This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] New hardrive working overtime with no running processe

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a dell 4550,OS XP Home - about 3mo ago we put a new hardrive in it. this really didnt help its issues ie: IEnot responding and spyware/infections, and extremely long starups. My daughters boyfriend installed the Hard drive in F: and the original hard drive is still in there as C: This may be some of the continuing issues i still have? and or i do believe that i still have major spyware/infections. anyway lately the new hard drive which is my primary drive sounds like its always working and i am afraid this one might fry on me too! Help!?



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:21:17 PM, on 6/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
F:\Program Files\McAfee\MPF\MPFSrv.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\WINDOWS\system32\tcpsvcs.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\MsPMSPSv.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
f:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\lxcfcoms.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-583907252-152049171-1417001333-1004\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe (User 'admin')
O15 - Trusted Zone: http://*.mcafee.com
O20 - Winlogon Notify: swapdm - swapdm.dll (file missing)
O23 - Service: lxcf_device - - F:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - F:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe

–
End of file - 3307 bytes

hello-I posted a new topic over the weekend, and became familiar with this forum . then i logged on today and saw the notice to people about keeping your pc maintenanced. great advice for any pc user and im sure by posting that advice, it eases your load a little!? anyways i just want to commend you people for doing such a great job for so many people who need assistance in any issues they may have. Really this website is cool. thanx soooo much. I followed the instructions on the maintenance page. and then ran another Hijackthis.log below. again thanx. and please let me know if i am good to go!




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:50:59 PM, on 6/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
F:\Program Files\McAfee\MPF\MPFSrv.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\WINDOWS\system32\tcpsvcs.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\MsPMSPSv.exe
f:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\WINDOWS\system32\WgaTray.exe
F:\WINDOWS\Explorer.EXE
F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
F:\WINDOWS\system32\ctfmon.exe
F:\WINDOWS\system32\taskmgr.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [LXCFCATS] rundll32 F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1244415498734
O20 - Winlogon Notify: swapdm - swapdm.dll (file missing)
O23 - Service: lxcf_device - - F:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - F:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe

–
End of file - 3269 bytes
Hi,

NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.



Please do the following:

STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.


Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 9:18:52.98 on Sat 06/13/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.24 [GMT -7:00] AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== F:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe F:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe F:\WINDOWS\system32\spoolsv.exe svchost.exe F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe F:\Program Files\McAfee\MPF\MPFSrv.exe F:\WINDOWS\system32\nvsvc32.exe F:\WINDOWS\system32\tcpsvcs.exe F:\WINDOWS\system32\svchost.exe -k imgsvc F:\WINDOWS\system32\MsPMSPSv.exe F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe f:\PROGRA~1\mcafee.com\agent\mcagent.exe F:\WINDOWS\system32\WgaTray.exe F:\WINDOWS\Explorer.EXE F:\WINDOWS\system32\wuauclt.exe F:\WINDOWS\system32\ctfmon.exe F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe F:\Program Files\Internet Explorer\iexplore.exe F:\Program Files\Internet Explorer\iexplore.exe F:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe F:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe F:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe F:\Documents and Settings\Lotta1\Desktop\dds.pif ============== Pseudo HJT Report =============== uSearch Bar = hxxp://www.google.com/ie uStart Page = hxxp://comcast.net/ mWinlogon: Userinit=userinit.exe uRun: [ctfmon.exe] f:\windows\system32\ctfmon.exe mRun: [LXCFCATS] rundll32 f:\windows\system32\spool\drivers\w32x86\3\LXCFtime.dll,_RunDLLEntry@16 uPolicies-explorer: ForceClassicControlPanel = 1 (0x1) mPolicies-explorer: = IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - f:\program files\pokerstars.net\PokerStarsUpdate.exe Trusted Zone: internet Trusted Zone: mcafee.com Trusted Zone: whatthetech.com\forums DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1244415498734 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: swapdm - swapdm.dll ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;f:\windows\system32\drivers\mfehidk.sys [2009-1-8 201320] R2 Iprip;RIP Listener;f:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336] R2 McProxy;McAfee Proxy Service;f:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-1-8 359248] R2 McShield;McAfee Real-time Scanner;f:\progra~1\mcafee\viruss~1\mcshield.exe [2009-1-8 144704] R3 McSysmon;McAfee SystemGuards;f:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-1-8 695624] R3 mfeavfk;McAfee Inc. mfeavfk;f:\windows\system32\drivers\mfeavfk.sys [2009-1-8 79304] R3 mfebopk;McAfee Inc. mfebopk;f:\windows\system32\drivers\mfebopk.sys [2009-1-8 35240] R3 mferkdk;McAfee Inc. mferkdk;f:\windows\system32\drivers\mferkdk.sys [2009-1-8 33832] R3 mfesmfk;McAfee Inc. mfesmfk;f:\windows\system32\drivers\mfesmfk.sys [2009-1-8 40488] S1 swapm;DRAM Cash Driver;f:\windows\system32\swapm.sys [2008-11-20 0] =============== Created Last 30 ================ 2009-06-11 11:01 –d—– f:\windows\ie8updates 2009-06-10 21:22 –d—– F:\Backup 2009-06-10 12:38 246,272 -c—— f:\windows\system32\dllcache\ieproxy.dll 2009-06-10 12:38 12,800 -c—— f:\windows\system32\dllcache\xpshims.dll 2009-06-10 12:38 1,985,024 -c—— f:\windows\system32\dllcache\iertutil.dll 2009-06-10 12:37 11,064,832 -c—— f:\windows\system32\dllcache\ieframe.dll 2009-06-09 01:42 –d—– f:\program files\PokerStars.NET 2009-06-08 11:00 –d—– f:\program files\MSXML 4.0 2009-06-07 16:10 –d—– f:\windows\system32\CatRoot_bak 2009-06-07 16:07 2,015,744 -c—— f:\windows\system32\dllcache\ntkrpamp.exe 2009-06-07 16:07 2,057,728 -c—— f:\windows\system32\dllcache\ntkrnlpa.exe 2009-06-07 16:04 272,128 ——– f:\windows\system32\drivers\bthport.sys 2009-06-07 16:01 268,648 a——- f:\windows\system32\mucltui.dll 2009-06-07 16:01 208,744 a——- f:\windows\system32\muweb.dll 2009-06-07 16:01 27,496 a——- f:\windows\system32\mucltui.dll.mui 2009-06-02 00:10 –d—– f:\program files\iPod 2009-06-02 00:10 –d—– f:\program files\iTunes 2009-05-26 17:18 90,112 a——- f:\windows\system32\QuickTimeVR.qtx 2009-05-26 17:18 57,344 a——- f:\windows\system32\QuickTime.qts 2009-05-18 23:44 107,368 a——- f:\windows\system32\GEARAspi.dll 2009-05-18 23:44 23,400 a——- f:\windows\system32\drivers\GEARAspiWDM.sys 2009-05-18 23:43 –d—– f:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-05-18 23:42 –d—– f:\program files\Bonjour ==================== Find3M ==================== 2009-06-10 21:56 219,588 a——- f:\windows\pchealth\helpctr\config\cache\Professional_32_1033.dat 2009-05-12 22:15 915,456 a——- f:\windows\system32\wininet.dll 2009-05-07 08:44 344,064 a——- f:\windows\system32\localspl.dll 2009-04-17 02:58 1,846,656 a——- f:\windows\system32\win32k.sys 2009-04-15 08:11 584,192 a——- f:\windows\system32\rpcrt4.dll 2008-11-04 02:23 61,224 ——– f:\documents and settings\lotta1\GoToAssistDownloadHelper.exe 2008-11-02 19:56 19,293 ac—— f:\program files\common files\qono.reg 2008-11-02 19:56 18,899 ac—— f:\program files\common files\lyhi._dl 2008-11-02 19:56 18,710 ac—— f:\program files\common files\rizas.exe 2008-11-02 18:29 13,489 ac—— f:\program files\common files\mitoj.ban 2008-11-02 18:29 17,835 -c—— f:\docume~1\lotta1\applic~1\egyjadoko.exe 2008-11-02 18:29 17,792 -c—— f:\docume~1\lotta1\applic~1\vavemidaz.scr 2008-11-02 18:29 16,555 -c—— f:\docume~1\lotta1\applic~1\uzuti.reg 2008-11-02 18:29 12,739 -c—— f:\docume~1\lotta1\applic~1\nupakibyf.sys 2008-11-02 18:29 10,517 -c—— f:\docume~1\alluse~1\applic~1\agoqycy.scr 2008-06-27 21:15 0 ac—— f:\program files\temp01 2004-01-15 02:34 259,539,966 ac—— f:\program files\Microsoft Office XP Publisher 2003.zip 2003-12-19 17:48 488 ac—— f:\program files\Read_me.txt 2001-04-04 18:11 1,499,904 ac—r– f:\program files\INSTMSIW.EXE 2001-04-04 18:11 184 ac–hr– f:\program files\AUTORUN.INF 2001-04-04 18:11 1,489,152 ac—r– f:\program files\INSTMSI.EXE 2001-04-02 20:50 29 ac—r– f:\program files\cd-key.txt 2001-03-02 00:38 3,485,184 ac—r– f:\program files\PROPLUS.MSI 2001-03-02 00:35 306,688 ac—r– f:\program files\OWC10.MSI 2001-03-01 15:35 224,771,818 ac–hr– f:\program files\OFFICE1.CAB 2001-02-28 13:14 476,576 ac—r– f:\program files\SETUP.EXE 2001-02-21 13:18 7,929 ac—r– f:\program files\README.HTM ============= FINISH: 9:21:35.79 =============== I also ran the GMER. scan and saved to my desktop.,however , I lost all the icons on the desktop and it seemed to freeze up so i rebooted and when i tried to post that scan to my post , that folder was empty! please let me know if i should run this scan again? thanx

Attachments:

Hi,

Please do the following:

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
ComboFix 09-06-13.03 - Lotta1 06/13/2009 15:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.139 [GMT -7:00]
Running from: f:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

f:\documents and settings\LocalService\Application Data\twain_32
f:\documents and settings\NetworkService\Application Data\gadcom
f:\documents and settings\NetworkService\Application Data\twain_32
f:\program files\Microsoft Common
f:\windows\system32\twain_32
f:\documents and settings\LocalService\Application Data\twain_32\user.ds
f:\documents and settings\Lotta1\Local Settings\Temporary Internet Files\awokogi.reg
f:\documents and settings\Lotta1\Local Settings\Temporary Internet Files\decodu.vbs
f:\documents and settings\NetworkService\Application Data\twain_32\user.ds
f:\documents and settings\NetworkService\Local Settings\Temporary Internet Files\fbk.sts
f:\program files\\setup.exe
f:\program files\autorun.inf
f:\windows\IE4 Error Log.txt
f:\windows\system32\DelSelf.bat
f:\windows\system32\E4D7wF1o.exe.a_a
f:\windows\system32\ipv17JY7.exe.a_a
f:\windows\system32\k86.bin
f:\windows\system32\lm.dat
f:\windows\system32\swapm.sys
f:\windows\system32\twain_32\local.ds
f:\windows\system32\twain_32\user.ds
f:\windows\system32\twain_32\user.ds.cla
f:\windows\system32\url(3).dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IPRIP
——-\Legacy_SWAPM
——-\Service_Iprip
——-\Service_swapm


((((((((((((((((((((((((( Files Created from 2009-05-13 to 2009-06-13 )))))))))))))))))))))))))))))))
.

2009-06-13 12:16 . 2009-06-13 12:18 ——– d—–w- f:\documents and settings\Lotta1\Application Data\ImgBurn
2009-06-13 12:12 . 2009-06-13 12:12 ——– d—–w- f:\program files\ImgBurn
2009-06-11 18:01 . 2009-06-11 18:01 ——– d—–w- f:\windows\ie8updates
2009-06-11 04:22 . 2009-06-11 04:24 ——– d—–w- F:\Backup
2009-06-10 19:38 . 2009-04-30 21:22 246272 -c—-w- f:\windows\system32\dllcache\ieproxy.dll
2009-06-10 19:38 . 2009-04-30 21:22 12800 -c—-w- f:\windows\system32\dllcache\xpshims.dll
2009-06-10 19:38 . 2009-04-30 21:22 1985024 -c—-w- f:\windows\system32\dllcache\iertutil.dll
2009-06-10 19:37 . 2009-04-30 21:22 11064832 -c—-w- f:\windows\system32\dllcache\ieframe.dll
2009-06-09 08:42 . 2009-06-13 08:48 ——– d—–w- f:\program files\PokerStars.NET
2009-06-08 18:00 . 2009-06-08 18:00 ——– d—–w- f:\program files\MSXML 4.0
2009-06-07 23:10 . 2009-06-13 18:16 ——– d—–w- f:\windows\system32\CatRoot_bak
2009-06-07 23:07 . 2009-02-06 16:49 2015744 -c—-w- f:\windows\system32\dllcache\ntkrpamp.exe
2009-06-07 23:07 . 2009-02-06 16:49 2057728 -c—-w- f:\windows\system32\dllcache\ntkrnlpa.exe
2009-06-07 23:04 . 2008-06-13 13:10 272128 ——w- f:\windows\system32\drivers\bthport.sys
2009-06-07 23:01 . 2008-10-16 21:06 268648 —-a-w- f:\windows\system32\mucltui.dll
2009-06-07 23:01 . 2008-10-16 21:06 208744 —-a-w- f:\windows\system32\muweb.dll
2009-06-07 11:09 . 2009-06-07 11:10 ——– d—–w- f:\program files\ERUNT
2009-06-07 10:49 . 2009-06-07 10:49 ——– d-sh–w- f:\documents and settings\admin\IETldCache
2009-06-02 07:10 . 2009-06-02 07:10 ——– d—–w- f:\program files\iPod
2009-06-02 07:10 . 2009-06-02 07:11 ——– d—–w- f:\program files\iTunes
2009-06-02 07:04 . 2009-06-02 07:06 ——– d—–w- f:\program files\QuickTime
2009-06-02 06:52 . 2009-06-02 06:52 75048 ——w- f:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-19 06:45 . 2009-06-07 07:37 ——– d—–w- f:\documents and settings\Lotta1\Application Data\Apple Computer
2009-05-19 06:44 . 2009-03-19 23:32 23400 —-a-w- f:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-19 06:44 . 2008-04-17 19:12 107368 —-a-w- f:\windows\system32\GEARAspi.dll
2009-05-19 06:43 . 2009-05-19 06:44 ——– d—–w- f:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-19 06:42 . 2009-05-19 06:42 ——– d—–w- f:\program files\Bonjour
2009-05-19 06:38 . 2009-05-19 06:43 ——– d—–w- f:\documents and settings\All Users\Application Data\Apple Computer
2009-05-19 06:37 . 2009-05-19 06:37 ——– d—–w- f:\documents and settings\Lotta1\Local Settings\Application Data\Apple
2009-05-19 06:37 . 2009-05-19 06:37 ——– d—–w- f:\program files\Apple Software Update
2009-05-19 06:37 . 2009-06-02 06:58 ——– dc—-w- f:\windows\system32\DRVSTORE
2009-05-19 06:35 . 2009-06-02 07:10 ——– d—–w- f:\program files\Common Files\Apple
2009-05-19 06:35 . 2009-05-19 06:35 ——– d—–w- f:\documents and settings\All Users\Application Data\Apple
2009-05-19 06:33 . 2009-05-19 06:45 ——– d—–w- f:\documents and settings\Lotta1\Local Settings\Application Data\Apple Computer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 21:51 . 2008-07-16 13:04 ——– d—–w- f:\program files\Lx_cats
2009-06-07 09:36 . 2008-06-28 04:22 ——– d—–w- f:\documents and settings\All Users\Application Data\TEMP
2009-05-13 20:35 . 2009-05-13 17:23 ——– d—–w- f:\program files\comcasttb
2009-05-13 20:35 . 2009-05-13 20:35 ——– d—–w- f:\documents and settings\Lotta1\Application Data\comcasttb
2009-05-13 20:34 . 2008-06-30 03:05 ——– d—–w- f:\documents and settings\All Users\Application Data\Viewpoint
2009-05-13 20:34 . 2008-06-21 07:38 ——– d–h–w- f:\program files\InstallShield Installation Information
2009-05-13 17:25 . 2009-05-13 17:25 ——– d—–w- f:\documents and settings\Lotta1\Application Data\CallingID
2009-05-13 17:24 . 2009-05-13 17:24 ——– d—–w- f:\program files\Common Files\scanner
2009-05-13 05:15 . 2004-08-04 15:00 915456 —-a-w- f:\windows\system32\wininet.dll
2009-05-07 15:44 . 2004-08-04 15:00 344064 —-a-w- f:\windows\system32\localspl.dll
2009-04-27 14:23 . 2008-06-27 07:18 ——– d—–w- f:\program files\Common Files\InstallShield
2009-04-27 03:35 . 2008-07-28 21:15 ——– d—–w- f:\program files\Google
2009-04-24 07:06 . 2009-04-24 07:06 ——– d—–w- f:\program files\PIXELA
2009-04-20 20:11 . 2009-01-08 13:29 ——– d—–w- f:\program files\McAfee
2009-04-17 09:58 . 2004-08-04 15:00 1846656 —-a-w- f:\windows\system32\win32k.sys
2009-04-15 15:11 . 2004-08-04 15:00 584192 —-a-w- f:\windows\system32\rpcrt4.dll
2009-03-19 23:32 . 2009-03-19 23:32 23400 ——w- f:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2008-11-03 02:56 . 2008-11-03 02:56 19293 -c–a-w- f:\program files\Common Files\qono.reg
2008-11-03 02:56 . 2008-11-03 02:56 18899 -c–a-w- f:\program files\Common Files\lyhi._dl
2008-11-03 02:56 . 2008-11-03 02:56 18710 -c–a-w- f:\program files\Common Files\rizas.exe
2008-11-03 01:29 . 2008-11-03 01:29 13489 -c–a-w- f:\program files\Common Files\mitoj.ban
2008-06-28 04:15 . 2008-06-28 04:15 0 -c–a-w- f:\program files\temp01
2004-01-15 09:34 . 2004-01-15 09:34 259539966 -c–a-w- f:\program files\Microsoft Office XP Publisher 2003.zip
2003-12-20 00:48 . 2003-12-20 00:48 488 -c–a-w- f:\program files\Read_me.txt
2001-04-05 01:11 . 2001-04-05 01:11 1499904 -c–a-r- f:\program files\INSTMSIW.EXE
2001-04-05 01:11 . 2001-04-05 01:11 1489152 -c–a-r- f:\program files\INSTMSI.EXE
2001-04-03 03:50 . 2001-04-03 03:50 29 -c–a-r- f:\program files\cd-key.txt
2001-03-02 07:38 . 2001-03-02 07:38 3485184 -c–a-r- f:\program files\PROPLUS.MSI
2001-03-02 07:35 . 2001-03-02 07:35 306688 -c–a-r- f:\program files\OWC10.MSI
2001-03-01 22:35 . 2001-03-01 22:35 224771818 -c-ha-r- f:\program files\OFFICE1.CAB
2001-02-21 20:18 . 2001-02-21 20:18 7929 -c–a-r- f:\program files\README.HTM
.

——- Sigcheck ——-

[-] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F f:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\termsrv.dll
[-] 2004-08-10 14:55 215552 A77219A971029DC2FB683E8513713803 f:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="f:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXCFCATS"="f:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 73728]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"f:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"f:\windows\system32\rundll32.exe" "f:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-08 f:\windows\Tasks\AppleSoftwareUpdate.job
- f:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-05-15 f:\windows\Tasks\McDefragTask.job
- f:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-08 21:32]

2009-06-01 f:\windows\Tasks\McQcTask.job
- f:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-08 21:32]

2009-06-13 f:\windows\Tasks\User_Feed_Synchronization-{FAD6FE1A-D4C9-4947-8014-74422C82B438}.job
- f:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-CTFMON - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://comcast.net/
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - f:\program files\PokerStars.NET\PokerStarsUpdate.exe
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: whatthetech.com\forums
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-13 15:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3632)
f:\windows\system32\WININET.dll
f:\windows\system32\ieframe.dll
f:\windows\system32\msi.dll
f:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
f:\windows\system32\WgaTray.exe
f:\windows\system32\CF25829.exe
f:\windows\system32\nvsvc32.exe
f:\windows\system32\tcpsvcs.exe
f:\windows\system32\MsPMSPSv.exe
f:\progra~1\McAfee\MSC\mcuimgr.exe
f:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
f:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
f:\progra~1\McAfee\MSC\mcmscsvc.exe
f:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
f:\progra~1\McAfee.com\Agent\mcagent.exe
f:\program files\McAfee\MPF\MpfSrv.exe
.
**************************************************************************
.
Completion time: 2009-06-13 15:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-13 22:31

Pre-Run: 102,620,794,880 bytes free
Post-Run: 103,452,852,224 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=signature(87a3b3ff)disk(1)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
signature(87a3b3ff)disk(1)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional main" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

218 — E O F — 2009-06-11 18:02
Hi,

there are a couple of suspicious files on your system that I would like to get analysed:


Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    f:\windows\system32\termsrv.dll

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Please do the same for these following files:

f:\program files\Common Files\qono.reg
f:\program files\Common Files\lyhi._dl
f:\program files\Common Files\rizas.exe
f:\program files\Common Files\mitoj.ban
f:\windows\system32\wininet.dll



If that site is busy, or you have difficulty uploading the files there:

try these:

virustotal
JOTTI
Hi, open notepad and right click then choose paste. 'clipboard' is not visible to you, when you copy text the computer places it on the 'clipboard' behind the scenes - it's just the way of being able to store the text you want until you put the text somewhere else - such as pasting it into Notepad. Hope that explains it well enough. So you can open the reply pane here into the thread and after pressing the 'copy to clipboard' button right click in the reply pane and choose 'paste' - the text from 'clipboard' will paste into the reply….because you have more than one file to scan… paste the replies into note pad, then you will have them all - then paste the entire contents of the notepad into your reply.
f:\windows\system32\termsrv.dll:

VirSCAN.org Scanned Report :
Scanned time : 2009/06/13 16:34:02 (PDT)
Scanner results: 3% Scanner(1/38) found malware!
File Name : termsrv.dll
File Size : 215552 byte
File Type : PE32 executable for MS Windows (DLL) (console) Intel 80386 3
MD5 : a77219a971029dc2fb683e8513713803
SHA1 : 1c456520a7b7faf71900c71167038185f5a7d312
Online report : http://virscan.org/report/9230dd752d175b32…ac95b13b66.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090612230239 2009-06-12 2.36 -
AhnLab V3 2009.06.14.00 2009.06.14 2009-06-14 0.72 -
AntiVir 8.2.0.187 7.1.4.88 2009-06-12 0.12 -
Antiy 2.0.18 20090613.2535569 2009-06-13 0.12 -
Arcavir 2009 200906131933 2009-06-13 0.07 -
Authentium 5.1.1 200906131805 2009-06-13 1.12 -
AVAST! 4.7.4 090613-0 2009-06-13 0.02 -
AVG 8.5.286 270.12.67/2174 2009-06-14 3.41 -
BitDefender 7.81008.3348507 7.25963 2009-06-14 3.00 -
CA (VET) 9.0.0.143 31.6.6555 2009-06-13 7.73 -
ClamAV 0.95.1 9463 2009-06-13 0.04 -
Comodo 3.9 1326 2009-06-13 0.74 Unclassified Malware
CP Secure 1.1.0.715 2009.06.13 2009-06-13 10.10 -
Dr.Web 4.44.0.9170 2009.06.13 2009-06-13 4.70 -
F-Prot 4.4.4.56 20090613 2009-06-13 1.12 -
F-Secure 5.51.6100 2009.06.13.02 2009-06-13 5.79 -
Fortinet 2.81-3.117 10.494 2009-06-13 0.20 -
GData 19.5810/19.363 20090613 2009-06-13 4.25 -
ViRobot 20090613 2009.06.13 2009-06-13 0.41 -
Ikarus T3.1.01.59 2009.06.13.72862 2009-06-13 3.34 -
JiangMin 11.0.706 2009.06.13 2009-06-13 2.00 -
Kaspersky 5.5.10 2009.06.13 2009-06-13 0.05 -
KingSoft 2009.2.5.15 2009.6.13.21 2009-06-13 0.49 -
McAfee 5.3.00 5645 2009-06-13 3.06 -
Microsoft 1.4701 2009.06.13 2009-06-13 4.24 -
mks_vir 2.01 2009.06.13 2009-06-13 3.25 -
Norman 6.01.09 6.01.00 2009-06-12 4.00 -
Panda 9.05.01 2009.06.12 2009-06-12 1.81 -
Trend Micro 8.700-1004 6.192.35 2009-06-13 0.03 -
Quick Heal 10.00 2009.06.13 2009-06-13 1.25 -
Rising 20.0 21.33.52.00 2009-06-13 0.77 -
Sophos 2.87.1 4.42 2009-06-14 2.43 -
Sunbelt 5187 5187 2009-06-13 0.85 -
Symantec 1.3.0.24 20090613.003 2009-06-13 0.05 -
nProtect 20090612.01 4239206 2009-06-12 5.27 -
The Hacker 6.3.4.3 v00345 2009-06-12 0.62 -
VBA32 3.12.10.7 20090612.1512 2009-06-12 1.97 -
VirusBuster 4.5.11.10 10.107.12/1629091 2009-06-13 2.02 -

f:\program files\Common Files\qono.reg:

VirSCAN.org Scanned Report :
Scanned time : 2009/06/13 17:42:28 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : qono.reg
File Size : 19293 byte
File Type : JVT NAL sequence
MD5 : bba465ee707e3d87893f29f9a863905c
SHA1 : 65726b182fea081a556a9191fb650e5d12de96f1
Online report : http://virscan.org/report/21911627754889e5…7850b44870.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090612230239 2009-06-12 2.19 -
AhnLab V3 2009.06.14.00 2009.06.14 2009-06-14 0.70 -
AntiVir 8.2.0.187 7.1.4.88 2009-06-12 0.21 -
Antiy 2.0.18 20090613.2535569 2009-06-13 0.12 -
Arcavir 2009 200906131933 2009-06-13 1.72 -
Authentium 5.1.1 200906131805 2009-06-13 1.11 -
AVAST! 4.7.4 090613-0 2009-06-13 0.01 -
AVG 8.5.286 270.12.67/2174 2009-06-14 3.38 -
BitDefender 7.81008.3348507 7.25963 2009-06-14 3.01 -
CA (VET) 9.0.0.143 31.6.6555 2009-06-13 8.09 -
ClamAV 0.95.1 9463 2009-06-13 0.01 -
Comodo 3.9 1327 2009-06-13 0.71 -
CP Secure 1.1.0.715 2009.06.13 2009-06-13 10.03 -
Dr.Web 4.44.0.9170 2009.06.13 2009-06-13 4.73 -
F-Prot 4.4.4.56 20090613 2009-06-13 1.11 -
F-Secure 5.51.6100 2009.06.13.02 2009-06-13 0.04 -
Fortinet 2.81-3.117 10.495 2009-06-13 0.16 -
GData 19.5812/19.363 20090614 2009-06-14 4.41 -
ViRobot 20090613 2009.06.13 2009-06-13 0.43 -
Ikarus T3.1.01.59 2009.06.13.72862 2009-06-13 3.31 -
JiangMin 11.0.706 2009.06.13 2009-06-13 2.01 -
Kaspersky 5.5.10 2009.06.13 2009-06-13 0.02 -
KingSoft 2009.2.5.15 2009.6.13.21 2009-06-13 0.48 -
McAfee 5.3.00 5645 2009-06-13 3.02 -
Microsoft 1.4701 2009.06.14 2009-06-14 4.34 -
mks_vir 2.01 2009.06.13 2009-06-13 3.16 -
Norman 6.01.09 6.01.00 2009-06-12 4.01 -
Panda 9.05.01 2009.06.12 2009-06-12 1.78 -
Trend Micro 8.700-1004 6.192.35 2009-06-13 0.02 -
Quick Heal 10.00 2009.06.13 2009-06-13 1.31 -
Rising 20.0 21.33.52.00 2009-06-13 0.39 -
Sophos 2.87.1 4.42 2009-06-14 2.44 -
Sunbelt 5187 5187 2009-06-13 0.88 -
Symantec 1.3.0.24 20090613.003 2009-06-13 0.05 -
nProtect 20090612.01 4239206 2009-06-12 5.89 -
The Hacker 6.3.4.3 v00345 2009-06-12 0.60 -
VBA32 3.12.10.7 20090612.1512 2009-06-12 1.96 -
VirusBuster 4.5.11.10 10.107.12/1629091 2009-06-13 1.96 -

f:\program files\Common Files\lyhi._dl:f:\program files\Common Files\rizas.exe:

VirSCAN.org Scanned Report :
Scanned time : 2009/06/13 17:46:23 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : lyhi._dl
File Size : 18899 byte
File Type : MPEG sequence
MD5 : d636fb5da1d85e100a8eeeda34fca5ff
SHA1 : 9bcf30275363e8839db0ae1513d7ae98e3969119
Online report : http://virscan.org/report/8915cbd78e91b26a…10755742a8.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090612230239 2009-06-12 2.74 -
AhnLab V3 2009.06.14.00 2009.06.14 2009-06-14 0.74 -
AntiVir 8.2.0.187 7.1.4.88 2009-06-12 0.20 -
Antiy 2.0.18 20090613.2535569 2009-06-13 0.12 -
Arcavir 2009 200906131933 2009-06-13 0.03 -
Authentium 5.1.1 200906131805 2009-06-13 1.11 -
AVAST! 4.7.4 090613-0 2009-06-13 0.00 -
AVG 8.5.286 270.12.67/2174 2009-06-14 3.33 -
BitDefender 7.81008.3348507 7.25963 2009-06-14 3.05 -
CA (VET) 9.0.0.143 31.6.6555 2009-06-13 6.96 -
ClamAV 0.95.1 9463 2009-06-13 0.01 -
Comodo 3.9 1327 2009-06-13 0.77 -
CP Secure 1.1.0.715 2009.06.13 2009-06-13 9.98 -
Dr.Web 4.44.0.9170 2009.06.13 2009-06-13 4.89 -
F-Prot 4.4.4.56 20090613 2009-06-13 1.10 -
F-Secure 5.51.6100 2009.06.13.02 2009-06-13 9.21 -
Fortinet 2.81-3.117 10.495 2009-06-13 0.16 -
GData 19.5812/19.363 20090614 2009-06-14 4.19 -
ViRobot 20090613 2009.06.13 2009-06-13 0.41 -
Ikarus T3.1.01.59 2009.06.13.72862 2009-06-13 3.31 -
JiangMin 11.0.706 2009.06.13 2009-06-13 2.00 -
Kaspersky 5.5.10 2009.06.13 2009-06-13 0.02 -
KingSoft 2009.2.5.15 2009.6.13.21 2009-06-13 0.49 -
McAfee 5.3.00 5645 2009-06-13 3.06 -
Microsoft 1.4701 2009.06.14 2009-06-14 4.23 -
mks_vir 2.01 2009.06.13 2009-06-13 3.17 -
Norman 6.01.09 6.01.00 2009-06-12 4.01 -
Panda 9.05.01 2009.06.12 2009-06-12 1.74 -
Trend Micro 8.700-1004 6.192.35 2009-06-13 0.02 -
Quick Heal 10.00 2009.06.13 2009-06-13 1.18 -
Rising 20.0 21.33.52.00 2009-06-13 0.26 -
Sophos 2.87.1 4.42 2009-06-14 2.45 -
Sunbelt 5187 5187 2009-06-13 0.81 -
Symantec 1.3.0.24 20090613.003 2009-06-13 0.05 -
nProtect 20090612.01 4239206 2009-06-12 5.72 -
The Hacker 6.3.4.3 v00345 2009-06-12 0.57 -
VBA32 3.12.10.7 20090612.1512 2009-06-12 1.97 -
VirusBuster 4.5.11.10 10.107.12/1629091 2009-06-13 1.98 -

f:\program files\Common Files\rizas.exe:

VirSCAN.org Scanned Report :
Scanned time : 2009/06/13 17:55:21 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : rizas.exe
File Size : 18710 byte
File Type : data
MD5 : 7676f0c33772d64dd4c3807cb88e0bef
SHA1 : 7ee6764a5fe8d6c849ca724a98d25f402e085ed5
Online report : http://virscan.org/report/dc8d623547bbd9d5…d140c4aafc.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090612230239 2009-06-12 2.18 -
AhnLab V3 2009.06.14.00 2009.06.14 2009-06-14 0.75 -
AntiVir 8.2.0.187 7.1.4.88 2009-06-12 0.20 -
Antiy 2.0.18 20090613.2535569 2009-06-13 0.12 -
Arcavir 2009 200906131933 2009-06-13 0.03 -
Authentium 5.1.1 200906131805 2009-06-13 1.12 -
AVAST! 4.7.4 090613-0 2009-06-13 0.00 -
AVG 8.5.286 270.12.67/2174 2009-06-14 3.34 -
BitDefender 7.81008.3348507 7.25963 2009-06-14 2.97 -
CA (VET) 9.0.0.143 31.6.6555 2009-06-13 8.21 -
ClamAV 0.95.1 9463 2009-06-13 0.01 -
Comodo 3.9 1327 2009-06-13 0.71 -
CP Secure 1.1.0.715 2009.06.13 2009-06-13 9.99 -
Dr.Web 4.44.0.9170 2009.06.13 2009-06-13 4.67 -
F-Prot 4.4.4.56 20090613 2009-06-13 1.10 -
F-Secure 5.51.6100 2009.06.13.02 2009-06-13 0.04 -
Fortinet 2.81-3.117 10.495 2009-06-13 0.18 -
GData 19.5812/19.363 20090614 2009-06-14 4.17 -
ViRobot 20090613 2009.06.13 2009-06-13 0.41 -
Ikarus T3.1.01.59 2009.06.13.72862 2009-06-13 3.29 -
JiangMin 11.0.706 2009.06.13 2009-06-13 2.02 -
Kaspersky 5.5.10 2009.06.13 2009-06-13 0.02 -
KingSoft 2009.2.5.15 2009.6.13.21 2009-06-13 0.48 -
McAfee 5.3.00 5645 2009-06-13 3.06 -
Microsoft 1.4701 2009.06.14 2009-06-14 4.26 -
mks_vir 2.01 2009.06.13 2009-06-13 3.16 -
Norman 6.01.09 6.01.00 2009-06-12 4.01 -
Panda 9.05.01 2009.06.12 2009-06-12 2.04 -
Trend Micro 8.700-1004 6.192.35 2009-06-13 0.02 -
Quick Heal 10.00 2009.06.13 2009-06-13 1.20 -
Rising 20.0 21.33.52.00 2009-06-13 0.28 -
Sophos 2.87.1 4.42 2009-06-14 2.43 -
Sunbelt 5187 5187 2009-06-13 0.85 -
Symantec 1.3.0.24 20090613.003 2009-06-13 0.05 -
nProtect 20090612.01 4239206 2009-06-12 5.32 -
The Hacker 6.3.4.3 v00345 2009-06-12 0.59 -
VBA32 3.12.10.7 20090612.1512 2009-06-12 2.60 -
VirusBuster 4.5.11.10 10.107.12/1629091 2009-06-13 2.22 -

f:\program files\Common Files\mitoj.ban:

VirSCAN.org Scanned Report :
Scanned time : 2009/06/13 17:58:06 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : mitoj.ban
File Size : 13489 byte
File Type : MPEG sequence
MD5 : c8daf853517f595fea4dba3feaf7a796
SHA1 : 275b8651068902a7e1ea44bfd8541cb7b1983883
Online report : http://virscan.org/report/d88fef2803a6ec03…7633173da0.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090612230239 2009-06-12 40.13 -
AhnLab V3 2009.06.14.00 2009.06.14 2009-06-14 0.72 -
AntiVir 8.2.0.187 7.1.4.88 2009-06-12 0.17 -
Antiy 2.0.18 20090613.2535569 2009-06-13 0.12 -
Arcavir 2009 200906131933 2009-06-13 0.02 -
Authentium 5.1.1 200906131805 2009-06-13 1.27 -
AVAST! 4.7.4 090613-0 2009-06-13 0.00 -
AVG 8.5.286 270.12.67/2174 2009-06-14 3.33 -
BitDefender 7.81008.3348507 7.25963 2009-06-14 2.96 -
CA (VET) 9.0.0.143 31.6.6555 2009-06-13 7.46 -
ClamAV 0.95.1 9463 2009-06-13 0.01 -
Comodo 3.9 1327 2009-06-13 0.71 -
CP Secure 1.1.0.715 2009.06.13 2009-06-13 9.99 -
Dr.Web 4.44.0.9170 2009.06.13 2009-06-13 4.66 -
F-Prot 4.4.4.56 20090613 2009-06-13 1.25 -
F-Secure 5.51.6100 2009.06.13.02 2009-06-13 0.04 -
Fortinet 2.81-3.117 10.495 2009-06-13 0.18 -
GData 19.5812/19.363 20090614 2009-06-14 4.20 -
ViRobot 20090613 2009.06.13 2009-06-13 0.41 -
Ikarus T3.1.01.59 2009.06.13.72862 2009-06-13 3.31 -
JiangMin 11.0.706 2009.06.13 2009-06-13 2.19 -
Kaspersky 5.5.10 2009.06.13 2009-06-13 0.02 -
KingSoft 2009.2.5.15 2009.6.13.21 2009-06-13 0.49 -
McAfee 5.3.00 5645 2009-06-13 3.09 -
Microsoft 1.4701 2009.06.14 2009-06-14 4.33 -
mks_vir 2.01 2009.06.13 2009-06-13 3.20 -
Norman 6.01.09 6.01.00 2009-06-12 4.01 -
Panda 9.05.01 2009.06.12 2009-06-12 1.97 -
Trend Micro 8.700-1004 6.192.35 2009-06-13 0.02 -
Quick Heal 10.00 2009.06.13 2009-06-13 1.16 -
Rising 20.0 21.33.52.00 2009-06-13 0.27 -
Sophos 2.87.1 4.42 2009-06-14 2.43 -
Sunbelt 5187 5187 2009-06-13 0.86 -
Symantec 1.3.0.24 20090613.003 2009-06-13 0.07 -
nProtect 20090612.01 4239206 2009-06-12 5.30 -
The Hacker 6.3.4.3 v00345 2009-06-12 0.60 -
VBA32 3.12.10.7 20090612.1512 2009-06-12 1.97 -
VirusBuster 4.5.11.10 10.107.12/1629091 2009-06-13 1.96 -

f:\windows\system32\wininet.dll:

VirSCAN.org Scanned Report :
Scanned time : 2009/06/13 18:03:28 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : wininet.dll
File Size : 915456 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : 366c72af6970db7bb39ab0142bf09db5
SHA1 : 8907d1c8a03f34bb1dff573c1fae4054f5dc0fbe
Online report : http://virscan.org/report/825fcd05876a0ccb…8173b216ad.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090612230239 2009-06-12 40.13 -
AhnLab V3 2009.06.14.00 2009.06.14 2009-06-14 0.79 -
AntiVir 8.2.0.187 7.1.4.88 2009-06-12 0.22 -
Antiy 2.0.18 20090613.2535569 2009-06-13 0.12 -
Arcavir 2009 200906131933 2009-06-13 0.07 -
Authentium 5.1.1 200906131805 2009-06-13 5.10 -
AVAST! 4.7.4 090613-0 2009-06-13 0.06 -
AVG 8.5.286 270.12.67/2174 2009-06-14 3.58 -
BitDefender 7.81008.3348507 7.25963 2009-06-14 3.08 -
CA (VET) 9.0.0.143 31.6.6555 2009-06-13 3.74 -
ClamAV 0.95.1 9463 2009-06-13 0.18 -
Comodo 3.9 1327 2009-06-13 0.75 -
CP Secure 1.1.0.715 2009.06.13 2009-06-13 10.11 -
Dr.Web 4.44.0.9170 2009.06.13 2009-06-13 4.66 -
F-Prot 4.4.4.56 20090613 2009-06-13 4.62 -
F-Secure 5.51.6100 2009.06.13.02 2009-06-13 0.08 -
Fortinet 2.81-3.117 10.495 2009-06-13 0.23 -
GData 19.5812/19.363 20090614 2009-06-14 4.31 -
ViRobot 20090613 2009.06.13 2009-06-13 0.43 -
Ikarus T3.1.01.59 2009.06.13.72862 2009-06-13 3.56 -
JiangMin 11.0.706 2009.06.13 2009-06-13 2.00 -
Kaspersky 5.5.10 2009.06.13 2009-06-13 0.05 -
KingSoft 2009.2.5.15 2009.6.13.21 2009-06-13 0.53 -
McAfee 5.3.00 5645 2009-06-13 3.09 -
Microsoft 1.4701 2009.06.14 2009-06-14 4.29 -
mks_vir 2.01 2009.06.13 2009-06-13 3.19 -
Norman 6.01.09 6.01.00 2009-06-12 4.00 -
Panda 9.05.01 2009.06.12 2009-06-12 1.81 -
Trend Micro 8.700-1004 6.192.36 2009-06-13 0.03 -
Quick Heal 10.00 2009.06.13 2009-06-13 1.41 -
Rising 20.0 21.33.52.00 2009-06-13 0.77 -
Sophos 2.87.1 4.42 2009-06-14 2.43 -
Sunbelt 5187 5187 2009-06-13 0.85 -
Symantec 1.3.0.24 20090613.003 2009-06-13 0.07 -
nProtect 20090612.01 4239206 2009-06-12 5.68 -
The Hacker 6.3.4.3 v00345 2009-06-12 0.65 -
VBA32 3.12.10.7 20090612.1512 2009-06-12 2.31 -
VirusBuster 4.5.11.10 10.107.12/1629091 2009-06-13 2.24 -

thank you!
Hi,

That's good,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • under the Scan section on the left:
    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.


In your next reply please include
  • MBAM Log
  • Kaspersky report


Also, please advise how your computer is running now and if there are nay outstanding issues.
Malwarebytes' Anti-Malware 1.37 Database version: 2273 Windows 5.1.2600 Service Pack 2 6/13/2009 8:37:26 PM mbam-log-2009-06-13 (20-37-26).txt Scan type: Quick Scan Objects scanned: 94660 Time elapsed: 7 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 1 Registry Data Items Infected: 5 Folders Infected: 1 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: f:\program files\AntivirusPro2009 (Rogue.AntiVirus2008) -> Quarantined and deleted successfully. Files Infected: f:\program files\antiviruspro2009\AntivirusPro2009.cfg (Rogue.AntiVirus2008) -> Quarantined and deleted successfully. f:\program files\antiviruspro2009\htmlayout.dll (Rogue.AntiVirus2008) -> Quarantined and deleted successfully. KASPERSKY ONLINE SCANNER 7.0 REPORT Sunday, June 14, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Sunday, June 14, 2009 07:57:42 Records in database: 2342374 Scan settings Scan using the following database extended Scan archives yes Scan mail databases yes Scan area Folder F:\ Scan statistics Files scanned 53993 Threat name 0 Infected objects 0 Suspicious objects 0 Duration of the scan 02:23:15 No malware has been detected. The scan area is clean. The selected area was scanned.
Hi,

As you can see, Malwarebiyes, located a 'backdoor bot' which it has cleaned off your system.

These programs have the ability to steal personal information from your computer.

As a precaution - from a different clean computer I would change all your passwords for all your online business and memberships, I would also notify your financial institutions and Credit Card companies that your personal information may have been compromised.

I cannot guarantee with 100% certainty that this machine will be completely trustworthy again as no-one knows. The only way to do that would be a total reformat / reinstall.


It appears that your machine is clean of malware.

Please re-run DDS and post a log so I can be certain, then we can clean up the tools used.


NEXT


Your Java is out of date

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer. (version 6, update 14)
DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 20:03:25.18 on Sun 06/14/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.103 [GMT -7:00] AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== F:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe F:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe F:\WINDOWS\system32\spoolsv.exe svchost.exe F:\Program Files\Java\jre6\bin\jqs.exe F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe F:\Program Files\McAfee\MPF\MPFSrv.exe F:\WINDOWS\system32\nvsvc32.exe F:\WINDOWS\system32\tcpsvcs.exe F:\WINDOWS\system32\svchost.exe -k imgsvc F:\WINDOWS\system32\MsPMSPSv.exe f:\PROGRA~1\mcafee.com\agent\mcagent.exe F:\WINDOWS\system32\WgaTray.exe F:\WINDOWS\Explorer.EXE F:\WINDOWS\system32\ctfmon.exe f:\PROGRA~1\mcafee\msc\mcuimgr.exe F:\WINDOWS\system32\wscntfy.exe F:\Documents and Settings\Lotta1\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://comcast.net/ BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - f:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] f:\windows\system32\ctfmon.exe mRun: [LXCFCATS] rundll32 f:\windows\system32\spool\drivers\w32x86\3\LXCFtime.dll,_RunDLLEntry@16 mRun: [SunJavaUpdateSched] "f:\program files\java\jre6\bin\jusched.exe" mPolicies-explorer: = IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - f:\program files\pokerstars.net\PokerStarsUpdate.exe Trusted Zone: internet Trusted Zone: mcafee.com Trusted Zone: whatthetech.com\forums DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1244415498734 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;f:\windows\system32\drivers\mfehidk.sys [2009-1-8 201320] R2 McProxy;McAfee Proxy Service;f:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-1-8 359248] R2 McShield;McAfee Real-time Scanner;f:\progra~1\mcafee\viruss~1\mcshield.exe [2009-1-8 144704] R3 mfeavfk;McAfee Inc. mfeavfk;f:\windows\system32\drivers\mfeavfk.sys [2009-1-8 79304] R3 mfebopk;McAfee Inc. mfebopk;f:\windows\system32\drivers\mfebopk.sys [2009-1-8 35240] S3 mferkdk;McAfee Inc. mferkdk;f:\windows\system32\drivers\mferkdk.sys [2009-1-8 33832] S3 mfesmfk;McAfee Inc. mfesmfk;f:\windows\system32\drivers\mfesmfk.sys [2009-1-8 40488] S4 McSysmon;McAfee SystemGuards;f:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-1-8 695624] =============== Created Last 30 ================ 2009-06-13 21:52 410,984 a——- f:\windows\system32\deploytk.dll 2009-06-13 19:54 –d—– f:\docume~1\lotta1\applic~1\Malwarebytes 2009-06-13 19:54 40,160 a——- f:\windows\system32\drivers\mbamswissarmy.sys 2009-06-13 19:54 –d—– f:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-13 19:54 19,096 a——- f:\windows\system32\drivers\mbam.sys 2009-06-13 19:54 –d—– f:\program files\Malwarebytes' Anti-Malware 2009-06-13 15:08 161,792 a——- f:\windows\SWREG.exe 2009-06-13 15:08 98,816 a——- f:\windows\sed.exe 2009-06-13 15:08 388,608 a——- f:\windows\system32\CF25829.exe 2009-06-11 11:01 –d—– f:\windows\ie8updates 2009-06-10 21:22 –d—– F:\Backup 2009-06-10 12:38 246,272 -c—— f:\windows\system32\dllcache\ieproxy.dll 2009-06-10 12:38 12,800 -c—— f:\windows\system32\dllcache\xpshims.dll 2009-06-10 12:38 1,985,024 -c—— f:\windows\system32\dllcache\iertutil.dll 2009-06-10 12:37 11,064,832 -c—— f:\windows\system32\dllcache\ieframe.dll 2009-06-09 01:42 –d—– f:\program files\PokerStars.NET 2009-06-08 11:00 –d—– f:\program files\MSXML 4.0 2009-06-07 16:10 –d—– f:\windows\system32\CatRoot_bak 2009-06-07 16:07 2,015,744 -c—— f:\windows\system32\dllcache\ntkrpamp.exe 2009-06-07 16:07 2,057,728 -c—— f:\windows\system32\dllcache\ntkrnlpa.exe 2009-06-07 16:04 272,128 ——– f:\windows\system32\drivers\bthport.sys 2009-06-07 16:01 268,648 a——- f:\windows\system32\mucltui.dll 2009-06-07 16:01 208,744 a——- f:\windows\system32\muweb.dll 2009-06-07 16:01 27,496 a——- f:\windows\system32\mucltui.dll.mui 2009-06-02 00:10 –d—– f:\program files\iPod 2009-06-02 00:10 –d—– f:\program files\iTunes 2009-05-26 17:18 90,112 a——- f:\windows\system32\QuickTimeVR.qtx 2009-05-26 17:18 57,344 a——- f:\windows\system32\QuickTime.qts 2009-05-18 23:44 107,368 a——- f:\windows\system32\GEARAspi.dll 2009-05-18 23:44 23,400 a——- f:\windows\system32\drivers\GEARAspiWDM.sys 2009-05-18 23:43 –d—– f:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-05-18 23:42 –d—– f:\program files\Bonjour ==================== Find3M ==================== 2009-05-12 22:15 915,456 a——- f:\windows\system32\wininet.dll 2009-05-07 08:44 344,064 a——- f:\windows\system32\localspl.dll 2009-04-17 02:58 1,846,656 a——- f:\windows\system32\win32k.sys 2009-04-15 08:11 584,192 a——- f:\windows\system32\rpcrt4.dll 2008-11-04 02:23 61,224 ——– f:\documents and settings\lotta1\GoToAssistDownloadHelper.exe 2008-11-02 19:56 19,293 ac—— f:\program files\common files\qono.reg 2008-11-02 19:56 18,899 ac—— f:\program files\common files\lyhi._dl 2008-11-02 19:56 18,710 ac—— f:\program files\common files\rizas.exe 2008-11-02 18:29 13,489 ac—— f:\program files\common files\mitoj.ban 2008-11-02 18:29 17,835 -c—— f:\docume~1\lotta1\applic~1\egyjadoko.exe 2008-11-02 18:29 17,792 -c—— f:\docume~1\lotta1\applic~1\vavemidaz.scr 2008-11-02 18:29 16,555 -c—— f:\docume~1\lotta1\applic~1\uzuti.reg 2008-11-02 18:29 12,739 -c—— f:\docume~1\lotta1\applic~1\nupakibyf.sys 2008-11-02 18:29 10,517 -c—— f:\docume~1\alluse~1\applic~1\agoqycy.scr 2008-06-27 21:15 0 ac—— f:\program files\temp01 2004-01-15 02:34 259,539,966 ac—— f:\program files\Microsoft Office XP Publisher 2003.zip 2003-12-19 17:48 488 ac—— f:\program files\Read_me.txt 2001-04-04 18:11 1,499,904 ac—r– f:\program files\INSTMSIW.EXE 2001-04-04 18:11 1,489,152 ac—r– f:\program files\INSTMSI.EXE 2001-04-02 20:50 29 ac—r– f:\program files\cd-key.txt 2001-03-02 00:38 3,485,184 ac—r– f:\program files\PROPLUS.MSI 2001-03-02 00:35 306,688 ac—r– f:\program files\OWC10.MSI 2001-03-01 15:35 224,771,818 ac–hr– f:\program files\OFFICE1.CAB 2001-02-21 13:18 7,929 ac—r– f:\program files\README.HTM ============= FINISH: 20:03:47.70 =============== hello my computers behavior seems much better, although i havent had time to really put it to test, i will this evening now. I upgraded my Java as per your insrtuctions, sucessfully. I do have one issue that is driving me crazy. when i start IE before it fully loads my home page i get two windows consecutively. first says "IE-Search provider default-a program on your computer has corrupted your default search provider setting for IE……then the second is "Manage Add-ons-view and manage IE add-ons. How do I bypass or rid of those annoying 2 windows? Also during the process of working with you , I was getting a lot of "windows virtual memory too low" warning windows. Is that bad or represent another issue? You have really worked miracles for me and I thank you so much. it was truly a learning experience and somewhat comforting and fun at the same time. I owe you! for now i am going to use it and see how it is behaving tonite! I will wait for your response. re: safety of personal info due to backdoor bot- where can i get better protection in the future, as i thought McAfee would catch and rid of these types of things? I am running a free version of mc afee courtesy of Comcast. is this software enough? thanx for any suggestions.

Attachments:

Hi,

visit this microsoft Page:

http://support.microsoft.com/kb/923737

scroll down the page till you see the FixIt button select the Fix It button to reset your internet explorer back to it's default settings…(any add-ons you installed will need to be installed again) but that should get rid of the messages..Alternately you can upgrade to I.E.8.

NEXT

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the quotebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the quote box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
f:\program files\common files\qono.reg
f:\program files\common files\lyhi._dl
f:\program files\common files\rizas.exe
f:\program files\common files\mitoj.ban
f:\docume~1\lotta1\applic~1\egyjadoko.exe
f:\docume~1\lotta1\applic~1\vavemidaz.scr
f:\docume~1\lotta1\applic~1\uzuti.reg
f:\docume~1\lotta1\applic~1\nupakibyf.sys
f:\docume~1\alluse~1\applic~1\agoqycy.scr
f:\program files\temp01

SkipFix::


Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 09-06-15.07 - Lotta1 06/16/2009 7:13.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.137 [GMT -7:00]
Running from: f:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: f:\documents and settings\Lotta1\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

FILE ::
"f:\docume~1\alluse~1\applic~1\agoqycy.scr"
"f:\docume~1\lotta1\applic~1\egyjadoko.exe"
"f:\docume~1\lotta1\applic~1\nupakibyf.sys"
"f:\docume~1\lotta1\applic~1\uzuti.reg"
"f:\docume~1\lotta1\applic~1\vavemidaz.scr"
"f:\program files\common files\lyhi._dl"
"f:\program files\common files\mitoj.ban"
"f:\program files\common files\qono.reg"
"f:\program files\common files\rizas.exe"
"f:\program files\temp01"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

f:\docume~1\alluse~1\applic~1\agoqycy.scr
f:\docume~1\lotta1\applic~1\egyjadoko.exe
f:\docume~1\lotta1\applic~1\nupakibyf.sys
f:\docume~1\lotta1\applic~1\uzuti.reg
f:\docume~1\lotta1\applic~1\vavemidaz.scr
f:\program files\common files\lyhi._dl
f:\program files\common files\mitoj.ban
f:\program files\common files\qono.reg
f:\program files\common files\rizas.exe
f:\program files\temp01

.
((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.

2009-06-14 04:52 . 2009-06-14 04:49 410984 —-a-w- f:\windows\system32\deploytk.dll
2009-06-14 04:47 . 2009-06-14 04:47 152576 —-a-w- f:\documents and settings\Lotta1\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-14 02:54 . 2009-06-14 02:54 ——– d—–w- f:\documents and settings\Lotta1\Application Data\Malwarebytes
2009-06-14 02:54 . 2009-05-26 20:20 40160 —-a-w- f:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 02:54 . 2009-06-14 02:54 ——– d—–w- f:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-14 02:54 . 2009-05-26 20:19 19096 —-a-w- f:\windows\system32\drivers\mbam.sys
2009-06-14 02:54 . 2009-06-14 02:54 ——– d—–w- f:\program files\Malwarebytes' Anti-Malware
2009-06-13 12:16 . 2009-06-13 12:18 ——– d—–w- f:\documents and settings\Lotta1\Application Data\ImgBurn
2009-06-13 12:12 . 2009-06-13 12:12 ——– d—–w- f:\program files\ImgBurn
2009-06-11 18:01 . 2009-06-11 18:01 ——– d—–w- f:\windows\ie8updates
2009-06-11 04:22 . 2009-06-11 04:24 ——– d—–w- F:\Backup
2009-06-10 19:38 . 2009-04-30 21:22 246272 -c—-w- f:\windows\system32\dllcache\ieproxy.dll
2009-06-10 19:38 . 2009-04-30 21:22 12800 -c—-w- f:\windows\system32\dllcache\xpshims.dll
2009-06-10 19:38 . 2009-04-30 21:22 1985024 -c—-w- f:\windows\system32\dllcache\iertutil.dll
2009-06-10 19:37 . 2009-04-30 21:22 11064832 -c—-w- f:\windows\system32\dllcache\ieframe.dll
2009-06-09 08:42 . 2009-06-16 08:15 ——– d—–w- f:\program files\PokerStars.NET
2009-06-08 18:00 . 2009-06-08 18:00 ——– d—–w- f:\program files\MSXML 4.0
2009-06-07 23:10 . 2009-06-15 01:12 ——– d—–w- f:\windows\system32\CatRoot_bak
2009-06-07 23:07 . 2009-02-06 16:49 2015744 -c—-w- f:\windows\system32\dllcache\ntkrpamp.exe
2009-06-07 23:07 . 2009-02-06 16:49 2057728 -c—-w- f:\windows\system32\dllcache\ntkrnlpa.exe
2009-06-07 23:04 . 2008-06-13 13:10 272128 ——w- f:\windows\system32\drivers\bthport.sys
2009-06-07 23:01 . 2008-10-16 21:06 268648 —-a-w- f:\windows\system32\mucltui.dll
2009-06-07 23:01 . 2008-10-16 21:06 208744 —-a-w- f:\windows\system32\muweb.dll
2009-06-07 11:09 . 2009-06-07 11:10 ——– d—–w- f:\program files\ERUNT
2009-06-07 10:49 . 2009-06-07 10:49 ——– d-sh–w- f:\documents and settings\admin\IETldCache
2009-06-02 07:10 . 2009-06-02 07:10 ——– d—–w- f:\program files\iPod
2009-05-19 06:35 . 2009-05-19 06:35 ——– d—–w- f:\documents and settings\All Users\Application Data\Apple
2009-05-19 06:33 . 2009-05-19 06:45 ——– d—–w- f:\documents and settings\Lotta1\Local Settings\Application Data\Apple Computer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 07:35 . 2008-07-16 13:04 ——– d—–w- f:\program files\Lx_cats
2009-06-15 00:56 . 2008-06-27 08:01 ——– d—–w- f:\program files\Java
2009-06-07 09:36 . 2008-06-28 04:22 ——– d—–w- f:\documents and settings\All Users\Application Data\TEMP
2009-06-07 07:37 . 2009-05-19 06:45 ——– d—–w- f:\documents and settings\Lotta1\Application Data\Apple Computer
2009-06-02 07:11 . 2009-06-02 07:10 ——– d—–w- f:\program files\iTunes
2009-06-02 07:10 . 2009-05-19 06:35 ——– d—–w- f:\program files\Common Files\Apple
2009-06-02 07:06 . 2009-06-02 07:04 ——– d—–w- f:\program files\QuickTime
2009-06-02 06:52 . 2009-06-02 06:52 75048 ——w- f:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-19 06:44 . 2009-05-19 06:43 ——– d—–w- f:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-19 06:43 . 2009-05-19 06:38 ——– d—–w- f:\documents and settings\All Users\Application Data\Apple Computer
2009-05-19 06:42 . 2009-05-19 06:42 ——– d—–w- f:\program files\Bonjour
2009-05-19 06:37 . 2009-05-19 06:37 ——– d—–w- f:\program files\Apple Software Update
2009-05-13 20:35 . 2009-05-13 17:23 ——– d—–w- f:\program files\comcasttb
2009-05-13 20:35 . 2009-05-13 20:35 ——– d—–w- f:\documents and settings\Lotta1\Application Data\comcasttb
2009-05-13 20:34 . 2008-06-30 03:05 ——– d—–w- f:\documents and settings\All Users\Application Data\Viewpoint
2009-05-13 20:34 . 2008-06-21 07:38 ——– d–h–w- f:\program files\InstallShield Installation Information
2009-05-13 17:25 . 2009-05-13 17:25 ——– d—–w- f:\documents and settings\Lotta1\Application Data\CallingID
2009-05-13 17:24 . 2009-05-13 17:24 ——– d—–w- f:\program files\Common Files\scanner
2009-05-13 05:15 . 2004-08-04 15:00 915456 —-a-w- f:\windows\system32\wininet.dll
2009-05-07 15:44 . 2004-08-04 15:00 344064 —-a-w- f:\windows\system32\localspl.dll
2009-04-27 14:23 . 2008-06-27 07:18 ——– d—–w- f:\program files\Common Files\InstallShield
2009-04-27 03:35 . 2008-07-28 21:15 ——– d—–w- f:\program files\Google
2009-04-24 07:06 . 2009-04-24 07:06 ——– d—–w- f:\program files\PIXELA
2009-04-20 20:11 . 2009-01-08 13:29 ——– d—–w- f:\program files\McAfee
2009-04-17 09:58 . 2004-08-04 15:00 1846656 —-a-w- f:\windows\system32\win32k.sys
2009-04-15 15:11 . 2004-08-04 15:00 584192 —-a-w- f:\windows\system32\rpcrt4.dll
2009-03-19 23:32 . 2009-05-19 06:44 23400 —-a-w- f:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-19 23:32 . 2009-03-19 23:32 23400 ——w- f:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2004-01-15 09:34 . 2004-01-15 09:34 259539966 -c–a-w- f:\program files\Microsoft Office XP Publisher 2003.zip
2003-12-20 00:48 . 2003-12-20 00:48 488 -c–a-w- f:\program files\Read_me.txt
2001-04-05 01:11 . 2001-04-05 01:11 1499904 -c–a-r- f:\program files\INSTMSIW.EXE
2001-04-05 01:11 . 2001-04-05 01:11 1489152 -c–a-r- f:\program files\INSTMSI.EXE
2001-04-03 03:50 . 2001-04-03 03:50 29 -c–a-r- f:\program files\cd-key.txt
2001-03-02 07:38 . 2001-03-02 07:38 3485184 -c–a-r- f:\program files\PROPLUS.MSI
2001-03-02 07:35 . 2001-03-02 07:35 306688 -c–a-r- f:\program files\OWC10.MSI
2001-03-01 22:35 . 2001-03-01 22:35 224771818 -c-ha-r- f:\program files\OFFICE1.CAB
2001-02-21 20:18 . 2001-02-21 20:18 7929 -c–a-r- f:\program files\README.HTM
.

——- Sigcheck ——-

[-] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F f:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\termsrv.dll
[-] 2004-08-10 14:55 215552 A77219A971029DC2FB683E8513713803 f:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-13_22.25.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-16 04:04 . 2009-06-16 04:04 16384 f:\windows\temp\Perflib_Perfdata_634.dat
- 2008-06-20 06:51 . 2009-06-13 20:14 32768 f:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-06-20 06:51 . 2009-06-16 13:56 32768 f:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-06-20 06:51 . 2009-06-13 20:14 32768 f:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-20 06:51 . 2009-06-16 13:56 32768 f:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-06-14 04:52 . 2009-06-14 04:49 148888 f:\windows\system32\javaws.exe
+ 2009-06-14 04:52 . 2009-06-14 04:49 144792 f:\windows\system32\javaw.exe
+ 2009-06-14 04:52 . 2009-06-14 04:49 144792 f:\windows\system32\java.exe
+ 2009-01-19 00:05 . 2009-01-19 00:05 675840 f:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\JP2KLib.dll
+ 2008-12-19 00:48 . 2008-12-19 00:48 3645440 f:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\authplay.dll
+ 2009-02-28 00:37 . 2009-02-28 00:37 20403568 f:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="f:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXCFCATS"="f:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 73728]
"SunJavaUpdateSched"="f:\program files\Java\jre6\bin\jusched.exe" [2009-06-14 148888]
"Adobe Reader Speed Launcher"="f:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"f:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"f:\windows\system32\rundll32.exe" "f:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-08 f:\windows\Tasks\AppleSoftwareUpdate.job
- f:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-05-15 f:\windows\Tasks\McDefragTask.job
- f:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-08 21:32]

2009-06-01 f:\windows\Tasks\McQcTask.job
- f:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-08 21:32]

2009-06-16 f:\windows\Tasks\User_Feed_Synchronization-{FAD6FE1A-D4C9-4947-8014-74422C82B438}.job
- f:\windows\system32\msfeedssync.exe [2007-08-14 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://comcast.net/
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - f:\program files\PokerStars.NET\PokerStarsUpdate.exe
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: whatthetech.com\forums
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 07:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCFCATS = rundll32 f:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-06-16 7:23
ComboFix-quarantined-files.txt 2009-06-16 14:23
ComboFix2.txt 2009-06-13 22:31

Pre-Run: 103,061,970,944 bytes free
Post-Run: 103,132,217,344 bytes free

190 — E O F — 2009-06-11 18:02

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI