This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Can't get rid of Rootkit.Agent -- Causing serious probl

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yesterday a scan found a file named syspck32.exe in my startup folder, identified as Hiloti.B! generic trojan. It was quarantined and removed but kept reappearing. Malwarebytes removed it but found Rootkit.Agent which it can't get rid of. Lots of error messages when the system boots and programs won't run at times. Running GMER causes a system crash. Then the system won't boot and I have to use Recovery Console to repair with the Fixboot command. The GMER log posted is just what it finds before it scans files as I have to halt the scan at that point to avoid a crash. Thanks in advance for your help. Eric ———– DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 13:44:10.46 on Thu 04/15/2010 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2704 [GMT -4:00] AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe svchost.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Documents and Settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\WINDOWS\system32\CAPM1RSK.EXE C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe C:\Program Files\TrayDay\TrayDay.exe C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\LxrSII1s.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\oodag.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\explorer.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Amy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://my.yahoo.com/index.html uDefault_Page_URL = hxxp://www.dell4me.com/myway uSearch Bar = hxxp://bfc.myway.com/search/de_srchlft.html uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway mURLSearchHooks: H - No File BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: : {4d25f921-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\1.bin\deSrcAs.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Viewpoint Toolbar BHO: {a7327c09-b521-4edb-8509-7d2660c9ec98} - c:\program files\viewpoint\viewpoint toolbar\3.9.0\ViewBarBHO.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Viewpoint Toolbar: {f8ad5aa5-d966-4667-9daf-2561d68b2012} - c:\program files\common files\viewpoint\toolbar runtime\3.9.0\IEViewBar.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_0_9 uRun: [LxrAutorun] c:\documents and settings\amy\local settings\application data\lexar media\LxrAutorun.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [CAVRID] "c:\program files\ca\etrust ez armor\etrust ez antivirus\CAVRID.exe" mRun: [eTrustPPAP] "c:\program files\ca\etrust ez armor\etrust pestpatrol\PPActiveDetection.exe" mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe" mRun: [QOELOADER] "c:\program files\ca\etrust ez armor\etrust anti-spam\qsp-5.1.18.0\QOELoader.exe" StartupFolder: c:\docume~1\amy\startm~1\programs\startup\trayday.lnk - c:\program files\trayday\TrayDay.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll LSP: c:\windows\system32\VetRedir.dll DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} - hxxp://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - hxxp://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxp://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136553665781 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxp://www.symantec.com/techsupp/asa/ctrl/SymAData.cab DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab ============= SERVICES / DRIVERS =============== R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2008-6-4 26352] R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2008-6-4 21104] R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-10-13 739696] R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2008-6-4 21488] R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2008-6-4 32240] R2 CAISafe;CAISafe;c:\program files\ca\etrust ez armor\etrust ez antivirus\isafe.exe [2008-6-4 144960] R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [2008-5-13 72672] R2 RapidPortM1;RapidPortM1;c:\windows\system32\drivers\CAPM1LP.SYS [2005-2-23 22912] R2 VETMSGNT;VET Message Service;c:\program files\ca\etrust ez armor\etrust ez antivirus\vetmsg.exe [2008-6-4 238832] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-10-24 24652] R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\etrust ez armor\etrust pestpatrol\PPCtlPriv.exe [2007-8-16 189704] R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-10-13 133520] S4 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [2005-2-4 140800] S4 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [2005-2-4 5504] =============== Created Last 30 ================ 2010-04-15 17:28:50 54 —-a-w- c:\documents and settings\amy\defogger_reenable 2010-04-14 16:47:24 100864 ——w- c:\windows\system32\dllcache\6to4svc.dll 2010-04-14 15:46:39 0 d—–w- C:\Netgear 2010-04-14 14:49:50 0 d—–w- c:\docume~1\amy\applic~1\Malwarebytes 2010-04-14 14:49:06 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-14 14:49:03 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-04-14 14:49:01 20824 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-04-14 14:49:01 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-04-14 13:33:39 0 d—–w- c:\windows\system32\wbem\Repository 2010-04-13 12:35:39 0 d—–w- c:\docume~1\amy\applic~1\Office Genuine Advantage 2010-04-07 13:08:24 845824 —-a-w- c:\windows\system32\drivers\ozlmzrs.sys 2010-04-07 13:07:53 44032 —ha-w- c:\windows\system32\EDLIyi64.dll ==================== Find3M ==================== 2010-03-10 13:18:21 13824 ——w- c:\windows\system32\dllcache\ieudinit.exe 2010-03-10 13:18:20 70656 ——w- c:\windows\system32\dllcache\ie4uinit.exe 2010-03-09 11:09:18 430080 —-a-w- c:\windows\system32\vbscript.dll 2010-03-09 11:09:18 430080 ——w- c:\windows\system32\dllcache\vbscript.dll 2010-02-24 13:11:07 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-02-24 13:11:07 455680 ——w- c:\windows\system32\dllcache\mrxsmb.sys 2010-02-23 05:20:02 634648 ——w- c:\windows\system32\dllcache\iexplore.exe 2010-02-23 05:18:28 161792 ——w- c:\windows\system32\dllcache\ieakui.dll 2010-02-17 13:10:28 2189952 ——w- c:\windows\system32\dllcache\ntoskrnl.exe 2010-02-16 14:08:49 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-02-16 14:08:49 2146304 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe 2010-02-16 13:25:04 2066816 ——w- c:\windows\system32\dllcache\ntkrnlpa.exe 2010-02-16 13:25:04 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe 2010-02-16 13:25:04 2024448 ——w- c:\windows\system32\dllcache\ntkrpamp.exe 2010-02-12 04:33:11 100864 —-a-w- c:\windows\system32\6to4svc.dll 2010-02-11 12:02:15 226880 ——w- c:\windows\system32\dllcache\tcpip6.sys ============= FINISH: 13:45:48.56 ===============

Attachments:

  • [attachment removed: Attach.zip]
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Thanks for your help!

Ran ComboFix. Log copied below.

Current problems:
Error message during boot up: "Update Manager – An error accured while creating the main dialog. Please reinstall the program."
Once booted, programs won't start. I get an error message: "The process terminated unexpectedly. This resolves after a while.
CA Anti–Spyware feeps turning itself off when the system restarts.
Also I got a message last night from my internet service provider ( Road Runner) that the address of my cable modem has been the source of spam emails.

Thanks again.
Eric

———————

ComboFix 10-04-17.05 - Amy 04/18/2010 9:01.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2534 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\ozlmzrs.sys

—– BITS: Possible infected sites —–

hxxp://au.download.wij+|Cv+@J:NGD_DQ{zGD_DQ{zGD_DQ{zGD_DQ{z+@J:Nj+|Cvob
c:\windows\system32\dbghlp.dll . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ozlmzrs
——-\Service_ozlmzrs


((((((((((((((((((((((((( Files Created from 2010-03-18 to 2010-04-18 )))))))))))))))))))))))))))))))
.

2010-04-15 15:47 . 2010-04-15 15:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-04-15 13:33 . 2010-04-15 13:33 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\Qurb4
2010-04-14 16:47 . 2010-02-12 04:33 100864 ——w- c:\windows\system32\dllcache\6to4svc.dll
2010-04-14 15:46 . 2010-04-14 16:00 ——– d—–w- C:\Netgear
2010-04-14 14:49 . 2010-04-14 14:49 ——– d—–w- c:\documents and settings\Amy\Application Data\Malwarebytes
2010-04-14 14:49 . 2010-03-30 04:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-14 14:49 . 2010-04-14 14:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-14 14:49 . 2010-04-16 13:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-14 14:49 . 2010-03-30 04:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-14 13:33 . 2010-04-14 13:33 ——– d—–w- c:\windows\system32\wbem\Repository
2010-04-13 12:35 . 2010-04-13 12:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-04-13 12:35 . 2010-04-13 12:35 ——– d—–w- c:\documents and settings\Amy\Application Data\Office Genuine Advantage
2010-04-07 13:07 . 2010-04-07 13:07 44032 —ha-w- c:\windows\system32\EDLIyi64.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-15 20:58 . 2010-04-15 20:58 525824 —-a-w- c:\documents and settings\Amy\Application Data\Qualcomm\Eudora\attach\dds.scr
2010-04-15 20:58 . 2010-04-15 20:58 293376 —-a-w- c:\documents and settings\Amy\Application Data\Qualcomm\Eudora\attach\k1g7pio9.exe
2010-04-12 11:54 . 2009-11-10 13:00 79488 —-a-w- c:\documents and settings\Amy\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-04-09 11:41 . 2010-04-09 11:41 16 —-a-w- c:\windows\system32\config\systemprofile\Application Data\jasltw.dat
2010-04-08 11:43 . 2010-04-08 11:43 16 —-a-w- c:\documents and settings\NetworkService\Application Data\jasltw.dat
2010-04-07 13:07 . 2010-04-07 13:07 16 —-a-w- c:\documents and settings\LocalService\Application Data\jasltw.dat
2010-03-11 19:16 . 2010-03-03 16:43 ——– d—–w- c:\program files\MSN Games
2010-03-11 17:03 . 2010-03-03 16:44 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-11 12:38 . 2004-08-04 11:00 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 11:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2004-08-04 11:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-10 13:47 . 2010-03-10 13:47 439816 —-a-w- c:\documents and settings\Amy\Application Data\Real\Update\setup3.10\setup.exe
2010-03-09 11:09 . 2004-08-04 11:00 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-03-03 16:50 . 2010-03-03 16:43 ——– d—–w- c:\program files\Oberon Media
2010-03-03 16:49 . 2010-03-03 16:49 10 —-a-w- c:\windows\popcinfo.dat
2010-02-24 13:11 . 2004-08-04 11:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 1980-01-01 06:00 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 1980-01-01 06:00 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2004-08-04 11:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 11:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 307200]
"LxrAutorun"="c:\documents and settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe" [2006-11-09 24576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-05 136600]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2004-09-14 131072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-05 98304]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-11-12 864256]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-10 185784]
"CAVRID"="c:\program files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe" [2009-12-01 230664]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-07-31 177392]
"QOELOADER"="c:\program files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2009-02-02 14088]

c:\documents and settings\Amy\Start Menu\Programs\Startup\
TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2005-1-28 204800]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-1-20 724992]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
logasdtc REG_SZ c:\windows\system32\EDLIyi64.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\UVU\\UVU Media Player\\HSAudioPlayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=

R2 LxrSII1d;Secure II Driver;c:\windows\SYSTEM32\DRIVERS\LxrSII1d.sys [5/13/2008 2:31 PM 72672]
R2 RapidPortM1;RapidPortM1;c:\windows\SYSTEM32\DRIVERS\CAPM1LP.SYS [2/23/2005 7:04 PM 22912]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/24/2008 9:24 AM 24652]
S3 PPCtlPriv;PPCtlPriv;c:\program files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe [8/16/2007 9:10 PM 189704]
S4 xmasbus;xmasbus;c:\windows\SYSTEM32\DRIVERS\xmasbus.sys [2/4/2005 2:11 PM 140800]
S4 xmasscsi;xmasscsi;c:\windows\SYSTEM32\DRIVERS\xmasscsi.sys [2/4/2005 2:11 PM 5504]
.
Contents of the 'Scheduled Tasks' folder

2009-04-01 c:\windows\Tasks\CAAntiSpywareScan_Daily as Amy at 4 43 PM.job
- c:\program files\CA\eTrust EZ Armor\eTrust PestPatrol\CAAntiSpyware.exe [2007-08-17 01:10]

2005-01-07 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 00:12]

2010-04-18 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]

2010-04-18 c:\windows\Tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 16:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/index.html
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\VetRedir.dll
DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-eTrustPPAP - c:\program files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-18 09:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D2
9192344801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D529013
6FAD41FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C8
7B3CA5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F
7876CB1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BE
CC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC
7933BA7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA
1B5F1912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE9
090018327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822
752F4157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBE
FD89D756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B
1B516982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD1
0ECC7C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE1193F68E275B6390C3DD5573
1F98B7B463104C0F062A9DB57EF066079EDE29EA21BF1044988DC2E76B6878286A8E57CD2B01C8D9F
02EAB857B98A4AF50271D02CEB3E3F93A7A94C89C54991FA9B08E947F18B11FCA5FA18855DE394A6E
CA038D5247EA53D089D34074727FC415B7460EEB3AED2914D7B33531FE1F411C253C95D2D15B86173
FBB61468B2B4AF08EFAF760B67CC0E0BD2789A985713DAAA3130624562EC42464E5E3A2DFE97C0D20
3DCF0609B6E4407AA0A94B71A0AD1E1254B697FCFACC37260E5676F267E9082FAA155F1359BAA7D72
3BE1BE046B64385E2C59C349546FFCC1BC6DD8C3B363F0EAE87ECEA229DDBBDB1705C3753A2891CF9
901CB3D34F000C785006A79721E0CA453295D53E49B25DB5AE530D06ED2E7318E1026A0921BA70918
3AF7EBEEC8D744B67955BD8B47332EF7CFC07B7542C5FDB99A376A27E135E201972943CE1468A41AF
3445DD167EECF13F108E12C75CBF3FC983416A0DD00757D7B792C2CD06969BA050A2D5DA679838860
6CF1EA112F97EF6828231D4D6E2405AA38D61574987589F9DB31CAD4044F6291279DF5DB37AEDAC7F
016B50FFE183BCC89798A994872AA84426D27E457FCE46146DB8B4241C5BFDB44F57029C3BB7D72E6
CA037D5F4EF53D9A6BF6EB4D1B8390AAA7DA54BBAACD2FA54E4B44DF415B0B9888E982573A789C153
A312657FBE8400B0009C5ACF16DAA"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(736)
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll

- - - - - - - > 'lsass.exe'(792)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll

- - - - - - - > 'explorer.exe'(3720)
c:\windows\system32\WININET.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\EDLIyi64.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\CAPM1RSK.EXE
c:\windows\system32\LxrSII1s.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\oodag.exe
c:\windows\system32\wdfmgr.exe
c:\program files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
c:\windows\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE
c:\windows\system32\wscntfy.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-04-18 09:13:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-18 13:13

Pre-Run: 47,643,951,104 bytes free
Post-Run: 51,680,096,256 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 38FCEDB15C1BF28DCCB2E595E7CA8390
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/Can_t_get_rid_Rootkit_Agent_Causing_serious_problems_t111599.html&gopid=648239#entry648239

Collect::
c:\windows\system32\EDLIyi64.dll
c:\documents and settings\Amy\Application Data\Qualcomm\Eudora\attach\k1g7pio9.exe

Folder::
c:\program files\Viewpoint

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
The computer is behaving much better at th moment. The boot up problems are not happening. ——— ComboFix 10-04-17.07 - Amy 04/18/2010 10:57:35.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2750 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Amy\Desktop\CFScript.txt AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} file zipped: c:\documents and settings\Amy\Application Data\Qualcomm\Eudora\attach\k1g7pio9.exe file zipped: c:\windows\system32\EDLIyi64.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Amy\Application Data\Qualcomm\Eudora\attach\k1g7pio9.exe c:\program files\Viewpoint c:\program files\Viewpoint\Common\ViewpointService.exe c:\program files\Viewpoint\Common\VistaBoot.sdll c:\program files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll c:\program files\Viewpoint\Viewpoint Experience Technology\AxMetaStream_0305000D.dll c:\program files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentMgr_0305001C.dll c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentRegistry.ini c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\Cursors.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo2.dll c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll c:\program files\Viewpoint\Viewpoint Experience Technology\DownloadedComponents\VMgr_Win\Exec.exe c:\program files\Viewpoint\Viewpoint Experience Technology\DownLoadHist.ini c:\program files\Viewpoint\Viewpoint Experience Technology\HostRegistry.ini c:\program files\Viewpoint\Viewpoint Experience Technology\MetaStreamConfig.ini c:\program files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini c:\program files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe c:\program files\Viewpoint\Viewpoint Experience Technology\MTSDownloadSites.txt c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\JpegReader.dll c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\MTS3Reader.dll c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\SWFView.dll c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMgr.dll c:\program files\Viewpoint\Viewpoint Experience Technology\NewComponents\WaveletReader.dll c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.xpt c:\program files\Viewpoint\Viewpoint Manager\CPtask.xml c:\program files\Viewpoint\Viewpoint Manager\VETScriptInterpreter.dll c:\program files\Viewpoint\Viewpoint Manager\ViewCP.cpl c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico c:\program files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html c:\program files\Viewpoint\Viewpoint Manager\ViewCPexe.exe c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe c:\program files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll c:\program files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\eula.txt c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\Uninstaller.exe c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarBHO.dll c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarSystemInfo.dll c:\windows\system32\EDLIyi64.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_Viewpoint_Manager_Service ——-\Service_Viewpoint Manager Service ((((((((((((((((((((((((( Files Created from 2010-03-18 to 2010-04-18 ))))))))))))))))))))))))))))))) . 2010-04-15 20:58 . 2010-04-15 20:58 525824 —-a-w- c:\documents and settings\Amy\Application Data\Qualcomm\Eudora\attach\dds.scr 2010-04-15 15:47 . 2010-04-15 15:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2010-04-15 13:33 . 2010-04-15 13:33 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\Qurb4 2010-04-14 16:47 . 2010-02-12 04:33 100864 ——w- c:\windows\system32\dllcache\6to4svc.dll 2010-04-14 15:46 . 2010-04-14 16:00 ——– d—–w- C:\Netgear 2010-04-14 14:49 . 2010-04-14 14:49 ——– d—–w- c:\documents and settings\Amy\Application Data\Malwarebytes 2010-04-14 14:49 . 2010-03-30 04:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-14 14:49 . 2010-04-14 14:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-04-14 14:49 . 2010-04-16 13:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-04-14 14:49 . 2010-03-30 04:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-04-14 13:33 . 2010-04-14 13:33 ——– d—–w- c:\windows\system32\wbem\Repository 2010-04-13 12:35 . 2010-04-13 12:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2010-04-13 12:35 . 2010-04-13 12:35 ——– d—–w- c:\documents and settings\Amy\Application Data\Office Genuine Advantage . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-04-12 11:54 . 2009-11-10 13:00 79488 —-a-w- c:\documents and settings\Amy\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-04-09 11:41 . 2010-04-09 11:41 16 —-a-w- c:\windows\system32\config\systemprofile\Application Data\jasltw.dat 2010-04-08 11:43 . 2010-04-08 11:43 16 —-a-w- c:\documents and settings\NetworkService\Application Data\jasltw.dat 2010-04-07 13:07 . 2010-04-07 13:07 16 —-a-w- c:\documents and settings\LocalService\Application Data\jasltw.dat 2010-03-11 19:16 . 2010-03-03 16:43 ——– d—–w- c:\program files\MSN Games 2010-03-11 17:03 . 2010-03-03 16:44 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-03-11 12:38 . 2004-08-04 11:00 832512 —-a-w- c:\windows\system32\wininet.dll 2010-03-11 12:38 . 2004-08-04 11:00 78336 —-a-w- c:\windows\system32\ieencode.dll 2010-03-11 12:38 . 2004-08-04 11:00 17408 —-a-w- c:\windows\system32\corpol.dll 2010-03-10 13:47 . 2010-03-10 13:47 439816 —-a-w- c:\documents and settings\Amy\Application Data\Real\Update\setup3.10\setup.exe 2010-03-09 11:09 . 2004-08-04 11:00 430080 —-a-w- c:\windows\system32\vbscript.dll 2010-03-03 16:50 . 2010-03-03 16:43 ——– d—–w- c:\program files\Oberon Media 2010-03-03 16:49 . 2010-03-03 16:49 10 —-a-w- c:\windows\popcinfo.dat 2010-02-24 13:11 . 2004-08-04 11:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2010-02-16 14:08 . 1980-01-01 06:00 2146304 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-02-16 13:25 . 1980-01-01 06:00 2024448 —-a-w- c:\windows\system32\ntkrnlpa.exe 2010-02-12 04:33 . 2004-08-04 11:00 100864 —-a-w- c:\windows\system32\6to4svc.dll 2010-02-11 12:02 . 2004-08-04 11:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 307200] "LxrAutorun"="c:\documents and settings\Amy\Local Settings\Application Data\Lexar Media\LxrAutorun.exe" [2006-11-09 24576] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-05 136600] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968] "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344] "UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939] "MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2004-09-14 131072] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-05 98304] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648] "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393] "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960] "ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-11-12 864256] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-10 185784] "CAVRID"="c:\program files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe" [2009-12-01 230664] "cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-07-31 177392] "QOELOADER"="c:\program files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2009-02-02 14088] c:\documents and settings\Amy\Start Menu\Programs\Startup\ TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2005-1-28 204800] c:\documents and settings\All Users\Start Menu\Programs\Startup\ QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-1-20 724992] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls] logasdtc REG_SZ c:\windows\system32\EDLIyi64.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "c:\\Program Files\\America Online 9.0\\waol.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\UVU\\UVU Media Player\\HSAudioPlayer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= R2 LxrSII1d;Secure II Driver;c:\windows\SYSTEM32\DRIVERS\LxrSII1d.sys [5/13/2008 2:31 PM 72672] R2 RapidPortM1;RapidPortM1;c:\windows\SYSTEM32\DRIVERS\CAPM1LP.SYS [2/23/2005 7:04 PM 22912] R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe [8/16/2007 9:10 PM 189704] S4 xmasbus;xmasbus;c:\windows\SYSTEM32\DRIVERS\xmasbus.sys [2/4/2005 2:11 PM 140800] S4 xmasscsi;xmasscsi;c:\windows\SYSTEM32\DRIVERS\xmasscsi.sys [2/4/2005 2:11 PM 5504] . Contents of the 'Scheduled Tasks' folder 2009-04-01 c:\windows\Tasks\CAAntiSpywareScan_Daily as Amy at 4 43 PM.job - c:\program files\CA\eTrust EZ Armor\eTrust PestPatrol\CAAntiSpyware.exe [2007-08-17 01:10] 2005-01-07 c:\windows\Tasks\ISP signup reminder 1.job - c:\windows\system32\OOBE\OOBEBALN.EXE [2004-08-04 00:12] 2010-04-18 c:\windows\Tasks\OGALogon.job - c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07] 2010-04-18 c:\windows\Tasks\User_Feed_Synchronization-{9F65D221-A6DA-4935-A0FB-B46D030E6DFB}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 16:58] . . ——- Supplementary Scan ——- . uStart Page = hxxp://my.yahoo.com/index.html uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 LSP: c:\windows\system32\VetRedir.dll DPF: {A762E064-A885-40E4-AC10-671BB62DC2B2} - hxxp://www.eomniform.com/OF5/nsplugins/OFMailX.cab . - - - - ORPHANS REMOVED - - - - AddRemove-Viewpoint Manager - c:\program files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe AddRemove-Viewpoint Toolbar - c:\program files\Viewpoint\Viewpoint Toolbar\3.9.0\Uninstaller.exe AddRemove-ViewpointMediaPlayer - c:\program files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*] "OODEFRAG08.00.00.01WORKSTATION"="4FDA30922D1D3A4A1A518A89786166259F7EDB5C427B6808351193CC975D2AF0366B0F1D0D2 9192344801B1DA40F8878C6AF3B417DB9EAC349444851CFCDD2C520FADA1F447948AE66148D529013 6FAD41FB00C56744F61778843EEBB9CBE595E3A5E2CF484EA8ED9D5A9C1B05ACF5CE1083F2333F7C8 7B3CA5D6961A87C1C5C2B89678E23ABCC46D823758EE164ADC908E54DF9DA09C8B29762B11806445F 7876CB1C5A70DAFB82DBC2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BE CC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E667C038D530D6EB3452A6A0AC4980AC 7933BA7FD869164D679495747435A8FAC96341B3DE98263F27383A1B78105C0A222DC2209BCEE5FCA 1B5F1912D37D708A550DD8E2F2D5E33805417129D6F9D6DDC5C788D9F09E36E97BCC0958BD1B4AAE9 090018327694D560A956A9839D36F5A005FAE07D91E80208B41FBE6C83E01A0F499528FA5547C6822 752F4157BA34C1065B38514688D8A98CAA471C58F33735ED1803CB46EA90DF7BB59A850AF96019EBE FD89D756A040433356B4207E3738766494751C2AA491235D2D1F4722F285965527A14F63A1BDD524B 1B516982ACA4B4A9B1982B35121BC8384D5A10251AF92F37222965D4783F057A6435970FEF3A24DD1 0ECC7C036DCFAB886F183D7EBB04E79607DA58FBF38B8C19522FD65DE1193F68E275B6390C3DD5573 1F98B7B463104C0F062A9DB57EF066079EDE29EA21BF1044988DC2E76B6878286A8E57CD2B01C8D9F 02EAB857B98A4AF50271D02CEB3E3F93A7A94C89C54991FA9B08E947F18B11FCA5FA18855DE394A6E CA038D5247EA53D089D34074727FC415B7460EEB3AED2914D7B33531FE1F411C253C95D2D15B86173 FBB61468B2B4AF08EFAF760B67CC0E0BD2789A985713DAAA3130624562EC42464E5E3A2DFE97C0D20 3DCF0609B6E4407AA0A94B71A0AD1E1254B697FCFACC37260E5676F267E9082FAA155F1359BAA7D72 3BE1BE046B64385E2C59C349546FFCC1BC6DD8C3B363F0EAE87ECEA229DDBBDB1705C3753A2891CF9 901CB3D34F000C785006A79721E0CA453295D53E49B25DB5AE530D06ED2E7318E1026A0921BA70918 3AF7EBEEC8D744B67955BD8B47332EF7CFC07B7542C5FDB99A376A27E135E201972943CE1468A41AF 3445DD167EECF13F108E12C75CBF3FC983416A0DD00757D7B792C2CD06969BA050A2D5DA679838860 6CF1EA112F97EF6828231D4D6E2405AA38D61574987589F9DB31CAD4044F6291279DF5DB37AEDAC7F 016B50FFE183BCC89798A994872AA84426D27E457FCE46146DB8B4241C5BFDB44F57029C3BB7D72E6 CA037D5F4EF53D9A6BF6EB4D1B8390AAA7DA54BBAACD2FA54E4B44DF415B0B9888E982573A789C153 A312657FBE8400B0009C5ACF16DAA" . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(732) c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll - - - - - - - > 'lsass.exe'(788) c:\windows\system32\VetRedir.dll c:\windows\system32\ISafeIf.dll - - - - - - - > 'explorer.exe'(2852) c:\windows\system32\WININET.dll c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll c:\progra~1\WINDOW~2\wmpband.dll c:\windows\system32\ieframe.dll . ———————— Other Running Processes ———————— . c:\windows\system32\Ati2evxx.exe c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe c:\program files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\LxrSII1s.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\oodag.exe c:\windows\system32\CAPM1RSK.EXE c:\windows\system32\wdfmgr.exe c:\program files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe c:\windows\system32\spool\drivers\w32x86\3\CAPM1SWK.EXE c:\windows\system32\wscntfy.exe c:\program files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe c:\program files\CA\CA Internet Security Suite\ccprovsp.exe . ************************************************************************** . Completion time: 2010-04-18 11:09:59 - machine was rebooted ComboFix-quarantined-files.txt 2010-04-18 15:09 ComboFix2.txt 2010-04-18 13:13 Pre-Run: 48,580,612,096 bytes free Post-Run: 51,622,551,552 bytes free - - End Of File - - EB7B60E1BFBCAD42B34270BBEEF8DB51
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

If you used DeFogger
You must remember to re-enable your Emulation drivers once we are finished, double click DeFogger to run the tool.

  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.


To be on the safe side, I would also change all my passwords.



Here's my usual all clean post

Log looks good :D


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
    5. Change the Download signed ActiveX controls to Prompt
    6. Change the Download unsigned ActiveX controls to Disable
    7. Change the Initialize and script ActiveX controls not marked as safe to Disable
    8. Change the Installation of desktop items to Prompt
    9. Change the Launching programs and files in an IFRAME to Prompt
    10. Change the Navigate sub-frames across different domains to Prompt
    11. When all these settings have been made, click on the OK button.
    12. If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI