Hi Jintan,
This computer is a HP AMD Athlon 2800+
It's about four years old.
I think I had a problem with typing
sc stop lsass and
sc delete lsass
because it didn't show in the command screen, but i blindly did it anyways.
Also, Windows had popped up saying I was not authorized to do this because it is illegal?
Safe Mode took me some time to figure out because the F8 tab key didn't seem to work.
So i did it manually myself by typing in MSCONFIG into the Start > Run
at first it didn't work so smoothly because all i got was a black screen with "Safe Mode" on all four corners.
After a few times of rebooting it finally worked :]
Other then the things mentioned above, everything you directed me to do ran quite nicely.
New HiJackThis scan:
Logfile of HijackThis v1.99.1
Scan saved at 4:02:32 PM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\AOL\1130986072\ee\AOLHostManager.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\AOL\1130986072\ee\AOLServiceHost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
C:\Program Files\2Wire\WebWorks.exe
C:\PROGRA~1\HEWLET~1\DIGITA~1\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Common Files\AOL\1130986072\ee\AOLServiceHost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\AOL\1130986072\ee\AOLServiceHost.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us9.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://sbc.yahoo.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://us9.hpwis.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: CIEPl Object - {F3727275-224F-4AB0-8642-7D461EFB82D8} - C:\WINDOWS\system32\dcmrm.dll
O2 - BHO: (no name) - {F39022DD-4718-4AF5-8F89-DB61016B14Ce} - C:\WINDOWS\system32\qpljqfvr.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1130986072\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [WinHound] C:\Program Files\WinHound\WinHound.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [WinPLOSION] "C:\Program Files\WinPLOSION\WinPlosion.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) -
http://community.web...wsaxcontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www.costcopho...stcoActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by109fd.bay10...es/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitd...can8/oscan8.cab
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) -
http://www.myheritag...EngineQuery.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1134859808406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1134859798828
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) -
http://community.web...otoUploader.CAB
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: dcmrm - C:\WINDOWS\SYSTEM32\dcmrm.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - c:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
SDFix Report.txt log:
SDFix: Version 1.91
Run by Owner on Sun 07/15/2007 at 10:30 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\Owner\Desktop\SDFix
Safe Mode:
Checking Services:
Name:
lsass
ImagePath:
"C:\WINDOWS\scvhost.exe"
lsass - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\IALMCOIN.DLL - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\win2E.tmp.exe - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\temp.exe - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\uninstall.exe - Deleted
C:\WINDOWS\system32\cmd.com - Deleted
C:\WINDOWS\system32\ipv6monr.dll - Deleted
C:\WINDOWS\system32\ipv6mons.dll - Deleted
C:\WINDOWS\system32\netstat.com - Deleted
C:\WINDOWS\system32\ping.com - Deleted
C:\WINDOWS\system32\regedit.com - Deleted
C:\WINDOWS\system32\taskkill.com - Deleted
C:\WINDOWS\system32\tasklist.com - Deleted
C:\WINDOWS\system32\tracert.com - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\Owner\Desktop\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\Documents and Settings\Owner\Desktop\carp**\New Folder\Jin-ABC-JP-[RapBlueprint.com]-2007-C4\Thumbs.db
C:\Documents and Settings\Owner\My Documents\My Music\Jin-ABC-JP-[RapBlueprint.com]-2007-C4\Thumbs.db
C:\Documents and Settings\Administrator\Local Settings\Temp\hwndgbkqd.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\mk.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\oktz7.dll
C:\Documents and Settings\Administrator\Local Settings\Temp\u0.dll
C:\Documents and Settings\Default User\Local Settings\Temp\hwndgbkqd.dll
C:\Documents and Settings\Default User\Local Settings\Temp\mk.dll
C:\Documents and Settings\Default User\Local Settings\Temp\oktz7.dll
C:\Documents and Settings\Default User\Local Settings\Temp\u0.dll
C:\Program Files\America Online 9.0a\AOLphx.exe
C:\Program Files\America Online 9.0a\rbm.exe
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\WINDOWS\SoftwareDistribution\Download\9ded4ee34a35fced0033d3e152a36e0e\download\BIT2A.tmp
Finished
Combofix.txt log:
"Owner" - 2007-07-15 11:02:01 - ComboFix 07-07-13.8 - Service Pack 2 NTFS [SAFE MODE]
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\xod.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ADMINI~1\APPLIC~1\Sskknwrd.dll
C:\DOCUME~1\ADMINI~1\APPLIC~1\Sskuknwrd.dll
C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sskknwrd.dll
C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sskuknwrd.dll
C:\DOCUME~1\Owner\APPLIC~1.\macromedia\Flash Player\#SharedObjects\TXN8K67Q\www.broadcaster.com
C:\DOCUME~1\Owner\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\Owner\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Program Files\Common Files\download
C:\Program Files\Common Files\download\freeprodtb.exe
C:\Program Files\Common Files\download\mc-110-12-0000166.exe
C:\Program Files\Common Files\download\mc-58-12-0000166.exe
C:\Program Files\Common Files\inetget
C:\Program Files\Common Files\inetget2
C:\Program Files\Common Files\inetget2\mc-58-12-0000166.exe
C:\Program Files\Common Files\services.exe
C:\Program Files\Common Files\system32.dll
C:\Program Files\inetget2
C:\Program Files\video activex access
C:\Program Files\windows
C:\Program Files\winupdates
C:\Program Files\winupdates\a.zip
C:\WINDOWS\1.exe -ppc_timeout=
C:\WINDOWS\144.exe
C:\WINDOWS\1800.exe
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\2272.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\bi.dll
C:\WINDOWS\biprep.exe
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\DOWNLO~1.\ysbactivex.dll
C:\WINDOWS\flt.dll
C:\WINDOWS\hosts
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\NDNuninstall6_38.exe
C:\WINDOWS\pbar.dll
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\satmat.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\susp.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wmvds32.dll
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
C:\WINDOWS\wml.exe
((((((((((((((((((((((((( Files Created from 2007-06-15 to 2007-07-15 )))))))))))))))))))))))))))))))
2007-07-15 11:01 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-15 10:28 <DIR> d-------- C:\WINDOWS\ERUNT
2007-07-15 02:32 2,268 ---hs---- C:\WINDOWS\system32\ospcont.dat
2007-07-15 02:30 836 --a------ C:\DOCUME~1\ADMINI~1\APPLIC~1\ViewerApp.dat
2007-07-15 01:25 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\APPLIC~1\GTek
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Publish Providers
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\NetMedia Providers
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\MSN6
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Motive
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Lycos
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\InterVideo
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\interMute
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Corel
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\ArcSoft
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Aim
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\.limewire
2007-07-15 01:25 <DIR> d-------- C:\DOCUME~1\ADMINI~1\.jpi_cache
2007-07-15 01:24 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-07-15 01:24 <DIR> d---s---- C:\DOCUME~1\ADMINI~1\UserData
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\WINDOWS
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Incomplete
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Yahoo! Messenger
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Template
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Sonic Foundry
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Sonic
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SampleView
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Roxio
2007-07-15 01:24 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
2007-07-15 01:17 <DIR> d-------- C:\WINDOWS\pss
2007-07-14 22:51 259,604 --a------ C:\WINDOWS\system32\sxccfhbu.dll
2007-07-14 22:51 124,948 --a------ C:\WINDOWS\system32\qpljqfvr.dll
2007-07-14 22:47 259,604 --------- C:\WINDOWS\system32\xggrywmk.dll
2007-07-14 22:47 124,948 --a------ C:\WINDOWS\system32\qhfmyjbl.dll
2007-07-14 22:25 259,604 --------- C:\WINDOWS\system32\lewpwqei.dll
2007-07-14 22:25 124,948 --a------ C:\WINDOWS\system32\rsbyiabe.dll
2007-07-14 22:09 259,604 --------- C:\WINDOWS\system32\smdfpndl.dll
2007-07-14 22:09 124,948 --a------ C:\WINDOWS\system32\mvoooelt.dll
2007-07-13 20:58 124,948 --a------ C:\WINDOWS\system32\eltyncab.dll
2007-07-13 20:57 259,604 --------- C:\WINDOWS\system32\ixddetki.dll
2007-07-12 22:49 124,948 --a------ C:\WINDOWS\system32\scxawvup.dll
2007-07-12 21:26 124,948 --a------ C:\WINDOWS\system32\njknlpnj.dll
2007-07-12 21:01 124,948 --a------ C:\WINDOWS\system32\ehioeisv.dll
2007-07-12 21:00 259,604 --a------ C:\WINDOWS\system32\hnoxhdoi.dll
2007-07-12 20:01 124,948 --a------ C:\WINDOWS\system32\sidvbvgb.dll
2007-07-07 21:03 259,604 --------- C:\WINDOWS\system32\cfosxvux.dll
2007-07-07 21:03 124,948 --a------ C:\WINDOWS\system32\iaeiantv.dll
2007-07-02 23:01 124,948 --a------ C:\WINDOWS\system32\aanqtiwg.dll
2007-07-02 22:54 259,604 --a------ C:\WINDOWS\system32\ihepbkvg.dll
2007-07-02 22:54 124,948 --a------ C:\WINDOWS\system32\ifjtuvye.dll
2007-07-02 21:29 124,948 --a------ C:\WINDOWS\system32\vfipepun.dll
2007-07-01 20:27 259,604 --------- C:\WINDOWS\system32\ojscttje.dll
2007-07-01 20:27 124,948 --a------ C:\WINDOWS\system32\mspfuugd.dll
2007-06-30 23:07 124,948 --a------ C:\WINDOWS\system32\nxfraact.dll
2007-06-21 00:08 124,948 --a------ C:\WINDOWS\system32\nioncira.dll
2007-06-21 00:05 978,413 --------- C:\WINDOWS\system32\dcmrm.dll
2007-06-17 21:10 32 --ahs---- C:\WINDOWS\system32\{981E6DF4-EF56-48B7-9837-71508F600CF8}.dat
2007-06-17 21:10 32 --ahs---- C:\WINDOWS\{C2DE7FE9-0E3A-4D91-8B0F-318831CE9792}.dat
2007-06-17 21:08 83,672 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-06-17 21:08 73,480 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-06-17 21:08 <DIR> d-------- C:\Program Files\Norton Personal Firewall
2007-06-17 21:07 14 --a------ C:\WINDOWS\system32\SR2.dat
2007-06-16 11:58 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-15 10:06:45 -------- d-----w C:\Program Files\Spyware Doctor
2007-07-15 08:42:08 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-07-08 06:04:27 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Skype
2007-07-08 05:02:13 630,200 ----a-w C:\WINDOWS\system32\drivers\VetEFile.sys
2007-07-08 05:02:12 108,392 ----a-w C:\WINDOWS\system32\drivers\VetEBoot.sys
2007-07-01 07:09:51 4 ----a-w C:\WINDOWS\system32\stfv.bin
2007-06-18 05:09:23 -------- d-----w C:\Program Files\Symantec
2007-06-17 05:27:46 -------- d-----w C:\Program Files\545 Studios
2007-06-16 20:18:13 -------- d-----w C:\Program Files\WinPLOSION
2007-06-15 02:20:15 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\PC Tools
2007-06-14 06:55:30 26,880 ----a-w C:\WINDOWS\vxddsk.exe
2007-06-14 06:55:14 567 ----a-w C:\WINDOWS\system32\drivers\users_rating.gif
2007-06-14 06:55:14 291 ----a-w C:\WINDOWS\system32\drivers\v.gif
2007-06-14 06:55:14 283 ----a-w C:\WINDOWS\system32\drivers\x.gif
2007-06-14 06:55:13 801 ----a-w C:\WINDOWS\system32\drivers\system_stable_header_small.gif
2007-06-14 06:55:13 6,533 ----a-w C:\WINDOWS\system32\drivers\system_stable_box_small.jpg
2007-06-14 06:55:13 15,075 ----a-w C:\WINDOWS\system32\drivers\system_stable_box.jpg
2007-06-14 06:55:13 1,636 ----a-w C:\WINDOWS\system32\drivers\system_stable_header.gif
2007-06-14 06:55:12 579 ----a-w C:\WINDOWS\system32\drivers\spy_away_header_small.gif
2007-06-14 06:55:12 5,097 ----a-w C:\WINDOWS\system32\drivers\spy_away_box_small.jpg
2007-06-14 06:55:12 13,618 ----a-w C:\WINDOWS\system32\drivers\spy_away_box.jpg
2007-06-14 06:55:12 1,139 ----a-w C:\WINDOWS\system32\drivers\spy_away_header.gif
2007-06-14 06:55:11 841 ----a-w C:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif
2007-06-14 06:55:11 14,484 ----a-w C:\WINDOWS\system32\drivers\protect.gif
2007-06-14 06:55:11 1,804 ----a-w C:\WINDOWS\system32\drivers\perfect_cleaner_header.gif
2007-06-14 06:55:10 737 ----a-w C:\WINDOWS\system32\drivers\logo_bg.gif
2007-06-14 06:55:10 4,557 ----a-w C:\WINDOWS\system32\drivers\perfect_cleaner_box_small.jpg
2007-06-14 06:55:10 3,099 ----a-w C:\WINDOWS\system32\drivers\logo.gif
2007-06-14 06:55:10 10,260 ----a-w C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
2007-06-14 06:55:09 811 ----a-w C:\WINDOWS\system32\drivers\download_btn.gif
2007-06-14 06:55:09 746 ----a-w C:\WINDOWS\system32\drivers\buy_btn.gif
2007-06-14 06:55:09 580 ----a-w C:\WINDOWS\system32\drivers\features.gif
2007-06-14 06:55:09 50,277 ----a-w C:\WINDOWS\system32\drivers\pt.htm
2007-06-14 06:55:09 427 ----a-w C:\WINDOWS\system32\drivers\4_stars.gif
2007-06-14 06:55:09 365 ----a-w C:\WINDOWS\system32\drivers\5_stars.gif
2007-06-14 06:55:07 945 ----a-w C:\WINDOWS\system32\drivers\s_detect.htm
2007-06-14 06:55:07 6,373 ----a-w C:\WINDOWS\system32\drivers\secuity_center_logo.gif
2007-06-14 06:55:06 64 ----a-w C:\WINDOWS\system32\drivers\close_icon.gif
2007-06-14 06:55:06 6,575 ----a-w C:\WINDOWS\system32\drivers\remove_spyware_button.gif
2007-06-14 06:55:06 360 ----a-w C:\WINDOWS\system32\drivers\header_bg.gif
2007-06-14 06:55:06 2,186 ----a-w C:\WINDOWS\system32\drivers\alert_icon.gif
2007-06-14 06:55:06 1,014 ----a-w C:\WINDOWS\system32\drivers\icon_warning.gif
2007-06-14 06:55:05 4,825 ----a-w C:\WINDOWS\system32\drivers\detect.htm
2007-06-12 03:50:04 75,264 ----a-w C:\WINDOWS\system32\WEP.dll
2007-06-12 03:50:03 11,776 ----a-w C:\WINDOWS\system32\WINPHK.DLL
2007-06-05 07:35:38 -------- d-----w C:\Program Files\Stardock
2007-05-31 01:06:19 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Snapfish
2007-05-24 00:58:54 29,264 ----a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-05-24 00:58:50 83,024 ----a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-05-24 00:58:46 57,424 ----a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-05-24 00:58:42 53,840 ----a-w C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-05-24 00:58:38 39,376 ----a-w C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-05-23 03:00:09 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Image Zone Express
2005-07-07 03:25:12 343,639 ------r C:\Program Files\Common Files\clbcatex.exe
2005-01-03 19:20:15 836 ----a-w C:\DOCUME~1\Owner\APPLIC~1\ViewerApp.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F3727275-224F-4AB0-8642-7D461EFB82D8}]
2007-06-21 00:06 978413 --------- C:\WINDOWS\system32\dcmrm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F39022DD-4718-4AF5-8F89-DB61016B14Ce}]
2007-07-14 22:51 124948 --a------ C:\WINDOWS\system32\qpljqfvr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD05"="c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 02:03]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 07:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2003-08-23 06:14]
"AutoTKit"="C:\hp\bin\AUTOTKIT.EXE" [2003-06-18 18:19]
"nwiz"="nwiz.exe" [2003-05-02 22:19 C:\WINDOWS\system32\nwiz.exe]
"mmtask"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2003-02-24 17:51]
"HostManager"="C:\Program Files\Common Files\AOL\1130986072\ee\AOLHostManager.exe" [2005-08-02 14:26]
"WinHound"="C:\Program Files\WinHound\WinHound.exe" []
"CaAvTray"="C:\Program Files\Yahoo!\Antivirus\CAVTray.exe" [2005-12-17 15:16]
"CAVRID"="C:\Program Files\Yahoo!\Antivirus\CAVRID.exe" [2005-12-17 15:16]
"YOP"="C:\PROGRA~1\Yahoo!\YOP\yop.exe" [2006-07-21 10:43]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 15:44]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"VF0060 STISvc"="V0060Pin.dll" [2004-10-31 17:00 C:\WINDOWS\system32\V0060Pin.dll]
"WinPLOSION"="C:\Program Files\WinPLOSION\WinPlosion.exe" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-07-01 21:10]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-11-14 19:29]
"ccRegVfy"="c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-11-14 19:29]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SDFix"="C:\DOCUME~1\Owner\Desktop\SDFix\RunThis.bat /second" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 20:25]
"NVIEW"="nview.dll,nViewLoadHook" []
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 08:24]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 19:25]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SDFix"=C:\DOCUME~1\Owner\Desktop\SDFix\RunThis.bat /second
"combofix"=C:\WINDOWS\system32\cmd.exe /c C:\ComboFix\Combobatch.bat
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\WINDOWS\warnhp.html
FriendlyName= Warning homepage
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dcmrm]
dcmrm.dll --------- 2007-06-21 00:06 978413 C:\WINDOWS\system32\dcmrm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll --a------ 2003-02-21 02:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F146C9B1-VMVQ-A9RC-NUFL-D0BA00B4E999}
C:\WINDOWS\system32\msorcl32.exe
Contents of the 'Scheduled Tasks' folder
2007-07-02 05:29:17 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2004-05-28 02:37:18 C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1072488026.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-15 11:21:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
Completion time: 2007-07-15 11:26:11 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-15 11:25
--- E O F ---