This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Need help with Combofix please

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Could someone please read through my Combofix log and tell me if my computer is clean?

I'm sorry for not following the rules! My computer was infected with a virus, and a friend told me to run Combofix. It was only after I ran the program that I realized I would need a specialist to review my log file. I came to this forum and then saw the "Do not run Combofix without explicit instruction" note…. sorry …

Here was my original problem: I kept getting a popup telling me that my computer was infected, and urging me to download their anti-virus program. I didn't - I tried to download and run a Norton product instead. However, my computer couldn't connect to the Norton site to update the virus definitions. I could connect to the internet, but I couldn't browse to Norton, AVG, McAfree, or other antivirus product sites. Also, if I clicked on links from a Google search result site, I would get redirected to odd locations.

The problem *seems* to be fixed since running Combofix, but the instructions strongly recommended having the log file reviewed … I would really appreciate it if someone could help me out. (File attached)



Please don't attach the scan results unless asked to. Copy/Paste them.

ComboFix 10-02-03.04 - srenzi 02/03/2010 21:54:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.284 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\captcha.dll
c:\program files\webserver
c:\windows\010112010146101105.rx
c:\windows\010112010146114101.xxe
c:\windows\01011201014650115.xxe
c:\windows\0101120101465348.xxe
c:\windows\Downloaded Program Files\MyWebEx
c:\windows\Downloaded Program Files\MyWebEx\419\atarm.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atas32.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atasanot.exe
c:\windows\Downloaded Program Files\MyWebEx\419\atasctrl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atasnt40.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atcarmcl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atdl2006.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atjpeg60.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atkbctl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atlchat.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atmemmgr.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atnetext.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atpack.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\attp.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atwbxui5.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmcliun.exe
c:\windows\Downloaded Program Files\MyWebEx\419\mwmproxy.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmtrace.txt
c:\windows\Downloaded Program Files\MyWebEx\419\mwmupd.exe
c:\windows\Downloaded Program Files\MyWebEx\419\ratrace.dll
c:\windows\Downloaded Program Files\MyWebEx\419\raurl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\uilibres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\wbxcrypt.dll
c:\windows\Downloaded Program Files\MyWebEx\419\webexmgr.dll
c:\windows\fdgg34353edfgdfdf
c:\windows\pp14.exe
c:\windows\rdr_1264952508.exe
c:\windows\system32\drivers\fio32.sys
c:\windows\system32\fio32.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FIOO32
——-\Service_fioo32
——-\Service_SfX
——-\Legacy_fio32
——-\Service_fio32


((((((((((((((((((((((((( Files Created from 2010-01-04 to 2010-02-04 )))))))))))))))))))))))))))))))
.

2010-01-31 21:56 . 2010-01-31 21:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-31 21:42 . 2010-01-31 21:42 ——– d—–w- c:\documents and settings\srenzi\Local Settings\Application Data\Downloaded Installations
2010-01-31 21:31 . 2010-01-31 21:31 ——– d—–w- c:\program files\Times Reader
2010-01-31 21:31 . 2010-01-31 21:31 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-31 21:30 . 2010-01-31 21:38 ——– d—–w- c:\documents and settings\srenzi\Local Settings\Application Data\Adobe
2010-01-31 21:30 . 2010-02-02 03:04 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-31 15:28 . 2010-02-02 03:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-01-31 15:28 . 2010-01-31 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-31 15:25 . 2010-01-31 15:25 ——– d—–w- c:\documents and settings\All Users\Symantec Temporary Files
2010-01-31 14:37 . 2010-01-31 14:37 1 —-a-w- c:\windows\conf21113.dat
2010-01-30 15:08 . 1998-04-25 10:32 210944 —-a-w- c:\windows\system32\MSVCRT10.DLL
2010-01-30 15:08 . 1998-04-25 10:32 212480 —-a-w- c:\windows\system32\pcdlib32.dll
2010-01-30 15:08 . 2010-01-30 15:08 ——– d—–w- C:\KPCMS
2010-01-30 15:08 . 1998-04-25 10:32 40129 —-a-w- c:\windows\iccsigs.dat
2010-01-30 15:08 . 1998-06-05 16:42 197120 —-a-w- c:\windows\kpcp32.dll
2010-01-30 15:08 . 1998-04-25 10:32 58368 —-a-w- c:\windows\pfpick.dll
2010-01-30 15:08 . 1998-04-25 10:32 37376 —-a-w- c:\windows\kpsys32.dll
2010-01-30 15:08 . 1998-04-25 10:32 20992 —-a-w- c:\windows\icccodes.dll
2010-01-30 15:08 . 1998-01-20 14:12 133120 —-a-w- c:\windows\sprof32.dll
2010-01-30 15:07 . 2010-01-30 15:07 ——– d—–w- c:\windows\system32\COLOR
2010-01-30 15:03 . 1998-04-25 10:19 299520 —-a-w- c:\windows\uninst.exe
2010-01-19 03:05 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-04 03:22 . 2007-03-30 00:42 ——– d—–w- c:\documents and settings\srenzi\Application Data\Skype
2010-02-04 03:21 . 2008-03-27 12:46 ——– d—–w- c:\documents and settings\srenzi\Application Data\skypePM
2010-02-04 03:06 . 2006-08-16 02:37 12 —-a-w- c:\windows\bthservsdp.dat
2010-02-01 03:00 . 2008-11-16 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Retrospect
2010-01-31 21:35 . 2006-05-19 23:43 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-31 21:30 . 2010-01-31 21:30 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-31 21:16 . 2007-03-30 00:50 82920 —-a-w- c:\documents and settings\srenzi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 21:16 . 2007-05-27 13:30 110197 -c–a-w- c:\windows\hpoins08.dat
2010-01-31 21:06 . 2007-04-04 03:25 ——– d—–w- c:\documents and settings\srenzi\Application Data\AdobeUM
2010-01-31 15:34 . 2005-02-02 08:21 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-31 15:34 . 2005-05-31 17:20 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-01-31 15:32 . 2009-07-15 15:21 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-01-21 00:21 . 2009-11-11 13:03 79488 —-a-w- c:\documents and settings\srenzi\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-19 03:25 . 2007-11-08 01:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-21 19:14 . 2004-08-11 22:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 22:44 . 2006-06-21 05:30 ——– d—–w- c:\program files\PowerArchiver
2009-12-16 19:42 . 2009-12-18 22:38 872960 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 19:42 . 2009-12-18 22:38 43008 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 19:42 . 2009-12-18 22:38 340480 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 19:41 . 2009-12-18 22:38 346624 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-20 11:08 . 2010-01-31 21:31 38784 —-a-w- c:\documents and settings\srenzi\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2006-08-31 20:51 . 2006-08-31 20:51 3711728 —-a-w- c:\program files\powarc963.exe
2006-07-06 00:20 . 2006-07-06 00:20 3988 —-a-w- c:\program files\pgupta.zip
2006-06-30 04:34 . 2006-06-30 04:32 13926456 —-a-w- c:\program files\snagit.exe
2006-06-13 23:07 . 2006-06-13 23:07 71932 —-a-w- c:\program files\Floresense_WorldClock.zip
2006-06-08 05:47 . 2006-06-08 05:47 15818536 —-a-w- c:\program files\Install_Messenger_Beta(2).exe
2006-06-02 05:43 . 2006-06-02 05:42 397352 —-a-w- c:\program files\msgr75us.exe
2006-06-02 05:42 . 2006-06-02 05:42 5118288 —-a-w- c:\program files\Firefox Setup 1.5.0.4.exe
2008-03-05 22:00 . 2006-08-31 18:02 27976 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-03-05 22:00 . 2006-08-31 18:02 125848 —-a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-03-05 22:00 . 2008-03-05 22:00 46408 —-a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2008-03-05 22:00 . 2006-08-31 18:02 98712 —-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2007-08-02 15:41 . 2006-08-31 18:02 94208 —-a-w- c:\program files\mozilla firefox\plugins\mwmcli.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-13 136600]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-02 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"SigmatelSysTrayApp"="stsystra.exe" [2006-01-09 417792]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048]
"openvpn-gui"="c:\program files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 99328]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2004-02-27 61440]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-05-20 188416]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"\\us-fs\EPSON Stylus Photo R1800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE" [2004-09-08 98304]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"WD Button Manager"="WDBtnMgr.exe" [2008-11-16 335872]
"SetIcon"="\Program Files\WDC\SetIcon.exe" [2004-04-28 42496]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\pgupta\Start Menu\Programs\Startup\
World Clock 2001.LNK - c:\program files\Zada Solutions\World Clock\zsWldClk.exe [2000-8-22 684032]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 45056]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-5-19 24576]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-27 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-24 13:27 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1292428093-839522115-1109\Scripts\Logon\0\0]
"Script"=all-au.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1292428093-839522115-1297\Scripts\Logon\0\0]
"Script"=all.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Codename Max\\max.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\msncall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"53:TCP"= 53:TCP:webserver

R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [6/7/2007 7:10 AM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [6/7/2007 7:10 AM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/7/2007 7:06 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/31/2009 3:40 PM 133104]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [6/23/2004 8:54 PM 23552]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-31 20:39]

2010-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-31 20:39]

2010-02-04 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]

2010-01-28 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyServer = 192.168.10.101:3128
uInternet Settings,ProxyOverride = maddmzmm1.ingdirect.es;;*.local
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: memetrics.com\project
DPF: {1D95A7C7-3282-4DB7-9A48-7C39CE152A19} - hxxps://myemail.t-mobile.com/html/web/client_tools/TOImport.cab
DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxp://project.memetrics.com/projectserver/objects/pjclient.cab
DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxp://project.memetrics.com/projectserver/objects/1033/pjcintl.cab
FF - ProfilePath - c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_us&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-03 22:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(864)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\windows\system32\LMIinit.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(1232)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\progra~1\Dantz\RETROS~1\retrorun.exe
c:\progra~1\Dantz\RETROS~1\wdsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\stsystra.exe
c:\program files\Apoint\HidFind.exe
c:\program files\Apoint\Apntex.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\WDBtnMgr.exe
c:\program files\WDC\SetIcon.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\program files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\HPBPRO.EXE
.
**************************************************************************
.
Completion time: 2010-02-03 22:32:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-04 03:32

Pre-Run: 12,537,458,688 bytes free
Post-Run: 12,724,928,512 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - CF9C08E1CE84032AD31887C386DE6978
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
Ok - I removed the attachment and I'm pasting the log file as requested:

ComboFix 10-02-03.04 - srenzi 02/03/2010 21:54:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.284 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\captcha.dll
c:\program files\webserver
c:\windows\010112010146101105.rx
c:\windows\010112010146114101.xxe
c:\windows\01011201014650115.xxe
c:\windows\0101120101465348.xxe
c:\windows\Downloaded Program Files\MyWebEx
c:\windows\Downloaded Program Files\MyWebEx\419\atarm.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atas32.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atasanot.exe
c:\windows\Downloaded Program Files\MyWebEx\419\atasctrl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atasnt40.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atcarmcl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atdl2006.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atjpeg60.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atkbctl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atlchat.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atmemmgr.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atnetext.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atpack.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\attp.dll
c:\windows\Downloaded Program Files\MyWebEx\419\atwbxui5.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmcliun.exe
c:\windows\Downloaded Program Files\MyWebEx\419\mwmproxy.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\mwmtrace.txt
c:\windows\Downloaded Program Files\MyWebEx\419\mwmupd.exe
c:\windows\Downloaded Program Files\MyWebEx\419\ratrace.dll
c:\windows\Downloaded Program Files\MyWebEx\419\raurl.dll
c:\windows\Downloaded Program Files\MyWebEx\419\uilibres.dll
c:\windows\Downloaded Program Files\MyWebEx\419\wbxcrypt.dll
c:\windows\Downloaded Program Files\MyWebEx\419\webexmgr.dll
c:\windows\fdgg34353edfgdfdf
c:\windows\pp14.exe
c:\windows\rdr_1264952508.exe
c:\windows\system32\drivers\fio32.sys
c:\windows\system32\fio32.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FIOO32
——-\Service_fioo32
——-\Service_SfX
——-\Legacy_fio32
——-\Service_fio32


((((((((((((((((((((((((( Files Created from 2010-01-04 to 2010-02-04 )))))))))))))))))))))))))))))))
.

2010-01-31 21:56 . 2010-01-31 21:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-31 21:42 . 2010-01-31 21:42 ——– d—–w- c:\documents and settings\srenzi\Local Settings\Application Data\Downloaded Installations
2010-01-31 21:31 . 2010-01-31 21:31 ——– d—–w- c:\program files\Times Reader
2010-01-31 21:31 . 2010-01-31 21:31 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-31 21:30 . 2010-01-31 21:38 ——– d—–w- c:\documents and settings\srenzi\Local Settings\Application Data\Adobe
2010-01-31 21:30 . 2010-02-02 03:04 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-01-31 15:28 . 2010-02-02 03:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-01-31 15:28 . 2010-01-31 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-01-31 15:25 . 2010-01-31 15:25 ——– d—–w- c:\documents and settings\All Users\Symantec Temporary Files
2010-01-31 14:37 . 2010-01-31 14:37 1 —-a-w- c:\windows\conf21113.dat
2010-01-30 15:08 . 1998-04-25 10:32 210944 —-a-w- c:\windows\system32\MSVCRT10.DLL
2010-01-30 15:08 . 1998-04-25 10:32 212480 —-a-w- c:\windows\system32\pcdlib32.dll
2010-01-30 15:08 . 2010-01-30 15:08 ——– d—–w- C:\KPCMS
2010-01-30 15:08 . 1998-04-25 10:32 40129 —-a-w- c:\windows\iccsigs.dat
2010-01-30 15:08 . 1998-06-05 16:42 197120 —-a-w- c:\windows\kpcp32.dll
2010-01-30 15:08 . 1998-04-25 10:32 58368 —-a-w- c:\windows\pfpick.dll
2010-01-30 15:08 . 1998-04-25 10:32 37376 —-a-w- c:\windows\kpsys32.dll
2010-01-30 15:08 . 1998-04-25 10:32 20992 —-a-w- c:\windows\icccodes.dll
2010-01-30 15:08 . 1998-01-20 14:12 133120 —-a-w- c:\windows\sprof32.dll
2010-01-30 15:07 . 2010-01-30 15:07 ——– d—–w- c:\windows\system32\COLOR
2010-01-30 15:03 . 1998-04-25 10:19 299520 —-a-w- c:\windows\uninst.exe
2010-01-19 03:05 . 2009-11-21 15:51 471552 ——w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-04 03:22 . 2007-03-30 00:42 ——– d—–w- c:\documents and settings\srenzi\Application Data\Skype
2010-02-04 03:21 . 2008-03-27 12:46 ——– d—–w- c:\documents and settings\srenzi\Application Data\skypePM
2010-02-04 03:06 . 2006-08-16 02:37 12 —-a-w- c:\windows\bthservsdp.dat
2010-02-01 03:00 . 2008-11-16 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Retrospect
2010-01-31 21:35 . 2006-05-19 23:43 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-31 21:30 . 2010-01-31 21:30 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-31 21:16 . 2007-03-30 00:50 82920 —-a-w- c:\documents and settings\srenzi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-31 21:16 . 2007-05-27 13:30 110197 -c–a-w- c:\windows\hpoins08.dat
2010-01-31 21:06 . 2007-04-04 03:25 ——– d—–w- c:\documents and settings\srenzi\Application Data\AdobeUM
2010-01-31 15:34 . 2005-02-02 08:21 26600 —-a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-01-31 15:34 . 2005-05-31 17:20 107368 —-a-r- c:\windows\system32\GEARAspi.dll
2010-01-31 15:32 . 2009-07-15 15:21 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-01-21 00:21 . 2009-11-11 13:03 79488 —-a-w- c:\documents and settings\srenzi\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-19 03:25 . 2007-11-08 01:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-21 19:14 . 2004-08-11 22:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 22:44 . 2006-06-21 05:30 ——– d—–w- c:\program files\PowerArchiver
2009-12-16 19:42 . 2009-12-18 22:38 872960 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-16 19:42 . 2009-12-18 22:38 43008 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-16 19:42 . 2009-12-18 22:38 340480 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-16 19:41 . 2009-12-18 22:38 346624 —-a-w- c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-20 11:08 . 2010-01-31 21:31 38784 —-a-w- c:\documents and settings\srenzi\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2006-08-31 20:51 . 2006-08-31 20:51 3711728 —-a-w- c:\program files\powarc963.exe
2006-07-06 00:20 . 2006-07-06 00:20 3988 —-a-w- c:\program files\pgupta.zip
2006-06-30 04:34 . 2006-06-30 04:32 13926456 —-a-w- c:\program files\snagit.exe
2006-06-13 23:07 . 2006-06-13 23:07 71932 —-a-w- c:\program files\Floresense_WorldClock.zip
2006-06-08 05:47 . 2006-06-08 05:47 15818536 —-a-w- c:\program files\Install_Messenger_Beta(2).exe
2006-06-02 05:43 . 2006-06-02 05:42 397352 —-a-w- c:\program files\msgr75us.exe
2006-06-02 05:42 . 2006-06-02 05:42 5118288 —-a-w- c:\program files\Firefox Setup 1.5.0.4.exe
2008-03-05 22:00 . 2006-08-31 18:02 27976 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-03-05 22:00 . 2006-08-31 18:02 125848 —-a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-03-05 22:00 . 2008-03-05 22:00 46408 —-a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2008-03-05 22:00 . 2006-08-31 18:02 98712 —-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2007-08-02 15:41 . 2006-08-31 18:02 94208 —-a-w- c:\program files\mozilla firefox\plugins\mwmcli.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-13 136600]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-02 1392640]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-04-06 1032192]
"SigmatelSysTrayApp"="stsystra.exe" [2006-01-09 417792]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048]
"openvpn-gui"="c:\program files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 99328]
"StatusClient 2.6"="c:\program files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2004-02-27 61440]
"TomcatStartup 2.5"="c:\program files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2004-05-20 188416]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"\\us-fs\EPSON Stylus Photo R1800"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE" [2004-09-08 98304]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"WD Button Manager"="WDBtnMgr.exe" [2008-11-16 335872]
"SetIcon"="\Program Files\WDC\SetIcon.exe" [2004-04-28 42496]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\pgupta\Start Menu\Programs\Startup\
World Clock 2001.LNK - c:\program files\Zada Solutions\World Clock\zsWldClk.exe [2000-8-22 684032]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 45056]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-5-19 24576]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-9-27 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 06:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-24 13:27 87352 —-a-w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1292428093-839522115-1109\Scripts\Logon\0\0]
"Script"=all-au.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-790525478-1292428093-839522115-1297\Scripts\Logon\0\0]
"Script"=all.bat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Codename Max\\max.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\msncall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"53:TCP"= 53:TCP:webserver

R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [6/7/2007 7:10 AM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [6/7/2007 7:10 AM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/7/2007 7:06 PM 24652]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/31/2009 3:40 PM 133104]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [6/23/2004 8:54 PM 23552]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-31 20:39]

2010-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-31 20:39]

2010-02-04 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]

2010-01-28 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2007-06-25 18:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyServer = 192.168.10.101:3128
uInternet Settings,ProxyOverride = maddmzmm1.ingdirect.es;;*.local
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: memetrics.com\project
DPF: {1D95A7C7-3282-4DB7-9A48-7C39CE152A19} - hxxps://myemail.t-mobile.com/html/web/client_tools/TOImport.cab
DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxp://project.memetrics.com/projectserver/objects/pjclient.cab
DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxp://project.memetrics.com/projectserver/objects/1033/pjcintl.cab
FF - ProfilePath - c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_us&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\srenzi\Application Data\Mozilla\Firefox\Profiles\lhjjhsrx.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-03 22:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(864)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\windows\system32\LMIinit.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(1232)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\progra~1\Dantz\RETROS~1\retrorun.exe
c:\progra~1\Dantz\RETROS~1\wdsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\stsystra.exe
c:\program files\Apoint\HidFind.exe
c:\program files\Apoint\Apntex.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\WDBtnMgr.exe
c:\program files\WDC\SetIcon.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\program files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
c:\program files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\HPBPRO.EXE
.
**************************************************************************
.
Completion time: 2010-02-03 22:32:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-04 03:32

Pre-Run: 12,537,458,688 bytes free
Post-Run: 12,724,928,512 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - CF9C08E1CE84032AD31887C386DE6978
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI