This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] "Your system is infected"

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, My step-son turned on his computer the other day to discover a warning message about spyware, informing him that a Trojan had been detected. At first I thought this was a genuine problem until I read the "warning" and noticed the terrible grammar . As a result of this, he cannot access his profile, and on my own profile, the wall paper has changed and cannot be changed back. We cannot access the internet via the PC (I am writing on my laptop). I have run a scan using Norton AV, but this does not appear to have helped at all (I don't know if this will affect anything, but I have not renewed my Norton AV as I cannot afford it!). Having heard horror stories about personal info being stolen via malicious software, I am anxious to sort this problem out. If there is anyone who can offer assistance I would appreciate it greatly. Many thanks Rich p.s. Thanks to JonTom for re-directing me here!
Hi,

Please do the following:

NOTE: exeHelper will run from a USB stick if you have trouble downloading:

Please download exeHelper to your desktop.
  • Double-click on exeHelper.com to run the fix.
  • A black window should pop up, press any key to close once the fix is completed.
  • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi there, I ran the exehelper program and recieved this txt: exeHelper by Raktor Build 20091220 run at 09:09:04 on 02/05/10 Now searching checking for numerical processes checking for sysguard processes checking for bad processes checking for bad files deleting file c:\windows\system32\41.exe error deleting c:\windows\system32\41.exe - set for removal on reboot - please reboot deleting file c:\windows\msa.exe deleting file c:\windows\msb.exe deleting file c:\windows\system32\sdra64.exe error deleting c:\windows\system32\sdra64.exe - set for removal in reboot - please reboot checking for bad registry entries resetting filetype association for .exe resetting filetype association for .com resetting userinit and shell values resetting policies finished I tried running DDS: it prompted a warning box - "Application cannot be executed. the file is infected. please activate antivirus software." i ignored this message as i believe it's part of the infection. DDS appeared to run, but nothing else happened. I have left it now for 15 mins and all that has happened is that it has created the following on my desktop: rundll32, sm56hlpr, smszac32 (2 of them), and soundman. i tried running gmer, but when it came to the scan, it seems to work for a bit and then restarts the computer. Have I done something wrong?
Did your system reboot?

If not - reboot the system - re-run exeHelper then run this program:

Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time.
HI there,
I've run exeHelper again and also OTL. As with other programs, it seems to have gone only so far before stopping. It is saying "Checking service: hkmsvc", and has done nothing else for ten mins or so. Also, it prompted the "warning" window to pop up again. A bubble has also shown up n the bottom right hand corner telling me to click to protect from spyware.

managed to get Gmer to work, here is the resulting info:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-05 13:12:20
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\pxtdypog.sys


—- System - GMER 1.0.15 —-

SSDT 85F8EC90 ZwAlertResumeThread
SSDT 85F8EC58 ZwAlertThread
SSDT 8605FAA8 ZwAllocateVirtualMemory
SSDT 85FE8108 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB7F057D0]
SSDT 8602DAB8 ZwCreateMutant
SSDT 86059008 ZwCreateThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB7F05A40]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB7F06100]
SSDT 860D52E0 ZwFreeVirtualMemory
SSDT 85F8F148 ZwImpersonateAnonymousToken
SSDT 85F8ECC8 ZwImpersonateThread
SSDT 860D7860 ZwMapViewOfSection
SSDT 85F911B8 ZwOpenEvent
SSDT 860FA120 ZwOpenProcessToken
SSDT 861B90F8 ZwOpenThreadToken
SSDT 86032438 ZwResumeThread
SSDT 860481C0 ZwSetContextThread
SSDT 860D8688 ZwSetInformationProcess
SSDT 8601E150 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB7F06330]
SSDT 85F4E1C0 ZwSuspendProcess
SSDT 8601E1C0 ZwSuspendThread
SSDT 860D4BA8 ZwTerminateProcess
SSDT 8601E188 ZwTerminateThread
SSDT 860D4140 ZwUnmapViewOfSection
SSDT 8606EB30 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows ® 2000 DDK provider)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat sisidex.sys (SISIDEX Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Fastfat \Fat sisidex.sys (SISIDEX Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 86ACE856

—- Processes - GMER 1.0.15 —-

Process C:\Program Files\Internet Explorer\wmpscfgs.exe (*** hidden *** ) 2124
Process C:\Program Files\Adobe\acrotray .exe (*** hidden *** ) 2136
Process c:\program files\usb flash disk utility\ufd utility\ufdmon .exe (*** hidden *** ) 3672
Process c:\windows\system32\keyhook .exe (*** hidden *** ) 3708
Process c:\program files\usb flash disk utility\ufd utility\usbtd .exe (*** hidden *** ) 3728
Process c:\program files\microsoft intellipoint\point32 .exe (*** hidden *** ) 3748
Process c:\program files\common files\symantec shared\ccapp .exe (*** hidden *** ) 3812
Process c:\program files\java\jre1.6.0_07\bin\jusched .exe (*** hidden *** ) 3832
Process c:\program files\itunes\ituneshelper .exe (*** hidden *** ) 4028

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-


Hope this is correct, and many thanks for your help also!
Rich
Hi,

Try the following:

Try the following:

copy/paste the links below into your browser, don't click them or you may be redirected.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.


http://download.bleepingcomputer.com/grinler/rkill.exe
http://download.bleepingcomputer.com/grinler/rkill.com
http://download.bleepingcomputer.com/grinler/rkill.scr
http://download.bleepingcomputer.com/grinler/rkill.pif


Note:

You may see a message telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message. Run rkill repeatedly until it's able to do it's job. This may take a few tries. You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

At this point, you should now be able to run analysis tools.

Once the tool has run, do NOT reboot the machine, and then try once again to run DDS and GMER.

If for some reason the machine reboots, repeat the process. Again, try not to restart the machine.



Then try the DDS, GMER and OTL programs again


Do you have access to your task manager (Ctrl + Alt +Del)

If so, list out all the running processes for me.

If there is a process called "warning.html" - end it.
Hi again, ran rKill on PC, which seems to have triggered active desktop recovery - warning b/g has gone, as has the bubble in the bottom right. Gmer info is included in my previous reply (it just worked this time!), however DDS doesn't: "The procedure entry point DoOpenPipeStream could not be located in the dynamic link library ScrRun.dll" I have not closed this box as i am not sure what it is! OTL still crashes at "Checking Service: hkmsvc" system processes are as follows: rundll32.exe dwwin.exe dds.com tabuserw.exe cscript.exe cmd.exe ctfmon.exe notepad.exe explorer.exe taskmgr.exe tablet.exe svchost.exe dumprep.exe ccSvcHost.exe BTNtService.exe AluSchedulerSvc.exe spoolsv.exe iPodService.exe AppSvc32.exe Isass.exe services.exe winlogon.exe csrss.exe smss.exe System System Idle Process [Further edit} DDS worked: DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 13:37:25.40 on 05/02/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.991.592 [GMT 0:00] AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\Owner\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://by124w.bay124.mail.live.com/mail/ApplicationMainReach.aspx?Control=Today uInternet Connection Wizard,ShellNext = iexplore BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll BHO: c:\windows\system32\oprswv96y.dll: {c4bf49a2-94f1-42bd-f034-3604811c807d} - c:\windows\system32\oprswv96y.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [Steam] uRun: [DiskEventChk] smszac32.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [BitTorrent] "c:\program files\bittorrent\bittorrent.exe" –force_start_minimized uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [smss32.exe] c:\windows\system32\smss32.exe mRun: [SiSUSBRG] c:\windows\SiSUSBrg.exe mRun: [SiS Windows KeyHook] c:\windows\system32\keyhook.exe mRun: [SMSERIAL] sm56hlpr.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [UFD Monitor] c:\program files\usb flash disk utility\ufd utility\UFDMon.exe mRun: [UFD Utility] c:\program files\usb flash disk utility\ufd utility\USBTD.exe mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe" mRun: [SoundMan] SOUNDMAN.EXE mRun: [DiskEventChk] smszac32.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask .exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll" mRun: [net] "c:\windows\system32\net.net" mRun: [Vgibuxujabowixa] rundll32.exe "c:\windows\edazenocopo.dll",Startup mRun: [smss32.exe] c:\windows\system32\smss32.exe dRun: [smss32.exe] c:\windows\system32\smss32.exe dRun: [asg984jgkfmgasi8ug98jgkfgfb] c:\windows\temp\smss.exe mExplorerRun: [RTHDBPL] c:\documents and settings\tom\application data\systemproc\lsass.exe uPolicies-system: DisableRegistryTools = 1 (0x1) mPolicies-system: EnableLUA = 0 (0x0) dPolicies-explorer: NoSetActiveDesktop = 1 (0x1) dPolicies-system: DisableRegistryTools = 1 (0x1) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll Trusted Zone: buy-internet-security10.com Trusted Zone: buy-internetsecurity10.com Trusted Zone: is-soft-download.com Trusted Zone: is-software-download.com Trusted Zone: is-software-download25.com Trusted Zone: buy-internet-security10.com Trusted Zone: buy-internetsecurity10.com DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://dirtybizatch.spaces.live.com//PhotoUpload/MsnPUpld.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123501245119 DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - hxxps://www.gamespyid.com/alaunch.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab32846.cab DPF: {BD393C14-72AD-4790-A095-76522973D6B8} - hxxp://messenger.zone.msn.com/binary/Bankshot.cab31267.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: NameServer = 93.188.164.209,93.188.166.18 TCP: {598F3782-FAAA-4D51-A0EA-D7EDCFE7FC44} = 93.188.164.209,93.188.166.18 TCP: {D3A114DF-B1B4-4207-9E8A-2EB5F51D7145} = [removed],[removed] TCP: {FF1904FE-3110-4BD1-B68E-5FF205997C16} = 93.188.164.209,93.188.166.18 AppInit_DLLs: app_dll.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll STS: c:\windows\system32\oprswv96y.dll: {c4bf49a2-94f1-42bd-f034-3604811c807d} - c:\windows\system32\oprswv96y.dll LSA: Notification Packages = scecli prexdp.dll mASetup: {ADEEAF15-7FE8-DEDD-3FFF-4DF56EBB1DFB} - c:\docume~1\owner\locals~1\temp\incognito.exe ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\j0fyj1z1.default user\ FF - prefs.js: browser.search.selectedEngine - Google.co.uk FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\j0fyj1z1.default user\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll FF - HiddenExtension: XULRunner: {1790732E-8ED0-446E-B2A1-E4FD5DB653FE} - c:\documents and settings\tom\local settings\application data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE} FF - HiddenExtension: XULRunner: {8F2E32BE-4934-442D-864D-547A1B69FCDC} - c:\documents and settings\owner\local settings\application data\{8F2E32BE-4934-442D-864D-547A1B69FCDC} FF - HiddenExtension: Firefox security: No Registry Reference - c:\program files\mozilla firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-10 108648] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-10 108648] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2007-11-12 112688] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20071111.007\NAVENG.SYS [2007-11-12 81232] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20071111.007\NAVEX15.SYS [2007-11-12 865904] S3 AlcrFilt;Alcor Micro Corp;c:\windows\system32\drivers\AlcrFilt.sys [2003-2-24 22860] S3 BTUsbrXP®;BT Voyager 1010 USB Adapter;c:\windows\system32\drivers\btusbrxp.sys –> c:\windows\system32\drivers\btusbrxp.sys [?] S3 FXDRV;FXDRV;\??\d:\fxdrv.sys –> d:\Fxdrv.sys [?] S3 RTLWUSB;USB 54M Wireless Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2006-9-20 167936] S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-2-14 1252232] =============== Created Last 30 ================ 2010-02-05 11:19:29 4 —-a-w- c:\program files\6445765.dat 2010-02-05 11:04:28 0 —-a-w- c:\windows\system32\19169.exe 2010-02-05 10:33:43 0 —-a-w- c:\windows\system32\26500.exe 2010-02-05 10:13:43 0 —-a-w- c:\windows\system32\6334.exe 2010-02-05 09:53:42 0 —-a-w- c:\windows\system32\18467.exe 2010-02-05 09:23:01 0 d-sh–w- c:\documents and settings\owner\PrivacIE 2010-02-05 09:14:06 0 —-a-w- c:\windows\system32\41.exe 2010-02-03 18:39:24 39424 —-a-w- c:\documents and settings\owner\rundll32.exe 2010-02-03 18:39:24 39424 —-a-w- c:\documents and settings\owner\rundll32 .exe 2010-02-03 18:39:14 39424 —-a-w- c:\documents and settings\owner\soundman.exe 2010-02-03 18:39:14 39424 —-a-w- c:\documents and settings\owner\soundman .exe 2010-02-03 18:39:09 39424 —-a-w- c:\documents and settings\owner\sm56hlpr.exe 2010-02-03 18:39:09 39424 —-a-w- c:\documents and settings\owner\sm56hlpr .exe 2010-02-03 18:39:03 39424 —-a-w- c:\documents and settings\owner\smszac32.exe 2010-02-03 18:39:03 39424 —-a-w- c:\documents and settings\owner\smszac32 .exe 2010-02-03 18:27:25 0 —-a-w- c:\windows\system32\IS15.exe 2010-02-03 18:27:25 0 —-a-w- c:\windows\system32\41.exe.vir 2010-02-03 18:27:24 0 —-a-w- c:\windows\system32\helper32.dll 2010-02-03 18:27:23 2931 —-a-w- c:\windows\system32\warning.html 2010-02-03 16:27:34 69120 —-a-w- c:\windows\system32\app_dll.dll 2010-02-03 16:27:18 114176 —-a-w- C:\xmjkek.exe 2010-01-30 16:27:36 0 —-a-w- c:\windows\Dwedi.bin 2010-01-30 16:27:33 120 —-a-w- c:\windows\Xrohabi.dat 2010-01-30 16:23:45 138752 —-a-w- c:\windows\msb .exe 2010-01-30 16:19:36 20000 —-a-w- c:\windows\system32\oprswv96y.dll 2010-01-30 16:19:36 0 d-sh–w- c:\windows\system32\lowsec 2010-01-30 16:15:00 30720 —-a-w- C:\dqccpnq.exe 2010-01-30 16:14:57 176128 —-a-w- C:\kkalf.exe 2010-01-30 16:14:56 52224 —-a-w- C:\ojjw.exe 2010-01-30 16:14:55 114688 —-a-w- C:\horj.exe 2010-01-30 16:14:54 16896 —-a-w- C:\duehpow.exe 2010-01-30 16:12:35 57828 —-a-w- c:\windows\system32\net.net 2010-01-12 18:59:41 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll ==================== Find3M ==================== 2010-02-05 12:24:52 39424 —-a-w- c:\windows\system32\smszac32.exe 2010-02-05 12:24:51 39424 —-a-w- c:\windows\system32\soundman.exe 2010-02-05 12:24:46 39424 —-a-w- c:\windows\system32\nerocheck.exe 2010-02-05 12:24:44 39424 —-a-w- c:\windows\system32\sm56hlpr.exe 2010-02-05 12:24:43 39424 —-a-w- c:\windows\system32\keyhook.exe 2010-02-05 12:24:41 39424 —-a-w- c:\windows\sisusbrg.exe 2010-02-05 12:22:01 12395 —-a-w- c:\windows\system32\tablet.dat 2010-02-05 09:52:23 96512 —-a-w- c:\windows\system32\drivers\atapi.sys 2010-02-03 16:27:57 26624 —-a-w- C:\hnftrf.exe 2010-02-03 16:27:25 114176 —-a-w- C:\qhdh.exe 2010-02-03 16:27:18 19456 —-a-w- C:\omav.exe 2010-02-03 16:27:18 124416 —-a-w- C:\vpwjq.exe 2010-02-03 16:26:52 39424 —-a-w- c:\windows\system32\smszac32 .exe 2010-02-03 16:26:51 39424 —-a-w- c:\windows\system32\soundman .exe 2010-02-03 16:26:46 39424 —-a-w- c:\windows\system32\sm56hlpr .exe 2010-02-03 16:26:23 39424 —-a-w- C:\qxbtlpjm.exe 2010-02-03 16:26:22 32256 —-a-w- c:\windows\system32\winlogon32.exe 2010-02-03 16:26:22 32256 —-a-w- c:\windows\system32\smss32.exe 2010-02-03 16:26:22 32256 —-a-w- c:\windows\system32\smss32 .exe 2010-02-03 16:26:22 32256 —-a-w- C:\ugts.exe 2009-12-21 19:14:05 916480 —-a-w- c:\windows\system32\wininet.dll 2005-09-17 01:02:09 774144 —-a-w- c:\program files\RngInterstitial.dll 2005-09-14 13:04:03 1116 —-a-w- c:\program files\edge.ico 2005-09-14 13:04:01 3 —-a-w- c:\program files\gp.info 2005-04-06 12:00:28 1240 -c–a-w- c:\program files\banner.html 2004-02-11 12:21:26 43 -c–a-w- c:\program files\AUTORUN.INF 2004-02-11 11:14:22 153644 -c–a-w- c:\program files\Setup.inx 2004-02-09 11:06:10 77671751 —-a-w- c:\program files\data2.cab 2004-02-09 11:06:10 417 -c–a-w- c:\program files\layout.bin 2004-02-09 11:06:10 135527 -c–a-w- c:\program files\data1.hdr 2004-02-09 11:06:00 1009211 -c–a-w- c:\program files\data1.cab 2004-02-09 11:05:50 245 —-a-w- c:\program files\Setup.ini 2003-08-29 09:46:10 25214 -c–a-w- c:\program files\autorun.ico 2003-05-22 16:13:42 26 -c–a-w- c:\program files\AUTORUN.ID 2002-07-25 18:07:36 346602 -c–a-w- c:\program files\ikernel.ex_ 2001-09-05 07:03:14 168448 —-a-w- c:\program files\Setup.exe 1998-07-23 16:36:52 4173 -c–a-w- c:\program files\AUTORUN.EXE 2009-05-01 20:03:31 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009050120090502\index.dat ============= FINISH: 13:38:49.70 ===============
Good stuff

Please run the following program

May sure you say "Yes" to allow the recovery console to install:



Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi there,

I ran ComboFix but could not install the windows recovery console - the program ran any way and here is the result:

ComboFix 10-02-04.06 - Owner 05/02/2010 14:49:33.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.991.522 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\rundll32 .exe
c:\documents and settings\Owner\rundll32.exe
c:\documents and settings\Owner\sm56hlpr .exe
c:\documents and settings\Owner\sm56hlpr.exe
c:\documents and settings\Owner\smszac32 .exe
c:\documents and settings\Owner\smszac32.exe
c:\documents and settings\Owner\soundman .exe
c:\documents and settings\Owner\soundman.exe
c:\documents and settings\Tom\Application Data\AntiVirus Plus
c:\documents and settings\Tom\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll
c:\documents and settings\Tom\Application Data\sdra64.exe
c:\documents and settings\Tom\Application Data\SystemProc
c:\documents and settings\Tom\Application Data\SystemProc\lsass.exe
c:\documents and settings\Tom\rundll32.exe
c:\documents and settings\Tom\sm56hlpr.exe
c:\documents and settings\Tom\smszac32.exe
c:\documents and settings\Tom\soundman.exe
c:\program files\\setup.exe
c:\program files\Adobe\acrotray .exe
c:\program files\autorun.inf
c:\program files\Internet Explorer\js.mui
c:\program files\Internet Explorer\wmpscfgs.exe
C:\s
c:\windows\edazenocopo.dll
c:\windows\msb .exe
c:\windows\sisusbrg .exe
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\app_dll.dll
c:\windows\system32\ctfmon .exe
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\system32\keyhook .exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\nerocheck .exe
c:\windows\system32\net.net
c:\windows\system32\oprswv96y.dll
c:\windows\system32\reboot.txt
c:\windows\system32\rundll32 .exe
c:\windows\system32\sdra64.exe
c:\windows\system32\sm56hlpr .exe
c:\windows\system32\smss32 .exe
c:\windows\system32\smss32.exe
c:\windows\system32\smszac32 .exe
c:\windows\system32\soundman .exe
c:\windows\system32\spool\prtprocs\w32x86\0000181c.tmp
c:\windows\system32\warning.html
c:\windows\system32\winlogon32.exe
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
c:\windows\TEMP\00000c49.sys
c:\windows\Temp\3177315136.exe
c:\windows\Temp\3856098038.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_00000c49.sys


((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.

2010-02-05 11:19 . 2010-02-05 11:19 4 —-a-w- c:\program files\6445765.dat
2010-02-05 09:23 . 2010-02-05 09:23 ——– d-sh–w- c:\documents and settings\Owner\PrivacIE
2010-02-03 18:27 . 2010-02-05 09:07 0 —-a-w- c:\windows\system32\41.exe.vir
2010-02-03 16:29 . 2010-02-03 16:29 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-02-03 16:27 . 2010-02-03 16:27 114176 —-a-w- C:\xmjkek.exe
2010-02-03 16:26 . 2010-02-05 12:24 39424 —-a-w- c:\windows\system32\smszac32.exe
2010-02-03 16:26 . 2010-02-05 12:24 39424 —-a-w- c:\windows\system32\soundman.exe
2010-02-03 16:26 . 2010-02-05 14:51 39424 —-a-w- c:\windows\system32\sm56hlpr.exe
2010-02-03 16:26 . 2010-02-03 16:27 19456 —-a-w- C:\omav.exe
2010-02-03 16:26 . 2010-02-03 16:27 26624 —-a-w- C:\hnftrf.exe
2010-02-03 16:26 . 2010-02-03 16:27 114176 —-a-w- C:\qhdh.exe
2010-02-03 16:26 . 2010-02-03 16:27 124416 —-a-w- C:\vpwjq.exe
2010-02-03 16:26 . 2010-02-03 16:26 32256 —-a-w- C:\ugts.exe
2010-02-03 16:26 . 2010-02-03 16:26 39424 —-a-w- C:\qxbtlpjm.exe
2010-02-02 10:57 . 2010-02-02 10:57 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}
2010-01-30 17:41 . 2010-01-30 17:41 336896 –sha-w- c:\documents and settings\Tom\Local Settings\Application Data\av.exe
2010-01-30 17:01 . 2010-01-30 17:01 ——– d—–w- c:\documents and settings\Tom\Application Data\AdobeUM
2010-01-30 16:27 . 2010-02-05 09:05 0 —-a-w- c:\windows\Dwedi.bin
2010-01-30 16:27 . 2010-02-03 18:27 120 —-a-w- c:\windows\Xrohabi.dat
2010-01-30 16:27 . 2010-01-30 16:27 ——– d—–w- c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}
2010-01-30 16:15 . 2010-01-30 16:17 30720 —-a-w- C:\dqccpnq.exe
2010-01-30 16:14 . 2010-01-30 16:17 176128 —-a-w- C:\kkalf.exe
2010-01-30 16:14 . 2010-01-30 16:17 52224 —-a-w- C:\ojjw.exe
2010-01-30 16:14 . 2010-01-30 16:17 114688 —-a-w- C:\horj.exe
2010-01-30 16:14 . 2010-01-30 16:17 16896 —-a-w- C:\duehpow.exe
2010-01-12 18:59 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 15:15 . 2007-02-14 18:45 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-02-05 15:12 . 2007-03-20 18:45 ——– d—–w- c:\program files\iTunes
2010-02-05 15:12 . 2007-03-07 21:19 ——– d—–w- c:\program files\QuickTime
2010-02-05 15:12 . 2005-09-20 14:51 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-02-05 15:12 . 2005-08-08 11:44 39424 —-a-w- c:\windows\system32\nerocheck.exe
2010-02-05 15:12 . 2005-08-08 11:35 39424 —-a-w- c:\windows\system32\keyhook.exe
2010-02-05 15:10 . 2006-02-24 15:28 12395 —-a-w- c:\windows\system32\tablet.dat
2010-02-05 15:02 . 2007-02-14 18:52 ——– d—–w- c:\program files\Norton Internet Security
2010-02-05 15:02 . 2005-08-08 11:33 39424 —-a-w- c:\windows\sisusbrg.exe
2010-02-05 09:52 . 2004-08-04 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-02-03 16:23 . 2007-02-14 18:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-21 19:14 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 15:51 . 2004-08-04 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2005-09-17 01:02 . 2005-09-17 01:02 774144 —-a-w- c:\program files\RngInterstitial.dll
2005-09-14 13:04 . 2005-09-14 12:55 1116 —-a-w- c:\program files\edge.ico
2005-09-14 13:04 . 2005-09-14 12:59 3 —-a-w- c:\program files\gp.info
2005-04-06 12:00 . 2005-09-14 12:54 1240 -c–a-w- c:\program files\banner.html
2004-02-11 11:14 . 2006-02-25 23:01 153644 -c–a-w- c:\program files\Setup.inx
2004-02-09 11:06 . 2006-02-25 23:01 417 -c–a-w- c:\program files\layout.bin
2004-02-09 11:06 . 2006-02-25 23:01 77671751 —-a-w- c:\program files\data2.cab
2004-02-09 11:06 . 2006-02-25 23:01 135527 -c–a-w- c:\program files\data1.hdr
2004-02-09 11:06 . 2006-02-25 23:01 1009211 -c–a-w- c:\program files\data1.cab
2004-02-09 11:05 . 2006-02-25 23:01 245 —-a-w- c:\program files\Setup.ini
2003-08-29 09:46 . 2006-02-25 23:01 25214 -c–a-w- c:\program files\autorun.ico
2003-05-22 16:13 . 2006-02-25 23:01 26 -c–a-w- c:\program files\AUTORUN.ID
2002-07-25 18:07 . 2006-02-25 23:01 346602 -c–a-w- c:\program files\ikernel.ex_
1998-07-23 16:36 . 2006-02-25 23:01 4173 -c–a-w- c:\program files\AUTORUN.EXE
.
c:\program files\Common Files\Symantec Shared\ccapp .exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre1.6.0_07\bin\jusched .exe
c:\program files\Microsoft IntelliPoint\point32 .exe
c:\program files\Norton Internet Security\oscheck .exe
c:\program files\QuickTime\qttask	   .exe
c:\program files\QuickTime\qttask	  .exe
c:\program files\QuickTime\qttask	 .exe
c:\program files\QuickTime\qttask	.exe
c:\program files\QuickTime\qttask   .exe
c:\program files\QuickTime\qttask  .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Skype\Phone\skype .exe
c:\program files\USB Flash Disk Utility\UFD Utility\ufdmon .exe
c:\program files\USB Flash Disk Utility\UFD Utility\usbtd .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [N/A]
"Steam"="" [N/A]
"DiskEventChk"="smszac32.exe" [2010-02-05 39424]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-05 39424]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [N/A]
"smss32.exe"="c:\windows\system32\smss32.exe" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\quicktime\qttask .exe -atboottime" [X]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2010-02-05 39424]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2010-02-05 39424]
"SMSERIAL"="sm56hlpr.exe" [2010-02-05 39424]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2010-02-05 39424]
"UFD Monitor"="c:\program files\USB Flash Disk Utility\UFD Utility\UFDMon.exe" [2010-02-05 39424]
"UFD Utility"="c:\program files\USB Flash Disk Utility\UFD Utility\USBTD.exe" [2010-02-05 39424]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2010-02-05 39424]
"SoundMan"="SOUNDMAN.EXE" [2010-02-05 39424]
"DiskEventChk"="smszac32.exe" [2010-02-05 39424]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2010-02-05 39424]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2010-02-05 39424]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2010-02-05 39424]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-05 39424]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2010-02-05 39424]
"Vgibuxujabowixa"="c:\windows\edazenocopo.dll" [N/A]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"smss32.exe"="c:\windows\system32\smss32.exe" [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"RTHDBPL"="c:\documents and settings\Tom\Application Data\SystemProc\lsass.exe" [N/A]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-2-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-1-31 1183744]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-2-24 106496]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli prexdp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\14 Degrees East\\Fallout Tactics\\BOS.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\WINDOWS\\system32\\smszac32.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/11/2007 18:25 112688]
R3 RTLWUSB;USB 54M Wireless Network Adapter;c:\windows\system32\drivers\RTL8187.sys [20/09/2006 16:55 167936]
S3 AlcrFilt;Alcor Micro Corp;c:\windows\system32\drivers\AlcrFilt.sys [24/02/2003 10:15 22860]
S3 BTUsbrXP®;BT Voyager 1010 USB Adapter;c:\windows\system32\DRIVERS\btusbrxp.sys –> c:\windows\system32\DRIVERS\btusbrxp.sys [?]
S3 FXDRV;FXDRV;\??\d:\fxdrv.sys –> d:\Fxdrv.sys [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ADEEAF15-7FE8-DEDD-3FFF-4DF56EBB1DFB}]
c:\docume~1\Owner\LOCALS~1\Temp\incognito.exe [N/A]
.
Contents of the 'Scheduled Tasks' folder

2009-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2006-11-05 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8126701198.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]

2010-01-18 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-01-14 09:09]

2010-02-05 c:\windows\Tasks\User_Feed_Synchronization-{A4C7DF90-1DC8-43C5-99FD-910C7D322751}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://by124w.bay124.mail.live.com/mail/ApplicationMainReach.aspx?Control=Today
uInternet Connection Wizard,ShellNext = iexplore
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
TCP: {598F3782-FAAA-4D51-A0EA-D7EDCFE7FC44} = [removed],[removed]
TCP: {D3A114DF-B1B4-4207-9E8A-2EB5F51D7145} = 93.188.164.209,93.188.166.18
TCP: {FF1904FE-3110-4BD1-B68E-5FF205997C16} = 93.188.164.209,93.188.166.18
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: XULRunner: {1790732E-8ED0-446E-B2A1-E4FD5DB653FE} - c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}
FF - HiddenExtension: XULRunner: {8F2E32BE-4934-442D-864D-547A1B69FCDC} - c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}
.
- - - - ORPHANS REMOVED - - - -

BHO-{C4BF49A2-94F1-42BD-F034-3604811C807D} - c:\windows\system32\oprswv96y.dll
SharedTaskScheduler-{C4BF49A2-94F1-42BD-F034-3604811C807D} - c:\windows\system32\oprswv96y.dll
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9b.exe
AddRemove-VobSub - c:\program files\Gabest\VobSub\uninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-05 15:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
RTHDBPL = c:\documents and settings\Tom\Application Data\SystemProc\lsass.exe?#???????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86AD3856]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7604f28
\Driver\ACPI -> ACPI.sys @ 0xf7577cb8
\Driver\atapi -> atapi.sys @ 0xf752f852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fd,e0,cc,8f,b7,21,09,40,95,6e,e4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fd,e0,cc,8f,b7,21,09,40,95,6e,e4,\

[HKEY_USERS\S-1-5-21-839522115-602609370-2147062339-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(816)
c:\windows\system32\WININET.dll
c:\windows\prexdp.dll

- - - - - - - > 'explorer.exe'(2876)
c:\windows\system32\WININET.dll
c:\windows\system32\tabhook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\prexdp.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\system32\Tablet.exe
c:\program files\usb flash disk utility\ufd utility\ufdmon .exe
c:\program files\microsoft intellipoint\point32 .exe
c:\program files\usb flash disk utility\ufd utility\usbtd .exe
c:\program files\java\jre1.6.0_07\bin\jusched .exe
c:\program files\common files\symantec shared\ccapp .exe
c:\program files\itunes\ituneshelper .exe
c:\program files\quicktime\qttask .exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\java\jre1.6.0_07\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-02-05 15:27:23 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-05 15:27

Pre-Run: 22,700,576,768 bytes free
Post-Run: 23,586,934,784 bytes free

- - End Of File - - 8F58602AE1A3F23F144E3BC55FE65E39
Hi,

please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Your_system_infected_t110029.html&view=findpost&p=630537#entry630537

Collect::
c:\program files\6445765.dat
C:\xmjkek.exe
c:\windows\system32\smszac32.exe
c:\windows\system32\soundman.exe
c:\windows\system32\sm56hlpr.exe
C:\omav.exe
C:\hnftrf.exe
C:\qhdh.exe
C:\vpwjq.exe
C:\ugts.exe
C:\qxbtlpjm.exe
c:\documents and settings\Tom\Local Settings\Application Data\av.exe
C:\dqccpnq.exe
C:\kkalf.exe
C:\ojjw.exe
C:\horj.exe
C:\duehpow.exe
c:\docume~1\Owner\LOCALS~1\Temp\incognito.exe 

File::
c:\windows\Dwedi.bin
c:\windows\Xrohabi.dat
c:\windows\system32\41.exe.vir

Folder::
c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}
c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}


RenV::
c:\program files\Common Files\Symantec Shared\ccapp .exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre1.6.0_07\bin\jusched .exe
c:\program files\Microsoft IntelliPoint\point32 .exe
c:\program files\Norton Internet Security\oscheck .exe
c:\program files\QuickTime\qttask	   .exe
c:\program files\QuickTime\qttask	  .exe
c:\program files\QuickTime\qttask	 .exe
c:\program files\QuickTime\qttask	.exe
c:\program files\QuickTime\qttask   .exe
c:\program files\QuickTime\qttask  .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Skype\Phone\skype .exe
c:\program files\USB Flash Disk Utility\UFD Utility\ufdmon .exe
c:\program files\USB Flash Disk Utility\UFD Utility\usbtd .exe

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"smss32.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vgibuxujabowixa"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"smss32.exe"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"RTHDBPL"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ADEEAF15-7FE8-DEDD-3FFF-4DF56EBB1DFB}]

DDS::
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
TCP: {598F3782-FAAA-4D51-A0EA-D7EDCFE7FC44} = [removed],[removed]
TCP: {D3A114DF-B1B4-4207-9E8A-2EB5F51D7145} = [removed],93.188.166.18
TCP: {FF1904FE-3110-4BD1-B68E-5FF205997C16} = 93.188.164.209,93.188.166.18

FireFox::
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\
FF - HiddenExtension: XULRunner: {1790732E-8ED0-446E-B2A1-E4FD5DB653FE} - c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}
FF - HiddenExtension: XULRunner: {8F2E32BE-4934-442D-864D-547A1B69FCDC} - c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}

RootKit::
c:\documents and settings\Tom\Application Data\SystemProc\lsass.exe

RegLock::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Hi There,
Sorry I took so long to reply.
Here is the log you requested:

ComboFix 10-02-04.06 - Owner 08/02/2010 12:40:02.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.991.744 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt

FILE ::
"c:\windows\Dwedi.bin"
"c:\windows\system32\41.exe.vir"
"c:\windows\Xrohabi.dat"

file zipped: c:\documents and settings\Tom\Local Settings\Application Data\av.exe
file zipped: C:\dqccpnq.exe
file zipped: C:\duehpow.exe
file zipped: C:\hnftrf.exe
file zipped: C:\horj.exe
file zipped: C:\kkalf.exe
file zipped: C:\ojjw.exe
file zipped: C:\omav.exe
file zipped: c:\program files\6445765.dat
file zipped: C:\qhdh.exe
file zipped: C:\qxbtlpjm.exe
file zipped: C:\ugts.exe
file zipped: C:\vpwjq.exe
file zipped: c:\windows\system32\sm56hlpr.exe
file zipped: c:\windows\system32\smszac32.exe
file zipped: c:\windows\system32\soundman.exe
file zipped: C:\xmjkek.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}
c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}\install.rdf
c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}
c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}\chrome.manifest
c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}\chrome\content\_cfg.js
c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}\chrome\content\overlay.xul
c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}\install.rdf
c:\documents and settings\Tom\Local Settings\Application Data\av.exe
C:\dqccpnq.exe
C:\duehpow.exe
C:\hnftrf.exe
C:\horj.exe
C:\kkalf.exe
C:\ojjw.exe
C:\omav.exe
c:\program files\6445765.dat
c:\program files\Internet Explorer\js.mui
c:\program files\Internet Explorer\wmpscfgs.exe
C:\qhdh.exe
C:\qxbtlpjm.exe
C:\ugts.exe
C:\vpwjq.exe
c:\windows\Dwedi.bin
c:\windows\sisusbrg .exe
c:\windows\system32\41.exe.vir
c:\windows\system32\keyhook .exe
c:\windows\system32\nerocheck .exe
c:\windows\system32\rundll32 .exe
c:\windows\system32\sm56hlpr .exe
c:\windows\system32\sm56hlpr.exe
c:\windows\system32\smss32.exe
c:\windows\system32\smszac32 .exe
c:\windows\system32\smszac32.exe
c:\windows\system32\soundman .exe
c:\windows\system32\soundman.exe
c:\windows\system32\Vbshell.tlb
c:\windows\Xrohabi.dat
C:\xmjkek.exe

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
.

2010-02-05 16:18 . 2010-02-05 16:46 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-05 16:17 . 2010-02-05 16:17 ——– d—–w- c:\program files\SpywareBlaster
2010-02-05 16:16 . 2010-02-05 16:17 ——– d—–w- c:\program files\SpywareGuard
2010-02-05 09:23 . 2010-02-05 09:23 ——– d-sh–w- c:\documents and settings\Owner\PrivacIE
2010-02-03 16:29 . 2010-02-03 16:29 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-01-30 17:01 . 2010-01-30 17:01 ——– d—–w- c:\documents and settings\Tom\Application Data\AdobeUM
2010-01-12 18:59 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-08 12:50 . 2007-03-20 18:45 ——– d—–w- c:\program files\iTunes
2010-02-08 12:50 . 2007-03-07 21:19 ——– d—–w- c:\program files\QuickTime
2010-02-08 12:50 . 2010-02-08 12:49 39424 —-a-w- c:\documents and settings\Owner\smszac32.exe
2010-02-08 12:50 . 2010-02-08 12:50 39424 —-a-w- c:\documents and settings\Owner\soundman.exe
2010-02-08 12:50 . 2005-09-20 14:51 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-02-08 12:50 . 2005-08-08 11:44 39424 —-a-w- c:\windows\system32\nerocheck.exe
2010-02-08 12:50 . 2010-02-08 12:50 39424 —-a-w- c:\documents and settings\Owner\sm56hlpr.exe
2010-02-08 12:50 . 2005-08-08 11:35 39424 —-a-w- c:\windows\system32\keyhook.exe
2010-02-08 12:49 . 2010-02-08 12:49 39424 —-a-w- c:\documents and settings\Owner\smszac32 .exe
2010-02-08 12:48 . 2006-02-24 15:28 12395 —-a-w- c:\windows\system32\tablet.dat
2010-02-08 12:39 . 2007-02-14 18:45 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-02-08 12:26 . 2005-08-08 11:44 39424 —-a-w- c:\windows\system32\nerocheck .exe
2010-02-08 12:26 . 2005-08-08 11:35 39424 —-a-w- c:\windows\system32\keyhook .exe
2010-02-08 12:26 . 2005-08-08 11:33 39424 —-a-w- c:\windows\sisusbrg.exe
2010-02-08 12:25 . 2007-02-14 18:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-02-05 16:09 . 2005-09-27 20:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-05 16:09 . 2005-09-27 20:10 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-05 09:52 . 2004-08-04 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-12-21 19:14 . 2004-08-04 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-11-21 15:51 . 2004-08-04 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2005-09-17 01:02 . 2005-09-17 01:02 774144 —-a-w- c:\program files\RngInterstitial.dll
2005-09-14 13:04 . 2005-09-14 12:55 1116 —-a-w- c:\program files\edge.ico
2005-09-14 13:04 . 2005-09-14 12:59 3 —-a-w- c:\program files\gp.info
2005-04-06 12:00 . 2005-09-14 12:54 1240 -c–a-w- c:\program files\banner.html
2004-02-11 11:14 . 2006-02-25 23:01 153644 -c–a-w- c:\program files\Setup.inx
2004-02-09 11:06 . 2006-02-25 23:01 417 -c–a-w- c:\program files\layout.bin
2004-02-09 11:06 . 2006-02-25 23:01 77671751 —-a-w- c:\program files\data2.cab
2004-02-09 11:06 . 2006-02-25 23:01 135527 -c–a-w- c:\program files\data1.hdr
2004-02-09 11:06 . 2006-02-25 23:01 1009211 -c–a-w- c:\program files\data1.cab
2004-02-09 11:05 . 2006-02-25 23:01 245 —-a-w- c:\program files\Setup.ini
2003-08-29 09:46 . 2006-02-25 23:01 25214 -c–a-w- c:\program files\autorun.ico
2003-05-22 16:13 . 2006-02-25 23:01 26 -c–a-w- c:\program files\AUTORUN.ID
2002-07-25 18:07 . 2006-02-25 23:01 346602 -c–a-w- c:\program files\ikernel.ex_
1998-07-23 16:36 . 2006-02-25 23:01 4173 -c–a-w- c:\program files\AUTORUN.EXE
.
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre1.6.0_07\bin\jusched .exe
c:\program files\Microsoft IntelliPoint\point32 .exe
c:\program files\QuickTime\qttask		 .exe
c:\program files\QuickTime\qttask		.exe
c:\program files\Skype\Phone\skype .exe
c:\program files\USB Flash Disk Utility\UFD Utility\ufdmon .exe
c:\program files\USB Flash Disk Utility\UFD Utility\usbtd .exe
c:\windows\system32\keyhook .exe
c:\windows\system32\nerocheck .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [N/A]
"Steam"="" [N/A]
"DiskEventChk"="smszac32.exe" [N/A]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-08 39424]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\quicktime\qttask .exe -atboottime" [X]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2010-02-08 39424]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2010-02-08 39424]
"SMSERIAL"="sm56hlpr.exe" [2005-08-24 548864]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2010-02-08 39424]
"UFD Monitor"="c:\program files\USB Flash Disk Utility\UFD Utility\UFDMon.exe" [2010-02-08 39424]
"UFD Utility"="c:\program files\USB Flash Disk Utility\UFD Utility\USBTD.exe" [2010-02-08 39424]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2010-02-08 39424]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 90112]
"DiskEventChk"="smszac32.exe" [N/A]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2010-02-08 39424]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-08 39424]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2010-02-08 39424]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-2-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-1-31 1183744]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-2-24 106496]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli prexdp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\14 Degrees East\\Fallout Tactics\\BOS.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

S3 AlcrFilt;Alcor Micro Corp;c:\windows\system32\drivers\AlcrFilt.sys [24/02/2003 10:15 22860]
S3 BTUsbrXP®;BT Voyager 1010 USB Adapter;c:\windows\system32\DRIVERS\btusbrxp.sys –> c:\windows\system32\DRIVERS\btusbrxp.sys [?]
S3 FXDRV;FXDRV;\??\d:\fxdrv.sys –> d:\Fxdrv.sys [?]
S3 RTLWUSB;USB 54M Wireless Network Adapter;c:\windows\system32\drivers\RTL8187.sys [20/09/2006 16:55 167936]
.
Contents of the 'Scheduled Tasks' folder

2009-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2010-02-08 c:\windows\Tasks\At1.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At10.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At11.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At12.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At13.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At14.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At15.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At16.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At17.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At18.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At19.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At2.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At20.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At21.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At22.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At23.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At24.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At3.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At4.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At5.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At6.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At7.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At8.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2010-02-08 c:\windows\Tasks\At9.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 12:50]

2006-11-05 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8126701198.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]

2010-02-08 c:\windows\Tasks\User_Feed_Synchronization-{A4C7DF90-1DC8-43C5-99FD-910C7D322751}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://by124w.bay124.mail.live.com/mail/ApplicationMainReach.aspx?Control=Today
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-08 12:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\nerocheck .exe 39424 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-839522115-602609370-2147062339-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(656)
c:\windows\prexdp.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2408)
c:\windows\system32\WININET.dll
c:\windows\system32\tabhook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\prexdp.dll
.
———————— Other Running Processes ————————
.
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\Tablet.exe
c:\windows\system32\wscntfy.exe
c:\windows\sm56hlpr.exe
c:\windows\SOUNDMAN.EXE
c:\program files\quicktime\qttask .exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-02-08 12:56:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-08 12:56
ComboFix2.txt 2010-02-05 15:27

Pre-Run: 24,077,619,200 bytes free
Post-Run: 24,048,357,376 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 8AE8076896148EABFE2F2809F8D26D24


Many thanks
Rich
Hi,

we have more work to do I'm afraid.

The files I had requested to upload didn't go automatically, so we have to upload them manually:

Please do the following:

Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/Your_system_infected_t110029.html

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip ( the * denotes Date and Time stamp - yours will be close to this 08/02/2010 12:40:02)
Select this file and click Open
In the Largest box please put
File Requested By CatByte 
Failed Submit::

Finally click SendFile

Please return here and let me know when that file has been uploaded.


NEXT


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Your_system_infected_t110029.html&view=findpost&p=631290#entry631290

Collect::
c:\documents and settings\Owner\smszac32.exe
c:\documents and settings\Owner\smszac32 .exe
c:\windows\system32\nerocheck .exe
c:\windows\system32\keyhook .exe
c:\windows\prexdp.dll
c:\program files\quicktime\qttask .exe

RenV::
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre1.6.0_07\bin\jusched .exe
c:\program files\Microsoft IntelliPoint\point32 .exe
c:\program files\QuickTime\qttask  .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Skype\Phone\skype .exe
c:\program files\USB Flash Disk Utility\UFD Utility\ufdmon .exe
c:\program files\USB Flash Disk Utility\UFD Utility\usbtd .exe
c:\windows\system32\keyhook .exe
c:\windows\system32\nerocheck .exe

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DiskEventChk"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\quicktime\qttask.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DiskEventChk"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00

AtJob::

Rootkit::
c:\windows\system32\nerocheck .exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Here is the Combofix log as requested:

Here is the combofix log:

ComboFix 10-02-07.07 - Owner 08/02/2010 13:57:42.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.991.580 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

file zipped: c:\documents and settings\Owner\smszac32 .exe
file zipped: c:\documents and settings\Owner\smszac32.exe
file zipped: c:\windows\prexdp.dll
file zipped: c:\windows\system32\keyhook .exe
file zipped: c:\windows\system32\nerocheck .exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\sm56hlpr.exe
c:\documents and settings\Owner\smszac32 .exe
c:\documents and settings\Owner\smszac32.exe
c:\documents and settings\Owner\soundman.exe
c:\program files\Internet Explorer\js.mui
c:\program files\Internet Explorer\wmpscfgs.exe
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul
c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
c:\windows\prexdp.dll
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job

.
((((((((((((((((((((((((( Files Created from 2010-01-08 to 2010-02-08 )))))))))))))))))))))))))))))))
.

2010-02-08 13:19 . 2010-02-08 13:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo
2010-02-08 13:18 . 2010-02-08 13:18 87104 —-a-w- c:\windows\system32\drivers\inspect.sys
2010-02-08 13:18 . 2010-02-08 13:18 25160 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-02-08 13:18 . 2010-02-08 13:18 171552 —-a-w- c:\windows\system32\guard32.dll
2010-02-08 13:18 . 2010-02-08 13:18 134344 —-a-w- c:\windows\system32\drivers\cmdguard.sys
2010-02-08 13:18 . 2010-02-08 13:18 ——– d—–w- c:\program files\COMODO
2010-02-08 13:13 . 2010-02-08 13:13 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\AVG Security Toolbar
2010-02-05 09:23 . 2010-02-05 09:23 ——– d-sh–w- c:\documents and settings\Owner\PrivacIE
2010-02-03 16:29 . 2010-02-03 16:29 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-01-30 17:01 . 2010-01-30 17:01 ——– d—–w- c:\documents and settings\Tom\Application Data\AdobeUM
2010-01-12 18:59 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-08 14:11 . 2007-03-20 18:45 ——– d—–w- c:\program files\iTunes
2010-02-08 14:11 . 2007-03-07 21:19 ——– d—–w- c:\program files\QuickTime
2010-02-08 14:11 . 2010-02-08 14:11 39424 —-a-w- c:\documents and settings\Owner\soundman.exe
2010-02-08 14:11 . 2005-09-20 14:51 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-02-08 14:11 . 2005-08-08 11:44 39424 —-a-w- c:\windows\system32\nerocheck.exe
2010-02-08 14:11 . 2010-02-08 14:11 39424 —-a-w- c:\documents and settings\Owner\sm56hlpr.exe
2010-02-08 14:11 . 2005-08-08 11:35 39424 —-a-w- c:\windows\system32\keyhook.exe
2010-02-08 14:07 . 2010-02-08 13:05 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-02-08 14:07 . 2006-02-24 15:28 12395 —-a-w- c:\windows\system32\tablet.dat
2010-02-08 13:09 . 2010-02-08 13:06 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-02-08 13:06 . 2010-02-08 13:06 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-08 13:06 . 2010-02-08 13:06 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-02-08 13:06 . 2010-02-08 13:06 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-08 13:06 . 2010-02-08 13:06 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-08 13:06 . 2010-02-05 16:16 ——– d—–w- c:\program files\SpywareGuard
2010-02-08 13:05 . 2010-02-08 13:32 3777280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-02-08 13:05 . 2010-02-08 13:32 1260800 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-02-08 13:05 . 2010-02-08 13:05 ——– d—–w- c:\program files\AVG
2010-02-08 12:39 . 2007-02-14 18:45 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-02-08 12:26 . 2005-08-08 11:44 39424 —-a-w- c:\windows\system32\nerocheck .exe
2010-02-08 12:26 . 2005-08-08 11:35 39424 —-a-w- c:\windows\system32\keyhook .exe
2010-02-08 12:26 . 2005-08-08 11:33 39424 —-a-w- c:\windows\sisusbrg.exe
2010-02-08 12:25 . 2007-02-14 18:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-02-05 16:46 . 2010-02-05 16:18 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-05 16:17 . 2010-02-05 16:17 ——– d—–w- c:\program files\SpywareBlaster
2010-02-05 16:09 . 2005-09-27 20:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-05 16:09 . 2005-09-27 20:10 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-05 09:52 . 2004-08-04 12:00 96512 ——w- c:\windows\system32\drivers\atapi.sys
2009-12-21 19:14 . 2004-08-04 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-11-21 15:51 . 2004-08-04 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2005-09-17 01:02 . 2005-09-17 01:02 774144 —-a-w- c:\program files\RngInterstitial.dll
2005-09-14 13:04 . 2005-09-14 12:55 1116 —-a-w- c:\program files\edge.ico
2005-09-14 13:04 . 2005-09-14 12:59 3 —-a-w- c:\program files\gp.info
2005-04-06 12:00 . 2005-09-14 12:54 1240 -c–a-w- c:\program files\banner.html
2004-02-11 11:14 . 2006-02-25 23:01 153644 -c–a-w- c:\program files\Setup.inx
2004-02-09 11:06 . 2006-02-25 23:01 417 -c–a-w- c:\program files\layout.bin
2004-02-09 11:06 . 2006-02-25 23:01 77671751 —-a-w- c:\program files\data2.cab
2004-02-09 11:06 . 2006-02-25 23:01 135527 -c–a-w- c:\program files\data1.hdr
2004-02-09 11:06 . 2006-02-25 23:01 1009211 -c–a-w- c:\program files\data1.cab
2004-02-09 11:05 . 2006-02-25 23:01 245 —-a-w- c:\program files\Setup.ini
2003-08-29 09:46 . 2006-02-25 23:01 25214 -c–a-w- c:\program files\autorun.ico
2003-05-22 16:13 . 2006-02-25 23:01 26 -c–a-w- c:\program files\AUTORUN.ID
2002-07-25 18:07 . 2006-02-25 23:01 346602 -c–a-w- c:\program files\ikernel.ex_
1998-07-23 16:36 . 2006-02-25 23:01 4173 -c–a-w- c:\program files\AUTORUN.EXE
.
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc .exe
c:\program files\COMODO\COMODO Internet Security\cfp .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre1.6.0_07\bin\jusched .exe
c:\program files\Microsoft IntelliPoint\point32 .exe
c:\program files\QuickTime\qttask		  .exe
c:\program files\QuickTime\qttask		 .exe
c:\program files\QuickTime\qttask		.exe
c:\program files\Skype\Phone\skype .exe
c:\program files\USB Flash Disk Utility\UFD Utility\ufdmon .exe
c:\program files\USB Flash Disk Utility\UFD Utility\usbtd .exe
c:\windows\system32\keyhook .exe
c:\windows\system32\nerocheck .exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 13:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [N/A]
"Steam"="" [N/A]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-08 39424]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\quicktime\qttask .exe -atboottime" [X]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2010-02-08 39424]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2010-02-08 39424]
"SMSERIAL"="sm56hlpr.exe" [2005-08-24 548864]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2010-02-08 39424]
"UFD Monitor"="c:\program files\USB Flash Disk Utility\UFD Utility\UFDMon.exe" [2010-02-08 39424]
"UFD Utility"="c:\program files\USB Flash Disk Utility\UFD Utility\USBTD.exe" [2010-02-08 39424]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2010-02-08 39424]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 90112]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-08 39424]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2010-02-08 39424]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-02-08 39424]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-2-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-1-31 1183744]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-2-24 106496]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-08 13:06 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\14 Degrees East\\Fallout Tactics\\BOS.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08/02/2010 13:06 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [08/02/2010 13:06 360584]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [08/02/2010 13:18 134344]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [08/02/2010 13:18 25160]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [08/02/2010 13:05 285392]
S3 AlcrFilt;Alcor Micro Corp;c:\windows\system32\drivers\AlcrFilt.sys [24/02/2003 10:15 22860]
S3 BTUsbrXP®;BT Voyager 1010 USB Adapter;c:\windows\system32\DRIVERS\btusbrxp.sys –> c:\windows\system32\DRIVERS\btusbrxp.sys [?]
S3 FXDRV;FXDRV;\??\d:\fxdrv.sys –> d:\Fxdrv.sys [?]
S3 RTLWUSB;USB 54M Wireless Network Adapter;c:\windows\system32\drivers\RTL8187.sys [20/09/2006 16:55 167936]
.
Contents of the 'Scheduled Tasks' folder

2009-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2010-02-08 c:\windows\Tasks\At1.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At10.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At11.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At12.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At13.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At14.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At15.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At16.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At17.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At18.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At19.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At2.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At20.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At21.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At22.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At23.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At24.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At3.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At4.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At5.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At6.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At7.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At8.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2010-02-08 c:\windows\Tasks\At9.job
- c:\program files\internet explorer\wmpscfgs.exe [2010-02-08 14:11]

2006-11-05 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8126701198.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]

2010-02-08 c:\windows\Tasks\User_Feed_Synchronization-{A4C7DF90-1DC8-43C5-99FD-910C7D322751}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://by124w.bay124.mail.live.com/mail/ApplicationMainReach.aspx?Control=Today
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-08 14:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\nerocheck .exe 39424 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-839522115-602609370-2147062339-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(796)
c:\windows\system32\WININET.dll
c:\windows\system32\tabhook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\Tablet.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\sm56hlpr.exe
c:\windows\SOUNDMAN.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\quicktime\qttask .exe
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
.
**************************************************************************
.
Completion time: 2010-02-08 14:17:42 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-08 14:17
ComboFix2.txt 2010-02-08 12:56
ComboFix3.txt 2010-02-05 15:27

Pre-Run: 23,558,881,280 bytes free
Post-Run: 23,538,089,984 bytes free

- - End Of File - - 97941434AE37F1D66ED0A067E2856725
Hi, same thing with this log - the upload didn't get sent automatically - maybe your firewall prevented it as I see it was still enabled: could you please upload the most recent zipped file from this script via the same method from my previous post: look for the zipped file with the date and time stamp close to this: 08/02/2010 13:57:42 and upload it manually. certain bad files keep regenerating in this log. I need to ask a colleague what it is I'm missing, I will try and get back to you as soon as possible: In the meantime can you advise how the computer is running and what outstanding issues you still have.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI