Hello again,
Below are the requested logs and the malware file was submitted.
ComboFix 07-09-18.4 - "Jake" 2007-09-18 21:44:03.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.214 [GMT -5:00]
* Created a new restore point
FILE::
C:\WINDOWS\SYSTEM32\drvbutr.dll
C:\WINDOWS\SYSTEM32\drvbut.dll
C:\Program Files\hlpsrv.exe
C:\WINDOWS\System32\DC.tmp
C:\WINDOWS\SYSTEM32\delFSF.bat
C:\qchrqilr1.exe
C:\qchrqilr3.exe
C:\qchrqilr2.exe
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\hlpsrv.exe
C:\Program Files\tyledqve
C:\Program Files\tyledqve\padgbezy.dll
C:\qchrqilr1.exe
C:\qchrqilr2.exe
C:\qchrqilr3.exe
C:\WINDOWS\2020search.exe
C:\WINDOWS\SYSTEM32\delFSF.bat
C:\WINDOWS\SYSTEM32\DRIVERS\Retk48.sys
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\SYSTEM32\DRIVERS\symavc32.sys
C:\WINDOWS\SYSTEM32\drvbut.dll
C:\WINDOWS\SYSTEM32\drvbutr.dll
C:\WINDOWS\SYSTEM32\forcedos.dll
.
((((((((((((((((((((((((( Files Created from 2007-08-19 to 2007-09-19 )))))))))))))))))))))))))))))))
.
2007-09-18 17:08 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-15 13:44 33,792 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2007-09-15 13:27 d——– C:\WINDOWS\SYSTEM32\LogFiles
2007-09-13 06:27 d——– C:\DOCUME~1\Jake\APPLIC~1\MSN6
2007-09-13 06:27 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-15 13:23 ——— d——– C:\Program Files\Common Files\AOL
2007-09-15 13:23 ——— d——– C:\DOCUME~1\Jake\APPLIC~1\Aim
2007-09-15 10:55 ——— d——– C:\Program Files\WinMX
2007-09-15 10:46 ——— d——– C:\Program Files\FamilyFeudHollywood_at
2007-09-15 10:43 ——— d——– C:\Program Files\Ball7_at
2007-09-15 10:41 ——— d——– C:\Program Files\Ares
2007-09-15 10:27 ——— d——– C:\Program Files\LimeWire
2007-09-13 21:12 ——— d——– C:\DOCUME~1\Jake\APPLIC~1\WeatherBug
.
((((((((((((((((((((((((((((( snapshot_2007-09-18_191047.34 )))))))))))))))))))))))))))))))))))))))))
.
—-a-w 14,048 2007-03-06 01:22:36 C:\WINDOWS\$hf_mig$\KB937143-IE7\spmsg.dll
—-a-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\$hf_mig$\KB937143-IE7\spuninst.exe
—-a-w 124,928 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\advpack.dll
—-a-w 132,608 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\extmgr.dll
—-a-w 63,488 2007-06-27 09:16:27 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ie4uinit.exe
—-a-w 153,088 2007-06-27 14:39:42 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieakeng.dll
—-a-w 230,400 2007-06-27 14:39:43 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieaksie.dll
—-a-w 161,792 2007-06-27 07:07:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieakui.dll
—-a-w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieapfltr.dat
—-a-w 383,488 2007-06-27 14:39:43 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieapfltr.dll
—-a-w 384,512 2007-06-27 14:39:44 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iedkcs32.dll
—-a-w 6,059,008 2007-06-27 14:39:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieframe.dll
—-a-w 44,544 2007-06-27 14:39:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iernonce.dll
—-a-w 267,776 2007-06-27 14:39:52 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iertutil.dll
—-a-w 13,824 2007-06-27 09:16:27 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\ieudinit.exe
—-a-w 625,152 2007-06-27 09:16:52 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
—-a-w 27,648 2007-06-27 14:39:54 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\jsproxy.dll
—-a-w 459,264 2007-06-27 14:39:55 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msfeeds.dll
—-a-w 52,224 2007-06-27 14:39:55 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msfeedsbs.dll
—-a-w 3,584,000 2007-07-18 21:09:49 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mshtml.dll
—-a-w 477,696 2007-06-27 14:40:00 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mshtmled.dll
—-a-w 193,024 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\msrating.dll
—-a-w 671,232 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mstime.dll
—-a-w 102,400 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\occache.dll
—-a-w 105,984 2007-06-27 14:40:01 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\url.dll
—-a-w 1,154,048 2007-06-27 14:40:02 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\urlmon.dll
—-a-w 232,960 2007-06-27 14:40:02 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\webcheck.dll
—-a-w 824,320 2007-06-27 14:40:03 C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
—-a-w 22,752 2007-03-06 01:22:34 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\spcustom.dll
—-a-w 716,000 2007-03-06 01:22:59 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\update.exe
—-a-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\$hf_mig$\KB937143-IE7\update\updspapi.dll
—-a-w 14,048 2007-03-06 01:22:36 C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
—-a-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
—-a-w 765,952 2007-07-12 23:28:55 C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
—-a-w 22,752 2007-03-06 01:22:34 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
—-a-w 716,000 2007-03-06 01:22:59 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
—-a-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
-c—-w 123,904 2006-11-07 08:26:24 C:\WINDOWS\ie7updates\KB937143-IE7\advpack.dll
-c—-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\extmgr.dll
-c—-w 54,784 2006-11-07 08:26:28 C:\WINDOWS\ie7updates\KB937143-IE7\ie4uinit.exe
-c—-w 152,064 2006-11-07 08:26:56 C:\WINDOWS\ie7updates\KB937143-IE7\ieakeng.dll
-c—-w 229,376 2006-11-07 08:27:02 C:\WINDOWS\ie7updates\KB937143-IE7\ieaksie.dll
-c—-w 161,792 2006-11-07 08:25:14 C:\WINDOWS\ie7updates\KB937143-IE7\ieakui.dll
-c—-w 2,451,824 2006-09-06 04:01:26 C:\WINDOWS\ie7updates\KB937143-IE7\ieapfltr.dat
-c—-w 380,928 2006-10-17 16:27:56 C:\WINDOWS\ie7updates\KB937143-IE7\ieapfltr.dll
-c—-w 382,976 2006-11-07 08:27:10 C:\WINDOWS\ie7updates\KB937143-IE7\iedkcs32.dll
-c—-w 6,049,280 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\ieframe.dll
-c—-w 43,008 2006-11-07 08:26:28 C:\WINDOWS\ie7updates\KB937143-IE7\iernonce.dll
-c—-w 266,752 2006-10-17 16:57:20 C:\WINDOWS\ie7updates\KB937143-IE7\iertutil.dll
-c—-w 13,312 2006-11-07 08:26:32 C:\WINDOWS\ie7updates\KB937143-IE7\ieudinit.exe
-c—-w 622,080 2006-10-17 17:04:40 C:\WINDOWS\ie7updates\KB937143-IE7\iexplore.exe
-c—-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\jsproxy.dll
-c—-w 458,752 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\msfeeds.dll
-c—-w 50,688 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\msfeedsbs.dll
-c—-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mshtml.dll
-c—-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mshtmled.dll
-c—-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\ie7updates\KB937143-IE7\msrating.dll
-c—-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\mstime.dll
-c—-w 101,376 2006-10-17 17:04:46 C:\WINDOWS\ie7updates\KB937143-IE7\occache.dll
-c—-w 105,984 2006-10-17 17:05:22 C:\WINDOWS\ie7updates\KB937143-IE7\url.dll
-c—-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\urlmon.dll
-c—-w 231,424 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\webcheck.dll
-c—-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB937143-IE7\wininet.dll
-c—-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe
-c—-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\updspapi.dll
-c—-w 765,952 2006-11-08 02:03:36 C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
-c—-w 213,216 2007-03-06 01:22:41 C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
-c—-w 371,424 2007-03-06 01:23:51 C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
—-a-w 124,928 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\advpack.dll
—-a-w 132,608 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\extmgr.dll
—-a-w 63,488 2007-06-27 08:27:04 C:\WINDOWS\SYSTEM32\ie4uinit.exe
—-a-w 153,088 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieakeng.dll
—-a-w 230,400 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieaksie.dll
—-a-w 161,792 2007-06-27 07:00:33 C:\WINDOWS\SYSTEM32\ieakui.dll
—-a-w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\SYSTEM32\ieapfltr.dat
—-a-w 383,488 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\ieapfltr.dll
—-a-w 384,512 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\iedkcs32.dll
—-a-w 6,058,496 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\ieframe.dll
—-a-w 44,544 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\iernonce.dll
—-a-w 267,776 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\iertutil.dll
—-a-w 13,824 2007-06-27 08:27:05 C:\WINDOWS\SYSTEM32\ieudinit.exe
—-a-w 27,648 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\jsproxy.dll
—-a-w 459,264 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\msfeeds.dll
—-a-w 52,224 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\msfeedsbs.dll
—-a-w 3,583,488 2007-07-19 06:59:59 C:\WINDOWS\SYSTEM32\mshtml.dll
—-a-w 477,696 2007-06-27 14:34:57 C:\WINDOWS\SYSTEM32\mshtmled.dll
—-a-w 193,024 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\msrating.dll
—-a-w 671,232 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\mstime.dll
—-a-w 102,400 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\occache.dll
—-a-w 105,984 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\url.dll
—-a-w 1,152,000 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\urlmon.dll
—-a-w 232,960 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\webcheck.dll
—-a-w 823,808 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\wininet.dll
——w 124,928 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
—-a-w 132,608 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
——w 63,488 2007-06-27 08:27:04 C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
——w 153,088 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
——w 230,400 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
——w 161,792 2007-06-27 07:00:33 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
——w 2,455,488 2007-04-17 09:32:38 C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
——w 383,488 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
——w 384,512 2007-06-27 14:34:51 C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
——w 6,058,496 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
——w 44,544 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
——w 267,776 2007-06-27 14:34:55 C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
——w 13,824 2007-06-27 08:27:05 C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
——w 625,152 2007-06-27 08:27:30 C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
—-a-w 27,648 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
——w 459,264 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
——w 52,224 2007-06-27 14:34:56 C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
—-a-w 3,583,488 2007-07-19 06:59:59 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
—-a-w 477,696 2007-06-27 14:34:57 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
—-a-w 193,024 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
—-a-w 671,232 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
——w 102,400 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
——w 105,984 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
—-a-w 1,152,000 2007-06-27 14:34:58 C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
—-a-w 765,952 2007-07-12 23:31:54 C:\WINDOWS\SYSTEM32\DLLCACHE\vgx.dll
——w 232,960 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
—-a-w 823,808 2007-06-27 14:34:59 C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
.
—-a-w 123,904 2006-11-07 08:26:24 C:\WINDOWS\SYSTEM32\advpack.dll
—-a-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\extmgr.dll
—-a-w 54,784 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\ie4uinit.exe
—-a-w 152,064 2006-11-07 08:26:56 C:\WINDOWS\SYSTEM32\ieakeng.dll
—-a-w 229,376 2006-11-07 08:27:02 C:\WINDOWS\SYSTEM32\ieaksie.dll
—-a-w 161,792 2006-11-07 08:25:14 C:\WINDOWS\SYSTEM32\ieakui.dll
—-a-w 2,451,824 2006-09-06 04:01:26 C:\WINDOWS\SYSTEM32\ieapfltr.dat
—-a-w 380,928 2006-10-17 16:27:56 C:\WINDOWS\SYSTEM32\ieapfltr.dll
—-a-w 382,976 2006-11-07 08:27:10 C:\WINDOWS\SYSTEM32\iedkcs32.dll
—-a-w 6,049,280 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\ieframe.dll
—-a-w 43,008 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\iernonce.dll
—-a-w 266,752 2006-10-17 16:57:20 C:\WINDOWS\SYSTEM32\iertutil.dll
—-a-w 13,312 2006-11-07 08:26:32 C:\WINDOWS\SYSTEM32\ieudinit.exe
—-a-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\jsproxy.dll
—-a-w 458,752 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\msfeeds.dll
—-a-w 50,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\msfeedsbs.dll
—-a-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mshtml.dll
—-a-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mshtmled.dll
—-a-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\SYSTEM32\msrating.dll
—-a-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\mstime.dll
—-a-w 101,376 2006-10-17 17:04:46 C:\WINDOWS\SYSTEM32\occache.dll
—-a-w 105,984 2006-10-17 17:05:22 C:\WINDOWS\SYSTEM32\url.dll
—-a-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\urlmon.dll
—-a-w 231,424 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\webcheck.dll
—-a-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\wininet.dll
——w 123,904 2006-11-07 08:26:24 C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
—-a-w 131,584 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
——w 54,784 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
——w 152,064 2006-11-07 08:26:56 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
——w 229,376 2006-11-07 08:27:02 C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
——w 161,792 2006-11-07 08:25:14 C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
——w 382,976 2006-11-07 08:27:10 C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
——w 43,008 2006-11-07 08:26:28 C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
——w 622,080 2006-10-17 17:04:40 C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
—-a-w 27,136 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
—-a-w 3,577,856 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
—-a-w 475,648 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
—-a-w 192,000 2006-10-17 17:05:10 C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
—-a-w 670,720 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
——w 101,376 2006-10-17 17:04:46 C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
——w 105,984 2006-10-17 17:05:22 C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
—-a-w 1,162,240 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
—-a-w 765,952 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\VGX.dll
——w 231,424 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
—-a-w 818,688 2006-11-08 02:03:36 C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"AGRSMMSG"="AGRSMMSG.exe" [2003-11-19 15:41 C:\WINDOWS\AGRSMMSG.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" [2006-07-26 03:03]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-05-12 16:22]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 01:04]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 11:43]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-27 23:22]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-04-02 21:12]
"clcl16"="C:\WINDOWS\system32\clcl16.exe" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"ares"="C:\Program Files\Ares\Ares.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]
Utility Tray.lnk - C:\WINDOWS\SYSTEM32\sistray.exe [2004-07-14 11:47:50]
C:\DOCUME~1\Jake\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2002-09-03 09:00:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"thmuggfn"= {009B503E-AA31-FA94-685C-4EDC49E3AAF1} - C:\WINDOWS\system32\sjlfxo.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DC]
C:\WINDOWS\System32\DC.tmp
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pØà]
pØà
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\È08]
È08
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Ø€]
Ø€
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=FORCEDOS.dll
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-18 21:48:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-18 21:51:21 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-18 21:50
C:\ComboFix2.txt … 2007-09-18 19:11
.
— E O F —
Ad-Aware SE Personal
Agere Systems AC'97 Modem
ALPS Touch Pad Driver
Dell Digital Jukebox Driver
Dell Solution Center
Dell Wireless WLAN Utility
Get High Speed Internet!
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Internet Explorer Default Page
J2SE Runtime Environment 5.0 Update 8
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
Macromedia Flash Player 8
McAfee SecurityCenter
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Modem Helper
PartyPoker
PCFriendly
PokerRoom.com (remove only)
PowerDVD 5.1
QuickTime
RealPlayer
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Select CashBack
SiS 900 PCI Fast Ethernet Adapter Driver
SiS VGA Utilities
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spybot - Search & Destroy 1.4
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WordPerfect Office 12
Logfile of HijackThis v1.99.1
Scan saved at 9:56:30 PM, on 9/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [clcl16] C:\WINDOWS\system32\clcl16.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O20 - AppInit_DLLs: FORCEDOS.dll
O20 - Winlogon Notify: DC - C:\WINDOWS\System32\DC.tmp (file missing)
O20 - Winlogon Notify: pØà - pØà (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: È08 - È08 (file missing)
O20 - Winlogon Notify: ؀ - ؀ (file missing)
O21 - SSODL: thmuggfn - {009B503E-AA31-FA94-685C-4EDC49E3AAF1} - C:\WINDOWS\system32\sjlfxo.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
There you go. I really appreciate your help.
Regards,
Jeff