This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] ccSvcHst.exe & winlogon.exe error

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So when i start up i immediately get the ccsvchst.exe error but i can still log on and use my computer. if i hit "ok" or "cancle" then the second error pops up and then in a few seconds the computer gives me blue screen saying "fatal error…." and its restarts on its own. ive tried running in safe mode and it still pops up. i have semantic endpoint protection definition september 12 2009 r9. ive scanned with malewarebytes anti-malware and it detects viruses but when i go to delete it says my computer must restart to get rid of the virus and this is where i have a problem. because of those error messages the computer wont shutdown properly for anti-malware to completely remove it. im running windows xp sp3

[external image: Posted Image]
Hi dirtydozen12,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

  • Download DDS and save it to your desktop from
  • Here
  • here or
  • here.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click DDS icon to run the tool (may take up to 3 minutes to run)
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
  • We Need to check for Rootkits with RootRepeal
    • Download RootRepeal from one of the following locations and save it to your desktop.
    • Open [external image: Posted Image] on your desktop.
    • Click the [external image: Posted Image] tab.
    • Click the [external image: Posted Image] button.
    • In the Select Scan dialog, check
      [external image: Posted Image]
    • Push Ok
    • Check the box for your main system drive (Usually C:), and press Ok.
    • Allow RootRepeal to run a scan of your system. This may take some time.
    • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
  • Copy/paste the log (that you've previously saved to your desktop) from RootRepeal onto your post.

  • Copy/paste the DDS.txt log (that you've previously saved to your desktop) onto your post.

  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
hi, here are my reports ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/15 12:12 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys Address: 0x8F409000 Size: 851968 File Visible: No Signed: - Status: - Name: PCI_PNP9498 Image Path: \Driver\PCI_PNP9498 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0x8B3D6000 Size: 49152 File Visible: No Signed: - Status: - Name: sphg.sys Image Path: sphg.sys Address: 0xB9EA6000 Size: 1052672 File Visible: No Signed: - Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - SSDT ——————- #: 031 Function Name: NtConnectPort Status: Hooked by "" at address 0x8a131960 #: 041 Function Name: NtCreateKey Status: Hooked by "sphg.sys" at address 0xb9ea70e0 #: 071 Function Name: NtEnumerateKey Status: Hooked by "sphg.sys" at address 0xb9ec5ca4 #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "sphg.sys" at address 0xb9ec6032 #: 119 Function Name: NtOpenKey Status: Hooked by "sphg.sys" at address 0xb9ea70c0 #: 160 Function Name: NtQueryKey Status: Hooked by "sphg.sys" at address 0xb9ec610a #: 177 Function Name: NtQueryValueKey Status: Hooked by "sphg.sys" at address 0xb9ec5f8a #: 247 Function Name: NtSetValueKey Status: Hooked by "sphg.sys" at address 0xb9ec619c ==EOF== DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 12:11:10.79 on Tue 09/15/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1116 [GMT -4:00] AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} ============== Running Processes =============== C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Symantec AntiVirus\Smc.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\WINDOWS\system32\acs.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\TPHDEXLG.exe C:\WINDOWS\system32\TpKmpSVC.exe C:\WINDOWS\system32\vmnat.exe C:\WINDOWS\system32\vmnetdhcp.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\VMware\VMware Workstation\vmware-authd.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\PROGRA~1\COMMON~1\Stardock\sdmcp.exe C:\WINDOWS\Explorer.EXE c:\program files\symantec antivirus\smcgui.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe c:\program files\intel\intel matrix storage manager\iaanotif.exe c:\program files\synaptics\syntp\syntpenh.exe c:\program files\lenovo\hotkey\tposdsvc.exe c:\windows\system32\rundll32.exe c:\program files\lenovo\npdirect\tpfnf7sp.exe c:\progra~1\thinkpad\utilit~1\ezejmnap.exe c:\program files\synaptics\syntp\syntplpr.exe c:\program files\lenovo\hotkey\tponscr.exe c:\windows\system32\tpshocks.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE c:\program files\lenovo\zoom\tpscrex.exe c:\progra~1\thinkv~1\prdctr\lpmgr.exe c:\progra~1\thinkv~1\prdctr\lpmlchk.exe c:\program files\analog devices\core\smax4pnp.exe c:\program files\thinkpad\connectutilities\actray.exe c:\program files\thinkpad\connectutilities\acwlicon.exe c:\windows\system32\dla\dlactrlw.exe c:\program files\adobe\acrobat 8.0\acrobat\acrotray.exe c:\program files\ati technologies\ati.ace\core-static\ccc.exe c:\program files\microsoft office\office12\groovemonitor.exe c:\program files\itunes\ituneshelper.exe c:\program files\hp\hp software update\hpwuschd2.exe c:\program files\verizon\mccitrayapp.exe c:\program files\malwarebytes' anti-malware\mbamgui.exe c:\windows\system32\ctfmon.exe c:\program files\registry mechanic\regmech.exe c:\program files\hp\digital imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Program Files\iPod\bin\iPodService.exe c:\program files\hp\digital imaging\bin\hpqste08.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 c:\program files\mozilla firefox\firefox.exe c:\documents and settings\kayialess\desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.symantec.com/enterprise/security_response/index.jsp BHO: Adobe PDF Reader Link Helper: {015be035-984b-4381-a5d8-5ed7467f47ed} - Adobe PDF Reader Link Helper BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Aim6] uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\adobeupdater.exe" mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog mRun: [TPFNF7] c:\program files\lenovo\npdirect\TPFNF7SP.exe /r mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe mRun: [] mRun: [TpShocks] TpShocks.exe mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper mRun: [LPManager] c:\progra~1\thinkv~1\prdctr\LPMGR.exe mRun: [LPMailChecker] c:\progra~1\thinkv~1\prdctr\LPMLCHK.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [PSQLLauncher] "c:\program files\thinkvantage fingerprint software\launcher.exe" /startup mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Verizon_McciTrayApp] "c:\program files\verizon\McciTrayApp.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\docume~1\kayial~1\startm~1\programs\startup\vzacce~1.lnk - c:\program files\verizon wireless\vzaccess manager\VZAccess Manager.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1) mPolicies-explorer: NoWelcomeScreen = 1 (0x1) IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device… - c:\program files\thinkpad\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: c:\program files\vmware\vmware workstation\vsocklib.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233088646327 DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233088293627 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://sdlc-esd.sun.com/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?AuthParam=1213124615_47ae4b5016a4abdbf19812ab989a0ba6&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab&File=jinstall-6u6-windows-i586-jc.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: ACNotify - ACNotify.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: MCPClient - c:\progra~1\common~1\stardock\mcpstub.dll Notify: psfus - c:\windows\system32\psqlpwd.dll Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\MCPCore.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll LSA: Notification Packages = scecli ACGina psqlpwd ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\kayial~1\applic~1\mozilla\firefox\profiles\czvyun4n.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\documents and settings\kayialess\application data\mozilla\firefox\profiles\czvyun4n.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071302000002.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll ============= SERVICES / DRIVERS =============== R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2007-10-16 103472] R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2007-10-16 19504] R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2008-6-10 11520] R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2008-6-10 4224] R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2008-6-10 4442] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-4-21 108392] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-4-21 232720] R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2007-8-14 10896] R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2008-10-28 54960] R3 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-4-21 108392] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-10 102448] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-4-21 19096] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090903.002\NAVENG.SYS [2009-9-3 84912] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090903.002\NAVEX15.SYS [2009-9-3 1323568] R3 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec antivirus\Rtvscan.exe [2009-4-21 2440120] R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-5-22 30336] R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [2008-6-10 57344] S0 fxef;fxef;c:\windows\system32\drivers\rxhol.sys –> c:\windows\system32\drivers\rxhol.sys [?] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-11-18 23888] S3 Smcinst;Symantec Auto-upgrade Agent;c:\program files\symantec antivirus\smclu\setup\smcinst.exe –> c:\program files\symantec antivirus\smclu\setup\smcinst.exe [?] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-4-21 79888] S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\vboxnetflt.sys –> c:\windows\system32\drivers\VBoxNetFlt.sys [?] =============== Created Last 30 ================ 2009-09-15 12:06 191,768 a——- c:\windows\system32\AcroIEHelpe.dll 2009-09-13 15:00 61,440 a——- c:\windows\system32\drivers\kvmvmuz.sys 2009-09-11 12:13 554 ——– c:\windows\system32\liveupdt.tri 2009-09-11 11:43 22 a——- c:\windows\system32\user.cfg 2009-09-11 11:41 2,267 ——– c:\windows\system32\liveupdt.sig 2009-09-11 11:41 518 ——– c:\windows\system32\liveupdt.grd 2009-09-10 12:39 35 a——- c:\windows\system32\urhtps.dat 2009-09-10 11:37 112 a——- c:\windows\system32\srvblck2.tmp 2009-09-10 11:33 –d—– c:\windows\system32\cock 2009-09-03 14:25 –d—– c:\windows\system32\xmldm 2009-09-03 14:25 –d—– c:\windows\system32\UAs 2009-09-03 13:21 993,792 a——- c:\windows\system32\nsysk.ini 2009-09-03 13:21 989,696 a——- c:\windows\system32\osysk.dat 2009-09-03 13:21 830,464 a——- c:\windows\system32\nsysw.ini 2009-09-03 13:21 826,368 a——- c:\windows\system32\osysw.dat 2009-09-03 13:21 22,568 a——- c:\windows\system32\wincode.dat 2009-09-03 13:21 21,504 a——- c:\windows\system32\nsysp.ini 2009-09-03 13:21 17,408 a——- c:\windows\system32\osysp.dat 2009-09-03 13:21 6,394 a——- c:\windows\system32\krncode.dat 2009-09-03 13:21 1,575 a——- c:\windows\system32\pwrcode.dat 2009-09-03 13:21 45,768 a——- c:\windows\system32\shifld2.old 2009-08-18 16:11 46,640 a——- c:\windows\system32\msln.exe 2009-08-18 16:11 46,640 a——- c:\windows\system32\msln(2).exe ==================== Find3M ==================== 2009-09-13 15:00 184 a——- c:\program files\ibezt.txt 2009-09-11 11:42 21,504 a——- c:\windows\system32\powrprof.dll 2009-09-11 11:42 830,464 a——- c:\windows\system32\wininet.dll 2009-09-03 13:21 993,792 a——- c:\windows\system32\sysk.tmp 2009-09-03 13:21 830,464 a——- c:\windows\system32\sysw.tmp 2009-09-03 13:21 21,504 a——- c:\windows\system32\sysp.tmp 2009-08-03 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-03 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-05-22 17:51 61,224 a——- c:\documents and settings\kayialess\GoToAssistDownloadHelper.exe 2008-06-30 12:31 32,768 a–sh— c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\userdata\index.dat 2008-07-02 13:50 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat ============= FINISH: 12:11:22.71 ===============

Attachments:

dirtydozen12,

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
dirtydozen12,

Let's whittle things down a little.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I can only start in safe mode with networking now. when i try to start up normally it just keeps loading at the log in screen. I use Malwarebytes' Anti-Malware and have the most updated version.

Malwarebytes' Anti-Malware 1.41
Database version: 2812
Windows 5.1.2600 Service Pack 3 (Safe Mode)

9/16/2009 1:06:26 PM
mbam-log-2009-09-16 (12-20-47).txt

Scan type: Quick Scan
Objects scanned: 122748
Time elapsed: 3 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\AcroIEHelpe.dll (Trojan.Banker) -> No action taken.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:22:37 PM, on 9/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Smc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\PROGRA~1\COMMON~1\Stardock\sdmcp.exe
C:\WINDOWS\Explorer.EXE
c:\program files\symantec antivirus\smcgui.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
c:\program files\trend micro\hijackthis\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.symantec.com/enterprise/securit…ponse/index.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.206.201.8 system-guard2009.microsoft.com
O1 - Hosts: 91.206.201.8 system-guard2009.com
O1 - Hosts: 91.206.201.8 www.system-guard2009.com
O2 - BHO: Adobe PDF Reader Link Helper - {015BE035-984B-4381-A5D8-5ED7467F47ED} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] "C:\Program Files\Verizon\McciTrayApp.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [AdobeUpdater] "c:\program files\common files\adobe\updater5\adobeupdater.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: VZAccess Manager.lnk = C:\Program Files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233088646327
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233088293627
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD42/JSCDL/jre/6u…ows-i586-jc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\Software\..\Telephony: DomainName = wit.private
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS5\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS6\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS7\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS8\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS9\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS10\Services\Tcpip\Parameters: Domain = wit.private
O17 - HKLM\System\CS11\Services\Tcpip\Parameters: Domain = wit.private
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Symantec Auto-upgrade Agent (Smcinst) - Unknown owner - C:\Program Files\Symantec AntiVirus\SmcLU\Setup\smcinst.exe (file missing)
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\SNAC.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe

–
End of file - 15063 bytes
dirtydozen12,

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O1 - Hosts: ::1 localhost
      O2 - BHO: Adobe PDF Reader Link Helper - {015BE035-984B-4381-A5D8-5ED7467F47ED} - (no file)
      O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Then see if you can log in normally. If not, re-enter safe mode.

Then drag your copy of ComboFix to the recycle bin, download a fresh copy and try to run it per earlier instructions.
still cant start normally. i dont get the winlogin.exe application error anymore, only the other one. i can choose "ok" or "cancel" when the error pops up and the computer wont restart anymore but the error keeps coming back. I reinstalled the fresh copy of combofix and get the same errors for that as before. I also removed all three of the entries you listed above
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 4/21/2009 4:39:32 PM System Uptime: 9/16/2009 3:19:42 PM (1 hours ago) Motherboard: LENOVO | | 8741W9G Processor: Intel® Core™2 CPU T7600 @ 2.33GHz | None | 2327/167mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 149 GiB total, 106.269 GiB free. D: is CDROM () E: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: VMware Virtual Ethernet Adapter for VMnet1 Device ID: ROOT\VMWARE\0000 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet1 PNP Device ID: ROOT\VMWARE\0000 Service: VMnetAdapter Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: VMware Virtual Ethernet Adapter for VMnet8 Device ID: ROOT\VMWARE\0001 Manufacturer: VMware, Inc. Name: VMware Virtual Ethernet Adapter for VMnet8 PNP Device ID: ROOT\VMWARE\0001 Service: VMnetAdapter ==== System Restore Points =================== RP20: 4/30/2009 6:25:13 PM - System Checkpoint RP21: 5/1/2009 1:35:44 PM - Software Distribution Service 3.0 RP22: 5/3/2009 12:58:12 AM - System Checkpoint RP23: 5/4/2009 11:11:10 AM - System Checkpoint RP24: 5/5/2009 12:48:02 AM - Configured Microsoft Office Enterprise 2007 RP25: 5/6/2009 12:46:10 PM - System Checkpoint RP26: 5/7/2009 7:41:01 PM - System Checkpoint RP27: 5/10/2009 11:46:12 PM - System Checkpoint RP28: 5/12/2009 1:50:06 PM - System Checkpoint RP29: 5/13/2009 1:54:20 PM - System Checkpoint RP30: 5/16/2009 5:34:36 PM - System Checkpoint RP31: 5/18/2009 12:01:31 AM - System Checkpoint RP32: 5/19/2009 12:56:25 AM - System Checkpoint RP33: 5/19/2009 7:52:36 PM - SPTD setup V1.58 RP34: 5/20/2009 10:57:20 PM - System Checkpoint RP35: 5/21/2009 11:03:57 PM - System Checkpoint RP36: 5/24/2009 7:36:28 PM - System Checkpoint RP37: 5/27/2009 11:51:37 AM - System Checkpoint RP38: 5/28/2009 11:29:39 PM - System Checkpoint RP39: 5/30/2009 1:44:49 PM - System Checkpoint RP40: 5/31/2009 11:21:53 PM - System Checkpoint RP41: 6/3/2009 10:43:03 PM - System Checkpoint RP42: 6/5/2009 11:40:01 PM - System Checkpoint RP43: 6/12/2009 12:29:38 AM - System Checkpoint RP44: 6/15/2009 11:56:38 PM - System Checkpoint RP45: 6/17/2009 12:58:16 PM - System Checkpoint RP46: 6/18/2009 1:41:00 PM - System Checkpoint RP47: 7/1/2009 2:02:37 PM - System Checkpoint RP48: 7/20/2009 5:12:53 PM - System Checkpoint RP49: 7/20/2009 6:19:37 PM - Installed LG USB Modem driver RP50: 7/20/2009 6:20:55 PM - Installed LG USB Modem driver RP51: 7/24/2009 12:51:53 PM - System Checkpoint RP52: 7/29/2009 5:46:51 PM - System Checkpoint RP53: 8/20/2009 1:28:50 PM - System Checkpoint RP54: 9/10/2009 12:20:06 PM - Restore Operation RP55: 9/10/2009 12:33:48 PM - Restore Operation ==== Installed Programs ====================== 2007 Microsoft Office Suite Service Pack 1 (SP1) 32 Bit HP CIO Components Installer Add or Remove Adobe Creative Suite 3 Design Premium Adobe Acrobat 8 Professional Adobe Acrobat 8.1.2 Professional Adobe Acrobat 8.1.2 Security Update 1 (KB403742) Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe BridgeTalk Plugin CS3 Adobe Camera Raw 4.0 Adobe CMaps Adobe Color - Photoshop Specific Adobe Color Common Settings Adobe Color EU Extra Settings Adobe Color JA Extra Settings Adobe Color NA Recommended Settings Adobe Creative Suite 3 Design Premium Adobe Default Language CS3 Adobe Device Central CS3 Adobe Dreamweaver CS3 Adobe ExtendScript Toolkit 2 Adobe Extension Manager CS3 Adobe Flash CS3 Adobe Flash Player 10 Plugin Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Flash Video Encoder Adobe Fonts All Adobe Help Viewer CS3 Adobe Illustrator CS3 Adobe InDesign CS3 Adobe InDesign CS3 Icon Handler Adobe Linguistics CS3 Adobe MotionPicture Color Files Adobe PDF Library Files Adobe Photoshop CS3 Adobe Setup Adobe SING CS3 Adobe Stock Photos CS3 Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client Adobe Version Cue CS3 Server {ko_KR} Adobe WAS CS3 Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS3 AHV content for Acrobat and Flash AIM 6 AIO_Scan Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver Bonjour BufferChm Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Localization Chinese Standard Catalyst Control Center Localization Chinese Traditional Catalyst Control Center Localization Dutch Catalyst Control Center Localization French Catalyst Control Center Localization German Catalyst Control Center Localization Italian Catalyst Control Center Localization Japanese Catalyst Control Center Localization Korean Catalyst Control Center Localization Portuguese Catalyst Control Center Localization Spanish Catalyst Control Center Localization Swedish ccc-core-preinstall ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Dutch CCC Help English CCC Help French CCC Help German CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Portuguese CCC Help Spanish CCC Help Swedish Copy Critical Update for Windows Media Player 11 (KB959772) Crystal Reports Basic for Visual Studio 2008 CustomerResearchQFolder DAEMON Tools Toolbar DesktopX Destination Component DeviceDiscovery DeviceManagementQFolder DivX Web Player DJ_AIO_ProductContext DJ_AIO_Software DJ_AIO_Software_min eSupportQFolder F4100 F4100_doccd F4100_Help FileMaker Pro 5.5 GlassFish V2 UR2 Graboid Video 1.5 Graphing Calculator HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Microsoft Visual Studio 2008 Professional Edition - ENU (KB952241) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) HP Customer Participation Program 9.0 HP Deskjet All-In-One Software 9.0 HP Imaging Device Functions 9.0 HP Photosmart Essential 2.01 HP Photosmart Essential2.01 HP Smart Web Printing HP Solution Center 9.0 HP Update HPProductAssistant HPSSupply iDump (Build: 28) Intel® Network Connections 13.0.42.0 Intel® Matrix Storage Manager InterVideo Register Manager InterVideo WinDVD iTunes Java DB 10.3.1.4 Java™ 6 Update 6 Java™ SE Development Kit 6 Update 6 LG USB Modem driver LibUSB-Win32-0.1.12.1 LiveUpdate 3.3 (Symantec Corporation) Magic DVD Ripper V5.4.1 Magic ISO Maker v5.5 (build 0276) Malwarebytes' Anti-Malware MarketResearch MATLAB R2008a Microsoft .NET Compact Framework 2.0 SP2 Microsoft .NET Compact Framework 3.5 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Device Emulator version 3.0 - ENU Microsoft Document Explorer 2008 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office FrontPage 2003 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Live Add-in 1.3 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Project 2007 Service Pack 1 (SP1) Microsoft Office Project MUI (English) 2007 Microsoft Office Project Professional 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Visio 2007 Service Pack 1 (SP1) Microsoft Office Visio MUI (English) 2007 Microsoft Office Visio Professional 2007 Microsoft Office Visual Web Developer 2007 Microsoft Office Visual Web Developer MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server Compact 3.5 Design Tools ENU Microsoft SQL Server Compact 3.5 ENU Microsoft SQL Server Compact 3.5 for Devices ENU Microsoft SQL Server Database Publishing Wizard 1.2 Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries Microsoft Visual Studio 2005 Tools for Office Runtime Microsoft Visual Studio 2008 Professional Edition - ENU Microsoft Visual Studio Web Authoring Component Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense Microsoft Windows SDK for Visual Studio 2008 Tools Microsoft Windows SDK for Visual Studio 2008 Win32 Tools Mozilla ActiveX Control v1.7.12 Mozilla Firefox (3.0.13) MSDN Library for Visual Studio 2008 - ENU MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser NetBeans IDE 6.1 On Screen Display PDF Settings PeerGuardian 2.0 Presentation Director Productivity Center Supplement for ThinkPad PSSWCORE QK SMTP Server 3 QuickFreedom 1.2.0 QuickTime RecordNow Audio RecordNow Copy RecordNow Data Registry Mechanic 8.0 Scan Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB960003) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB959997) Security Update for Microsoft Office OneNote 2007 (KB950130) Security Update for Microsoft Office PowerPoint 2007 (KB951338) Security Update for Microsoft Office Project 2007 (KB949046) Security Update for Microsoft Office Publisher 2007 (KB950114) Security Update for Microsoft Office system 2007 (KB954326) Security Update for Microsoft Office system 2007 (KB956828) Security Update for Microsoft Office Visio 2007 (KB957831) Security Update for Microsoft Office Word 2007 (KB956358) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Skins SoftwarePassport SolutionCenter Sonic DLA Sonic Express Labeler SoundMAX SpywareBlaster 4.2 Status SUPERAntiSpyware Professional Symantec Endpoint Protection Taskbar Hide ThinkPad Bluetooth with Enhanced Data Rate Software ThinkPad EasyEject Utility ThinkPad FullScreen Magnifier ThinkPad Hotkey Features Setup ThinkPad Keyboard Customizer Utility ThinkPad Modem ThinkPad Power Management Driver ThinkPad Power Manager ThinkPad UltraNav Driver ThinkPad UltraNav Utility ThinkPad Wireless LAN Adapters Software (11a/b, 11b/g, 11a/b/g) ThinkVantage Access Connections ThinkVantage Active Protection System ThinkVantage Fingerprint Software 5.6 ThinkVantage Productivity Center Toolbox Total Video Converter 3.21 090220 TrayApp Tweak UI UnloadSupport Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office 2007 Help for Common Features (KB957244) Update for Microsoft Office Access 2007 Help (KB957241) Update for Microsoft Office Excel 2007 Help (KB957242) Update for Microsoft Office InfoPath 2007 Help (KB957243) Update for Microsoft Office OneNote 2007 Help (KB957245) Update for Microsoft Office Outlook 2007 (KB952142) Update for Microsoft Office Outlook 2007 Help (KB957246) Update for Microsoft Office PowerPoint 2007 Help (KB957247) Update for Microsoft Office Project 2007 Help (KB957248) Update for Microsoft Office Publisher 2007 Help (KB957249) Update for Microsoft Office Visio 2007 Help (KB957251) Update for Microsoft Office Word 2007 Help (KB957252) Update for Microsoft Script Editor Help (KB957253) Update for Outlook 2007 Junk Email Filter (kb968503) Update for Windows XP (KB943729) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951618-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VC80CRTRedist - 8.0.50727.762 Verizon Help and Support Tool VideoLAN VLC media player 0.8.6d VideoToolkit01 Visual Studio 2005 Tools for Office Second Edition Runtime Visual Studio Tools for the Office system 3.0 Runtime VMware Workstation VZAccess Manager WebFldrs XP WebReg Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows Mobile 5.0 SDK R2 for Pocket PC Windows Mobile 5.0 SDK R2 for Smartphone WinRAR archiver XML Paper Specification Shared Components Pack 1.0 ==== Event Viewer Messages From Past Week ======== 9/13/2009 1:34:57 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {B20E899D-B079-479D-A4DC-10F758D9CD9A} 9/13/2009 1:24:13 PM, error: Service Control Manager [7034] - The hpqcxs08 service terminated unexpectedly. It has done this 1 time(s). 9/13/2009 1:24:13 PM, error: Service Control Manager [7034] - The HP CUE DeviceDiscovery Service service terminated unexpectedly. It has done this 1 time(s). 9/12/2009 9:38:41 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'SrtETmp' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 9/10/2009 4:52:42 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. 9/10/2009 4:37:44 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 9/10/2009 4:35:36 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ANC eeCtrl Fips IBMTPCHK intelppm SRTSP SRTSPX SYMTDI TPHKDRV TPPWRIF TSMAPIP 9/10/2009 12:32:29 PM, error: PlugPlayManager [12] - The device 'Intel® PRO/1000 PL Network Connection' (PCI\VEN_8086&DEV_109A&SUBSYS_200117AA&REV_00\4&192ac53f&0&00E0) disappeared from the system without first being prepared for removal. 9/10/2009 12:32:29 PM, error: NETLOGON [5719] - No Domain Controller is available for domain WIT due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator. 9/10/2009 12:21:11 PM, error: Service Control Manager [7031] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service. 9/10/2009 12:21:11 PM, error: Service Control Manager [7031] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 200 milliseconds: Restart the service. 9/10/2009 11:24:41 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SRTSP 9/10/2009 11:23:59 AM, error: SRTSP [5] - Error loading Symantec real time Anti-Virus driver. 9/10/2009 11:23:59 AM, error: SRTSP [4] - Error loading virus definitions. ==== End Of File ===========================
yup sorry about that DDS (Ver_09-06-26.01) - NTFSx86 NETWORK Run by [removed] at 16:08:50.51 on Wed 09/16/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1564 [GMT -4:00] AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Symantec AntiVirus\Smc.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\PROGRA~1\COMMON~1\Stardock\sdmcp.exe C:\WINDOWS\Explorer.EXE c:\program files\symantec antivirus\smcgui.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe c:\program files\mozilla firefox\firefox.exe c:\documents and settings\kayialess\desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.symantec.com/enterprise/security_response/index.jsp BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_06\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: {050C8642-C1A9-480b-95A1-55FECB2B8C9A} - No File TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Aim6] uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\adobeupdater.exe" uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog mRun: [TPFNF7] c:\program files\lenovo\npdirect\TPFNF7SP.exe /r mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe mRun: [] mRun: [TpShocks] TpShocks.exe mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper mRun: [LPManager] c:\progra~1\thinkv~1\prdctr\LPMGR.exe mRun: [LPMailChecker] c:\progra~1\thinkv~1\prdctr\LPMLCHK.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [PSQLLauncher] "c:\program files\thinkvantage fingerprint software\launcher.exe" /startup mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Verizon_McciTrayApp] "c:\program files\verizon\McciTrayApp.exe" mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\docume~1\kayial~1\startm~1\programs\startup\vzacce~1.lnk - c:\program files\verizon wireless\vzaccess manager\VZAccess Manager.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1) mPolicies-explorer: NoWelcomeScreen = 1 (0x1) IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device… - c:\program files\thinkpad\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_06\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: c:\program files\vmware\vmware workstation\vsocklib.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233088646327 DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233088293627 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://sdlc-esd.sun.com/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?AuthParam=1213124615_47ae4b5016a4abdbf19812ab989a0ba6&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab&File=jinstall-6u6-windows-i586-jc.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: ACNotify - ACNotify.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: MCPClient - c:\progra~1\common~1\stardock\mcpstub.dll Notify: psfus - c:\windows\system32\psqlpwd.dll Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - c:\progra~1\common~1\stardock\MCPCore.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL LSA: Notification Packages = scecli ACGina psqlpwd ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\kayial~1\applic~1\mozilla\firefox\profiles\czvyun4n.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\documents and settings\kayialess\application data\mozilla\firefox\profiles\czvyun4n.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071302000002.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll ============= SERVICES / DRIVERS =============== R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [2007-10-16 103472] R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [2007-10-16 19504] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-4-21 108392] R3 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-4-21 108392] R3 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec antivirus\Rtvscan.exe [2009-4-21 2440120] R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [2008-6-10 57344] S0 fxef;fxef;c:\windows\system32\drivers\rxhol.sys –> c:\windows\system32\drivers\rxhol.sys [?] S1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2008-6-10 11520] S1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2008-6-10 4224] S1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2008-6-10 4442] S2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2007-8-14 10896] S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2008-10-28 54960] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-11-18 23888] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-10 102448] S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090903.002\NAVENG.SYS [2009-9-3 84912] S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090903.002\NAVEX15.SYS [2009-9-3 1323568] S3 Smcinst;Symantec Auto-upgrade Agent;c:\program files\symantec antivirus\smclu\setup\smcinst.exe –> c:\program files\symantec antivirus\smclu\setup\smcinst.exe [?] S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-5-22 30336] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-4-21 79888] S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\vboxnetflt.sys –> c:\windows\system32\drivers\VBoxNetFlt.sys [?] =============== Created Last 30 ================ 2009-09-16 12:02 –d—– c:\program files\Trend Micro 2009-09-16 11:58 112 a——- c:\windows\system32\srvblck2.tmp 2009-09-15 16:34 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-09-15 16:34 –d—– c:\program files\SUPERAntiSpyware 2009-09-15 16:34 –d—– c:\docume~1\kayial~1\applic~1\SUPERAntiSpyware.com 2009-09-15 16:34 –d—– c:\program files\common files\Wise Installation Wizard 2009-09-15 15:55 –d—– c:\program files\SpywareBlaster 2009-09-11 12:13 554 ——– c:\windows\system32\liveupdt.tri 2009-09-11 11:43 22 a——- c:\windows\system32\user.cfg 2009-09-11 11:41 2,267 ——– c:\windows\system32\liveupdt.sig 2009-09-11 11:41 518 ——– c:\windows\system32\liveupdt.grd 2009-09-10 11:33 –d—– c:\windows\system32\cock 2009-09-03 14:25 –d—– c:\windows\system32\xmldm 2009-09-03 14:25 –d—– c:\windows\system32\UAs 2009-09-03 13:21 993,792 a——- c:\windows\system32\nsysk.ini 2009-09-03 13:21 989,696 a——- c:\windows\system32\osysk.dat 2009-09-03 13:21 830,464 a——- c:\windows\system32\nsysw.ini 2009-09-03 13:21 826,368 a——- c:\windows\system32\osysw.dat 2009-09-03 13:21 22,568 a——- c:\windows\system32\wincode.dat 2009-09-03 13:21 21,504 a——- c:\windows\system32\nsysp.ini 2009-09-03 13:21 17,408 a——- c:\windows\system32\osysp.dat 2009-09-03 13:21 6,394 a——- c:\windows\system32\krncode.dat 2009-09-03 13:21 1,575 a——- c:\windows\system32\pwrcode.dat 2009-09-03 13:21 45,768 a——- c:\windows\system32\shifld2.old 2009-08-18 16:11 46,640 a——- c:\windows\system32\msln.exe 2009-08-18 16:11 46,640 a——- c:\windows\system32\msln(2).exe ==================== Find3M ==================== 2009-09-11 11:42 21,504 a——- c:\windows\system32\powrprof.dll 2009-09-11 11:42 830,464 a——- c:\windows\system32\wininet.dll 2009-09-10 14:54 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 14:53 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-05-22 17:51 61,224 a——- c:\documents and settings\kayialess\GoToAssistDownloadHelper.exe 2008-06-30 12:31 32,768 a–sh— c:\windows\system32\config\systemprofile\application data\microsoft\internet explorer\userdata\index.dat 2008-07-02 13:50 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat ============= FINISH: 16:09:21.65 ===============
dirtydozen12,

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Files
    c:\windows\system32\osysk.dat
    c:\windows\system32\osysw.dat
    c:\windows\system32\wincode.dat
    c:\windows\system32\osysp.dat
    c:\windows\system32\krncode.dat
    c:\windows\system32\pwrcode.dat
    c:\windows\system32\nsysp.ini
    c:\windows\system32\shifld2.old
    c:\windows\system32\nsysw.ini
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Then drag your copy of ComboFix to the recycle bin.

Download a new copy but this time save it to your desktop as WorkNow.com

Double click and attempt to run as before.
I dont have the application errors anymore but i havent tried running XP out of safemode yet. So far so good. =]

ComboFix 09-09-16.02 - kayialess 09/16/2009 23:09.1.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1634 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Worknow.com.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
ADS - system32: deleted 12 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
c:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
c:\recycler\S-1-5-21-1284193018-2690920046-2573575750-500
c:\recycler\S-1-5-21-1417001333-1409082233-682003330-1005
c:\recycler\S-1-5-21-1417001333-1409082233-682003330-500
c:\recycler\S-1-5-21-1717359693-725540966-1392451680-1005
c:\recycler\S-1-5-21-1717359693-725540966-1392451680-500
c:\recycler\S-1-5-21-2097178511-3723882698-4260316654-500
c:\recycler\S-1-5-21-2323265706-4101010762-3771514121-500
c:\recycler\S-1-5-21-3434858073-770328501-1186697724-500
c:\recycler\S-1-5-21-3981961388-1238095360-2153429229-1005
c:\recycler\S-1-5-21-3981961388-1238095360-2153429229-500
c:\recycler\S-1-5-21-4264208443-1597490366-951982877-1005
c:\recycler\S-1-5-21-4264208443-1597490366-951982877-500
c:\recycler\S-1-5-21-975613499-1138187149-3970294880-500
c:\windows\Installer\69d82.msp
c:\windows\run.log
c:\windows\system32\AutoRun.inf
c:\windows\system32\images
c:\windows\system32\images\toolbar\calendar.gif
c:\windows\system32\images\toolbar\crlogo.gif
c:\windows\system32\images\toolbar\export.gif
c:\windows\system32\images\toolbar\export_over.gif
c:\windows\system32\images\toolbar\exportd.gif
c:\windows\system32\images\toolbar\First.gif
c:\windows\system32\images\toolbar\first_over.gif
c:\windows\system32\images\toolbar\Firstd.gif
c:\windows\system32\images\toolbar\gotopage.gif
c:\windows\system32\images\toolbar\gotopage_over.gif
c:\windows\system32\images\toolbar\gotopaged.gif
c:\windows\system32\images\toolbar\grouptree.gif
c:\windows\system32\images\toolbar\grouptree_over.gif
c:\windows\system32\images\toolbar\grouptreed.gif
c:\windows\system32\images\toolbar\grouptreepressed.gif
c:\windows\system32\images\toolbar\Last.gif
c:\windows\system32\images\toolbar\last_over.gif
c:\windows\system32\images\toolbar\Lastd.gif
c:\windows\system32\images\toolbar\Next.gif
c:\windows\system32\images\toolbar\next_over.gif
c:\windows\system32\images\toolbar\Nextd.gif
c:\windows\system32\images\toolbar\Prev.gif
c:\windows\system32\images\toolbar\prev_over.gif
c:\windows\system32\images\toolbar\Prevd.gif
c:\windows\system32\images\toolbar\print.gif
c:\windows\system32\images\toolbar\print_over.gif
c:\windows\system32\images\toolbar\printd.gif
c:\windows\system32\images\toolbar\Refresh.gif
c:\windows\system32\images\toolbar\refresh_over.gif
c:\windows\system32\images\toolbar\refreshd.gif
c:\windows\system32\images\toolbar\Search.gif
c:\windows\system32\images\toolbar\search_over.gif
c:\windows\system32\images\toolbar\searchd.gif
c:\windows\system32\images\toolbar\up.gif
c:\windows\system32\images\toolbar\up_over.gif
c:\windows\system32\images\toolbar\upd.gif
c:\windows\system32\images\tree\begindots.gif
c:\windows\system32\images\tree\beginminus.gif
c:\windows\system32\images\tree\beginplus.gif
c:\windows\system32\images\tree\blank.gif
c:\windows\system32\images\tree\blankdots.gif
c:\windows\system32\images\tree\dots.gif
c:\windows\system32\images\tree\lastdots.gif
c:\windows\system32\images\tree\lastminus.gif
c:\windows\system32\images\tree\lastplus.gif
c:\windows\system32\images\tree\Magnify.gif
c:\windows\system32\images\tree\minus.gif
c:\windows\system32\images\tree\minusbox.gif
c:\windows\system32\images\tree\plus.gif
c:\windows\system32\images\tree\plusbox.gif
c:\windows\system32\images\tree\singleminus.gif
c:\windows\system32\images\tree\singleplus.gif
c:\windows\system32\UAs
c:\windows\system32\UAs\aim6_UAs001.dat
c:\windows\system32\UAs\aolsoftware_UAs001.dat
c:\windows\system32\UAs\Explorer_UAs001.dat
c:\windows\system32\UAs\firefox_UAs001.dat
c:\windows\system32\UAs\firefox_UAs002.dat
c:\windows\system32\UAs\hprbupdate_UAs001.dat
c:\windows\system32\UAs\hpwucli_UAs001.dat
c:\windows\system32\UAs\hpwucli_UAs002.dat
c:\windows\system32\UAs\hpwucli_UAs003.dat
c:\windows\system32\UAs\hpwucli_UAs004.dat
c:\windows\system32\UAs\LUCOMS~1_UAs001.dat
c:\windows\system32\UAs\LUCOMS~1_UAs002.dat
c:\windows\system32\UAs\LUCOMS~1_UAs003.dat
c:\windows\system32\UAs\LUCOMS~1_UAs004.dat
c:\windows\system32\UAs\LUCOMS~1_UAs005.dat
c:\windows\system32\UAs\LUCOMS~1_UAs006.dat
c:\windows\system32\UAs\LUCOMS~1_UAs007.dat
c:\windows\system32\UAs\LUCOMS~1_UAs008.dat
c:\windows\system32\UAs\LUCOMS~1_UAs009.dat
c:\windows\system32\UAs\LUCOMS~1_UAs010.dat
c:\windows\system32\UAs\LUCOMS~1_UAs011.dat
c:\windows\system32\UAs\LUCOMS~1_UAs012.dat
c:\windows\system32\UAs\LUCOMS~1_UAs013.dat
c:\windows\system32\UAs\LUCOMS~1_UAs014.dat
c:\windows\system32\UAs\LUCOMS~1_UAs015.dat
c:\windows\system32\UAs\LUCOMS~1_UAs016.dat
c:\windows\system32\UAs\LUCOMS~1_UAs017.dat
c:\windows\system32\UAs\LUCOMS~1_UAs018.dat
c:\windows\system32\UAs\LUCOMS~1_UAs019.dat
c:\windows\system32\UAs\LUCOMS~1_UAs020.dat
c:\windows\system32\UAs\LUCOMS~1_UAs021.dat
c:\windows\system32\UAs\LUCOMS~1_UAs022.dat
c:\windows\system32\UAs\LUCOMS~1_UAs023.dat
c:\windows\system32\UAs\LUCOMS~1_UAs024.dat
c:\windows\system32\UAs\LUCOMS~1_UAs025.dat
c:\windows\system32\UAs\mbam_UAs001.dat
c:\windows\system32\UAs\mbam_UAs002.dat
c:\windows\system32\UAs\mbam_UAs003.dat
c:\windows\system32\UAs\mbam_UAs004.dat
c:\windows\system32\UAs\McciBrowser_UAs001.dat
c:\windows\system32\UAs\McciBrowser_UAs002.dat
c:\windows\system32\UAs\McciBrowser_UAs003.dat
c:\windows\system32\UAs\Smc_UAs001.dat
c:\windows\system32\UAs\smupdate_UAs001.dat
c:\windows\system32\UAs\SUPERAntiSpyware_UAs001.dat
c:\windows\system32\UAs\wgatray_UAs001.dat

—– BITS: Possible infected sites —–

hxxp://witwsus.wit.private
Infected copy of c:\windows\system32\powrprof.dll was found and disinfected
Restored copy from - c:\system volume information\_restore{C7A74BFA-C672-4486-A207-C0D9A9138B5A}\RP53\A0028911.dll

Infected copy of c:\windows\system32\wininet.dll was found and disinfected
Restored copy from - c:\system volume information\_restore{C7A74BFA-C672-4486-A207-C0D9A9138B5A}\RP53\A0028912.dll

.
((((((((((((((((((((((((( Files Created from 2009-08-17 to 2009-09-17 )))))))))))))))))))))))))))))))
.

2009-09-17 02:53 . 2009-09-17 02:53 ——– d—–w- C:\_OTM
2009-09-16 16:02 . 2009-09-16 16:02 ——– d—–w- c:\program files\Trend Micro
2009-09-15 20:34 . 2009-09-15 20:34 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-15 20:34 . 2009-09-15 20:34 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-09-15 20:34 . 2009-09-15 20:34 ——– d—–w- c:\documents and settings\kayialess\Application Data\SUPERAntiSpyware.com
2009-09-15 20:34 . 2009-09-15 20:34 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-09-15 19:55 . 2009-09-15 20:08 ——– d—–w- c:\program files\SpywareBlaster
2009-09-10 15:33 . 2009-09-11 16:09 ——– d—–w- c:\windows\system32\cock
2009-09-03 18:25 . 2009-09-16 16:02 ——– d—–w- c:\windows\system32\xmldm
2009-08-18 20:11 . 2009-09-03 18:24 46640 —-a-w- c:\windows\system32\msln.exe
2009-08-18 20:11 . 2009-09-03 18:24 46640 —-a-w- c:\windows\system32\msln(2).exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-16 21:37 . 2009-05-02 04:43 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2009-09-16 19:17 . 2009-04-22 14:57 ——– d—–w- c:\documents and settings\NetworkService\Application Data\VMware
2009-09-16 19:17 . 2009-04-22 14:48 ——– d—–w- c:\documents and settings\All Users\Application Data\VMware
2009-09-16 16:02 . 2009-04-21 23:38 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-15 20:01 . 2009-04-21 23:41 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-13 02:40 . 2009-04-28 05:01 ——– d—–w- c:\documents and settings\kayialess\Application Data\uTorrent
2009-09-10 18:54 . 2009-04-21 23:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-04-21 23:38 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-25 02:10 . 2009-07-25 01:55 ——– d—–w- c:\program files\dvrfxe
2009-07-20 22:23 . 2009-07-20 22:23 ——– d—–w- c:\documents and settings\kayialess\Application Data\Smith Micro
2009-07-20 22:20 . 2009-07-20 22:20 ——– d—–w- c:\program files\Verizon Wireless
2009-07-20 22:19 . 2009-07-20 22:19 ——– d—–w- c:\program files\LG Electronics
2009-07-20 22:19 . 2008-06-10 14:31 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-29 20:29 . 2008-06-10 18:43 71752 —-a-w- c:\documents and settings\Default User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-01 21:02 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

——- Sigcheck ——-

[-] 2009-09-11 . FF9650BE501D152437001D21DD24727C . 993792 . . [5.1.2600.5781] . . c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2009-09-11 . FF9650BE501D152437001D21DD24727C . 993792 . . [5.1.2600.5781] . . c:\windows\$NtUninstallKB959426$\kernel32.dll
[-] 2009-09-11 . FF9650BE501D152437001D21DD24727C . 993792 . . [5.1.2600.5781] . . c:\windows\system32\kernel32.dll
[-] 2009-09-11 . FF9650BE501D152437001D21DD24727C . 993792 . . [5.1.2600.5781] . . c:\windows\system32\dllcache\kernel32.dll

[-] 2008-05-28 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
"AdobeUpdater"="c:\program files\common files\adobe\updater5\adobeupdater.exe" [2009-04-22 2356088]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-04 1994480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-07-04 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-04 1323008]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 66928]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2008-01-11 294912]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2008-01-11 208896]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-03-26 59680]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-04-27 243248]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 868352]
"LPManager"="c:\progra~1\THINKV~1\PrdCtr\LPMGR.exe" [2008-01-11 144728]
"LPMailChecker"="c:\progra~1\THINKV~1\PrdCtr\LPMLCHK.exe" [2008-01-11 124248]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-03-14 425984]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-03-14 126976]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-02-02 122940]
"PSQLLauncher"="c:\program files\ThinkVantage Fingerprint Software\launcher.exe" [2007-08-14 48904]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 623992]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-04-21 115560]
"QuickTime Task"="c:\program files\quicktime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2009-03-10 1553920]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2007-11-22 181536]

c:\documents and settings\Admin\Start Menu\Programs\Startup\
Shortcut to bg.lnk - c:\documents and settings\Admin\BGinfo\bg.bat [2008-6-11 34]

c:\documents and settings\kayialess\Start Menu\Programs\Startup\
VZAccess Manager.lnk - c:\program files\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [2009-7-20 1738032]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceStartMenuLogOff"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2005-01-31 19:13 49152 —-a-w- c:\progra~1\COMMON~1\stardock\MCPStub.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-08-14 19:54 89600 —-a-w- c:\windows\system32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 20:37 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2007-12-14 20:36 28672 —-a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2008-03-14 22:54 32768 —-a-w- c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ACGina psqlpwd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2746289630-3061505222-2800193894-17083\Scripts\Logon\0\0]
"Script"=\\wit.private\SysVol\wit.private\scripts\students.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2746289630-3061505222-2800193894-61192\Scripts\Logon\0\0]
"Script"=\\wit.private\SysVol\wit.private\scripts\students.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre1.6.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\QK SMTP Server 3\\QKSmtpServer3.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

R0 Shockprf;Shockprf;c:\windows\system32\drivers\ApsX86.sys [10/16/2007 6:33 PM 103472]
R0 TPDIGIMN;TPDIGIMN;c:\windows\system32\drivers\ApsHM86.sys [10/16/2007 6:32 PM 19504]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [6/10/2008 11:37 AM 57344]
S0 fxef;fxef;c:\windows\system32\drivers\rxhol.sys –> c:\windows\system32\drivers\rxhol.sys [?]
S1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [6/10/2008 11:45 AM 4442]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/21/2009 7:38 PM 269648]
S2 smihlp;SMI Helper Driver (smihlp);c:\program files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [8/14/2007 3:46 PM 10896]
S2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [10/28/2008 11:08 PM 54960]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [11/18/2008 6:56 PM 23888]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [9/10/2009 11:58 AM 102448]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [4/21/2009 7:38 PM 19160]
S3 Smcinst;Symantec Auto-upgrade Agent;c:\program files\Symantec AntiVirus\SmcLU\Setup\smcinst.exe –> c:\program files\Symantec AntiVirus\SmcLU\Setup\smcinst.exe [?]
S3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [5/22/2007 2:59 PM 30336]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [4/21/2009 9:07 PM 79888]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-09-15 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2008-06-10 05:30]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.symantec.com/enterprise/security_response/index.jsp
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\ThinkPad\Bluetooth Software\btsendto_ie.htm
LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
FF - ProfilePath - c:\documents and settings\kayialess\Application Data\Mozilla\Firefox\Profiles\czvyun4n.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\documents and settings\kayialess\Application Data\Mozilla\Firefox\Profiles\czvyun4n.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071302000002.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)
Notify-NavLogon - (no file)
SafeBoot-Symantec Antvirus
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-16 23:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1076)
c:\windows\system32\vrlogon.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\kayialess\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
c:\program files\ThinkPad\ConnectUtilities\ACNotify.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\windows\system32\Ati2evxx.dll
c:\progra~1\COMMON~1\Stardock\mcpstub.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\program files\ThinkVantage Fingerprint Software\crypto.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll

- - - - - - - > 'lsass.exe'(1132)
c:\program files\ThinkPad\ConnectUtilities\ACGina.dll
c:\program files\ThinkPad\ConnectUtilities\ACHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcSvcStub.dll
c:\program files\ThinkPad\ConnectUtilities\AcLocSettings.dll
c:\program files\ThinkPad\ConnectUtilities\ACON.dll
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgr.dll
c:\program files\ThinkPad\ConnectUtilities\AcCryptHlpr.dll
c:\program files\ThinkPad\ConnectUtilities\ACTurinSupport.dll
c:\program files\ThinkPad\ConnectUtilities\AcSmBiosHelper.dll
c:\program files\ThinkPad\ConnectUtilities\AcAdaptersInfo.dll
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
.
———————— Other Running Processes ————————
.
c:\program files\Symantec AntiVirus\Smc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\progra~1\COMMON~1\stardock\SDMCP.exe
c:\program files\Symantec AntiVirus\SmcGui.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
.
**************************************************************************
.
Completion time: 2009-09-17 23:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-17 03:27

Pre-Run: 114,007,310,336 bytes free
Post-Run: 113,956,319,232 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=10 Default=10 Failed=9 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11
381 — E O F — 2009-05-01 17:39


All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
c:\windows\system32\osysk.dat moved successfully.
c:\windows\system32\osysw.dat moved successfully.
c:\windows\system32\wincode.dat moved successfully.
c:\windows\system32\osysp.dat moved successfully.
c:\windows\system32\krncode.dat moved successfully.
c:\windows\system32\pwrcode.dat moved successfully.
c:\windows\system32\nsysp.ini moved successfully.
c:\windows\system32\shifld2.old moved successfully.
c:\windows\system32\nsysw.ini moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Admin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes

User: jstudent
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes

User: kayialess
->Temp folder emptied: 737280 bytes
->Temporary Internet Files folder emptied: 6856253 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 40067971 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 49152 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Setup
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 112 bytes
Windows Temp folder emptied: 53369 bytes
RecycleBin emptied: 4103671 bytes

Total Files Cleaned = 49.53 mb


OTM by OldTimer - Version 3.0.0.6 log created on 09162009_225328

Files moved on Reboot…

Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI