wicked Remix (straight).wma Infected: Trojan-Downloader.WMA.Wimad.k 1



1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Program Files\Applications\iebr.dll
C:\Program Files\Applications\iebt.dll
C:\Program Files\Applications\iebtm.exe
C:\Program Files\Applications\wcs.exe
C:\WINDOWS\system32\ubpr01.exe


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

#10 Ant84

Ant84
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:26 PM

Posted 20 August 2008 - 05:46 PM

New Combo Fix Log


ComboFix 08-08-15.04 - a 2008-08-20 18:27:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.156 [GMT -4:00]
Running from: C:\Documents and Settings\a\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\a\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Program Files\Applications\iebr.dll
C:\Program Files\Applications\iebt.dll
C:\Program Files\Applications\iebtm.exe
C:\Program Files\Applications\wcs.exe
C:\WINDOWS\system32\ubpr01.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\a\Cookies\a@ad.yieldmanager[1].txt
C:\Documents and Settings\a\Cookies\a@adserver[1].txt
C:\Documents and Settings\a\Cookies\a@revsci[1].txt
C:\Program Files\Applications\iebr.dll
C:\Program Files\Applications\iebt.dll
C:\Program Files\Applications\iebtm.exe
C:\Program Files\Applications\wcs.exe
C:\WINDOWS\system32\ubpr01.exe

.
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.

2008-08-17 16:36 . 2008-08-17 16:36 <DIR> d-------- C:\_OTMoveIt
2008-08-15 17:12 . 2008-08-15 17:12 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-15 17:12 . 2008-08-15 17:12 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-13 12:42 . 2008-06-24 12:23 74,240 --------- C:\WINDOWS\system32\dllcache\mscms.dll
2008-08-12 16:36 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-11 20:18 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\15496916.sys
2008-08-11 19:46 . 2008-08-11 19:46 <DIR> d-------- C:\Deckard
2008-08-03 08:53 . 2008-08-03 08:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comcast
2008-08-01 23:05 . 2008-08-01 23:05 <DIR> d-------- C:\Program Files\Unity
2008-08-01 18:17 . 2008-08-20 18:29 <DIR> d-------- C:\Program Files\Applications
2008-08-01 18:17 . 2008-08-01 18:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-20 22:35 162,433,056 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-20 02:20 1,895,228 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-19 22:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-18 21:36 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-09 15:43 --------- d-----w C:\Program Files\Google
2008-07-16 00:04 --------- d-----w C:\Program Files\Java
2008-07-13 13:49 7,168 ----a-w C:\WINDOWS\system32\drivers\utm1mzm5.sys
2008-07-13 01:06 5,018 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-07-13 00:45 --------- d-----w C:\Program Files\Dell Support Center
2008-07-13 00:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-07-13 00:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Dell
2008-07-13 00:42 --------- d-----w C:\Program Files\Picasa2
2008-07-12 22:13 12,464 ----a-w C:\WINDOWS\system32\drivers\CDAC15BA.SYS
2008-07-12 21:24 --------- d-----w C:\Documents and Settings\a\Application Data\Lavasoft
2008-07-10 01:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-10 00:17 --------- d-----w C:\Program Files\Trend Micro
2008-07-09 01:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-09 01:56 --------- d-----w C:\Documents and Settings\a\Application Data\SUPERAntiSpyware.com
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:49 --------- d-----w C:\Program Files\Dell
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:12 667,136 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-23 16:12 667,136 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2008-06-23 16:12 618,496 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2008-06-23 16:12 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2008-06-23 16:12 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-06-23 16:12 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2008-06-23 16:12 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-06-23 16:12 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2008-06-23 16:12 1,499,136 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-06-23 16:11 96,256 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2008-06-23 16:11 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2008-06-23 16:11 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2008-06-23 16:11 3,067,392 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 16:11 251,904 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2008-06-23 16:11 205,312 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2008-06-23 16:11 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2008-06-23 16:11 151,040 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2008-06-23 16:11 1,054,208 ------w C:\WINDOWS\system32\dllcache\danim.dll
2008-06-23 16:11 1,024,000 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2008-06-23 09:53 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-04-01 13:53 514 ----a-w C:\Documents and Settings\a\Application Data\wklnhst.dat
2007-02-02 03:17 74,656 ----a-w C:\Documents and Settings\a\Application Data\GDIPFONTCACHEV1.DAT
.

------- Sigcheck -------

2004-08-10 07:00 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe

2005-03-02 14:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 11:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-08-10 07:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 14:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\dllcache\user32.dll

2004-08-10 07:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll

2004-08-10 07:00 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe

2004-08-10 07:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys

2004-08-10 07:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys

2005-03-01 20:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 12:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 05:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2004-08-04 00:59 2015232 fb142b7007ca2eea76966c6c5cc12150 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 20:34 2015232 3cd941e472ddf3534e53038535719771 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 08:55 2015744 bbb2322eb14ad9ad55b1024ffd4d88bf C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2007-02-28 04:38 2015744 a58ac1c6199ef34228abee7fc057ae09 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe

2005-03-01 21:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 12:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 05:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2004-08-04 01:18 2148352 626309040459c3915997ef98ec1c8d40 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 20:57 2135552 48b3e89af7074cee0314a3e0c7faffdb C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 10:15 2136064 8318ed54797f3e513fd5817a1d4bbd18 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2007-02-28 05:08 2136064 1220faf071dea8653ee21de7dcda8bfd C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\dllcache\ntoskrnl.exe

2004-08-10 07:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe

2004-08-10 07:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe

2004-08-10 07:00 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe

2005-06-10 20:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-10 19:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe

2004-08-10 07:00 24576 39b1ffb03c2296323832acbae50d2aff C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((( snapshot@2008-08-16_15.58.58.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-18 21:36:48 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A81200000003}\SC_Reader.exe
+ 2008-08-20 22:17:48 1,954 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{389AC7E5-7DD8-409B-91E5-6B15DB38973F}.bin
- 2008-08-16 18:53:37 32,768 ------w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-20 21:44:50 32,768 ------w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-08-16 18:53:37 32,768 ------w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-08-20 21:44:50 32,768 ------w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-06-05 19:14:28 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
+ 2006-06-05 18:14:28 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcm80.dll
- 2006-06-05 19:14:28 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
+ 2006-06-05 18:14:28 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcp80.dll
- 2006-06-05 19:14:28 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
+ 2006-06-05 18:14:28 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 20:23 102400]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 19:40 24576 C:\WINDOWS\MIDIDEF.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01 67584]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-20 01:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-20 01:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-20 01:10 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 22:12 221184]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19 53248]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 18:10 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 03:00 90112]
"VoiceCenter"="C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" [2005-02-23 13:08 1159168]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-28 11:24 98304]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 03:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44 81920]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 21:20 8192]
"MMTray"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe" [2005-09-08 21:20 110592]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-25 07:39 1836544]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-12 22:29 185632]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 15:21 198184]
"is-U85SF"="C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-U85SF\is-U85SF.exe" [2008-06-07 15:26 217088]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"MBMon"="CTMBHA.DLL" [2005-05-19 18:54 1345520 C:\WINDOWS\system32\CTMBHA.DLL]

C:\Documents and Settings\a\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
dlbcserv.lnk - C:\Program Files\Dell Photo Printer 720\dlbcserv.exe [2006-07-10 11:27:13 315392]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2006-10-25 22:38:45 124912]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-05-15 11:10:00 394856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=

R1 is-74P1Ddrv;is-74P1Ddrv;C:\WINDOWS\system32\drivers\98442555.sys [2008-03-05 11:41]
R1 is-QTKTPdrv;is-QTKTPdrv;C:\WINDOWS\system32\drivers\95151642.sys [2008-03-05 11:41]
R1 is-SPSHUdrv;is-SPSHUdrv;C:\WINDOWS\system32\drivers\22422312.sys [2008-03-05 11:41]
R1 is-U85SFdrv;is-U85SFdrv;C:\WINDOWS\system32\drivers\31914939.sys [2008-03-05 11:41]
S1 is-B98LMdrv;is-B98LMdrv;C:\WINDOWS\system32\drivers\15496916.sys [2008-03-05 11:41]
S2 0124351215957598mcinstcleanup;McAfee Application Installer Cleanup (0124351215957598);C:\WINDOWS\TEMP\012435~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S2 is-74P1D;is-74P1D;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-74P1D\is-74P1D.exe []
S2 is-B98LM;is-B98LM;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-B98LM\is-B98LM.exe []
S2 is-QTKTP;is-QTKTP;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-QTKTP\is-QTKTP.exe []
S2 is-U85SF;is-U85SF;C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\is-U85SF\is-U85SF.exe [2008-06-07 15:26]
S3 utm1mzm5;AVZ Kernel Driver;C:\WINDOWS\system32\Drivers\utm1mzm5.sys [2008-07-13 09:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder

2007-12-15 C:\WINDOWS\Tasks\McDefragTask.job
- C:\WINDOWS\system32\defrag.exe [2004-08-10 07:00]

2007-12-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-20 18:34:30
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-20 18:36:49
ComboFix-quarantined-files.txt 2008-08-20 22:36:38
ComboFix2.txt 2008-08-16 20:00:19

Pre-Run: 138,504,179,712 bytes free
Post-Run: 138,599,251,968 bytes free

240 --- E O F --- 2008-08-14 00:28:10

#11 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:05:26 PM

Posted 21 August 2008 - 06:21 PM

Nice work :thumbsup:

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • The next screen will ask you to select the drives to scan. Leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

#12 Ant84

Ant84
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:26 PM

Posted 24 August 2008 - 11:46 AM

Malwarebytes log:



Malwarebytes' Anti-Malware 1.25
Database version: 1081
Windows 5.1.2600 Service Pack 2

12:44:15 PM 8/24/2008
mbam-log-08-24-2008 (12-44-15).txt

Scan type: Quick Scan
Objects scanned: 49289
Time elapsed: 4 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\bndshell3.bho (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bndshell3.bho.1 (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhcgn3j0en3p (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhcgn3j0en3p (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Applications\iebtmm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\iebtu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\iebu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\myd.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\mym.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\myp.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\myv.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\ot.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\ts.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\wcm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\wcu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Antivirus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Online Spyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.

#13 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:05:26 PM

Posted 30 August 2008 - 07:20 AM

My apologies I missed your reply here

everything looks fine now any further issues ? How is the machine running ?

#14 Ant84

Ant84
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:26 PM

Posted 30 August 2008 - 01:26 PM

It seems to be running fine now, but for some reason when it is starting up the sonic updater asks me to insert a cd to complete the update, if I click cancel the dialog box just blinks and opens again right after. The only way to get it to stop is with the task manager. This is the only thing wrong right now as far as I can tell.

#15 don77

don77

    Forum Regular


  • Members
  • 3,212 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Boston Mass
  • Local time:05:26 PM

Posted 30 August 2008 - 08:26 PM

Could you post a fresh HJT log please




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users