This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected Desktop Wallpaper + bottom right corner has a red

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am running windows xp after boot up the following show up in order: -ec2: iTunesHelper.exe - Bad Image "The application or DLL C:\WINDOWS|system32\winhelper86.dll is not a valid WIndows image. Please check this against your installation diskette." -AOLDial.exe - Bad Image "The application or DLL C:\WINDOWS|system32\winhelper86.dll is not a valid WIndows image. Please check this against your installation diskette." -sprtcmd.exe - Bad Image "The application or DLL C:\WINDOWS|system32\winhelper86.dll is not a valid WIndows image. Please check this against your installation diskette." -HelperMsgListenerWnd: iTunesHelper.exe - Bad Image "The application or DLL C:\WINDOWS|system32\winhelper86.dll is not a valid WIndows image. Please check this against your installation diskette." * . WARNING; Application cannot be executed. The file is infected * . wallpaper has changed to " your system is infected"… screen and it will not allow me to change in the settings * . bottom right corner has a red circle with white x * . warning sign that says "Attention! Sysem detected a potential hazard (TrojanSPM/LX) on you computer… The computer has both Spybot and Malwarebytes' Anti-Malware running when this infection occurred both have been used to scan the computer and appeared to have the issue quarantined or removed but the infection is still there. Thanks and Regards ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/12/15 21:32 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xAFC2C000 Size: 49152 File Visible: No Signed: - Status: - ==EOF== DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 21:25:00.70 on Tue 12/15/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.363 [GMT -6:00] AV: AntiMalware *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9} AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\CenturyTel\Home Network Manager\AffinegyService.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\Program Files\WinPcap\rpcapd.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\wanmpsvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\rundll32.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\stsystra.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\Common Files\AOL\1167193101\ee\AOLSoftware.exe C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\CenturyTel\Home Network Manager\HomeNetworkManager.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\DellSupport\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe C:\Program Files\CenturyTel\Home Network Manager\ndis_events.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Documents and Settings\Dawn Galvin\Desktop\dds(2).scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.aol.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us uWindow Title = Microsoft Internet Explorer provided by CenturyTel mWindow Title = Microsoft Internet Explorer provided by CenturyTel mSearch Bar = about:blank uInternet Connection Wizard,ShellNext = hxxp://us.mcafee.com/apps/vso/en-us/vso10/setexp.asp?systempopup=true&affid=105-72&dtag=hgvclb1&langid=1 uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {8CAA65F8-E703-4CF0-93D4-EDCF8D8ABC5B} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [Aim6] uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [] mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [DLCFCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCFtime.dll,_RunDLLEntry@16 mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe mRun: [HostManager] c:\program files\common files\aol\1167193101\ee\AOLSoftware.exe mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [InstaLAN] "c:\program files\centurytel\home network manager\HomeNetworkManager.exe" startup mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imaget~1.lnk - c:\program files\sony corporation\image transfer\SonyTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll LSP: c:\windows\system32\winhelper86.dll Trusted Zone: musicmatch.com\online DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://usbii.webex.com/client/T26L10NSP49EP30/training/ieatgpc.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Filter: text/html - {a42a5361-a0c6-4b1d-88a1-2ce3996d15e1} - Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-10-21 214664] R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-8-2 32512] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-11-20 19160] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-10-21 79816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-10-21 35272] R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-10-21 40552] S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2006-8-7 30192] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-10-21 34248] =============== Created Last 30 ================ 2009-12-15 20:26 0 a——- c:\windows\system32\24464.exe 2009-12-15 20:21 4,508 a——- c:\windows\system32\tmp.reg 2009-12-15 20:06 0 a——- c:\windows\system32\26962.exe 2009-12-15 19:46 0 a——- c:\windows\system32\29358.exe 2009-12-15 19:26 0 a——- c:\windows\system32\11478.exe 2009-12-14 19:05 0 a——- c:\windows\system32\15724.exe 2009-12-14 18:45 0 a——- c:\windows\system32\19169.exe 2009-12-14 18:25 0 a——- c:\windows\system32\26500.exe 2009-12-14 15:38 –d—– c:\program files\Trend Micro 2009-12-13 18:34 0 a——- c:\windows\system32\AVR10.exe 2009-12-13 18:34 0 a——- c:\windows\system32\winhelper86.dll 2009-12-11 15:38 0 a——- c:\windows\system32\6334.exe 2009-12-11 15:18 0 a——- c:\windows\system32\18467.exe 2009-12-11 14:57 35,328 a——- c:\windows\system32\winlogon86.exe 2009-11-20 21:22 –d—– c:\program files\Spybot - Search & Destroy 2009-11-20 21:22 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-11-20 21:15 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-11-20 21:15 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-11-20 21:15 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-11-20 17:13 –dsh— c:\documents and settings\dawn galvin\IECompatCache 2009-11-19 12:18 –dsh— c:\documents and settings\dawn galvin\PrivacIE 2009-11-19 12:14 –dsh— c:\documents and settings\dawn galvin\IETldCache 2009-11-18 18:19 5,632 a——- c:\windows\system32\ptpusb.dll 2009-11-18 18:19 15,104 a——- c:\windows\system32\drivers\usbscan.sys 2009-11-18 18:19 15,104 a——- c:\windows\system32\dllcache\usbscan.sys 2009-11-18 18:19 159,232 a——- c:\windows\system32\ptpusd.dll 2009-11-17 17:11 92,160 ——– c:\windows\system32\dllcache\iecompat.dll 2009-11-17 17:10 –d—– c:\windows\ie8updates 2009-11-17 17:10 12,800 ——– c:\windows\system32\dllcache\xpshims.dll 2009-11-17 17:10 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll 2009-11-17 17:07 -cd-h— c:\windows\ie8 2009-11-17 17:06 –d—– c:\windows\system32\MpEngineStore ==================== Find3M ==================== 2009-12-14 19:35 3,350 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-12-13 14:01 96,512 a——- c:\windows\system32\drivers\atapi.sys 2009-12-13 14:01 96,512 a——- c:\windows\system32\dllcache\atapi.sys 2009-10-29 01:45 916,480 a——- c:\windows\system32\wininet.dll 2009-10-29 01:45 916,480 ——– c:\windows\system32\dllcache\wininet.dll 2009-10-29 01:45 5,940,736 ——– c:\windows\system32\dllcache\mshtml.dll 2009-10-29 01:45 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll 2009-10-29 01:45 206,848 ——– c:\windows\system32\dllcache\occache.dll 2009-10-29 01:45 594,432 ——– c:\windows\system32\dllcache\msfeeds.dll 2009-10-29 01:45 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll 2009-10-29 01:45 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll 2009-10-29 01:45 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll 2009-10-29 01:45 184,320 ——– c:\windows\system32\dllcache\iepeers.dll 2009-10-29 01:45 11,069,952 ——– c:\windows\system32\dllcache\ieframe.dll 2009-10-29 01:45 387,584 ——– c:\windows\system32\dllcache\iedkcs32.dll 2009-10-28 08:40 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll 2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll 2009-10-20 23:38 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll 2009-10-20 23:38 25,088 ——– c:\windows\system32\dllcache\httpapi.dll 2009-10-20 10:20 265,728 a——- c:\windows\system32\drivers\http.sys 2009-10-20 10:20 265,728 ——– c:\windows\system32\dllcache\http.sys 2009-10-13 04:30 270,336 a——- c:\windows\system32\oakley.dll 2009-10-13 04:30 270,336 ——– c:\windows\system32\dllcache\oakley.dll 2009-10-12 07:38 149,504 a——- c:\windows\system32\rastls.dll 2009-10-12 07:38 149,504 ——– c:\windows\system32\dllcache\rastls.dll 2009-10-12 07:38 79,872 a——- c:\windows\system32\raschap.dll 2009-10-12 07:38 79,872 ——– c:\windows\system32\dllcache\raschap.dll 2009-09-26 10:44 13,008 a——- c:\docume~1\dawnga~1\applic~1\wklnhst.dat 2009-01-23 21:46 63,624 a——- c:\docume~1\dawnga~1\applic~1\GDIPFONTCACHEV1.DAT 2009-09-02 17:30 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009090220090903\index.dat ============= FINISH: 21:28:39.90 ===============

Attachments:

Hi,

Please do the following:

Download ComboFix from HERE


VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Thanks Catbyte I did as you said and disabled the scans and started the Combofix, however I am unable to connect to the internet with this computer. The Combofix found that the computer does not have Microsoft Windows Recovery Console and is trying to download the software. This is a problem that I should have noted in the initial post. I have tried to connect to the internet via cat5 cable and the modem however this has been down since this infiection started so I tried a Trendnet wireless dongle and transmission is good but does not stay open long enough to download the file. I not sure if this infection is blocking ports or something but I cannot get on the internet to install this. Another issue, I should have mentioned, I noticed in my initial attempts to cure this on my with Malwarebytes and Spybot, When I tried to boot to safe mode I got some blue screen saying it cannot proceed. Let me know if there is another option.
Hi, Yes you do have malware which is likely blocking your ability to connect. Run ComboFix and hopefully that will clean enough malware to enable you to restore your connection. If you have your installation CD, recovery console is on the CD should we need it.
Please run this program first and we will try and get you back connected.

Download the following program to your other computer and transfer to the infected computer and run it:


Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
exeHelper by Raktor Build 20091204 Run at 20:26:33 on 12/16/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished–
HAIL to ComboFix!!!!

I was able to bypass the Microsoft Windows Recovery Console by clicking "NO" and let ComboFix run its magic. The desktop no longer has the "infected" screen and no nagging bad image banners. I have not tried to connect to the internet, I am waiting on my next post.

I am willing to remove any junk programs from this system you want like google toolbar, ask toolbar or any others.



Here is my ComboFix log:

ComboFix 09-12-16.01 - Dawn Galvin 12/16/2009 20:39:00.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.572 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\KittyFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Shared
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\24464.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\29358.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\6334.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\AVR10.exe
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WanPacket.dll
c:\windows\system32\winhelper86.dll
c:\windows\system32\winlogon86.exe
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-11-17 to 2009-12-17 )))))))))))))))))))))))))))))))
.

2009-12-16 23:15 . 2009-12-16 23:15 21035 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-12-16 23:15 . 2008-01-23 22:02 20480 —-a-w- c:\windows\system32\drivers\WLNdis50.sys
2009-12-16 23:15 . 2009-12-16 23:15 ——– d—–w- c:\program files\TRENDnet
2009-12-16 23:15 . 2007-07-19 06:40 264576 —-a-w- c:\windows\system32\drivers\RTL8187B.sys
2009-12-16 23:15 . 2009-12-16 23:15 ——– d—–w- c:\documents and settings\Dawn Galvin\Application Data\InstallShield
2009-12-16 03:23 . 2009-12-16 03:23 ——– d—–w- c:\program files\ERUNT
2009-12-14 21:38 . 2009-12-14 21:38 ——– d—–w- c:\program files\Trend Micro
2009-12-06 05:27 . 2009-12-06 05:27 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2009-11-28 05:52 . 2009-11-28 05:52 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-11-27 19:43 . 2009-11-27 19:43 ——– d—–w- c:\documents and settings\Chris Galvin\Application Data\Malwarebytes
2009-11-27 19:42 . 2009-11-27 19:42 ——– d-sh–w- c:\documents and settings\Chris Galvin\PrivacIE
2009-11-21 08:33 . 2009-11-21 08:33 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-11-21 04:20 . 2009-11-21 04:20 ——– d—–w- c:\documents and settings\Glenn Galvin\Application Data\Malwarebytes
2009-11-21 03:22 . 2009-12-16 06:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-21 03:22 . 2009-11-21 03:27 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-21 03:15 . 2009-09-10 20:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-21 03:15 . 2009-11-21 03:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-21 03:15 . 2009-09-10 20:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 03:09 . 2009-11-21 03:09 ——– d-sh–w- c:\documents and settings\Chris Galvin\IETldCache
2009-11-21 02:50 . 2009-11-21 02:50 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-11-21 02:32 . 2009-11-21 02:38 ——– d—–w- c:\documents and settings\Matthew Galvin\Application Data\QuickScan
2009-11-20 23:13 . 2009-11-20 23:13 ——– d-sh–w- c:\documents and settings\Dawn Galvin\IECompatCache
2009-11-20 23:00 . 2009-11-20 23:00 ——– d-sh–w- c:\documents and settings\Glenn Galvin\PrivacIE
2009-11-20 22:55 . 2009-11-20 22:55 ——– d-sh–w- c:\documents and settings\Glenn Galvin\IETldCache
2009-11-19 18:18 . 2009-11-19 18:18 ——– d-sh–w- c:\documents and settings\Dawn Galvin\PrivacIE
2009-11-19 18:14 . 2009-11-19 18:14 ——– d-sh–w- c:\documents and settings\Dawn Galvin\IETldCache
2009-11-19 00:19 . 2001-08-18 04:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2009-11-19 00:19 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-11-19 00:19 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2009-11-19 00:19 . 2008-04-14 00:12 159232 —-a-w- c:\windows\system32\ptpusd.dll
2009-11-19 00:09 . 2009-11-19 00:09 ——– d-sh–w- c:\documents and settings\Matthew Galvin\IECompatCache
2009-11-17 23:25 . 2009-11-17 23:25 ——– d-sh–w- c:\documents and settings\Matthew Galvin\PrivacIE
2009-11-17 23:22 . 2009-11-17 23:22 ——– d-sh–w- c:\documents and settings\Matthew Galvin\IETldCache
2009-11-17 23:14 . 2009-11-17 23:14 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2009-11-17 23:11 . 2009-10-02 04:44 92160 ——w- c:\windows\system32\dllcache\iecompat.dll
2009-11-17 23:10 . 2009-11-17 23:10 ——– d—–w- c:\windows\ie8updates
2009-11-17 23:10 . 2009-10-29 07:45 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2009-11-17 23:10 . 2009-10-29 07:45 246272 ——w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-17 23:07 . 2009-11-17 23:09 ——– dc-h–w- c:\windows\ie8
2009-11-17 23:06 . 2009-11-17 23:06 ——– d—–w- c:\windows\system32\MpEngineStore

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-17 00:25 . 2004-08-04 03:59 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-12-17 00:25 . 2004-08-04 03:59 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2009-12-16 23:15 . 2006-08-08 03:55 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-15 01:35 . 2007-01-29 01:34 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-12-15 01:35 . 2007-01-29 01:34 88 –sh–r- c:\windows\system32\39608939DF.sys
2009-12-10 00:14 . 2006-08-10 23:07 ——– d—–w- c:\program files\Dl_cats
2009-12-08 21:24 . 2006-10-26 22:19 ——– d—–w- c:\documents and settings\Dawn Galvin\Application Data\Apple Computer
2009-12-06 05:22 . 2006-08-08 04:06 ——– d—–w- c:\program files\McAfee
2009-12-03 21:59 . 2008-09-19 17:58 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-12-01 23:15 . 2006-08-08 04:06 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-30 21:21 . 2008-01-24 21:40 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-11-21 02:40 . 2009-05-23 15:44 ——– d—–w- c:\documents and settings\Matthew Galvin\Application Data\LimeWire
2009-11-19 00:19 . 2006-10-22 01:15 ——– d—–w- c:\documents and settings\Matthew Galvin\Application Data\Apple Computer
2009-11-19 00:19 . 2007-12-28 01:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-11-17 21:39 . 2009-11-17 21:39 79488 —-a-w- c:\documents and settings\Matthew Galvin\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-10-29 07:45 . 2004-08-10 17:51 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 17:51 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 17:51 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 04:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-18 16:50 . 2006-11-12 16:53 ——– d—–w- c:\documents and settings\Glenn Galvin\Application Data\Apple Computer
2009-10-18 16:49 . 2006-08-10 02:25 64400 —-a-w- c:\documents and settings\Glenn Galvin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-14 23:31 . 2006-12-14 22:15 2204 —-a-w- c:\documents and settings\Matthew Galvin\Application Data\wklnhst.dat
2009-10-13 10:30 . 2004-08-10 17:51 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 17:51 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 17:51 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-01 12:56 . 2006-12-10 22:04 64400 —-a-w- c:\documents and settings\Dawn Galvin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-26 16:44 . 2006-08-26 19:42 13008 —-a-w- c:\documents and settings\Dawn Galvin\Application Data\wklnhst.dat
2009-09-26 16:24 . 2009-09-26 16:24 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-09 03:08 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-23 30192]
"DLCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2005-09-08 73728]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"HostManager"="c:\program files\Common Files\AOL\1167193101\ee\AOLSoftware.exe" [2007-10-08 41824]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-06 149280]
"InstaLAN"="c:\program files\CenturyTel\Home Network Manager\HomeNetworkManager.exe" [2008-10-14 1127712]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]

c:\documents and settings\Matthew Galvin\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-3-4 225280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-7 24576]
Image Transfer.lnk - c:\program files\Sony Corporation\Image Transfer\SonyTray.exe [2008-11-11 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Wireless Configuration Utility.lnk - c:\program files\TRENDnet\TEW-424UB\WlanCU.exe [2009-12-16 368640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1167193101\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Matthew Galvin\\My Documents\\LimeWire\\matt\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/20/2009 9:15 PM 269648]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/19/2008 11:36 AM 93320]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/9/2008 7:13 PM 24652]
R2 WLNdis50;Wireless Lan NDIS Protocol I/O Control;c:\windows\system32\drivers\WLNdis50.sys [12/16/2009 5:15 PM 20480]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [8/7/2006 10:08 PM 30192]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/20/2009 9:15 PM 19160]
S2 WLSVC;WLSVC;c:\program files\TRENDnet\TEW-424UB\WLSVC.exe [12/16/2009 5:15 PM 167936]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;c:\windows\system32\drivers\RTL8187B.sys [12/16/2009 5:15 PM 264576]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
mWindow Title = Microsoft Internet Explorer provided by CenturyTel
mSearch Bar = about:blank
uInternet Connection Wizard,ShellNext = hxxp://us.mcafee.com/apps/vso/en-us/vso10/setexp.asp?systempopup=true&affid;=105-72&dtag;=hgvclb1&langid;=1
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AIM; Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: musicmatch.com\online
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8CAA65F8-E703-4CF0-93D4-EDCF8D8ABC5B} - (no file)
HKCU-Run-Aim6 - (no file)
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-16 20:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCFCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …


c:\windows\TEMP\sqlite_petohnXISwqd0v2 0 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(968)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\CenturyTel\Home Network Manager\AffinegyService.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\wanmpsvc.exe
c:\windows\system32\rundll32.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\stsystra.exe
c:\program files\CenturyTel\Home Network Manager\ndis_events.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\AOL\Loader\aolload.exe
.
**************************************************************************
.
Completion time: 2009-12-16 21:08:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-17 03:08

Pre-Run: 121,866,412,032 bytes free
Post-Run: 121,366,347,776 bytes free

- - End Of File - - 38246DD4D5CEFFD90EE83F05B3B7447C
Hi,

Please do the following:

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
C:\WINDOWS\Explorer.EXE 

:Files
c:\windows\system32\winhelper86.dll
c:\windows\system32\24464.exe
c:\windows\system32\tmp.reg
c:\windows\system32\26962.exe
c:\windows\system32\29358.exe
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\AVR10.exe
c:\windows\system32\winhelper86.dll
c:\windows\system32\6334.exe
c:\windows\system32\18467.exe
c:\windows\system32\winlogon86.exe

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



NEXT


Please download LSPFix from HERE
or here.
  • Run the LSPFix.exe that you have just finished downloading,
  • list all of the protocols that are in the 'Keep' and 'Remove' lists;
  • if there are protocols in the 'Remove' list, then please don't click 'Finish>>'
  • Simply close the program by pressing ALT+F4 or the Close [x] button.
Okay here is the log:

All processes killed
========== PROCESSES ==========
No active process named C:\WINDOWS\Explorer.EXE was found!
========== FILES ==========
File/Folder c:\windows\system32\winhelper86.dll not found.
File/Folder c:\windows\system32\24464.exe not found.
File/Folder c:\windows\system32\tmp.reg not found.
File/Folder c:\windows\system32\26962.exe not found.
File/Folder c:\windows\system32\29358.exe not found.
File/Folder c:\windows\system32\11478.exe not found.
File/Folder c:\windows\system32\15724.exe not found.
File/Folder c:\windows\system32\19169.exe not found.
File/Folder c:\windows\system32\26500.exe not found.
File/Folder c:\windows\system32\AVR10.exe not found.
File/Folder c:\windows\system32\winhelper86.dll not found.
File/Folder c:\windows\system32\6334.exe not found.
File/Folder c:\windows\system32\18467.exe not found.
File/Folder c:\windows\system32\winlogon86.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 134 bytes

User: All Users

User: Chris Galvin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 4307 bytes
->Java cache emptied: 13689516 bytes

User: Dawn Galvin
->Temp folder emptied: 163840 bytes
->Temporary Internet Files folder emptied: 50869 bytes
->Java cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32768 bytes

User: Glenn Galvin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49286 bytes

User: Matthew Galvin
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1784 bytes
->Java cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Owner
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 3244049 bytes
Windows Temp folder emptied: 255 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 67 bytes
RecycleBin emptied: 534528 bytes

Total Files Cleaned = 16.97 mb


OTM by OldTimer - Version 3.1.2.2 log created on 12162009_213712

Files moved on Reboot…

Registry entries deleted on Reboot…


Here is what LSPFix.exe said:

No Problems found

Keep Side:
mswsock.dll
minmr.dll
mdnsNSP.dll
rsvpsp.dll

Remove side:
empty
Ran ComboFix here is the log

ComboFix 09-12-16.01 - Dawn Galvin 12/17/2009 18:05:51.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.472 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\KittyFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((( Files Created from 2009-11-18 to 2009-12-18 )))))))))))))))))))))))))))))))
.

2009-12-17 23:18 . 2009-12-17 23:29 ——– d—–w- C:\KittyFix17202K
2009-12-17 03:37 . 2009-12-17 03:37 ——– d—–w- C:\_OTM
2009-12-17 02:38 . 2009-12-17 03:09 ——– d—–w- C:\KittyFix
2009-12-16 23:15 . 2009-12-16 23:15 21035 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-12-16 23:15 . 2008-01-23 22:02 20480 —-a-w- c:\windows\system32\drivers\WLNdis50.sys
2009-12-16 23:15 . 2009-12-16 23:15 ——– d—–w- c:\program files\TRENDnet
2009-12-16 23:15 . 2007-07-19 06:40 264576 —-a-w- c:\windows\system32\drivers\RTL8187B.sys
2009-12-16 23:15 . 2009-12-16 23:15 ——– d—–w- c:\documents and settings\Dawn Galvin\Application Data\InstallShield
2009-12-16 03:23 . 2009-12-16 03:23 ——– d—–w- c:\program files\ERUNT
2009-12-14 21:38 . 2009-12-14 21:38 ——– d—–w- c:\program files\Trend Micro
2009-12-06 05:27 . 2009-12-06 05:27 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2009-11-28 05:52 . 2009-11-28 05:52 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2009-11-27 19:43 . 2009-11-27 19:43 ——– d—–w- c:\documents and settings\Chris Galvin\Application Data\Malwarebytes
2009-11-27 19:42 . 2009-11-27 19:42 ——– d-sh–w- c:\documents and settings\Chris Galvin\PrivacIE
2009-11-21 08:33 . 2009-11-21 08:33 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-11-21 04:20 . 2009-11-21 04:20 ——– d—–w- c:\documents and settings\Glenn Galvin\Application Data\Malwarebytes
2009-11-21 03:22 . 2009-12-16 06:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-21 03:22 . 2009-11-21 03:27 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-11-21 03:15 . 2009-09-10 20:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-21 03:15 . 2009-11-21 03:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-21 03:15 . 2009-09-10 20:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-21 03:09 . 2009-11-21 03:09 ——– d-sh–w- c:\documents and settings\Chris Galvin\IETldCache
2009-11-21 02:50 . 2009-11-21 02:50 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-11-21 02:32 . 2009-11-21 02:38 ——– d—–w- c:\documents and settings\Matthew Galvin\Application Data\QuickScan
2009-11-20 23:13 . 2009-11-20 23:13 ——– d-sh–w- c:\documents and settings\Dawn Galvin\IECompatCache
2009-11-20 23:00 . 2009-11-20 23:00 ——– d-sh–w- c:\documents and settings\Glenn Galvin\PrivacIE
2009-11-20 22:55 . 2009-11-20 22:55 ——– d-sh–w- c:\documents and settings\Glenn Galvin\IETldCache
2009-11-19 18:18 . 2009-11-19 18:18 ——– d-sh–w- c:\documents and settings\Dawn Galvin\PrivacIE
2009-11-19 18:14 . 2009-11-19 18:14 ——– d-sh–w- c:\documents and settings\Dawn Galvin\IETldCache
2009-11-19 00:19 . 2001-08-18 04:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2009-11-19 00:19 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-11-19 00:19 . 2008-04-13 18:45 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2009-11-19 00:19 . 2008-04-14 00:12 159232 —-a-w- c:\windows\system32\ptpusd.dll
2009-11-19 00:09 . 2009-11-19 00:09 ——– d-sh–w- c:\documents and settings\Matthew Galvin\IECompatCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-17 00:25 . 2004-08-04 03:59 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2009-12-17 00:25 . 2004-08-04 03:59 96512 ——w- c:\windows\system32\drivers\atapi.sys
2009-12-16 23:15 . 2006-08-08 03:55 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-15 01:35 . 2007-01-29 01:34 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-12-15 01:35 . 2007-01-29 01:34 88 –sh–r- c:\windows\system32\39608939DF.sys
2009-12-10 00:14 . 2006-08-10 23:07 ——– d—–w- c:\program files\Dl_cats
2009-12-08 21:24 . 2006-10-26 22:19 ——– d—–w- c:\documents and settings\Dawn Galvin\Application Data\Apple Computer
2009-12-06 05:22 . 2006-08-08 04:06 ——– d—–w- c:\program files\McAfee
2009-12-03 21:59 . 2008-09-19 17:58 ——– d—–w- c:\documents and settings\LocalService\Application Data\SACore
2009-12-01 23:15 . 2006-08-08 04:06 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-30 21:21 . 2008-01-24 21:40 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-11-21 02:40 . 2009-05-23 15:44 ——– d—–w- c:\documents and settings\Matthew Galvin\Application Data\LimeWire
2009-11-19 00:19 . 2006-10-22 01:15 ——– d—–w- c:\documents and settings\Matthew Galvin\Application Data\Apple Computer
2009-11-19 00:19 . 2007-12-28 01:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-11-17 21:39 . 2009-11-17 21:39 79488 —-a-w- c:\documents and settings\Matthew Galvin\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-10-29 07:45 . 2004-08-10 17:51 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 17:51 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 17:51 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 04:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-18 16:49 . 2006-08-10 02:25 64400 —-a-w- c:\documents and settings\Glenn Galvin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-14 23:31 . 2006-12-14 22:15 2204 —-a-w- c:\documents and settings\Matthew Galvin\Application Data\wklnhst.dat
2009-10-13 10:30 . 2004-08-10 17:51 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 17:51 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 17:51 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-01 12:56 . 2006-12-10 22:04 64400 —-a-w- c:\documents and settings\Dawn Galvin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-26 16:44 . 2006-08-26 19:42 13008 —-a-w- c:\documents and settings\Dawn Galvin\Application Data\wklnhst.dat
2009-09-26 16:24 . 2009-09-26 16:24 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-12-17_23.27.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-17 23:41 . 2009-12-17 23:41 16384 c:\windows\Temp\Perflib_Perfdata_530.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-09 03:08 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-23 30192]
"DLCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2005-09-08 73728]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"HostManager"="c:\program files\Common Files\AOL\1167193101\ee\AOLSoftware.exe" [2007-10-08 41824]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-06 149280]
"InstaLAN"="c:\program files\CenturyTel\Home Network Manager\HomeNetworkManager.exe" [2008-10-14 1127712]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-09-10 420176]

c:\documents and settings\Matthew Galvin\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-3-4 225280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-7 24576]
Image Transfer.lnk - c:\program files\Sony Corporation\Image Transfer\SonyTray.exe [2008-11-11 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Wireless Configuration Utility.lnk - c:\program files\TRENDnet\TEW-424UB\WlanCU.exe [2009-12-16 368640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1167193101\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Matthew Galvin\\My Documents\\LimeWire\\matt\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/20/2009 9:15 PM 269648]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/19/2008 11:36 AM 93320]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/9/2008 7:13 PM 24652]
R2 WLNdis50;Wireless Lan NDIS Protocol I/O Control;c:\windows\system32\drivers\WLNdis50.sys [12/16/2009 5:15 PM 20480]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/20/2009 9:15 PM 19160]
S2 WLSVC;WLSVC;c:\program files\TRENDnet\TEW-424UB\WLSVC.exe [12/16/2009 5:15 PM 167936]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [8/7/2006 10:08 PM 30192]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;c:\windows\system32\drivers\RTL8187B.sys [12/16/2009 5:15 PM 264576]

— Other Services/Drivers In Memory —

*NewlyCreated* - ATWPKT2
*Deregistered* - ATWPKT2
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.aol.com/
mWindow Title = Microsoft Internet Explorer provided by CenturyTel
mSearch Bar = about:blank
uInternet Connection Wizard,ShellNext = hxxp://us.mcafee.com/apps/vso/en-us/vso10/setexp.asp?systempopup=true&affid=105-72&dtag=hgvclb1&langid=1
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: musicmatch.com\online
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-17 18:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCFCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3804)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-12-17 18:12:16
ComboFix-quarantined-files.txt 2009-12-18 00:12
ComboFix2.txt 2009-12-17 23:29
ComboFix3.txt 2009-12-17 03:08

Pre-Run: 121,324,986,368 bytes free
Post-Run: 121,288,151,040 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 3C1691E3B437A03C9A7ECF7B3ADF09E7

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI