HI! =) i'm so sorry this reply took so long. Thanks for helping me! really appreciate it! =) and yes, i definitely still need your help.
I've tried my best to follow the instructions you gave me but i encountered some problems along the way.
Firstly, when disabling spybot teatimer, i couldnt locate the box u wanted me to check. Instead, i disabled Spybot by clicking on tools, den clicking Resident and checking the box that disables teatimer. i hope i dint make things complicated for you. If so, please do tell me.
When running Hijack This, i couldnt locate the last two files you wanted me to check, namely:
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
So here's my new HijackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:16 PM, on 9/17/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Policies\Explorer\Run: [w] %SystemRoot%\WinRaR.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O20 - AppInit_DLLs: wlhpri.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
–
End of file - 6349 bytes
And As for ComboFix, Here's the log:
ComboFix 07-09-17.2 - "Owner" 2007-09-17 23:32:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.44 [GMT 8:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\_desktop.ini
C:\privilege.dat
C:\WINDOWS\richdll.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\lyloader.exe
C:\WINDOWS\system32\lymangr.dll
C:\WINDOWS\system32\msdeg32.dll
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\SHQMANGR.DLL
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_NPF
——-\NPF
((((((((((((((((((((((((( Files Created from 2007-08-17 to 2007-09-17 )))))))))))))))))))))))))))))))
.
2007-09-17 23:31 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-12 22:37 16,608 –a—— C:\WINDOWS\system32\LYLOADMR.EXE
2007-09-09 22:34 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-09 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-09-09 20:01 d——– C:\Program Files\Common Files\Panda Software
2007-09-09 19:24 d——– C:\DOCUME~1\Owner\.housecall6.6
2007-09-09 18:18 d——– C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-09-09 15:33 d——– C:\Program Files\Lavasoft
2007-09-09 15:33 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-09 15:31 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-09 14:51 d——– C:\Program Files\Trend Micro
2007-09-09 13:54 d—s—- C:\DOCUME~1\Owner\UserData
2007-09-09 13:46 24,576 ——— C:\WINDOWS\system32\ftmgpd.dll
2007-09-08 23:17 27,648 –a—— C:\WINDOWS\system32\SHQ.DLL
2007-09-08 23:17 20 –a—— C:\WINDOWS\system32\mhsha1.dat
2007-09-08 22:39 182,880 –a–c— C:\WINDOWS\system32\dllcache\iuengine.dll
2007-09-08 22:39 182,880 –a—— C:\WINDOWS\system32\iuengine.dll
2007-09-08 22:19 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-09-08 22:16 d——– C:\Program Files\Microsoft ActiveSync
2007-09-08 22:16 d——– C:\Program Files\Common Files\L&H
2007-09-08 22:14 d——– C:\WINDOWS\SHELLNEW
2007-09-08 22:13 d——– C:\Program Files\Microsoft.NET
2007-09-08 22:11 dr-h—– C:\MSOCache
2007-09-08 22:08 51,056 -ra—— C:\WINDOWS\system32\drivers\hpzid412.sys
2007-09-08 22:08 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-08 22:08 16,496 -ra—— C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-09-08 22:07 28,160 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-09-08 22:07 28,160 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-08 22:07 24,960 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-08 22:07 24,960 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-08 22:07 21,488 -ra—— C:\WINDOWS\system32\drivers\HPZius12.sys
2007-09-08 22:07 14,208 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-08 22:07 14,208 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-08 22:03 626,960 -ra—— C:\WINDOWS\system32\hpvaut32.dll
2007-09-08 22:03 487,424 -ra—— C:\WINDOWS\system32\hpvcp70.dll
2007-09-08 22:03 44,544 -ra—— C:\WINDOWS\system32\MSXML4a.dll
2007-09-08 22:03 344,064 -ra—— C:\WINDOWS\system32\hpvcr70.dll
2007-09-08 22:02 d——– C:\Program Files\Common Files\Hewlett-Packard
2007-09-08 21:59 43,488 –a—— C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-08 21:59 d——– C:\Program Files\Common Files\HP
2007-09-08 21:55 34,383 ——— C:\WINDOWS\hpomdl03.dat
2007-09-08 21:55 28,886 –a—— C:\WINDOWS\hpoins03.dat
2007-09-08 21:55 d——– C:\Program Files\HP
2007-09-08 21:49 23,552 –a—— C:\WINDOWS\system32\oubttg.dll
2007-09-08 21:48 24,064 –a—— C:\WINDOWS\system32\gbekry.dll
2007-09-08 21:48 19,968 –a—— C:\WINDOWS\system32\mohekj.dll
2007-09-08 09:49 58 –a—— C:\WINDOWS\system32\wlgini.dll
2007-09-08 09:49 23,552 –a—— C:\WINDOWS\system32\DbgHlp32.dll
2007-09-08 09:48 59 –a—— C:\WINDOWS\system32\kawdacs.dll
2007-09-08 09:48 58 –a—— C:\WINDOWS\system32\kaqhacs.dll
2007-09-08 09:48 58 –a—— C:\WINDOWS\system32\kapjacs.dll
2007-09-08 09:48 56 –a—— C:\WINDOWS\system32\rsjzafg.dll
2007-09-08 09:48 55 –a—— C:\WINDOWS\system32\kvdxacf.dll
2007-09-08 09:48 51 –a—— C:\WINDOWS\system32\zxiini.dll
2007-09-08 09:48 50 –a—— C:\WINDOWS\system32\raqjani.dll
2007-09-08 09:48 32,768 ——— C:\WINDOWS\dbhelp.dll
2007-09-08 09:47 52 –a—— C:\WINDOWS\system32\mygini.dll
2007-09-03 08:39 249 –a—— C:\WINDOWS\system\hpsysdrv.dat
2007-09-03 08:38 d——– C:\WINDOWS\I386
2007-09-03 08:33 dr——- C:\DOCUME~1\ALLUSE~1\Documents
2007-09-02 17:59 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2007-09-02 17:57 204,800 –a—— C:\WINDOWS\system32\IVIresizeW7.dll
2007-09-02 17:57 200,704 –a—— C:\WINDOWS\system32\IVIresizeA6.dll
2007-09-02 17:57 20,480 –a—— C:\WINDOWS\system32\IVIresize.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeP6.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeM6.dll
2007-09-02 17:57 188,416 –a—— C:\WINDOWS\system32\IVIresizePX.dll
2007-09-02 17:57 10,368 ——— C:\WINDOWS\system32\drivers\pfc.sys
2007-09-02 17:57 d——– C:\WINDOWS\uninstall
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\WINDOWS
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Symantec
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\SampleView
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Real
2007-09-02 17:57 d——– C:\863d765bceb76777372b95ff1d0a40
2007-09-02 17:57 d——– C:\54f4ff25124b3b9e53a7416b03
2007-09-02 17:56 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-09-02 17:56 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-09-02 17:56 d——– C:\Program Files\InterVideo
2007-09-02 17:54 51,072 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-09-02 17:54 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-09-02 17:54 d——– C:\DOCUME~1\DEFAUL~1\WINDOWS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-09 21:34 ——— d——– C:\Program Files\QuickTime
2007-09-09 21:34 ——— d——– C:\Program Files\Presario PC Help
2007-09-09 21:34 ——— d——– C:\Program Files\PC-Doctor for Windows
2007-09-09 21:33 ——— d——– C:\Program Files\Norton AntiVirus
2007-09-09 21:33 ——— d——– C:\Program Files\Microsoft Works
2007-09-09 21:32 ——— d——– C:\Program Files\iTunes
2007-09-09 21:28 ——— d——– C:\Program Files\Easy Internet signup
2007-09-09 20:02 ——— d——– C:\Program Files\Common Files\InstallShield
2007-09-02 17:59 3674 -rahs—- C:\WINDOWS\system32\drivers\HP_P9902CV-AB4 SR1120CF SE610_YC_Pres_QTHT424_E43SEhwRET1_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J80_7Intel_8Pentium 4_92.8_111063044_N10EC8139_P_Z_K_A808624C5.MRK
2007-09-02 17:56 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-07 13:58 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-08-17 06:57]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-08-17 00:24]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-01 20:57]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-11 00:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 02:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-01 22:04]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-17 02:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 23:50]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 07:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-13 02:13]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 03:35 C:\WINDOWS\ALCXMNTR.EXE]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2003-08-16 09:54]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-01 22:26:37]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 01:20:40]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoStartMenuSubFolders"=1 (0x1)
"NoFavoritesMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8562452F-FA36-BA4F-892A-FF5FBBAC5318}"= C:\WINDOWS\System32\myhpri.dll [2004-08-04 09:47 20521]
"{2C87A354-ABC3-DEDE-FF33-3213FD7447C2}"= C:\WINDOWS\System32\kvdxbma.dll [2004-08-04 09:48 17494]
"{28907901-1416-3389-9981-372178569982}"= C:\WINDOWS\System32\kawdbzy.dll [2004-08-04 09:48 17502]
"{9A65498A-7653-9801-1647-987114AB7F49}"= C:\WINDOWS\System32\zxipri.dll [2004-08-04 09:48 20520]
"{14783410-4F90-34A0-7820-3230ACD05F41}"= C:\WINDOWS\System32\raqjapi.dll [2004-08-04 09:48 20556]
"{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}"= C:\WINDOWS\System32\rsjzapm.dll [2004-08-04 09:48 19544]
"{1A321487-4977-D98A-C8D5-6488257545A1}"= C:\WINDOWS\System32\kapjazy.dll [2004-08-04 09:48 18012]
"{37D81718-1314-5200-2597-587901018073}"= C:\WINDOWS\System32\kaqhczy.dll [2004-08-04 09:48 16988]
"{5182C1EB-375C-573D-1F5E-234552345215}"= C:\WINDOWS\System32\wlhpri.dll [2004-08-04 09:49 20527]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=raqjapi.dll
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 14:13:19 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189260524.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-15 02:31:28 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189262568.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-15 02:27:55 C:\WINDOWS\Tasks\WebReg 20070915102754.job"
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-17 23:36:34
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-17 23:38:28 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-17 23:38
.
— E O F —
i used virustotal to scan my computer and here are the results:
For c:\windows\system32\wlhpri.dll
File wlhpri.dll_ received on 09.17.2007 17:45:36 (CET)
Result: 26/32 (81.25%)
Antivirus Version Last Update Result
AhnLab-V3 2007.9.14.0 2007.09.14 -
AntiVir 7.6.0.10 2007.09.17 TR/Spy.Delf.aao.4
Authentium 4.93.8 2007.09.16 W32/Trojan.BYIC
Avast 4.7.1043.0 2007.09.16 Win32:Delf-FVM
AVG 7.5.0.485 2007.09.17 PSW.Generic5.JGE
BitDefender 7.2 2007.09.17 BehavesLike:Trojan.WUDisable
CAT-QuickHeal 9.00 2007.09.17 TrojanSpy.Delf.aao
ClamAV 0.91.2 2007.09.17 Trojan.Spy-12343
DrWeb 4.33 2007.09.17 Trojan.PWS.Gamania.3932
eSafe 7.0.15.0 2007.09.17 Win32.Delf.aao
eTrust-Vet 31.1.5141 2007.09.17 Win32/Storark.AO
Ewido 4.0 2007.09.17 Logger.Delf.aao
FileAdvisor 1 2007.09.17 -
Fortinet 3.11.0.0 2007.09.17 Gampass.A
F-Prot 4.3.2.48 2007.09.16 W32/Trojan.BYIC
F-Secure 6.70.13030.0 2007.09.17 Trojan-Spy.Win32.Delf.aao
Ikarus T3.1.1.12 2007.09.17 Trojan-Spy.Win32.Delf.uv
Kaspersky 4.0.2.24 2007.09.17 Trojan-Spy.Win32.Delf.aao
McAfee 5120 2007.09.14 -
Microsoft 1.2803 2007.09.17 Trojan:Win32/Delf.AT!dll
NOD32v2 2534 2007.09.17 -
Norman 5.80.02 2007.09.17 W32/Malware.AJMA
Panda 9.0.0.4 2007.09.17 Trj/Lineage.FCW
Prevx1 V2 2007.09.17 -
Rising 19.41.02.00 2007.09.17 Trojan.PSW.Win32.OnlineGames.yat
Sophos 4.21.0 2007.09.17 Mal/Delagen-A
Sunbelt 2.2.907.0 2007.09.15 Trojan.WUDisable
Symantec 10 2007.09.17 Infostealer.Gampass
TheHacker 6.2.5.061 2007.09.17 Trojan/Spy.Delf.aao
VBA32 3.12.2.4 2007.09.17 Trojan-Spy.Win32.Delf.aao
VirusBuster 4.3.26:9 2007.09.17 -
Webwasher-Gateway 6.0.1 2007.09.17 Trojan.Spy.Delf.aao.4
Additional information
File size: 20527 bytes
MD5: 449ffc4fef1e9ad73c14624fa8131e66
SHA1: 41268c23d6006211ef5e72e1e2965148cc37b044
For c:\windows\WinRaR.exe
it said, "0 bytes size received / Se ha recibido un archivo vacio"
i hope the information i've provided is helpful… Please help me!!!
