Hey Ken…took me awhile to get the software and do these scans.
1. Here is the Rootkit Reveal log….
HKU\.DEFAULT\RemoteAccess\InternetProfile 9/4/2004 9:59 PM 7 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-21-1227912602-687269903-1541898498-1008\RemoteAccess\InternetProfile 11/28/2003 10:51 AM 7 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-18\RemoteAccess\InternetProfile 9/4/2004 9:59 PM 7 bytes Data mismatch between Windows API and raw hive data.
HKLM\SECURITY\Policy\Secrets\SAC* 9/3/2002 9:18 AM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 9/3/2002 9:18 AM 0 bytes Key name contains embedded nulls (*)
C:\Documents and Settings\Scott\Local Settings\Temp\TFR6D.tmp 11/11/2006 7:57 PM 8.00 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\css_14[2].css 11/11/2006 12:23 AM 26.71 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\dnserrordiagoff[1] 11/11/2006 7:57 PM 7.93 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\down[2] 11/11/2006 7:54 PM 3.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\favcenter[1] 11/11/2006 7:54 PM 3.29 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\favcenter[2] 11/11/2006 7:57 PM 3.29 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\google[1].htm 11/11/2006 7:57 PM 4.72 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\5FMNMLCU\tools[1] 11/11/2006 7:57 PM 3.48 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NMSDDN19\bullet[1] 11/11/2006 7:54 PM 3.09 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NMSDDN19\css_14[1].css 11/11/2006 7:57 PM 26.71 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NMSDDN19\down[1] 11/11/2006 7:57 PM 3.33 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\NMSDDN19\index[4].htm 11/11/2006 12:24 AM 103.21 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\bullet[1] 11/11/2006 7:57 PM 3.09 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\dnserrordiagoff[2] 11/11/2006 7:54 PM 7.93 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\errorPageStrings[1] 11/11/2006 7:57 PM 850 bytes Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\ErrorPageTemplate[1] 11/11/2006 7:54 PM 2.12 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\ErrorPageTemplate[2] 11/11/2006 7:57 PM 2.12 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S4OAFANE\info_48[1] 11/11/2006 7:54 PM 6.83 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\ads[1].htm 11/11/2006 7:57 PM 9.81 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\background_gradient[1] 11/11/2006 7:54 PM 453 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\background_gradient[2] 11/11/2006 7:57 PM 453 bytes Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\errorPageStrings[1] 11/11/2006 7:54 PM 850 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\google[1].htm 11/11/2006 7:09 PM 4.72 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\httpErrorPagesScripts[1] 11/11/2006 7:57 PM 6.81 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\httpErrorPagesScripts[2] 11/11/2006 7:54 PM 6.81 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\index[3].htm 11/11/2006 7:57 PM 103.24 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\info_48[1] 11/11/2006 7:57 PM 6.83 KB Hidden from Windows API.
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\S5JXY022\tools[1] 11/11/2006 7:54 PM 3.48 KB Visible in Windows API, but not in MFT or directory index.
2. Now the Blacklight log…
11/11/06 20:02:18 [Info]: BlackLight Engine 1.0.47 initialized
11/11/06 20:02:18 [Info]: OS: 5.1 build 2600 (Service Pack 2)
11/11/06 20:02:19 [Note]: 7019 4
11/11/06 20:02:19 [Note]: 7005 0
11/11/06 20:02:25 [Note]: 7006 0
11/11/06 20:02:25 [Note]: 7011 3472
11/11/06 20:02:25 [Note]: 7026 0
11/11/06 20:02:25 [Note]: 7026 0
11/11/06 20:02:30 [Note]: FSRAW library version 1.7.1020
11/11/06 20:14:25 [Note]: 7007 0
3. And finally a new HJT log…
Logfile of HijackThis v1.99.1
Scan saved at 8:16:07 PM, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINDOWS\Explorer.EXE
c:\program files\mcafee\msc\mcupdui.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\hjt\analyze.exe
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
Hopefully this will explain things some more.
I will be on the lookout for your reply.
Scott