I'm back. I'v uninstalled and installed the Google Toolbar, this one has the'wrench'. What are
appropriate setting adjustments?
I've disabled the Spybot resident protection and am sure it is unchecked. (will I need to undo these changes when we are done?)
The whole Combofix log is included. There is
no Ohter Deletionsportion I did run it twice, I forget why.
I've uninstalled all the Java and updates you directed.
The next step stumps me. What text am I to copy and past in the window under 'custom scans/fixes'?
The whole combofix log that is missing the 'Other Deletions" follows.
ComboFix 09-03-25.04 - Owner 2009-03-26 15:31:36.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.200 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((( Files Created from 2009-02-26 to 2009-03-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-21 18:24 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-21 18:24 ——— d—–w c:\program files\SpywareBlaster
2009-03-14 13:07 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-02-25 15:25 ——— d—–w c:\program files\SUPERAntiSpyware
2009-02-24 16:04 ——— d—–w c:\documents and settings\Owner\Application Data\HPAppData
2009-02-22 00:23 ——— d—–w c:\program files\Iomega
2009-02-21 20:04 ——— d—–w c:\program files\Avira
2009-02-21 20:04 ——— d—–w c:\documents and settings\All Users\Application Data\Avira
2009-02-21 14:48 ——— d—–w c:\program files\Lavasoft
2009-02-21 14:48 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-02-21 14:10 ——— d—–w c:\program files\Eusing Free Registry Cleaner
2009-02-20 21:04 ——— d—–w c:\program files\MSECache
2009-02-19 14:41 ——— d—–w c:\program files\Java
2009-02-14 14:04 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-13 21:22 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-13 21:19 ——— d—–w c:\documents and settings\Owner\Application Data\Image Zone Express
2009-02-13 15:09 ——— d—–w c:\program files\HP
2009-02-13 15:08 ——— d—–w c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-02-11 22:14 ——— d—–w c:\documents and settings\Owner\Application Data\HP
2009-02-11 22:06 ——— d—–w c:\program files\Hewlett-Packard
2009-02-11 22:06 ——— d—–w c:\program files\Common Files\HP
2009-02-11 22:06 ——— d—–w c:\documents and settings\All Users\Application Data\HP
2009-02-11 15:19 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 15:19 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2009-01-17 18:29 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-01-06 14:21 28,672 —-a-w c:\windows\PCHealth\HelpCtr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHNARS4EN\plugin\bin\InetWrap.dll
2004-09-20 17:15 0 -csha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-02-25 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-01-16 229376]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"Iomega Startup Options"="c:\program files\Iomega\Common\ImgStart.exe" [2000-06-02 32768]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2000-06-13 36864]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-06-29 286720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-14 185896]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-16 28672]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-17 148888]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 c:\windows\AGRSMMSG.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
HP Image Zone Fast Start.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]
PopSubtract.lnk - c:\program files\InterMute\PopSubtract\PopSub.exe [2004-08-24 233472]
Wireless Client Manager.lnk - c:\program files\Wireless\Client Manager\CMAGS.EXE [2004-09-04 339968]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Conference\\Conference.dll"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqcopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-01-05 28544]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-12-22 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-12-22 55024]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-22 7408]
R3 wlags51b;Wireless LAN USB Driver;c:\windows\system32\drivers\wlags51b.sys [2004-09-04 177664]
S2 mrtRate;mrtRate; [x]
S2 TBQIZVJN;TBQIZVJN;\??\c:\windows\system32\tbqizvjn.ocn –> c:\windows\system32\tbqizvjn.ocn [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2009-03-26 c:\windows\Tasks\At1.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At10.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At11.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At11.job
- =:\ []
2009-03-26 c:\windows\Tasks\At12.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At13.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At14.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At15.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-25 c:\windows\Tasks\At16.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-25 c:\windows\Tasks\At17.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-25 c:\windows\Tasks\At18.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-25 c:\windows\Tasks\At19.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At2.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At20.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At21.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At22.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At23.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At24.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At25.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At26.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At27.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At28.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At29.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At3.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At30.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At31.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At32.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At33.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At34.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At35.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At36.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At37.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At38.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At39.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At4.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-25 c:\windows\Tasks\At40.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-25 c:\windows\Tasks\At41.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-25 c:\windows\Tasks\At42.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-25 c:\windows\Tasks\At43.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At44.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At45.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At46.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At47.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At48.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At5.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At6.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At7.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At8.job
- c:\windows\system32\4LU7K1qI.exe []
2009-03-26 c:\windows\Tasks\At9.job
- c:\windows\system32\4LU7K1qI.exe []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.rr.com/flash/index.cfm
uInternet Connection Wizard,ShellNext = hxxp://activation.rr.com/
uInternet Settings,ProxyOverride = localhost
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-26 15:33:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TBQIZVJN]
"ImagePath"="\??\c:\windows\system32\tbqizvjn.ocn"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-174384309-967217451-886241972-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(556)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-03-26 15:36:52
ComboFix-quarantined-files.txt 2009-03-26 20:36:36
ComboFix2.txt 2009-03-26 20:06:28
Pre-Run: 55,856,869,376 bytes free
Post-Run: 55,845,654,528 bytes free
254 — E O F — 2009-03-21 08:04:39
Thanx,
keltics