This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HJT log. please help

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello WhattheTech.

I was wondering if anyone could give me a hand with this issue I have. A friend of mine asked me to take a look at her laptop due to some problems overall issues. Looking at the computer, I noticed she didn´t had installed any firewall or antispyware (also, antivirus was not updated).
I proceeded to run the following programs in order to fix the issues:

-Avira antivir
-Superanti Spyware
-AdAware
-Malwarebytes

Every programs detected something during the scan and most of the issues were fixed. However, there is still a browser hijack that I can´t get rid of.

The following is the log I got from HJT. I also posted the log from the last program I run (Malwarebytes).

As you may noticed, the laptop is running Service Pack 2. I´m doing the update to 3 at this moment. I appreciate any help on this. Thank you :thumbup:


—-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:12:01 AM, on 5/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\TFNF5.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\WINDOWS\System32\EZSP_PX.EXE
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Usuario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Documents and Settings\Usuario\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Usuario\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.live.com/sphome.aspx
O1 - Hosts: 94.247.2.216 www.google.com
O1 - Hosts: 94.247.2.216 www.google.de
O1 - Hosts: 94.247.2.216 www.google.fr
O1 - Hosts: 94.247.2.216 www.google.co.uk
O1 - Hosts: 94.247.2.216 www.google.com.br
O1 - Hosts: 94.247.2.216 www.google.it
O1 - Hosts: 94.247.2.216 www.google.es
O1 - Hosts: 94.247.2.216 www.google.co.jp
O1 - Hosts: 94.247.2.216 www.google.com.mx
O1 - Hosts: 94.247.2.216 www.google.ca
O1 - Hosts: 94.247.2.216 www.google.com.au
O1 - Hosts: 94.247.2.216 www.google.nl
O1 - Hosts: 94.247.2.216 www.google.co.za
O1 - Hosts: 94.247.2.216 www.google.be
O1 - Hosts: 94.247.2.216 www.google.gr
O1 - Hosts: 94.247.2.216 www.google.at
O1 - Hosts: 94.247.2.216 www.google.se
O1 - Hosts: 94.247.2.216 www.google.ch
O1 - Hosts: 94.247.2.216 www.google.pt
O1 - Hosts: 94.247.2.216 www.google.dk
O1 - Hosts: 94.247.2.216 www.google.fi
O1 - Hosts: 94.247.2.216 www.google.ie
O1 - Hosts: 94.247.2.216 www.google.no
O1 - Hosts: 94.247.2.216 search.yahoo.com
O1 - Hosts: 94.247.2.216 us.search.yahoo.com
O1 - Hosts: 94.247.2.216 uk.search.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\EZSP_PX.EXE
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4100 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEL.EXE /P26 "EPSON Stylus CX4100 Series" /O6 "USB001" /M "Stylus CX4100"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Usuario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1216077222801
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10165 bytes


——

Malwarebytes' Anti-Malware 1.36
Database version: 2015
Windows 5.1.2600 Service Pack 2

5/21/2009 2:19:09 PM
mbam-log-2009-05-21 (14-19-09).txt

Scan type: Full Scan (C:\|)
Objects scanned: 143578
Time elapsed: 55 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\dmns.cfg (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\avp.id (Rogue.AntiVirusPro) -> Quarantined and deleted successfully.
Hi polloloco21, :welcome:

My name is SpySentinel and I will be helping you with your malware problem.



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Thank you for your help on this, Sentinel. Here is the log from Combofix. I will proceed according to your advice.

ComboFix 09-04-21.06 - Usuario 05/21/2009 17:14.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.170 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
FW: ZoneAlarm Security Suite Firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Usuario\LOCALS~1\Temp\install_flash_player.exe
c:\windows\IE4 Error Log.txt

.
((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 )))))))))))))))))))))))))))))))
.

2009-05-21 23:31 . 2009-05-21 23:31 ——– d—–w c:\windows\LastGood.Tmp
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\system32\scripting
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\l2schemas
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\system32\en
2009-05-21 20:19 . 2009-05-21 20:19 ——– d—–w c:\documents and settings\Usuario\Application Data\Malwarebytes
2009-05-21 20:18 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-21 20:18 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-21 20:18 . 2009-05-21 20:18 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-21 10:21 . 2009-05-21 10:21 ——– d—–w c:\documents and settings\Usuario\Local Settings\Application Data\Opera
2009-05-21 10:03 . 2009-05-21 21:38 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-21 09:23 . 2008-04-14 00:12 221184 —-a-w c:\windows\system32\wmpns.dll
2009-05-21 08:12 . 2009-03-09 19:06 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-21 07:52 . 2009-05-21 07:52 ——– d—–w c:\documents and settings\Usuario\Application Data\GlarySoft
2009-05-21 06:59 . 2009-02-13 18:31 55640 —-a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-21 06:58 . 2009-05-21 06:58 ——– d—–w c:\documents and settings\All Users\Application Data\Avira
2009-05-21 06:47 . 2009-05-21 06:47 ——– d—–w c:\documents and settings\Usuario\Application Data\MailFrontier
2009-05-21 06:40 . 2009-05-22 00:18 21745696 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-21 06:40 . 2009-05-21 23:41 243548 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-21 06:30 . 2009-05-21 23:45 4212 —ha-w c:\windows\system32\zllictbl.dat
2009-05-21 06:30 . 2009-04-01 02:20 72584 —-a-w c:\windows\zllsputility.exe
2009-05-21 06:28 . 2009-04-01 02:20 1221512 —-a-w c:\windows\system32\zpeng25.dll
2009-05-21 06:28 . 2009-05-21 20:06 ——– d—–w c:\windows\system32\ZoneLabs
2009-05-21 06:28 . 2009-05-21 23:44 351218 —-a-w c:\windows\system32\vsconfig.xml
2009-05-21 06:21 . 2009-05-22 00:07 ——– d—–w c:\windows\Internet Logs
2009-05-21 05:13 . 2009-05-21 05:13 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-21 05:13 . 2009-05-21 05:13 ——– d—–w c:\documents and settings\Usuario\Application Data\SUPERAntiSpyware.com
2009-05-21 04:57 . 2009-03-09 19:06 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-21 04:51 . 2009-05-21 04:51 ——– dc-h–w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-21 04:51 . 2009-05-21 04:56 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-21 03:08 . 2009-05-21 03:08 197 —-a-w c:\windows\system32\MRT.INI
2009-05-21 03:04 . 2003-03-01 01:26 139536 —-a-w c:\windows\system32\javaee.dll
2009-05-16 19:34 . 2009-05-21 04:24 ——– d—–w c:\documents and settings\Usuario\Tracing
2009-05-16 19:29 . 2009-05-16 19:37 ——– d—–w c:\windows\SxsCaPendDel
2009-05-16 19:04 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-05-16 19:03 . 2009-02-06 10:39 35328 -c—-w c:\windows\system32\dllcache\sc.exe
2009-05-16 19:03 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-05-16 19:03 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-05-16 19:03 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-05-16 19:03 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-05-16 19:03 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-16 19:03 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-05-16 19:03 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-05-16 19:03 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-05-16 19:03 . 2009-02-06 11:06 2145280 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-16 19:03 . 2009-02-06 11:08 2189056 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-16 19:03 . 2009-02-06 10:32 2023936 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-16 19:02 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-05-16 19:02 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-05-16 19:02 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-05-05 15:36 . 2009-05-17 19:31 132152 —-a-w c:\windows\system\cmd

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-22 00:09 . 2009-05-22 00:09 3493 —-a-w C:\Bug.txt
2009-05-21 23:42 . 2009-05-21 09:29 1116 —-a-w C:\aaw7boot.log
2009-05-21 23:29 . 2003-08-12 17:34 77607 —-a-w c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-05-21 23:15 . 2003-08-12 17:09 250048 –sha-r C:\ntldr
2009-05-21 20:18 . 2009-05-21 20:18 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-21 10:24 . 2009-05-21 19:48 1886208 —-a-w c:\windows\Internet Logs\xDB1.tmp
2009-05-21 10:21 . 2009-05-21 10:21 ——– d—–w c:\program files\Opera
2009-05-21 10:11 . 2009-05-21 10:11 ——– d—–w c:\program files\Trend Micro
2009-05-21 06:58 . 2009-05-21 06:58 ——– d—–w c:\program files\Avira
2009-05-21 06:55 . 2008-08-21 21:45 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-21 06:55 . 2003-08-12 22:15 ——– d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-05-21 06:54 . 2008-08-21 21:45 ——– d—–w c:\program files\Symantec
2009-05-21 06:21 . 2009-05-21 06:21 ——– d—–w c:\program files\Zone Labs
2009-05-21 05:23 . 2008-09-16 01:32 ——– d—–w c:\documents and settings\Usuario\Application Data\Skype
2009-05-21 05:13 . 2009-05-21 05:13 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-21 05:12 . 2009-05-21 05:12 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-21 04:51 . 2009-05-21 04:51 ——– d—–w c:\program files\Lavasoft
2009-05-21 04:47 . 2009-05-21 04:47 ——– d—–w c:\program files\Glary Utilities
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\VJHNNBVP.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\NPRH3LZL.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\XNV337PZ.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\17TBZNV1.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\0HFX7313.DAT
2009-05-16 19:33 . 2008-08-21 23:07 65984 —-a-w c:\documents and settings\Usuario\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-16 19:31 . 2008-08-25 23:19 ——– d—–w c:\program files\Windows Live
2009-05-16 19:31 . 2008-08-26 00:40 ——– d—–w c:\program files\Windows Live Toolbar
2009-05-16 19:30 . 2009-05-16 19:30 ——– d—–w c:\program files\Microsoft Sync Framework
2009-05-16 19:25 . 2009-05-16 19:25 ——– d—–w c:\program files\Microsoft
2009-05-16 19:25 . 2009-05-16 19:25 ——– d—–w c:\program files\Windows Live SkyDrive
2009-05-16 19:04 . 2009-05-16 19:04 ——– d—–w c:\program files\Common Files\Windows Live
2009-05-16 18:53 . 2008-09-16 01:32 ——– d—–w c:\documents and settings\Usuario\Application Data\skypePM
2009-03-18 22:59 . 2009-03-18 23:00 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-18 19:31 . 2009-03-18 19:31 65400 —-a-w c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-06 14:22 . 2003-08-12 17:08 284160 —-a-w c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-21 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Usuario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-21 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="c:\windows\System32\00THotkey.exe" [2003-01-17 17:41 253952]
"PmProxy"="c:\program files\Analog Devices\SoundMAX\PmProxy.exe" [2003-03-01 40960]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-12-25 159744]
"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.Exe" [2003-01-22 126976]
"ezShieldProtector for Px"="c:\windows\System32\EZSP_PX.EXE" [2002-08-20 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2002-10-17 159744]
"Ink Monitor"="c:\program files\EPSON\Ink Monitor\InkMonitor.exe" [2004-05-05 262210]
"EPSON Stylus CX4100 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEL.EXE" [2005-03-08 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-04-01 982408]
"000StTHK"="000StTHK.exe" - c:\windows\system32\000StTHK.exe [2001-06-24 03:28 24576]
"TFNF5"="TFNF5.exe" - c:\windows\system32\TFNF5.exe [2001-08-04 73728]
"Tpwrtray"="TPWRTRAY.EXE" - c:\windows\system32\TPWRTRAY.EXE [2002-12-10 237568]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2003-8-12 155648]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 mrtRate;mrtRate; [x]
R3 ALiIRDA;ALi Infrared Device Driver;c:\windows\system32\DRIVERS\aliirda.sys [2001-12-18 26112]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
R3 wlags48b;Wireless LAN PCCard Driver;c:\windows\system32\DRIVERS\wlags48b.sys [2002-06-28 156672]
S0 ALiAGP;ALi AGP Bus Filter Driver;c:\windows\System32\DRIVERS\ALiAGP.sys [2002-09-02 26880]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-09 64160]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-02-17 8944]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-02-17 55024]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-05 108289]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-15 226656]
S3 tridxp;tridxp;c:\windows\system32\DRIVERS\tridxpm.sys [2003-04-24 248448]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51c683a0-b2b1-11dd-8e4f-0090967da7da}]
\Shell\Auto\command - MSOCache\doWTP_RESTORE_0.exe -autorun
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MSOCache\doWTP_RESTORE_0.exe -autorun

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4d66d22-bf4a-11dd-8e5d-0090967da7da}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL protector.exe
\Shell\infected\command - protector.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9248c30-8b42-11dd-8e23-0090967da7da}]
\Shell\AutoRun\command - v.cmd
\Shell\explore\Command - v.cmd
\Shell\open\Command - v.cmd
.
Contents of the 'Scheduled Tasks' folder

2009-05-21 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-05-21 00:10]

2009-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1150335450-1252657108-495523350-1005.job
- c:\documents and settings\Usuario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-21 04:27]

2009-05-21 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-08-21 16:04]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-21 17:18
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ôw*]
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ôw*]
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(632)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-05-22 17:21
ComboFix-quarantined-files.txt 2009-05-22 00:21

Pre-Run: 63,824,953,344 bytes free
Post-Run: 64,301,039,616 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

221 — E O F — 2009-05-21 22:06
Hi polloloco21,

You're welcome.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ôw*]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ôw*]

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51c683a0-b2b1-11dd-8e4f-0090967da7da}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4d66d22-bf4a-11dd-8e5d-0090967da7da}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9248c30-8b42-11dd-8e23-0090967da7da}]


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Hi Sentinel,

Here´s the second log from ComboFix. Please let me know if you need any other information.

Thanks :thumbup:


ComboFix 09-04-21.06 - Usuario 05/21/2009 19:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.216 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Usuario\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
FW: ZoneAlarm Security Suite Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 )))))))))))))))))))))))))))))))
.

2009-05-22 00:47 . 2009-05-22 00:47 ——– d—–w c:\windows\LastGood
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\system32\scripting
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\l2schemas
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\system32\en
2009-05-21 20:19 . 2009-05-21 20:19 ——– d—–w c:\documents and settings\Usuario\Application Data\Malwarebytes
2009-05-21 20:18 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-21 20:18 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-21 20:18 . 2009-05-21 20:18 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-21 10:21 . 2009-05-21 10:21 ——– d—–w c:\documents and settings\Usuario\Local Settings\Application Data\Opera
2009-05-21 10:03 . 2009-05-21 21:38 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-21 09:23 . 2008-04-14 00:12 221184 —-a-w c:\windows\system32\wmpns.dll
2009-05-21 08:12 . 2009-03-09 19:06 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-21 07:52 . 2009-05-21 07:52 ——– d—–w c:\documents and settings\Usuario\Application Data\GlarySoft
2009-05-21 06:59 . 2009-02-13 18:31 55640 —-a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-21 06:58 . 2009-05-21 06:58 ——– d—–w c:\documents and settings\All Users\Application Data\Avira
2009-05-21 06:47 . 2009-05-21 06:47 ——– d—–w c:\documents and settings\Usuario\Application Data\MailFrontier
2009-05-21 06:40 . 2009-05-22 02:25 24305696 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-21 06:40 . 2009-05-22 00:49 272588 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-21 06:30 . 2009-05-21 23:45 4212 —ha-w c:\windows\system32\zllictbl.dat
2009-05-21 06:30 . 2009-04-01 02:20 72584 —-a-w c:\windows\zllsputility.exe
2009-05-21 06:28 . 2009-04-01 02:20 1221512 —-a-w c:\windows\system32\zpeng25.dll
2009-05-21 06:28 . 2009-05-21 20:06 ——– d—–w c:\windows\system32\ZoneLabs
2009-05-21 06:28 . 2009-05-22 02:11 351218 —-a-w c:\windows\system32\vsconfig.xml
2009-05-21 06:21 . 2009-05-22 02:17 ——– d—–w c:\windows\Internet Logs
2009-05-21 05:13 . 2009-05-21 05:13 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-21 05:13 . 2009-05-21 05:13 ——– d—–w c:\documents and settings\Usuario\Application Data\SUPERAntiSpyware.com
2009-05-21 04:57 . 2009-03-09 19:06 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-21 04:51 . 2009-05-21 04:51 ——– dc-h–w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-21 04:51 . 2009-05-21 04:56 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-21 03:08 . 2009-05-21 03:08 197 —-a-w c:\windows\system32\MRT.INI
2009-05-21 03:04 . 2003-03-01 01:26 139536 —-a-w c:\windows\system32\javaee.dll
2009-05-16 19:34 . 2009-05-21 04:24 ——– d—–w c:\documents and settings\Usuario\Tracing
2009-05-16 19:29 . 2009-05-16 19:37 ——– d—–w c:\windows\SxsCaPendDel
2009-05-16 19:04 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-05-16 19:03 . 2009-02-06 10:39 35328 -c—-w c:\windows\system32\dllcache\sc.exe
2009-05-16 19:03 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-05-16 19:03 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-05-16 19:03 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-05-16 19:03 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-05-16 19:03 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-16 19:03 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-05-16 19:03 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-05-16 19:03 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-05-16 19:03 . 2009-02-06 11:06 2145280 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-16 19:03 . 2009-02-06 11:08 2189056 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-16 19:03 . 2009-02-06 10:32 2023936 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-16 19:02 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-05-16 19:02 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-05-16 19:02 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-05-05 15:36 . 2009-05-17 19:31 132152 —-a-w c:\windows\system\cmd

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-22 02:09 . 2009-05-21 09:29 1340 —-a-w C:\aaw7boot.log
2009-05-21 23:29 . 2003-08-12 17:34 77607 —-a-w c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-05-21 23:15 . 2003-08-12 17:09 250048 –sha-r C:\ntldr
2009-05-21 20:18 . 2009-05-21 20:18 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-21 10:24 . 2009-05-21 19:48 1886208 —-a-w c:\windows\Internet Logs\xDB1.tmp
2009-05-21 10:21 . 2009-05-21 10:21 ——– d—–w c:\program files\Opera
2009-05-21 10:11 . 2009-05-21 10:11 ——– d—–w c:\program files\Trend Micro
2009-05-21 06:58 . 2009-05-21 06:58 ——– d—–w c:\program files\Avira
2009-05-21 06:55 . 2008-08-21 21:45 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-21 06:55 . 2003-08-12 22:15 ——– d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-05-21 06:54 . 2008-08-21 21:45 ——– d—–w c:\program files\Symantec
2009-05-21 06:21 . 2009-05-21 06:21 ——– d—–w c:\program files\Zone Labs
2009-05-21 05:23 . 2008-09-16 01:32 ——– d—–w c:\documents and settings\Usuario\Application Data\Skype
2009-05-21 05:13 . 2009-05-21 05:13 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-21 05:12 . 2009-05-21 05:12 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-21 04:51 . 2009-05-21 04:51 ——– d—–w c:\program files\Lavasoft
2009-05-21 04:47 . 2009-05-21 04:47 ——– d—–w c:\program files\Glary Utilities
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\VJHNNBVP.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\NPRH3LZL.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\XNV337PZ.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\17TBZNV1.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\0HFX7313.DAT
2009-05-16 19:33 . 2008-08-21 23:07 65984 —-a-w c:\documents and settings\Usuario\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-16 19:31 . 2008-08-25 23:19 ——– d—–w c:\program files\Windows Live
2009-05-16 19:31 . 2008-08-26 00:40 ——– d—–w c:\program files\Windows Live Toolbar
2009-05-16 19:30 . 2009-05-16 19:30 ——– d—–w c:\program files\Microsoft Sync Framework
2009-05-16 19:25 . 2009-05-16 19:25 ——– d—–w c:\program files\Microsoft
2009-05-16 19:25 . 2009-05-16 19:25 ——– d—–w c:\program files\Windows Live SkyDrive
2009-05-16 19:04 . 2009-05-16 19:04 ——– d—–w c:\program files\Common Files\Windows Live
2009-05-16 18:53 . 2008-09-16 01:32 ——– d—–w c:\documents and settings\Usuario\Application Data\skypePM
2009-03-18 22:59 . 2009-03-18 23:00 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-18 19:31 . 2009-03-18 19:31 65400 —-a-w c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-06 14:22 . 2003-08-12 17:08 284160 —-a-w c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-22_00.18.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-22 02:10 . 2009-05-22 02:10 16384 c:\windows\Temp\Perflib_Perfdata_7c4.dat
+ 2003-08-12 20:49 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
- 2003-08-12 20:49 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
+ 2009-05-21 23:52 . 2008-04-15 17:47 1724416 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-21 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Usuario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-21 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="c:\windows\System32\00THotkey.exe" [2003-01-17 17:41 253952]
"PmProxy"="c:\program files\Analog Devices\SoundMAX\PmProxy.exe" [2003-03-01 40960]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-12-25 159744]
"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.Exe" [2003-01-22 126976]
"ezShieldProtector for Px"="c:\windows\System32\EZSP_PX.EXE" [2002-08-20 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2002-10-17 159744]
"Ink Monitor"="c:\program files\EPSON\Ink Monitor\InkMonitor.exe" [2004-05-05 262210]
"EPSON Stylus CX4100 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEL.EXE" [2005-03-08 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-04-01 982408]
"000StTHK"="000StTHK.exe" - c:\windows\system32\000StTHK.exe [2001-06-24 03:28 24576]
"TFNF5"="TFNF5.exe" - c:\windows\system32\TFNF5.exe [2001-08-04 73728]
"Tpwrtray"="TPWRTRAY.EXE" - c:\windows\system32\TPWRTRAY.EXE [2002-12-10 237568]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2003-8-12 155648]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R2 mrtRate;mrtRate; [x]
R3 ALiIRDA;ALi Infrared Device Driver;c:\windows\system32\DRIVERS\aliirda.sys [2001-12-18 26112]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
R3 wlags48b;Wireless LAN PCCard Driver;c:\windows\system32\DRIVERS\wlags48b.sys [2002-06-28 156672]
S0 ALiAGP;ALi AGP Bus Filter Driver;c:\windows\System32\DRIVERS\ALiAGP.sys [2002-09-02 26880]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-09 64160]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-02-17 8944]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-02-17 55024]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-05 108289]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-15 226656]
S3 tridxp;tridxp;c:\windows\system32\DRIVERS\tridxpm.sys [2003-04-24 248448]

.
Contents of the 'Scheduled Tasks' folder

2009-05-22 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-05-21 00:10]

2009-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1150335450-1252657108-495523350-1005.job
- c:\documents and settings\Usuario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-21 04:27]

2009-05-22 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-08-21 16:04]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xportar; a Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-21 19:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ôw*]
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ôw*]
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(624)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Completion time: 2009-05-22 19:27
ComboFix-quarantined-files.txt 2009-05-22 02:27
ComboFix2.txt 2009-05-22 00:21

Pre-Run: 64,252,694,528 bytes free
Post-Run: 64,238,493,696 bytes free

207 — E O F — 2009-05-22 00:48
Hi polloloco21, sorry for the delay.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

RegNull::
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ôw*]
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ôw*]

Driver::
mrtRate


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Hi Sentinel,

Hope you are doing fine. Don´t worry about the delay.

Here´s the new Combofix log.



ComboFix 09-04-23.02 - Usuario 05/23/2009 14:40.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.479.192 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Usuario\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
FW: ZoneAlarm Security Suite Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_mrtRate


((((((((((((((((((((((((( Files Created from 2009-04-23 to 2009-05-23 )))))))))))))))))))))))))))))))
.

2009-05-22 19:07 . 2009-05-22 19:07 52356 —ha-w c:\windows\system32\mlfcache.dat
2009-05-22 19:04 . 2009-05-22 19:04 ——– d—–w c:\documents and settings\Usuario\Application Data\Apple Computer
2009-05-22 19:04 . 2009-05-22 19:04 ——– d—–w c:\documents and settings\Usuario\Local Settings\Application Data\Apple Computer
2009-05-22 19:03 . 2009-05-22 19:03 ——– d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-22 19:02 . 2009-05-22 19:02 ——– d—–w c:\documents and settings\Usuario\Local Settings\Application Data\Apple
2009-05-22 19:02 . 2009-05-22 19:02 ——– d—–w c:\documents and settings\All Users\Application Data\Apple
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\system32\scripting
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\l2schemas
2009-05-21 23:24 . 2009-05-21 23:24 ——– d—–w c:\windows\system32\en
2009-05-21 20:19 . 2009-05-21 20:19 ——– d—–w c:\documents and settings\Usuario\Application Data\Malwarebytes
2009-05-21 20:18 . 2009-05-21 20:18 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-21 10:21 . 2009-05-21 10:21 ——– d—–w c:\documents and settings\Usuario\Local Settings\Application Data\Opera
2009-05-21 10:03 . 2009-05-21 21:38 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-21 09:23 . 2008-04-14 00:12 221184 —-a-w c:\windows\system32\wmpns.dll
2009-05-21 08:12 . 2009-03-09 19:06 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-21 07:52 . 2009-05-21 07:52 ——– d—–w c:\documents and settings\Usuario\Application Data\GlarySoft
2009-05-21 06:59 . 2009-02-13 18:31 55640 —-a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-21 06:58 . 2009-05-21 06:58 ——– d—–w c:\documents and settings\All Users\Application Data\Avira
2009-05-21 06:47 . 2009-05-21 06:47 ——– d—–w c:\documents and settings\Usuario\Application Data\MailFrontier
2009-05-21 06:40 . 2009-05-23 21:49 29984800 –sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-21 06:40 . 2009-05-23 21:45 351500 –sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-21 06:30 . 2009-05-21 23:45 4212 —ha-w c:\windows\system32\zllictbl.dat
2009-05-21 06:30 . 2009-04-01 02:20 72584 —-a-w c:\windows\zllsputility.exe
2009-05-21 06:28 . 2009-04-01 02:20 1221512 —-a-w c:\windows\system32\zpeng25.dll
2009-05-21 06:28 . 2009-05-22 18:39 ——– d—–w c:\windows\system32\ZoneLabs
2009-05-21 06:28 . 2009-05-23 21:46 351218 —-a-w c:\windows\system32\vsconfig.xml
2009-05-21 06:21 . 2009-05-23 21:36 ——– d—–w c:\windows\Internet Logs
2009-05-21 05:13 . 2009-05-21 05:13 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-21 05:13 . 2009-05-22 18:40 ——– d—–w c:\documents and settings\Usuario\Application Data\SUPERAntiSpyware.com
2009-05-21 04:57 . 2009-03-09 19:06 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-21 04:51 . 2009-05-21 04:51 ——– dc-h–w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-21 04:51 . 2009-05-21 04:56 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-21 03:08 . 2009-05-21 03:08 197 —-a-w c:\windows\system32\MRT.INI
2009-05-21 03:04 . 2003-03-01 01:26 139536 —-a-w c:\windows\system32\javaee.dll
2009-05-16 19:34 . 2009-05-21 04:24 ——– d—–w c:\documents and settings\Usuario\Tracing
2009-05-16 19:29 . 2009-05-16 19:37 ——– d—–w c:\windows\SxsCaPendDel
2009-05-16 19:04 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-05-16 19:03 . 2009-02-06 10:39 35328 -c—-w c:\windows\system32\dllcache\sc.exe
2009-05-16 19:03 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-05-16 19:03 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-05-16 19:03 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-05-16 19:03 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-05-16 19:03 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-16 19:03 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-05-16 19:03 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-05-16 19:03 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-05-16 19:03 . 2009-02-06 11:06 2145280 -c—-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-05-16 19:03 . 2009-02-06 11:08 2189056 -c—-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-05-16 19:03 . 2009-02-06 10:32 2023936 -c—-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-05-16 19:02 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-05-16 19:02 . 2009-03-27 06:58 1203922 -c—-w c:\windows\system32\dllcache\sysmain.sdb
2009-05-16 19:02 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-05-05 15:36 . 2009-05-17 19:31 132152 —-a-w c:\windows\system\cmd

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-23 21:45 . 2009-05-21 09:29 2236 —-a-w C:\aaw7boot.log
2009-05-22 19:03 . 2009-05-22 19:03 ——– d—–w c:\program files\Safari
2009-05-22 19:02 . 2009-05-22 19:02 ——– d—–w c:\program files\Bonjour
2009-05-22 19:02 . 2009-05-22 19:02 ——– d—–w c:\program files\Apple Software Update
2009-05-22 18:42 . 2009-05-21 10:21 ——– d—–w c:\program files\Opera
2009-05-22 18:40 . 2009-05-21 05:13 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-21 23:29 . 2003-08-12 17:34 77607 —-a-w c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-05-21 23:15 . 2003-08-12 17:09 250048 –sha-r C:\ntldr
2009-05-21 10:24 . 2009-05-21 19:48 1886208 —-a-w c:\windows\Internet Logs\xDB1.tmp
2009-05-21 10:11 . 2009-05-21 10:11 ——– d—–w c:\program files\Trend Micro
2009-05-21 06:58 . 2009-05-21 06:58 ——– d—–w c:\program files\Avira
2009-05-21 06:55 . 2008-08-21 21:45 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-21 06:55 . 2003-08-12 22:15 ——– d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-05-21 06:54 . 2008-08-21 21:45 ——– d—–w c:\program files\Symantec
2009-05-21 06:21 . 2009-05-21 06:21 ——– d—–w c:\program files\Zone Labs
2009-05-21 05:23 . 2008-09-16 01:32 ——– d—–w c:\documents and settings\Usuario\Application Data\Skype
2009-05-21 04:51 . 2009-05-21 04:51 ——– d—–w c:\program files\Lavasoft
2009-05-21 04:47 . 2009-05-21 04:47 ——– d—–w c:\program files\Glary Utilities
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\VJHNNBVP.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\NPRH3LZL.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\XNV337PZ.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\17TBZNV1.DAT
2009-05-21 03:04 . 2009-05-21 03:04 2678 —-a-w c:\windows\java\Packages\Data\0HFX7313.DAT
2009-05-16 19:33 . 2008-08-21 23:07 65984 —-a-w c:\documents and settings\Usuario\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-16 19:31 . 2008-08-25 23:19 ——– d—–w c:\program files\Windows Live
2009-05-16 19:31 . 2008-08-26 00:40 ——– d—–w c:\program files\Windows Live Toolbar
2009-05-16 19:30 . 2009-05-16 19:30 ——– d—–w c:\program files\Microsoft Sync Framework
2009-05-16 19:25 . 2009-05-16 19:25 ——– d—–w c:\program files\Microsoft
2009-05-16 19:25 . 2009-05-16 19:25 ——– d—–w c:\program files\Windows Live SkyDrive
2009-05-16 19:04 . 2009-05-16 19:04 ——– d—–w c:\program files\Common Files\Windows Live
2009-05-16 18:53 . 2008-09-16 01:32 ——– d—–w c:\documents and settings\Usuario\Application Data\skypePM
2009-03-18 22:59 . 2009-03-18 23:00 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-18 19:31 . 2009-03-18 19:31 65400 —-a-w c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-06 14:22 . 2003-08-12 17:08 284160 —-a-w c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-22_00.18.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-23 21:46 . 2009-05-23 21:46 16384 c:\windows\Temp\Perflib_Perfdata_784.dat
+ 2003-08-12 17:08 . 2008-05-09 10:53 90112 c:\windows\system32\wshext.dll
- 2003-08-12 17:08 . 2008-04-14 00:12 90112 c:\windows\system32\wshext.dll
+ 2003-08-12 20:49 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
- 2003-08-12 20:49 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
+ 2008-12-12 18:11 . 2008-12-12 18:11 61440 c:\windows\system32\dnssd.dll
+ 2008-12-12 18:18 . 2008-12-12 18:18 87336 c:\windows\system32\dns-sd.exe
+ 2008-05-09 10:53 . 2008-05-09 10:53 90112 c:\windows\system32\dllcache\wshext.dll
+ 2009-05-22 19:02 . 2009-05-22 19:02 27136 c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2009-05-22 19:03 . 2009-05-22 19:03 86016 c:\windows\Installer\{07287123-B8AC-41CE-8346-3D777245C35B}\PrntWzrdIco.exe
- 2003-08-12 17:08 . 2008-04-14 00:12 155648 c:\windows\system32\wscript.exe
+ 2003-08-12 17:08 . 2008-05-08 11:24 155648 c:\windows\system32\wscript.exe
+ 2003-08-12 17:08 . 2008-05-09 10:53 430080 c:\windows\system32\vbscript.dll
- 2003-08-12 17:08 . 2008-04-14 00:12 172032 c:\windows\system32\scrrun.dll
+ 2003-08-12 17:08 . 2008-05-09 10:53 172032 c:\windows\system32\scrrun.dll
+ 2003-08-12 17:08 . 2008-05-09 10:53 180224 c:\windows\system32\scrobj.dll
- 2003-08-12 17:08 . 2008-04-14 00:12 180224 c:\windows\system32\scrobj.dll
- 2003-08-12 21:55 . 2008-04-14 00:12 103936 c:\windows\system32\logagent.exe
+ 2003-08-12 21:55 . 2008-06-10 10:11 103936 c:\windows\system32\logagent.exe
+ 2003-01-13 21:57 . 2008-05-09 10:53 512000 c:\windows\system32\jscript.dll
- 2003-01-13 21:57 . 2008-04-14 00:11 512000 c:\windows\system32\jscript.dll
+ 2008-05-08 11:24 . 2008-05-08 11:24 155648 c:\windows\system32\dllcache\wscript.exe
+ 2008-05-09 10:53 . 2008-05-09 10:53 430080 c:\windows\system32\dllcache\vbscript.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
+ 2008-06-10 09:31 . 2008-06-10 10:11 103936 c:\windows\system32\dllcache\logagent.exe
- 2008-06-10 09:31 . 2008-04-14 00:12 103936 c:\windows\system32\dllcache\logagent.exe
+ 2008-05-09 10:53 . 2008-05-09 10:53 512000 c:\windows\system32\dllcache\jscript.dll
+ 2008-05-07 09:07 . 2008-05-07 09:07 135168 c:\windows\system32\dllcache\cscript.exe
+ 2003-08-12 17:07 . 2008-05-07 09:07 135168 c:\windows\system32\cscript.exe
+ 2009-05-22 19:03 . 2009-05-22 19:04 307200 c:\windows\Installer\{AF10D7E4-D29A-45DA-8050-B116097B69B5}\SafariIco.exe
+ 2009-05-21 23:52 . 2008-04-15 17:47 1724416 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
+ 2003-08-12 21:55 . 2008-11-07 23:45 2174976 c:\windows\system32\WMVCore.dll
+ 2003-08-12 21:55 . 2008-06-10 13:11 1053696 c:\windows\system32\WMNetmgr.dll
+ 2008-09-21 19:56 . 2008-09-10 01:14 1307648 c:\windows\system32\msxml6.dll
+ 2008-11-08 02:32 . 2008-11-07 23:45 2174976 c:\windows\system32\dllcache\WMVCore.dll
+ 2008-06-11 02:18 . 2008-06-10 13:11 1053696 c:\windows\system32\dllcache\WMNetmgr.dll
+ 2008-09-21 19:56 . 2008-09-10 01:14 1307648 c:\windows\system32\dllcache\msxml6.dll
+ 2009-05-21 07:22 . 2009-05-22 18:39 11829940 c:\windows\system32\ZoneLabs\spyware.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-21 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Usuario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-21 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="c:\windows\System32\00THotkey.exe" [2003-01-17 17:41 253952]
"PmProxy"="c:\program files\Analog Devices\SoundMAX\PmProxy.exe" [2003-03-01 40960]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-12-25 159744]
"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.Exe" [2003-01-22 126976]
"ezShieldProtector for Px"="c:\windows\System32\EZSP_PX.EXE" [2002-08-20 40960]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2002-10-17 159744]
"Ink Monitor"="c:\program files\EPSON\Ink Monitor\InkMonitor.exe" [2004-05-05 262210]
"EPSON Stylus CX4100 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEL.EXE" [2005-03-08 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-04-01 982408]
"000StTHK"="000StTHK.exe" - c:\windows\system32\000StTHK.exe [2001-06-24 03:28 24576]
"TFNF5"="TFNF5.exe" - c:\windows\system32\TFNF5.exe [2001-08-04 73728]
"Tpwrtray"="TPWRTRAY.EXE" - c:\windows\system32\TPWRTRAY.EXE [2002-12-10 237568]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2003-8-12 155648]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

R3 ALiIRDA;ALi Infrared Device Driver;c:\windows\system32\DRIVERS\aliirda.sys [2001-12-18 26112]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
R3 wlags48b;Wireless LAN PCCard Driver;c:\windows\system32\DRIVERS\wlags48b.sys [2002-06-28 156672]
S0 ALiAGP;ALi AGP Bus Filter Driver;c:\windows\System32\DRIVERS\ALiAGP.sys [2002-09-02 26880]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-09 64160]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-05 108289]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-15 226656]
S3 tridxp;tridxp;c:\windows\system32\DRIVERS\tridxpm.sys [2003-04-24 248448]

.
Contents of the 'Scheduled Tasks' folder

2009-05-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-05-23 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-05-21 00:10]

2009-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1150335450-1252657108-495523350-1005.job
- c:\documents and settings\Usuario\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-21 04:27]

2009-05-23 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2008-08-21 16:04]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-23 14:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ôw*]
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|þ»Ôw*]
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\DVDRAMSV.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Apoint2K\ApntEx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-23 14:52 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-23 21:52
ComboFix2.txt 2009-05-22 02:27
ComboFix3.txt 2009-05-22 00:21

Pre-Run: 63,902,052,352 bytes free
Post-Run: 63,841,140,736 bytes free

260 — E O F — 2009-05-22 19:10
Sentinel, I was doing some testing with all the browsers and I think you did the trick (no hijack). I believe the problem is resolved. However, if you think there something else to be done, I will proceed accoding. Thank you for expertise help on this. :notworthy:
Hi polloloco21, glad to here the browser hijack si gone.


You're welcome. :thumbup:

mrtRate was the cause of your browser hijack.

Lets do a few scans to make sure nothing is hiding.


Launch Malwarebytes' Anti-Malware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Sentinel, Here is the log from Malwarebytes (clean). I will be posting the Kaspersky log once it's ready. Do you think it's required to uninstall ComboFix in order to complete the cleaning process? Thank you Malwarebytes' Anti-Malware 1.36 Database version: 2029 Windows 5.1.2600 Service Pack 3 5/23/2009 5:49:12 PM mbam-log-2009-05-23 (17-49-12).txt Scan type: Quick Scan Objects scanned: 77121 Time elapsed: 6 minute(s), 24 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello Sentinel, I just wanted to let you know I was not able to complete the Kaspersky scan. My friend (owner of the computer) came to my house and took the laptop back. Before that, I unistalled ComboFix (hope that was the right thing to do) and set up the basic security programs. Thanks again for your concern on the issue and for showing us how to proceed on this :thumbup: . You may close the thread if you want to. Thank you WhattheTech!
Thanks for letting me know polloloco21,

Before that, I unistalled ComboFix (hope that was the right thing to do) and set up the basic security programs.


Yes that was the right thing to do, well done :thumbup:


Thanks again for your concern on the issue and for showing us how to proceed on this


You're welcome, glad I was able to help. If you ever need this topic reopened, feel free to send me a PM, and if you need help in the future, you know where to find me ;)


Take care,
SpySentinel
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI