This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Can't get rid of Trojan.Virtumonde

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi mine name is Lin and I've seen others get help here with their virus issue…so please, please help me.

I downloaded Spyware Doctor today and it was a godsend, it got rid of everything but a pesky trojan.virtumonde that has something to do with c:\winnt\system32\pmnlm.dll

Below is my hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:41:23 PM, on 12/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\locator.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINNT\System32\svchost.exe
c:\WINNT\system32\ZuneBusEnum.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Documents and Settings\Mom\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\WINNT\System32\alg.exe
C:\WINNT\system32\dumprep.exe
C:\WINNT\system32\dumprep.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet (User 'Default user')
O4 - Startup: YouTube Uploader.lnk = C:\Documents and Settings\Mom\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINNT\system32\GPhotos.scr/200
O9 - Extra button: ShopperReports - Compare travel rates - {946B3E9E-E21A-49c8-9F63-900533FAFE14} - C:\WINNT\System32\shdocvw.dll
O9 - Extra button: ShopperReports - Compare product prices - {E77EDA01-3C56-4a96-8D08-02B42891C169} - C:\WINNT\System32\shdocvw.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download…ne_Inst_Win.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…181/mcfscan.cab
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 5531 bytes

Thanks so much!!
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Step 1

Please disable Spyware Doctor OnGuard, as it may interfere with the fix.

  • From within Spyware Doctor, click the OnGuard button on the left side.
  • Uncheck Activate OnGuard.
  • Reboot your computer to complete the process.

Note: Be sure to enable Spyware Doctor OnGuard when you are clean!

Step 2

Please download ATF Cleaner. Double-click on ATF-Cleaner.exe to start the program.

  • Under the Main tab, put a check next to Select All.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Firefox browser:
    Click on Firefox at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Opera browser:
    Click on Opera at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)

Step 3

Please download Combofix:

  • From BleepingComputer
  • From InfoSpyware
  • From GeeksToGo

Double-click on combofix.exe and follow the prompts.
When finished, it will produce a log for you. Save it to a convenient location.

Note: Do not mouseclick Combofix's window whilst it's running. That may cause it to stall.

Step 4

Please download and install CCleaner.

  • Open CCleaner. In the Left Pane, click Tools.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save.
  • Exit Ccleaner by clicking on the X button in the upper right of the CCleaner window.

Step 5

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the CCleaner Uninstall List (install.txt)
  • a new HijackThis log
Thank you so much!! here are my logs below:

ComboFix 07-12-21.4 - Mom 2007-12-23 12:52:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.75 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Mom\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Travis\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Travis\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Travis\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\stem32~1
C:\Program Files\Common Files\stem32~1\??stem32\
C:\setup.exe
C:\WINNT\cookies.ini
C:\WINNT\system32\aejqxjan.exe
C:\WINNT\system32\afyhevxt.dll
C:\WINNT\system32\alcqddam.exe
C:\WINNT\system32\axcrlhot.dll
C:\WINNT\system32\bgdwugkc.exe
C:\WINNT\system32\dsrxylro.exe
C:\WINNT\system32\eidwcjch.ini
C:\WINNT\system32\epesmekm.dll
C:\WINNT\system32\epitbqik.dll
C:\WINNT\system32\evgcpqbq.exe
C:\WINNT\system32\fdwnpmgu.exe
C:\WINNT\system32\fivftuky.dll
C:\WINNT\system32\fsejjrwy.exe
C:\WINNT\system32\ftlwsbsl.exe
C:\WINNT\system32\fuhympgg.exe
C:\WINNT\system32\ggsfxwfn.dll
C:\WINNT\system32\grhecutl.dll
C:\WINNT\system32\hcjcwdie.dll
C:\WINNT\system32\hvmfcuie.dll
C:\WINNT\system32\iitngkjk.exe
C:\WINNT\system32\jaqssdas.exe
C:\WINNT\system32\kclhwmkm.exe
C:\WINNT\system32\kohvhwnj.exe
C:\WINNT\system32\ksnskkkt.exe
C:\WINNT\system32\kuebwhvy.exe
C:\WINNT\system32\lxslceld.exe
C:\WINNT\system32\lydckhly.dllbox
C:\WINNT\system32\mlnmp.ini
C:\WINNT\system32\mlnmp.ini2
C:\WINNT\system32\npnbevby.dll
C:\WINNT\system32\ovwvkase.dll
C:\WINNT\system32\phvwdhqv.dll
C:\WINNT\system32\pkwakvtk.dll
C:\WINNT\system32\pmnlm.dll
C:\WINNT\system32\pnpnkmnc.exe
C:\WINNT\system32\qehqheyu.exe
C:\WINNT\system32\qmenbern.exe
C:\WINNT\system32\qvcqytvu.exe
C:\WINNT\system32\qyrbolxu.dll
C:\WINNT\system32\rereqtdo.exe
C:\WINNT\system32\rpjjygjn.dll
C:\WINNT\system32\saxusvjq.dll
C:\WINNT\system32\sxsgpfyb.exe
C:\WINNT\system32\taifjbmo.exe
C:\WINNT\system32\tqqaqcny.exe
C:\WINNT\system32\tsctitfp.exe
C:\WINNT\system32\uvamteyp.exe
C:\WINNT\system32\uviwnnbb.exe
C:\WINNT\system32\uxlobryq.ini
C:\WINNT\system32\vemboger.exe
C:\WINNT\system32\vnynjjih.exe
C:\WINNT\system32\vqhdwvhp.ini
C:\WINNT\system32\wgiqeoql.exe
C:\WINNT\system32\xsuolqia.exe
C:\WINNT\system32\ybvebnpn.ini
C:\WINNT\system32\yfdaarcx.dll
C:\WINNT\system32\ypaqsigd.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-23 to 2007-12-23 )))))))))))))))))))))))))))))))
.

2007-12-23 06:54 . 2006-10-04 21:42 2,560 ——— C:\WINNT\system32\drivers\cdralw2k.sys
2007-12-23 06:54 . 2006-10-04 21:42 2,432 ——— C:\WINNT\system32\drivers\cdr4_xp.sys
2007-12-23 06:53 . 2007-12-23 06:55 d——– C:\Program Files\Picasa2
2007-12-22 17:00 . 2007-12-22 17:00 d——– C:\Documents and Settings\Mom\Application Data\Skype
2007-12-22 14:21 . 2007-12-22 14:21 d——– C:\WINNT\system32\runtime
2007-12-22 14:19 . 2007-12-22 17:18 d——– C:\Program Files\Norton Security Scan
2007-12-22 14:13 . 2007-12-23 13:34 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-22 14:12 . 2007-12-23 12:57 d——– C:\Program Files\Spyware Doctor
2007-12-22 14:12 . 2007-12-22 14:12 d——– C:\Documents and Settings\Mom\Application Data\PC Tools
2007-12-22 14:12 . 2005-09-23 07:29 626,688 –a—— C:\WINNT\system32\msvcr80.dll
2007-12-22 14:12 . 2007-10-04 17:10 79,688 –a—— C:\WINNT\system32\drivers\iksyssec.sys
2007-12-22 14:12 . 2007-10-04 17:10 62,280 –a—— C:\WINNT\system32\drivers\iksysflt.sys
2007-12-22 14:12 . 2007-10-04 17:10 41,288 –a—— C:\WINNT\system32\drivers\ikfilesec.sys
2007-12-22 14:12 . 2007-10-04 17:11 29,000 –a—— C:\WINNT\system32\drivers\kcom.sys
2007-12-22 14:05 . 2007-12-23 07:02 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-12-22 06:28 . 2007-12-22 17:16 992,049 –ahs—- C:\WINNT\system32\srrfjebb.ini
2007-12-22 05:45 . 2007-12-22 05:45 d–hs—- C:\found.005
2007-12-21 16:16 . 2007-12-21 16:16 0 –ah—– C:\WINNT\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-12-21 16:16 . 2007-12-21 16:16 0 –ah—– C:\WINNT\system32\drivers\Msft_Kernel_zumbus_01005.Wdf
2007-12-21 16:10 . 2007-12-21 16:10 d—-c— C:\WINNT\system32\DRVSTORE
2007-12-21 16:10 . 2007-12-22 15:02 d——– C:\Program Files\Zune
2007-12-20 15:21 . 2007-12-20 15:21 d——– C:\Documents and Settings\All Users\Application Data\Protexis
2007-12-20 15:21 . 2007-12-21 20:52 80 -r-hs—- C:\WINNT\system32\14A2C59260.dll
2007-12-20 15:19 . 2007-12-22 15:01 d——– C:\Program Files\Spy Cleaner Gold
2007-12-20 14:39 . 2007-12-20 14:39 d——– C:\Program Files\Trend Micro
2007-12-20 05:10 . 2007-12-21 06:24 946,866 –ahs—- C:\WINNT\system32\hcumjxre.ini
2007-12-19 04:55 . 2007-12-20 05:08 953,156 –ahs—- C:\WINNT\system32\swrjlryv.ini
2007-12-17 18:53 . 2007-12-19 04:53 971,331 –ahs—- C:\WINNT\system32\tcxplesi.ini
2007-12-16 17:58 . 2007-12-17 18:48 971,332 –ahs—- C:\WINNT\system32\dwkbpoln.ini
2007-12-14 18:00 . 2007-12-15 14:11 947,980 –ahs—- C:\WINNT\system32\yybfqbfx.ini
2007-12-13 17:59 . 2007-12-14 17:27 1,031,019 –ahs—- C:\WINNT\system32\uxadagwn.ini
2007-12-12 17:58 . 2007-12-13 17:17 934,416 –ahs—- C:\WINNT\system32\tlybdsfe.ini
2007-12-10 15:23 . 2007-12-11 17:02 991,684 –ahs—- C:\WINNT\system32\xlifslvv.ini
2007-12-09 15:45 . 2007-12-10 15:18 862,421 –ahs—- C:\WINNT\system32\vprheuoq.ini
2007-12-09 09:49 . 2007-10-06 15:03 74,608 –a—— C:\WINNT\TrueInstall.exe
2007-12-09 08:37 . 2007-12-11 08:00 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-09 08:36 . 2007-12-09 12:19 143 –a—— C:\WINNT\system32\mcrh.tmp
2007-12-09 08:24 . 2007-12-09 08:24 d——– C:\WINNT\McAfee.com
2007-12-08 12:23 . 2007-12-22 06:34 d——– C:\Documents and Settings\Mom\Shared
2007-12-08 12:23 . 2007-12-22 06:29 d——– C:\Documents and Settings\Mom\Incomplete
2007-12-08 12:22 . 2007-12-21 21:00 d——– C:\Documents and Settings\Mom\Application Data\LimeWire
2007-12-08 12:20 . 2007-12-11 08:13 d——– C:\Program Files\LimeWire
2007-12-08 12:18 . 2007-12-08 12:18 4,286 –a—— C:\WINNT\system32\MobileSidewalk.ico
2007-11-25 13:13 . 2007-11-25 13:13 d——– C:\Program Files\Netflix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 04:38 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-22 20:00 ——— d—–w C:\Program Files\TaxCut06
2007-12-22 19:21 ——— d—–w C:\Program Files\Google
2007-12-11 12:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-11 12:18 ——— d—–w C:\Program Files\Trillian
2007-12-11 12:16 ——— d—–w C:\Program Files\Microsoft Games
2007-12-11 12:08 ——— d—–w C:\Program Files\Comcast
2007-12-11 12:08 ——— d—–w C:\Documents and Settings\Mom\Application Data\Comcast
2007-12-09 14:53 ——— d—–w C:\Program Files\TrueSwitchComcast
2007-12-09 14:53 ——— d—–w C:\Documents and Settings\Mom\Application Data\TrueSwitch
2007-12-01 05:03 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-28 23:10 ——— d—–w C:\Documents and Settings\Travis\Application Data\U3
2007-11-18 03:29 ——— d—–w C:\Program Files\Common Files\AOL
2007-11-18 03:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-11-16 02:38 40,832 —-a-w C:\WINNT\system32\drivers\zumbus.sys
2007-11-13 10:25 20,480 —-a-w C:\WINNT\system32\drivers\secdrv.sys
2007-11-11 14:11 ——— d—–w C:\Program Files\IncrediMail
2007-11-11 14:08 ——— d—–w C:\Program Files\The Weather Channel FW
2007-11-11 13:43 ——— d—–w C:\Documents and Settings\Mom\Application Data\StumbleUpon
2007-11-10 22:53 ——— d—–w C:\Documents and Settings\Travis\Application Data\StumbleUpon
2007-11-10 00:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-11-10 00:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-27 11:40 ——— d—–w C:\Program Files\Java
2007-10-27 03:57 ——— d—–w C:\Documents and Settings\Dad\Application Data\StumbleUpon
2007-10-23 23:07 ——— d—–w C:\Documents and Settings\Mom\Application Data\Snapfish
2004-11-02 20:30 77,432 —-a-w C:\Documents and Settings\Mom\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 02:56]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 02:33]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-22 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 13:21]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-02 16:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"UserFaultCheck"="C:\WINNT\system32\dumprep 0 -u" []
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-15 21:51]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" []
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 02:33]

C:\Documents and Settings\Mom\Start Menu\Programs\Startup\
YouTube Uploader.lnk - C:\Documents and Settings\Mom\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe [2007-11-09 13:33:08]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-12-22 14:05:42]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R2 zumbus;Zune Bus Enumerator Driver;C:\WINNT\system32\DRIVERS\zumbus.sys [2007-11-15 21:38]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINNT\system32\ZuneBusEnum.exe [2007-11-15 21:51]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINNT\system32\ZuneWlanCfgSvc.exe [2007-11-15 21:51]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{129076a8-7673-11da-932d-9b645495d66c}]
\Shell\AutoRun\command - F:\SYNC.BAT

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e0ff17e-6719-11dc-8e5c-a3bfdd614efe}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd55e26c-9426-11db-8c17-b2d435a3617f}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f058dab9-5492-11db-8b75-d8a296f53b28}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f058daba-5492-11db-8b75-d8a296f53b28}]
\Shell\AutoRun\command - PortableApps\PortableAppsMenu\PortableAppsMenu.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-22 19:20:15 C:\WINNT\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-12-23 18:33:00 C:\WINNT\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-23 13:34:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-23 13:38:44 - machine was rebooted
.
2007-12-22 23:05:42 — E O F —


7-Zip 4.55 beta
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.1
Age of Empires III
Age of Empires III - The WarChiefs
CCleaner (remove only)
Desktop Doctor
Digimax Master
DogProxy II
DogProxy II Update
DoMore
DVD
Gateway Drivers and Applications Recovery
Google Photos Screensaver
Google Updater
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB926239)
InCD
Intel® 537EP Data Fax Modem
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet
iPod Update 2004-04-28
iTunes
Java 2 Runtime Environment, SE v1.4.2
Java™ 6 Update 2
Java™ 6 Update 3
Lexmark Skin: Helix
Lexmark Z600 Series
LimeWire PRO 4.14.12
Macromedia Extension Manager
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Office FrontPage 2003
Microsoft Office Professional Edition 2003
Microsoft Office Project Professional 2003
Microsoft Office XP Media Content
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Move Networks Media Player for Internet Explorer
Mozilla Firefox (2.0.0.11)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MySpaceIM
Netflix Movie Viewer
Norton Security Scan
oggcodecs 0.71.0946
Palm
PC-Doctor for Windows
Picasa 2
QuickTime
Rhapsody Player Engine
Samsung USB Driver
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
SplashPhoto
SplashShopper
Spybot - Search & Destroy 1.2
Spyware Doctor 5.1
Switch Uninstall
TaxCut Basic 2006
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
YouTube Uploader
Zune
Zune Language Pack (ES)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:43:31 PM, on 12/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\locator.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINNT\System32\svchost.exe
c:\WINNT\system32\ZuneBusEnum.exe
C:\WINNT\System32\alg.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Documents and Settings\Mom\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINNT\System32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet (User 'Default user')
O4 - Startup: YouTube Uploader.lnk = C:\Documents and Settings\Mom\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINNT\system32\GPhotos.scr/200
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download…ne_Inst_Win.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…181/mcfscan.cab
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 5708 bytes
Hi :)

Step 1

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINNT\system32\srrfjebb.ini
C:\WINNT\system32\14A2C59260.dll
C:\WINNT\system32\hcumjxre.ini
C:\WINNT\system32\swrjlryv.ini
C:\WINNT\system32\tcxplesi.ini
C:\WINNT\system32\dwkbpoln.ini
C:\WINNT\system32\yybfqbfx.ini
C:\WINNT\system32\uxadagwn.ini
C:\WINNT\system32\tlybdsfe.ini
C:\WINNT\system32\xlifslvv.ini
C:\WINNT\system32\vprheuoq.ini
C:\WINNT\system32\mcrh.tmp

Registry::

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"=-

DirLook::

C:\found.005

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 2

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s):

  • Java 2 Runtime Environment, SE v1.4.2
  • Java™ 6 Update 2

Step 3

Please do an online scan with Kaspersky WebScanner.

Click on Kaspersky Online Scanner. On the welcome screen, click Accept.

You will be promted to install an ActiveX component from Kaspersky, click Install.

  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded click on Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:

  • Scan using the following Anti-Virus database:

    Extended (if available, otherwise Standard)

  • Scan Options:

    Scan Archives
    Scan Mail Bases

  • Click OK.
  • Now under Select a Target to Scan:

    Select My Computer.

  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button and save the file to your desktop.

Step 4

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the Kaspersky Online Scan report
  • a new HijackThis log
Okay the Kaspersky file is very large, lots of items locked and therefore skipped…this normal?? In fact I can't send all of them together….I will try seperate posts for each
ComboFix 07-12-21.4 - Mom 2007-12-23 17:32:22.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mom\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINNT\system32\14A2C59260.dll
C:\WINNT\system32\dwkbpoln.ini
C:\WINNT\system32\hcumjxre.ini
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\srrfjebb.ini
C:\WINNT\system32\swrjlryv.ini
C:\WINNT\system32\tcxplesi.ini
C:\WINNT\system32\tlybdsfe.ini
C:\WINNT\system32\uxadagwn.ini
C:\WINNT\system32\vprheuoq.ini
C:\WINNT\system32\xlifslvv.ini
C:\WINNT\system32\yybfqbfx.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINNT\system32\14A2C59260.dll
C:\WINNT\system32\dwkbpoln.ini
C:\WINNT\system32\hcumjxre.ini
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\srrfjebb.ini
C:\WINNT\system32\swrjlryv.ini
C:\WINNT\system32\tcxplesi.ini
C:\WINNT\system32\tlybdsfe.ini
C:\WINNT\system32\uxadagwn.ini
C:\WINNT\system32\vprheuoq.ini
C:\WINNT\system32\xlifslvv.ini
C:\WINNT\system32\yybfqbfx.ini

.
((((((((((((((((((((((((( Files Created from 2007-11-23 to 2007-12-23 )))))))))))))))))))))))))))))))
.

2007-12-23 13:42 . 2007-12-23 13:42 d——– C:\Program Files\CCleaner
2007-12-23 06:54 . 2006-10-04 21:42 2,560 ——— C:\WINNT\system32\drivers\cdralw2k.sys
2007-12-23 06:54 . 2006-10-04 21:42 2,432 ——— C:\WINNT\system32\drivers\cdr4_xp.sys
2007-12-23 06:53 . 2007-12-23 06:55 d——– C:\Program Files\Picasa2
2007-12-22 17:00 . 2007-12-22 17:00 d——– C:\Documents and Settings\Mom\Application Data\Skype
2007-12-22 14:21 . 2007-12-22 14:21 d——– C:\WINNT\system32\runtime
2007-12-22 14:19 . 2007-12-22 17:18 d——– C:\Program Files\Norton Security Scan
2007-12-22 14:13 . 2007-12-23 17:29 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-22 14:12 . 2007-12-23 12:57 d——– C:\Program Files\Spyware Doctor
2007-12-22 14:12 . 2007-12-22 14:12 d——– C:\Documents and Settings\Mom\Application Data\PC Tools
2007-12-22 14:12 . 2005-09-23 07:29 626,688 –a—— C:\WINNT\system32\msvcr80.dll
2007-12-22 14:12 . 2007-10-04 17:10 79,688 –a—— C:\WINNT\system32\drivers\iksyssec.sys
2007-12-22 14:12 . 2007-10-04 17:10 62,280 –a—— C:\WINNT\system32\drivers\iksysflt.sys
2007-12-22 14:12 . 2007-10-04 17:10 41,288 –a—— C:\WINNT\system32\drivers\ikfilesec.sys
2007-12-22 14:12 . 2007-10-04 17:11 29,000 –a—— C:\WINNT\system32\drivers\kcom.sys
2007-12-22 14:05 . 2007-12-23 07:02 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-12-22 05:45 . 2007-12-22 05:45 d–hs—- C:\found.005
2007-12-21 16:16 . 2007-12-21 16:16 0 –ah—– C:\WINNT\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-12-21 16:16 . 2007-12-21 16:16 0 –ah—– C:\WINNT\system32\drivers\Msft_Kernel_zumbus_01005.Wdf
2007-12-21 16:10 . 2007-12-21 16:10 d—-c— C:\WINNT\system32\DRVSTORE
2007-12-21 16:10 . 2007-12-22 15:02 d——– C:\Program Files\Zune
2007-12-20 15:21 . 2007-12-20 15:21 d——– C:\Documents and Settings\All Users\Application Data\Protexis
2007-12-20 15:19 . 2007-12-22 15:01 d——– C:\Program Files\Spy Cleaner Gold
2007-12-20 14:39 . 2007-12-20 14:39 d——– C:\Program Files\Trend Micro
2007-12-09 09:49 . 2007-10-06 15:03 74,608 –a—— C:\WINNT\TrueInstall.exe
2007-12-09 08:37 . 2007-12-11 08:00 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-09 08:24 . 2007-12-09 08:24 d——– C:\WINNT\McAfee.com
2007-12-08 12:23 . 2007-12-22 06:34 d——– C:\Documents and Settings\Mom\Shared
2007-12-08 12:23 . 2007-12-22 06:29 d——– C:\Documents and Settings\Mom\Incomplete
2007-12-08 12:22 . 2007-12-21 21:00 d——– C:\Documents and Settings\Mom\Application Data\LimeWire
2007-12-08 12:20 . 2007-12-11 08:13 d——– C:\Program Files\LimeWire
2007-12-08 12:18 . 2007-12-08 12:18 4,286 –a—— C:\WINNT\system32\MobileSidewalk.ico
2007-11-25 13:13 . 2007-11-25 13:13 d——– C:\Program Files\Netflix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-23 04:38 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-22 20:00 ——— d—–w C:\Program Files\TaxCut06
2007-12-22 19:21 ——— d—–w C:\Program Files\Google
2007-12-11 12:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-11 12:18 ——— d—–w C:\Program Files\Trillian
2007-12-11 12:16 ——— d—–w C:\Program Files\Microsoft Games
2007-12-11 12:08 ——— d—–w C:\Program Files\Comcast
2007-12-11 12:08 ——— d—–w C:\Documents and Settings\Mom\Application Data\Comcast
2007-12-09 14:53 ——— d—–w C:\Program Files\TrueSwitchComcast
2007-12-09 14:53 ——— d—–w C:\Documents and Settings\Mom\Application Data\TrueSwitch
2007-12-01 05:03 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-28 23:10 ——— d—–w C:\Documents and Settings\Travis\Application Data\U3
2007-11-18 03:29 ——— d—–w C:\Program Files\Common Files\AOL
2007-11-18 03:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-11-16 02:51 80,288 —-a-w C:\WINNT\system32\ZuneIpTransport.dll
2007-11-16 02:51 72,608 —-a-w C:\WINNT\system32\ZuneUsbTransport.dll
2007-11-16 02:51 59,296 —-a-w C:\WINNT\system32\ZuneBusEnum.exe
2007-11-16 02:51 45,472 —-a-w C:\WINNT\system32\ZuneUsbConnection.dll
2007-11-16 02:51 245,664 —-a-w C:\WINNT\system32\ZuneWlanCfgSvc.exe
2007-11-16 02:51 155,552 —-a-w C:\WINNT\system32\ZuneMTPZ.dll
2007-11-16 02:38 40,832 —-a-w C:\WINNT\system32\drivers\zumbus.sys
2007-11-13 10:25 20,480 —-a-w C:\WINNT\system32\drivers\secdrv.sys
2007-11-11 14:11 ——— d—–w C:\Program Files\IncrediMail
2007-11-11 14:08 ——— d—–w C:\Program Files\The Weather Channel FW
2007-11-11 13:43 ——— d—–w C:\Documents and Settings\Mom\Application Data\StumbleUpon
2007-11-10 22:53 ——— d—–w C:\Documents and Settings\Travis\Application Data\StumbleUpon
2007-11-10 00:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-11-10 00:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-10-30 23:42 3,590,656 ——w C:\WINNT\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINNT\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINNT\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINNT\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINNT\system32\dllcache\wmasf.dll
2007-10-27 11:40 ——— d—–w C:\Program Files\Java
2007-10-27 03:57 ——— d—–w C:\Documents and Settings\Dad\Application Data\StumbleUpon
2007-10-26 03:34 8,460,288 —-a-w C:\WINNT\system32\dllcache\shell32.dll
2007-10-23 23:07 ——— d—–w C:\Documents and Settings\Mom\Application Data\Snapfish
2007-10-18 18:09 1,419,232 —-a-w C:\WINNT\system32\WdfCoInstaller01005.dll
2007-10-11 20:47 245,408 —-a-w C:\WINNT\system32\unicows.dll
2007-10-10 23:56 824,832 ——w C:\WINNT\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINNT\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ——w C:\WINNT\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ——w C:\WINNT\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINNT\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINNT\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINNT\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ——w C:\WINNT\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINNT\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINNT\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINNT\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINNT\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ——w C:\WINNT\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINNT\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINNT\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ——w C:\WINNT\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ——w C:\WINNT\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINNT\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ——w C:\WINNT\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINNT\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINNT\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINNT\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINNT\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINNT\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINNT\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINNT\system32\dllcache\ieakui.dll
2007-09-28 18:42 2,790,976 —-a-w C:\WINNT\system32\GPhotos.scr
2004-11-02 20:30 77,432 —-a-w C:\Documents and Settings\Mom\Application Data\GDIPFONTCACHEV1.DAT
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\found.005 —-

2007-12-15 06:49 43393 –a—— C:\found.005\dir0002.chk\l_cf618bc3b3275a2fc2b23552a69d8c92[1].jpg
2007-12-15 06:49 32862 –a—— C:\found.005\dir0000.chk\l_6313d395c5eb48f42bb3c2dec9aebd21[1].jpg
2007-12-15 06:49 28800 –a—— C:\found.005\dir0000.chk\l_db3b697433123273c0aa659d37ef64db[1].jpg
2007-12-15 06:49 26594 –a—— C:\found.005\dir0002.chk\l_caac1e2dd83669daff372baec78b4512[1].jpg
2007-12-15 06:49 24528 –a—— C:\found.005\dir0000.chk\l_8f6f8ef3b028e336fa027b9f7ac34d04[1].jpg
2007-12-15 06:49 23663 –a—— C:\found.005\dir0002.chk\l_b49d312830e20af0b05b92e93c9ff465[1].jpg
2007-12-15 06:49 21898 –a—— C:\found.005\dir0001.chk\l_b3bb0be33e687c7244a3137d8765ac7e[1].jpg
2007-12-15 06:49 21316 –a—— C:\found.005\dir0001.chk\l_75d0daa2c8cf5ed85d6d5ccfce52be05[1].jpg
2007-12-15 06:49 19801 –a—— C:\found.005\dir0000.chk\l_2c2c2945d95aab783edebbbc5b55332f[1].jpg
2007-12-15 06:49 17640 –a—— C:\found.005\dir0000.chk\l_cd6863204dc0b2af3904524ef6d9bb40[1].jpg
2007-12-15 06:49 13403 –a—— C:\found.005\dir0000.chk\l_776aae79bd4aac82dc0150c69d89d63a[1].jpg
2007-12-15 06:48 7083 –a—— C:\found.005\dir0000.chk\l_dc5d78ef6167c2feb905c86ff5afd31b[1].jpg
2007-12-15 06:48 4753 –a—— C:\found.005\dir0002.chk\l_deed23f84ee01e5f49d6ce09fa943502[1].jpg
2007-12-15 06:48 33846 –a—— C:\found.005\dir0002.chk\l_7439e2d56dfd0eba9145bc902e368b7e[1].jpg
2007-12-15 06:48 27959 –a—— C:\found.005\dir0001.chk\l_8babf453d9e9499b2810c10f02a2a627[1].jpg
2007-12-15 06:48 18799 –a—— C:\found.005\dir0002.chk\l_8bbfe91d9f201a14a696c6463b54e4d9[1].jpg


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 02:56]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 02:33]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-22 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 13:21]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-02 16:09]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2007-11-15 21:51]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" []
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-07 02:33]

C:\Documents and Settings\Mom\Start Menu\Programs\Startup\
YouTube Uploader.lnk - C:\Documents and Settings\Mom\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe [2007-11-09 13:33:08]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-12-22 14:05:42]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R2 zumbus;Zune Bus Enumerator Driver;C:\WINNT\system32\DRIVERS\zumbus.sys [2007-11-15 21:38]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINNT\system32\ZuneBusEnum.exe [2007-11-15 21:51]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINNT\system32\ZuneWlanCfgSvc.exe [2007-11-15 21:51]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{129076a8-7673-11da-932d-9b645495d66c}]
\Shell\AutoRun\command - F:\SYNC.BAT

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5e0ff17e-6719-11dc-8e5c-a3bfdd614efe}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd55e26c-9426-11db-8c17-b2d435a3617f}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f058dab9-5492-11db-8b75-d8a296f53b28}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f058daba-5492-11db-8b75-d8a296f53b28}]
\Shell\AutoRun\command - PortableApps\PortableAppsMenu\PortableAppsMenu.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-22 19:20:15 C:\WINNT\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-12-23 22:38:00 C:\WINNT\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-23 17:41:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-23 17:43:21
C:\ComboFix2.txt … 2007-12-23 13:38
.
2007-12-22 23:05:42 — E O F —
Hi :)

The file is too big and I can't send it…should those that are locked be unlocked?

The locked items probably belong to programs you were using while scanning with the Kaspersky online scan. We'll try to eliminate them:

Please download FixEdit.

  • Double-click on FixEdit.exe to open the program.
  • Go to File > Open, select the Kaspersky Online Scan report and click on Open.
  • Click on the Make Global Changes tab.
  • In the upper part (red lines), select Does NOT Contain the Test Key anywhere.
  • In the Test Key Text box, enter the text in the quotebox below:

    Object is locked skipped
  • Make sure Retain only the lines that pass the Test Parameter, Discard the Rest is checked.
  • Click OK.
  • Now, click on the Show/Edit Current Text tab. Your Kaspersky Online Scan report should be a lot shorter now. Go to File > SaveAs and save the file to your desktop.
  • Please post the contents of that file in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI