This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Dropper Agent GIT and maybe more?

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, any help here would be appreciated! Running XP SP2, and appear to have gotten the Trojan dropper agent.GIT, and I think some other malware as well.
McAfee VS has kept things at bay, but this stuff is still there and would like to clean it out.

Here is Hijack This file - many thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 2:59:59 PM, on 01/16/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\WLTRAY .exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting .exe
C:\Program Files\LivePerson\hc.exe
C:\Applications\MSOffice\OFFICE11\OUTLOOK.EXE
C:\Applications\MSOffice\OFFICE11\WINWORD.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Applications\MSOffice\OFFICE11\EXCEL.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Applications\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting .exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LivePerson.lnk = C:\Program Files\LivePerson\hc.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\npjpi160_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\npjpi160_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Applications\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!

1. Download Combo fix from one of these locations.
* IMPORTANT !!! Place combofix.exe on your Desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt



______________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
Thanks!

Here is combofix log:

ComboFix 08-01-18.5 - acerveny 2008-01-18 11:23:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.215 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\acerveny\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\acerveny\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\acerveny\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\bwnbbpyp.ini
C:\WINDOWS\system32\dxtaltop.dll
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini2
C:\WINDOWS\system32\pypbbnwb.dll
C:\WINDOWS\system32\sdaheqtv.ini
C:\WINDOWS\system32\tohoxaiu.dll
C:\WINDOWS\system32\vtqehads.dll
C:\WINDOWS\system32\vtsqp.dll

.
((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.


Here is HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:43, on 2008-01-18
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting .exe
C:\Program Files\LivePerson\hc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Applications\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting .exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LivePerson.lnk = C:\Program Files\LivePerson\hc.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Applications\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


Thanks for help, let me know where to go next!
Sorry about that and the delay, here are logs as requested:

ComboFix 08-01-20.1 - acerveny 2008-01-21 10:02:20.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.201 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini2
C:\WINDOWS\system32\vtsqp.dll
.
—- Previous Run ——-
.
C:\Documents and Settings\acerveny\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\acerveny\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\acerveny\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\bwnbbpyp.ini
C:\WINDOWS\system32\dxtaltop.dll
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini2
C:\WINDOWS\system32\pypbbnwb.dll
C:\WINDOWS\system32\sdaheqtv.ini
C:\WINDOWS\system32\tohoxaiu.dll
C:\WINDOWS\system32\vtqehads.dll
C:\WINDOWS\system32\vtsqp.dll

.
((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-21 10:09 . 2008-01-21 10:09 336,384 ——— C:\WINDOWS\system32\vtsqp.dll
2008-01-21 10:09 . 2008-01-21 10:10 0 –ahs—- C:\WINDOWS\system32\pqstv.ini
2008-01-18 11:20 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-17 10:58 . 2008-01-17 10:58 d——– C:\Binaries
2008-01-17 10:54 . 2008-01-17 10:57 d——– C:\Program Files\ESM
2008-01-15 10:32 . 2008-01-15 10:32 593 –a—— C:\WINDOWS\system32\DWRCCMDError.ini
2008-01-15 09:54 . 2008-01-15 16:58 d——– C:\TEMP
2008-01-15 09:54 . 2008-01-15 09:54 d——– C:\Sun
2008-01-15 09:45 . 2008-01-15 09:51 d——– C:\Documents and Settings\acerveny.REALHEALTH\.SunDownloadManager
2008-01-12 22:49 . 2008-01-17 08:08 1,392,640 –a—— C:\WINDOWS\system32\WLTRAY .exe
2008-01-12 22:49 . 2008-01-12 22:49 118,784 –a—— C:\WINDOWS\system32\igfxpers .exe
2008-01-12 22:49 . 2008-01-12 22:49 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2008-01-12 22:49 . 2008-01-12 22:49 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2008-01-12 22:20 . 2008-01-12 22:58 40,448 –a—— C:\WINDOWS\system32\gebxxxy.dll
2008-01-12 22:19 . 2008-01-21 10:09 d——– C:\QUARANTINE
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Real
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\xing shared
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\Real
2007-12-24 09:58 . 2008-01-15 10:32 2,850 –a—— C:\WINDOWS\system32\DWRCS.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-21 18:09 ——— d—–w C:\Program Files\NetWaiting
2008-01-18 19:38 ——— d—–w C:\Program Files\LivePerson
2008-01-17 01:30 ——— d—–w C:\Program Files\Trillian
2008-01-16 00:04 ——— d—–w C:\Program Files\Java
2008-01-13 07:02 ——— d—–w C:\Program Files\QuickTime
2008-01-13 07:02 ——— d—–w C:\Program Files\Apoint
2007-11-14 07:26 450,560 ——w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 09:55 3,065,856 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 01:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 01:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-01-19 01:08 5,971,432 —-a-w C:\Program Files\Firefox Setup 2.0.0.1.exe
2007-01-19 00:31 5,274,776 —-a-w C:\Program Files\ps2pdf995.exe
2007-01-19 00:04 6,563,928 —-a-w C:\Program Files\cuteftp.exe
.
—-a-w		   136,768 2008-01-13 06:49:29  C:\Applications\Common Framework\UdaterUI .exe
—-a-w		   176,128 2008-01-13 06:49:05  C:\Program Files\Apoint\Apoint .exe
—-a-w		   185,896 2008-01-13 06:49:38  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			49,152 2008-01-13 06:49:21  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w			61,440 2008-01-13 06:49:53  C:\RECYCLER\S-1-5-21-1356091609-2353797385-2624897383-1611\Dc19\Dot1XCfg .exe
—-a-w			77,824 2008-01-13 06:49:37  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   118,784 2008-01-13 06:49:38  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2008-01-13 06:49:34  C:\WINDOWS\system32\igfxtray .exe
—-a-w		 1,392,640 2008-01-17 16:08:08  C:\WINDOWS\system32\WLTRAY .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B972C40C-F630-44A5-9D7D-CA577DF70B46}]
2008-01-21 10:09 336384 ——— C:\WINDOWS\system32\vtsqp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting .exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [ ]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 14:30 282624 C:\WINDOWS\stsystra.exe]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ShStatEXE"="C:\Applications\VScan\SHSTAT.exe" [2006-11-30 08:50 112216]
"McAfeeUpdaterUI"="C:\Applications\Common Framework\UdaterUI.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]

C:\Documents and Settings\acerveny.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34 5468160]

C:\Documents and Settings\benito.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34 5468160]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-01-18 21:39:00 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Cisco Systems VPN Client.lnk - C:\Applications\Cisco VPN\vpngui.exe [2007-01-15 09:27:28 1474576]
Palo Alto Software Update Manager 9.0.lnk - C:\WINDOWS\Installer\{6B2D979E-216D-43A4-BAE2-71A185922CA1}\NewShortcut1.BDD3527A_D6D6_4DD6_AEAD_6B5236DA8F67.exe [2007-06-21 13:38:52 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebxxxy]
gebxxxy.dll 2008-01-12 22:58 40448 C:\WINDOWS\system32\gebxxxy.dll

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\vtsqp.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vtsqp


.
Contents of the 'Scheduled Tasks' folder
"2007-02-12 17:33:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-21 10:09:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\vtsqp.dll
.
Completion time: 2008-01-21 10:12:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-21 18:12:41
.
2008-01-10 01:28:32 — E O F —


Logfile of HijackThis v1.99.1
Scan saved at 10:17, on 2008-01-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting .exe
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Applications\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting .exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\npjpi160_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\npjpi160_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Applications\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = ?


________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\vtsqp.exe

Renv::
C:\Applications\Common Framework\UdaterUI .exe
C:\Program Files\Apoint\Apoint .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\system32\WLTRAY .exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebxxxy]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.





___________________________________________
We now suggest that you install the Windows Recovery Console.
The Windows recovery console will allow you to boot up into a special recovery mode that allows us to help you in the case that your computer has a problem after an attempted removal of malware.


Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System

[external image: Posted Image]

Download the file & save it as it's originally named, to your desktop along with ComboFix.exe.


[external image: Posted Image]


Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it.
Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.

Please do not reboot your machine until we have reviewed the log.

_______________________________________________________


______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


_________________________________

Using Internet explorer (firefox will not work)
Please do an online scan with Kaspersky Online Scanner
Click accept on the first page.

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer


Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.




_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from CF_RC.txt
  • The report from comboFix
  • Do you know this domain ? >> realhealth.local <<
  • The report from Kasperskys
OK, here are logs as requested, following having done the above -

ISSUES TO NOTE:
- Combofix generated a zip file that then needed to be uploaded to BLEEPINGCOMPUTER for further analysis
- following the running of the WXP set up disks in Combofix i lost essential productivity and was forced to reboot (despite instructions not to)
- Yes I do recognize the domain realhealth.local as safe

HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 14:16, on 2008-01-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting .exe
C:\Program Files\LivePerson\hc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Applications\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting .exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LivePerson.lnk = C:\Program Files\LivePerson\hc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Applications\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


CF_RC
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

COMBOFIX

ComboFix 08-01-18.5 - acerveny 2008-01-23 10:31:27.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.210 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\acerveny.REALHEALTH\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\vtsqp.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini2
C:\WINDOWS\system32\vtsqp.dll

.
((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 )))))))))))))))))))))))))))))))
.

2008-01-23 10:40 . 2008-01-23 10:40 336,384 ——— C:\WINDOWS\system32\vtsqp.dll
2008-01-18 11:20 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-17 10:58 . 2008-01-17 10:58 d——– C:\Binaries
2008-01-17 10:54 . 2008-01-17 10:57 d——– C:\Program Files\ESM
2008-01-15 10:32 . 2008-01-15 10:32 593 –a—— C:\WINDOWS\system32\DWRCCMDError.ini
2008-01-15 09:54 . 2008-01-15 16:58 d——– C:\TEMP
2008-01-15 09:54 . 2008-01-15 09:54 d——– C:\Sun
2008-01-15 09:45 . 2008-01-15 09:51 d——– C:\Documents and Settings\acerveny.REALHEALTH\.SunDownloadManager
2008-01-12 22:20 . 2008-01-12 22:58 40,448 –a—— C:\WINDOWS\system32\gebxxxy.dll
2008-01-12 22:19 . 2008-01-23 10:40 d——– C:\QUARANTINE
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Real
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\xing shared
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\Real
2007-12-24 09:58 . 2008-01-15 10:32 2,850 –a—— C:\WINDOWS\system32\DWRCS.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-23 18:40 ——— d—–w C:\Program Files\NetWaiting
2008-01-23 18:40 ——— d—–w C:\Program Files\LivePerson
2008-01-23 18:31 ——— d—–w C:\Program Files\Apoint
2008-01-17 01:30 ——— d—–w C:\Program Files\Trillian
2008-01-16 00:04 ——— d—–w C:\Program Files\Java
2008-01-13 07:02 ——— d—–w C:\Program Files\QuickTime
2007-11-14 07:26 450,560 ——w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 09:55 3,065,856 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 01:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 01:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-01-19 01:08 5,971,432 —-a-w C:\Program Files\Firefox Setup 2.0.0.1.exe
2007-01-19 00:31 5,274,776 —-a-w C:\Program Files\ps2pdf995.exe
2007-01-19 00:04 6,563,928 —-a-w C:\Program Files\cuteftp.exe
.
—-a-w			61,440 2008-01-13 06:49:53  C:\RECYCLER\S-1-5-21-1356091609-2353797385-2624897383-1611\Dc19\Dot1XCfg .exe


((((((((((((((((((((((((((((( snapshot@2008-01-21_10.12.07.12 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 18:01:09 688,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-23 18:30:04 688,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-21 18:01:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-23 18:30:04 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-21 18:01:09 692,224 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-23 18:30:04 692,224 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-21 18:01:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-23 18:30:04 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-21 18:01:10 2,793,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-23 18:30:04 4,173,824 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-21 18:01:10 147,456 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-23 18:30:04 217,088 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-21 17:56:04 64,262 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-23 17:14:54 64,262 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-21 17:56:04 405,878 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-23 17:14:54 405,878 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2008-01-21 18:09:09 16,384 —-a-w C:\WINDOWS\TEMP\Cookies\index.dat
+ 2008-01-23 18:40:15 16,384 —-a-w C:\WINDOWS\TEMP\Cookies\index.dat
- 2008-01-21 18:09:09 16,384 —-a-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
+ 2008-01-23 18:40:15 16,384 —-a-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
- 2008-01-21 18:09:13 32,768 —-a-w C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-23 18:40:15 32,768 —-a-w C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D8E70DB4-B843-47A6-BB5E-99382D5726F7}]
2008-01-23 10:40 336384 ——— C:\WINDOWS\system32\vtsqp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting .exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [ ]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 14:30 282624 C:\WINDOWS\stsystra.exe]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ShStatEXE"="C:\Applications\VScan\SHSTAT.exe" [2006-11-30 08:50 112216]
"McAfeeUpdaterUI"="C:\Applications\Common Framework\UdaterUI.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]

C:\Documents and Settings\benito.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34]

C:\Documents and Settings\acerveny.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\vtsqp.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vtsqp


.
Contents of the 'Scheduled Tasks' folder
"2007-02-12 17:33:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-23 10:40:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\pqstv.ini 6514 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\vtsqp.dll
.
Completion time: 2008-01-23 10:43:26 - machine was rebooted [acerveny]
ComboFix-quarantined-files.txt 2008-01-23 18:43:19
ComboFix2.txt 2008-01-21 18:12:48
.
2008-01-10 01:28:32 — E O F —


KASPERSKY

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2008-01-23 14:10
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 23/01/2008
Kaspersky Anti-Virus database records: 528347
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
F:\
M:\
N:\
O:\
P:\
R:\
S:\
T:\
U:\
V:\
W:\

Scan Statistics:
Total number of scanned objects: 161366
Number of viruses found: 3
Number of infected objects: 8
Number of suspicious objects: 0
Duration of the scan process: 02:14:20

Infected Object Name / Virus Name / Last Action
C:\374606318cd2201c70b6153211d585cd\msxml4-KB927978-enu.log Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\Local Settings\Application Data\BVRP Software\NetWaiting\MoHlog.txt Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\Local Settings\History\History.IE5\MSHist012008012320080124\index.dat Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\Local Settings\Temporary Internet Files\Content.IE5\2SL5HTW7\bind[1].htm Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\acerveny.REALHEALTH\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\Agent_ADMIN2269LT.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\PrdMgr_ADMIN2269LT.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\AccessProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\BufferOverflowProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\LivePerson\PLog.txt Object is locked skipped
C:\Program Files\NetWaiting\netWaiting.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir/stream Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\000080.exe.vir NSIS: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP14\A0000587.exe Infected: Trojan-Downloader.Win32.Adload.pr skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP14\change.log Object is locked skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000010.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000010.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000010.exe NSIS: infected - 2 skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{2DC264DD-3A86-43CC-A65B-3B4425E8E53B}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\Cookies\index.dat Object is locked skipped
C:\WINDOWS\TEMP\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Let's run this again to be sure.
Looks as if 1 file is being stubborn.



Please do this first.

Right click on hijackthis.exe and choose rename:
Rename it to noname:


______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe


________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\vtsqp.exe
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\gebxxxy.dll
C:\WINDOWS\system32\vtsqp.dll



Registry::
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D8E70DB4-B843-47A6-BB5E-99382D5726F7}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebxxxy]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.

____________________________________



Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click OK.
Turn your computer back on.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.

_________________________
In your next reply I would like to see:
  • A new HJT log renamed
  • The report from ComboFix
  • The report from Vundo
ok this is getting quite vexing - here is the HJT file (note the vtsqp.exe file is back after fixing)

Logfile of HijackThis v1.99.1
Scan saved at 17:18, on 2008-01-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\DWRCST.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting .exe
C:\Program Files\LivePerson\hc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Applications\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting .exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LivePerson.lnk = C:\Program Files\LivePerson\hc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Applications\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


Here is combofix file:

ComboFix 08-01-18.5 - acerveny 2008-01-23 16:53:44.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.211 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\acerveny.REALHEALTH\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\gebxxxy.dll
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\vtsqp.dll
C:\WINDOWS\system32\vtsqp.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\gebxxxy.dll
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini2
C:\WINDOWS\system32\vtsqp.dll

.
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.

2008-01-23 17:00 . 2008-01-23 17:00 336,384 ——— C:\WINDOWS\system32\vtsqp.dll
2008-01-23 11:30 . 2008-01-23 11:30 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-23 11:30 . 2008-01-23 11:30 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-23 11:16 . 2008-01-23 11:16 d——– C:\Program Files\CCleaner
2008-01-23 10:53 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-23 10:53 . 2007-01-11 10:34 211 –a—— C:\Boot.bak
2008-01-18 11:20 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-17 10:58 . 2008-01-17 10:58 d——– C:\Binaries
2008-01-17 10:54 . 2008-01-17 10:57 d——– C:\Program Files\ESM
2008-01-15 10:32 . 2008-01-15 10:32 593 –a—— C:\WINDOWS\system32\DWRCCMDError.ini
2008-01-15 09:54 . 2008-01-15 16:58 d——– C:\TEMP
2008-01-15 09:54 . 2008-01-15 09:54 d——– C:\Sun
2008-01-15 09:45 . 2008-01-15 09:51 d——– C:\Documents and Settings\acerveny.REALHEALTH\.SunDownloadManager
2008-01-12 22:19 . 2008-01-23 17:00 d——– C:\QUARANTINE
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Real
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\xing shared
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\Real
2007-12-24 09:58 . 2008-01-15 10:32 2,850 –a—— C:\WINDOWS\system32\DWRCS.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 01:00 ——— d—–w C:\Program Files\NetWaiting
2008-01-24 01:00 ——— d—–w C:\Program Files\LivePerson
2008-01-23 18:31 ——— d—–w C:\Program Files\Apoint
2008-01-17 01:30 ——— d—–w C:\Program Files\Trillian
2008-01-16 00:04 ——— d—–w C:\Program Files\Java
2008-01-13 07:02 ——— d—–w C:\Program Files\QuickTime
2007-11-14 07:26 450,560 ——w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 09:55 3,065,856 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 01:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 01:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-01-19 01:08 5,971,432 —-a-w C:\Program Files\Firefox Setup 2.0.0.1.exe
2007-01-19 00:31 5,274,776 —-a-w C:\Program Files\ps2pdf995.exe
2007-01-19 00:04 6,563,928 —-a-w C:\Program Files\cuteftp.exe
.

((((((((((((((((((((((((((((( snapshot@2008-01-21_10.12.07.12 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 18:01:09 688,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-24 00:52:26 688,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-21 18:01:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-24 00:52:26 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-21 18:01:09 692,224 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-24 00:52:26 692,224 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-21 18:01:09 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-24 00:52:27 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-21 18:01:10 2,793,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-24 00:52:27 4,194,304 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-21 18:01:10 147,456 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-24 00:52:27 217,088 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2005-05-24 20:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 23:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 23:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-01-21 17:56:04 64,262 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-24 00:03:38 64,262 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-21 17:56:04 405,878 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-24 00:03:38 405,878 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2008-01-21 18:09:09 16,384 —-a-w C:\WINDOWS\TEMP\Cookies\index.dat
+ 2008-01-24 01:00:58 16,384 —-a-w C:\WINDOWS\TEMP\Cookies\index.dat
- 2008-01-21 18:09:09 16,384 —-a-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
+ 2008-01-24 01:00:58 16,384 —-a-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
- 2008-01-21 18:09:13 32,768 —-a-w C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-24 01:00:59 32,768 —-a-w C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8B123076-BF8B-4697-B77E-692473348FF0}]
2008-01-23 17:00 336384 ——— C:\WINDOWS\system32\vtsqp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting .exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [ ]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 14:30 282624 C:\WINDOWS\stsystra.exe]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ShStatEXE"="C:\Applications\VScan\SHSTAT.exe" [2006-11-30 08:50 112216]
"McAfeeUpdaterUI"="C:\Applications\Common Framework\UdaterUI.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]

C:\Documents and Settings\benito.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34]

C:\Documents and Settings\acerveny.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\vtsqp.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vtsqp


.
Contents of the 'Scheduled Tasks' folder
"2007-02-12 17:33:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-23 17:01:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\pqstv.ini 6514 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\vtsqp.dll
.
Completion time: 2008-01-23 17:04:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-24 01:04:06
ComboFix2.txt 2008-01-23 18:43:26
ComboFix3.txt 2008-01-21 18:12:48
.
2008-01-10 01:28:32 — E O F —


The Atribune site was not responding, so found VundoFix.exe at another source, downloaded and ran.
After running it said it found no files, when I clicked remove it said "no files found, VundoFix will now shut down"

Meanwhile MacAfee is still showing this stuff …

what next?
ok, renamed, here is log

Logfile of HijackThis v1.99.1
Scan saved at 17:50, on 2008-01-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\DWRCST.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting .exe
C:\Program Files\LivePerson\hc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\noname\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Applications\Spybot\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Applications\VScan\scriptcl.dll
O2 - BHO: (no name) - {8B123076-BF8B-4697-B77E-692473348FF0} - C:\WINDOWS\system32\vtsqp.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Applications\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting .exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LivePerson.lnk = C:\Program Files\LivePerson\hc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Applications\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
Let's try the big guns.

______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe



__________________________________
. Please download The Avenger by Swandog46 to your Desktop.

http://swandog46.geekstogo.com/avenger.zip



Click on Avenger.zip to open the file
Extract avenger.exe to your desktop

2. Copy all the text in bold contained in the code box below to your Clipboard by highlighting it and right clicking and then copy:

Files to delete:

C:\WINDOWS\system32\vtsqp.dll
C:\WINDOWS\system32\vtsqp.exe

Registry keys to delete:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D8E70DB4-B843-47A6-BB5E-99382D5726F7}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{44EDD236-D1F3-4D91-0F95-860D83FF8F5D}]

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, start The Avenger program by clicking on its icon on your desktop.
Under "Script file to execute" choose "Input Script Manually".
Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
Paste the text copied to clipboard into this window
Click Done
Now click on the Green Light to begin execution of the script
Answer "Yes" twice when prompted.

4. Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.) [*]On reboot, briefly open a black command window on your desktop, this is normal.
[*]After the restart, create a log file that should open with the results of Avenger's actions. This log file will be located at C:\avenger.txt
[*]The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of avenger.txt into your reply along with a fresh HJT log by using Add/Reply



_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Avenger.txt

grrr… ok, followed instructions, but don't think is good news….

HJT Log:


Logfile of HijackThis v1.99.1
Scan saved at 09:01, on 2008-01-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\DWRCST.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetWaiting\netWaiting .exe
C:\Program Files\LivePerson\hc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\noname\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Applications\Spybot\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Applications\VScan\scriptcl.dll
O2 - BHO: (no name) - {A7543F82-0FBA-4FD9-A2A9-2EE4E262721F} - C:\WINDOWS\system32\vtsqp.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Applications\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting .exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LivePerson.lnk = C:\Program Files\LivePerson\hc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Applications\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


AVENGER LOG

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\vjgtpxgi

*******************

Script file located at: \??\C:\Program Files\bwhinedq.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\vtsqp.dll deleted successfully.


File C:\WINDOWS\system32\vtsqp.exe not found!
Deletion of file C:\WINDOWS\system32\vtsqp.exe failed!

Could not process line:
C:\WINDOWS\system32\vtsqp.exe
Status: 0xc0000034



Could not open registry key [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D8E70DB4-B843-47A6-BB5E-99382D5726F7}] for deletion
Deletion of registry key [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D8E70DB4-B843-47A6-BB5E-99382D5726F7}] failed!
Status: 0xc000003b



Could not open registry key [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{44EDD236-D1F3-4D91-0F95-860D83FF8F5D}] for deletion
Deletion of registry key [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{44EDD236-D1F3-4D91-0F95-860D83FF8F5D}] failed!
Status: 0xc000003b


Completed script processing.

*******************

Finished! Terminate.
Ok I'm going for help on this.
In the meantime let me get you to run ComboFix once again and post a new log so I can confirm something.

Please delete the comboFix.exe you have now and let's make sure we have the latest version. It's updated often.

1. Download Combo fix from one of these locations. ( Please save it to your desktop )
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe


combofix.exe

2.Close all open windows
3. Double click combofix.exe & follow the prompts.
4. When finished, it shall produce a log for you. Post that log in your next reply . (c:\comboFix.txt)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combo fix in order to be effecient is going to disconect you from the internet. If when it is done and you can't get back on the internet just restart the computer.

______________________________

Just need the new log from ComboFix for now.
Ok, deleted old combofix, downloaded new. Lots of strange problems…. first time running combofix, makes it through reboot, but froze with blank desktop. Rebooted, reran combofix, at stage 3 McAfee goes nuts with on access scan messages, mostly .tmp files but also WIN.INI

After combofix forced reboot mouse freezes, log from combofix does generate.

Here is combofix log:

ComboFix 08-01-23.1B - acerveny 2008-01-24 11:34:35.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.184 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini2
C:\WINDOWS\system32\vtsqp.dll
.
—- Previous Run ——-
.
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini2
C:\WINDOWS\system32\vtsqp.dll

.
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.

2008-01-24 11:42 . 2008-01-24 11:42 336,384 ——— C:\WINDOWS\system32\vtsqp.dll
2008-01-24 11:42 . 2008-01-24 11:43 318 –ahs—- C:\WINDOWS\system32\pqstv.ini
2008-01-24 11:13 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\Nircmd.exe
2008-01-24 08:59 . 2008-01-24 08:59 0 –a—— C:\backup.reg
2008-01-24 08:57 . 2008-01-24 08:57 126,976 –a—— C:\zip.exe
2008-01-24 08:57 . 2008-01-24 08:57 292 –a—— C:\avexport.bat
2008-01-23 11:30 . 2008-01-23 11:30 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-23 11:16 . 2008-01-23 11:16 d——– C:\Program Files\CCleaner
2008-01-23 10:53 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-23 10:53 . 2007-01-11 10:34 211 –a—— C:\Boot.bak
2008-01-17 10:58 . 2008-01-17 10:58 d——– C:\Binaries
2008-01-17 10:54 . 2008-01-17 10:57 d——– C:\Program Files\ESM
2008-01-15 10:32 . 2008-01-15 10:32 593 –a—— C:\WINDOWS\system32\DWRCCMDError.ini
2008-01-15 10:19 . 2008-01-24 09:01 d——– C:\Program Files\noname
2008-01-15 09:54 . 2008-01-15 16:58 d——– C:\TEMP
2008-01-15 09:54 . 2008-01-15 09:54 d——– C:\Sun
2008-01-12 22:19 . 2008-01-24 11:42 d——– C:\QUARANTINE
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Real
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\xing shared
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\Real
2007-12-24 09:58 . 2008-01-15 10:32 2,850 –a—— C:\WINDOWS\system32\DWRCS.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 19:42 ——— d—–w C:\Program Files\NetWaiting
2008-01-24 19:42 ——— d—–w C:\Program Files\LivePerson
2008-01-23 18:31 ——— d—–w C:\Program Files\Apoint
2008-01-17 01:30 ——— d—–w C:\Program Files\Trillian
2008-01-16 00:04 ——— d—–w C:\Program Files\Java
2008-01-13 07:02 ——— d—–w C:\Program Files\QuickTime
2007-11-14 07:26 450,560 ——w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 09:55 3,065,856 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 01:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 01:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-01-19 01:08 5,971,432 —-a-w C:\Program Files\Firefox Setup 2.0.0.1.exe
2007-01-19 00:31 5,274,776 —-a-w C:\Program Files\ps2pdf995.exe
2007-01-19 00:04 6,563,928 —-a-w C:\Program Files\cuteftp.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{001A22EE-E54A-44B7-BBA2-043C933C8622}]
2008-01-24 11:42 336384 ——— C:\WINDOWS\system32\vtsqp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting .exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [ ]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 14:30 282624 C:\WINDOWS\stsystra.exe]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ShStatEXE"="C:\Applications\VScan\SHSTAT.exe" [2006-11-30 08:50 112216]
"McAfeeUpdaterUI"="C:\Applications\Common Framework\UdaterUI.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]

C:\Documents and Settings\benito.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34 5468160]

C:\Documents and Settings\acerveny.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34 5468160]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\vtsqp.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vtsqp


.
Contents of the 'Scheduled Tasks' folder
"2007-02-12 17:33:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-24 11:42:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\vtsqp.dll
.
Completion time: 2008-01-24 11:45:22 - machine was rebooted [acerveny]
ComboFix-quarantined-files.txt 2008-01-24 19:45:15
ComboFix2.txt 2008-01-24 01:04:13
.
2008-01-10 01:28:32 — E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI