Renzo McDuffy
Topic Starter
My tcpip.sys were removed as an infected/corrupt set of files after I installed the free version of AVG. I had also previously had to remove malware/spware, etc using a variety of programs. I was also concerned that after removing these files, and the running HiJack This, I hit "Fix all." May have inadverntenly deleted necessary files. I had Avast running at the time AVG was installed, and have since removed Avast. Now I have no internet connectivity. Here are my HJT log and ComboFix logs.
Please help, as I am this close to running a Windows XP Repair! Thank you!
Logfile of HijackThis v1.99.1
Scan saved at 9:58:34 AM, on 8/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HiJackThis v1.99\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpeedswitchXP] C:\Program Files\SpeedswitchXP\SpeedswitchXP.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifescapeinc.com/installers…ll/pinstall.cab
O16 - DPF: {7E0FDFBB-87D4-43A1-9AD4-41F0EA8AFF7B} - https://bhcsecuregateway.boone.org/net6helper.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{49B78B45-F973-4AD7-87E1-E41351B65776}: NameServer = 216.104.64.5,216.104.72.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{728EF0C8-6F6E-4305-9A6D-02253A1CF29F}: NameServer = 216.228.160.5,216.228.160.36
O17 - HKLM\System\CS1\Services\Tcpip\..\{49B78B45-F973-4AD7-87E1-E41351B65776}: NameServer = 216.104.64.5,216.104.72.5
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
ComboFix 07-08-14.4 - "Brook Derenzy" 2007-08-19 18:58:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.216 [GMT -7:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\BROOKD~1\APPLIC~1\..\err.log
C:\DOCUME~1\LOCALS~1\APPLIC~1\install.dat
C:\DOCUME~1\NETWOR~1\APPLIC~1\install.dat
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\Companion Wizard\log.txt
C:\Program Files\Common Files\companion wizard\log.txt
C:\Program Files\Common Files\companion wizard\WapCHK.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
C:\Program Files\Common Files\companion wizard\WapCHK{C819BC0C-8BE1-4CD6-BDFE-00D63D89975D}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{C819BC0C-8BE1-4CD6-BDFE-00D63D89975D}.dll
C:\Program Files\sembly~1
C:\Program Files\sembly~1\??sembly\
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Ultimate Cleaner
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\bass.exe
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\tn3
C:\WA6P
C:\WINDOWS\Casino.ico
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\system32\15242115641.dll
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\B1\chkq22011.exe
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\asc3550u.sys
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\dygliohx.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f06WtR
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\setup155.exe
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\win
C:\WINDOWS\system32\Y1
C:\WINDOWS\system32\Y2
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_ASC3550U
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NET_AGENT
——-\LEGACY_POOF
——-\LEGACY_VSPF
——-\LEGACY_VSPF_HK
——-\LEGACY_WINDOWS_OVERLAY_COMPONENTS
——-\Net Agent
——-\nm
((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))
2007-08-19 18:56 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-19 15:35 4,608 –a—— C:\WINDOWS\system32\dllcache\xrxflnch.exe
2007-08-19 15:35 27,648 –a—— C:\WINDOWS\system32\dllcache\xrxftplt.exe
2007-08-19 15:35 23,040 –a—— C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2007-08-19 15:35 17,408 –a—— C:\WINDOWS\system32\dllcache\xrxscnui.dll
2007-08-19 15:35 116,224 –a—— C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2007-08-19 15:34 99,865 –a—— C:\WINDOWS\system32\dllcache\xlog.exe
2007-08-19 15:34 8,192 –a—— C:\WINDOWS\system32\dllcache\wshirda.dll
2007-08-19 15:34 19,455 –a—— C:\WINDOWS\system32\dllcache\wvchntxx.sys
2007-08-19 15:34 16,970 –a—— C:\WINDOWS\system32\dllcache\xem336n5.sys
2007-08-19 15:34 12,063 –a—— C:\WINDOWS\system32\dllcache\wsiintxx.sys
2007-08-19 15:33 8,832 –a—— C:\WINDOWS\system32\dllcache\wmiacpi.sys
2007-08-19 15:33 34,890 –a—— C:\WINDOWS\system32\dllcache\wlandrv2.sys
2007-08-19 15:33 154,624 –a—— C:\WINDOWS\system32\dllcache\wlluc48.sys
2007-08-19 15:32 9,216 –a—— C:\WINDOWS\system32\dllcache\wamps51.dll
2007-08-19 15:32 87,040 –a—— C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2007-08-19 15:32 771,581 –a—— C:\WINDOWS\system32\dllcache\winacisa.sys
2007-08-19 15:32 76,800 –a—— C:\WINDOWS\system32\dllcache\wam51.dll
2007-08-19 15:32 701,386 –a—— C:\WINDOWS\system32\dllcache\wdhaalba.sys
2007-08-19 15:32 53,760 –a—— C:\WINDOWS\system32\dllcache\wiamsmud.dll
2007-08-19 15:32 53,248 –a—— C:\WINDOWS\system32\dllcache\wamreg51.dll
2007-08-19 15:32 41,600 –a—— C:\WINDOWS\system32\dllcache\weitekp9.dll
2007-08-19 15:32 35,871 –a—— C:\WINDOWS\system32\dllcache\wbfirdma.sys
2007-08-19 15:32 33,599 –a—— C:\WINDOWS\system32\dllcache\watv04nt.sys
2007-08-19 15:32 31,744 –a—— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2007-08-19 15:32 31,232 –a—— C:\WINDOWS\system32\dllcache\weitekp9.sys
2007-08-19 15:32 29,311 –a—— C:\WINDOWS\system32\dllcache\watv01nt.sys
2007-08-19 15:32 25,471 –a—— C:\WINDOWS\system32\dllcache\watv10nt.sys
2007-08-19 15:32 23,615 –a—— C:\WINDOWS\system32\dllcache\wch7xxnt.sys
2007-08-19 15:32 22,271 –a—— C:\WINDOWS\system32\dllcache\watv06nt.sys
2007-08-19 15:32 19,551 –a—— C:\WINDOWS\system32\dllcache\watv02nt.sys
2007-08-19 15:32 16,925 –a—— C:\WINDOWS\system32\dllcache\w940nd.sys
2007-08-19 15:32 13,568 –a—— C:\WINDOWS\system32\dllcache\wacompen.sys
2007-08-19 15:32 12,415 –a—— C:\WINDOWS\system32\dllcache\wadv01nt.sys
2007-08-19 15:32 12,127 –a—— C:\WINDOWS\system32\dllcache\wadv02nt.sys
2007-08-19 15:32 11,935 –a—— C:\WINDOWS\system32\dllcache\wadv11nt.sys
2007-08-19 15:32 11,871 –a—— C:\WINDOWS\system32\dllcache\wadv09nt.sys
2007-08-19 15:32 11,807 –a—— C:\WINDOWS\system32\dllcache\wadv07nt.sys
2007-08-19 15:32 11,775 –a—— C:\WINDOWS\system32\dllcache\wadv05nt.sys
2007-08-19 15:32 11,295 –a—— C:\WINDOWS\system32\dllcache\wadv08nt.sys
2007-08-19 15:31 86,073 –a—— C:\WINDOWS\system32\dllcache\voicesub.dll
2007-08-19 15:31 765,884 –a—— C:\WINDOWS\system32\dllcache\usrti.sys
2007-08-19 15:31 73,728 –a—— C:\WINDOWS\system32\dllcache\w3ext.dll
2007-08-19 15:31 687,999 –a—— C:\WINDOWS\system32\dllcache\usrwdxjs.sys
2007-08-19 15:31 64,605 –a—— C:\WINDOWS\system32\dllcache\vvoice.sys
2007-08-19 15:31 604,253 –a—— C:\WINDOWS\system32\dllcache\vmodem.sys
2007-08-19 15:31 5,632 –a—— C:\WINDOWS\system32\dllcache\w3svapi.dll
2007-08-19 15:31 48,256 –a—— C:\WINDOWS\system32\dllcache\w32.dll
2007-08-19 15:31 426,041 –a—— C:\WINDOWS\system32\dllcache\voicepad.dll
2007-08-19 15:31 4,608 –a—— C:\WINDOWS\system32\dllcache\w3ctrs51.dll
2007-08-19 15:31 397,502 –a—— C:\WINDOWS\system32\dllcache\vpctcom.sys
2007-08-19 15:31 363,520 –a—— C:\WINDOWS\system32\dllcache\w3svc.dll
2007-08-19 15:31 249,402 –a—— C:\WINDOWS\system32\dllcache\vinwm.sys
2007-08-19 15:31 24,576 –a—— C:\WINDOWS\system32\dllcache\viairda.sys
2007-08-19 15:31 19,528 –a—— C:\WINDOWS\system32\dllcache\w840nd.sys
2007-08-19 15:31 19,016 –a—— C:\WINDOWS\system32\dllcache\w926nd.sys
2007-08-19 15:31 11,325 –a—— C:\WINDOWS\system32\dllcache\vchnt5.dll
2007-08-19 15:30 94,720 –a—— C:\WINDOWS\system32\dllcache\umaxud32.dll
2007-08-19 15:30 794,654 –a—— C:\WINDOWS\system32\dllcache\usr1801.sys
2007-08-19 15:30 794,399 –a—— C:\WINDOWS\system32\dllcache\usr1806v.sys
2007-08-19 15:30 793,598 –a—— C:\WINDOWS\system32\dllcache\usr1806.sys
2007-08-19 15:30 78,464 –a—— C:\WINDOWS\system32\dllcache\usbvideo.sys
2007-08-19 15:30 76,288 –a—— C:\WINDOWS\system32\dllcache\uniime.dll
2007-08-19 15:30 7,556 –a—— C:\WINDOWS\system32\dllcache\usroslba.sys
2007-08-19 15:30 32,384 –a—— C:\WINDOWS\system32\dllcache\usb101et.sys
2007-08-19 15:30 28,160 –a—— C:\WINDOWS\system32\dllcache\umaxu40.dll
2007-08-19 15:30 26,624 –a—— C:\WINDOWS\system32\dllcache\umaxu22.dll
2007-08-19 15:30 25,600 –a—— C:\WINDOWS\system32\dllcache\usbser.sys
2007-08-19 15:30 224,802 –a—— C:\WINDOWS\system32\dllcache\usr1807a.sys
2007-08-19 15:30 17,024 –a—— C:\WINDOWS\system32\dllcache\usbohci.sys
2007-08-19 15:30 12,672 –a—— C:\WINDOWS\system32\dllcache\usb8023x.sys
2007-08-19 15:30 113,762 –a—— C:\WINDOWS\system32\dllcache\usrpda.sys
2007-08-19 15:29 69,632 –a—— C:\WINDOWS\system32\dllcache\umaxu12.dll
2007-08-19 15:29 525,568 –a—— C:\WINDOWS\system32\dllcache\tridxp.dll
2007-08-19 15:29 50,688 –a—— C:\WINDOWS\system32\dllcache\umaxscan.dll
2007-08-19 15:29 50,176 –a—— C:\WINDOWS\system32\dllcache\umaxp60.dll
2007-08-19 15:29 47,616 –a—— C:\WINDOWS\system32\dllcache\umaxcam.dll
2007-08-19 15:29 44,672 –a—— C:\WINDOWS\system32\dllcache\uagp35.sys
2007-08-19 15:29 22,912 –a—— C:\WINDOWS\system32\dllcache\umaxpcls.sys
2007-08-19 15:29 216,064 –a—— C:\WINDOWS\system32\dllcache\um34scan.dll
2007-08-19 15:29 211,968 –a—— C:\WINDOWS\system32\dllcache\um54scan.dll
2007-08-19 15:29 166,784 –a—— C:\WINDOWS\system32\dllcache\tridxpm.sys
2007-08-19 15:29 159,232 –a—— C:\WINDOWS\system32\dllcache\tridkbm.sys
2007-08-19 15:29 14,336 –a—— C:\WINDOWS\system32\dllcache\tsprof.exe
2007-08-19 15:29 11,520 –a—— C:\WINDOWS\system32\dllcache\twotrack.sys
2007-08-19 15:29 103,424 –a—— C:\WINDOWS\system32\dllcache\uihelper.dll
2007-08-19 15:28 82,432 –a—— C:\WINDOWS\system32\dllcache\tp4mon.exe
2007-08-19 15:28 455,168 –a—— C:\WINDOWS\system32\dllcache\tintsetp.exe
2007-08-19 15:28 440,576 –a—— C:\WINDOWS\system32\dllcache\tridkb.dll
2007-08-19 15:28 44,032 –a—— C:\WINDOWS\system32\dllcache\tintlphr.exe
2007-08-19 15:28 42,496 –a—— C:\WINDOWS\system32\dllcache\tp4res.dll
2007-08-19 15:28 34,375 –a—— C:\WINDOWS\system32\dllcache\tpro4.sys
2007-08-19 15:28 315,520 –a—— C:\WINDOWS\system32\dllcache\trid3d.dll
2007-08-19 15:28 31,744 –a—— C:\WINDOWS\system32\dllcache\tp4.dll
2007-08-19 15:28 31,232 –a—— C:\WINDOWS\system32\dllcache\tools.dll
2007-08-19 15:28 28,232 –a—— C:\WINDOWS\system32\dllcache\tos4mo.sys
2007-08-19 15:28 241,664 –a—— C:\WINDOWS\system32\dllcache\tosdvd02.sys
2007-08-19 15:28 230,912 –a—— C:\WINDOWS\system32\dllcache\tosdvd03.sys
2007-08-19 15:28 222,336 –a—— C:\WINDOWS\system32\dllcache\trid3dm.sys
2007-08-19 15:28 185,344 –a—— C:\WINDOWS\system32\dllcache\thawbrkr.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-19 19:07 ——— d——– C:\Program Files\Plaxo
2007-08-16 21:12 ——— d——– C:\Program Files\New Tier
2007-08-16 20:08 ——— d——– C:\DOCUME~1\BROOKD~1\APPLIC~1\New Tier
2007-08-16 11:08 ——— d——– C:\Program Files\Picasa2
2007-08-13 20:59 ——— d——– C:\Program Files\Logitech
2007-08-11 09:44 ——— d——– C:\Program Files\Citrix
2007-08-10 14:48 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-07 22:27 ——— d——– C:\DOCUME~1\BROOKD~1\APPLIC~1\AdobeUM
2007-07-29 17:27 ——— d——– C:\DOCUME~1\BROOKD~1\APPLIC~1\Move Networks
2007-06-26 08:13 851968 –a—— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 07:09 658944 –a—— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-25 23:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-25 23:08 1104896 –a—— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 06:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 06:31 282112 –a—— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-14 11:09 96256 –a—— C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 11:09 615424 –a—— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 11:09 55808 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 11:09 532480 –a—— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 11:09 474112 –a—— C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 11:09 449024 –a—— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 11:09 39424 –a—— C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 11:09 357888 –a—— C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 11:09 3058688 –a—— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 11:09 251392 –a—— C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 11:09 205312 –a—— C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 11:09 16384 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 11:09 151040 –a—— C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 11:09 1494528 –a—— C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 11:09 146432 –a—— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 11:09 1054208 –a—— C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 11:09 1023488 –a—— C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 07:07 18432 –a—— C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 03:23 1033216 –a—— C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 03:23 1033216 –a—— C:\WINDOWS\explorer.exe
2005-10-21 14:06 13492969 –a—— C:\Program Files\iTunes.zip
2005-10-21 13:20 2991946 –a—— C:\Program Files\Windows Media Player.zip
2005-06-12 18:55 128 –a—— C:\Program Files\wMjLdXwBoD!ulNm6ti3oRWdOHPqXdNRxtPD1eH58yPfSS3FKbUSwA_JMx2wNbvwdmXME5N0V150YZ106WUOpKA=
.ram
2005-06-12 18:54 128 –a—— C:\Program Files\wMjLdXwBoD!ulNm6ti3oRWdOHPqXdNRxtPD1eH58yPfLbNzBCnJ!xCBhmeDk1U4l6qgQkm9!7kCr!9ukanrPcw==.ram
2005-06-12 18:53 120 –a—— C:\Program Files\UPrSy!2waSkKlx_tHz2gg2x4Gydd7RjyJ!E7BUbakWHWbk5sZbSN!JJQ7CiiubD78!7xPYMjacpA_QQCaRHdkg==.ram
2005-06-04 15:09 8219278 –a—— C:\Program Files\RhapsodyReal.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 15:48]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 06:04]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-06 23:01]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-05 23:05]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-06-15 16:15]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" [2006-11-16 13:42]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-01 12:34]
"SpeedswitchXP"="C:\Program Files\SpeedswitchXP\SpeedswitchXP.exe" [2006-07-14 14:56]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-14 23:19:50]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-05-25 21:03:38]
HotSync Manager.lnk - C:\Program Files\Sony Handheld\HOTSYNC.EXE [2005-06-20 11:25:14]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-10-22 14:23:53]
R2 BASFND;BASFND;\??\C:\WINDOWS\system32\Drivers\BASFND.sys
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys
S3 SbcpHid;SbcpHid;\??\C:\WINDOWS\system32\Drivers\SbcpHid.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\LaunchU3.exe -a
Contents of the 'Scheduled Tasks' folder
2007-08-07 15:43:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-20 02:01:00 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDetect.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-19 19:07:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-19 19:09:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-19 19:09
— E O F —
Please help, as I am this close to running a Windows XP Repair! Thank you!
Logfile of HijackThis v1.99.1
Scan saved at 9:58:34 AM, on 8/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HiJackThis v1.99\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpeedswitchXP] C:\Program Files\SpeedswitchXP\SpeedswitchXP.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifescapeinc.com/installers…ll/pinstall.cab
O16 - DPF: {7E0FDFBB-87D4-43A1-9AD4-41F0EA8AFF7B} - https://bhcsecuregateway.boone.org/net6helper.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{49B78B45-F973-4AD7-87E1-E41351B65776}: NameServer = 216.104.64.5,216.104.72.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{728EF0C8-6F6E-4305-9A6D-02253A1CF29F}: NameServer = 216.228.160.5,216.228.160.36
O17 - HKLM\System\CS1\Services\Tcpip\..\{49B78B45-F973-4AD7-87E1-E41351B65776}: NameServer = 216.104.64.5,216.104.72.5
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
ComboFix 07-08-14.4 - "Brook Derenzy" 2007-08-19 18:58:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.216 [GMT -7:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\BROOKD~1\APPLIC~1\..\err.log
C:\DOCUME~1\LOCALS~1\APPLIC~1\install.dat
C:\DOCUME~1\NETWOR~1\APPLIC~1\install.dat
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\Companion Wizard\log.txt
C:\Program Files\Common Files\companion wizard\log.txt
C:\Program Files\Common Files\companion wizard\WapCHK.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
C:\Program Files\Common Files\companion wizard\WapCHK{C819BC0C-8BE1-4CD6-BDFE-00D63D89975D}.dll
C:\Program Files\Common Files\Companion Wizard\WapCHK{C819BC0C-8BE1-4CD6-BDFE-00D63D89975D}.dll
C:\Program Files\sembly~1
C:\Program Files\sembly~1\??sembly\
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Ultimate Cleaner
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\bass.exe
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\tn3
C:\WA6P
C:\WINDOWS\Casino.ico
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\system32\15242115641.dll
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\B1\chkq22011.exe
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\asc3550u.sys
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\dygliohx.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f06WtR
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\setup155.exe
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\win
C:\WINDOWS\system32\Y1
C:\WINDOWS\system32\Y2
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_ASC3550U
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NET_AGENT
——-\LEGACY_POOF
——-\LEGACY_VSPF
——-\LEGACY_VSPF_HK
——-\LEGACY_WINDOWS_OVERLAY_COMPONENTS
——-\Net Agent
——-\nm
((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))
2007-08-19 18:56 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-19 15:35 4,608 –a—— C:\WINDOWS\system32\dllcache\xrxflnch.exe
2007-08-19 15:35 27,648 –a—— C:\WINDOWS\system32\dllcache\xrxftplt.exe
2007-08-19 15:35 23,040 –a—— C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2007-08-19 15:35 17,408 –a—— C:\WINDOWS\system32\dllcache\xrxscnui.dll
2007-08-19 15:35 116,224 –a—— C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2007-08-19 15:34 99,865 –a—— C:\WINDOWS\system32\dllcache\xlog.exe
2007-08-19 15:34 8,192 –a—— C:\WINDOWS\system32\dllcache\wshirda.dll
2007-08-19 15:34 19,455 –a—— C:\WINDOWS\system32\dllcache\wvchntxx.sys
2007-08-19 15:34 16,970 –a—— C:\WINDOWS\system32\dllcache\xem336n5.sys
2007-08-19 15:34 12,063 –a—— C:\WINDOWS\system32\dllcache\wsiintxx.sys
2007-08-19 15:33 8,832 –a—— C:\WINDOWS\system32\dllcache\wmiacpi.sys
2007-08-19 15:33 34,890 –a—— C:\WINDOWS\system32\dllcache\wlandrv2.sys
2007-08-19 15:33 154,624 –a—— C:\WINDOWS\system32\dllcache\wlluc48.sys
2007-08-19 15:32 9,216 –a—— C:\WINDOWS\system32\dllcache\wamps51.dll
2007-08-19 15:32 87,040 –a—— C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2007-08-19 15:32 771,581 –a—— C:\WINDOWS\system32\dllcache\winacisa.sys
2007-08-19 15:32 76,800 –a—— C:\WINDOWS\system32\dllcache\wam51.dll
2007-08-19 15:32 701,386 –a—— C:\WINDOWS\system32\dllcache\wdhaalba.sys
2007-08-19 15:32 53,760 –a—— C:\WINDOWS\system32\dllcache\wiamsmud.dll
2007-08-19 15:32 53,248 –a—— C:\WINDOWS\system32\dllcache\wamreg51.dll
2007-08-19 15:32 41,600 –a—— C:\WINDOWS\system32\dllcache\weitekp9.dll
2007-08-19 15:32 35,871 –a—— C:\WINDOWS\system32\dllcache\wbfirdma.sys
2007-08-19 15:32 33,599 –a—— C:\WINDOWS\system32\dllcache\watv04nt.sys
2007-08-19 15:32 31,744 –a—— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2007-08-19 15:32 31,232 –a—— C:\WINDOWS\system32\dllcache\weitekp9.sys
2007-08-19 15:32 29,311 –a—— C:\WINDOWS\system32\dllcache\watv01nt.sys
2007-08-19 15:32 25,471 –a—— C:\WINDOWS\system32\dllcache\watv10nt.sys
2007-08-19 15:32 23,615 –a—— C:\WINDOWS\system32\dllcache\wch7xxnt.sys
2007-08-19 15:32 22,271 –a—— C:\WINDOWS\system32\dllcache\watv06nt.sys
2007-08-19 15:32 19,551 –a—— C:\WINDOWS\system32\dllcache\watv02nt.sys
2007-08-19 15:32 16,925 –a—— C:\WINDOWS\system32\dllcache\w940nd.sys
2007-08-19 15:32 13,568 –a—— C:\WINDOWS\system32\dllcache\wacompen.sys
2007-08-19 15:32 12,415 –a—— C:\WINDOWS\system32\dllcache\wadv01nt.sys
2007-08-19 15:32 12,127 –a—— C:\WINDOWS\system32\dllcache\wadv02nt.sys
2007-08-19 15:32 11,935 –a—— C:\WINDOWS\system32\dllcache\wadv11nt.sys
2007-08-19 15:32 11,871 –a—— C:\WINDOWS\system32\dllcache\wadv09nt.sys
2007-08-19 15:32 11,807 –a—— C:\WINDOWS\system32\dllcache\wadv07nt.sys
2007-08-19 15:32 11,775 –a—— C:\WINDOWS\system32\dllcache\wadv05nt.sys
2007-08-19 15:32 11,295 –a—— C:\WINDOWS\system32\dllcache\wadv08nt.sys
2007-08-19 15:31 86,073 –a—— C:\WINDOWS\system32\dllcache\voicesub.dll
2007-08-19 15:31 765,884 –a—— C:\WINDOWS\system32\dllcache\usrti.sys
2007-08-19 15:31 73,728 –a—— C:\WINDOWS\system32\dllcache\w3ext.dll
2007-08-19 15:31 687,999 –a—— C:\WINDOWS\system32\dllcache\usrwdxjs.sys
2007-08-19 15:31 64,605 –a—— C:\WINDOWS\system32\dllcache\vvoice.sys
2007-08-19 15:31 604,253 –a—— C:\WINDOWS\system32\dllcache\vmodem.sys
2007-08-19 15:31 5,632 –a—— C:\WINDOWS\system32\dllcache\w3svapi.dll
2007-08-19 15:31 48,256 –a—— C:\WINDOWS\system32\dllcache\w32.dll
2007-08-19 15:31 426,041 –a—— C:\WINDOWS\system32\dllcache\voicepad.dll
2007-08-19 15:31 4,608 –a—— C:\WINDOWS\system32\dllcache\w3ctrs51.dll
2007-08-19 15:31 397,502 –a—— C:\WINDOWS\system32\dllcache\vpctcom.sys
2007-08-19 15:31 363,520 –a—— C:\WINDOWS\system32\dllcache\w3svc.dll
2007-08-19 15:31 249,402 –a—— C:\WINDOWS\system32\dllcache\vinwm.sys
2007-08-19 15:31 24,576 –a—— C:\WINDOWS\system32\dllcache\viairda.sys
2007-08-19 15:31 19,528 –a—— C:\WINDOWS\system32\dllcache\w840nd.sys
2007-08-19 15:31 19,016 –a—— C:\WINDOWS\system32\dllcache\w926nd.sys
2007-08-19 15:31 11,325 –a—— C:\WINDOWS\system32\dllcache\vchnt5.dll
2007-08-19 15:30 94,720 –a—— C:\WINDOWS\system32\dllcache\umaxud32.dll
2007-08-19 15:30 794,654 –a—— C:\WINDOWS\system32\dllcache\usr1801.sys
2007-08-19 15:30 794,399 –a—— C:\WINDOWS\system32\dllcache\usr1806v.sys
2007-08-19 15:30 793,598 –a—— C:\WINDOWS\system32\dllcache\usr1806.sys
2007-08-19 15:30 78,464 –a—— C:\WINDOWS\system32\dllcache\usbvideo.sys
2007-08-19 15:30 76,288 –a—— C:\WINDOWS\system32\dllcache\uniime.dll
2007-08-19 15:30 7,556 –a—— C:\WINDOWS\system32\dllcache\usroslba.sys
2007-08-19 15:30 32,384 –a—— C:\WINDOWS\system32\dllcache\usb101et.sys
2007-08-19 15:30 28,160 –a—— C:\WINDOWS\system32\dllcache\umaxu40.dll
2007-08-19 15:30 26,624 –a—— C:\WINDOWS\system32\dllcache\umaxu22.dll
2007-08-19 15:30 25,600 –a—— C:\WINDOWS\system32\dllcache\usbser.sys
2007-08-19 15:30 224,802 –a—— C:\WINDOWS\system32\dllcache\usr1807a.sys
2007-08-19 15:30 17,024 –a—— C:\WINDOWS\system32\dllcache\usbohci.sys
2007-08-19 15:30 12,672 –a—— C:\WINDOWS\system32\dllcache\usb8023x.sys
2007-08-19 15:30 113,762 –a—— C:\WINDOWS\system32\dllcache\usrpda.sys
2007-08-19 15:29 69,632 –a—— C:\WINDOWS\system32\dllcache\umaxu12.dll
2007-08-19 15:29 525,568 –a—— C:\WINDOWS\system32\dllcache\tridxp.dll
2007-08-19 15:29 50,688 –a—— C:\WINDOWS\system32\dllcache\umaxscan.dll
2007-08-19 15:29 50,176 –a—— C:\WINDOWS\system32\dllcache\umaxp60.dll
2007-08-19 15:29 47,616 –a—— C:\WINDOWS\system32\dllcache\umaxcam.dll
2007-08-19 15:29 44,672 –a—— C:\WINDOWS\system32\dllcache\uagp35.sys
2007-08-19 15:29 22,912 –a—— C:\WINDOWS\system32\dllcache\umaxpcls.sys
2007-08-19 15:29 216,064 –a—— C:\WINDOWS\system32\dllcache\um34scan.dll
2007-08-19 15:29 211,968 –a—— C:\WINDOWS\system32\dllcache\um54scan.dll
2007-08-19 15:29 166,784 –a—— C:\WINDOWS\system32\dllcache\tridxpm.sys
2007-08-19 15:29 159,232 –a—— C:\WINDOWS\system32\dllcache\tridkbm.sys
2007-08-19 15:29 14,336 –a—— C:\WINDOWS\system32\dllcache\tsprof.exe
2007-08-19 15:29 11,520 –a—— C:\WINDOWS\system32\dllcache\twotrack.sys
2007-08-19 15:29 103,424 –a—— C:\WINDOWS\system32\dllcache\uihelper.dll
2007-08-19 15:28 82,432 –a—— C:\WINDOWS\system32\dllcache\tp4mon.exe
2007-08-19 15:28 455,168 –a—— C:\WINDOWS\system32\dllcache\tintsetp.exe
2007-08-19 15:28 440,576 –a—— C:\WINDOWS\system32\dllcache\tridkb.dll
2007-08-19 15:28 44,032 –a—— C:\WINDOWS\system32\dllcache\tintlphr.exe
2007-08-19 15:28 42,496 –a—— C:\WINDOWS\system32\dllcache\tp4res.dll
2007-08-19 15:28 34,375 –a—— C:\WINDOWS\system32\dllcache\tpro4.sys
2007-08-19 15:28 315,520 –a—— C:\WINDOWS\system32\dllcache\trid3d.dll
2007-08-19 15:28 31,744 –a—— C:\WINDOWS\system32\dllcache\tp4.dll
2007-08-19 15:28 31,232 –a—— C:\WINDOWS\system32\dllcache\tools.dll
2007-08-19 15:28 28,232 –a—— C:\WINDOWS\system32\dllcache\tos4mo.sys
2007-08-19 15:28 241,664 –a—— C:\WINDOWS\system32\dllcache\tosdvd02.sys
2007-08-19 15:28 230,912 –a—— C:\WINDOWS\system32\dllcache\tosdvd03.sys
2007-08-19 15:28 222,336 –a—— C:\WINDOWS\system32\dllcache\trid3dm.sys
2007-08-19 15:28 185,344 –a—— C:\WINDOWS\system32\dllcache\thawbrkr.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-19 19:07 ——— d——– C:\Program Files\Plaxo
2007-08-16 21:12 ——— d——– C:\Program Files\New Tier
2007-08-16 20:08 ——— d——– C:\DOCUME~1\BROOKD~1\APPLIC~1\New Tier
2007-08-16 11:08 ——— d——– C:\Program Files\Picasa2
2007-08-13 20:59 ——— d——– C:\Program Files\Logitech
2007-08-11 09:44 ——— d——– C:\Program Files\Citrix
2007-08-10 14:48 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-07 22:27 ——— d——– C:\DOCUME~1\BROOKD~1\APPLIC~1\AdobeUM
2007-07-29 17:27 ——— d——– C:\DOCUME~1\BROOKD~1\APPLIC~1\Move Networks
2007-06-26 08:13 851968 –a—— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 07:09 658944 –a—— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-25 23:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-25 23:08 1104896 –a—— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 06:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 06:31 282112 –a—— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-14 11:09 96256 –a—— C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 11:09 615424 –a—— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 11:09 55808 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 11:09 532480 –a—— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 11:09 474112 –a—— C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 11:09 449024 –a—— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 11:09 39424 –a—— C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 11:09 357888 –a—— C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 11:09 3058688 –a—— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 11:09 251392 –a—— C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 11:09 205312 –a—— C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 11:09 16384 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 11:09 151040 –a—— C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 11:09 1494528 –a—— C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 11:09 146432 –a—— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 11:09 1054208 –a—— C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 11:09 1023488 –a—— C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 07:07 18432 –a—— C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 03:23 1033216 –a—— C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 03:23 1033216 –a—— C:\WINDOWS\explorer.exe
2005-10-21 14:06 13492969 –a—— C:\Program Files\iTunes.zip
2005-10-21 13:20 2991946 –a—— C:\Program Files\Windows Media Player.zip
2005-06-12 18:55 128 –a—— C:\Program Files\wMjLdXwBoD!ulNm6ti3oRWdOHPqXdNRxtPD1eH58yPfSS3FKbUSwA_JMx2wNbvwdmXME5N0V150YZ106WUOpKA=
.ram
2005-06-12 18:54 128 –a—— C:\Program Files\wMjLdXwBoD!ulNm6ti3oRWdOHPqXdNRxtPD1eH58yPfLbNzBCnJ!xCBhmeDk1U4l6qgQkm9!7kCr!9ukanrPcw==.ram
2005-06-12 18:53 120 –a—— C:\Program Files\UPrSy!2waSkKlx_tHz2gg2x4Gydd7RjyJ!E7BUbakWHWbk5sZbSN!JJQ7CiiubD78!7xPYMjacpA_QQCaRHdkg==.ram
2005-06-04 15:09 8219278 –a—— C:\Program Files\RhapsodyReal.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 15:48]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 06:04]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-06 23:01]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-05 23:05]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-06-15 16:15]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
"PlaxoUpdate"="C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe" [2006-11-16 13:42]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-01 12:34]
"SpeedswitchXP"="C:\Program Files\SpeedswitchXP\SpeedswitchXP.exe" [2006-07-14 14:56]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-14 23:19:50]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-05-25 21:03:38]
HotSync Manager.lnk - C:\Program Files\Sony Handheld\HOTSYNC.EXE [2005-06-20 11:25:14]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-10-22 14:23:53]
R2 BASFND;BASFND;\??\C:\WINDOWS\system32\Drivers\BASFND.sys
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys
S3 SbcpHid;SbcpHid;\??\C:\WINDOWS\system32\Drivers\SbcpHid.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\LaunchU3.exe -a
Contents of the 'Scheduled Tasks' folder
2007-08-07 15:43:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-20 02:01:00 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDetect.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-19 19:07:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-19 19:09:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-19 19:09
— E O F —