This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Firefox and Internet Explorer Adware

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I am attempting to clean my sister's Windows XP desktop computer which seems to be infected with Adware (multiple pop op windows appear when opening Firefox or Internet Explorer). There may be other issues such as malware or viruses but I haven't had long enough with the computer to investigate. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 14:28:46.75 on Wed 30/06/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.237 [GMT 10:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\NavNT\defwatch.exe C:\Program Files\Java\jre6\bin\jqs.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\NavNT\rtvscan.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\MsgSys.EXE C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe C:\Program Files\Cyberlink\Shared Files\brs.exe C:\Program Files\NavNT\vptray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\DNA\btdna.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Documents and Settings\David\Start Menu\Programs\Startup\monskc32.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Mozilla Firefox\firefox.exe c:\program files\mcafee.com\shared\mcinfo.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\SearchFilterHost.exe C:\Documents and Settings\David\Desktop\dds.scr c:\program files\real\realplayer\RealPlay.exe C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.iprimus.com.au/ uDefault_Page_URL = hxxp://www.iprimus.com.au uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172. 22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172. 31.*;192.168.*;;*.local uInternet Settings,ProxyServer = proxy.iprimus.com.au:8080 mSearchAssistant = hxxp://www.google.com/ie mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe, BHO: 0B49E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File BHO: rsion - No File BHO: `B3D70E-1895-11CF-8E15-001234567890} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll BHO: ¨¨8-01DD-4d91-8333-CF10577473F7} - No File BHO: °B497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [MSKAGENTEXE] c:\progra~1\mcafee\spamki~1\MSKAgent.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [EPSON Stylus CX5500 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticap.exe /fu "c:\windows\temp\E_S6B.tmp" /EF "HKCU" uRun: [BitComet] "c:\documents and settings\david\desktop\temp\bitcomet\BitComet.exe" /tray uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe" uRun: [Bait 64] c:\docume~1\david\applic~1\2downl~1\bore list heart.exe uRun: [cleansweep.exe] c:\cleansweep.exe\cleansweep.exe uRun: [Iyiye] rundll32.exe "c:\windows\kbjlprb.dll",Startup mRun: [MCUpdateExe] c:\progra~1\mcafee.com\agent\mcupdate.exe mRun: [MCAgentExe] c:\progra~1\mcafee.com\agent\mcagent.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe" mRun: [PDVD8LanguageShortcut] "c:\program files\cyberlink\powerdvd8\language\Language.exe" mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe mRun: [vptray] c:\program files\navnt\vptray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Odajudi] rundll32.exe "c:\windows\utabonat.dll",Startup mRun: [CleanUp] c:\progra~1\mcafee.com\shared\mcappins.exe /v=3 /cleanup dRunOnce: [RunNarrator] Narrator.exe StartupFolder: c:\docume~1\david\startm~1\programs\startup\imvu.lnk - c:\program files\imvu\IMVUClient.exe StartupFolder: c:\documents and settings\david\start menu\programs\startup\monskc32.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000 IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\david\start menu\programs\imvu\Run IMVU.lnk IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www4.snapfish.com.au/SnapfishActivia.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://shelbyprettyprincessrulz.spaces.msn.com//PhotoUpload/MsnPUpld.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/ultrashim.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: igfxcui - igfxdev.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\david\applic~1\mozilla\firefox\profiles\9gozxyl5.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - www.google.com.au FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101849&gct=&gc=1&q= FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll FF - component: c:\documents and settings\david\application data\mozilla\firefox\profiles\9gozxyl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\documents and settings\david\desktop\temp\divx\divx player\npDivxPlayerPlugin.dll FF - plugin: c:\documents and settings\david\desktop\temp\divx\divx web player\npdivx32.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: XULRunner: {F76DDB26-BB84-4954-9395-CE30EB8664F3} - c:\documents and settings\david\local settings\application data\{F76DDB26-BB84-4954-9395-CE30EB8664F3} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R2 CAN300;CAN300;c:\windows\system32\drivers\can300.sys [2005-8-3 10224] R2 McDetect.exe;McAfee WSC Integration;c:\program files\mcafee.com\agent\Mcdetect.exe [2005-8-24 126976] R2 McTskshd.exe;McAfee Task Scheduler;c:\progra~1\mcafee.com\agent\mctskshd.exe [2005-8-24 122368] R2 NAVAPEL;NAVAPEL;c:\program files\navnt\Navapel.sys [2001-9-24 9232] R2 Norton AntiVirus Server;Norton AntiVirus Client;c:\program files\navnt\rtvscan.exe [2001-9-24 454656] R3 NAVAP;NAVAP;c:\program files\navnt\navap.sys [2001-9-24 176208] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100623.002\NAVENG.sys [2010-6-24 85552] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100623.002\NAVEX15.sys [2010-6-24 1347504] S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};\??\c:\program files\cyberlink\powerdvd8\000.fcl –> c:\program files\cyberlink\powerdvd8\000.fcl [?] S2 gupdate1ca8e7346fd63f8;Google Update Service (gupdate1ca8e7346fd63f8);c:\program files\google\update\GoogleUpdate.exe [2010-1-6 133104] S2 suh4niiio;BsHelpCS;c:\windows\system32\lyssu.exe –> c:\windows\system32\lyssu.exe [?] S3 Ascnuntin;Ascnuntin; [x] S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager;c:\progra~1\mcafee.com\agent\mcupdmgr.exe [2005-7-25 245760] =============== Created Last 30 ================ 2010-06-23 08:06 120 a——- c:\windows\Ccumituyihitama.dat 2010-06-23 08:06 0 a——- c:\windows\Cmulu.bin 2010-06-16 13:54 –dsh— c:\documents and settings\david\IECompatCache 2010-06-16 13:51 –dsh— c:\windows\system32\lowsec 2010-06-16 13:51 4 a——- c:\docume~1\david\applic~1\avdrn.dat 2010-06-16 13:49 –dsh— c:\documents and settings\david\PrivacIE 2010-06-16 13:44 –dsh— c:\documents and settings\david\IETldCache 2010-06-16 13:35 12,800 ——– c:\windows\system32\dllcache\xpshims.dll 2010-06-16 13:35 743,424 ——– c:\windows\system32\dllcache\iedvtool.dll 2010-06-16 13:35 247,808 ——– c:\windows\system32\dllcache\ieproxy.dll 2010-06-16 13:35 –d—– c:\windows\ie8updates 2010-06-16 13:34 41,984 ——– c:\windows\system32\dllcache\iecompat.dll 2010-06-16 13:29 -cd-h— c:\windows\ie8 2010-06-16 13:24 –d—– c:\docume~1\david\applic~1\Windows Desktop Search 2010-06-16 13:23 –d—– c:\program files\Windows Desktop Search 2010-06-16 13:23 –d—– c:\windows\system32\GroupPolicy 2010-06-16 13:20 192,000 ——– c:\windows\system32\dllcache\offfilt.dll 2010-06-16 13:20 98,304 ——– c:\windows\system32\dllcache\nlhtml.dll 2010-06-16 13:20 29,696 ——– c:\windows\system32\dllcache\mimefilt.dll 2010-06-16 11:51 3,558,912 ——– c:\windows\system32\dllcache\moviemk.exe 2010-06-16 10:18 20,992 a——- c:\windows\system32\drivers\RTL8139.sys 2010-06-16 10:18 20,992 a——- c:\windows\system32\dllcache\rtl8139.sys 2010-06-10 11:00 1,902 ——– c:\windows\system32\SetupBD.din 2010-06-10 10:59 –d—– C:\drvrtmp ==================== Find3M ==================== 2010-05-05 23:30 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe 2010-05-05 03:20 133,120 a——- c:\windows\system32\dllcache\extmgr.dll 2010-05-04 22:39 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2010-05-02 15:22 1,851,264 a——- c:\windows\system32\win32k.sys 2010-05-02 15:22 1,851,264 ——– c:\windows\system32\dllcache\win32k.sys 2010-04-20 15:30 285,696 a——- c:\windows\system32\atmfd.dll 2010-04-20 15:30 285,696 ——– c:\windows\system32\dllcache\atmfd.dll 2010-04-06 04:52 2,462,720 a——- c:\windows\system32\dllcache\WMVCore.dll 2010-04-05 16:49 499,712 a——- c:\windows\system32\msvcp71.dll 2008-12-17 16:48 45,256 ac—— c:\docume~1\david\applic~1\GDIPFONTCACHEV1.DAT 2008-02-07 20:26 32 ac—— c:\docume~1\alluse~1\applic~1\ezsid.dat 2007-06-19 10:45 92,064 ac—— c:\documents and settings\david\mqdmmdm.sys 2007-06-19 10:45 79,328 ac—— c:\documents and settings\david\mqdmserd.sys 2007-06-19 10:45 66,656 ac—— c:\documents and settings\david\mqdmbus.sys 2007-06-19 10:45 25,600 ac—— c:\documents and settings\david\usbsermptxp.sys 2007-06-19 10:45 22,768 ac—— c:\documents and settings\david\usbsermpt.sys 2007-06-19 10:45 9,232 ac—— c:\documents and settings\david\mqdmmdfl.sys 2007-06-19 10:45 6,208 ac—— c:\documents and settings\david\mqdmcmnt.sys 2007-06-19 10:45 5,936 ac—— c:\documents and settings\david\mqdmwhnt.sys 2007-06-19 10:45 4,048 ac—— c:\documents and settings\david\mqdmcr.sys 2008-08-25 16:34 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082520080826\index.dat 2007-05-04 16:03 49,152 ac-sh— c:\windows\temp\history\history.ie5\mshist012007050420070505\index.dat 2010-01-16 08:51 32,768 ac-sh— c:\windows\temp\history\history.ie5\mshist012010011620100117\index.dat ============= FINISH: 14:30:33.48 =============== Thanks for your help.

Attachments:

  • [attachment removed: Attach.zip]
Hello Shaenaus and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.
  • I am looking over your log and will reply back shortly with instructions.
Hello Shaenaus

Thank you for the logs.

There may be other issues such as malware or viruses

There are many things going on here.

Please work your way through the following steps. If you encounter any difficulties come back and let me know.


  • Security Programs


    • I can see evidence of multiple real-time security programs running on your system, namely Norton AntiVirus Corporate Edition and McAfee Internet Security Suite.
    • Whilst both of these programs provide good security, they may clash with each other which can leave your system vulnerable to infection.
    • You are advised to remove one of these programs.
    • Please make sure that you only have ONE Firewall and ONE real-time Antivirus running on your system.

  • Please disable Spybot Teatimer


    • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
    • On the left hand side, click "Tools", then click on the "Resident" icon in the list.
    • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active" box.
    • Click the "System Startup" icon in the List.
    • Uncheck the "TeaTimer" box and "OK" any prompts.
    • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
    • Exit Spybot S&D when done.

  • Download Combofix and RE-NAME it BEFORE saving


    • Download Combofix from either of the links below. You must rename it to shaenaus.exe before saving it.
    • Save it to your desktop. Change the "save as file type" to "all files".
    • Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop.


    • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".


    Link 1
    Link 2



    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.


    • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.


    • Double click on the renamed ComboFix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Hi JonTom, 1. Security Programs - I uninstalled Macafee and now there is only Norton anti-virus and Windows firewall. 2. Spybot Teatimer - I ran into a problem at dot point five: there is no "Teatimer" box to uncheck, as far as I can tell. I followed your instructions carefully so I don't know what to do now. The SS&D is version 1.6.2.46, if that's any help.
Hello Shaenaus

I followed your instructions carefully so I don't know what to do now

Please disable your Norton AntiVirus and run ComboFix :)
When I try to run the renamed Combofix, the following error message is displayed: "shaenaus.exe has encountered a problem and needs to close. We are sorry for the inconvenience." When I look at the error report, it contains (in part) the following information: "Exception Information Code: 0xc0000005 Flags: 0x00000000 Record: 0x0000000000000000 Address: 0x0000000000425b14" I tried deleting the first instance of shaenaus.exe and downloading again using Link 1 but the same error occurred. I tried link 2 but it opened a Spanish (I think) website…?
Hello Shaenaus

Thank you for letting me know.

The malware on your system is interfering with our tools. Your machine is heavily infected and we will most likely need several rounds of treatment to get it clean.

Before we continue, please do the following:


  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please post the GMER log in your next reply.

If you encounter any difficulties come back and let me know.
Hi JonTom, After about 1 minute of the Gmer scan, the following blue screen error message was displayed: "STOP: c000021a {Fatal System Error} The Windows Subsystem system process terminated unexpectedly with a status of 0xc0000005 (0x001436bc 0x0292e888). The system has been shut down." I rebooted the PC and attempted another Gmer scan. After about 7 minutes, the following blue screen error message was displayed: "A problem has been detected and windows has been shut down to prevent damage to your computer. A process or thread crucial to system operation has unexpectedly exited or been terminated. If this is the first time you've seen this Stop error screen, restart your computer. If this screen appears again, follow these steps: Check to make sure any new hardware or software is properly installed. If this is a new installation, ask your hardware or software manufacturer for any Windows updates you might need. If problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup Options, and then select Safe Mode. Technical Information: *** STOP: 0x000000F4 (0x00000003, 0x86F4B020, 0x86F4B194, 0x805Fb146) Beginning dump of physical memory Physical memory dump complete. Contact your system administrator or technical support group for further assistance." I am travelling overseas on a business trip in about 3 hours so I won't have access to this PC until I return. Would you please keep this thread open until 15th July? Shane.
Hello Shaenaus

Would you please keep this thread open until 15th July?

Don't worry, the thread will be open and I will be here when you get back :)


If GMER does not run in Normal Mode, please run it from Safe Mode (if you are unable to boot into Safe Mode come back and let me know):


  • Reboot Your System in Safe Mode


    • Please print out the GMER instructions and the instructions provided below before proceeding, as once you are in Safe Mode you will be unable to connect to the Internet.
    • Follow the steps below to Start Your Computer in Safe Mode:
    • Restart your computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
    • Use the arrow keys to select the "Safe mode" menu item.
    • Press Enter.

  • Please run GMER in Safe Mode


    • Once you are in Safe Mode, open GMER.
    • Work your way through the steps listed to run the scan.
    • Once GMER has finished, reboot back into normal mode and post the log created in your next reply.
    • If GMER crashes again please try RootRepeal (instructions provided below).

  • RootRepeal


    • Please download RootRepeal to your desktop
    • Physically disconnect your machine from the internet as your system will be unprotected.
    • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
    • Click the Report tab at the bottom and then the Scan button.
    • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
    • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
    • The scan will take a little while to run, so let it go unhindered.
    • Once it is done, click the "Save Report" button, call it RepealScan and save the log to your desktop.
    • Reconnect to the internet.

    Please post the GMER/RootRepeal log in your next reply.
I tried to run GMER in Safe Mode but the window was so large that I could not see the "Scan" button and therefore could not click it. Instead, I have run the RootRepeal scan and here is the log: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2010/07/12 18:55 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xED5AC000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7DC3000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xEC1CA000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: c:\documents and settings\david\local settings\application data\gdipfontcachev1.dat Status: Allocation size mismatch (API: 16384, Raw: 12288) Path: C:\Documents and Settings\Donna\Local Settings\Application Data\Microsoft\CD Burning\My Pictures\video of shelby carly and shanae\VIDEOO~1.AVI Status: Locked to the Windows API! Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\16\30-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\17\31-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\18\32-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\19\33-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\20\34-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\21\35-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\22\36-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\23\37-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\24\38-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\25\39-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\26\40-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\[removed]\DFSR\Staging\CS{85F5DFD4-146A-FBF1-6C46-1A6E48C8E80C}\27\41-{A3~1.FRX:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk. ==EOF==
Hello Shaenaus

Thank you for the log.

I have it on good authority that the reason why ComboFix did not run last time was most likely due to a corrupted upload. This issue has since been resolved so there should be no more problems.

Please delete the copy of ComboFix that is on your desktop and download a fresh copy using the instructions provided previously (Post number 3).

Follow the instructions provided and post the ComboFix log that is created in your next reply :)
Hi JonTom,

Here is the ComboFix log:

ComboFix 10-07-12.02 - David 13/07/2010 12:46:31.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.492 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\shaenaus.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\cleansweep.exe
c:\cleansweep.exe\config.bin
c:\documents and settings\David\Application Data\avdrn.dat
C:\start.bat
c:\windows\cdmxtras
c:\windows\jestertb.dll
c:\windows\kbjlprb.dll
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_0_105300.htm
c:\windows\system32\cache329\B_329_0_0_106800.htm
c:\windows\system32\cache329\B_329_0_0_107400.htm
c:\windows\system32\cache329\B_329_1_0_449200.htm
c:\windows\system32\cache329\B_329_1_0_449600.htm
c:\windows\system32\cache329\B_329_1_0_454300.htm
c:\windows\system32\cache329\B_329_2_0_105300.htm
c:\windows\system32\cache329\B_329_2_0_106800.htm
c:\windows\system32\cache329\B_329_2_0_107400.htm
c:\windows\system32\cache329\B_329_3_0_105300.htm
c:\windows\system32\cache329\B_329_3_0_106800.htm
c:\windows\system32\cache329\B_329_3_0_107400.htm
c:\windows\system32\cache329\B_329_4_0_111600.htm
c:\windows\system32\cache329\B_329_4_0_152400.htm
c:\windows\system32\cache329\B_329_4_0_155300.htm
c:\windows\system32\cache329\B_329_4_0_164100.htm
c:\windows\system32\cache329\t_B_329_0_0_105300.htm
c:\windows\system32\cache329\t_B_329_0_0_106800.htm
c:\windows\system32\cache329\t_B_329_0_0_107400.htm
c:\windows\system32\cache329\t_B_329_1_0_449200.htm
c:\windows\system32\cache329\t_B_329_1_0_449600.htm
c:\windows\system32\cache329\t_B_329_1_0_454300.htm
c:\windows\system32\cache329\t_B_329_2_0_105300.htm
c:\windows\system32\cache329\t_B_329_2_0_106800.htm
c:\windows\system32\cache329\t_B_329_2_0_107400.htm
c:\windows\system32\cache329\t_B_329_3_0_105300.htm
c:\windows\system32\cache329\t_B_329_3_0_106800.htm
c:\windows\system32\cache329\t_B_329_3_0_107400.htm
c:\windows\system32\cache329\t_B_329_4_0_111600.htm
c:\windows\system32\cache329\t_B_329_4_0_152400.htm
c:\windows\system32\cache329\t_B_329_4_0_155300.htm
c:\windows\system32\cache329\t_B_329_4_0_164100.htm
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\utabonat.dll
c:\windows\xpsp1hfm.log

.
((((((((((((((((((((((((( Files Created from 2010-06-13 to 2010-07-13 )))))))))))))))))))))))))))))))
.

2010-07-13 01:30 . 2010-07-13 01:30 ——– d—–w- c:\documents and settings\David\Application Data\Windows Search
2010-07-08 08:25 . 2010-07-08 08:25 ——– d-sh–w- c:\documents and settings\Donna\PrivacIE
2010-07-04 01:21 . 2010-07-04 01:21 ——– d-sh–w- c:\documents and settings\Donna\IETldCache
2010-06-22 22:06 . 2010-07-12 07:02 0 —-a-w- c:\windows\Ccumituyihitama.dat
2010-06-22 22:06 . 2010-07-10 01:38 0 —-a-w- c:\windows\Cmulu.bin
2010-06-22 22:06 . 2010-06-22 22:06 ——– d—–w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
2010-06-16 12:19 . 2010-06-16 12:19 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-06-16 08:26 . 2010-06-16 08:26 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-06-16 03:55 . 2010-06-16 03:56 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-06-16 03:54 . 2010-06-16 03:54 ——– d-sh–w- c:\documents and settings\David\IECompatCache
2010-06-16 03:51 . 2010-06-16 03:51 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-06-16 03:49 . 2010-06-16 03:49 ——– d-sh–w- c:\documents and settings\David\PrivacIE
2010-06-16 03:47 . 2010-06-16 03:47 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-06-16 03:44 . 2010-06-16 03:44 ——– d-sh–w- c:\documents and settings\David\IETldCache
2010-06-16 03:35 . 2010-05-06 10:41 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2010-06-16 03:35 . 2010-05-06 10:41 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2010-06-16 03:35 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-16 03:35 . 2010-06-16 04:05 ——– d—–w- c:\windows\ie8updates
2010-06-16 03:34 . 2010-04-16 11:43 41984 ——w- c:\windows\system32\dllcache\iecompat.dll
2010-06-16 03:29 . 2010-06-16 03:33 ——– dc-h–w- c:\windows\ie8
2010-06-16 03:24 . 2010-06-16 03:24 ——– d—–w- c:\documents and settings\David\Application Data\Windows Desktop Search
2010-06-16 03:23 . 2010-06-16 04:12 ——– d—–w- c:\program files\Windows Desktop Search
2010-06-16 03:23 . 2010-06-16 03:23 ——– d—–w- c:\windows\system32\GroupPolicy
2010-06-16 03:20 . 2008-03-07 17:02 98304 ——w- c:\windows\system32\dllcache\nlhtml.dll
2010-06-16 03:20 . 2008-03-07 17:02 29696 ——w- c:\windows\system32\dllcache\mimefilt.dll
2010-06-16 03:20 . 2008-03-07 17:02 192000 ——w- c:\windows\system32\dllcache\offfilt.dll
2010-06-16 01:51 . 2009-10-23 15:28 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-06-16 00:18 . 2004-08-03 12:31 20992 —-a-w- c:\windows\system32\drivers\RTL8139.sys
2010-06-16 00:18 . 2004-08-03 12:31 20992 —-a-w- c:\windows\system32\dllcache\rtl8139.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-13 03:05 . 2009-02-01 00:06 ——– d—–w- c:\program files\DNA
2010-07-13 03:05 . 2009-02-01 00:06 ——– d—–w- c:\documents and settings\David\Application Data\DNA
2010-07-12 08:32 . 2005-08-03 14:04 45840 -c–a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-07 08:00 . 2007-09-02 09:36 ——– d—–w- c:\program files\Norton Security Scan
2010-07-02 23:05 . 2010-07-02 23:05 8 —-a-w- c:\documents and settings\NetworkService\Application Data\cakzob.dat
2010-07-02 00:06 . 2010-07-02 00:06 8 —-a-w- c:\documents and settings\David\Application Data\cakzob.dat
2010-06-16 03:51 . 2010-06-16 03:51 4 —-a-w- c:\documents and settings\LocalService\Application Data\cakzob.dat
2010-05-06 10:41 . 2004-08-10 04:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 04:51 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 04:50 285696 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
"Bait 64"="c:\windows\system32\config\SYSTEM~1\APPLIC~1\2DOWNL~1\bore list heart.exe" [2009-12-16 491520]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2008-05-19 91432]
"vptray"="c:\program files\NavNT\vptray.exe" [2001-09-23 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-05 202256]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=c:\windows\pss\dlbcserv.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2005-05-30 19:33 122941 -c–a-w- c:\windows\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-04-28 04:34 53248 -c–a-w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2003-03-11 08:08 172032 -c–a-w- c:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-19 22:32 77824 -c–a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-19 22:36 114688 -c–a-w- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-19 22:35 94208 -c–a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 08:50 221184 -c–a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 08:50 81920 -c–a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 05:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 12:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-04 12:32 53248 ——w- c:\program files\REGSHAVE\REGSHAVE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 11:42 1404928 —-a-w- c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2006-12-14 17:23 75520 -c–a-w- c:\program files\Java\jre1.5.0_11\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-04-05 06:49 202256 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
2001-09-23 21:59 73728 —-a-w- c:\program files\NavNT\vptray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Documents and Settings\\Donna\\Local Settings\\Temp\\iCBB_21_21 R14-24 PRIMUS B01 Temporary Items\\iConnectDSLsvr.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1339:UDP"= 1339:UDP:Windows Media Format SDK (iexplore.exe)
"1338:UDP"= 1338:UDP:Windows Media Format SDK (iexplore.exe)
"1340:UDP"= 1340:UDP:Windows Media Format SDK (iexplore.exe)
"20856:TCP"= 20856:TCP:BitComet 20856 TCP
"20856:UDP"= 20856:UDP:BitComet 20856 UDP
"23208:TCP"= 23208:TCP:BitComet 23208 TCP
"23208:UDP"= 23208:UDP:BitComet 23208 UDP

R2 CAN300;CAN300;c:\windows\system32\drivers\can300.sys [3/08/2005 8:23 AM 10224]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};\??\c:\program files\CyberLink\PowerDVD8\000.fcl –> c:\program files\CyberLink\PowerDVD8\000.fcl [?]
S2 gupdate1ca8e7346fd63f8;Google Update Service (gupdate1ca8e7346fd63f8);c:\program files\Google\Update\GoogleUpdate.exe [6/01/2010 11:55 AM 133104]
S2 suh4niiio;BsHelpCS;c:\windows\system32\lyssu.exe –> c:\windows\system32\lyssu.exe [?]
S3 Ascnuntin;Ascnuntin; [x]
.
Contents of the 'Scheduled Tasks' folder

2010-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]

2010-07-12 c:\windows\Tasks\B35DDA3D945A4D01.job
- c:\docume~1\david\applic~1\2downl~1\RegsRemoteBib.exe [2009-02-07 23:12]

2010-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 01:54]

2010-07-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 01:54]

2010-07-08 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2008-01-08 17:08]

2010-07-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3774946206-295064592-2716718800-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]

2010-07-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3774946206-295064592-2716718800-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]

2010-07-04 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3774946206-295064592-2716718800-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]

2010-07-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3774946206-295064592-2716718800-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.iprimus.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.
22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172.
31.*;192.168.*;;*.local
uInternet Settings,ProxyServer = proxy.iprimus.com.au:8080
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\David\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101849&gct=&gc=1&q=
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\David\Desktop\Temp\DivX\DivX Web Player\npdivx32.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {F76DDB26-BB84-4954-9395-CE30EB8664F3} - c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
FF - HiddenExtension: XULRunner: {8E596A9C-3AD3-4249-9528-A8991CE62159} - c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-MSKAGENTEXE - c:\progra~1\McAfee\SPAMKI~1\MSKAgent.exe
HKCU-Run-BitComet - c:\documents and settings\David\Desktop\Temp\BitComet\BitComet.exe
HKCU-Run-Iyiye - c:\windows\kbjlprb.dll
HKLM-Run-Odajudi - c:\windows\utabonat.dll
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
MSConfigStartUp-DeviceDiscovery - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
MSConfigStartUp-DMXLauncher - c:\program files\Dell\Media Experience\DMXLauncher.exe
MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-HP Software Update - c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
MSConfigStartUp-MCAgentExe - c:\progra~1\mcafee.com\agent\mcagent.exe
MSConfigStartUp-MCUpdateExe - c:\progra~1\mcafee.com\agent\mcupdate.exe
MSConfigStartUp-Yahoo! Pager - c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-13 13:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(628)
c:\windows\system32\NavLogon.dll

- - - - - - - > 'explorer.exe'(2544)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NavNT\defwatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\NavNT\rtvscan.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\MsgSys.EXE
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-13 13:25:56 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-13 03:25

Pre-Run: 67,084,460,032 bytes free
Post-Run: 67,504,996,352 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 9012F597559A8C93E66AFBB46804B8F3
Hello Shaenaus

Thank you for the log.

Please work your way through the following steps:


  • P2P Programs:


    • P2P programs are a major source of Malware infections.
    • From your log I see you have Kazaa, LimeWire and BitTorrent. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • A list of currently installed programs will be displayed.
    • Find the "Kazaa 3.0", "LimeWire 5.2.0" and "BitTorrent DNA" programs, click on them once and then click on the "Remove" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.


      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Foistware


    • I can see from your log that you have Viewpoint Media Player installed.
    • Viewpoint Media Player is considered as foistware rather than malware since it is installed without user's approval but doesn't spy or do anything "bad".
    • It is recommended that you remove Viewpoint products. However, this choice is up to you.
    • To remove these programs, click "Start" and then on "Control Panel" and then on "Add or Remove Programs".
    • Select Viewpoint Media Player and click on "Remove".


    I can see evidence of a LOP infection on your machine. This infection may have been obtained inadvertantly when you installed Messenger Plus! Live, as this software often contains "sponsored programs" that are bundled together with the Messenger Plus! Live install.

    It would be in your best interests to un-install Messenger Plus! Live from your machine (You can do this through Add/Remove Programs - see above). If you use Messenger Plus! Live, please let me know and we can re-install it (without the bundled adware) once your system is clean.

  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the codebox below (including the link) into the open Notepad window:

      File::
      c:\windows\Ccumituyihitama.dat
      c:\windows\Cmulu.bin
      c:\windows\system32\lyssu.exe
      
      Collect::
      c:\windows\system32\config\SYSTEM~1\APPLIC~1\2DOWNL~1\bore list heart.exe
      c:\documents and settings\NetworkService\Application Data\cakzob.dat
      c:\documents and settings\David\Application Data\cakzob.dat
      c:\documents and settings\LocalService\Application Data\cakzob.dat
      
      Driver::
      suh4niiio
      Ascnuntin
      
      Registry::
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Bait 64"=-
      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "20856:TCP"=-
      "23208:TCP"=-
      
      Firefox::
      FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\
      FF - HiddenExtension: XULRunner: {F76DDB26-BB84-4954-9395-CE30EB8664F3} - c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
      FF - HiddenExtension: XULRunner: {8E596A9C-3AD3-4249-9528-A8991CE62159} - c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}
      
      Folder::
      FF - HiddenExtension: XULRunner: {F76DDB26-BB84-4954-9395-CE30EB8664F3} - c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
      FF - HiddenExtension: XULRunner: {8E596A9C-3AD3-4249-9528-A8991CE62159} - c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}
      
      DirLook::
      c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.
    • Note: When ComboFix finishes running, the ComboFix log will open along with a message box - do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
    • Ensure you are connected to the internet and click OK on the message box.

    Please post the ComboFix log in your next reply.
Hi JonTom,

This is not my computer so I did not uninstall the P2P programs nor Viewpoint MediaPlayer. I did uninstall Messenger Plus! Live which I would like to reinstall later.

Here is the ComboFix log:

ComboFix 10-07-13.02 - David 14/07/2010 12:24:07.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.607 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\shaenaus.exe
Command switches used :: c:\documents and settings\David\Desktop\CFScript.txt
* Created a new restore point

FILE ::
"c:\windows\Ccumituyihitama.dat"
"c:\windows\Cmulu.bin"
"c:\windows\system32\lyssu.exe"

file zipped: c:\documents and settings\David\Application Data\cakzob.dat
file zipped: c:\documents and settings\LocalService\Application Data\cakzob.dat
file zipped: c:\documents and settings\NetworkService\Application Data\cakzob.dat
file zipped: c:\windows\system32\config\SYSTEM~1\APPLIC~1\2DOWNL~1\bore list heart.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\David\Application Data\cakzob.dat
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome.manifest
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome\content\_cfg.js
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome\content\overlay.xul
c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\install.rdf
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}\chrome.manifest
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}\chrome\content\_cfg.js
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}\chrome\content\overlay.xul
c:\documents and settings\Donna\Local Settings\Application Data\{8E596A9C-3AD3-4249-9528-A8991CE62159}\install.rdf
c:\documents and settings\LocalService\Application Data\cakzob.dat
c:\documents and settings\NetworkService\Application Data\cakzob.dat
c:\windows\Ccumituyihitama.dat
c:\windows\Cmulu.bin
c:\windows\system32\config\SYSTEM~1\APPLIC~1\2DOWNL~1\bore list heart.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_SUH4NIIIO
——-\Service_Ascnuntin
——-\Service_suh4niiio


((((((((((((((((((((((((( Files Created from 2010-06-14 to 2010-07-14 )))))))))))))))))))))))))))))))
.

2010-07-13 01:30 . 2010-07-13 01:30 ——– d—–w- c:\documents and settings\David\Application Data\Windows Search
2010-07-08 08:25 . 2010-07-08 08:25 ——– d-sh–w- c:\documents and settings\Donna\PrivacIE
2010-07-04 01:21 . 2010-07-04 01:21 ——– d-sh–w- c:\documents and settings\Donna\IETldCache
2010-06-16 12:19 . 2010-06-16 12:19 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-06-16 08:26 . 2010-06-16 08:26 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-06-16 03:55 . 2010-06-16 03:56 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-06-16 03:54 . 2010-06-16 03:54 ——– d-sh–w- c:\documents and settings\David\IECompatCache
2010-06-16 03:51 . 2010-06-16 03:51 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-06-16 03:49 . 2010-06-16 03:49 ——– d-sh–w- c:\documents and settings\David\PrivacIE
2010-06-16 03:47 . 2010-06-16 03:47 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-06-16 03:44 . 2010-06-16 03:44 ——– d-sh–w- c:\documents and settings\David\IETldCache
2010-06-16 03:35 . 2010-05-06 10:41 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2010-06-16 03:35 . 2010-05-06 10:41 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2010-06-16 03:35 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-16 03:35 . 2010-06-16 04:05 ——– d—–w- c:\windows\ie8updates
2010-06-16 03:34 . 2010-04-16 11:43 41984 ——w- c:\windows\system32\dllcache\iecompat.dll
2010-06-16 03:29 . 2010-06-16 03:33 ——– dc-h–w- c:\windows\ie8
2010-06-16 03:24 . 2010-06-16 03:24 ——– d—–w- c:\documents and settings\David\Application Data\Windows Desktop Search
2010-06-16 03:23 . 2010-06-16 04:12 ——– d—–w- c:\program files\Windows Desktop Search
2010-06-16 03:23 . 2010-06-16 03:23 ——– d—–w- c:\windows\system32\GroupPolicy
2010-06-16 03:20 . 2008-03-07 17:02 98304 ——w- c:\windows\system32\dllcache\nlhtml.dll
2010-06-16 03:20 . 2008-03-07 17:02 29696 ——w- c:\windows\system32\dllcache\mimefilt.dll
2010-06-16 03:20 . 2008-03-07 17:02 192000 ——w- c:\windows\system32\dllcache\offfilt.dll
2010-06-16 01:51 . 2009-10-23 15:28 3558912 ——w- c:\windows\system32\dllcache\moviemk.exe
2010-06-16 00:18 . 2004-08-03 12:31 20992 —-a-w- c:\windows\system32\drivers\RTL8139.sys
2010-06-16 00:18 . 2004-08-03 12:31 20992 —-a-w- c:\windows\system32\dllcache\rtl8139.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-14 02:43 . 2009-02-01 00:06 ——– d—–w- c:\program files\DNA
2010-07-14 02:43 . 2009-02-01 00:06 ——– d—–w- c:\documents and settings\David\Application Data\DNA
2010-07-12 08:32 . 2005-08-03 14:04 45840 -c–a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-07 08:00 . 2007-09-02 09:36 ——– d—–w- c:\program files\Norton Security Scan
2010-05-06 10:41 . 2004-08-10 04:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-10 04:51 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-10 04:50 285696 —-a-w- c:\windows\system32\atmfd.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3} —-

2010-06-22 22:06 . 2010-06-22 22:06 6778 —-a-w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome\content\overlay.xul
2010-06-22 22:06 . 2010-06-22 22:06 2060 —-a-w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome\content\_cfg.js
2010-06-22 22:06 . 2010-06-22 22:06 764 —-a-w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\install.rdf
2010-06-22 22:06 . 2010-06-22 22:06 122 —-a-w- c:\documents and settings\David\Local Settings\Application Data\{F76DDB26-BB84-4954-9395-CE30EB8664F3}\chrome.manifest


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2008-05-19 91432]
"vptray"="c:\program files\NavNT\vptray.exe" [2001-09-23 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-24 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-05 202256]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=c:\windows\pss\dlbcserv.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2005-05-30 19:33 122941 -c–a-w- c:\windows\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-04-28 04:34 53248 -c–a-w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2003-03-11 08:08 172032 -c–a-w- c:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-19 22:32 77824 -c–a-w- c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-19 22:36 114688 -c–a-w- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-19 22:35 94208 -c–a-w- c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 08:50 221184 -c–a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 08:50 81920 -c–a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 05:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 12:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-04 12:32 53248 ——w- c:\program files\REGSHAVE\REGSHAVE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 11:42 1404928 —-a-w- c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2006-12-14 17:23 75520 -c–a-w- c:\program files\Java\jre1.5.0_11\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-04-05 06:49 202256 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
2001-09-23 21:59 73728 —-a-w- c:\program files\NavNT\vptray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Documents and Settings\\Donna\\Local Settings\\Temp\\iCBB_21_21 R14-24 PRIMUS B01 Temporary Items\\iConnectDSLsvr.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1339:UDP"= 1339:UDP:Windows Media Format SDK (iexplore.exe)
"1338:UDP"= 1338:UDP:Windows Media Format SDK (iexplore.exe)
"1340:UDP"= 1340:UDP:Windows Media Format SDK (iexplore.exe)
"20856:UDP"= 20856:UDP:BitComet 20856 UDP
"23208:UDP"= 23208:UDP:BitComet 23208 UDP

R2 CAN300;CAN300;c:\windows\system32\drivers\can300.sys [3/08/2005 8:23 AM 10224]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};\??\c:\program files\CyberLink\PowerDVD8\000.fcl –> c:\program files\CyberLink\PowerDVD8\000.fcl [?]
S2 gupdate1ca8e7346fd63f8;Google Update Service (gupdate1ca8e7346fd63f8);c:\program files\Google\Update\GoogleUpdate.exe [6/01/2010 11:55 AM 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-07-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]

2010-07-14 c:\windows\Tasks\B35DDA3D945A4D01.job
- c:\docume~1\david\applic~1\2downl~1\RegsRemoteBib.exe [2009-02-07 23:12]

2010-07-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 01:54]

2010-07-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-06 01:54]

2010-07-08 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2008-01-08 17:08]

2010-07-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3774946206-295064592-2716718800-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]

2010-07-14 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3774946206-295064592-2716718800-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]

2010-07-04 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3774946206-295064592-2716718800-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]

2010-07-14 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3774946206-295064592-2716718800-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 12:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.iprimus.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.
22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172
.
31.*;192.168.*;;*.local
uInternet Settings,ProxyServer = proxy.iprimus.com.au:8080
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\David\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com.au
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101849&gct=&gc=1&q=
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\9gozxyl5.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-14 12:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(628)
c:\windows\system32\NavLogon.dll

- - - - - - - > 'explorer.exe'(2860)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\NavNT\defwatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\NavNT\rtvscan.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\MsgSys.EXE
c:\windows\system32\WgaTray.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-14 12:57:24 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-14 02:57
ComboFix2.txt 2010-07-13 03:25

Pre-Run: 67,461,906,432 bytes free
Post-Run: 67,319,545,856 bytes free

- - End Of File - - 4FFC6A88BF5BF828D0E3DA1D9793EA63
Hello Shaenaus

Thank you for the log.

This is not my computer so I did not uninstall the P2P programs nor Viewpoint MediaPlayer.

Okay. Please do not use these programs until we have finished cleaning the system. Once you return the machine to your Sister, please advise her that it would be in her best interests to uninstall those programs.

I did uninstall Messenger Plus! Live which I would like to reinstall later

No problem. We will take care of that once your machine is clean :)


Before we continue:


uInternet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.
22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172
.
31.*;192.168.*;;*.local
uInternet Settings,ProxyServer = proxy.iprimus.com.au:8080

Do you/your Sister recognise these proxies? Did you set them?


  • Please manually upload the following files for analysis


  • The CFScript I asked you to run was designed to upload the malware files on your system for analysis. Unfortunately the upload failed so I would like you to upload these files manually. Please do the following:
  • Please click on the following LINK. A new window will open.
  • In the box marked "Link to topic where this file was requested:" please paste in the following text:

http://forums.whatthetech.com/index.php?showtopic=112907

  • Click the "Browse" button and navigate to C:\Qoobox\Quarantine
  • There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip (the * denotes the Date and Time stamp - it will be close to this: 14/07/2010 12:24:07).
  • Select this file and click "Open".
  • In the Largest box please paste in:

File Requested By JonTom
Failed Collect::

  • Finally click "SendFile".
  • Please return here and let me know when that file has been uploaded.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI