i did the zbove steps twice as rem2.bat returned an message: "the service has already been started" in the commandline and the error popup: "deletekey: wrong parameter." (it rebootet nonetheless).
reading your last post i feared i had made a mistake with the script, but the second attempt resulted in the same way. here are the details:
1. created and ran trendit.bat
2. ran flash_disinfector several times with all the flash drives that had been attached to the box and once with no drive attached. took only a second or two independently if a drive was mounted or not… no idea if that means anything but i thought you should know.
3. ran rem2.bat with firewall and avg disabled. resulted in the error message above and rebooted.
4. kaspersky. (log below)
5. combofix. (log below)
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, June 30, 2007 11:07:29 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 30/06/2007
Kaspersky Anti-Virus database records: 356018
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
E:\
Scan Statistics:
Total number of scanned objects: 41884
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 00:49:54
Infected Object Name / Virus Name / Last Action
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\avg7\Log\emc.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Dokumente und Einstellungen\anto\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\Lokale Einstellungen\Verlauf\History.IE5\MSHist012007063020070701\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\anto\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\anto\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped
C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\ANTO.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\SeagateFlash.exe Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT021ab.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT021ae.TMP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
==============================================================================
"anto" - 2007-06-30 23:08:51 - ComboFix 07-06-27.7 - Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-30 )))))))))))))))))))))))))))))))
2007-06-30 22:10 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-06-30 21:43 drahs—- C:\autorun.inf
2007-06-30 13:44 853 –a—— C:\reboot.cmd
2007-06-30 13:44 68,096 –a—— C:\diff.exe
2007-06-30 13:44 103,424 –a—— C:\grep.exe
2007-06-30 13:39 d——– C:\DiagHelp
2007-06-29 21:41 d——– C:\Programme\EVEREST Ultimate Edition
2007-06-29 00:58 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Kaspersky Lab
2007-06-27 09:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-06-27 09:36 d——– C:\Programme\regbackup
2007-06-26 08:34 d——– C:\WINDOWS\BDOSCAN8
2007-06-25 23:01 d——– C:\DOKUME~1\anto\ricerche di mercato
2007-06-18 09:26 d——– C:\gmer
2007-06-18 09:10 d——– C:\getservice
2007-06-16 15:41 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-13 14:52 d——– C:\Programme\ht
2007-06-13 13:46 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-13 12:04 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-06-13 12:03 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-06-13 12:03 d——– C:\WINDOWS\system32\ZoneLabs
2007-06-13 11:42 5,632 –a—— C:\WINDOWS\system32\C22EE0C9.exe
2007-06-13 11:40 5,632 –a—— C:\WINDOWS\system32\A7F4841F.exe
2007-06-13 11:12 d——– C:\RkUnhooker
2007-06-13 09:45 d——– C:\pulire
2007-06-12 10:05 d——– C:\program files
2007-06-12 09:43 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-12 09:42 d——– C:\DOKUME~1\anto\.housecall6.6
2007-06-11 16:27 d——– C:\DOKUME~1\anto\ANWEND~1\Comodo
2007-06-11 16:26 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Comodo
2007-06-11 16:20 d——– C:\Programme\Comodo
2007-06-11 16:06 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-06-11 16:06 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-06-11 16:06 154,112 –a—— C:\WINDOWS\system32\irftp.exe
2007-05-29 11:14 d——– C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-29 11:13 d——– C:\Programme\ClamWin
2007-05-29 11:13 d——– C:\DOKUME~1\ALLUSE~1\.clamwin
2007-05-15 10:57 276,208 –a—— C:\vspubapi.dll
2007-05-15 10:57 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-05-15 10:57 104,176 –a—— C:\vsmonapi.dll
2007-05-06 20:43 d——– C:\Programme\Windows Media Connect 2
2007-05-06 20:36 d——– C:\WINDOWS\system32\drivers\UMDF
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-25 15:31:48 ——– d—–w C:\Programme\JKDefrag
2007-06-25 11:36:29 48,486 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-06-25 11:36:29 316,888 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-13 10:07:48 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-06-12 08:37:18 ——– d—–w C:\Programme\Spybot
2007-06-11 11:48:27 ——– d—–w C:\Programme\Startup Optimizer
2007-06-11 10:40:11 ——– d—–w C:\Programme\SyncBack
2007-05-29 15:33:50 ——– d—–w C:\Programme\CCleaner
2007-05-29 09:14:44 ——– d—–w C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-16 15:11:44 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:22:27 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Programme\Spybot\SDHelper.dll [2005-05-31 01:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-15 12:03]
"ZoneAlarm Client"="C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" [2007-05-30 14:29]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
2kadiras.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
9xadiras.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
"C:\Programme\ClamWin\bin\ClamTray.exe" –logon
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZCfgSvc.exe]
C:\WINDOWS\System32\ZCfgSvc.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
Contents of the 'Scheduled Tasks' folder
2007-01-15 18:05:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-30 23:11:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]
Completion time: 2007-06-30 23:13:01
C:\ComboFix-quarantined-files.txt … 2007-06-30 23:12
C:\ComboFix2.txt … 2007-06-30 17:21
— E O F —