This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] UACinit.dll issue possibly?

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. Stumbled upon your site via Google and thought it was cool. Noticed a few posts that were similar to my issue: Post #1 and Post #2.

Here's my HJT log. I've had to rename mbam.exe to stuff.com to run it. Symptoms are Google result redirections and Adobe documents error out after being open a couple minutes. Thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:59:59 PM, on 6/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\RemoteSupportManager\DaMaint.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\system32\nvsvc32.exe
C:\Program Files\RemoteSupportManager\DesktopAuthority.exe
C:\Program Files\RDS\RsiSvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\RDS\srscandr.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\N-able Technologies\Windows Agent\bin\AgentMaint.exe
C:\Program Files\RemoteSupportManager\RMGui.exe
C:\Program Files\N-able Technologies\Windows Agent\bin\agent.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\RDS\ddsschednt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\WINNT\Mixer.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\TickerCom\TickerCom.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\WINNT\LMI22B.tmp\lmi_rescue.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil_.exe
C:\WINNT\LMI22B.tmp\lmi_rescue.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Remote Support Manager GUI] "C:\Program Files\RemoteSupportManager\rmgui.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TickerCom] C:\Program Files\TickerCom\TickerCom.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [*LogMeInRescue_2077703930] "C:\WINNT\LMI22B.tmp\lmi_rescue.exe" -runonce reboot
O4 - HKUS\S-1-5-19\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1078081533-1425521274-839522115-1110\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe (User 'SSIMMONS')
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = kfnn.com
O17 - HKLM\Software\..\Telephony: DomainName = kfnn.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = kfnn.com
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Remote Support Manager Maintenance Service (DAMaint) - ScriptLogic Corporation - C:\Program Files\RemoteSupportManager\DaMaint.exe
O23 - Service: Dds Scheduler Deamon (DdsSched) - RICOH Company Ltd. - C:\Program Files\RDS\ddsschednt.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Remote Support Manager Service (RemoteSupportManager) - ScriptLogic Corporation - C:\Program Files\RemoteSupportManager\DesktopAuthority.exe
O23 - Service: Ridoc Server Information Service (RsiSvc) - RICOH Company Ltd. - C:\Program Files\RDS\RsiSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScanRouterDriverV2 - Ricoh Co.,Ltd. - C:\Program Files\RDS\srscandr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SOption - RICOH Company Ltd. - C:\Program Files\RDS\SOption.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Windows Agent Maintenance Service - N-able Technologies - C:\Program Files\N-able Technologies\Windows Agent\bin\AgentMaint.exe
O23 - Service: Windows Agent Service - N-able Technologies - C:\Program Files\N-able Technologies\Windows Agent\bin\agent.exe

–
End of file - 10850 bytes
Hi and welcome,

NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.

Please do the following:

STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2

Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.


Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
Hi, see if GMER will run in safe mode. to enter safe mode - reboot and tap F8 repeatedly on startup till you reach a windows option screen. arrow up to 'safe mode' > select log on with your usual account > see if the program will run
OK,

Leave that for now then.

Please do the following:

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Sorry it took so long.

ComboFix 09-06-18.02 - ccastaneda 06/19/2009 15:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1407.1000 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\driver
c:\winnt\system32\drivers\UACmarnnawaadhdhvi.sys
c:\winnt\system32\UACafwacegfmwqepje.dll
c:\winnt\system32\UACccfpbklocnocvdv.dll
c:\winnt\system32\UACiahkbmhdbeguqxo.log
c:\winnt\system32\UACjgsbjvsqbntvkvn.log
c:\winnt\system32\UACjhpvnywhisgtghm.dat
c:\winnt\system32\UACojmvsebfujpmkkj.dll
c:\winnt\system32\UACosrxhayfidupytt.dll
c:\winnt\system32\UACtgtlxomrlmjbrxh.log
c:\winnt\system32\UACwewynrojcmswjis.dll
c:\program files\driver\driver.sys
c:\winnt\system32\drivers\UACmarnnawaadhdhvi.sys
c:\winnt\system32\lenumenu.dll
c:\winnt\system32\mdm.exe
c:\winnt\system32\UACafwacegfmwqepje.dll
c:\winnt\system32\UACccfpbklocnocvdv.dll
c:\winnt\system32\UACiahkbmhdbeguqxo.log
c:\winnt\system32\uacinit.dll
c:\winnt\system32\UACjgsbjvsqbntvkvn.log
c:\winnt\system32\UACjhpvnywhisgtghm.dat
c:\winnt\system32\UACojmvsebfujpmkkj.dll
c:\winnt\system32\UACosrxhayfidupytt.dll
c:\winnt\system32\UACtgtlxomrlmjbrxh.log
c:\winnt\system32\UACwewynrojcmswjis.dll
c:\winnt\Web\default.htt

c:\winnt\system32\proquota.exe was missing
Restored copy from - c:\winnt\ServicePackFiles\i386\proquota.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys
——-\Legacy_BOONTY_GAMES
——-\Legacy_DRIVER
——-\Legacy_DRIVERDRV
——-\Service_Boonty Games
——-\Service_driver
——-\Service_driverdrv
——-\Service_IAS


((((((((((((((((((((((((( Files Created from 2009-05-19 to 2009-06-19 )))))))))))))))))))))))))))))))
.

2009-06-19 22:22 . 2008-04-14 00:12 50176 -c–a-w- c:\winnt\system32\dllcache\proquota.exe
2009-06-19 22:22 . 2008-04-14 00:12 50176 —-a-w- c:\winnt\system32\proquota.exe
2009-06-19 16:44 . 2009-06-19 22:12 ——– d—–w- c:\winnt\LMI6.tmp
2009-06-18 22:18 . 2009-06-18 22:18 47616 —-a-w- c:\winnt\soc_1245363526.exe
2009-06-18 22:18 . 2009-06-18 22:18 2 —-a-w- c:\winnt\010112010146118114.dat
2009-06-15 04:10 . 2009-02-12 23:04 876144 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d8203.vdb\navex15.sys
2009-06-15 04:10 . 2009-02-12 23:04 89104 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d8203.vdb\naveng.sys
2009-06-15 04:10 . 2009-02-12 23:03 1181040 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d8203.vdb\navex32a.dll
2009-06-15 04:10 . 2009-02-12 23:03 177520 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d8203.vdb\naveng32.dll
2009-06-15 04:10 . 2009-06-01 08:00 259368 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d8203.vdb\ecmsvr32.dll
2009-06-15 04:10 . 2009-02-18 19:41 2414128 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d8203.vdb\cceraser.dll
2009-06-15 04:10 . 2009-02-06 19:26 101936 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d8203.vdb\ERASER.sys
2009-06-15 04:10 . 2009-02-06 19:26 371248 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d8203.vdb\eeCtrl.sys
2009-06-15 04:09 . 2009-06-14 08:00 259368 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d9c04.vdb\ecmsvr32.dll
2009-06-15 04:09 . 2009-02-18 19:41 2414128 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d9c04.vdb\cceraser.dll
2009-06-15 04:09 . 2009-02-12 23:04 876144 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d9c04.vdb\navex15.sys
2009-06-15 04:09 . 2009-02-12 23:04 89104 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d9c04.vdb\naveng.sys
2009-06-15 04:09 . 2009-02-12 23:03 1181040 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d9c04.vdb\navex32a.dll
2009-06-15 04:09 . 2009-02-12 23:03 177520 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d9c04.vdb\naveng32.dll
2009-06-15 04:09 . 2009-02-06 19:26 101936 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d9c04.vdb\ERASER.sys
2009-06-15 04:09 . 2009-02-06 19:26 371248 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\I2_LDVP.VDB\vd2d9c04.vdb\eeCtrl.sys
2009-06-12 22:09 . 2009-06-12 22:09 152576 —-a-w- c:\documents and settings\ccastaneda\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-09 18:16 . 2007-01-18 17:24 26496 —-a-r- c:\winnt\system32\drivers\RimSerial.sys
2009-06-09 18:16 . 2009-06-09 18:16 65536 —-a-r- c:\documents and settings\ccastaneda\Application Data\Microsoft\Installer\{02807340-8FA2-44B6-ABA1-E443E4FF0A20}\ARPPRODUCTICON.exe
2009-06-09 18:16 . 2009-06-09 18:16 ——– d—–w- c:\program files\Verizon Wireless
2009-06-09 18:16 . 2009-06-09 18:16 ——– d—–w- c:\program files\Common Files\Research in Motion
2009-06-05 23:44 . 2009-06-05 23:44 ——– d–h–w- c:\winnt\PIF
2009-06-05 23:05 . 2009-06-19 20:12 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-05 22:57 . 2009-06-05 22:57 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\SerialPortTerminal
2009-06-05 22:38 . 2009-06-05 22:38 367160 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-05 21:45 . 2009-06-05 21:45 ——– d—–w- C:\VundoFix Backups
2009-06-05 21:40 . 2009-06-05 21:40 137728 —-a-w- c:\temp\VundoFix.exe
2009-06-05 21:25 . 2009-05-07 07:04 157712 —-a-w- c:\winnt\system32\drivers\tmcomm.sys
2009-06-05 18:54 . 2009-06-05 18:54 ——– d—–w- c:\documents and settings\ccastaneda\.housecall6.6
2009-06-05 18:14 . 2009-06-05 18:14 ——– d—–w- c:\program files\Windows Media Connect 2
2009-06-05 18:11 . 2009-06-05 18:12 ——– d—–w- c:\winnt\system32\drivers\UMDF
2009-06-05 18:11 . 2009-06-05 18:11 ——– d—–w- c:\winnt\system32\LogFiles
2009-06-05 17:23 . 2009-06-05 17:21 3371384 —-a-w- c:\temp\stuff.exe
2009-06-05 17:08 . 2009-06-05 22:36 ——– d—–w- c:\winnt\LMI13.tmp
2009-05-28 00:17 . 2008-10-16 21:06 268648 —-a-w- c:\winnt\system32\mucltui.dll
2009-05-27 22:10 . 2009-05-27 22:10 ——– d—–w- c:\winnt\system32\scripting
2009-05-27 22:10 . 2009-05-27 22:10 ——– d—–w- c:\winnt\l2schemas
2009-05-27 22:10 . 2009-05-27 22:10 ——– d—–w- c:\winnt\system32\en
2009-05-27 19:22 . 2009-05-27 19:22 ——– d—–w- c:\documents and settings\ccastaneda\Local Settings\Application Data\SerialPortTerminal
2009-05-27 19:16 . 2009-05-27 19:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Bluetooth
2009-05-27 19:15 . 2009-05-27 19:15 ——– d—–w- c:\program files\IVT Corporation
2009-05-27 19:13 . 2009-05-27 19:13 ——– d—–w- c:\program files\TickerCom
2009-05-27 09:35 . 2009-04-29 04:55 52224 -c—-w- c:\winnt\system32\dllcache\msfeedsbs.dll
2009-05-27 09:35 . 2009-04-29 04:55 459264 -c—-w- c:\winnt\system32\dllcache\msfeeds.dll
2009-05-27 09:35 . 2009-04-29 04:55 268288 -c—-w- c:\winnt\system32\dllcache\iertutil.dll
2009-05-27 09:35 . 2009-04-28 09:05 13824 -c—-w- c:\winnt\system32\dllcache\ieudinit.exe
2009-05-27 09:35 . 2009-04-29 04:55 6066176 -c—-w- c:\winnt\system32\dllcache\ieframe.dll
2009-05-27 09:35 . 2009-04-29 04:55 63488 -c—-w- c:\winnt\system32\dllcache\icardie.dll
2009-05-27 09:35 . 2009-04-29 04:55 383488 -c—-w- c:\winnt\system32\dllcache\ieapfltr.dll
2009-05-27 09:35 . 2008-07-09 14:25 2455488 -c—-w- c:\winnt\system32\dllcache\ieapfltr.dat
2009-05-27 08:40 . 2009-05-27 08:40 ——– d—–w- c:\winnt\system32\XPSViewer
2009-05-27 08:40 . 2009-05-27 08:40 ——– d—–w- c:\program files\MSBuild
2009-05-27 08:40 . 2009-05-27 08:40 ——– d—–w- c:\program files\Reference Assemblies
2009-05-27 08:39 . 2008-07-06 12:06 89088 -c—-w- c:\winnt\system32\dllcache\filterpipelineprintproc.dll
2009-05-27 08:39 . 2008-07-06 12:06 117760 ——w- c:\winnt\system32\prntvpt.dll
2009-05-27 08:39 . 2009-05-27 08:40 ——– d—–w- C:\6450dbb54ab7796580f9857ca0
2009-05-27 08:39 . 2008-07-06 12:06 575488 -c—-w- c:\winnt\system32\dllcache\xpsshhdr.dll
2009-05-27 08:39 . 2008-07-06 12:06 575488 ——w- c:\winnt\system32\xpsshhdr.dll
2009-05-27 08:39 . 2008-07-06 12:06 1676288 -c—-w- c:\winnt\system32\dllcache\xpssvcs.dll
2009-05-27 08:39 . 2008-07-06 12:06 1676288 ——w- c:\winnt\system32\xpssvcs.dll
2009-05-27 08:39 . 2008-07-06 10:50 597504 -c—-w- c:\winnt\system32\dllcache\printfilterpipelinesvc.exe
2009-05-27 08:35 . 2009-05-27 08:35 ——– d—–w- c:\program files\MSXML 6.0
2009-05-27 07:50 . 2009-05-27 07:50 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-05-27 07:43 . 2004-08-04 05:41 1041536 ——w- c:\winnt\system32\drivers\hsfdpsp2.sys
2009-05-27 07:43 . 2004-08-04 05:41 685056 ——w- c:\winnt\system32\drivers\hsfcxts2.sys
2009-05-27 07:43 . 2004-08-04 05:41 220032 ——w- c:\winnt\system32\drivers\hsfbs2s2.sys
2009-05-27 07:09 . 2008-06-13 11:05 272128 -c—-w- c:\winnt\system32\dllcache\bthport.sys
2009-05-27 07:09 . 2008-06-13 11:05 272128 ——w- c:\winnt\system32\drivers\bthport.sys
2009-05-27 07:07 . 2008-12-11 10:57 333952 -c—-w- c:\winnt\system32\dllcache\srv.sys
2009-05-27 07:05 . 2008-10-24 11:21 455296 -c—-w- c:\winnt\system32\dllcache\mrxsmb.sys
2009-05-27 07:03 . 2008-10-15 16:34 337408 -c—-w- c:\winnt\system32\dllcache\netapi32.dll
2009-05-27 07:02 . 2008-05-03 11:55 2560 ——w- c:\winnt\system32\xpsp4res.dll
2009-05-27 07:02 . 2008-04-21 12:08 215552 -c—-w- c:\winnt\system32\dllcache\wordpad.exe
2009-05-27 06:41 . 2009-06-10 21:02 ——– d–h–w- c:\winnt\$hf_mig$
2009-05-27 06:19 . 2009-06-19 22:16 ——– d—–w- c:\winnt\system32\CatRoot2
2009-05-27 02:14 . 2009-05-21 18:33 410984 —-a-w- c:\winnt\system32\deploytk.dll
2009-05-27 02:12 . 2009-05-27 02:12 152576 —-a-w- c:\documents and settings\ccastaneda\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-26 20:55 . 2009-04-14 19:59 2967800 —-a-w- C:\mbam-setup.exe
2009-05-26 20:55 . 2009-05-15 20:19 3227248 —-a-w- C:\ccsetup219.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-19 22:28 . 2005-08-30 19:33 ——– d—–w- c:\program files\Symantec AntiVirus
2009-06-19 20:09 . 2008-06-06 21:55 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-19 17:37 . 2008-09-17 23:53 ——– d—–w- c:\program files\RemoteSupportManager
2009-06-12 22:10 . 2008-06-17 22:11 ——– d—–w- c:\program files\Java
2009-06-05 18:52 . 2007-03-23 16:29 1744 —-a-w- c:\winnt\system32\d3d9caps.dat
2009-05-27 23:03 . 2008-12-10 21:57 367160 —-a-w- c:\documents and settings\ccastaneda\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-27 22:12 . 2007-03-20 00:04 86315 —-a-w- c:\winnt\PCHEALTH\helpctr\OfflineCache\index.dat
2009-05-27 19:03 . 2009-05-08 20:53 ——– d—–w- c:\program files\MSN Games
2009-05-27 08:00 . 2009-03-11 18:44 ——– d—–w- c:\program files\Microsoft Works
2009-05-15 20:37 . 2008-06-06 22:09 1632 —-a-w- c:\winnt\system32\d3d8caps.dat
2009-05-14 21:24 . 2009-05-08 20:53 ——– d—–w- c:\program files\Oberon Media
2009-05-08 16:11 . 2009-05-08 15:49 ——– d—–w- c:\documents and settings\ccastaneda\Application Data\ZoomBrowser EX
2009-05-08 15:49 . 2009-05-08 15:47 ——– d—–w- c:\documents and settings\ccastaneda\Application Data\CameraWindowDC
2009-05-08 15:47 . 2009-05-08 15:47 ——– d—–w- c:\documents and settings\ccastaneda\Application Data\CANON INC
2009-05-08 15:32 . 2009-05-08 15:32 ——– d—–w- c:\program files\Common Files\Canon
2009-05-07 16:09 . 2009-01-07 06:51 ——– d—–w- c:\program files\Yahoo!
2009-05-07 15:32 . 2004-08-04 12:00 345600 —-a-w- c:\winnt\system32\localspl.dll
2009-04-30 23:45 . 2007-04-19 15:53 ——– d—–w- c:\program files\Google
2009-04-29 04:56 . 2004-08-04 12:00 827392 —-a-w- c:\winnt\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 12:00 78336 —-a-w- c:\winnt\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-04 12:00 1847168 —-a-w- c:\winnt\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 —-a-w- c:\winnt\system32\rpcrt4.dll
2009-03-26 02:23 . 2008-09-17 23:53 1618728 —-a-w- c:\winnt\system32\OpenSshPackage.EXE
2009-03-26 02:23 . 2009-03-26 02:23 983793 —-a-w- c:\winnt\system32\VNCSetup.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-06-14 282624]
"ctfmon.exe"="c:\winnt\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"*LogMeInRescue_332824324"="c:\winnt\LMI14.tmp\lmi_rescue.exe" [2009-06-19 1667888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~2\VPTray.exe" [2005-06-24 85696]
"Synchronization Manager"="c:\winnt\system32\mobsync.exe" [2008-04-14 143360]
"NeroCheck"="c:\winnt\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-06-14 282624]
"NvCplDaemon"="c:\winnt\system32\NvCpl.dll" [2003-07-28 4841472]
"Remote Support Manager GUI"="c:\program files\RemoteSupportManager\rmgui.exe" [2007-07-07 452528]
"TickerCom"="c:\program files\TickerCom\TickerCom.exe" [2009-05-11 42496]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"nwiz"="nwiz.exe" - c:\winnt\system32\nwiz.exe [2003-07-28 323584]
"C-Media Mixer"="Mixer.exe" - c:\winnt\mixer.exe [2003-03-20 1855488]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\winnt\system32\NVMCTRAY.DLL" [2003-07-28 49152]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2008-04-14 214528]
"tscuninstall"="c:\winnt\system32\tscupgrd.exe" [2004-08-04 44544]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\winnt\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-7-28 25214]
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-5-17 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2002-02-15 17:51 24638 —-a-w- c:\winnt\system32\PCANotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0"
"UpdatesDisableNotify"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil_.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 DAInfo;Remote Support Manager Kernel Information Provider;c:\program files\RemoteSupportManager\DAinfo.sys [7/6/2007 7:02 PM 7040]
R2 DAMaint;Remote Support Manager Maintenance Service;c:\program files\RemoteSupportManager\DaMaint.exe [7/6/2007 7:02 PM 59312]
R2 DAtf;Remote Support Manager Token Factory;c:\program files\RemoteSupportManager\DAtf.sys [7/6/2007 7:02 PM 5120]
R2 DdsSched;Dds Scheduler Deamon;c:\program files\RDS\DdsSchedNT.exe [3/29/2007 12:28 PM 36864]
R2 RemoteSupportManager;Remote Support Manager Service;c:\program files\RemoteSupportManager\DesktopAuthority.exe [7/6/2007 7:02 PM 1230768]
R2 RsiSvc;Ridoc Server Information Service;c:\program files\RDS\RsiSvc.exe [3/29/2007 12:29 PM 65536]
R2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [6/23/2005 7:27 PM 124608]
R2 ScanRouterDriverV2;ScanRouterDriverV2;c:\program files\RDS\SrScanDr.exe [3/29/2007 12:29 PM 178688]
R2 SOption;SOption;c:\program files\RDS\SOption.exe [3/29/2007 12:29 PM 98304]
R2 Windows Agent Maintenance Service;Windows Agent Maintenance Service;c:\program files\N-able Technologies\Windows Agent\bin\AgentMaint.exe [5/29/2008 10:58 PM 28672]
R2 Windows Agent Service;Windows Agent Service;c:\program files\N-able Technologies\Windows Agent\bin\agent.exe [5/29/2008 10:58 PM 114688]
R3 DAmirr;DAmirr;c:\winnt\system32\drivers\DAmirr.sys [7/6/2007 7:02 PM 3200]
R3 EraserUtilDrv10910;EraserUtilDrv10910;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10910.sys [6/19/2009 11:31 AM 101936]
S3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [7/7/2003 1:17 PM 49776]
.
Contents of the 'Scheduled Tasks' folder

2009-06-19 c:\winnt\Tasks\movescans.job
- C:\movescans.bat [2007-03-29 20:40]

2009-06-19 c:\winnt\Tasks\Symantec NetDetect.job
- c:\progra~1\Symantec\LiveUpdate\NDETECT.EXE [2003-07-08 00:32]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-sglfb.sys
SafeBoot-tga.sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-19 15:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3304)
c:\winnt\LMI14.tmp\LMIRhook.000.dll
c:\winnt\LMI14.tmp\rahook.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\winnt\system32\LEXBCES.EXE
c:\winnt\system32\LEXPPS.EXE
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\winnt\system32\nvsvc32.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe
c:\documents and settings\ccastaneda\Local Settings\Temporary Internet Files\Content.IE5\L86JHKCS\Support-LogMeInRescue[1].exe
.
**************************************************************************
.
Completion time: 2009-06-19 15:34 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-19 22:34

Pre-Run: 13,234,343,936 bytes free
Post-Run: 13,194,125,312 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINNT="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

291 — E O F — 2009-06-10 21:02

Attachments:

Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/UACinit_dll_issue_possibly_t103959.html&view=findpost&p=569996#entry569996

collect::
c:\temp\stuff.exe
c:\winnt\soc_1245363526.exe
c:\winnt\010112010146118114.dat

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi,

Please do the following:

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

In your next reply please include
  • MBAM Log
  • Kaspersky report
Hi, Things are looking good, the items noted by Kaspersky are of no concern. Please post a fresh HJT log and describe how your computer is running now.
Hi,

Your log is clean, time to do some housekeeping now:

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI