Thanks LD,
Script input and ran … results follow with new HJT log … will check some of the computer behaviors and report back to ya … will re-start and see what happens … thanks again for all your help.
Mouse
Oh yeah … PS: i noticed a new file (doc) appeared on the desktop (desktop.ini) … when attempting to remove it i received notice that it was a system file and should not be deleted … what is this, where did it come from and can i send it back ???
Also, noticed entries for ps2.exe … as i do NOT use this … should it be deleted ??
*** how many svchost.exe files are necessary ?? *** someone also mentioned to me that the version of Adobe Acrobat that is installed should be removed cause it is outdated and potentially dangerous … do you recommend removal???
ComboFix 08-02.05.3 - Owner 2008-02-11 18:42:00.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.297 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\WINDOWS\ALCXMNTR.EXE
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\WildTangent
C:\WINDOWS\ALCXMNTR.EXE
.
((((((((((((((((((((((((( Files Created from 2008-01-11 to 2008-02-11 )))))))))))))))))))))))))))))))
.
2008-02-06 06:21 . 2008-02-06 06:21 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-06 06:21 . 2008-02-06 06:21 d——– C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-02-06 06:21 . 2008-02-06 06:21 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-05 09:21 . 2002-07-31 23:28 81,920 –a—— C:\WINDOWS\system32\ps2.EXE
2008-01-29 20:08 . 2008-01-29 20:08 d——– C:\Program Files\Windows Defender
2008-01-29 16:06 . 2008-01-29 16:06 d——– C:\Program Files\CCleaner
2008-01-27 14:46 . 2008-01-27 14:46 d——– C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-01-27 14:45 . 2002-10-29 16:55 d——– C:\Documents and Settings\Administrator\WINDOWS
2008-01-27 14:45 . 2002-10-29 16:40 d——– C:\Documents and Settings\Administrator\Application Data\VERITAS
2008-01-27 14:45 . 2002-10-29 16:56 d——– C:\Documents and Settings\Administrator\Application Data\SampleView
2008-01-27 14:45 . 2002-10-29 16:48 d——– C:\Documents and Settings\Administrator\Application Data\InterTrust
2008-01-27 14:27 . 2008-01-27 14:27 d——– C:\Documents and Settings\Owner\Application Data\Grisoft
2008-01-27 14:26 . 2008-01-27 14:26 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-27 14:26 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-24 16:57 . 2008-01-24 16:57 0 –a—— C:\WINDOWS\nsreg.dat
2008-01-24 10:47 . 2008-01-24 10:47 d——– C:\Documents and Settings\Owner\Application Data\MailFrontier
2008-01-24 10:42 . 2008-02-11 18:45 3,094,816 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-24 10:42 . 2008-02-11 13:38 41,996 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-24 10:37 . 2007-11-14 16:05 75,248 –a—— C:\WINDOWS\zllsputility.exe
2008-01-24 10:36 . 2008-01-24 10:36 d——– C:\Program Files\Zone Labs
2008-01-24 10:36 . 2007-11-14 16:05 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2008-01-24 10:36 . 2008-02-11 17:34 355,091 –a—— C:\WINDOWS\system32\vsconfig.xml
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-30 10:44 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-01-30 00:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-29 11:19 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-29 11:19 ——— d—–w C:\Program Files\Logitech
2008-01-29 11:19 ——— d—–w C:\Program Files\Common Files\Logitech
2008-01-13 11:53 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
2008-01-09 15:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-01-09 15:25 ——— d—–w C:\Program Files\ZoneAlarmSB
2008-01-08 15:12 ——— d—–w C:\Program Files\Verizon
2008-01-08 15:12 ——— d—–w C:\Documents and Settings\Owner\Application Data\Verizon
2008-01-08 15:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\Verizon
2008-01-08 12:00 ——— d—–w C:\Program Files\HP
2008-01-08 12:00 ——— d—–w C:\Program Files\Hewlett-Packard
2008-01-08 11:59 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-31 11:59 ——— d—–w C:\Documents and Settings\Owner\Application Data\Image Zone Express
2007-12-29 11:05 ——— d—–w C:\Documents and Settings\Owner\Application Data\Template
2007-12-26 13:04 ——— d—–w C:\Program Files\MSXML 4.0
2007-12-23 14:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-23 14:33 ——— d—–w C:\Program Files\AWS
2007-12-23 02:33 ——— d—–w C:\Program Files\FinePixViewer
2007-12-23 02:25 ——— d—–w C:\Program Files\REGSHAVE
2007-12-23 02:12 ——— d—–w C:\Program Files\Common Files\HP
2007-12-23 02:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\HP
2007-12-23 01:48 ——— d—–w C:\Documents and Settings\Owner\Application Data\HP
2007-12-21 04:42 ——— d—–w C:\Documents and Settings\Owner\Application Data\Symantec
2007-12-18 18:14 ——— d—–w C:\Program Files\Common Files\Adobe
2007-12-18 02:19 3,468 –sha-r C:\WINDOWS\system32\drivers\HP_DA234A-ABA 6400nx NA910_YC_Pres_QMX250A_E31NAheRED4_4_IKM266-8235_S_V_BAM37307_T021128_WXH1_L409_M112_J40_7AMD_8Athlon XP 1800+_91.53_1_N10EC8139_P_Z_K_A11063059_U11063038_G53338D04_OCyberDrv CW058D CD-R RW_DDELD005.MRK
2007-12-18 02:13 ——— d—–w C:\Program Files\Encarta Online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-13 06:53 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BlockTracker"="c:\hp\bin\BlockTracker.exe" [ ]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-09-09 10:05 114688]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2002-10-29 16:41 151597]
"WCOLOREAL"="C:\Program Files\COMPAQ\Coloreal\coloreal.exe" [2002-02-20 22:40 143360]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 00:42 212992]
"AlcxMonitor"="ALCXMNTR.EXE" []
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32 53248]
"hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 16:31 80896]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05 919016]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-07-31 23:28 81920]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2002-09-20 22:20:02 53248]
S3 msCMTSrvc;Content Monitoring Tool;C:\WINDOWS\system32\msCMTSrvc.exe []
.
Contents of the 'Scheduled Tasks' folder
"2008-02-11 22:54:52 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-11 02:01:23 C:\WINDOWS\Tasks\WebReg Deskjet 3900 series.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-11 18:45:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-11 18:47:28
ComboFix-quarantined-files.txt 2008-02-11 23:46:44
ComboFix2.txt 2008-02-11 03:53:30
.
2008-01-09 16:23:06 — E O F —
Logfile of HijackThis v1.99.1
Scan saved at 6:49:46 PM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll
O3 - Toolbar: (no name) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - (no file)
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupd…b?1197953197663
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1198859641343
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe