This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan / Malware Removal - HELP NEEDED!

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Need some help on removing a trojan/malware from friends computer. Started after she opened an email and clicked a link for a video or something along those lines. I've scanned the system with Norton, which found PackGeneric.200 and Ad-Ware that is finding Win32Trojan.TDSS. Additionally, she had PAV.exe on the system and other virus that I've been able to remvoe but at this point, I'm stuck with Ad-ware reporting the Win32Trojan.TDSS and Malwarebytes Anti-Malware reporting Trojan.Agent & Rootkit.Trace and can't seem to remove those files, eventhough the aren't seachable on system or registry, they keep popping up.

Since I don't care much for Norton, and it was a eval kit, I've downloaded System Mechanic w/ anti-virus and firewall. Currently running is Anti-virus, firewall, Startup Guard (alson included w/ System Mechanic, and Ad-Ware (lavasoft). Below I'll post the latest and greatest logs from HJT, Malwarebytes, and the info from Ad-Ware. ** note during the process I had disabled a few start up items in msconfig, but prior to running tools this last time for posting I've enabled normal startup again.

**Also, downloaded and ran ATF-Cleaner prior running Malwarebytes and HJT and posting**

LOGS LISTED BELOW:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:42:34 AM, on 6/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iolo\System Mechanic Professional\SystemGuardAlerter.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\Jewel\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Documents and Settings\Jewel\Desktop\scan tools\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - HKLM\..\Run: [iolo AntiVirus] "C:\Program Files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe"
O4 - HKLM\..\Run: [SystemGuardAlerter] C:\Program Files\iolo\System Mechanic Professional\SystemGuardAlerter.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iolo Personal Firewall] "C:\Program Files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Jewel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 8460 bytes




Malwarebytes' Anti-Malware 1.37
Database version: 2263
Windows 5.1.2600 Service Pack 3

6/12/2009 8:54:42 AM
mbam-log-2009-06-12 (08-54-23).txt

Scan type: Quick Scan
Objects scanned: 89345
Time elapsed: 4 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> No action taken.



Ad-Ware Reporting the following: (sorry i've retyped this since I couldn't find the log and I'm posting from non infected system)

Family:
Win32Trojan.TDSS

Category
Malware

Quanity
4

TAI
10

Action
Recommended


Files:
c:\windows\system32\UACdxkfvbeyttppqmn.dll
c:\windows\system32\UACjctnirkrdoygeso.dll
c:\windows\system32\UACptnvtnmisjfvvka.dll

Process
\\?\globalroot\syste\.\cjctnirkrdoygeso.dll


I'd like to try and clean this as best as possible. I know at this point formatting would probably be the best option since it is reporting a Rootkit, but $$$ for her is quite tight and she has not CD for reinstall.

Thanks in advanced..
Update and additional information from reading the forums. During the removal of PackGeneric.200, it was advised to disable system restore, so that has been disabled. I've downloaded and run DSS and posted the log and attachment. DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 9:25:08.39 on Fri 06/12/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.576 [GMT 3:00] AV: iolo AntiVirus® *On-access scanning disabled* (Updated) {2565CEEE-6BDB-4A6D-AD6D-F682F2695014} FW: iolo Personal Firewall® *disabled* {38254411-9AEC-4967-913E-F892C2A4DF89} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe C:\Program Files\iolo\common\lib\ioloServiceManager.exe C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Internet Explorer\Iexplore.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxpers.exe C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE C:\WINDOWS\system32\igfxtray.exe C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe C:\Program Files\Skype\Phone\Skype.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\igfxext.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\DOCUME~1\Jewel\LOCALS~1\Temp\RtkBtMnt.exe C:\Program Files\iolo\System Mechanic Professional\AntiVirus\iAVEmailScanner.exe D:\Scan Tools\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com uDefault_Page_URL = hxxp://www.msn.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [Google Update] "c:\documents and settings\jewel\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [iolo AntiVirus] "c:\program files\iolo\system mechanic professional\antivirus\ioloAV.exe" mRun: [SystemGuardAlerter] c:\program files\iolo\system mechanic professional\SystemGuardAlerter.exe mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE mRun: [LaunchApp] Alaunch mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe mRun: [AzMixerSel] c:\program files\realtek\audio\installshield\AzMixerSel.exe mRun: [Alcmtr] ALCMTR.EXE mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [iolo Personal Firewall] "c:\program files\iolo\system mechanic professional\personal firewall\ioloFW.exe" StartupFolder: c:\docume~1\jewel\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\interv~1.lnk - c:\program files\intervideo\common\bin\WinCinemaMgr.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL LSP: c:\windows\system32\iavlsp.dll LSP: c:\program files\iolo\common\firewall\iFW_Xfilter.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper20073151.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-11 64160] R0 XPacket;iolo Personal Firewall Driver;c:\windows\system32\xpacket.sys [2009-6-10 39424] R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-6-10 600944] R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-6-10 600944] R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [2008-5-5 151936] S2 hchzlugy;hchzlugy;c:\windows\system32\drivers\wxtmq.sys –> c:\windows\system32\drivers\wxtmq.sys [?] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904] S2 mfyetl;mfyetl;c:\windows\system32\drivers\drqmusb.sys –> c:\windows\system32\drivers\drqmusb.sys [?] S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-12-28 96856] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-6-11 40160] S3 ute4ntgz;AVZ Kernel Driver;\??\c:\windows\system32\drivers\ute4ntgz.sys –> c:\windows\system32\drivers\ute4ntgz.sys [?] ============== File Associations =============== JSEFile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-06-12 02:04 124 a——- c:\windows\Control Panel.lnk 2009-06-11 23:39 –d—– c:\docume~1\jewel\applic~1\Malwarebytes 2009-06-11 23:32 15,688 a——- c:\windows\system32\lsdelete.exe 2009-06-11 23:25 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-06-11 23:23 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-06-11 23:23 –d—– c:\program files\Lavasoft 2009-06-11 19:50 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-11 19:50 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-11 19:50 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-11 19:50 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-11 19:06 –d—– c:\program files\oldMalwarebytes'Anti-Malware 2009-06-10 05:30 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll 2009-06-10 05:30 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2009-06-10 04:32 432 a——- c:\windows\system32\iolo.ini 2009-06-10 04:30 118,784 a——- c:\windows\system32\iavlsp.dll 2009-06-10 04:30 –d—– c:\program files\common files\Authentium 2009-06-10 04:29 39,424 a——- c:\windows\system32\xpacket.sys 2009-06-10 03:58 406 a——- c:\windows\system32\ioloBootDefrag.cfg 2009-06-10 03:56 940,896 a——- c:\windows\system32\Incinerator.dll 2009-06-10 03:56 28,672 a——- c:\windows\system32\iolobtdfg.exe 2009-06-10 03:56 8,192 a——- c:\windows\system32\smrgdf.exe 2009-06-10 03:56 –d—– c:\program files\iolo 2009-06-10 03:53 74,703 a——- c:\windows\system32\mfc45.dll 2009-06-10 03:49 –d—– c:\docume~1\jewel\applic~1\iolo 2009-06-10 03:49 –d—– c:\docume~1\alluse~1\applic~1\iolo 2009-06-09 08:07 –dsh— c:\documents and settings\jewel\IECompatCache 2009-06-01 20:02 –d—– c:\program files\common files\Uninstall 2009-05-27 22:27 –d—– c:\program files\common files\Hewlett-Packard 2009-05-27 22:26 46,592 a——- c:\windows\system32\hpzll43a.dll 2009-05-27 22:26 15,104 ac—— c:\windows\system32\dllcache\usbscan.sys 2009-05-27 22:26 15,104 a——- c:\windows\system32\drivers\usbscan.sys 2009-05-27 22:26 69,632 a——- c:\windows\system32\HPZipm12.exe 2009-05-27 22:26 65,536 a——- c:\windows\system32\HPZinw12.exe 2009-05-27 22:26 57,344 a——- c:\windows\system32\HPZisn12.dll 2009-05-27 22:26 278,584 a——- c:\windows\system32\HPZidr12.dll 2009-05-27 22:26 204,800 a——- c:\windows\system32\HPZipr12.dll 2009-05-27 22:26 94,208 a——- c:\windows\system32\HPZipt12.dll 2009-05-27 22:25 306,688 a——- c:\windows\IsUninst.exe 2009-05-27 22:02 103,193 a——- c:\windows\hpoins08.dat 2009-05-27 22:02 4,445 ——– c:\windows\hpomdl08.dat 2009-05-27 22:02 49,664 a——- c:\windows\system32\drivers\HPZid412.sys 2009-05-27 22:02 21,568 a——- c:\windows\system32\drivers\HPZius12.sys 2009-05-27 22:02 16,496 a——- c:\windows\system32\drivers\HPZipr12.sys 2009-05-27 22:02 614,400 a——- c:\windows\system32\hpotscl2.dll 2009-05-27 22:02 602,112 a——- c:\windows\system32\hpowiax2.dll 2009-05-27 22:02 282,624 a——- c:\windows\system32\HPZc3212.dll 2009-05-27 22:02 254,026 a——- c:\windows\system32\hpovst09.dll 2009-05-27 22:02 98,304 a——- c:\windows\system32\hpzjsn01.dll 2009-05-27 22:02 77,824 a——- c:\windows\system32\hpzids01.dll ==================== Find3M ==================== 2009-05-13 08:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-07 18:32 345,600 a——- c:\windows\system32\localspl.dll 2009-04-17 15:26 1,847,168 a——- c:\windows\system32\win32k.sys 2009-04-15 17:51 585,216 a——- c:\windows\system32\rpcrt4.dll 2008-08-15 20:51 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat 2008-12-28 12:57 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008122820081229\index.dat ============= FINISH: 9:27:39.18 ===============

Attachments:

Hi and welcome,

NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.

Please do the following:


Please re-enable system restore - an infected restore point is better than no restore point at all should things not go well.


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.
Sorry for the delay in posting back, but this weekend has been a little busy. I've gone back and enabled system restore, download GMER, but having issues running that tool. It's been extracted to the desktop, and extracts to GMER folder. When double clicking on the gmer.exe, I get a hour glass for a few seconds and then nothing. I've let it run for quite a while but nothing ever happens. You can see gmer.exe showing up in the task manager, but seems to not fully complete. Anythoughts?
Hi,

It's malware likely preventing it from running:

please do the following

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**



If this program won't run in normal mode - try it in safe mode
Below is the Combo-Fix Log file:

ComboFix 09-06-14.02 - Jewel 06/15/2009 17:14.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.712 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: iolo AntiVirus® *On-access scanning disabled* (Updated) {2565CEEE-6BDB-4A6D-AD6D-F682F2695014}
FW: iolo Personal Firewall® *disabled* {38254411-9AEC-4967-913E-F892C2A4DF89}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\TDSSosvd.dat
c:\windows\system32\autorun.ini
c:\windows\system32\drivers\UACctjlatvtmnbaqjk.sys
c:\windows\system32\UACapgcfqmtljoumug.log
c:\windows\system32\UACdjlsmlrngjutoyv.dll
c:\windows\system32\UACdxkfvbeyttppqmn.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiwfsgdhlawywnge.log
c:\windows\system32\UACjctnirkrdoygeso.dll
c:\windows\system32\UACkydxegimsucmems.log
c:\windows\system32\UACpktptuoxdxpwcmd.dat
c:\windows\system32\UACptnvtnmisjfvvka.dll
c:\windows\system32\UACyiyondgxnxuhfla.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.

2009-06-12 07:37 . 2009-06-12 07:37 ——– d—–w- c:\program files\Microsoft
2009-06-12 07:37 . 2009-06-12 07:37 ——– d—–w- c:\windows\Sun
2009-06-12 07:36 . 2009-06-12 07:36 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-12 07:36 . 2009-06-12 07:36 ——– d—–w- c:\program files\Java
2009-06-12 07:35 . 2009-06-12 07:35 152576 —-a-w- c:\documents and settings\Jewel\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-11 20:39 . 2009-06-11 20:39 ——– d—–w- c:\documents and settings\Jewel\Application Data\Malwarebytes
2009-06-11 20:32 . 2009-06-11 20:25 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-11 20:23 . 2009-06-11 20:23 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-11 20:23 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-11 20:23 . 2009-06-11 20:23 ——– d—–w- c:\program files\Lavasoft
2009-06-11 16:50 . 2009-05-26 10:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-11 16:50 . 2009-06-11 20:38 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-11 16:50 . 2009-06-11 16:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-11 16:50 . 2009-05-26 10:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-11 16:06 . 2009-06-11 16:49 ——– d—–w- c:\program files\oldMalwarebytes'Anti-Malware
2009-06-10 19:10 . 2009-06-10 19:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-10 02:30 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 02:30 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 01:30 . 2008-11-12 14:05 118784 —-a-w- c:\windows\system32\iavlsp.dll
2009-06-10 01:30 . 2009-06-10 01:30 ——– d—–w- c:\program files\Common Files\Authentium
2009-06-10 01:29 . 2007-10-02 09:41 39424 —-a-w- c:\windows\system32\xpacket.sys
2009-06-10 00:56 . 2009-06-10 00:56 ——– d—–w- c:\documents and settings\LocalService\Application Data\iolo
2009-06-10 00:56 . 2009-05-29 12:54 940896 —-a-w- c:\windows\system32\Incinerator.dll
2009-06-10 00:56 . 2009-02-17 08:31 28672 —-a-w- c:\windows\system32\iolobtdfg.exe
2009-06-10 00:56 . 2009-02-17 08:26 8192 —-a-w- c:\windows\system32\smrgdf.exe
2009-06-10 00:56 . 2009-06-10 00:56 ——– d—–w- c:\program files\iolo
2009-06-10 00:53 . 2009-06-10 00:53 74703 —-a-w- c:\windows\system32\mfc45.dll
2009-06-10 00:52 . 2009-06-10 00:52 44771760 —-a-w- c:\documents and settings\Jewel\Application Data\iolo\Installers\SystemMechanicPro.exe
2009-06-10 00:49 . 2009-06-10 01:29 ——– d—–w- c:\documents and settings\All Users\Application Data\iolo
2009-06-10 00:49 . 2009-06-10 00:52 ——– d—–w- c:\documents and settings\Jewel\Application Data\iolo
2009-06-09 07:03 . 2009-06-10 00:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-09 06:20 . 2009-06-09 06:20 152576 —-a-w- c:\documents and settings\Jewel\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-09 05:07 . 2009-06-09 05:07 ——– d-sh–w- c:\documents and settings\Jewel\IECompatCache
2009-06-05 04:39 . 2009-06-05 04:39 ——– d—–w- c:\documents and settings\Jewel\Local Settings\Application Data\Symantec
2009-06-01 17:02 . 2009-06-09 05:34 ——– d—–w- c:\program files\Common Files\Uninstall
2009-05-27 19:27 . 2009-05-27 19:27 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2009-05-27 19:26 . 2005-10-14 19:42 46592 —-a-w- c:\windows\system32\hpzll43a.dll
2009-05-27 19:26 . 2008-04-13 21:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2009-05-27 19:26 . 2008-04-13 21:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-05-27 19:26 . 2005-03-14 10:39 65536 —-a-w- c:\windows\system32\HPZinw12.exe
2009-05-27 19:26 . 2005-03-14 09:05 69632 —-a-w- c:\windows\system32\HPZipm12.exe
2009-05-27 19:26 . 2005-03-08 08:55 57344 —-a-w- c:\windows\system32\HPZisn12.dll
2009-05-27 19:26 . 2005-03-14 09:05 204800 —-a-w- c:\windows\system32\HPZipr12.dll
2009-05-27 19:26 . 2005-03-14 09:03 278584 —-a-w- c:\windows\system32\HPZidr12.dll
2009-05-27 19:26 . 2005-03-08 08:55 94208 —-a-w- c:\windows\system32\HPZipt12.dll
2009-05-27 19:25 . 1998-10-29 13:45 306688 —-a-w- c:\windows\IsUninst.exe
2009-05-27 19:02 . 2009-05-27 19:27 103193 —-a-w- c:\windows\hpoins08.dat
2009-05-27 19:02 . 2006-01-24 21:03 4445 ——w- c:\windows\hpomdl08.dat
2009-05-27 19:02 . 2005-10-28 01:24 21568 —-a-w- c:\windows\system32\drivers\HPZius12.sys
2009-05-27 19:02 . 2005-10-28 01:24 16496 —-a-w- c:\windows\system32\drivers\HPZipr12.sys
2009-05-27 19:02 . 2005-10-28 01:24 49664 —-a-w- c:\windows\system32\drivers\HPZid412.sys
2009-05-27 19:02 . 2005-10-28 23:11 602112 —-a-w- c:\windows\system32\hpowiax2.dll
2009-05-27 19:02 . 2005-10-28 23:11 614400 —-a-w- c:\windows\system32\hpotscl2.dll
2009-05-27 19:02 . 2005-10-28 23:11 254026 —-a-w- c:\windows\system32\hpovst09.dll
2009-05-27 19:02 . 2005-10-28 01:23 77824 —-a-w- c:\windows\system32\hpzids01.dll
2009-05-27 19:02 . 2005-10-28 01:23 282624 —-a-w- c:\windows\system32\HPZc3212.dll
2009-05-27 19:02 . 2005-09-09 23:28 98304 —-a-w- c:\windows\system32\hpzjsn01.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 13:57 . 2009-03-22 05:51 ——– d—–w- c:\documents and settings\Jewel\Application Data\Skype
2009-06-12 07:35 . 2008-08-15 18:11 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-11 02:10 . 2008-08-15 18:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-11 02:09 . 2008-08-15 18:18 ——– d—–w- c:\program files\Microsoft Works
2009-06-10 01:11 . 2009-01-26 23:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-10 00:24 . 2009-04-23 04:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-06-10 00:21 . 2009-01-26 23:05 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-10 00:21 . 2009-04-23 04:53 ——– d—–w- c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-10 00:05 . 2008-12-28 10:03 ——– d—–w- c:\program files\Google
2009-06-01 23:31 . 2009-04-23 04:45 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-05-27 19:26 . 2009-03-11 00:55 ——– d—–w- c:\program files\HP
2009-05-13 05:15 . 2007-08-14 01:54 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2008-04-15 03:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-23 04:48 . 2009-01-26 23:11 ——– d—–w- c:\documents and settings\Jewel\Application Data\Symantec
2009-04-23 04:45 . 2009-04-23 04:45 ——– d—–w- c:\documents and settings\All Users\Application Data\PCSettings
2009-04-17 12:26 . 2008-04-15 03:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2008-04-15 03:00 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-15 13:23 . 2009-04-15 13:23 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-04-11 15:53 . 2009-04-11 15:53 60592 —-a-w- c:\documents and settings\Cinnamon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-24 15:33 . 2009-03-24 15:33 237264 —-a-w- c:\documents and settings\Jewel\Application Data\Mozilla\plugins\npgoogletalk.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-11 24095528]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]
"Google Update"="c:\documents and settings\Jewel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-06 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"iolo AntiVirus"="c:\program files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe" [2009-05-13 1109856]
"SystemGuardAlerter"="c:\program files\iolo\System Mechanic Professional\SystemGuardAlerter.exe" [2009-05-29 364896]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-11 518488]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-05-22 425984]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-12 148888]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"iolo Personal Firewall"="c:\program files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe" [2009-05-13 1322848]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]

c:\documents and settings\Jewel\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Jewel\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Jewel\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\iolo\\System Mechanic Professional\\Personal Firewall\\ioloFW.exe"=
"c:\\Program Files\\iolo\\System Mechanic Professional\\AntiVirus\\ioloAV.exe"=
"c:\\Program Files\\iolo\\System Mechanic Professional\\AntiVirus\\iAVEmailScanner.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/11/2009 11:25 PM 64160]
R0 XPacket;iolo Personal Firewall Driver;c:\windows\system32\xpacket.sys [6/10/2009 4:29 AM 39424]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [6/10/2009 3:56 AM 600944]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [6/10/2009 3:56 AM 600944]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 10:06 PM 1005904]
R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [5/5/2008 7:01 PM 151936]
S2 hchzlugy;hchzlugy;c:\windows\system32\drivers\wxtmq.sys –> c:\windows\system32\drivers\wxtmq.sys [?]
S2 mfyetl;mfyetl;c:\windows\system32\drivers\drqmusb.sys –> c:\windows\system32\drivers\drqmusb.sys [?]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [12/28/2008 1:06 PM 96856]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/11/2009 7:50 PM 40160]
S3 ute4ntgz;AVZ Kernel Driver;\??\c:\windows\system32\Drivers\ute4ntgz.sys –> c:\windows\system32\Drivers\ute4ntgz.sys [?]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2009-06-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 20:25]

2009-06-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1329659041-3897513097-3082879975-1006.job
- c:\documents and settings\Jewel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-06 18:47]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-M3000Mnt - M3000Rmv.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\iavlsp.dll
LSP: c:\program files\iolo\Common\Firewall\iFW_Xfilter.dll
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-15 17:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(776)
c:\windows\system32\iavlsp.dll
c:\program files\iolo\Common\Firewall\iFW_Xfilter.dll
.
Completion time: 2009-06-15 17:22
ComboFix-quarantined-files.txt 2009-06-15 14:22

Pre-Run: 141,628,329,984 bytes free
Post-Run: 141,676,052,480 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

233 — E O F — 2009-06-13 00:00
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Trojan_Malware_Removal_HELP_NEEDED_t104012.html&view=findpost&p=568294#entry568294

KillAll::

Collect::
c:\windows\system32\drivers\wxtmq.sys 
c:\windows\system32\drivers\drqmusb.sys 
c:\windows\system32\Drivers\ute4ntgz.sys 

Driver::
ute4ntgz
mfyetl
hchzlugy

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComFix Log with your last instructions:

ComboFix 09-06-14.02 - Jewel 06/15/2009 18:06.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.649 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Jewel\Desktop\CFScript.txt
AV: iolo AntiVirus® *On-access scanning disabled* (Updated) {2565CEEE-6BDB-4A6D-AD6D-F682F2695014}
FW: iolo Personal Firewall® *disabled* {38254411-9AEC-4967-913E-F892C2A4DF89}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_HCHZLUGY
——-\Legacy_MFYETL
——-\Legacy_UTE4NTGZ
——-\Service_hchzlugy
——-\Service_mfyetl
——-\Service_ute4ntgz


((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.

2009-06-12 07:37 . 2009-06-12 07:37 ——– d—–w- c:\program files\Microsoft
2009-06-12 07:37 . 2009-06-12 07:37 ——– d—–w- c:\windows\Sun
2009-06-12 07:36 . 2009-06-12 07:36 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-12 07:36 . 2009-06-12 07:36 ——– d—–w- c:\program files\Java
2009-06-12 07:35 . 2009-06-12 07:35 152576 —-a-w- c:\documents and settings\Jewel\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-11 20:39 . 2009-06-11 20:39 ——– d—–w- c:\documents and settings\Jewel\Application Data\Malwarebytes
2009-06-11 20:32 . 2009-06-11 20:25 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-11 20:23 . 2009-06-11 20:23 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-11 20:23 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-11 20:23 . 2009-06-11 20:23 ——– d—–w- c:\program files\Lavasoft
2009-06-11 16:50 . 2009-05-26 10:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-11 16:50 . 2009-06-11 20:38 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-11 16:50 . 2009-06-11 16:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-11 16:50 . 2009-05-26 10:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-11 16:06 . 2009-06-11 16:49 ——– d—–w- c:\program files\oldMalwarebytes'Anti-Malware
2009-06-10 19:10 . 2009-06-10 19:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-10 02:30 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 02:30 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 01:30 . 2008-11-12 14:05 118784 —-a-w- c:\windows\system32\iavlsp.dll
2009-06-10 01:30 . 2009-06-10 01:30 ——– d—–w- c:\program files\Common Files\Authentium
2009-06-10 01:29 . 2007-10-02 09:41 39424 —-a-w- c:\windows\system32\xpacket.sys
2009-06-10 00:56 . 2009-06-10 00:56 ——– d—–w- c:\documents and settings\LocalService\Application Data\iolo
2009-06-10 00:56 . 2009-05-29 12:54 940896 —-a-w- c:\windows\system32\Incinerator.dll
2009-06-10 00:56 . 2009-02-17 08:31 28672 —-a-w- c:\windows\system32\iolobtdfg.exe
2009-06-10 00:56 . 2009-02-17 08:26 8192 —-a-w- c:\windows\system32\smrgdf.exe
2009-06-10 00:56 . 2009-06-10 00:56 ——– d—–w- c:\program files\iolo
2009-06-10 00:53 . 2009-06-10 00:53 74703 —-a-w- c:\windows\system32\mfc45.dll
2009-06-10 00:52 . 2009-06-10 00:52 44771760 —-a-w- c:\documents and settings\Jewel\Application Data\iolo\Installers\SystemMechanicPro.exe
2009-06-10 00:49 . 2009-06-10 01:29 ——– d—–w- c:\documents and settings\All Users\Application Data\iolo
2009-06-10 00:49 . 2009-06-10 00:52 ——– d—–w- c:\documents and settings\Jewel\Application Data\iolo
2009-06-09 07:03 . 2009-06-10 00:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-09 06:20 . 2009-06-09 06:20 152576 —-a-w- c:\documents and settings\Jewel\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-09 05:07 . 2009-06-09 05:07 ——– d-sh–w- c:\documents and settings\Jewel\IECompatCache
2009-06-05 04:39 . 2009-06-05 04:39 ——– d—–w- c:\documents and settings\Jewel\Local Settings\Application Data\Symantec
2009-06-01 17:02 . 2009-06-09 05:34 ——– d—–w- c:\program files\Common Files\Uninstall
2009-05-27 19:27 . 2009-05-27 19:27 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2009-05-27 19:26 . 2005-10-14 19:42 46592 —-a-w- c:\windows\system32\hpzll43a.dll
2009-05-27 19:26 . 2008-04-13 21:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2009-05-27 19:26 . 2008-04-13 21:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-05-27 19:26 . 2005-03-14 10:39 65536 —-a-w- c:\windows\system32\HPZinw12.exe
2009-05-27 19:26 . 2005-03-14 09:05 69632 —-a-w- c:\windows\system32\HPZipm12.exe
2009-05-27 19:26 . 2005-03-08 08:55 57344 —-a-w- c:\windows\system32\HPZisn12.dll
2009-05-27 19:26 . 2005-03-14 09:05 204800 —-a-w- c:\windows\system32\HPZipr12.dll
2009-05-27 19:26 . 2005-03-14 09:03 278584 —-a-w- c:\windows\system32\HPZidr12.dll
2009-05-27 19:26 . 2005-03-08 08:55 94208 —-a-w- c:\windows\system32\HPZipt12.dll
2009-05-27 19:25 . 1998-10-29 13:45 306688 —-a-w- c:\windows\IsUninst.exe
2009-05-27 19:02 . 2009-05-27 19:27 103193 —-a-w- c:\windows\hpoins08.dat
2009-05-27 19:02 . 2006-01-24 21:03 4445 ——w- c:\windows\hpomdl08.dat
2009-05-27 19:02 . 2005-10-28 01:24 21568 —-a-w- c:\windows\system32\drivers\HPZius12.sys
2009-05-27 19:02 . 2005-10-28 01:24 16496 —-a-w- c:\windows\system32\drivers\HPZipr12.sys
2009-05-27 19:02 . 2005-10-28 01:24 49664 —-a-w- c:\windows\system32\drivers\HPZid412.sys
2009-05-27 19:02 . 2005-10-28 23:11 602112 —-a-w- c:\windows\system32\hpowiax2.dll
2009-05-27 19:02 . 2005-10-28 23:11 614400 —-a-w- c:\windows\system32\hpotscl2.dll
2009-05-27 19:02 . 2005-10-28 23:11 254026 —-a-w- c:\windows\system32\hpovst09.dll
2009-05-27 19:02 . 2005-10-28 01:23 77824 —-a-w- c:\windows\system32\hpzids01.dll
2009-05-27 19:02 . 2005-10-28 01:23 282624 —-a-w- c:\windows\system32\HPZc3212.dll
2009-05-27 19:02 . 2005-09-09 23:28 98304 —-a-w- c:\windows\system32\hpzjsn01.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 15:12 . 2009-03-22 05:51 ——– d—–w- c:\documents and settings\Jewel\Application Data\Skype
2009-06-12 07:35 . 2008-08-15 18:11 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-11 02:10 . 2008-08-15 18:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-11 02:09 . 2008-08-15 18:18 ——– d—–w- c:\program files\Microsoft Works
2009-06-10 01:11 . 2009-01-26 23:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-10 00:24 . 2009-04-23 04:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-06-10 00:21 . 2009-01-26 23:05 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-10 00:21 . 2009-04-23 04:53 ——– d—–w- c:\documents and settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-06-10 00:05 . 2008-12-28 10:03 ——– d—–w- c:\program files\Google
2009-06-01 23:31 . 2009-04-23 04:45 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-05-27 19:26 . 2009-03-11 00:55 ——– d—–w- c:\program files\HP
2009-05-13 05:15 . 2007-08-14 01:54 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2008-04-15 03:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-23 04:48 . 2009-01-26 23:11 ——– d—–w- c:\documents and settings\Jewel\Application Data\Symantec
2009-04-23 04:45 . 2009-04-23 04:45 ——– d—–w- c:\documents and settings\All Users\Application Data\PCSettings
2009-04-17 12:26 . 2008-04-15 03:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2008-04-15 03:00 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-15 13:23 . 2009-04-15 13:23 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-04-11 15:53 . 2009-04-11 15:53 60592 —-a-w- c:\documents and settings\Cinnamon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-24 15:33 . 2009-03-24 15:33 237264 —-a-w- c:\documents and settings\Jewel\Application Data\Mozilla\plugins\npgoogletalk.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-15_14.20.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-15 15:10 . 2009-06-15 15:10 16384 c:\windows\temp\Perflib_Perfdata_ce0.dat
- 2009-06-15 14:07 . 2009-06-15 14:07 16384 c:\windows\Temp\Perflib_Perfdata_6bc.dat
+ 2009-06-15 15:10 . 2009-06-15 15:10 16384 c:\windows\temp\Perflib_Perfdata_6bc.dat
+ 2008-08-15 19:59 . 2009-06-15 14:51 63418 c:\windows\system32\perfc009.dat
- 2008-08-15 19:59 . 2009-06-15 14:11 63418 c:\windows\system32\perfc009.dat
+ 2008-08-15 19:59 . 2009-06-15 14:51 402974 c:\windows\system32\perfh009.dat
- 2008-08-15 19:59 . 2009-06-15 14:11 402974 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-11 24095528]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]
"Google Update"="c:\documents and settings\Jewel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-06 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"iolo AntiVirus"="c:\program files\iolo\System Mechanic Professional\AntiVirus\ioloAV.exe" [2009-05-13 1109856]
"SystemGuardAlerter"="c:\program files\iolo\System Mechanic Professional\SystemGuardAlerter.exe" [2009-05-29 364896]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-11 518488]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-05-22 425984]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-12 148888]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"iolo Personal Firewall"="c:\program files\iolo\System Mechanic Professional\Personal Firewall\ioloFW.exe" [2009-05-13 1322848]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]

c:\documents and settings\Jewel\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Jewel\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Jewel\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\iolo\\System Mechanic Professional\\Personal Firewall\\ioloFW.exe"=
"c:\\Program Files\\iolo\\System Mechanic Professional\\AntiVirus\\ioloAV.exe"=
"c:\\Program Files\\iolo\\System Mechanic Professional\\AntiVirus\\iAVEmailScanner.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/11/2009 11:25 PM 64160]
R0 XPacket;iolo Personal Firewall Driver;c:\windows\system32\xpacket.sys [6/10/2009 4:29 AM 39424]
R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [6/10/2009 3:56 AM 600944]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [6/10/2009 3:56 AM 600944]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 10:06 PM 1005904]
R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [5/5/2008 7:01 PM 151936]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [12/28/2008 1:06 PM 96856]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [6/11/2009 7:50 PM 40160]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2009-06-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 20:25]

2009-06-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1329659041-3897513097-3082879975-1006.job
- c:\documents and settings\Jewel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-06 18:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\iavlsp.dll
LSP: c:\program files\iolo\Common\Firewall\iFW_Xfilter.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-15 18:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\TEMP\SEP5.tmp 0 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(776)
c:\windows\system32\iavlsp.dll
c:\program files\iolo\Common\Firewall\iFW_Xfilter.dll

- - - - - - - > 'explorer.exe'(932)
c:\windows\system32\WININET.dll
c:\program files\iolo\Common\Lib\sguard.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Authentium\AntiVirus\dvpapi.exe
c:\program files\iolo\System Mechanic Professional\IoloSGCtrl.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\docume~1\Jewel\LOCALS~1\temp\RtkBtMnt.exe
c:\program files\iolo\System Mechanic Professional\AntiVirus\iAVEmailScanner.exe
.
**************************************************************************
.
Completion time: 2009-06-15 18:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-15 15:15
ComboFix2.txt 2009-06-15 14:22

Pre-Run: 141,655,441,408 bytes free
Post-Run: 141,586,755,584 bytes free

245 — E O F — 2009-06-13 00:00
Hi,

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report

Also, please describe in detail how your computer is running now and if there are any outstanding issues
The two scan logs posted below:

Malwarebytes' Anti-Malware 1.37
Database version: 2283
Windows 5.1.2600 Service Pack 3

6/15/2009 6:42:13 PM
mbam-log-2009-06-15 (18-42-13).txt

Scan type: Quick Scan
Objects scanned: 89020
Time elapsed: 3 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Monday, June 15, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Monday, June 15, 2009 11:27:39
Records in database: 2345167
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\

Scan statistics:
Files scanned: 37434
Threat name: 5
Infected objects: 12
Suspicious objects: 0
Duration of the scan: 01:09:21


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACctjlatvtmnbaqjk.sys.vir Infected: Rootkit.Win32.Agent.lhm 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACdjlsmlrngjutoyv.dll.vir Infected: Packed.Win32.Tdss.m 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACdxkfvbeyttppqmn.dll.vir Infected: Trojan.Win32.TDSS.adzz 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACjctnirkrdoygeso.dll.vir Infected: Trojan.Win32.TDSS.aegg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACptnvtnmisjfvvka.dll.vir Infected: Trojan.Win32.TDSS.adzx 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACyiyondgxnxuhfla.dll.vir Infected: Packed.Win32.Tdss.m 1
C:\System Volume Information\_restore{D24A3BE8-4CBB-48D0-81AD-ACAFA6A6C48B}\RP0\A0000001.sys Infected: Rootkit.Win32.Agent.lhm 1
C:\System Volume Information\_restore{D24A3BE8-4CBB-48D0-81AD-ACAFA6A6C48B}\RP0\A0000002.dll Infected: Packed.Win32.Tdss.m 1
C:\System Volume Information\_restore{D24A3BE8-4CBB-48D0-81AD-ACAFA6A6C48B}\RP0\A0000003.dll Infected: Packed.Win32.Tdss.m 1
C:\System Volume Information\_restore{D24A3BE8-4CBB-48D0-81AD-ACAFA6A6C48B}\RP0\A0000004.dll Infected: Trojan.Win32.TDSS.adzx 1
C:\System Volume Information\_restore{D24A3BE8-4CBB-48D0-81AD-ACAFA6A6C48B}\RP0\A0000005.dll Infected: Trojan.Win32.TDSS.adzz 1
C:\System Volume Information\_restore{D24A3BE8-4CBB-48D0-81AD-ACAFA6A6C48B}\RP0\A0000006.dll Infected: Trojan.Win32.TDSS.aegg 1

The selected area was scanned.


System appers to be running better, performance is better, quicker boot times, no hangs, except for running GMER.

Little more detail:

When first starting to work on the system, it was hanging / freezing requiring a hard reset of system. (this is not longer happening)
Boot times is improved greatly on the system.
Attempting to open IE 7, and browser was constantly redirected to other websites and or displaying a warning screen that the page unsecure
***see screen shot***
[external image: Posted Image]

Redirects and warning page in screenshot no longer appearing.
Web pages loading quickly.


Thanks,
Everything kaspersky found is in quarantine or an old system restore point which we will clear up shortly,


Please do the following:

Download Rooter.exe to your desktop

  • Doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows).
  • Post that in your next reply.


NEXT


Please run a fresh DDS log, so i can make sure you are clean.
Ran Rooter.exe and DSS. Rooter Log, DSS Log, and DSS attachment.txt are below. Rooter brought up a GUI and I selected scan, which generated that this report below. Hope that was right. Rooter.exe (v1.0) by Eric_71 ¨ Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3 32_bits - x86 Family 6 Model 28 Stepping 2, GenuineIntel ¨ C:\ [Fixed-NTFS] .. ( Total:144 Go - Free:131 Go ) ¨ Scan : 21:42.18 Path : C:\Documents and Settings\Jewel\Desktop\Rooter.exe User : Jewel ( Administrator -> YES ) ¨ ———————-\\ Processes ¨ Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (640) ______ \??\C:\WINDOWS\system32\csrss.exe (696) ______ \??\C:\WINDOWS\system32\winlogon.exe (720) ______ C:\WINDOWS\system32\services.exe (764) ______ C:\WINDOWS\system32\lsass.exe (776) ______ C:\WINDOWS\system32\svchost.exe (944) ______ C:\WINDOWS\system32\svchost.exe (988) ______ C:\WINDOWS\System32\svchost.exe (1036) ______ C:\WINDOWS\system32\svchost.exe (1144) ______ C:\WINDOWS\system32\svchost.exe (1168) ______ C:\WINDOWS\system32\spoolsv.exe (1428) ______ C:\WINDOWS\system32\svchost.exe (1504) ______ C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe (1572) ______ C:\Program Files\iolo\common\lib\ioloServiceManager.exe (1608) ______ C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe (1640) ______ C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (1712) ______ C:\Program Files\Java\jre6\bin\jqs.exe (1724) ______ C:\WINDOWS\system32\HPZipm12.exe (1760) ______ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (1792) ______ C:\WINDOWS\system32\svchost.exe (1864) ______ C:\WINDOWS\System32\alg.exe (212) ______ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (2756) ______ C:\WINDOWS\RTHDCPL.EXE (2772) ______ C:\WINDOWS\system32\igfxpers.exe (2796) ______ C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE (2868) ______ C:\WINDOWS\system32\hkcmd.exe (2920) ______ C:\Program Files\Java\jre6\bin\jusched.exe (2984) ______ C:\WINDOWS\system32\ctfmon.exe (3024) ______ C:\WINDOWS\system32\igfxsrvc.exe (3036) ______ C:\Documents and Settings\Jewel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (3084) ______ C:\WINDOWS\system32\igfxext.exe (3600) ______ C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe (2220) ______ C:\DOCUME~1\Jewel\LOCALS~1\Temp\RtkBtMnt.exe (2248) ______ C:\Program Files\iolo\System Mechanic Professional\AntiVirus\iAVEmailScanner.exe (3240) ______ C:\WINDOWS\explorer.exe (932) ______ C:\WINDOWS\system32\wscntfy.exe (2192) ______ C:\Documents and Settings\Jewel\Desktop\Rooter.exe (2076) ¨ ———————-\\ Device\Harddisk0\ ¨ \Device\Harddisk0 [Sectors : 63 x 512 Bytes] ¨ \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:5239471104) \Device\Harddisk0\Partition2 –[ MBR ]– (Start_Offset:5239503360 | Length:154799769600) ¨ ———————-\\ Scheduled Tasks ¨ C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1329659041-3897513097-3082879975-1006.job C:\WINDOWS\Tasks\SA.DAT ¨ ———————-\\ Registry ¨ ¨ ———————-\\ Files & Folders ¨ ———————-\\ Scan completed at 21:42.25 ¨ C:\Rooter$\Rooter_1.txt - (15/06/2009 | 21:42.25) DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 21:44:44.53 on Mon 06/15/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.643 [GMT 3:00] AV: iolo AntiVirus® *On-access scanning disabled* (Updated) {2565CEEE-6BDB-4A6D-AD6D-F682F2695014} FW: iolo Personal Firewall® *disabled* {38254411-9AEC-4967-913E-F892C2A4DF89} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe C:\Program Files\iolo\common\lib\ioloServiceManager.exe C:\Program Files\iolo\System Mechanic Professional\IoloSGCtrl.exe C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\alg.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxpers.exe C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Documents and Settings\Jewel\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\WINDOWS\system32\igfxext.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\DOCUME~1\Jewel\LOCALS~1\Temp\RtkBtMnt.exe C:\Program Files\iolo\System Mechanic Professional\AntiVirus\iAVEmailScanner.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\wscntfy.exe D:\Scan Tools\dds.pif C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [Google Update] "c:\documents and settings\jewel\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [iolo AntiVirus] "c:\program files\iolo\system mechanic professional\antivirus\ioloAV.exe" mRun: [SystemGuardAlerter] c:\program files\iolo\system mechanic professional\SystemGuardAlerter.exe mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE mRun: [LaunchApp] Alaunch mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe mRun: [AzMixerSel] c:\program files\realtek\audio\installshield\AzMixerSel.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [iolo Personal Firewall] "c:\program files\iolo\system mechanic professional\personal firewall\ioloFW.exe" StartupFolder: c:\docume~1\jewel\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\interv~1.lnk - c:\program files\intervideo\common\bin\WinCinemaMgr.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL LSP: c:\windows\system32\iavlsp.dll LSP: c:\program files\iolo\common\firewall\iFW_Xfilter.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper20073151.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-11 64160] R0 XPacket;iolo Personal Firewall Driver;c:\windows\system32\xpacket.sys [2009-6-10 39424] R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-6-10 600944] R2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2009-6-10 600944] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512] R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [2008-5-5 151936] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1005904] S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-12-28 96856] ============== File Associations =============== JSEFile=NOTEPAD.EXE %1 VBEFile=NOTEPAD.EXE %1 VBSFile=NOTEPAD.EXE %1 =============== Created Last 30 ================ 2009-06-15 21:42 –d—– C:\Rooter$ 2009-06-15 17:02 a-dshr– C:\cmdcons 2009-06-15 17:00 161,792 a——- c:\windows\SWREG.exe 2009-06-15 17:00 155,136 a——- c:\windows\PEV.exe 2009-06-15 17:00 98,816 a——- c:\windows\sed.exe 2009-06-12 10:37 –d—– c:\program files\Microsoft 2009-06-12 10:36 410,984 a——- c:\windows\system32\deploytk.dll 2009-06-12 10:36 73,728 a——- c:\windows\system32\javacpl.cpl 2009-06-12 02:04 124 a——- c:\windows\Control Panel.lnk 2009-06-11 23:39 –d—– c:\docume~1\jewel\applic~1\Malwarebytes 2009-06-11 23:32 15,688 a——- c:\windows\system32\lsdelete.exe 2009-06-11 23:25 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-06-11 23:23 -cd-h— c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-06-11 23:23 –d—– c:\program files\Lavasoft 2009-06-11 19:50 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-11 19:50 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-11 19:50 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-11 19:50 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-11 19:06 –d—– c:\program files\oldMalwarebytes'Anti-Malware 2009-06-10 05:30 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll 2009-06-10 05:30 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2009-06-10 04:32 432 a——- c:\windows\system32\iolo.ini 2009-06-10 04:30 118,784 a——- c:\windows\system32\iavlsp.dll 2009-06-10 04:30 –d—– c:\program files\common files\Authentium 2009-06-10 04:29 39,424 a——- c:\windows\system32\xpacket.sys 2009-06-10 03:58 406 a——- c:\windows\system32\ioloBootDefrag.cfg 2009-06-10 03:56 940,896 a——- c:\windows\system32\Incinerator.dll 2009-06-10 03:56 28,672 a——- c:\windows\system32\iolobtdfg.exe 2009-06-10 03:56 8,192 a——- c:\windows\system32\smrgdf.exe 2009-06-10 03:56 –d—– c:\program files\iolo 2009-06-10 03:53 74,703 a——- c:\windows\system32\mfc45.dll 2009-06-10 03:49 –d—– c:\docume~1\jewel\applic~1\iolo 2009-06-10 03:49 –d—– c:\docume~1\alluse~1\applic~1\iolo 2009-06-09 08:07 –dsh— c:\documents and settings\jewel\IECompatCache 2009-06-01 20:02 –d—– c:\program files\common files\Uninstall 2009-05-27 22:27 –d—– c:\program files\common files\Hewlett-Packard 2009-05-27 22:26 46,592 a——- c:\windows\system32\hpzll43a.dll 2009-05-27 22:26 15,104 ac—— c:\windows\system32\dllcache\usbscan.sys 2009-05-27 22:26 15,104 a——- c:\windows\system32\drivers\usbscan.sys 2009-05-27 22:26 69,632 a——- c:\windows\system32\HPZipm12.exe 2009-05-27 22:26 65,536 a——- c:\windows\system32\HPZinw12.exe 2009-05-27 22:26 57,344 a——- c:\windows\system32\HPZisn12.dll 2009-05-27 22:26 278,584 a——- c:\windows\system32\HPZidr12.dll 2009-05-27 22:26 204,800 a——- c:\windows\system32\HPZipr12.dll 2009-05-27 22:26 94,208 a——- c:\windows\system32\HPZipt12.dll 2009-05-27 22:25 306,688 a——- c:\windows\IsUninst.exe 2009-05-27 22:02 103,193 a——- c:\windows\hpoins08.dat 2009-05-27 22:02 4,445 ——– c:\windows\hpomdl08.dat 2009-05-27 22:02 49,664 a——- c:\windows\system32\drivers\HPZid412.sys 2009-05-27 22:02 21,568 a——- c:\windows\system32\drivers\HPZius12.sys 2009-05-27 22:02 16,496 a——- c:\windows\system32\drivers\HPZipr12.sys 2009-05-27 22:02 614,400 a——- c:\windows\system32\hpotscl2.dll 2009-05-27 22:02 602,112 a——- c:\windows\system32\hpowiax2.dll 2009-05-27 22:02 282,624 a——- c:\windows\system32\HPZc3212.dll 2009-05-27 22:02 254,026 a——- c:\windows\system32\hpovst09.dll 2009-05-27 22:02 98,304 a——- c:\windows\system32\hpzjsn01.dll 2009-05-27 22:02 77,824 a——- c:\windows\system32\hpzids01.dll ==================== Find3M ==================== 2009-05-13 08:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-07 18:32 345,600 a——- c:\windows\system32\localspl.dll 2009-04-17 15:26 1,847,168 a——- c:\windows\system32\win32k.sys 2009-04-15 17:51 585,216 a——- c:\windows\system32\rpcrt4.dll 2008-08-15 20:51 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat 2008-12-28 12:57 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008122820081229\index.dat ============= FINISH: 21:45:35.89 ===============
Hi,

you are clean :thumbup:

time for some housekeeping now:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

Should you wish to contribute to the ongoing development of ComboFix, donations are being accepted via PayPal.


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Ran the ComboFix /u option Downloaded and ran OTC (rebooted) Ran windows Update Downloaded and installed both Spywareblaster and SypwareGuard updated IE internet properties for Internet Zone Put WOT on the system Seems like all is good to go. Thank you so much and a donation will be coming this way!!!!!!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI