Attached are the files you requested. When running ComboFix I received several alert pop-ups from the McAfee program asking about programs wanting to access the internet or change security settings. I allowed access for the ones identified as being from the ComboFix program but a couple of others were for executable files that I could not recognize as having anything to do with the Combofix program. These files were not granted access. I hope I didn't screw things up. I ran the ComboFix program, there are two files resulting from this, the ComboFix Notepad log and the ComboFix Quarantine-file. Just in case I will attach a copy of each. When I ran the VundoFix program it said no files were found and there was nothing listed as C:/vundofix.txt . I did a search for the file and found a Notepad document saying no files found, which is attached. I want to thank you for your help with this problem.
Mike24970
ComboFix 07-11-07.3 - William E. McDowell 2007-11-07 8:21:41.1 - NTFSx86
Running from: C:\Documents and Settings\William E. McDowell\Desktop\ComboFix.exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\William E. McDowell\Application Data\ICROSO~1
C:\Documents and Settings\William E. McDowell\Application Data\ICROSO~1\?icrosoft\
C:\Documents and Settings\William E. McDowell\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\William E. McDowell\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\William E. McDowell\Application Data\WinTouch\WTUninstaller.exe
C:\Documents and Settings\William E. McDowell\Favorites\Online Security Guide.lnk
C:\Documents and Settings\William E. McDowell\ResErrors.log
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\PopSwatr\History\allowed
C:\Program Files\FunWebProducts\PopSwatr\History\notallow
C:\Program Files\FunWebProducts\ScreenSaver\Images\
0C190FA8.urr
C:\Program Files\inetget2
C:\Program Files\Insider
C:\Program Files\Insider\Insider.exe
C:\Program Files\Insider\UnInstall.exe
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\History\search
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\network monitor
C:\Program Files\Temporary
C:\Program Files\WinAble
C:\Program Files\WinAble\winable.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fCOe
C:\Temp\fCOe\tOasF.log
C:\WINDOWS\b122.exe
C:\WINDOWS\b147.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\oTt02e
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\SYSTEM32\pstwa.bak1
C:\WINDOWS\SYSTEM32\pstwa.bak2
C:\WINDOWS\SYSTEM32\pstwa.tmp
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\tdesjmxf.dll
C:\WINDOWS\system32\vtutq.dll
C:\WINDOWS\system32\wcpicomsv.exe
C:\WINDOWS\system32\zhwhbvkd.dllbox
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_NETWORK_MONITOR
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 )))))))))))))))))))))))))))))))
.
2007-11-07 08:18 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 10:14 <DIR> C:\WINDOWS\LastGood.Tmp
2007-11-03 14:21 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-03 14:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-03 14:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-03 13:56 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-03 13:51 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-11-03 13:29 <DIR> d--h----- C:\WINDOWS\PIF
2007-11-02 11:50 <DIR> d-------- C:\Documents and Settings\William E. McDowell\Application Data\Motive
2007-11-02 07:30 954,368 -ra------ C:\WINDOWS\SYSTEM32\hpotiop5.dll
2007-11-02 07:30 675,840 -ra------ C:\WINDOWS\SYSTEM32\hpowiax5.dll
2007-11-02 07:30 303,104 -ra------ C:\WINDOWS\SYSTEM32\hpovst12.dll
2007-11-02 07:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2007-11-02 07:29 267,864 -ra------ C:\WINDOWS\SYSTEM32\hpzids01.dll
2007-11-02 07:29 118,272 --a------ C:\WINDOWS\SYSTEM32\hpz3l5ha.dll
2007-11-02 07:28 <DIR> d----c--- C:\WINDOWS\SYSTEM32\DRVSTORE
2007-11-02 07:28 364,544 -ra------ C:\WINDOWS\SYSTEM32\hppldcoi.dll
2007-11-02 07:28 309,760 -ra------ C:\WINDOWS\SYSTEM32\difxapi.dll
2007-11-02 06:43 <DIR> d-------- C:\WINDOWS\pss
2007-11-01 20:24 <DIR> d-------- C:\Program Files\Windows Defender
2007-11-01 19:42 6,058,496 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-11-01 19:42 2,455,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2007-11-01 19:42 459,264 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-11-01 19:42 383,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-11-01 19:42 267,776 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-11-01 19:42 63,488 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-11-01 19:42 52,224 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-11-01 19:42 33,792 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2007-11-01 19:42 13,824 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-11-01 19:02 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-11-01 18:59 <DIR> d-------- C:\WINDOWS\SYSTEM32\LogFiles
2007-11-01 18:59 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\UMDF
2007-11-01 13:48 <DIR> d-------- C:\Program Files\SiteAdvisor
2007-11-01 13:48 <DIR> d-------- C:\Documents and Settings\William E. McDowell\Application Data\SiteAdvisor
2007-11-01 13:44 143,360 --a------ C:\WINDOWS\SYSTEM32\dunzip32.dll
2007-11-01 13:39 171,240 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys
2007-11-01 13:39 71,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys
2007-11-01 13:39 37,480 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys
2007-11-01 13:39 34,184 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys
2007-11-01 13:39 32,008 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys
2007-11-01 13:38 109,608 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\Mpfp.sys
2007-11-01 13:33 <DIR> d-------- C:\Program Files\McAfee.com
2007-11-01 13:31 <DIR> d-------- C:\Program Files\Common Files\McAfee
2007-11-01 13:30 <DIR> d-------- C:\Program Files\McAfee
2007-11-01 12:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2007-11-01 11:44 <DIR> d-------- C:\Documents and Settings\William E. McDowell\Application Data\Verizon
2007-11-01 11:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Verizon
2007-11-01 11:43 <DIR> d-------- C:\WINDOWS\bin
2007-11-01 11:43 <DIR> d-------- C:\Documents and Settings\WILLIA~1\LOCALS~1
2007-11-01 11:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2007-11-01 11:25 <DIR> d-------- C:\Program Files\Common Files\Motive
2007-11-01 11:21 <DIR> d-------- C:\Program Files\Yahoo!
2007-11-01 11:03 <DIR> d-------- C:\WINDOWS\DSL
2007-11-01 11:03 <DIR> d-------- C:\Program Files\Verizon
2007-11-01 10:59 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
2007-11-01 08:34 <DIR> d-------- C:\WINDOWS\wfmo
2007-11-01 08:34 <DIR> d-------- C:\Program Files\Common Files\wfmo
2007-11-01 08:32 17,664 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sermouse.sys
2007-11-01 08:32 17,664 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\sermouse.sys
2007-10-27 18:22 <DIR> d--hs---- C:\WINDOWS\V2lsbGlhbSBFLiBNY0Rvd2VsbA
2007-10-26 14:52 1,060,864 --a------ C:\WINDOWS\SYSTEM32\mfc71.dll
2007-10-26 14:52 89,088 --a------ C:\WINDOWS\SYSTEM32\atl71.dll
2007-10-24 08:36 144,385 --a------ C:\WINDOWS\SYSTEM32\xilclrra.dll
2007-10-23 08:21 144,385 --a------ C:\WINDOWS\SYSTEM32\krshdqiq.dll
2007-10-18 20:03 172,080 --a------ C:\WINDOWS\SYSTEM32\pmnnn.dll
2007-10-17 22:51 <DIR> d-------- C:\WINDOWS\SYSTEM32\ib1
2007-10-17 22:51 <DIR> d-------- C:\WINDOWS\SYSTEM32\cp1
2007-10-17 22:51 <DIR> d-------- C:\WINDOWS\SYSTEM32\bo2
2007-10-17 22:51 <DIR> d-------- C:\WINDOWS\SYSTEM32\ap1
2007-10-17 22:48 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-05 01:03 --------- d-----w C:\Program Files\The Holy Bible v2.0
2007-11-02 22:12 --------- d-----w C:\Program Files\Common Files\AOL
2007-11-02 21:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-11-01 23:26 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-01 18:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-08-22 12:55 474,112 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shlwapi.dll
2007-08-22 12:55 151,040 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\cdfview.dll
2007-08-22 12:55 1,498,112 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shdocvw.dll
2007-08-22 12:55 1,054,208 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\danim.dll
2007-08-22 12:55 1,022,976 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\browseui.dll
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\SYSTEM32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\inetcomm.dll
2007-08-20 20:34 3,584,512 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-08-20 10:04 824,832 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-08-20 10:04 671,232 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-08-20 10:04 477,696 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
2007-08-20 10:04 27,648 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
2007-08-20 10:04 214,528 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-08-20 10:04 193,024 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
2007-08-20 10:04 132,608 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
2007-08-20 10:04 1,152,000 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2007-08-13 23:54 413,696 ----a-w C:\WINDOWS\SYSTEM32\vbscript.dll
2007-08-13 23:54 413,696 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\vbscript.dll
2007-08-13 23:54 191,488 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iepeers.dll
2007-08-13 23:54 156,160 ----a-w C:\WINDOWS\SYSTEM32\msls31.dll
2007-08-13 23:54 156,160 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msls31.dll
2007-08-13 23:45 78,336 ----a-w C:\WINDOWS\SYSTEM32\ieencode.dll
2007-08-13 23:45 78,336 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieencode.dll
2007-08-13 23:44 69,120 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
2007-08-13 23:44 40,960 ----a-w C:\WINDOWS\SYSTEM32\licmgr10.dll
2007-08-13 23:44 40,960 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\licmgr10.dll
2007-08-13 23:42 17,408 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\corpol.dll
2007-08-13 23:39 92,672 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\inseng.dll
2007-08-13 23:39 71,680 ----a-w C:\WINDOWS\SYSTEM32\admparse.dll
2007-08-13 23:39 71,680 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\admparse.dll
2007-08-13 23:39 55,296 ----a-w C:\WINDOWS\SYSTEM32\iesetup.dll
2007-08-13 23:39 55,296 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iesetup.dll
2007-08-13 23:38 491,520 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
2007-08-13 23:36 44,544 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
2007-08-13 23:36 36,352 ----a-w C:\WINDOWS\SYSTEM32\imgutil.dll
2007-08-13 23:36 36,352 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\imgutil.dll
2007-08-13 23:35 346,624 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
2007-08-13 23:32 45,568 ----a-w C:\WINDOWS\SYSTEM32\mshta.exe
2007-08-13 23:32 45,568 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshta.exe
2007-08-13 23:18 60,416 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\hmmapi.dll
2007-08-13 23:01 48,128 ----a-w C:\WINDOWS\SYSTEM32\mshtmler.dll
2007-08-13 23:01 48,128 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmler.dll
2005-03-29 21:17 56,584 ----a-w C:\Documents and Settings\William E. McDowell\Application Data\GDIPFONTCACHEV1.DAT
2003-12-17 23:23 0 ---ha-w C:\Documents and Settings\William E. McDowell\hpothb07.dat
2003-12-17 23:13 0 ---ha-w C:\Documents and Settings\William E. McDowell\Application Data\hpothb07.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27CA9C29-FFAF-4527-9D5D-AC870CDF23EF}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
2005-12-14 09:52 180224 --a------ C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AC5343D8-7908-42DE-8BCB-2B5D905622B0}]
C:\WINDOWS\system32\awtsp.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A8FB8EB3-183B-4598-924D-86F0E5E37085}"= C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll [2005-12-14 09:52 180224]
[HKEY_CLASSES_ROOT\CLSID\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[HKEY_CLASSES_ROOT\PeoplePC.Toolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
[HKEY_CLASSES_ROOT\PeoplePC.Toolbar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 07:59]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 07:59]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 C:\WINDOWS\BCMSMMSG.exe]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 02:04]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 02:01]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 20:47]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-08-14 18:29]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2003-11-19 11:37]
"DwlClient"="C:\Program Files\Common Files\Dell\EUSW\Support.exe" [2005-10-13 22:26]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-03-09 15:30]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-16 08:21]
"Bart Station"="C:\Program Files\ISP50\BIN\PPCOLink -STATION" []
"PPCRunonce"="C:\WINDOWS\system32\PPCRunOnce.exe" [2004-06-29 17:46]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-09-16 08:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-12-30 23:49]
"Verizon_McciTrayApp"="C:\Program Files\Verizon\McciTrayApp.exe" [2007-06-06 18:52]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" [2007-05-11 15:20]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 15:30]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"AIM"="C:\Program Files\AIM\aim.exe" [2005-08-05 14:08]
"wfmo"="C:\PROGRA~1\COMMON~1\wfmo\wfmom.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 01:17:18]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
S2 0073611194362100mcinstcleanup;McAfee Application Installer Cleanup (0073611194362100);C:\WINDOWS\TEMP\
007361~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service
*Newly Created Service* - 0073611194362100MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
"2004-02-22 17:11:42 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1069511551.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
"2007-11-01 18:36:39 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2007-11-01 18:36:38 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-11-07 13:37:27 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-07 08:34:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-07 8:44:36 - machine was rebooted
.
--- E O F ---
This is the ComboFix Quarantined-files Notepad document.
2003-01-30 13:52 12073 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\DRIVERS\FAD.sys.vir
2004-04-01 17:06 16 --a------ C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Settings\s_pid.dat.vir
2004-04-01 21:22 1024 --a------ C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\History\search.vir
2004-04-02 09:35 32768 --a------ C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\PopSwatr\History\notallow.vir
2004-04-03 11:00 32768 --a------ C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\PopSwatr\History\allowed.vir
2004-06-16 20:34 4 --a------ C:\Qoobox\Quarantine\C\Program Files\FunWebProducts\ScreenSaver\ImagesC190FA8.urr.vir
2007-04-24 11:21 9248 --a------ C:\Qoobox\Quarantine\C\Temp\1cb\syscheck.log.vir
2007-09-23 20:05 279600 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\pac.txt.vir
2007-10-17 22:51 1858 --a------ C:\Qoobox\Quarantine\C\Temp\fCOe\tOasF.log.vir
2007-10-17 22:55 145800 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\vtutq.dll.vir
2007-10-24 09:20 428792 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\pstwa.bak1.vir
2007-10-24 09:24 1184 --a------ C:\Qoobox\Quarantine\C\WINDOWS\cookies.ini.vir
2007-10-24 09:29 77376 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\tdesjmxf.dll.vir
2007-10-25 08:24 53760 --a------ C:\Qoobox\Quarantine\C\WINDOWS\b122.exe.vir
2007-10-25 09:40 97280 --a------ C:\Qoobox\Quarantine\C\WINDOWS\b147.exe.vir
2007-10-27 17:59 0 --a------ C:\Qoobox\Quarantine\C\Program Files\Insider\Insider.exe.vir
2007-10-27 17:59 0 --a------ C:\Qoobox\Quarantine\C\Program Files\Insider\UnInstall.exe.vir
2007-10-27 18:03 61440 --a------ C:\Qoobox\Quarantine\C\Program Files\WinAble\winable.exe.vir
2007-11-01 08:35 2 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\wcpicomsv.exe.vir
2007-11-01 08:37 2422 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\William E. McDowell\ResErrors.log.vir
2007-11-01 08:50 167424 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\William E. McDowell\Application Data\WinTouch\WinTouch.exe.vir
2007-11-01 08:50 48640 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\William E. McDowell\Application Data\WinTouch\WTUninstaller.exe.vir
2007-11-01 11:09 1268 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\William E. McDowell\Favorites\Online Security Guide.lnk.vir
2007-11-01 14:16 423215 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\pstwa.bak2.vir
2007-11-01 15:42 20640 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\zhwhbvkd.dllbox.vir
2007-11-01 15:42 413774 --a------ C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\pstwa.tmp.vir
2007-11-01 18:19 177690 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\LocalService\Application Data\NetMon\log.txt.vir
2007-11-01 18:19 39 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\LocalService\Application Data\NetMon\domains.txt.vir
2007-11-07 08:26 161701 --a------ C:\Qoobox\Quarantine\catchme2007-11-07_ 83336.98.zip
2007-11-07 08:26 2956 --a------ C:\Qoobox\Quarantine\Registry_backups\services_DomainService.reg.dat
2007-11-07 08:26 370 --a------ C:\Qoobox\Quarantine\catchme.log
2007-11-07 08:26 832 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_CMDSERVICE.reg.dat
2007-11-07 08:26 846 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_DOMAINSERVICE.reg.dat
2007-11-07 08:26 862 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_NETWORK_MONITOR.reg.dat
Folder PATH listing
Volume serial number is 301C-E931
C:\QOOBOX\QUARANTINE
| catchme.log
| catchme2007-11-07_ 83336.98.zip
|
+---C
| +---Documents and Settings
| | +---LocalService
| | | \---Application Data
| | | \---NetMon
| | | domains.txt.vir
| | | log.txt.vir
| | |
| | \---William E. McDowell
| | | ResErrors.log.vir
| | |
| | +---Application Data
| | | +---WinTouch
| | | | WinTouch.exe.vir
| | | | WTUninstaller.exe.vir
| | | |
| | | \---WinTouch.vir
| | \---Favorites
| | Online Security Guide.lnk.vir
| |
| +---Program Files
| | +---FunWebProducts
| | | +---PopSwatr
| | | | \---History
| | | | allowed.vir
| | | | notallow.vir
| | | |
| | | \---ScreenSaver
| | | \---Images
| | | 0C190FA8.urr.vir
| | |
| | +---Insider
| | | Insider.exe.vir
| | | UnInstall.exe.vir
| | |
| | +---MyWebSearch
| | | \---bar
| | | +---History
| | | | search.vir
| | | |
| | | \---Settings
| | | s_pid.dat.vir
| | |
| | \---WinAble
| | winable.exe.vir
| |
| +---Temp
| | +---1cb
| | | syscheck.log.vir
| | |
| | \---fCOe
| | tOasF.log.vir
| |
| \---WINDOWS
| | b122.exe.vir
| | b147.exe.vir
| | cookies.ini.vir
| |
| \---SYSTEM32
| | pac.txt.vir
| | pstwa.bak1.vir
| | pstwa.bak2.vir
| | pstwa.tmp.vir
| | tdesjmxf.dll.vir
| | vtutq.dll.vir
| | wcpicomsv.exe.vir
| | zhwhbvkd.dllbox.vir
| |
| \---DRIVERS
| FAD.sys.vir
|
\---Registry_backups
LEGACY_CMDSERVICE.reg.dat
LEGACY_DOMAINSERVICE.reg.dat
LEGACY_NETWORK_MONITOR.reg.dat
services_DomainService.reg.dat
VundoFix V6.5.11
Checking Java version...
Scan started at 8:51:45 AM 11/7/2007
Listing files found while scanning....
No infected files were found.
Beginning removal...
Logfile of HijackThis v1.99.1
Scan saved at 9:18:08 AM, on 11/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ISP50\Bin\Bartshel.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\ISP50\bin\ppshared.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Hijackthis\Scanner.exe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.accoona.com/search?q=%s
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {27CA9C29-FFAF-4527-9D5D-AC870CDF23EF} - \
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O2 - BHO: (no name) - {AC5343D8-7908-42DE-8BCB-2B5D905622B0} - C:\WINDOWS\system32\awtsp.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {364B6276-C6C1-40B6-A6D7-6C48871FD707} - (no file)
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP50\BIN\PPCOLink -STATION
O4 - HKLM\..\Run: [PPCRunonce] C:\WINDOWS\system32\PPCRunOnce.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [wfmo] C:\PROGRA~1\COMMON~1\wfmo\wfmom.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.co...etup1.0.0.8.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) -
http://www.callwave....DL_DownLoad.CAB
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: McAfee Application Installer Cleanup (0073611194362100) (0073611194362100mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP 7361~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBackMonitor - - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe