This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Need Help With Slow/sluggish Laptop.

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Please help…I've been trying to clean up my son's laptop, which would not boot up at all. I've got it running now and have run AdAware and Spybot, which has improved its performance greatly. Can you please look over the below listed HijackThis log and let me know if there is any thing else I need to clean it up.

Thank you in advance for your reply.

Regards,

Jeff Winn



Logfile of HijackThis v1.99.1
Scan saved at 4:39:59 PM, on 9/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\tmrsrv32.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\clcl16.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: (no name) - {3995dcc9-b590-4d4b-913f-36e2e67d586b} - C:\WINDOWS\system32\ACChlp.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [clcl16] C:\WINDOWS\system32\clcl16.exe
O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\qonomk.dll",forkonce
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\ACChlp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\ACChlp.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - AppInit_DLLs: FORCEDOS.dll
O20 - Winlogon Notify: ACChlp - C:\WINDOWS\SYSTEM32\ACChlp.dll
O20 - Winlogon Notify: DC - C:\WINDOWS\System32\DC.tmp (file missing)
O20 - Winlogon Notify: instcat - instcat.dll (file missing)
O20 - Winlogon Notify: pØà - pØà (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: È08 - È08 (file missing)
O20 - Winlogon Notify: Ø€ - Ø€ (file missing)
O21 - SSODL: thmuggfn - {009B503E-AA31-FA94-685C-4EDC49E3AAF1} - C:\WINDOWS\system32\sjlfxo.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Hi winnj,

First we need to upload some files for checking:

Open http://virusscan.jotti.org/
Copy/paste this file and path into the white box at the top:

C:\WINDOWS\system32\tmrsrv32.exe

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the results in your next response.

Note: If Jotti is busy, you can use VirusTotal instead.

Then please repeat this process for the following files:

C:\WINDOWS\system32\clcl16.exe
C:\WINDOWS\system32\ACChlp.dll
C:\WINDOWS\system32\sjlfxo.dll


Next press Start->Run, copy/paste the following command into the box and press OK:

cmd /c dir /a /s C:\FORCEDOS.dll >> "%userprofile%\desktop\look.txt"

A black box will appear and a file called look.txt should appear on your Desktop, please don't open it yet
Wait for the black box to disappear, then press Start->Run again and copy/paste the following command into the box and press OK:

cmd /c dir /a /s C:\instcat.dll >> "%userprofile%\desktop\look.txt"

Again wait for the black box to disappear. Please post the contents of look.txt in your next response.

Now download ComboFix to your desktop
  • Double click combofix.exe and follow the prompts.
  • Note: Do not click ComboFix's window while it's running - it may cause it to stall!
  • When finished, it shall produce a log for you, please post it in your next response.
Once complete, please post the Jotti results, the look.txt output, the ComboFix report and a new HijackThis log.
The logs may not fit into one post so please check that they are complete and use multiple posts if necessary.
Greetings,

Thanks so much for your reply.

Below are the logs you requested:


tmrsrv32.exe
Scan taken on 18 Sep 2007 21:28:49 (GMT)
A-Squared Found Trojan-Downloader.Win32.VB.avl
AntiVir Found TR/Crypt.FKM.Gen
ArcaVir Found Trojan.Downloader.Vb.Avl
Avast Found Win32:VB-EDC
AVG Antivirus Found Obfustat.HVJ
BitDefender Found Trojan.Downloader.VB.AIV
ClamAV Found Trojan.Downloader-11782
CPsecure Found Troj.Downloader.W32.VB.avl
Dr.Web Found BackDoor.Generic.1598
F-Prot Antivirus Found security risk or a "backdoor" program
F-Secure Anti-Virus Found Trojan-Downloader.Win32.VB.avl
Fortinet Found W32/VB.AVL!tr.dldr
Kaspersky Anti-Virus Found Trojan-Downloader.Win32.VB.avl
NOD32 Found Win32/TrojanDownloader.VB.AVL
Norman Virus Control Found W32/DLoader.CQDH
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found Troj/VB-DRP
VirusBuster Found Trojan.DL.VB.EWW
VBA32 Found Trojan-Downloader.Win32.VB.avl


clcl16.exe
Scan taken on 18 Sep 2007 21:38:10 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing


ACChlp.dll
Scan taken on 18 Sep 2007 21:44:04 (GMT)
A-Squared Found nothing
AntiVir Found TR/Agent.37420
ArcaVir Found nothing
Avast Found Win32:Virtumonde-DC
AVG Antivirus Found Downloader.Generic5.KEY
BitDefender Found Trojan.Downloader.ConHook.AI
ClamAV Found nothing
CPsecure Found Troj.Downloader.W32.Aphex.060
Dr.Web Found Trojan.Virtumod F-Prot
Antivirus Found nothing
F-Secure Anti-Virus Found not-a-virus:AdWare.Win32.Virtumonde.ke (4, 1, 400)
Fortinet Found nothing
Kaspersky Anti-Virus Found not-a-virus:AdWare.Win32.Virtumonde.ke
NOD32 Found Win32/Adware.Virtumonde application
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing


sjlfxo.dll
The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file


Volume in drive C has no label.
Volume Serial Number is 009B-503D

Directory of C:\WINDOWS\SYSTEM32

09/13/2007 09:13 PM 4,096 FORCEDOS.dll
1 File(s) 4,096 bytes

Total Files Listed:
1 File(s) 4,096 bytes
0 Dir(s) 25,136,406,528 bytes free
Volume in drive C has no label.
Volume Serial Number is 009B-503D



ComboFix 07-09-18.4 - "Jake" 2007-09-18 18:53:17.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.196 [GMT -5:00]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\3456346345643.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp10A.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp10C.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp112.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp113.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp114.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp115.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp116.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp117.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp118.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp11A.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp11C.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp133.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp152.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp156.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp157.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp15C.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp1A6.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp1A7.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp1A9.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp1DC.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp1DD.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp201.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp20C.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp20D.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp20E.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp730.tmp.exe
C:\DOCUME~1\Jake\APPLIC~1\tmp77B.tmp.exe
C:\DOCUME~1\Jake\Desktop\Find Spyware Remover.lnk
C:\DOCUME~1\Jake\Desktop\Free Online Dating.lnk
C:\DOCUME~1\Jake\Desktop\Go to Casino.lnk
C:\DOCUME~1\Jake\LOCALS~1\APPLIC~1.\n.ini
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Documents and Settings\Jake.\svchost.exe
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Ultimate Cleaner
C:\WINDOWS\180ax.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\awtspo.dll
C:\WINDOWS\awwttt.dll
C:\WINDOWS\bi.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bywxuv.dll
C:\WINDOWS\Casino.ico
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\csrss.exe
C:\WINDOWS\ddaxuv.dll
C:\WINDOWS\fcbbxw.dll
C:\WINDOWS\fcbyab.dll
C:\WINDOWS\filoqr.ini
C:\WINDOWS\filoqr.ini2
C:\WINDOWS\filoqr.tmp
C:\WINDOWS\flt.dll
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\kmlnoq.ini
C:\WINDOWS\kmonoq.ini
C:\WINDOWS\ljgfcb.dll
C:\WINDOWS\mgrs.exe
C:\WINDOWS\mmnpoq.ini
C:\WINDOWS\mssvr.exe
C:\WINDOWS\pbar.dll
C:\WINDOWS\qonlmk.dll
C:\WINDOWS\qonomk.dll
C:\WINDOWS\qopnmm.dll
C:\WINDOWS\rqolif.dll
C:\WINDOWS\rrsttv.ini
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\susp.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\sysrlb32.exe
C:\WINDOWS\system32\ACChlp.dll
C:\WINDOWS\system32\byxvt.dll
C:\WINDOWS\system32\clcl7.exe
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\SYSTEM32\fhiii.bak1
C:\WINDOWS\SYSTEM32\fhiii.ini
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\SYSTEM32\iiihf.dll
C:\WINDOWS\system32\iiihf.dll
C:\WINDOWS\system32\KB_963491.exe
C:\WINDOWS\system32\KB21542167.exe
C:\WINDOWS\system32\KB34040802.exe
C:\WINDOWS\system32\KB42687917.exe
C:\WINDOWS\system32\KB52358626.exe
C:\WINDOWS\system32\KB52383366.exe
C:\WINDOWS\system32\KB55963079.exe
C:\WINDOWS\system32\KB58620628.exe
C:\WINDOWS\system32\KB60114410.exe
C:\WINDOWS\system32\KB89127940.exe
C:\WINDOWS\system32\KB91010333.exe
C:\WINDOWS\system32\kernels88.exe
C:\WINDOWS\system32\lfd32.ini
C:\WINDOWS\system32\maxd641.exe
C:\WINDOWS\system32\msdn_lib.dll
C:\WINDOWS\system32\ntio256.sys
C:\WINDOWS\system32\pmnonkl.dll
C:\WINDOWS\system32\protector.exe
C:\WINDOWS\system32\scchk32.exe
C:\WINDOWS\system32\sl.bin
C:\WINDOWS\system32\svehost.exe
C:\WINDOWS\system32\tmp113.tmp.dll
C:\WINDOWS\system32\tmp117.tmp.dll
C:\WINDOWS\system32\tmp118.tmp.dll
C:\WINDOWS\system32\tmp20C.tmp.dll
C:\WINDOWS\system32\vista.dll
C:\WINDOWS\system32\vista.log
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\system32\windbg48.sys
C:\WINDOWS\system32\winload.dll
C:\WINDOWS\system32\winrtp32.dll
C:\WINDOWS\system32\wmvds32.dll
C:\WINDOWS\temp\salm.exe
C:\WINDOWS\tttwwa.ini
C:\WINDOWS\voiceip.dll
C:\WINDOWS\vttsrr.dll
C:\WINDOWS\wml.exe
C:\wsusupd.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\LEGACY_RETK48
——-\LEGACY_RUNTIME
——-\LEGACY_RUNTIME2
——-\LEGACY_SMTPDRV


((((((((((((((((((((((((( Files Created from 2007-08-19 to 2007-09-19 )))))))))))))))))))))))))))))))
.

2007-09-18 18:57 15,360 –a—— C:\WINDOWS\SYSTEM32\drvbutr.dll
2007-09-18 18:57 103,936 –a—— C:\WINDOWS\SYSTEM32\drvbut.dll
2007-09-18 18:57 d——– C:\Program Files\tyledqve
2007-09-18 17:08 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-18 16:13 10,240 –a—— C:\Program Files\hlpsrv.exe
2007-09-15 13:44 33,792 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2007-09-15 13:27 d——– C:\WINDOWS\SYSTEM32\LogFiles
2007-09-14 23:34 153 –a—— C:\WINDOWS\SYSTEM32\delFSF.bat
2007-09-13 21:14 178,176 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\Retk48.sys
2007-09-13 21:13 4,096 –a—— C:\WINDOWS\SYSTEM32\FORCEDOS.dll
2007-09-13 21:13 178,176 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\symavc32.sys
2007-09-13 21:13 15,360 –a—— C:\WINDOWS\2020search.exe
2007-09-13 06:27 d——– C:\DOCUME~1\Jake\APPLIC~1\MSN6
2007-09-13 06:27 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-15 13:23 ——— d——– C:\Program Files\Common Files\AOL
2007-09-15 13:23 ——— d——– C:\DOCUME~1\Jake\APPLIC~1\Aim
2007-09-15 10:55 ——— d——– C:\Program Files\WinMX
2007-09-15 10:46 ——— d——– C:\Program Files\FamilyFeudHollywood_at
2007-09-15 10:43 ——— d——– C:\Program Files\Ball7_at
2007-09-15 10:41 ——— d——– C:\Program Files\Ares
2007-09-15 10:27 ——— d——– C:\Program Files\LimeWire
2007-09-13 21:12 ——— d——– C:\DOCUME~1\Jake\APPLIC~1\WeatherBug
2007-06-26 14:13 99072 –a—— C:\qchrqilr1.exe
2007-06-26 14:13 94464 –a—— C:\qchrqilr3.exe
2007-06-26 14:13 100096 –a—— C:\qchrqilr2.exe
2007-05-01 10:35 146432 –a—— C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"AGRSMMSG"="AGRSMMSG.exe" [2003-11-19 15:41 C:\WINDOWS\AGRSMMSG.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 01:04]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 11:43]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-27 23:22]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-02 21:12]
"clcl16"="C:\WINDOWS\system32\clcl16.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ares"="C:\Program Files\Ares\Ares.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]
Utility Tray.lnk - C:\WINDOWS\SYSTEM32\sistray.exe [2004-07-14 11:47:50]

C:\DOCUME~1\Jake\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"thmuggfn"= {009B503E-AA31-FA94-685C-4EDC49E3AAF1} - C:\WINDOWS\system32\sjlfxo.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DC]
C:\WINDOWS\System32\DC.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pØà]
pØà

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\È08]
È08

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Ø€]
Ø€

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=FORCEDOS.dll


.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-18 19:09:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************
.
Completion time: 2007-09-18 19:11:50 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-18 19:11
.
— E O F —



Logfile of HijackThis v1.99.1
Scan saved at 7:13:16 PM, on 9/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [clcl16] C:\WINDOWS\system32\clcl16.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - AppInit_DLLs: FORCEDOS.dll
O20 - Winlogon Notify: DC - C:\WINDOWS\System32\DC.tmp (file missing)
O20 - Winlogon Notify: pØà - pØà (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: È08 - È08 (file missing)
O20 - Winlogon Notify: Ø€ - Ø€ (file missing)
O21 - SSODL: thmuggfn - {009B503E-AA31-FA94-685C-4EDC49E3AAF1} - C:\WINDOWS\system32\sjlfxo.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe


Again, thank you for your help.

Regards,

Jeff Winn
Hi winnj,

Your machine is heavily infected, and one or more of the files found has backdoor capabilities - here is my standard warning for victims of this type of malware:

Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.



We will continue with ComboFix:
  • Check that combofix.exe is on your Desktop
  • Then open Notepad: press Start->Run, type notepad and click OK
  • Copy/paste the contents of the below code box into Notepad:
    Collect::[32]
    C:\WINDOWS\system32\tmrsrv32.exe
    C:\WINDOWS\system32\clcl16.exe
    C:\WINDOWS\SYSTEM32\forcedos.dll
    C:\WINDOWS\SYSTEM32\DRIVERS\Retk48.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\symavc32.sys
    C:\WINDOWS\2020search.exe
    C:\WINDOWS\system32\sjlfxo.dll
    
    File::
    C:\WINDOWS\SYSTEM32\drvbutr.dll
    C:\WINDOWS\SYSTEM32\drvbut.dll
    C:\Program Files\hlpsrv.exe
    C:\WINDOWS\System32\DC.tmp
    C:\WINDOWS\SYSTEM32\delFSF.bat
    C:\qchrqilr1.exe
    C:\qchrqilr3.exe
    C:\qchrqilr2.exe
    C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
    
    Folder::
    C:\Program Files\tyledqve
  • Save this to your Desktop as CFScript.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, ComboFix will ask you to upload malware files for further analysis, when your browser opens, copy and paste the file and path which appears on the screen and press Send File
  • ComboFix will also produce a log, please copy and paste the contents of the log in your next reply.
Note: Do not click ComboFix's window while it's running - it may cause it to stall!

Now open HijackThis, select Open the Misc Tools section
Press the Open Uninstall Manager… button, then press Save list…
Save the Uninstall log to your Desktop and include a copy in your next response.
Now press Back and Scan and then Save log to create and save a new HijackThis log.

Once complete, please post the ComboFix report, the uninstall list and a new HijackThis log.
Hello again,

Below are the requested logs and the malware file was submitted.



ComboFix 07-09-18.4 - "Jake" 2007-09-18 21:44:03.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.214 [GMT -5:00]
* Created a new restore point

FILE::
C:\WINDOWS\SYSTEM32\drvbutr.dll
C:\WINDOWS\SYSTEM32\drvbut.dll
C:\Program Files\hlpsrv.exe
C:\WINDOWS\System32\DC.tmp
C:\WINDOWS\SYSTEM32\delFSF.bat
C:\qchrqilr1.exe
C:\qchrqilr3.exe
C:\qchrqilr2.exe
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\hlpsrv.exe
C:\Program Files\tyledqve
C:\Program Files\tyledqve\padgbezy.dll
C:\qchrqilr1.exe
C:\qchrqilr2.exe
C:\qchrqilr3.exe
C:\WINDOWS\2020search.exe
C:\WINDOWS\SYSTEM32\delFSF.bat
C:\WINDOWS\SYSTEM32\DRIVERS\Retk48.sys
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\SYSTEM32\DRIVERS\symavc32.sys
C:\WINDOWS\SYSTEM32\drvbut.dll
C:\WINDOWS\SYSTEM32\drvbutr.dll
C:\WINDOWS\SYSTEM32\forcedos.dll

.
((((((((((((((((((((((((( Files Created from 2007-08-19 to 2007-09-19 )))))))))))))))))))))))))))))))
.

2007-09-18 17:08 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-15 13:44 33,792 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2007-09-15 13:27 d——– C:\WINDOWS\SYSTEM32\LogFiles
2007-09-13 06:27 d——– C:\DOCUME~1\Jake\APPLIC~1\MSN6
2007-09-13 06:27 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-15 13:23 ——— d——– C:\Program Files\Common Files\AOL
2007-09-15 13:23 ——— d——– C:\DOCUME~1\Jake\APPLIC~1\Aim
2007-09-15 10:55 ——— d——– C:\Program Files\WinMX
2007-09-15 10:46 ——— d——– C:\Program Files\FamilyFeudHollywood_at
2007-09-15 10:43 ——— d——– C:\Program Files\Ball7_at
2007-09-15 10:41 ——— d——– C:\Program Files\Ares
2007-09-15 10:27 ——— d——– C:\Program Files\LimeWire
2007-09-13 21:12 ——— d——– C:\DOCUME~1\Jake\APPLIC~1\WeatherBug
.

((((((((((((((((((((((((((((( snapshot_2007-09-18_191047.34 )))))))))))))))))))))))))))))))))))))))))
.
—-a-w 14,048 2007-03-06 01:22:36 C:\WINDOWS\$hf_mig$\KB937143-IE7\spmsg.dll
—-a-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\$hf_mig$\KB937143-IE7\spuninst.exe
—-a-w 124,928 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\advpack.dll
—-a-w 132,608 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\extmgr.dll
—-a-w 63,488 2007-06-27 09:16:27 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ie4uinit.exe
—-a-w 153,088 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieakeng.dll
—-a-w 230,400 2007-06-27 14:39:43 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieaksie.dll
—-a-w 161,792 2007-06-27 07:07:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieakui.dll
—-a-w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieapfltr.dat
—-a-w 383,488 2007-06-27 14:39:43 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieapfltr.dll
—-a-w 384,512 2007-06-27 14:39:44 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iedkcs32.dll
—-a-w 6,059,008 2007-06-27 14:39:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieframe.dll
—-a-w 44,544 2007-06-27 14:39:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iernonce.dll
—-a-w 267,776 2007-06-27 14:39:52 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iertutil.dll
—-a-w 13,824 2007-06-27 09:16:27 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieudinit.exe
—-a-w 625,152 2007-06-27 09:16:52 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
—-a-w 27,648 2007-06-27 14:39:54 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\jsproxy.dll
—-a-w 459,264 2007-06-27 14:39:55 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msfeeds.dll
—-a-w 52,224 2007-06-27 14:39:55 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msfeedsbs.dll
—-a-w 3,584,000 2007-07-18 21:09:49 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mshtml.dll
—-a-w 477,696 2007-06-27 14:40:00 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mshtmled.dll
—-a-w 193,024 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msrating.dll
—-a-w 671,232 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mstime.dll
—-a-w 102,400 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\occache.dll
—-a-w 105,984 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\url.dll
—-a-w 1,154,048 2007-06-27 14:40:02 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\urlmon.dll
—-a-w 232,960 2007-06-27 14:40:02 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\webcheck.dll
—-a-w 824,320 2007-06-27 14:40:03 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
—-a-w 22,752 2007-03-06 01:22:34 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\spcustom.dll
—-a-w 716,000 2007-03-06 01:22:59 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\update.exe
—-a-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\updspapi.dll
—-a-w 14,048 2007-03-06 01:22:36 C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
—-a-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
—-a-w 765,952 2007-07-12 23:28:55 C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
—-a-w 22,752 2007-03-06 01:22:34 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
—-a-w 716,000 2007-03-06 01:22:59 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
—-a-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
-c—-w 123,904 2006-11-07 08:26:24 C:\WINDOWS\ie7updates\KB937143-IE7\advpack.dll
-c—-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\extmgr.dll
-c—-w 54,784 2006-11-07 08:26:28 C:\WINDOWS\ie7updates\KB937143-IE7\ie4uinit.exe
-c—-w 152,064 2006-11-07 08:26:56 C:\WINDOWS\ie7updates\KB937143-IE7\ieakeng.dll
-c—-w 229,376 2006-11-07 08:27:02 C:\WINDOWS\ie7updates\KB937143-IE7\ieaksie.dll
-c—-w 161,792 2006-11-07 08:25:14 C:\WINDOWS\ie7updates\KB937143-IE7\ieakui.dll
-c—-w 2,451,824 2006-09-06 04:01:26 C:\WINDOWS\ie7updates\KB937143-IE7\ieapfltr.dat
-c—-w 380,928 2006-10-17 16:27:56 C:\WINDOWS\ie7updates\KB937143-IE7\ieapfltr.dll
-c—-w 382,976 2006-11-07 08:27:10 C:\WINDOWS\ie7updates\KB937143-IE7\iedkcs32.dll
-c—-w 6,049,280 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\ieframe.dll
-c—-w 43,008 2006-11-07 08:26:28 C:\WINDOWS\ie7updates\KB937143-IE7\iernonce.dll
-c—-w 266,752 2006-10-17 16:57:20 C:\WINDOWS\ie7updates\KB937143-IE7\iertutil.dll
-c—-w 13,312 2006-11-07 08:26:32 C:\WINDOWS\ie7updates\KB937143-IE7\ieudinit.exe
-c—-w 622,080 2006-10-17 17:04:40 C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
-c—-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\jsproxy.dll
-c—-w 458,752 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\msfeeds.dll
-c—-w 50,688 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\msfeedsbs.dll
-c—-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mshtml.dll
-c—-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mshtmled.dll
-c—-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\ie7updates\KB937143-IE7\msrating.dll
-c—-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mstime.dll
-c—-w 101,376 2006-10-17 17:04:46 C:\WINDOWS\ie7updates\KB937143-IE7\occache.dll
-c—-w 105,984 2006-10-17 17:05:22 C:\WINDOWS\ie7updates\KB937143-IE7\url.dll
-c—-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\urlmon.dll
-c—-w 231,424 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\webcheck.dll
-c—-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\wininet.dll
-c—-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe
-c—-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\updspapi.dll
-c—-w 765,952 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
-c—-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
-c—-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
—-a-w 124,928 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\advpack.dll
—-a-w 132,608 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\extmgr.dll
—-a-w 63,488 2007-06-27 08:27:04 C:\WINDOWS\SYSTEM32\ie4uinit.exe
—-a-w 153,088 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieakeng.dll
—-a-w 230,400 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieaksie.dll
—-a-w 161,792 2007-06-27 07:00:33 C:\WINDOWS\SYSTEM32\ieakui.dll
—-a-w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\SYSTEM32\ieapfltr.dat
—-a-w 383,488 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieapfltr.dll
—-a-w 384,512 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\iedkcs32.dll
—-a-w 6,058,496 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\ieframe.dll
—-a-w 44,544 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\iernonce.dll
—-a-w 267,776 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\iertutil.dll
—-a-w 13,824 2007-06-27 08:27:05 C:\WINDOWS\SYSTEM32\ieudinit.exe
—-a-w 27,648 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\jsproxy.dll
—-a-w 459,264 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\msfeeds.dll
—-a-w 52,224 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\msfeedsbs.dll
—-a-w 3,583,488 2007-07-19 06:59:59 C:\WINDOWS\SYSTEM32\mshtml.dll
—-a-w 477,696 2007-06-27 14:34:57 C:\WINDOWS\SYSTEM32\mshtmled.dll
—-a-w 193,024 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\msrating.dll
—-a-w 671,232 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\mstime.dll
—-a-w 102,400 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\occache.dll
—-a-w 105,984 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\url.dll
—-a-w 1,152,000 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\urlmon.dll
—-a-w 232,960 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\webcheck.dll
—-a-w 823,808 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\wininet.dll
——w 124,928 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
—-a-w 132,608 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
——w 63,488 2007-06-27 08:27:04 C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
——w 153,088 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
——w 230,400 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
——w 161,792 2007-06-27 07:00:33 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
——w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
——w 383,488 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
——w 384,512 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
——w 6,058,496 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
——w 44,544 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
——w 267,776 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
——w 13,824 2007-06-27 08:27:05 C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
——w 625,152 2007-06-27 08:27:30 C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
—-a-w 27,648 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
——w 459,264 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
——w 52,224 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
—-a-w 3,583,488 2007-07-19 06:59:59 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
—-a-w 477,696 2007-06-27 14:34:57 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
—-a-w 193,024 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
—-a-w 671,232 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
——w 102,400 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
——w 105,984 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
—-a-w 1,152,000 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
—-a-w 765,952 2007-07-12 23:31:54 C:\WINDOWS\SYSTEM32\DLLCACHE\vgx.dll
——w 232,960 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
—-a-w 823,808 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
.
—-a-w 123,904 2006-11-07 08:26:24 C:\WINDOWS\SYSTEM32\advpack.dll
—-a-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\extmgr.dll
—-a-w 54,784 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\ie4uinit.exe
—-a-w 152,064 2006-11-07 08:26:56 C:\WINDOWS\SYSTEM32\ieakeng.dll
—-a-w 229,376 2006-11-07 08:27:02 C:\WINDOWS\SYSTEM32\ieaksie.dll
—-a-w 161,792 2006-11-07 08:25:14 C:\WINDOWS\SYSTEM32\ieakui.dll
—-a-w 2,451,824 2006-09-06 04:01:26 C:\WINDOWS\SYSTEM32\ieapfltr.dat
—-a-w 380,928 2006-10-17 16:27:56 C:\WINDOWS\SYSTEM32\ieapfltr.dll
—-a-w 382,976 2006-11-07 08:27:10 C:\WINDOWS\SYSTEM32\iedkcs32.dll
—-a-w 6,049,280 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\ieframe.dll
—-a-w 43,008 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\iernonce.dll
—-a-w 266,752 2006-10-17 16:57:20 C:\WINDOWS\SYSTEM32\iertutil.dll
—-a-w 13,312 2006-11-07 08:26:32 C:\WINDOWS\SYSTEM32\ieudinit.exe
—-a-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\jsproxy.dll
—-a-w 458,752 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\msfeeds.dll
—-a-w 50,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\msfeedsbs.dll
—-a-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mshtml.dll
—-a-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mshtmled.dll
—-a-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\SYSTEM32\msrating.dll
—-a-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mstime.dll
—-a-w 101,376 2006-10-17 17:04:46 C:\WINDOWS\SYSTEM32\occache.dll
—-a-w 105,984 2006-10-17 17:05:22 C:\WINDOWS\SYSTEM32\url.dll
—-a-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\urlmon.dll
—-a-w 231,424 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\webcheck.dll
—-a-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\wininet.dll
——w 123,904 2006-11-07 08:26:24 C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
—-a-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
——w 54,784 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
——w 152,064 2006-11-07 08:26:56 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
——w 229,376 2006-11-07 08:27:02 C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
——w 161,792 2006-11-07 08:25:14 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
——w 382,976 2006-11-07 08:27:10 C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
——w 43,008 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
——w 622,080 2006-10-17 17:04:40 C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
—-a-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
—-a-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
—-a-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
—-a-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
—-a-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
——w 101,376 2006-10-17 17:04:46 C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
——w 105,984 2006-10-17 17:05:22 C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
—-a-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
—-a-w 765,952 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\VGX.dll
——w 231,424 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
—-a-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"AGRSMMSG"="AGRSMMSG.exe" [2003-11-19 15:41 C:\WINDOWS\AGRSMMSG.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 01:04]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 11:43]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-27 23:22]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-02 21:12]
"clcl16"="C:\WINDOWS\system32\clcl16.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ares"="C:\Program Files\Ares\Ares.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]
Utility Tray.lnk - C:\WINDOWS\SYSTEM32\sistray.exe [2004-07-14 11:47:50]

C:\DOCUME~1\Jake\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"thmuggfn"= {009B503E-AA31-FA94-685C-4EDC49E3AAF1} - C:\WINDOWS\system32\sjlfxo.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DC]
C:\WINDOWS\System32\DC.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pØà]
pØà

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\È08]
È08

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Ø€]
Ø€

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=FORCEDOS.dll


.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-18 21:48:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-18 21:51:21 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-18 21:50
C:\ComboFix2.txt … 2007-09-18 19:11
.
— E O F —




Ad-Aware SE Personal
Agere Systems AC'97 Modem
ALPS Touch Pad Driver
Dell Digital Jukebox Driver
Dell Solution Center
Dell Wireless WLAN Utility
Get High Speed Internet!
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Internet Explorer Default Page
J2SE Runtime Environment 5.0 Update 8
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
Macromedia Flash Player 8
McAfee SecurityCenter
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Modem Helper
PartyPoker
PCFriendly
PokerRoom.com (remove only)
PowerDVD 5.1
QuickTime
RealPlayer
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Select CashBack
SiS 900 PCI Fast Ethernet Adapter Driver
SiS VGA Utilities
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spybot - Search & Destroy 1.4
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WordPerfect Office 12




Logfile of HijackThis v1.99.1
Scan saved at 9:56:30 PM, on 9/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [clcl16] C:\WINDOWS\system32\clcl16.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - AppInit_DLLs: FORCEDOS.dll
O20 - Winlogon Notify: DC - C:\WINDOWS\System32\DC.tmp (file missing)
O20 - Winlogon Notify: pØà - pØà (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: È08 - È08 (file missing)
O20 - Winlogon Notify: Ø€ - Ø€ (file missing)
O21 - SSODL: thmuggfn - {009B503E-AA31-FA94-685C-4EDC49E3AAF1} - C:\WINDOWS\system32\sjlfxo.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe



There you go. I really appreciate your help.

Regards,

Jeff
Hi winnj,

Good job, that looks a lot better :)

Please open Start->Control Panel->Add/Remove Programs, look down the list for these items and remove them:

J2SE Runtime Environment 5.0 Update 8
Java 2 Runtime Environment, SE v1.4.2_03
Select CashBack

Select CashBack is malware, and the Java installations are out of date and now a security risk, you can get the latest update (version 6 update 2) from here

Party Poker and PokerRoom have been reported as being malware-related so I strongly recommend you remove them, to do so, look down the Add/Remove Programs list for these and remove them:

PartyPoker
PokerRoom.com (remove only)


Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [clcl16] C:\WINDOWS\system32\clcl16.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O20 - AppInit_DLLs: FORCEDOS.dll
O20 - Winlogon Notify: DC - C:\WINDOWS\System32\DC.tmp (file missing)
O20 - Winlogon Notify: pØà - pØà (file missing)
O20 - Winlogon Notify: È08 - È08 (file missing)
O20 - Winlogon Notify: Ø€ - Ø€ (file missing)
O21 - SSODL: thmuggfn - {009B503E-AA31-FA94-685C-4EDC49E3AAF1} - C:\WINDOWS\system32\sjlfxo.dll (file missing)

If you removed Party Poker then also check these lines:

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Then please do an online scan with Kaspersky:

Open Kaspersky Online Scanner in Internet Explorer

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

Once complete, please post the Kaspersky report and a new HijackThis log.
Good Evening Silver,

I think I got everything done you requested. I did go ahead and remove the two poker programs.

Here are the requested logs:



——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, September 19, 2007 8:55:39 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 20/09/2007
Kaspersky Anti-Virus database records: 420994
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 41770
Number of viruses found: 59
Number of infected objects: 183
Number of suspicious objects: 6
Duration of the scan process: 00:44:47

Infected Object Name / Virus Name / Last Action
C:\6F8.tmp Infected: Packed.Win32.PolyCrypt.b skipped
C:\boot.inx Infected: Email-Worm.Win32.Zhelatin.i skipped
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd002.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ABetterInternet1.zip/satmat.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ABetterInternet1.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISTbarSlotch.zip/istsvc.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISTbarSlotch.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PWSLDPinchIE2.zip/koos.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PWSLDPinchIE2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-3de270ec-1713420c.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-3de270ec-1713420c.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-3de270ec-1713420c.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-3de270ec-1713420c.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-138dbac7-45e8f742.zip/BaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-138dbac7-45e8f742.zip/VaaaaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-138dbac7-45e8f742.zip/Baaaaa.class Infected: Trojan.Java.ClassLoader.ao skipped
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-138dbac7-45e8f742.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Jake\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Jake\Desktop\[32]-[removed]/forcedos.dll Infected: Trojan.Win32.Agent.aqo skipped
C:\Documents and Settings\Jake\Desktop\[32]-[removed]/Retk48.sys Infected: Rootkit.Win32.Agent.ea skipped
C:\Documents and Settings\Jake\Desktop\[32]-[removed]/symavc32.sys Infected: Rootkit.Win32.Agent.ea skipped
C:\Documents and Settings\Jake\Desktop\[32]-[removed]/2020search.exe Infected: Trojan.Win32.Agent.bea skipped
C:\Documents and Settings\Jake\Desktop\[32]-[removed] ZIP: infected - 4 skipped
C:\Documents and Settings\Jake\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Jake\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Jake\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Jake\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Jake\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BearShareV6.exe/WISE0045.BIN/stream/data0005 Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BearShareV6.exe/WISE0045.BIN/stream Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BearShareV6.exe/WISE0045.BIN Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BearShareV6.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BearShareV6.exe WiseSFX Dropper: infected - 3 skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BSINSTALL.exe/WISE0024.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BSINSTALL.exe/WISE0024.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BSINSTALL.exe/WISE0024.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BSINSTALL.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\BSINSTALL.exe WiseSFX Dropper: infected - 3 skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe/data0020/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe/data0020/v2.0.4b.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel.g skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe/data0020/v2.0.4b.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe/data0020/v2.0.4b.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe/data0020/v2.0.4b.cab Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe/data0020 Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe/data0021 Infected: not-a-virus:AdWare.Win32.NavExcel.i skipped
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe NSIS: infected - 7 skipped
C:\Documents and Settings\Jake\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Jake\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\qoobox\Quarantine\C\3456346345643.exe.vir Infected: Email-Worm.Win32.Zhelatin.i skipped
C:\qoobox\Quarantine\C\Documents and Settings\Jake\svchost.exe.vir Infected: Packed.Win32.PolyCrypt.b skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp10A.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp10C.tmp.exe.vir Infected: Trojan.Win32.Agent.anr skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp116.tmp.exe.vir Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp11A.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp11C.tmp.exe.vir Infected: Trojan.Win32.Agent.anr skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp152.tmp.exe.vir Infected: Trojan.Win32.BHO.bd skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp156.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp15C.tmp.exe.vir Infected: Trojan.Win32.Agent.anr skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp1A6.tmp.exe.vir Infected: Trojan.Win32.BHO.bd skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp1A7.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp1A9.tmp.exe.vir Infected: Trojan.Win32.Agent.anr skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp1DC.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp1DD.tmp.exe.vir Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp20D.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp20E.tmp.exe.vir Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp730.tmp.exe.vir Infected: Trojan.Win32.BHO.bd skipped
C:\qoobox\Quarantine\C\DOCUME~1\Jake\APPLIC~1\tmp77B.tmp.exe.vir Infected: Trojan.Win32.BHO.bd skipped
C:\qoobox\Quarantine\C\Program Files\Common Files\Yazzle1162OinAdmin.exe.vir Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\qoobox\Quarantine\C\Program Files\hlpsrv.exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\qoobox\Quarantine\C\Program Files\ucleaner_setup.exe.vir Infected: not-a-virus:FraudTool.Win32.UltimateDefender.b skipped
C:\qoobox\Quarantine\C\qchrqilr1.exe.vir Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\qoobox\Quarantine\C\qchrqilr2.exe.vir Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\qoobox\Quarantine\C\qchrqilr3.exe.vir Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\qoobox\Quarantine\C\WINDOWS\avp.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\qoobox\Quarantine\C\WINDOWS\bywxuv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\qoobox\Quarantine\C\WINDOWS\csrss.exe.vir Infected: Trojan.Win32.Agent.app skipped
C:\qoobox\Quarantine\C\WINDOWS\mgrs.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\qoobox\Quarantine\C\WINDOWS\qonlmk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.kw skipped
C:\qoobox\Quarantine\C\WINDOWS\qonomk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.sg skipped
C:\qoobox\Quarantine\C\WINDOWS\sysrlb32.exe.vir Infected: Trojan.Win32.VB.azo skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\clcl7.exe.vir Infected: Trojan-Downloader.Win32.Agent.es skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\ip6fw.sys.vir Infected: Rootkit.Win32.Agent.dp skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\svchost.exe.vir Infected: Packed.Win32.PolyCrypt.b skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\drvbut.dll.vir Infected: Trojan.Win32.Dialer.qn skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB21542167.exe.vir Infected: Trojan.Win32.Qhost.it skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB34040802.exe.vir Infected: Trojan-Downloader.Win32.Searcher.a skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB42687917.exe.vir Infected: Trojan-Downloader.Win32.Small.ddx skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB52358626.exe.vir Infected: Trojan-Downloader.Win32.Small.ddx skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB52383366.exe.vir Infected: Trojan-Downloader.Win32.Agent.cwz skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB55963079.exe.vir Infected: Trojan.Win32.Qhost.it skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB58620628.exe.vir Infected: Trojan.Win32.Qhost.it skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB60114410.exe.vir Infected: Trojan-Downloader.Win32.Small.esu skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB89127940.exe.vir Infected: Trojan-Downloader.Win32.Small.esu skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB91010333.exe.vir Infected: Trojan-Downloader.Win32.Small.ddx skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\KB_963491.exe.vir Infected: Trojan-Downloader.Win32.Murlo.fe skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\kernels88.exe.vir Infected: Email-Worm.Win32.Zhelatin.i skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\maxd641.exe.vir Infected: not-a-virus:Porn-Dialer.Win32.GBDialer.i skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\msdn_lib.dll.vir Infected: Trojan-Downloader.Win32.VB.apq skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\ntio256.sys.vir Infected: Rootkit.Win32.Agent.cf skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\protector.exe.vir Infected: Trojan-Proxy.Win32.Wopla.ac skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\svehost.exe.vir Infected: Trojan.Win32.Agent.kq skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\tmp20C.tmp.dll.vir Infected: Trojan.Win32.BHO.bd skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\windbg48.sys.vir Infected: Rootkit.Win32.Agent.ea skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\winload.dll.vir Infected: Trojan-Downloader.Win32.Small.fqe skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\winrtp32.dll.vir Infected: Trojan.Win32.Dialer.qn skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\wmvds32.dll.vir Infected: Trojan-Downloader.Win32.VB.asx skipped
C:\qoobox\Quarantine\C\WINDOWS\vttsrr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\qoobox\Quarantine\C\wsusupd.exe.vir Infected: Trojan-Downloader.Win32.Searcher.a skipped
C:\qoobox\Quarantine\catchme2007-09-18_190921.24.zip/ACChlp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ke skipped
C:\qoobox\Quarantine\catchme2007-09-18_190921.24.zip/pmnonkl.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\qoobox\Quarantine\catchme2007-09-18_190921.24.zip ZIP: infected - 2 skipped
C:\syst.exe Infected: Email-Worm.Win32.Zhelatin.i skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP473\A0022356.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP474\A0022360.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP478\A0023335.exe Infected: Trojan-Downloader.Win32.Small.eum skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP487\A0025391.exe Infected: Trojan.Win32.Agent.app skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP487\A0028387.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP487\A0030387.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sg skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP489\A0031387.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP490\A0031396.sys Infected: Rootkit.Win32.Agent.ey skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP490\A0031534.dll Infected: Backdoor.Win32.Agent.adr skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP492\A0031643.dll Infected: Email-Worm.Win32.Locksky.bh skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP493\A0032735.exe Infected: Trojan-Downloader.Win32.VB.avl skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032834.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032835.exe Infected: Trojan.Win32.Agent.anr skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032840.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032843.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032844.exe Infected: Trojan.Win32.Agent.anr skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032846.exe Infected: Trojan.Win32.BHO.bd skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032847.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032849.exe Infected: Trojan.Win32.Agent.anr skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032850.exe Infected: Trojan.Win32.BHO.bd skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032851.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032852.exe Infected: Trojan.Win32.Agent.anr skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032853.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032854.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032857.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032858.exe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032859.exe Infected: Trojan.Win32.BHO.bd skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032860.exe Infected: Trojan.Win32.BHO.bd skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032864.exe Infected: Email-Worm.Win32.Zhelatin.i skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032868.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032869.dll Infected: Trojan.Win32.BHO.bd skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032870.exe Infected: Trojan-Downloader.Win32.Agent.es skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032871.exe Infected: Trojan.Win32.Qhost.it skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032872.exe Infected: Trojan-Downloader.Win32.Searcher.a skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032873.exe Infected: Trojan-Downloader.Win32.Small.ddx skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032874.exe Infected: Trojan-Downloader.Win32.Small.ddx skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032875.exe Infected: Trojan-Downloader.Win32.Agent.cwz skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032876.exe Infected: Trojan.Win32.Qhost.it skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032877.exe Infected: Trojan.Win32.Qhost.it skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032878.exe Infected: Trojan-Downloader.Win32.Small.esu skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032879.exe Infected: Trojan-Downloader.Win32.Small.esu skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032880.exe Infected: Trojan-Downloader.Win32.Small.ddx skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032881.exe Infected: Trojan-Downloader.Win32.Murlo.fe skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032882.exe Infected: Email-Worm.Win32.Zhelatin.i skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032883.sys Infected: Rootkit.Win32.Agent.dp skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032888.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032895.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032896.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.sg skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032899.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032900.dll Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032907.exe Infected: not-a-virus:Porn-Dialer.Win32.GBDialer.i skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032908.sys Infected: Rootkit.Win32.Agent.cf skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032909.exe Infected: Trojan-Proxy.Win32.Wopla.ac skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032910.exe Infected: Trojan.Win32.Agent.kq skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032911.sys Infected: Rootkit.Win32.Agent.ea skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032912.dll Infected: Trojan-Downloader.Win32.Small.fqe skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032913.dll Infected: Trojan-Downloader.Win32.VB.asx skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032914.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032915.exe Infected: Trojan.Win32.Agent.app skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032916.exe Infected: Packed.Win32.PolyCrypt.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032917.dll Infected: Trojan-Downloader.Win32.VB.apq skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032933.exe Infected: Packed.Win32.PolyCrypt.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032937.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.b skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032938.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032941.exe Infected: Trojan-Downloader.Win32.Searcher.a skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032952.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ke skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP494\A0032953.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP496\A0033162.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP496\A0033165.dll Infected: Trojan.Win32.Agent.aqo skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP496\A0033169.dll Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP496\A0033170.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP496\A0033172.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP496\A0033173.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP496\A0033174.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.c skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP498\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\SYSTEM32\24sd0648.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\credigui.dll Infected: Trojan-Downloader.Win32.Small.fqe skipped
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20070914-183804.backup Infected: Trojan.Win32.Qhost.it skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\iphelp.dll Infected: Trojan.Win32.Agent.bfu skipped
C:\WINDOWS\SYSTEM32\LogFiles\HTTPERR\httperr1.log Object is locked skipped
C:\WINDOWS\SYSTEM32\mscert.dll Infected: Trojan.Win32.BHO.dw skipped
C:\WINDOWS\SYSTEM32\netd.dll Infected: Trojan-Downloader.Win32.Small.fqe skipped
C:\WINDOWS\SYSTEM32\protect.dll Infected: Trojan-Downloader.Win32.Small.flp skipped
C:\WINDOWS\SYSTEM32\psx.dll Infected: Trojan.Win32.BHO.dy skipped
C:\WINDOWS\SYSTEM32\rcdll.dll Infected: Trojan-Downloader.Win32.Small.fqe skipped
C:\WINDOWS\SYSTEM32\rsh.dll Infected: Trojan-Downloader.Win32.Small.fqe skipped
C:\WINDOWS\SYSTEM32\thjtown.dll Infected: Backdoor.Win32.Agent.adr skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\yatool.dll Infected: Trojan-Downloader.Win32.Small.flo skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.




Logfile of HijackThis v1.99.1
Scan saved at 8:56:33 PM, on 9/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &AIM; Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe



Thank you and I look forward to hearing back.

Regards,

Jeff Winn
Hi winnj,

Good job :) we have a few more infected files to delete but we're nearly there.

Clean Spybots quarantined files:
Open Spybot - Search & Destroy
Select Recovery from the menu on the left side
Select the relevant item(s) and choose Purge selected items
Close Spybot - Search & Destroy


Check that ComboFix.exe is on your Desktop
  • Then open Notepad: press Start->Run, type notepad and click OK
  • Copy/paste the contents of the below code box into Notepad:
    File::
    C:\6F8.tmp
    C:\boot.inx
    C:\syst.exe
    C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-3de270ec-1713420c.zip
    C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-138dbac7-45e8f742.zip
    C:\Documents and Settings\Jake\Desktop\[32]-[removed]
    C:\Documents and Settings\Jake\My Documents\DL stuff\BearShareV6.exe
    C:\Documents and Settings\Jake\My Documents\DL stuff\BSINSTALL.exe
    C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe
    C:\WINDOWS\SYSTEM32\24sd0648.ini
    C:\WINDOWS\SYSTEM32\credigui.dll
    C:\WINDOWS\SYSTEM32\iphelp.dll
    C:\WINDOWS\SYSTEM32\mscert.dll
    C:\WINDOWS\SYSTEM32\netd.dll
    C:\WINDOWS\SYSTEM32\protect.dll
    C:\WINDOWS\SYSTEM32\psx.dll
    C:\WINDOWS\SYSTEM32\rcdll.dll
    C:\WINDOWS\SYSTEM32\rsh.dll
    C:\WINDOWS\SYSTEM32\thjtown.dll
    C:\WINDOWS\SYSTEM32\yatool.dll
  • Save this to your Desktop as CFScript.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Note: Do not click ComboFix's window while it's running - it may cause it to stall!

Once complete, please post the new ComboFix report and a new HijackThis log.
Also, let me know how your machine is running now.
Good Morning,

The laptop seems to running very well, thank you.

Below are the requested logs:



ComboFix 07-09-18.4 - "Jake" 2007-09-20 2:47:24.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.197 [GMT -5:00]
* Created a new restore point

FILE::
C:\6F8.tmp
C:\boot.inx
C:\syst.exe
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-3de270ec-1713420c.zip
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-138dbac7-45e8f742.zip
C:\Documents and Settings\Jake\Desktop\[32]-[removed]
C:\Documents and Settings\Jake\My Documents\DL stuff\BearShareV6.exe
C:\Documents and Settings\Jake\My Documents\DL stuff\BSINSTALL.exe
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe
C:\WINDOWS\SYSTEM32\24sd0648.ini
C:\WINDOWS\SYSTEM32\credigui.dll
C:\WINDOWS\SYSTEM32\iphelp.dll
C:\WINDOWS\SYSTEM32\mscert.dll
C:\WINDOWS\SYSTEM32\netd.dll
C:\WINDOWS\SYSTEM32\protect.dll
C:\WINDOWS\SYSTEM32\psx.dll
C:\WINDOWS\SYSTEM32\rcdll.dll
C:\WINDOWS\SYSTEM32\rsh.dll
C:\WINDOWS\SYSTEM32\thjtown.dll
C:\WINDOWS\SYSTEM32\yatool.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\6F8.tmp
C:\boot.inx
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-3de270ec-1713420c.zip
C:\Documents and Settings\Jake\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-138dbac7-45e8f742.zip
C:\Documents and Settings\Jake\Desktop\[32]-[removed]
C:\Documents and Settings\Jake\My Documents\DL stuff\BearShareV6.exe
C:\Documents and Settings\Jake\My Documents\DL stuff\BSINSTALL.exe
C:\Documents and Settings\Jake\My Documents\DL stuff\setup_ares.exe
C:\syst.exe
C:\WINDOWS\SYSTEM32\24sd0648.ini
C:\WINDOWS\SYSTEM32\credigui.dll
C:\WINDOWS\SYSTEM32\iphelp.dll
C:\WINDOWS\SYSTEM32\mscert.dll
C:\WINDOWS\SYSTEM32\netd.dll
C:\WINDOWS\SYSTEM32\protect.dll
C:\WINDOWS\SYSTEM32\psx.dll
C:\WINDOWS\SYSTEM32\rcdll.dll
C:\WINDOWS\SYSTEM32\rsh.dll
C:\WINDOWS\SYSTEM32\thjtown.dll
C:\WINDOWS\SYSTEM32\yatool.dll

.
((((((((((((((((((((((((( Files Created from 2007-08-20 to 2007-09-20 )))))))))))))))))))))))))))))))
.

2007-09-19 19:46 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-09-19 19:46 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-18 17:08 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-15 13:44 33,792 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2007-09-15 13:27 d——– C:\WINDOWS\SYSTEM32\LogFiles
2007-09-13 21:16 0 –a—— C:\WINDOWS\kwkx.exe
2007-09-13 06:27 d——– C:\DOCUME~1\Jake\APPLIC~1\MSN6
2007-09-13 06:27 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-19 19:36 ——— d——– C:\Program Files\PokerRoom.com
2007-09-19 19:36 ——— d——– C:\Program Files\PartyGaming
2007-09-15 13:23 ——— d——– C:\Program Files\Common Files\AOL
2007-09-15 13:23 ——— d——– C:\DOCUME~1\Jake\APPLIC~1\Aim
2007-09-15 10:55 ——— d——– C:\Program Files\WinMX
2007-09-15 10:46 ——— d——– C:\Program Files\FamilyFeudHollywood_at
2007-09-15 10:43 ——— d——– C:\Program Files\Ball7_at
2007-09-15 10:41 ——— d——– C:\Program Files\Ares
2007-09-15 10:27 ——— d——– C:\Program Files\LimeWire
2007-09-13 21:12 ——— d——– C:\DOCUME~1\Jake\APPLIC~1\WeatherBug
.

((((((((((((((((((((((((((((( snapshot_2007-09-18_191047.34 )))))))))))))))))))))))))))))))))))))))))
.
—-a-w 14,048 2007-03-06 01:22:36 C:\WINDOWS\$hf_mig$\KB937143-IE7\spmsg.dll
—-a-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\$hf_mig$\KB937143-IE7\spuninst.exe
—-a-w 124,928 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\advpack.dll
—-a-w 132,608 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\extmgr.dll
—-a-w 63,488 2007-06-27 09:16:27 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ie4uinit.exe
—-a-w 153,088 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieakeng.dll
—-a-w 230,400 2007-06-27 14:39:43 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieaksie.dll
—-a-w 161,792 2007-06-27 07:07:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieakui.dll
—-a-w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieapfltr.dat
—-a-w 383,488 2007-06-27 14:39:43 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieapfltr.dll
—-a-w 384,512 2007-06-27 14:39:44 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iedkcs32.dll
—-a-w 6,059,008 2007-06-27 14:39:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieframe.dll
—-a-w 44,544 2007-06-27 14:39:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iernonce.dll
—-a-w 267,776 2007-06-27 14:39:52 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iertutil.dll
—-a-w 13,824 2007-06-27 09:16:27 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieudinit.exe
—-a-w 625,152 2007-06-27 09:16:52 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
—-a-w 27,648 2007-06-27 14:39:54 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\jsproxy.dll
—-a-w 459,264 2007-06-27 14:39:55 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msfeeds.dll
—-a-w 52,224 2007-06-27 14:39:55 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msfeedsbs.dll
—-a-w 3,584,000 2007-07-18 21:09:49 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mshtml.dll
—-a-w 477,696 2007-06-27 14:40:00 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mshtmled.dll
—-a-w 193,024 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msrating.dll
—-a-w 671,232 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mstime.dll
—-a-w 102,400 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\occache.dll
—-a-w 105,984 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\url.dll
—-a-w 1,154,048 2007-06-27 14:40:02 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\urlmon.dll
—-a-w 232,960 2007-06-27 14:40:02 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\webcheck.dll
—-a-w 824,320 2007-06-27 14:40:03 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
—-a-w 22,752 2007-03-06 01:22:34 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\spcustom.dll
—-a-w 716,000 2007-03-06 01:22:59 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\update.exe
—-a-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\updspapi.dll
—-a-w 14,048 2007-03-06 01:22:36 C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
—-a-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
—-a-w 765,952 2007-07-12 23:28:55 C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
—-a-w 22,752 2007-03-06 01:22:34 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
—-a-w 716,000 2007-03-06 01:22:59 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
—-a-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
-c—-w 123,904 2006-11-07 08:26:24 C:\WINDOWS\ie7updates\KB937143-IE7\advpack.dll
-c—-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\extmgr.dll
-c—-w 54,784 2006-11-07 08:26:28 C:\WINDOWS\ie7updates\KB937143-IE7\ie4uinit.exe
-c—-w 152,064 2006-11-07 08:26:56 C:\WINDOWS\ie7updates\KB937143-IE7\ieakeng.dll
-c—-w 229,376 2006-11-07 08:27:02 C:\WINDOWS\ie7updates\KB937143-IE7\ieaksie.dll
-c—-w 161,792 2006-11-07 08:25:14 C:\WINDOWS\ie7updates\KB937143-IE7\ieakui.dll
-c—-w 2,451,824 2006-09-06 04:01:26 C:\WINDOWS\ie7updates\KB937143-IE7\ieapfltr.dat
-c—-w 380,928 2006-10-17 16:27:56 C:\WINDOWS\ie7updates\KB937143-IE7\ieapfltr.dll
-c—-w 382,976 2006-11-07 08:27:10 C:\WINDOWS\ie7updates\KB937143-IE7\iedkcs32.dll
-c—-w 6,049,280 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\ieframe.dll
-c—-w 43,008 2006-11-07 08:26:28 C:\WINDOWS\ie7updates\KB937143-IE7\iernonce.dll
-c—-w 266,752 2006-10-17 16:57:20 C:\WINDOWS\ie7updates\KB937143-IE7\iertutil.dll
-c—-w 13,312 2006-11-07 08:26:32 C:\WINDOWS\ie7updates\KB937143-IE7\ieudinit.exe
-c—-w 622,080 2006-10-17 17:04:40 C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
-c—-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\jsproxy.dll
-c—-w 458,752 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\msfeeds.dll
-c—-w 50,688 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\msfeedsbs.dll
-c—-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mshtml.dll
-c—-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mshtmled.dll
-c—-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\ie7updates\KB937143-IE7\msrating.dll
-c—-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mstime.dll
-c—-w 101,376 2006-10-17 17:04:46 C:\WINDOWS\ie7updates\KB937143-IE7\occache.dll
-c—-w 105,984 2006-10-17 17:05:22 C:\WINDOWS\ie7updates\KB937143-IE7\url.dll
-c—-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\urlmon.dll
-c—-w 231,424 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\webcheck.dll
-c—-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\wininet.dll
-c—-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe
-c—-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\updspapi.dll
-c—-w 765,952 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
-c—-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
-c—-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
—-a-w 124,928 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\advpack.dll
—-a-w 132,608 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\extmgr.dll
—-a-w 63,488 2007-06-27 08:27:04 C:\WINDOWS\SYSTEM32\ie4uinit.exe
—-a-w 153,088 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieakeng.dll
—-a-w 230,400 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieaksie.dll
—-a-w 161,792 2007-06-27 07:00:33 C:\WINDOWS\SYSTEM32\ieakui.dll
—-a-w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\SYSTEM32\ieapfltr.dat
—-a-w 383,488 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieapfltr.dll
—-a-w 384,512 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\iedkcs32.dll
—-a-w 6,058,496 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\ieframe.dll
—-a-w 44,544 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\iernonce.dll
—-a-w 267,776 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\iertutil.dll
—-a-w 13,824 2007-06-27 08:27:05 C:\WINDOWS\SYSTEM32\ieudinit.exe
—-a-w 27,648 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\jsproxy.dll
—-a-w 459,264 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\msfeeds.dll
—-a-w 52,224 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\msfeedsbs.dll
—-a-w 3,583,488 2007-07-19 06:59:59 C:\WINDOWS\SYSTEM32\mshtml.dll
—-a-w 477,696 2007-06-27 14:34:57 C:\WINDOWS\SYSTEM32\mshtmled.dll
—-a-w 193,024 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\msrating.dll
—-a-w 671,232 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\mstime.dll
—-a-w 102,400 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\occache.dll
—-a-w 105,984 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\url.dll
—-a-w 1,152,000 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\urlmon.dll
—-a-w 232,960 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\webcheck.dll
—-a-w 823,808 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\wininet.dll
——w 124,928 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
—-a-w 132,608 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
——w 63,488 2007-06-27 08:27:04 C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
——w 153,088 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
——w 230,400 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
——w 161,792 2007-06-27 07:00:33 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
——w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
——w 383,488 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
——w 384,512 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
——w 6,058,496 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
——w 44,544 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
——w 267,776 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
——w 13,824 2007-06-27 08:27:05 C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
——w 625,152 2007-06-27 08:27:30 C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
—-a-w 27,648 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
——w 459,264 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
——w 52,224 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
—-a-w 3,583,488 2007-07-19 06:59:59 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
—-a-w 477,696 2007-06-27 14:34:57 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
—-a-w 193,024 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
—-a-w 671,232 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
——w 102,400 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
——w 105,984 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
—-a-w 1,152,000 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
—-a-w 765,952 2007-07-12 23:31:54 C:\WINDOWS\SYSTEM32\DLLCACHE\vgx.dll
——w 232,960 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
—-a-w 823,808 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
—-a-w 213,048 2005-05-24 16:27:16 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
—-a-w 94,208 2007-09-07 16:29:00 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
—-a-w 946,176 2007-09-07 16:29:00 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
—-a-w 123,904 2006-11-07 08:26:24 C:\WINDOWS\SYSTEM32\advpack.dll
—-a-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\extmgr.dll
—-a-w 54,784 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\ie4uinit.exe
—-a-w 152,064 2006-11-07 08:26:56 C:\WINDOWS\SYSTEM32\ieakeng.dll
—-a-w 229,376 2006-11-07 08:27:02 C:\WINDOWS\SYSTEM32\ieaksie.dll
—-a-w 161,792 2006-11-07 08:25:14 C:\WINDOWS\SYSTEM32\ieakui.dll
—-a-w 2,451,824 2006-09-06 04:01:26 C:\WINDOWS\SYSTEM32\ieapfltr.dat
—-a-w 380,928 2006-10-17 16:27:56 C:\WINDOWS\SYSTEM32\ieapfltr.dll
—-a-w 382,976 2006-11-07 08:27:10 C:\WINDOWS\SYSTEM32\iedkcs32.dll
—-a-w 6,049,280 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\ieframe.dll
—-a-w 43,008 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\iernonce.dll
—-a-w 266,752 2006-10-17 16:57:20 C:\WINDOWS\SYSTEM32\iertutil.dll
—-a-w 13,312 2006-11-07 08:26:32 C:\WINDOWS\SYSTEM32\ieudinit.exe
—-a-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\jsproxy.dll
—-a-w 458,752 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\msfeeds.dll
—-a-w 50,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\msfeedsbs.dll
—-a-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mshtml.dll
—-a-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mshtmled.dll
—-a-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\SYSTEM32\msrating.dll
—-a-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mstime.dll
—-a-w 101,376 2006-10-17 17:04:46 C:\WINDOWS\SYSTEM32\occache.dll
—-a-w 105,984 2006-10-17 17:05:22 C:\WINDOWS\SYSTEM32\url.dll
—-a-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\urlmon.dll
—-a-w 231,424 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\webcheck.dll
—-a-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\wininet.dll
——w 123,904 2006-11-07 08:26:24 C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
—-a-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
——w 54,784 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
——w 152,064 2006-11-07 08:26:56 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
——w 229,376 2006-11-07 08:27:02 C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
——w 161,792 2006-11-07 08:25:14 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
——w 382,976 2006-11-07 08:27:10 C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
——w 43,008 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
——w 622,080 2006-10-17 17:04:40 C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
—-a-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
—-a-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
—-a-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
—-a-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
—-a-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
——w 101,376 2006-10-17 17:04:46 C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
——w 105,984 2006-10-17 17:05:22 C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
—-a-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
—-a-w 765,952 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\VGX.dll
——w 231,424 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
—-a-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"AGRSMMSG"="AGRSMMSG.exe" [2003-11-19 15:41 C:\WINDOWS\AGRSMMSG.exe]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 01:04]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 11:43]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-27 23:22]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-02 21:12]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ares"="C:\Program Files\Ares\Ares.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]
Utility Tray.lnk - C:\WINDOWS\SYSTEM32\sistray.exe [2004-07-14 11:47:50]

C:\DOCUME~1\Jake\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]


.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 02:50:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************
.
Completion time: 2007-09-20 2:53:30 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-20 02:52
C:\ComboFix2.txt … 2007-09-18 21:51
C:\ComboFix3.txt … 2007-09-18 19:11
.
— E O F —



Logfile of HijackThis v1.99.1
Scan saved at 5:07:15 AM, on 9/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe




Have a great day.

Jeff
Hi winnj,

Use Windows Explorer (right-click Start, select Explore) to find and delete the following files (if present):

C:\WINDOWS\kwkx.exe


Also delete this folder:

C:\qoobox


Once complete, please let me know if you deleted those successfully.
Hi winnj,

That's great, some important final steps:

Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm

You should now delete ComboFix.exe from your Desktop.

I think your machine is now clean of malware :) here are some tips to help you keep it that way:

Operating system vulnerabilities can easily be exploited by malware so please ensure your operating system is automatically kept up to date by using Windows Update:
Go to Start->Control Panel->Automatic Updates
Select Automatic and select a suitable schedule
Also, check that your antivirus and antispyware programs are set to automatically update daily.

You have a good antivirus program installed, however I recommend you also install antispyware software with real-time capabilities - this will protect you from a wider range of malware and also that it will protect you from system changes and spyware while you are working, not just removing malware after it has been installed. There are a range of paid-for and free packages available, a free one I can recommend is Windows Defender, available here:
http://www.microsoft.com/athome/security/s…re/default.mspx

You should consider installing a Personal Firewall program. Even if you are behind a NAT router, I recommend you use firewall software as it will improve the security of your computer by monitoring and controlling outbound connections to the internet as well as inbound. There are various free packages available, such as Sunbelt Personal Firewall and Zone Alarm:
http://www.sunbelt-software.com/Home-Home-…sonal-Firewall/
http://www.zonelabs.com/

Spywareblaster is a free program which prevents the download and installation of Internet Explorer ActiveX based malware by immunizing your system against it. You can download Spywareblaster from here and a tutorial to help you get started is available here.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins orActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Hi silver, All steps have been taken. I have installed Windows Defender and will follow your other recommendations as well I'm sure. Thanks again for all your help. You guys, and gals, are great and provide an invaluable service. Best regards, Jeff Winn
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI