
machine acting strange
#106
Posted 10 November 2008 - 05:58 PM
Register to Remove
#107
Posted 10 November 2008 - 06:09 PM
AutoRuns for Windows v9.35
At the bottom of the page is the download.
Run the tool and post the results.
Simply run Autoruns and it shows you the currently configured auto-start applications as well as the full list of Registry and file system locations available for auto-start configuration. Autostart locations displayed by Autoruns include logon entries, Explorer add-ons, Internet Explorer add-ons including Browser Helper Objects (BHOs), Appinit DLLs, image hijacks, boot execute images, Winlogon notification DLLs, Windows Services and Winsock Layered Service Providers.
Just click this link, save it and run it.
http://live.sysinter...om/autoruns.exe
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#108
Posted 10 November 2008 - 06:23 PM
#109
Posted 10 November 2008 - 06:27 PM
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#110
Posted 10 November 2008 - 06:44 PM
#111
Posted 10 November 2008 - 07:25 PM
#112
Posted 10 November 2008 - 07:26 PM
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#113
Posted 10 November 2008 - 07:26 PM
Headed there soon myself,Got to get some sleep. Will check in tomorrow morning for your next instructions.
Thanks
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#114
Posted 11 November 2008 - 07:23 AM
#115
Posted 11 November 2008 - 07:48 AM
Please use the Internet Explorer browser and do an online scan with Kaspersky Online Scanner
Note: If you have used this particular scanner before, you MAY HAVE TO UNINSTALL the program through Add/Remove Programs before downloading the new ActiveX component
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
- Once the files are downloaded click on Next
- Click on Scan Settings and configure as follows:
- Scan using the following Anti-Virus database:
- Extended
- Scan Options:Scan Archives
Scan Mail Bases
- Scan using the following Anti-Virus database:
- Click OK and, under select a target to scan, select My Computer
There is no option to clean/disinfect, however, we need to analyze the information on the report.
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
Register to Remove
#116
Posted 11 November 2008 - 08:17 AM
Edited by Gator, 11 November 2008 - 08:22 AM.
#117
Posted 11 November 2008 - 09:31 AM
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
#118
Posted 11 November 2008 - 10:43 AM
Was unable to get ComboFix to run. Deleted it and downloaded again.
Ran it and here is the log.
ComboFix 08-11-10.01 - James 2008-11-11 11:31:31.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1478 [GMT -5:00]
Running from: c:\documents and settings\James\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-10-11 to 2008-11-11 )))))))))))))))))))))))))))))))
.
2008-11-11 11:16 . 2008-11-11 11:16 <DIR> d--h----- c:\windows\system32\GroupPolicy
2008-11-09 16:31 . 2008-11-09 16:31 <DIR> d---s---- c:\documents and settings\James\UserData
2008-11-09 13:49 . 2004-08-10 06:00 169,984 --a------ c:\windows\system32\dllcache\iisui.dll
2008-11-09 13:49 . 2004-08-10 06:00 94,720 --a------ c:\windows\system32\dllcache\certmap.ocx
2008-11-09 13:49 . 2001-08-17 14:56 66,048 --a------ c:\windows\system32\dllcache\s3legacy.dll
2008-11-09 13:49 . 2004-08-10 06:00 19,968 --a------ c:\windows\system32\dllcache\inetsloc.dll
2008-11-09 13:49 . 2004-08-10 06:00 14,336 --a------ c:\windows\system32\dllcache\iisreset.exe
2008-11-09 13:49 . 2004-08-10 06:00 7,680 --a------ c:\windows\system32\dllcache\inetmgr.exe
2008-11-09 13:49 . 2004-08-10 06:00 7,168 --a------ c:\windows\system32\dllcache\wamregps.dll
2008-11-09 13:49 . 2004-08-10 06:00 6,144 --a------ c:\windows\system32\dllcache\ftpsapi2.dll
2008-11-09 13:49 . 2004-08-10 06:00 5,632 --a------ c:\windows\system32\dllcache\iisrstap.dll
2008-11-09 11:28 . 2008-11-09 11:28 <DIR> d-------- c:\program files\Sun
2008-11-09 11:27 . 2008-11-09 11:27 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-09 11:27 . 2008-11-09 11:27 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-09 10:14 . 2008-11-09 10:16 <DIR> d-------- C:\Lop SD
2008-11-07 20:11 . 2008-11-07 20:11 <DIR> d-------- c:\program files\ERUNT
2008-11-07 19:50 . 2008-11-07 19:50 <DIR> d-------- c:\documents and settings\James\Application Data\U3
2008-11-06 18:41 . 2008-11-06 18:41 <DIR> d-------- c:\documents and settings\Earlene\Application Data\Malwarebytes
2008-11-05 15:35 . 2008-11-05 15:35 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-05 15:35 . 2008-11-05 15:35 <DIR> d-------- c:\documents and settings\James\Application Data\Malwarebytes
2008-11-05 15:35 . 2008-11-05 15:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-05 15:35 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-05 15:35 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-10-16 00:07 . 2008-09-15 07:12 1,846,400 --------- c:\windows\system32\dllcache\win32k.sys
2008-10-16 00:07 . 2008-09-08 05:41 333,824 --------- c:\windows\system32\dllcache\srv.sys
2008-10-16 00:06 . 2008-08-14 05:11 2,189,184 --a------ c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-16 00:06 . 2008-08-14 04:33 2,066,048 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-16 00:06 . 2008-08-14 04:33 2,023,936 --------- c:\windows\system32\dllcache\ntkrpamp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-09 16:27 --------- d-----w c:\program files\Java
2008-10-15 16:34 337,408 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-14 01:11 --------- d-----w c:\program files\LimeWire
2008-10-14 01:11 --------- d-----w c:\documents and settings\Earlene\Application Data\LimeWire
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-08-20 05:30 666,112 ----a-w c:\windows\system32\wininet.dll
2008-08-20 05:30 666,112 ----a-w c:\windows\system32\dllcache\wininet.dll
2008-08-20 05:30 619,520 ----a-w c:\windows\system32\dllcache\urlmon.dll
2008-08-20 05:30 3,067,904 ------w c:\windows\system32\dllcache\mshtml.dll
2008-08-20 05:30 1,499,136 ----a-w c:\windows\system32\dllcache\shdocvw.dll
2008-08-14 10:09 2,145,280 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 10:09 2,145,280 ----a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 10:04 138,496 ------w c:\windows\system32\dllcache\afd.sys
2008-08-14 09:33 2,023,936 ----a-w c:\windows\system32\ntkrnlpa.exe
2007-02-04 15:55 0 ----a-w c:\documents and settings\Earlene\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-11-07_21.09.25.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-14 00:11:48 136,192 ----a-w c:\windows\system32\dllcache\aaclient.dll
+ 2008-04-14 00:11:48 1,852,928 ----a-w c:\windows\system32\dllcache\acgenral.dll
+ 2008-04-14 00:11:48 451,072 ----a-w c:\windows\system32\dllcache\aclayers.dll
+ 2008-04-14 00:11:48 245,248 ----a-w c:\windows\system32\dllcache\acspecfc.dll
+ 2008-04-14 00:11:48 116,224 ----a-w c:\windows\system32\dllcache\acxtrnal.dll
+ 2008-04-14 00:11:48 20,540 ----a-w c:\windows\system32\dllcache\admin.dll
+ 2008-04-14 00:12:12 16,439 ----a-w c:\windows\system32\dllcache\admin.exe
+ 2008-04-14 00:11:48 43,520 ----a-w c:\windows\system32\dllcache\admwprox.dll
+ 2008-04-14 00:11:48 290,816 ----a-w c:\windows\system32\dllcache\adsiis51.dll
+ 2008-04-14 00:12:12 98,304 ----a-w c:\windows\system32\dllcache\ahui.exe
+ 2008-04-14 00:11:49 125,952 ----a-w c:\windows\system32\dllcache\apphelp.dll
+ 2008-04-14 00:11:49 65,024 ----a-w c:\windows\system32\dllcache\asycfilt.dll
+ 2008-04-14 00:11:50 30,208 ----a-w c:\windows\system32\dllcache\atmlib.dll
+ 2008-04-14 00:11:50 20,540 ----a-w c:\windows\system32\dllcache\author.dll
+ 2008-04-14 00:12:12 16,439 ----a-w c:\windows\system32\dllcache\author.exe
+ 2008-04-14 00:11:50 233,472 ----a-w c:\windows\system32\dllcache\azroles.dll
+ 2008-04-14 00:11:50 7,168 ----a-w c:\windows\system32\dllcache\bitsprx4.dll
+ 2008-04-14 00:09:05 16,896 ----a-w c:\windows\system32\dllcache\cfgmgr32.dll
+ 2008-04-14 00:12:14 188,480 ----a-w c:\windows\system32\dllcache\cfgwiz.exe
+ 2008-04-14 00:11:51 46,592 ----a-w c:\windows\system32\dllcache\coadmin.dll
+ 2008-04-14 00:11:51 617,472 ----a-w c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 00:11:51 276,992 ----a-w c:\windows\system32\dllcache\comdlg32.dll
+ 2008-04-14 00:11:51 252,928 ----a-w c:\windows\system32\dllcache\compatui.dll
+ 2008-04-14 00:11:51 599,040 ----a-w c:\windows\system32\dllcache\crypt32.dll
+ 2008-04-14 00:11:51 74,752 ----a-w c:\windows\system32\dllcache\cryptdlg.dll
+ 2008-04-14 00:11:51 33,280 ----a-w c:\windows\system32\dllcache\cryptdll.dll
+ 2008-04-14 00:11:51 53,760 ----a-w c:\windows\system32\dllcache\cryptext.dll
+ 2008-04-14 00:11:51 64,512 ----a-w c:\windows\system32\dllcache\cryptnet.dll
+ 2008-04-14 00:11:51 62,464 ----a-w c:\windows\system32\dllcache\cryptsvc.dll
+ 2008-04-14 00:11:51 512,512 ----a-w c:\windows\system32\dllcache\cryptui.dll
+ 2004-08-10 11:00:00 27,136 ----a-w c:\windows\system32\dllcache\ctl3d32.dll
+ 2008-04-14 00:11:52 19,456 ----a-w c:\windows\system32\dllcache\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 ----a-w c:\windows\system32\dllcache\dimsroam.dll
+ 2008-04-14 00:11:52 32,768 ----a-w c:\windows\system32\dllcache\dispex.dll
+ 2004-08-10 11:00:00 246,272 ----a-w c:\windows\system32\dllcache\drmclien.dll
+ 2004-08-10 11:00:00 92,672 ----a-w c:\windows\system32\dllcache\drmstor.dll
+ 2008-04-14 00:11:52 16,384 ----a-w c:\windows\system32\dllcache\ds32gt.dll
+ 2008-04-13 17:37:57 138,752 ----a-w c:\windows\system32\dllcache\dssenh.dll
+ 2008-04-14 00:11:53 380,445 ----a-w c:\windows\system32\dllcache\expsrv.dll
+ 2008-04-13 19:14:29 143,744 ----a-w c:\windows\system32\dllcache\fastfat.sys
+ 2008-04-14 00:11:53 184,435 ----a-w c:\windows\system32\dllcache\fp4amsft.dll
+ 2008-04-14 00:11:53 82,035 ----a-w c:\windows\system32\dllcache\fp4anscp.dll
+ 2008-04-14 00:11:53 147,513 ----a-w c:\windows\system32\dllcache\fp4apws.dll
+ 2008-04-14 00:11:53 49,210 ----a-w c:\windows\system32\dllcache\fp4areg.dll
+ 2008-04-14 00:11:53 102,509 ----a-w c:\windows\system32\dllcache\fp4atxt.dll
+ 2008-04-14 00:11:53 41,020 ----a-w c:\windows\system32\dllcache\fp4avnb.dll
+ 2008-04-14 00:11:53 32,826 ----a-w c:\windows\system32\dllcache\fp4avss.dll
+ 2008-04-14 00:11:53 49,212 ----a-w c:\windows\system32\dllcache\fp4awebs.dll
+ 2008-04-14 00:11:53 876,653 ----a-w c:\windows\system32\dllcache\fp4awel.dll
+ 2008-04-14 00:12:20 15,120 ----a-w c:\windows\system32\dllcache\fp98sadm.exe
+ 2008-04-14 00:12:20 109,840 ----a-w c:\windows\system32\dllcache\fp98swin.exe
+ 2008-04-14 00:12:20 188,494 ----a-w c:\windows\system32\dllcache\fpcount.exe
+ 2008-04-14 00:11:53 20,541 ----a-w c:\windows\system32\dllcache\fpexedll.dll
+ 2008-04-14 00:11:53 598,071 ----a-w c:\windows\system32\dllcache\fpmmc.dll
+ 2007-04-02 16:36:04 208,896 ----a-w c:\windows\system32\dllcache\fpmmcsat.dll
+ 2008-04-14 00:12:20 20,538 ----a-w c:\windows\system32\dllcache\fpremadm.exe
+ 2008-04-14 00:11:54 68,608 ----a-w c:\windows\system32\dllcache\iisext51.dll
+ 2008-04-14 00:11:54 64,512 ----a-w c:\windows\system32\dllcache\iismap.dll
+ 2008-04-14 00:12:22 30,720 ----a-w c:\windows\system32\dllcache\iisrstas.exe
+ 2008-04-14 00:11:54 133,632 ----a-w c:\windows\system32\dllcache\iisrtl.dll
+ 2008-04-14 00:11:54 36,921 ----a-w c:\windows\system32\dllcache\imeshare.dll
+ 2008-04-14 00:11:55 829,440 ----a-w c:\windows\system32\dllcache\inetmgr.dll
+ 2008-04-14 00:11:55 13,312 ----a-w c:\windows\system32\dllcache\infoadmn.dll
+ 2008-04-13 19:19:42 75,264 ----a-w c:\windows\system32\dllcache\ipsec.sys
+ 2008-04-14 00:11:55 68,608 ----a-w c:\windows\system32\dllcache\isatq.dll
+ 2008-04-14 00:11:55 155,136 ----a-w c:\windows\system32\dllcache\itircl.dll
+ 2008-04-14 00:11:55 138,240 ----a-w c:\windows\system32\dllcache\itss.dll
+ 2008-04-14 00:11:56 15,872 ----a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\dllcache\kbdbhc.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\dllcache\kbdiultn.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\dllcache\kbdnepr.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\dllcache\kbdpash.dll
+ 2008-04-14 00:11:56 989,696 ----a-w c:\windows\system32\dllcache\kernel32.dll
+ 2006-10-19 02:47:14 11,264 ----a-w c:\windows\system32\dllcache\laprxy.dll
+ 2006-10-19 01:03:58 100,864 ----a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-04-14 00:11:56 728,064 ----a-w c:\windows\system32\dllcache\lsasrv.dll
+ 2004-08-10 11:00:00 924,432 ----a-w c:\windows\system32\dllcache\mfc40.dll
+ 2008-04-14 00:11:56 927,504 ----a-w c:\windows\system32\dllcache\mfc40u.dll
+ 2008-04-14 00:11:56 1,028,096 ----a-w c:\windows\system32\dllcache\mfc42.dll
+ 2008-04-14 00:11:56 22,528 ----a-w c:\windows\system32\dllcache\mfcsubs.dll
+ 2008-04-13 17:25:57 20,480 ----a-w c:\windows\system32\dllcache\msadcer.dll
+ 2008-04-14 00:11:58 61,440 ----a-w c:\windows\system32\dllcache\msadcf.dll
+ 2008-04-13 17:25:57 16,384 ----a-w c:\windows\system32\dllcache\msadcfr.dll
+ 2008-04-14 00:11:58 143,360 ----a-w c:\windows\system32\dllcache\msadco.dll
+ 2008-04-13 17:25:57 16,384 ----a-w c:\windows\system32\dllcache\msadcor.dll
+ 2008-04-14 00:11:58 53,248 ----a-w c:\windows\system32\dllcache\msadcs.dll
+ 2008-04-14 00:11:58 155,648 ----a-w c:\windows\system32\dllcache\msadds.dll
+ 2008-04-13 17:25:58 24,576 ----a-w c:\windows\system32\dllcache\msaddsr.dll
+ 2008-04-13 17:26:17 24,576 ----a-w c:\windows\system32\dllcache\msader15.dll
+ 2008-04-14 00:11:58 536,576 ----a-w c:\windows\system32\dllcache\msado15.dll
+ 2008-04-14 00:11:58 180,224 ----a-w c:\windows\system32\dllcache\msadomd.dll
+ 2008-04-14 00:11:58 57,344 ----a-w c:\windows\system32\dllcache\msador15.dll
+ 2008-04-14 00:11:58 200,704 ----a-w c:\windows\system32\dllcache\msadox.dll
+ 2008-04-14 00:11:58 57,344 ----a-w c:\windows\system32\dllcache\msadrh15.dll
+ 2008-04-14 00:11:58 36,864 ----a-w c:\windows\system32\dllcache\mscpxl32.dll
+ 2008-04-14 00:11:58 4,096 ----a-w c:\windows\system32\dllcache\msdadc.dll
+ 2008-04-14 00:11:58 4,096 ----a-w c:\windows\system32\dllcache\msdaenum.dll
+ 2008-04-14 00:11:58 4,096 ----a-w c:\windows\system32\dllcache\msdaer.dll
+ 2008-04-14 00:11:58 233,472 ----a-w c:\windows\system32\dllcache\msdaora.dll
+ 2008-04-14 00:11:58 77,824 ----a-w c:\windows\system32\dllcache\msdaosp.dll
+ 2008-04-13 17:25:58 16,384 ----a-w c:\windows\system32\dllcache\msdaprsr.dll
+ 2008-04-14 00:11:58 200,704 ----a-w c:\windows\system32\dllcache\msdaprst.dll
+ 2008-04-14 00:11:59 204,800 ----a-w c:\windows\system32\dllcache\msdaps.dll
+ 2008-04-14 00:11:59 118,784 ----a-w c:\windows\system32\dllcache\msdarem.dll
+ 2008-04-13 17:25:58 16,384 ----a-w c:\windows\system32\dllcache\msdaremr.dll
+ 2008-04-14 00:11:59 4,096 ----a-w c:\windows\system32\dllcache\msdasc.dll
+ 2008-04-14 00:11:59 315,392 ----a-w c:\windows\system32\dllcache\msdasql.dll
+ 2008-04-13 17:26:07 16,384 ----a-w c:\windows\system32\dllcache\msdasqlr.dll
+ 2008-04-14 00:11:59 20,480 ----a-w c:\windows\system32\dllcache\msdatt.dll
+ 2008-04-14 00:11:59 4,096 ----a-w c:\windows\system32\dllcache\msdaurl.dll
+ 2008-04-14 00:11:59 36,864 ----a-w c:\windows\system32\dllcache\msdfmap.dll
+ 2008-04-14 00:10:08 4,126 ----a-w c:\windows\system32\dllcache\msdxmlc.dll
+ 2008-04-14 00:12:00 151,583 ----a-w c:\windows\system32\dllcache\msjint40.dll
+ 2008-04-14 00:12:00 102,400 ----a-w c:\windows\system32\dllcache\msjro.dll
+ 2008-04-14 00:12:00 143,360 ----a-w c:\windows\system32\dllcache\msorcl32.dll
+ 2004-08-10 11:00:00 4,608 ----a-w c:\windows\system32\dllcache\mssip32.dll
+ 2008-04-14 00:12:01 343,040 ----a-w c:\windows\system32\dllcache\msvcrt.dll
+ 2008-04-13 18:30:46 61,440 ----a-w c:\windows\system32\dllcache\msvcrt40.dll
+ 2008-04-14 00:12:01 24,576 ----a-w c:\windows\system32\dllcache\msxactps.dll
+ 2008-04-13 19:20:42 91,520 ----a-w c:\windows\system32\dllcache\ndiswan.sys
+ 2008-04-14 00:11:24 706,048 ----a-w c:\windows\system32\dllcache\ntdll.dll
+ 2008-04-13 19:15:53 574,976 ----a-w c:\windows\system32\dllcache\ntfs.sys
+ 2004-08-10 11:00:00 17,408 ----a-w c:\windows\system32\dllcache\nwapi16.dll
+ 2008-04-14 00:12:02 64,000 ----a-w c:\windows\system32\dllcache\nwapi32.dll
+ 2008-04-14 00:12:02 67,584 ----a-w c:\windows\system32\dllcache\ocmanage.dll
+ 2008-04-14 00:12:02 106,496 ----a-w c:\windows\system32\dllcache\odbccp32.dll
+ 2008-04-14 00:12:02 20,511 ----a-w c:\windows\system32\dllcache\odtext32.dll
+ 2004-08-19 19:25:28 13,107,200 ----a-w c:\windows\system32\dllcache\oembios.bin
+ 2004-08-19 19:25:28 4,627 ----a-w c:\windows\system32\dllcache\oembios.dat
+ 2008-04-14 00:12:02 1,287,168 ----a-w c:\windows\system32\dllcache\ole32.dll
+ 2008-04-14 00:12:02 551,936 ----a-w c:\windows\system32\dllcache\oleaut32.dll
+ 2008-04-14 00:12:02 84,992 ----a-w c:\windows\system32\dllcache\olepro32.dll
+ 2008-04-14 00:12:04 433,664 ----a-w c:\windows\system32\dllcache\riched20.dll
+ 2004-08-10 11:00:00 3,584 ----a-w c:\windows\system32\dllcache\riched32.dll
+ 2008-04-13 17:37:57 208,384 ----a-w c:\windows\system32\dllcache\rsaenh.dll
+ 2008-04-14 00:12:04 64,000 ----a-w c:\windows\system32\dllcache\samlib.dll
+ 2008-04-14 00:12:04 415,744 ----a-w c:\windows\system32\dllcache\samsrv.dll
+ 2008-04-14 00:12:05 144,384 ----a-w c:\windows\system32\dllcache\schannel.dll
+ 2008-04-14 00:12:34 77,312 ----a-w c:\windows\system32\dllcache\sdbinst.exe
+ 2004-08-10 11:00:00 4,569 ----a-w c:\windows\system32\dllcache\secupd.dat
+ 2008-04-14 09:42:06 985,088 ----a-w c:\windows\system32\dllcache\setupapi.dll
+ 2008-04-14 00:12:05 5,120 ----a-w c:\windows\system32\dllcache\sfc.dll
+ 2004-08-10 11:00:00 9,728 ----a-w c:\windows\system32\dllcache\sfc.exe
+ 2008-04-14 00:12:05 1,614,848 ----a-w c:\windows\system32\dllcache\sfcfiles.dll
+ 2008-04-14 00:12:05 65,024 ----a-w c:\windows\system32\dllcache\shimeng.dll
+ 2008-04-14 00:12:05 20,536 ----a-w c:\windows\system32\dllcache\shtml.dll
+ 2008-04-14 00:12:35 16,437 ----a-w c:\windows\system32\dllcache\shtml.exe
+ 2008-04-14 00:12:06 25,088 ----a-w c:\windows\system32\dllcache\slayerxp.dll
+ 2008-04-14 00:12:06 189,440 ----a-w c:\windows\system32\dllcache\smtpadm.dll
+ 2008-04-14 00:12:06 2,134,528 ----a-w c:\windows\system32\dllcache\smtpsnap.dll
+ 2008-04-14 00:12:07 8,192 ----a-w c:\windows\system32\dllcache\staxmem.dll
+ 2008-04-14 00:12:37 106,496 ----a-w c:\windows\system32\dllcache\sysocmgr.exe
+ 2008-04-14 00:12:37 32,827 ----a-w c:\windows\system32\dllcache\tcptest.exe
+ 2007-04-02 16:36:07 16,384 ----a-w c:\windows\system32\dllcache\tcptsat.dll
+ 2004-08-10 11:00:00 49,680 ----a-w c:\windows\system32\dllcache\twunk_16.exe
+ 2004-08-10 11:00:00 25,600 ----a-w c:\windows\system32\dllcache\twunk_32.exe
+ 2004-08-10 11:00:00 177,856 ----a-w c:\windows\system32\dllcache\typelib.dll
+ 2008-04-14 00:12:07 123,392 ----a-w c:\windows\system32\dllcache\umpnpmgr.dll
+ 2008-04-14 00:12:08 37,888 ----a-w c:\windows\system32\dllcache\url.dll
+ 2008-04-14 00:12:39 507,904 ----a-w c:\windows\system32\dllcache\winlogon.exe
+ 2008-04-14 00:12:09 176,640 ----a-w c:\windows\system32\dllcache\wintrust.dll
- 2005-11-10 17:27:06 49,248 ----a-w c:\windows\system32\java.exe
+ 2008-11-09 16:27:22 144,792 ----a-w c:\windows\system32\java.exe
- 2005-11-10 17:27:16 49,250 ----a-w c:\windows\system32\javaw.exe
+ 2008-11-09 16:27:22 144,792 ----a-w c:\windows\system32\javaw.exe
- 2005-11-10 19:03:54 127,078 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-09 16:27:22 148,888 ----a-w c:\windows\system32\javaws.exe
- 2008-11-08 02:03:05 62,126 ----a-w c:\windows\system32\perfc009.dat
+ 2008-11-09 15:56:59 69,896 ----a-w c:\windows\system32\perfc009.dat
- 2008-11-08 02:03:05 396,276 ----a-w c:\windows\system32\perfh009.dat
+ 2008-11-09 15:56:59 409,416 ----a-w c:\windows\system32\perfh009.dat
+ 2008-11-11 13:20:08 16,384 ----atw c:\windows\temp\Perflib_Perfdata_6f0.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 398864]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1764864]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-22 1470464]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1105920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 831579]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 126976]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 294912]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 155648]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-09 214424]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 283888]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-01-23 24576]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2008-01-11 389120]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 249856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.speex32"= speex32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\WRAL DESKTOP WEATHER\\TrueWeather.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe"=
"c:\\WINDOWS\\system32\\Ati2evxx.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Dell\\QuickSet\\quickset.exe"=
"c:\\Program Files\\Dell Support\\DSAgnt.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe"=
"c:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe"=
"c:\\WINDOWS\\stsystra.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security 14\\TMAS_OE\\TMAS_OEMon.exe"=
"c:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security 14\\pccmain.exe"=
R3 abp470n5;abp470n5;c:\windows\system32\drivers\hhgmrs.sys [ ]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);c:\windows\system32\DRIVERS\w300bus.sys [2006-03-13 60800]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
2008-11-08 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - James.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\James\Application Data\Mozilla\Firefox\Profiles\6isqf98n.default\
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-11 11:33:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-11-11 11:37:31
ComboFix-quarantined-files.txt 2008-11-11 16:36:28
ComboFix2.txt 2008-11-09 14:05:57
ComboFix3.txt 2008-11-09 03:50:23
ComboFix4.txt 2008-11-09 03:17:52
ComboFix5.txt 2008-11-11 16:31:01
Pre-Run: 50,651,627,520 bytes free
Post-Run: 50,582,069,248 bytes free
347 --- E O F --- 2008-10-24 17:55:59
#119
Posted 11 November 2008 - 10:44 AM
Was unable to get ComboFix to run. Deleted it and downloaded again.
Ran it and here is the log.
ComboFix 08-11-10.01 - James 2008-11-11 11:31:31.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1478 [GMT -5:00]
Running from: c:\documents and settings\James\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-10-11 to 2008-11-11 )))))))))))))))))))))))))))))))
.
2008-11-11 11:16 . 2008-11-11 11:16 <DIR> d--h----- c:\windows\system32\GroupPolicy
2008-11-09 16:31 . 2008-11-09 16:31 <DIR> d---s---- c:\documents and settings\James\UserData
2008-11-09 13:49 . 2004-08-10 06:00 169,984 --a------ c:\windows\system32\dllcache\iisui.dll
2008-11-09 13:49 . 2004-08-10 06:00 94,720 --a------ c:\windows\system32\dllcache\certmap.ocx
2008-11-09 13:49 . 2001-08-17 14:56 66,048 --a------ c:\windows\system32\dllcache\s3legacy.dll
2008-11-09 13:49 . 2004-08-10 06:00 19,968 --a------ c:\windows\system32\dllcache\inetsloc.dll
2008-11-09 13:49 . 2004-08-10 06:00 14,336 --a------ c:\windows\system32\dllcache\iisreset.exe
2008-11-09 13:49 . 2004-08-10 06:00 7,680 --a------ c:\windows\system32\dllcache\inetmgr.exe
2008-11-09 13:49 . 2004-08-10 06:00 7,168 --a------ c:\windows\system32\dllcache\wamregps.dll
2008-11-09 13:49 . 2004-08-10 06:00 6,144 --a------ c:\windows\system32\dllcache\ftpsapi2.dll
2008-11-09 13:49 . 2004-08-10 06:00 5,632 --a------ c:\windows\system32\dllcache\iisrstap.dll
2008-11-09 11:28 . 2008-11-09 11:28 <DIR> d-------- c:\program files\Sun
2008-11-09 11:27 . 2008-11-09 11:27 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-09 11:27 . 2008-11-09 11:27 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-09 10:14 . 2008-11-09 10:16 <DIR> d-------- C:\Lop SD
2008-11-07 20:11 . 2008-11-07 20:11 <DIR> d-------- c:\program files\ERUNT
2008-11-07 19:50 . 2008-11-07 19:50 <DIR> d-------- c:\documents and settings\James\Application Data\U3
2008-11-06 18:41 . 2008-11-06 18:41 <DIR> d-------- c:\documents and settings\Earlene\Application Data\Malwarebytes
2008-11-05 15:35 . 2008-11-05 15:35 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-05 15:35 . 2008-11-05 15:35 <DIR> d-------- c:\documents and settings\James\Application Data\Malwarebytes
2008-11-05 15:35 . 2008-11-05 15:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-05 15:35 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-05 15:35 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-10-16 00:07 . 2008-09-15 07:12 1,846,400 --------- c:\windows\system32\dllcache\win32k.sys
2008-10-16 00:07 . 2008-09-08 05:41 333,824 --------- c:\windows\system32\dllcache\srv.sys
2008-10-16 00:06 . 2008-08-14 05:11 2,189,184 --a------ c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-16 00:06 . 2008-08-14 04:33 2,066,048 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-16 00:06 . 2008-08-14 04:33 2,023,936 --------- c:\windows\system32\dllcache\ntkrpamp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-09 16:27 --------- d-----w c:\program files\Java
2008-10-15 16:34 337,408 ----a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-14 01:11 --------- d-----w c:\program files\LimeWire
2008-10-14 01:11 --------- d-----w c:\documents and settings\Earlene\Application Data\LimeWire
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-08-20 05:30 666,112 ----a-w c:\windows\system32\wininet.dll
2008-08-20 05:30 666,112 ----a-w c:\windows\system32\dllcache\wininet.dll
2008-08-20 05:30 619,520 ----a-w c:\windows\system32\dllcache\urlmon.dll
2008-08-20 05:30 3,067,904 ------w c:\windows\system32\dllcache\mshtml.dll
2008-08-20 05:30 1,499,136 ----a-w c:\windows\system32\dllcache\shdocvw.dll
2008-08-14 10:09 2,145,280 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 10:09 2,145,280 ----a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 10:04 138,496 ------w c:\windows\system32\dllcache\afd.sys
2008-08-14 09:33 2,023,936 ----a-w c:\windows\system32\ntkrnlpa.exe
2007-02-04 15:55 0 ----a-w c:\documents and settings\Earlene\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-11-07_21.09.25.11 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-14 00:11:48 136,192 ----a-w c:\windows\system32\dllcache\aaclient.dll
+ 2008-04-14 00:11:48 1,852,928 ----a-w c:\windows\system32\dllcache\acgenral.dll
+ 2008-04-14 00:11:48 451,072 ----a-w c:\windows\system32\dllcache\aclayers.dll
+ 2008-04-14 00:11:48 245,248 ----a-w c:\windows\system32\dllcache\acspecfc.dll
+ 2008-04-14 00:11:48 116,224 ----a-w c:\windows\system32\dllcache\acxtrnal.dll
+ 2008-04-14 00:11:48 20,540 ----a-w c:\windows\system32\dllcache\admin.dll
+ 2008-04-14 00:12:12 16,439 ----a-w c:\windows\system32\dllcache\admin.exe
+ 2008-04-14 00:11:48 43,520 ----a-w c:\windows\system32\dllcache\admwprox.dll
+ 2008-04-14 00:11:48 290,816 ----a-w c:\windows\system32\dllcache\adsiis51.dll
+ 2008-04-14 00:12:12 98,304 ----a-w c:\windows\system32\dllcache\ahui.exe
+ 2008-04-14 00:11:49 125,952 ----a-w c:\windows\system32\dllcache\apphelp.dll
+ 2008-04-14 00:11:49 65,024 ----a-w c:\windows\system32\dllcache\asycfilt.dll
+ 2008-04-14 00:11:50 30,208 ----a-w c:\windows\system32\dllcache\atmlib.dll
+ 2008-04-14 00:11:50 20,540 ----a-w c:\windows\system32\dllcache\author.dll
+ 2008-04-14 00:12:12 16,439 ----a-w c:\windows\system32\dllcache\author.exe
+ 2008-04-14 00:11:50 233,472 ----a-w c:\windows\system32\dllcache\azroles.dll
+ 2008-04-14 00:11:50 7,168 ----a-w c:\windows\system32\dllcache\bitsprx4.dll
+ 2008-04-14 00:09:05 16,896 ----a-w c:\windows\system32\dllcache\cfgmgr32.dll
+ 2008-04-14 00:12:14 188,480 ----a-w c:\windows\system32\dllcache\cfgwiz.exe
+ 2008-04-14 00:11:51 46,592 ----a-w c:\windows\system32\dllcache\coadmin.dll
+ 2008-04-14 00:11:51 617,472 ----a-w c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 00:11:51 276,992 ----a-w c:\windows\system32\dllcache\comdlg32.dll
+ 2008-04-14 00:11:51 252,928 ----a-w c:\windows\system32\dllcache\compatui.dll
+ 2008-04-14 00:11:51 599,040 ----a-w c:\windows\system32\dllcache\crypt32.dll
+ 2008-04-14 00:11:51 74,752 ----a-w c:\windows\system32\dllcache\cryptdlg.dll
+ 2008-04-14 00:11:51 33,280 ----a-w c:\windows\system32\dllcache\cryptdll.dll
+ 2008-04-14 00:11:51 53,760 ----a-w c:\windows\system32\dllcache\cryptext.dll
+ 2008-04-14 00:11:51 64,512 ----a-w c:\windows\system32\dllcache\cryptnet.dll
+ 2008-04-14 00:11:51 62,464 ----a-w c:\windows\system32\dllcache\cryptsvc.dll
+ 2008-04-14 00:11:51 512,512 ----a-w c:\windows\system32\dllcache\cryptui.dll
+ 2004-08-10 11:00:00 27,136 ----a-w c:\windows\system32\dllcache\ctl3d32.dll
+ 2008-04-14 00:11:52 19,456 ----a-w c:\windows\system32\dllcache\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 ----a-w c:\windows\system32\dllcache\dimsroam.dll
+ 2008-04-14 00:11:52 32,768 ----a-w c:\windows\system32\dllcache\dispex.dll
+ 2004-08-10 11:00:00 246,272 ----a-w c:\windows\system32\dllcache\drmclien.dll
+ 2004-08-10 11:00:00 92,672 ----a-w c:\windows\system32\dllcache\drmstor.dll
+ 2008-04-14 00:11:52 16,384 ----a-w c:\windows\system32\dllcache\ds32gt.dll
+ 2008-04-13 17:37:57 138,752 ----a-w c:\windows\system32\dllcache\dssenh.dll
+ 2008-04-14 00:11:53 380,445 ----a-w c:\windows\system32\dllcache\expsrv.dll
+ 2008-04-13 19:14:29 143,744 ----a-w c:\windows\system32\dllcache\fastfat.sys
+ 2008-04-14 00:11:53 184,435 ----a-w c:\windows\system32\dllcache\fp4amsft.dll
+ 2008-04-14 00:11:53 82,035 ----a-w c:\windows\system32\dllcache\fp4anscp.dll
+ 2008-04-14 00:11:53 147,513 ----a-w c:\windows\system32\dllcache\fp4apws.dll
+ 2008-04-14 00:11:53 49,210 ----a-w c:\windows\system32\dllcache\fp4areg.dll
+ 2008-04-14 00:11:53 102,509 ----a-w c:\windows\system32\dllcache\fp4atxt.dll
+ 2008-04-14 00:11:53 41,020 ----a-w c:\windows\system32\dllcache\fp4avnb.dll
+ 2008-04-14 00:11:53 32,826 ----a-w c:\windows\system32\dllcache\fp4avss.dll
+ 2008-04-14 00:11:53 49,212 ----a-w c:\windows\system32\dllcache\fp4awebs.dll
+ 2008-04-14 00:11:53 876,653 ----a-w c:\windows\system32\dllcache\fp4awel.dll
+ 2008-04-14 00:12:20 15,120 ----a-w c:\windows\system32\dllcache\fp98sadm.exe
+ 2008-04-14 00:12:20 109,840 ----a-w c:\windows\system32\dllcache\fp98swin.exe
+ 2008-04-14 00:12:20 188,494 ----a-w c:\windows\system32\dllcache\fpcount.exe
+ 2008-04-14 00:11:53 20,541 ----a-w c:\windows\system32\dllcache\fpexedll.dll
+ 2008-04-14 00:11:53 598,071 ----a-w c:\windows\system32\dllcache\fpmmc.dll
+ 2007-04-02 16:36:04 208,896 ----a-w c:\windows\system32\dllcache\fpmmcsat.dll
+ 2008-04-14 00:12:20 20,538 ----a-w c:\windows\system32\dllcache\fpremadm.exe
+ 2008-04-14 00:11:54 68,608 ----a-w c:\windows\system32\dllcache\iisext51.dll
+ 2008-04-14 00:11:54 64,512 ----a-w c:\windows\system32\dllcache\iismap.dll
+ 2008-04-14 00:12:22 30,720 ----a-w c:\windows\system32\dllcache\iisrstas.exe
+ 2008-04-14 00:11:54 133,632 ----a-w c:\windows\system32\dllcache\iisrtl.dll
+ 2008-04-14 00:11:54 36,921 ----a-w c:\windows\system32\dllcache\imeshare.dll
+ 2008-04-14 00:11:55 829,440 ----a-w c:\windows\system32\dllcache\inetmgr.dll
+ 2008-04-14 00:11:55 13,312 ----a-w c:\windows\system32\dllcache\infoadmn.dll
+ 2008-04-13 19:19:42 75,264 ----a-w c:\windows\system32\dllcache\ipsec.sys
+ 2008-04-14 00:11:55 68,608 ----a-w c:\windows\system32\dllcache\isatq.dll
+ 2008-04-14 00:11:55 155,136 ----a-w c:\windows\system32\dllcache\itircl.dll
+ 2008-04-14 00:11:55 138,240 ----a-w c:\windows\system32\dllcache\itss.dll
+ 2008-04-14 00:11:56 15,872 ----a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\dllcache\kbdbhc.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\dllcache\kbdiultn.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\dllcache\kbdnepr.dll
+ 2008-04-14 00:09:55 6,144 ----a-w c:\windows\system32\dllcache\kbdpash.dll
+ 2008-04-14 00:11:56 989,696 ----a-w c:\windows\system32\dllcache\kernel32.dll
+ 2006-10-19 02:47:14 11,264 ----a-w c:\windows\system32\dllcache\laprxy.dll
+ 2006-10-19 01:03:58 100,864 ----a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-04-14 00:11:56 728,064 ----a-w c:\windows\system32\dllcache\lsasrv.dll
+ 2004-08-10 11:00:00 924,432 ----a-w c:\windows\system32\dllcache\mfc40.dll
+ 2008-04-14 00:11:56 927,504 ----a-w c:\windows\system32\dllcache\mfc40u.dll
+ 2008-04-14 00:11:56 1,028,096 ----a-w c:\windows\system32\dllcache\mfc42.dll
+ 2008-04-14 00:11:56 22,528 ----a-w c:\windows\system32\dllcache\mfcsubs.dll
+ 2008-04-13 17:25:57 20,480 ----a-w c:\windows\system32\dllcache\msadcer.dll
+ 2008-04-14 00:11:58 61,440 ----a-w c:\windows\system32\dllcache\msadcf.dll
+ 2008-04-13 17:25:57 16,384 ----a-w c:\windows\system32\dllcache\msadcfr.dll
+ 2008-04-14 00:11:58 143,360 ----a-w c:\windows\system32\dllcache\msadco.dll
+ 2008-04-13 17:25:57 16,384 ----a-w c:\windows\system32\dllcache\msadcor.dll
+ 2008-04-14 00:11:58 53,248 ----a-w c:\windows\system32\dllcache\msadcs.dll
+ 2008-04-14 00:11:58 155,648 ----a-w c:\windows\system32\dllcache\msadds.dll
+ 2008-04-13 17:25:58 24,576 ----a-w c:\windows\system32\dllcache\msaddsr.dll
+ 2008-04-13 17:26:17 24,576 ----a-w c:\windows\system32\dllcache\msader15.dll
+ 2008-04-14 00:11:58 536,576 ----a-w c:\windows\system32\dllcache\msado15.dll
+ 2008-04-14 00:11:58 180,224 ----a-w c:\windows\system32\dllcache\msadomd.dll
+ 2008-04-14 00:11:58 57,344 ----a-w c:\windows\system32\dllcache\msador15.dll
+ 2008-04-14 00:11:58 200,704 ----a-w c:\windows\system32\dllcache\msadox.dll
+ 2008-04-14 00:11:58 57,344 ----a-w c:\windows\system32\dllcache\msadrh15.dll
+ 2008-04-14 00:11:58 36,864 ----a-w c:\windows\system32\dllcache\mscpxl32.dll
+ 2008-04-14 00:11:58 4,096 ----a-w c:\windows\system32\dllcache\msdadc.dll
+ 2008-04-14 00:11:58 4,096 ----a-w c:\windows\system32\dllcache\msdaenum.dll
+ 2008-04-14 00:11:58 4,096 ----a-w c:\windows\system32\dllcache\msdaer.dll
+ 2008-04-14 00:11:58 233,472 ----a-w c:\windows\system32\dllcache\msdaora.dll
+ 2008-04-14 00:11:58 77,824 ----a-w c:\windows\system32\dllcache\msdaosp.dll
+ 2008-04-13 17:25:58 16,384 ----a-w c:\windows\system32\dllcache\msdaprsr.dll
+ 2008-04-14 00:11:58 200,704 ----a-w c:\windows\system32\dllcache\msdaprst.dll
+ 2008-04-14 00:11:59 204,800 ----a-w c:\windows\system32\dllcache\msdaps.dll
+ 2008-04-14 00:11:59 118,784 ----a-w c:\windows\system32\dllcache\msdarem.dll
+ 2008-04-13 17:25:58 16,384 ----a-w c:\windows\system32\dllcache\msdaremr.dll
+ 2008-04-14 00:11:59 4,096 ----a-w c:\windows\system32\dllcache\msdasc.dll
+ 2008-04-14 00:11:59 315,392 ----a-w c:\windows\system32\dllcache\msdasql.dll
+ 2008-04-13 17:26:07 16,384 ----a-w c:\windows\system32\dllcache\msdasqlr.dll
+ 2008-04-14 00:11:59 20,480 ----a-w c:\windows\system32\dllcache\msdatt.dll
+ 2008-04-14 00:11:59 4,096 ----a-w c:\windows\system32\dllcache\msdaurl.dll
+ 2008-04-14 00:11:59 36,864 ----a-w c:\windows\system32\dllcache\msdfmap.dll
+ 2008-04-14 00:10:08 4,126 ----a-w c:\windows\system32\dllcache\msdxmlc.dll
+ 2008-04-14 00:12:00 151,583 ----a-w c:\windows\system32\dllcache\msjint40.dll
+ 2008-04-14 00:12:00 102,400 ----a-w c:\windows\system32\dllcache\msjro.dll
+ 2008-04-14 00:12:00 143,360 ----a-w c:\windows\system32\dllcache\msorcl32.dll
+ 2004-08-10 11:00:00 4,608 ----a-w c:\windows\system32\dllcache\mssip32.dll
+ 2008-04-14 00:12:01 343,040 ----a-w c:\windows\system32\dllcache\msvcrt.dll
+ 2008-04-13 18:30:46 61,440 ----a-w c:\windows\system32\dllcache\msvcrt40.dll
+ 2008-04-14 00:12:01 24,576 ----a-w c:\windows\system32\dllcache\msxactps.dll
+ 2008-04-13 19:20:42 91,520 ----a-w c:\windows\system32\dllcache\ndiswan.sys
+ 2008-04-14 00:11:24 706,048 ----a-w c:\windows\system32\dllcache\ntdll.dll
+ 2008-04-13 19:15:53 574,976 ----a-w c:\windows\system32\dllcache\ntfs.sys
+ 2004-08-10 11:00:00 17,408 ----a-w c:\windows\system32\dllcache\nwapi16.dll
+ 2008-04-14 00:12:02 64,000 ----a-w c:\windows\system32\dllcache\nwapi32.dll
+ 2008-04-14 00:12:02 67,584 ----a-w c:\windows\system32\dllcache\ocmanage.dll
+ 2008-04-14 00:12:02 106,496 ----a-w c:\windows\system32\dllcache\odbccp32.dll
+ 2008-04-14 00:12:02 20,511 ----a-w c:\windows\system32\dllcache\odtext32.dll
+ 2004-08-19 19:25:28 13,107,200 ----a-w c:\windows\system32\dllcache\oembios.bin
+ 2004-08-19 19:25:28 4,627 ----a-w c:\windows\system32\dllcache\oembios.dat
+ 2008-04-14 00:12:02 1,287,168 ----a-w c:\windows\system32\dllcache\ole32.dll
+ 2008-04-14 00:12:02 551,936 ----a-w c:\windows\system32\dllcache\oleaut32.dll
+ 2008-04-14 00:12:02 84,992 ----a-w c:\windows\system32\dllcache\olepro32.dll
+ 2008-04-14 00:12:04 433,664 ----a-w c:\windows\system32\dllcache\riched20.dll
+ 2004-08-10 11:00:00 3,584 ----a-w c:\windows\system32\dllcache\riched32.dll
+ 2008-04-13 17:37:57 208,384 ----a-w c:\windows\system32\dllcache\rsaenh.dll
+ 2008-04-14 00:12:04 64,000 ----a-w c:\windows\system32\dllcache\samlib.dll
+ 2008-04-14 00:12:04 415,744 ----a-w c:\windows\system32\dllcache\samsrv.dll
+ 2008-04-14 00:12:05 144,384 ----a-w c:\windows\system32\dllcache\schannel.dll
+ 2008-04-14 00:12:34 77,312 ----a-w c:\windows\system32\dllcache\sdbinst.exe
+ 2004-08-10 11:00:00 4,569 ----a-w c:\windows\system32\dllcache\secupd.dat
+ 2008-04-14 09:42:06 985,088 ----a-w c:\windows\system32\dllcache\setupapi.dll
+ 2008-04-14 00:12:05 5,120 ----a-w c:\windows\system32\dllcache\sfc.dll
+ 2004-08-10 11:00:00 9,728 ----a-w c:\windows\system32\dllcache\sfc.exe
+ 2008-04-14 00:12:05 1,614,848 ----a-w c:\windows\system32\dllcache\sfcfiles.dll
+ 2008-04-14 00:12:05 65,024 ----a-w c:\windows\system32\dllcache\shimeng.dll
+ 2008-04-14 00:12:05 20,536 ----a-w c:\windows\system32\dllcache\shtml.dll
+ 2008-04-14 00:12:35 16,437 ----a-w c:\windows\system32\dllcache\shtml.exe
+ 2008-04-14 00:12:06 25,088 ----a-w c:\windows\system32\dllcache\slayerxp.dll
+ 2008-04-14 00:12:06 189,440 ----a-w c:\windows\system32\dllcache\smtpadm.dll
+ 2008-04-14 00:12:06 2,134,528 ----a-w c:\windows\system32\dllcache\smtpsnap.dll
+ 2008-04-14 00:12:07 8,192 ----a-w c:\windows\system32\dllcache\staxmem.dll
+ 2008-04-14 00:12:37 106,496 ----a-w c:\windows\system32\dllcache\sysocmgr.exe
+ 2008-04-14 00:12:37 32,827 ----a-w c:\windows\system32\dllcache\tcptest.exe
+ 2007-04-02 16:36:07 16,384 ----a-w c:\windows\system32\dllcache\tcptsat.dll
+ 2004-08-10 11:00:00 49,680 ----a-w c:\windows\system32\dllcache\twunk_16.exe
+ 2004-08-10 11:00:00 25,600 ----a-w c:\windows\system32\dllcache\twunk_32.exe
+ 2004-08-10 11:00:00 177,856 ----a-w c:\windows\system32\dllcache\typelib.dll
+ 2008-04-14 00:12:07 123,392 ----a-w c:\windows\system32\dllcache\umpnpmgr.dll
+ 2008-04-14 00:12:08 37,888 ----a-w c:\windows\system32\dllcache\url.dll
+ 2008-04-14 00:12:39 507,904 ----a-w c:\windows\system32\dllcache\winlogon.exe
+ 2008-04-14 00:12:09 176,640 ----a-w c:\windows\system32\dllcache\wintrust.dll
- 2005-11-10 17:27:06 49,248 ----a-w c:\windows\system32\java.exe
+ 2008-11-09 16:27:22 144,792 ----a-w c:\windows\system32\java.exe
- 2005-11-10 17:27:16 49,250 ----a-w c:\windows\system32\javaw.exe
+ 2008-11-09 16:27:22 144,792 ----a-w c:\windows\system32\javaw.exe
- 2005-11-10 19:03:54 127,078 ----a-w c:\windows\system32\javaws.exe
+ 2008-11-09 16:27:22 148,888 ----a-w c:\windows\system32\javaws.exe
- 2008-11-08 02:03:05 62,126 ----a-w c:\windows\system32\perfc009.dat
+ 2008-11-09 15:56:59 69,896 ----a-w c:\windows\system32\perfc009.dat
- 2008-11-08 02:03:05 396,276 ----a-w c:\windows\system32\perfh009.dat
+ 2008-11-09 15:56:59 409,416 ----a-w c:\windows\system32\perfh009.dat
+ 2008-11-11 13:20:08 16,384 ----atw c:\windows\temp\Perflib_Perfdata_6f0.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"OE_OEM"="c:\program files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe" [2006-08-04 398864]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1764864]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-22 1470464]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-03 1105920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 831579]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 126976]
"pccguide.exe"="c:\program files\Trend Micro\Internet Security 14\pccguide.exe" [2006-11-21 1807960]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 294912]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 155648]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-09 214424]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 283888]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-01-23 24576]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2008-01-11 389120]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 249856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.speex32"= speex32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Common Files\\WRAL DESKTOP WEATHER\\TrueWeather.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe"=
"c:\\WINDOWS\\system32\\Ati2evxx.exe"=
"c:\\WINDOWS\\system32\\WLTRAY.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Dell\\QuickSet\\quickset.exe"=
"c:\\Program Files\\Dell Support\\DSAgnt.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe"=
"c:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe"=
"c:\\WINDOWS\\stsystra.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security 14\\TMAS_OE\\TMAS_OEMon.exe"=
"c:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security 14\\pccmain.exe"=
R3 abp470n5;abp470n5;c:\windows\system32\drivers\hhgmrs.sys [ ]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);c:\windows\system32\DRIVERS\w300bus.sys [2006-03-13 60800]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
2008-11-08 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - James.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\James\Application Data\Mozilla\Firefox\Profiles\6isqf98n.default\
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-11 11:33:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-11-11 11:37:31
ComboFix-quarantined-files.txt 2008-11-11 16:36:28
ComboFix2.txt 2008-11-09 14:05:57
ComboFix3.txt 2008-11-09 03:50:23
ComboFix4.txt 2008-11-09 03:17:52
ComboFix5.txt 2008-11-11 16:31:01
Pre-Run: 50,651,627,520 bytes free
Post-Run: 50,582,069,248 bytes free
347 --- E O F --- 2008-10-24 17:55:59
#120
Posted 11 November 2008 - 11:11 AM
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
Driver:: abp470n5 Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\TEMP\\winddcb.exe"=- "c:\\WINDOWS\\TEMP\\hcuxw.exe"=-
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As... Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save ...

Drag CFScript.txt into ComboFix.exe
Then post the results log and a new HijackThis log.
Also please describe how your computer behaves at the moment.
The forum is run by volunteers who donate their time and expertise.
Want to help others? Join the ClassRoom and learn how.
Logs will be closed if you haven't replied within 3 days
If you would like to for the help you received.
Proud graduate of TC/WTT Classroom
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users