This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] trojan?! help please

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have no idea whats going on..!!
2 weird icons on the desktop..fake help & support and windows update icons.
i have the same thing described in this thread on a different forum (http://www.bullguard.com/forum/10/Infected-computer-refusing-to-_57752.html)
i've ran adaware, search&destroy, avg (which i think is infected now!?), & dr web cureit.

pleaseeee help! :(



Logfile of HijackThis v1.99.1
Scan saved at 4:46:27 PM, on 1/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ctfmon.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/support/downloads/…amp;appindex=ds
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1A3C23DE-FDA4-4EAB-AE01-3D2C15867183} - C:\WINDOWS\system32\awvtu.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FA16FE06-B462-470E-9653-79C54B1871FF} - C:\WINDOWS\system32\fccdcbx.dll (file missing)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134969474508
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147219792931
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O20 - Winlogon Notify: fccdcbx - fccdcbx.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DVRMSFileWatcherService - - c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi jazzer36 and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Make sure to make a backup of any data that you have created, such as documents, pictures, music, ect… before we begin the fix.

Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I've ran search & destroy a few times since the inital post…There's a lot less going on from what I see..but my Zune software is still shot–encounters an error every time :(

Here's the log–


ComboFix 08-01-31.1 - Emily Z 2008-01-30 21:18:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.440 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\fhkmp.ini2
C:\WINDOWS\system32\gqicxnbu.dllbox
C:\WINDOWS\system32\ilnmp.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\onearcpg.dllbox
C:\WINDOWS\system32\prqss.ini2
C:\WINDOWS\system32\RCX38.tmp
C:\WINDOWS\system32\RCX3C.tmp
C:\WINDOWS\system32\utvwa.ini
C:\WINDOWS\system32\utvwa.ini2

—– BITS: Possible infected sites —–

hxxp://resources.zune.net

.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.

2008-01-28 22:15 . 2008-01-28 22:16 d——– C:\Documents and Settings\Mike Z\Application Data\AVG7
2008-01-28 16:11 . 2008-01-28 16:11 d——– C:\Documents and Settings\Emily Z\DoctorWeb
2008-01-28 16:07 . 2008-01-28 16:07 d——– C:\Program Files\Windows Live
2008-01-28 16:07 . 2008-01-28 16:08 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-28 16:07 . 2008-01-28 16:10 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-28 16:04 . 2008-01-28 16:04 d——– C:\Documents and Settings\Emily Z\Application Data\acccore
2008-01-28 16:03 . 2008-01-28 16:04 d——– C:\Program Files\AIM6
2008-01-27 21:43 . 2008-01-27 21:43 d——– C:\Program Files\SpywareBlaster
2008-01-27 21:43 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-01-27 19:16 . 2008-01-27 23:39 d——– C:\Documents and Settings\Emily Z\Application Data\AVG7
2008-01-27 19:15 . 2008-01-27 19:15 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-27 19:15 . 2008-01-30 21:14 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-27 18:58 . 2008-01-11 17:39 145,408 –a—— C:\WINDOWS\system32\ZuneMTPZ.dll
2008-01-27 18:58 . 2008-01-11 17:39 70,656 –a—— C:\WINDOWS\system32\ZuneIpTransport.dll
2008-01-27 18:58 . 2008-01-11 17:39 62,464 –a—— C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-01-27 18:58 . 2008-01-11 17:39 35,840 –a—— C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-01-27 18:36 . 2008-01-28 07:37 659,456 –a—— C:\WINDOWS\system32\hphmon06 .exe
2008-01-27 18:36 . 2008-01-28 07:37 90,112 –a—— C:\WINDOWS\UpdReg .EXE
2008-01-27 17:24 . 2008-01-27 17:24 d——– C:\Program Files\NoteWorthy Composer
2008-01-26 16:16 . 2008-01-27 17:22 d——– C:\Program Files\Lenogo DVD to Zune Converter
2008-01-25 19:53 . 2008-01-25 19:53 348,160 –a—— C:\WINDOWS\system32\RCXB54.tmp
2008-01-22 23:23 . 2008-01-25 20:43 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-22 23:23 . 2008-01-22 23:23 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-11 17:54 . 2008-01-11 17:54 245,664 –a—— C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2008-01-11 17:54 . 2008-01-11 17:54 61,856 –a—— C:\WINDOWS\system32\ZuneBusEnum.exe
2008-01-10 17:07 . 2008-01-10 17:07 d——– C:\Program Files\Lavasoft
2008-01-10 17:06 . 2008-01-27 21:50 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-10 16:19 . 2008-01-27 17:27 d——– C:\Documents and Settings\Emily Z\.housecall6.6
2008-01-08 20:13 . 2008-01-08 20:13 d——– C:\Program Files\Aimersoft
2008-01-08 20:13 . 2008-01-08 20:13 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-08 19:41 . 2008-01-28 07:37 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-02 18:14 . 2008-01-02 18:14 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-19 20:51 . 2007-12-19 20:51 d——– C:\Program Files\PlayFirst
2007-12-14 11:32 . 2007-12-14 11:32 12,632 –a—— C:\WINDOWS\system32\lsdelete.exe
2007-12-09 13:17 . 2007-10-10 17:55 6,065,664 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-09 13:17 . 2007-04-17 03:32 2,455,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-09 13:17 . 2007-03-07 23:10 991,232 ——— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-09 13:17 . 2007-10-10 17:55 459,264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-09 13:17 . 2007-10-10 17:55 383,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-09 13:17 . 2007-10-10 17:55 267,776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-09 13:17 . 2007-10-10 17:55 63,488 ——— C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-09 13:17 . 2007-10-10 17:55 52,224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-09 13:17 . 2007-10-10 04:59 13,824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-09 10:42 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2007-12-09 10:41 . 2007-12-09 10:41 d——– C:\Documents and Settings\Mathew Z\Contacts
2007-12-03 20:20 . 2007-12-03 20:20 d——– C:\Program Files\Disney

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 03:25 ——— d—–w C:\Program Files\SymNetDrv
2008-01-29 06:18 ——— d—–w C:\Program Files\Symantec
2008-01-29 06:18 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-29 06:14 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-29 06:12 ——— d—–w C:\Program Files\Norton Internet Security
2008-01-29 05:44 ——— d—–w C:\Program Files\Mpeg2Decoder
2008-01-28 22:13 ——— d—–w C:\Program Files\Zune
2008-01-28 22:13 ——— d—–w C:\Program Files\iTunes
2008-01-28 22:13 ——— d—–w C:\Program Files\Dell Support
2008-01-28 22:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-28 22:03 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-28 21:59 ——— d—–w C:\Program Files\BitTorrent
2008-01-28 21:58 ——— d—–w C:\Program Files\MSN Messenger
2008-01-28 21:57 ——— d—–w C:\Program Files\WildGames
2008-01-28 21:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-28 13:37 ——— d—–w C:\Program Files\QuickTime
2008-01-28 03:49 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 23:25 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-21 16:33 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\BitTorrent
2008-01-21 15:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-11 23:39 40,832 —-a-w C:\WINDOWS\system32\drivers\zumbus.sys
2008-01-09 02:13 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\uTorrent
2008-01-09 01:36 ——— d—–w C:\Program Files\Yahoo!
2007-12-15 04:33 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\AdobeUM
2007-12-09 16:42 ——— d—–w C:\Program Files\Java
2007-10-01 15:26 13,012 —-a-w C:\Documents and Settings\Mathew Z\Bubblets.dat
2007-09-20 04:00 722,176 —-a-w C:\Documents and Settings\Mike Z\gotomypc_428.exe
2007-08-27 02:26 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2005-12-20 01:02 251 —-a-w C:\Program Files\wt3d.ini
.
—-a-w		   344,064 2008-01-28 13:37:37  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w			81,920 2008-01-28 13:37:43  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-28 13:37:42  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w			49,824 2008-01-28 13:37:45  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			45,056 2008-01-28 13:37:39  C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET .EXE
—-a-w			57,344 2008-01-28 13:37:38  C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol .exe
—-a-w			53,248 2008-01-28 13:37:40  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   395,776 2008-01-28 13:38:03  C:\Program Files\Dell Support\DSAgnt .exe
—-a-w		   579,072 2008-01-28 13:37:55  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-28 13:37:50  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 .exe
—-a-w		   139,264 2008-01-28 13:37:37  C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe
—-a-w		   221,184 2008-01-28 13:37:38  C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
—-a-w		   229,952 2008-01-28 13:37:53  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-28 13:37:35  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		 1,694,208 2008-01-28 02:18:45  C:\Program Files\Messenger\msmsgs .exe
—-a-w		 5,674,352 2008-01-28 13:38:16  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		   282,624 2008-01-28 13:37:41  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   657,920 2008-01-28 13:35:54  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,460,560 2008-01-28 13:38:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   100,056 2008-01-28 13:37:53  C:\Program Files\SymNetDrv\SNDMon .exe
—-a-w		   166,304 2008-01-28 13:37:54  C:\Program Files\Zune\ZuneLauncher .exe
—-a-w			90,112 2008-01-28 13:37:42  C:\WINDOWS\UpdReg .EXE
—-a-w			15,360 2008-01-03 00:14:44  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   659,456 2008-01-28 13:37:52  C:\WINDOWS\system32\hphmon06 .exe
—-a-w		   127,035 2008-01-28 13:37:43  C:\WINDOWS\system32\dla\tfswctrl .exe
—-a-w		   172,032 2008-01-28 13:37:46  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A3C23DE-FDA4-4EAB-AE01-3D2C15867183}]
C:\WINDOWS\system32\awvtu.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent .exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 10:15 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"CTHelper"="CTHELPER.EXE" [2004-03-11 14:50 28672 C:\WINDOWS\system32\CTHELPER.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-28 07:37 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]

C:\Documents and Settings\Mike Z\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2002-08-09 17:36:20 299008]

C:\Documents and Settings\Emily Z\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 11:57:16 2913584]

C:\Documents and Settings\Mathew Z\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-01-02 18:14:37 575488]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-07-30 01:52:00 217195]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\digital imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-01-04 18:18:27 724992]
Wireless USB 2.0 WLAN Card Utility.lnk - C:\Program Files\Dell Wireless\PRISMCFG.exe [2005-09-03 16:31:02 917611]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccdcbx]
fccdcbx.dll

R2 DVRMSFileWatcherService;DVRMSFileWatcherService;c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe [2007-02-27 20:53]
R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-10 04:00]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 15:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 17:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 17:54]
R3 Angel;Angel MPEG Device;C:\WINDOWS\system32\DRIVERS\Angel.sys [2005-02-24 23:20]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2004-11-02 14:12]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 17:54]
S4 PRISMSVC;PRISMSVC;C:\WINDOWS\system32\PRISMSVC.EXE [2004-10-04 13:12]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{884f971f-9572-11dc-aff0-0014a535f203}]
\Shell\AutoRun\command - F:\RCAMemoryMgr.exe
\Shell\Manage your videos\command - F:\RCAMemoryMgr.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 01:37:00 C:\WINDOWS\Tasks\HP Usg Daily FY04.job"
- c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe
"2008-01-31 01:46:12 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 21:29:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-01-30 21:36:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-31 03:36:14
.
2008-01-28 09:10:31 — E O F —

I've ran search & destroy a few times since the inital post..There's a lot less going on from what I see..but my Zune software is still shot–encounters an error every time sad.gif

Yes, much has been fixed but we still have work to do. I imagine you have many programs that are not working correctly right now. You have the new file infecting Vundo trojan that replaces legit. exe files, causing programs to fail. We will attempt to restore whatever we can but you may need to either re-install or repair some programs after. We will do our best to restore them before doing that though.

On with the fix as there is still much to do. Please don't run any other tools until instructed to do so.


1. Please open Notepad
  • Click Start ,then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

RenV::
—-a-w		   344,064 2008-01-28 13:37:37  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w			81,920 2008-01-28 13:37:43  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-28 13:37:42  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w			49,824 2008-01-28 13:37:45  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			45,056 2008-01-28 13:37:39  C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET .EXE
—-a-w			57,344 2008-01-28 13:37:38  C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol .exe
—-a-w			53,248 2008-01-28 13:37:40  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   395,776 2008-01-28 13:38:03  C:\Program Files\Dell Support\DSAgnt .exe
—-a-w		   579,072 2008-01-28 13:37:55  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-28 13:37:50  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 .exe
—-a-w		   139,264 2008-01-28 13:37:37  C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe
—-a-w		   221,184 2008-01-28 13:37:38  C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
—-a-w		   229,952 2008-01-28 13:37:53  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-28 13:37:35  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		 1,694,208 2008-01-28 02:18:45  C:\Program Files\Messenger\msmsgs .exe
—-a-w		 5,674,352 2008-01-28 13:38:16  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		   282,624 2008-01-28 13:37:41  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   657,920 2008-01-28 13:35:54  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,460,560 2008-01-28 13:38:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   100,056 2008-01-28 13:37:53  C:\Program Files\SymNetDrv\SNDMon .exe
—-a-w		   166,304 2008-01-28 13:37:54  C:\Program Files\Zune\ZuneLauncher .exe
—-a-w			90,112 2008-01-28 13:37:42  C:\WINDOWS\UpdReg .EXE
—-a-w			15,360 2008-01-03 00:14:44  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   659,456 2008-01-28 13:37:52  C:\WINDOWS\system32\hphmon06 .exe
—-a-w		   127,035 2008-01-28 13:37:43  C:\WINDOWS\system32\dla\tfswctrl .exe
—-a-w		   172,032 2008-01-28 13:37:46  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 .exe

File::
C:\WINDOWS\system32\awvtu.dll
C:\WINDOWS\system32\fccdcbx.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A3C23DE-FDA4-4EAB-AE01-3D2C15867183}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccdcbx]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
ComboFix 08-01-31.1 - Emily Z 2008-02-03 1:27:16.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.578 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Emily Z\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\awvtu.dll
C:\WINDOWS\system32\fccdcbx.dll
.

((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.

2008-01-31 21:23 . 2008-01-31 21:23 d——– C:\Program Files\MSECache
2008-01-28 22:15 . 2008-01-28 22:16 d——– C:\Documents and Settings\Mike Z\Application Data\AVG7
2008-01-28 16:11 . 2008-01-28 16:11 d——– C:\Documents and Settings\Emily Z\DoctorWeb
2008-01-28 16:07 . 2008-01-28 16:07 d——– C:\Program Files\Windows Live
2008-01-28 16:07 . 2008-01-28 16:08 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-28 16:07 . 2008-01-28 16:10 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-28 16:04 . 2008-01-28 16:04 d——– C:\Documents and Settings\Emily Z\Application Data\acccore
2008-01-28 16:03 . 2008-01-28 16:04 d——– C:\Program Files\AIM6
2008-01-27 21:43 . 2008-01-27 21:43 d——– C:\Program Files\SpywareBlaster
2008-01-27 21:43 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-01-27 19:16 . 2008-01-27 23:39 d——– C:\Documents and Settings\Emily Z\Application Data\AVG7
2008-01-27 19:15 . 2008-01-27 19:15 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-27 19:15 . 2008-01-30 21:14 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-27 18:58 . 2008-01-11 17:39 145,408 –a—— C:\WINDOWS\system32\ZuneMTPZ.dll
2008-01-27 18:58 . 2008-01-11 17:39 70,656 –a—— C:\WINDOWS\system32\ZuneIpTransport.dll
2008-01-27 18:58 . 2008-01-11 17:39 62,464 –a—— C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-01-27 18:58 . 2008-01-11 17:39 35,840 –a—— C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-01-27 18:36 . 2008-01-28 07:37 659,456 –a—— C:\WINDOWS\system32\hphmon06 .exe
2008-01-27 18:36 . 2008-01-28 07:37 90,112 –a—— C:\WINDOWS\UpdReg .EXE
2008-01-27 17:24 . 2008-01-27 17:24 d——– C:\Program Files\NoteWorthy Composer
2008-01-26 16:16 . 2008-01-27 17:22 d——– C:\Program Files\Lenogo DVD to Zune Converter
2008-01-25 19:53 . 2008-01-25 19:53 348,160 –a—— C:\WINDOWS\system32\RCXB54.tmp
2008-01-22 23:23 . 2008-01-25 20:43 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-22 23:23 . 2008-01-22 23:23 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-11 17:54 . 2008-01-11 17:54 245,664 –a—— C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2008-01-11 17:54 . 2008-01-11 17:54 61,856 –a—— C:\WINDOWS\system32\ZuneBusEnum.exe
2008-01-10 17:07 . 2008-01-10 17:07 d——– C:\Program Files\Lavasoft
2008-01-10 17:06 . 2008-01-27 21:50 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-10 16:19 . 2008-01-27 17:27 d——– C:\Documents and Settings\Emily Z\.housecall6.6
2008-01-08 20:13 . 2008-01-08 20:13 d——– C:\Program Files\Aimersoft
2008-01-08 20:13 . 2008-01-08 20:13 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-08 19:41 . 2008-01-28 07:37 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 03:25 ——— d—–w C:\Program Files\SymNetDrv
2008-01-29 06:18 ——— d—–w C:\Program Files\Symantec
2008-01-29 06:18 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-29 06:14 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-29 06:12 ——— d—–w C:\Program Files\Norton Internet Security
2008-01-29 05:44 ——— d—–w C:\Program Files\Mpeg2Decoder
2008-01-28 22:13 ——— d—–w C:\Program Files\Zune
2008-01-28 22:13 ——— d—–w C:\Program Files\iTunes
2008-01-28 22:13 ——— d—–w C:\Program Files\Dell Support
2008-01-28 22:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-28 22:03 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-28 21:59 ——— d—–w C:\Program Files\BitTorrent
2008-01-28 21:58 ——— d—–w C:\Program Files\MSN Messenger
2008-01-28 21:57 ——— d—–w C:\Program Files\WildGames
2008-01-28 21:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-28 13:37 ——— d—–w C:\Program Files\QuickTime
2008-01-28 03:49 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 23:25 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-22 21:20 1,014,272 —-a-w C:\WINDOWS\system32\hphmon06(2).exe
2008-01-21 16:33 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\BitTorrent
2008-01-21 15:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-11 23:39 40,832 —-a-w C:\WINDOWS\system32\drivers\zumbus.sys
2008-01-09 02:13 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\uTorrent
2008-01-09 01:36 ——— d—–w C:\Program Files\Yahoo!
2008-01-03 00:14 15,360 —-a-w C:\WINDOWS\system32\ctfmon .exe
2007-12-20 02:51 ——— d—–w C:\Program Files\PlayFirst
2007-12-15 04:33 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\AdobeUM
2007-12-14 17:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-09 16:42 ——— d—–w C:\Program Files\Java
2007-12-04 02:20 ——— d—–w C:\Program Files\Disney
2007-12-01 00:16 1,419,232 —-a-w C:\WINDOWS\system32\WdfCoInstaller01005.dll
2007-11-09 23:26 21,840 —-atw C:\WINDOWS\system32\SIntfNT.dll
2007-11-09 23:26 17,212 —-atw C:\WINDOWS\system32\SIntf32.dll
2007-11-09 23:26 12,067 —-atw C:\WINDOWS\system32\SIntf16.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-01 15:26 13,012 —-a-w C:\Documents and Settings\Mathew Z\Bubblets.dat
2007-09-20 04:00 722,176 —-a-w C:\Documents and Settings\Mike Z\gotomypc_428.exe
2007-08-27 02:26 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2005-12-20 01:02 251 —-a-w C:\Program Files\wt3d.ini
2004-08-10 10:00 1,431,144 —-a-w C:\WINDOWS\inf\SET59F5.tmp
.
—-a-w		   344,064 2008-01-28 13:37:37  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w			81,920 2008-01-28 13:37:43  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-28 13:37:42  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w			49,824 2008-01-28 13:37:45  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			45,056 2008-01-28 13:37:39  C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET .EXE
—-a-w			57,344 2008-01-28 13:37:38  C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol .exe
—-a-w			53,248 2008-01-28 13:37:40  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   395,776 2008-01-28 13:38:03  C:\Program Files\Dell Support\DSAgnt .exe
—-a-w		   579,072 2008-01-28 13:37:55  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-28 13:37:50  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 .exe
—-a-w		   139,264 2008-01-28 13:37:37  C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe
—-a-w		   221,184 2008-01-28 13:37:38  C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
—-a-w		   229,952 2008-01-28 13:37:53  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-28 13:37:35  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		 1,694,208 2008-01-28 02:18:45  C:\Program Files\Messenger\msmsgs .exe
—-a-w		 5,674,352 2008-01-28 13:38:16  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		   282,624 2008-01-28 13:37:41  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   657,920 2008-01-28 13:35:54  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,460,560 2008-01-28 13:38:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   100,056 2008-01-28 13:37:53  C:\Program Files\SymNetDrv\SNDMon .exe
—-a-w		   166,304 2008-01-28 13:37:54  C:\Program Files\Zune\ZuneLauncher .exe
—-a-w			90,112 2008-01-28 13:37:42  C:\WINDOWS\UpdReg .EXE
—-a-w			15,360 2008-01-03 00:14:44  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   659,456 2008-01-28 13:37:52  C:\WINDOWS\system32\hphmon06 .exe
—-a-w		   127,035 2008-01-28 13:37:43  C:\WINDOWS\system32\dla\tfswctrl .exe
—-a-w		   172,032 2008-01-28 13:37:46  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent .exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 10:15 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"CTHelper"="CTHELPER.EXE" [2004-03-11 14:50 28672 C:\WINDOWS\system32\CTHELPER.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-28 07:37 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]

C:\Documents and Settings\Mathew Z\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-01-02 18:14:37 575488]

C:\Documents and Settings\Mike Z\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2002-08-09 17:36:20 299008]

C:\Documents and Settings\Emily Z\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 11:57:16 2913584]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-07-30 01:52:00 217195]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\digital imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-01-04 18:18:27 724992]
Wireless USB 2.0 WLAN Card Utility.lnk - C:\Program Files\Dell Wireless\PRISMCFG.exe [2005-09-03 16:31:02 917611]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R2 DVRMSFileWatcherService;DVRMSFileWatcherService;c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe [2007-02-27 20:53]
R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-10 04:00]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 15:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 17:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 17:54]
R3 Angel;Angel MPEG Device;C:\WINDOWS\system32\DRIVERS\Angel.sys [2005-02-24 23:20]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2004-11-02 14:12]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 17:54]
S4 PRISMSVC;PRISMSVC;C:\WINDOWS\system32\PRISMSVC.EXE [2004-10-04 13:12]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{884f971f-9572-11dc-aff0-0014a535f203}]
\Shell\AutoRun\command - F:\RCAMemoryMgr.exe
\Shell\Manage your videos\command - F:\RCAMemoryMgr.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-03 05:37:00 C:\WINDOWS\Tasks\HP Usg Daily FY04.job"
- c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe
"2008-02-03 05:46:13 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 01:32:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\WinRAR\rarext.dll
.
Completion time: 2008-02-03 1:33:11
ComboFix-quarantined-files.txt 2008-02-03 07:32:44
ComboFix2.txt 2008-01-31 03:36:18
.
2008-01-28 09:10:31 — E O F —


___________________


Logfile of HijackThis v1.99.1
Scan saved at 1:37:38 AM, on 2/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/support/downloads/…amp;appindex=ds
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134969474508
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147219792931
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A572AAF-EC0B-4773-AC2B-1E8DC1500772}: NameServer = 192.168.5.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{2A572AAF-EC0B-4773-AC2B-1E8DC1500772}: NameServer = 192.168.5.1
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DVRMSFileWatcherService - - c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi, There was a bug with some versions of combofix that prevented the renv section from working. Can you please delete your current version from the desktop and download a fresh copy. Then re-run the same script. Thanks
ComboFix 08-01-31.1 - Emily Z 2008-01-30 21:18:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.440 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\fhkmp.ini2
C:\WINDOWS\system32\gqicxnbu.dllbox
C:\WINDOWS\system32\ilnmp.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\onearcpg.dllbox
C:\WINDOWS\system32\prqss.ini2
C:\WINDOWS\system32\RCX38.tmp
C:\WINDOWS\system32\RCX3C.tmp
C:\WINDOWS\system32\utvwa.ini
C:\WINDOWS\system32\utvwa.ini2

—– BITS: Possible infected sites —–

hxxp://resources.zune.net

.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.

2008-01-28 22:15 . 2008-01-28 22:16 d——– C:\Documents and Settings\Mike Z\Application Data\AVG7
2008-01-28 16:11 . 2008-01-28 16:11 d——– C:\Documents and Settings\Emily Z\DoctorWeb
2008-01-28 16:07 . 2008-01-28 16:07 d——– C:\Program Files\Windows Live
2008-01-28 16:07 . 2008-01-28 16:08 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-28 16:07 . 2008-01-28 16:10 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-28 16:04 . 2008-01-28 16:04 d——– C:\Documents and Settings\Emily Z\Application Data\acccore
2008-01-28 16:03 . 2008-01-28 16:04 d——– C:\Program Files\AIM6
2008-01-27 21:43 . 2008-01-27 21:43 d——– C:\Program Files\SpywareBlaster
2008-01-27 21:43 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-01-27 19:16 . 2008-01-27 23:39 d——– C:\Documents and Settings\Emily Z\Application Data\AVG7
2008-01-27 19:15 . 2008-01-27 19:15 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-27 19:15 . 2008-01-30 21:14 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-27 18:58 . 2008-01-11 17:39 145,408 –a—— C:\WINDOWS\system32\ZuneMTPZ.dll
2008-01-27 18:58 . 2008-01-11 17:39 70,656 –a—— C:\WINDOWS\system32\ZuneIpTransport.dll
2008-01-27 18:58 . 2008-01-11 17:39 62,464 –a—— C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-01-27 18:58 . 2008-01-11 17:39 35,840 –a—— C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-01-27 18:36 . 2008-01-28 07:37 659,456 –a—— C:\WINDOWS\system32\hphmon06 .exe
2008-01-27 18:36 . 2008-01-28 07:37 90,112 –a—— C:\WINDOWS\UpdReg .EXE
2008-01-27 17:24 . 2008-01-27 17:24 d——– C:\Program Files\NoteWorthy Composer
2008-01-26 16:16 . 2008-01-27 17:22 d——– C:\Program Files\Lenogo DVD to Zune Converter
2008-01-25 19:53 . 2008-01-25 19:53 348,160 –a—— C:\WINDOWS\system32\RCXB54.tmp
2008-01-22 23:23 . 2008-01-25 20:43 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-22 23:23 . 2008-01-22 23:23 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-11 17:54 . 2008-01-11 17:54 245,664 –a—— C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2008-01-11 17:54 . 2008-01-11 17:54 61,856 –a—— C:\WINDOWS\system32\ZuneBusEnum.exe
2008-01-10 17:07 . 2008-01-10 17:07 d——– C:\Program Files\Lavasoft
2008-01-10 17:06 . 2008-01-27 21:50 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-10 16:19 . 2008-01-27 17:27 d——– C:\Documents and Settings\Emily Z\.housecall6.6
2008-01-08 20:13 . 2008-01-08 20:13 d——– C:\Program Files\Aimersoft
2008-01-08 20:13 . 2008-01-08 20:13 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-08 19:41 . 2008-01-28 07:37 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-02 18:14 . 2008-01-02 18:14 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-19 20:51 . 2007-12-19 20:51 d——– C:\Program Files\PlayFirst
2007-12-14 11:32 . 2007-12-14 11:32 12,632 –a—— C:\WINDOWS\system32\lsdelete.exe
2007-12-09 13:17 . 2007-10-10 17:55 6,065,664 ——— C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-09 13:17 . 2007-04-17 03:32 2,455,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-09 13:17 . 2007-03-07 23:10 991,232 ——— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-09 13:17 . 2007-10-10 17:55 459,264 ——— C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-09 13:17 . 2007-10-10 17:55 383,488 ——— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-09 13:17 . 2007-10-10 17:55 267,776 ——— C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-09 13:17 . 2007-10-10 17:55 63,488 ——— C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-09 13:17 . 2007-10-10 17:55 52,224 ——— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-09 13:17 . 2007-10-10 04:59 13,824 ——— C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-09 10:42 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2007-12-09 10:41 . 2007-12-09 10:41 d——– C:\Documents and Settings\Mathew Z\Contacts
2007-12-03 20:20 . 2007-12-03 20:20 d——– C:\Program Files\Disney

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 03:25 ——— d—–w C:\Program Files\SymNetDrv
2008-01-29 06:18 ——— d—–w C:\Program Files\Symantec
2008-01-29 06:18 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-29 06:14 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-29 06:12 ——— d—–w C:\Program Files\Norton Internet Security
2008-01-29 05:44 ——— d—–w C:\Program Files\Mpeg2Decoder
2008-01-28 22:13 ——— d—–w C:\Program Files\Zune
2008-01-28 22:13 ——— d—–w C:\Program Files\iTunes
2008-01-28 22:13 ——— d—–w C:\Program Files\Dell Support
2008-01-28 22:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-28 22:03 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-28 21:59 ——— d—–w C:\Program Files\BitTorrent
2008-01-28 21:58 ——— d—–w C:\Program Files\MSN Messenger
2008-01-28 21:57 ——— d—–w C:\Program Files\WildGames
2008-01-28 21:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-28 13:37 ——— d—–w C:\Program Files\QuickTime
2008-01-28 03:49 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 23:25 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-21 16:33 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\BitTorrent
2008-01-21 15:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-11 23:39 40,832 —-a-w C:\WINDOWS\system32\drivers\zumbus.sys
2008-01-09 02:13 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\uTorrent
2008-01-09 01:36 ——— d—–w C:\Program Files\Yahoo!
2007-12-15 04:33 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\AdobeUM
2007-12-09 16:42 ——— d—–w C:\Program Files\Java
2007-10-01 15:26 13,012 —-a-w C:\Documents and Settings\Mathew Z\Bubblets.dat
2007-09-20 04:00 722,176 —-a-w C:\Documents and Settings\Mike Z\gotomypc_428.exe
2007-08-27 02:26 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2005-12-20 01:02 251 —-a-w C:\Program Files\wt3d.ini
.
—-a-w		   344,064 2008-01-28 13:37:37  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w			81,920 2008-01-28 13:37:43  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-28 13:37:42  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w			49,824 2008-01-28 13:37:45  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			45,056 2008-01-28 13:37:39  C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET .EXE
—-a-w			57,344 2008-01-28 13:37:38  C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol .exe
—-a-w			53,248 2008-01-28 13:37:40  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   395,776 2008-01-28 13:38:03  C:\Program Files\Dell Support\DSAgnt .exe
—-a-w		   579,072 2008-01-28 13:37:55  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-28 13:37:50  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 .exe
—-a-w		   139,264 2008-01-28 13:37:37  C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe
—-a-w		   221,184 2008-01-28 13:37:38  C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
—-a-w		   229,952 2008-01-28 13:37:53  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-28 13:37:35  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		 1,694,208 2008-01-28 02:18:45  C:\Program Files\Messenger\msmsgs .exe
—-a-w		 5,674,352 2008-01-28 13:38:16  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		   282,624 2008-01-28 13:37:41  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   657,920 2008-01-28 13:35:54  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,460,560 2008-01-28 13:38:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   100,056 2008-01-28 13:37:53  C:\Program Files\SymNetDrv\SNDMon .exe
—-a-w		   166,304 2008-01-28 13:37:54  C:\Program Files\Zune\ZuneLauncher .exe
—-a-w			90,112 2008-01-28 13:37:42  C:\WINDOWS\UpdReg .EXE
—-a-w			15,360 2008-01-03 00:14:44  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   659,456 2008-01-28 13:37:52  C:\WINDOWS\system32\hphmon06 .exe
—-a-w		   127,035 2008-01-28 13:37:43  C:\WINDOWS\system32\dla\tfswctrl .exe
—-a-w		   172,032 2008-01-28 13:37:46  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A3C23DE-FDA4-4EAB-AE01-3D2C15867183}]
C:\WINDOWS\system32\awvtu.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 04:00 15360]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent .exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-03 10:15 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"CTHelper"="CTHELPER.EXE" [2004-03-11 14:50 28672 C:\WINDOWS\system32\CTHELPER.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-28 07:37 282624]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]

C:\Documents and Settings\Mike Z\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2002-08-09 17:36:20 299008]

C:\Documents and Settings\Emily Z\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 11:57:16 2913584]

C:\Documents and Settings\Mathew Z\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-01-02 18:14:37 575488]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-07-30 01:52:00 217195]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\digital imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-01-04 18:18:27 724992]
Wireless USB 2.0 WLAN Card Utility.lnk - C:\Program Files\Dell Wireless\PRISMCFG.exe [2005-09-03 16:31:02 917611]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccdcbx]
fccdcbx.dll

R2 DVRMSFileWatcherService;DVRMSFileWatcherService;c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe [2007-02-27 20:53]
R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-10 04:00]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 15:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 17:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 17:54]
R3 Angel;Angel MPEG Device;C:\WINDOWS\system32\DRIVERS\Angel.sys [2005-02-24 23:20]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2004-11-02 14:12]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 17:54]
S4 PRISMSVC;PRISMSVC;C:\WINDOWS\system32\PRISMSVC.EXE [2004-10-04 13:12]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{884f971f-9572-11dc-aff0-0014a535f203}]
\Shell\AutoRun\command - F:\RCAMemoryMgr.exe
\Shell\Manage your videos\command - F:\RCAMemoryMgr.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 01:37:00 C:\WINDOWS\Tasks\HP Usg Daily FY04.job"
- c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe
"2008-01-31 01:46:12 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 21:29:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-01-30 21:36:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-31 03:36:14
.
2008-01-28 09:10:31 — E O F —



___________________________________________________________



Logfile of HijackThis v1.99.1
Scan saved at 11:56:46 PM, on 2/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Zune\ZuneLauncher .exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aim6 .exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/support/downloads/…amp;appindex=ds
F3 - REG:win.ini: load=C:\WINDOWS\system32\awvtu.exe
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [24d38e9e] rundll32.exe "C:\WINDOWS\system32\sjrmwopj.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134969474508
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147219792931
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2B17EEE-FF68-437A-B73D-5B20BC0072AD}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DVRMSFileWatcherService - - c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Looks like you were completely reinfected again. Let's give this another go.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

RenV::
—-a-w		   344,064 2008-01-28 13:37:37  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w			81,920 2008-01-28 13:37:43  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   221,184 2008-01-28 13:37:42  C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
—-a-w			49,824 2008-01-28 13:37:45  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			45,056 2008-01-28 13:37:39  C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET .EXE
—-a-w			57,344 2008-01-28 13:37:38  C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol .exe
—-a-w			53,248 2008-01-28 13:37:40  C:\Program Files\CyberLink\PowerDVD\DVDLauncher .exe
—-a-w		   395,776 2008-01-28 13:38:03  C:\Program Files\Dell Support\DSAgnt .exe
—-a-w		   579,072 2008-01-28 13:37:55  C:\Program Files\Grisoft\AVG7\avgcc .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   241,664 2008-01-28 13:37:50  C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
—-a-w			49,152 2008-01-28 13:37:48  C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06 .exe
—-a-w		   139,264 2008-01-28 13:37:37  C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif .exe
—-a-w		   221,184 2008-01-28 13:37:38  C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
—-a-w		   229,952 2008-01-28 13:37:53  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-28 13:37:35  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		 1,694,208 2008-01-28 02:18:45  C:\Program Files\Messenger\msmsgs .exe
—-a-w		 5,674,352 2008-01-28 13:38:16  C:\Program Files\MSN Messenger\MsnMsgr .Exe
—-a-w		   282,624 2008-01-28 13:37:41  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   657,920 2008-01-28 13:35:54  C:\Program Files\QuickTime\qttask .exe
—-a-w		 1,460,560 2008-01-28 13:38:06  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		   100,056 2008-01-28 13:37:53  C:\Program Files\SymNetDrv\SNDMon .exe
—-a-w		   166,304 2008-01-28 13:37:54  C:\Program Files\Zune\ZuneLauncher .exe
—-a-w			90,112 2008-01-28 13:37:42  C:\WINDOWS\UpdReg .EXE
—-a-w			15,360 2008-01-03 00:14:44  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   659,456 2008-01-28 13:37:52  C:\WINDOWS\system32\hphmon06 .exe
—-a-w		   127,035 2008-01-28 13:37:43  C:\WINDOWS\system32\dla\tfswctrl .exe
—-a-w		   172,032 2008-01-28 13:37:46  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11 .exe

File::
C:\WINDOWS\system32\awvtu.dll
C:\WINDOWS\system32\fccdcbx.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A3C23DE-FDA4-4EAB-AE01-3D2C15867183}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccdcbx]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
so this is infecting my aim6 and windows live messenger also, correct? I reinstalled them because they never work after combofix…how smart of me…ha

any way to get them back without the trojan?





ComboFix 08-02.03.1 - Emily Z 2008-02-05 16:09:20.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.585 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Emily Z\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\awvtu.dll
C:\WINDOWS\system32\fccdcbx.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\awvtu.dll
C:\WINDOWS\system32\awvtu.exe
C:\WINDOWS\system32\cgvcvavf.dll
C:\WINDOWS\system32\gnskrrmo.dll
C:\WINDOWS\system32\gnskrrmo.dllbox
C:\WINDOWS\system32\jpowmrjs.ini
C:\WINDOWS\system32\sjrmwopj.dll
C:\WINDOWS\system32\utvwa.ini
C:\WINDOWS\system32\utvwa.ini2
C:\WINDOWS\system32\wnxdlvny.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-05 to 2008-02-05 )))))))))))))))))))))))))))))))
.

2008-02-04 21:27 . 2008-02-04 21:27 d——– C:\Documents and Settings\All Users\Application Data\Dell
2008-02-04 20:58 . 2008-02-05 16:09 d——– C:\Program Files\MSN Messenger
2008-02-04 20:58 . 2008-02-04 20:58 d——– C:\Documents and Settings\Emily Z\Application Data\acccore
2008-02-04 20:57 . 2008-02-05 16:13 d——– C:\Program Files\AIM6
2008-02-03 22:26 . 2008-02-05 16:09 d——– C:\Program Files\Zune
2008-01-31 21:23 . 2008-01-31 21:23 d——– C:\Program Files\MSECache
2008-01-28 22:15 . 2008-01-28 22:16 d——– C:\Documents and Settings\Mike Z\Application Data\AVG7
2008-01-28 16:11 . 2008-01-28 16:11 d——– C:\Documents and Settings\Emily Z\DoctorWeb
2008-01-28 16:07 . 2008-01-28 16:07 d——– C:\Program Files\Windows Live
2008-01-28 16:07 . 2008-01-28 16:08 d–hsc— C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-28 16:07 . 2008-01-28 16:10 d——– C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-27 21:43 . 2008-01-27 21:43 d——– C:\Program Files\SpywareBlaster
2008-01-27 21:43 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-01-27 19:16 . 2008-01-27 23:39 d——– C:\Documents and Settings\Emily Z\Application Data\AVG7
2008-01-27 19:15 . 2008-01-27 19:15 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-27 19:15 . 2008-01-30 21:14 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-27 18:58 . 2008-01-11 17:39 145,408 –a—— C:\WINDOWS\system32\ZuneMTPZ.dll
2008-01-27 18:58 . 2008-01-11 17:39 70,656 –a—— C:\WINDOWS\system32\ZuneIpTransport.dll
2008-01-27 18:58 . 2008-01-11 17:39 62,464 –a—— C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-01-27 18:58 . 2008-01-11 17:39 35,840 –a—— C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-01-27 18:36 . 2008-01-28 07:37 659,456 –a—— C:\WINDOWS\system32\hphmon06.exe
2008-01-27 18:36 . 2008-01-28 07:37 90,112 –a—— C:\WINDOWS\UpdReg.EXE
2008-01-27 17:24 . 2008-01-27 17:24 d——– C:\Program Files\NoteWorthy Composer
2008-01-26 16:16 . 2008-01-27 17:22 d——– C:\Program Files\Lenogo DVD to Zune Converter
2008-01-25 19:53 . 2008-01-25 19:53 348,160 –a—— C:\WINDOWS\system32\RCXB54.tmp
2008-01-22 23:23 . 2008-02-03 02:41 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-22 23:23 . 2008-01-22 23:23 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-11 17:54 . 2008-01-11 17:54 245,664 –a—— C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2008-01-11 17:54 . 2008-01-11 17:54 61,856 –a—— C:\WINDOWS\system32\ZuneBusEnum.exe
2008-01-10 17:07 . 2008-01-10 17:07 d——– C:\Program Files\Lavasoft
2008-01-10 17:06 . 2008-01-27 21:50 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-10 16:19 . 2008-01-27 17:27 d——– C:\Documents and Settings\Emily Z\.housecall6.6
2008-01-08 20:13 . 2008-01-08 20:13 d——– C:\Program Files\Aimersoft
2008-01-08 20:13 . 2008-01-08 20:13 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-08 19:41 . 2008-02-04 12:57 d——– C:\Program Files\Spybot - Search & Destroy
2008-01-08 19:41 . 2008-01-28 07:37 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 22:09 ——— d—–w C:\Program Files\Dell Support
2008-02-05 02:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-04 19:01 ——— d—–w C:\Program Files\QuickTime
2008-02-04 18:57 ——— d—–w C:\Program Files\SymNetDrv
2008-02-04 18:57 ——— d—–w C:\Program Files\iTunes
2008-02-04 18:57 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-29 06:18 ——— d—–w C:\Program Files\Symantec
2008-01-29 06:14 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-29 06:12 ——— d—–w C:\Program Files\Norton Internet Security
2008-01-29 05:44 ——— d—–w C:\Program Files\Mpeg2Decoder
2008-01-28 22:03 ——— d—–w C:\Program Files\Common Files\AOL
2008-01-28 21:59 ——— d—–w C:\Program Files\BitTorrent
2008-01-28 21:57 ——— d—–w C:\Program Files\WildGames
2008-01-28 21:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-28 03:49 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 23:25 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-21 16:33 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\BitTorrent
2008-01-21 15:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-11 23:39 40,832 —-a-w C:\WINDOWS\system32\drivers\zumbus.sys
2008-01-09 02:13 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\uTorrent
2008-01-09 01:36 ——— d—–w C:\Program Files\Yahoo!
2007-12-20 02:51 ——— d—–w C:\Program Files\PlayFirst
2007-12-15 04:33 ——— d—–w C:\Documents and Settings\Emily Z\Application Data\AdobeUM
2007-12-09 16:42 ——— d—–w C:\Program Files\Java
2007-10-01 15:26 13,012 —-a-w C:\Documents and Settings\Mathew Z\Bubblets.dat
2007-09-20 04:00 722,176 —-a-w C:\Documents and Settings\Mike Z\gotomypc_428.exe
2007-08-27 02:26 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2005-12-20 01:02 251 —-a-w C:\Program Files\wt3d.ini
.
—-a-w		   575,488 2008-02-05 03:17:20  C:\Documents and Settings\Mathew Z\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
—-a-w			50,528 2008-02-05 05:33:16  C:\Program Files\AIM6\aim6 .exe
—-a-w		   350,053 2008-02-04 00:49:58  C:\Program Files\SlySoft\AnyDVD\AnyDVD .exe
—-a-w		   166,304 2008-01-28 13:37:54  C:\RECYCLER\S-1-5-21-3155914777-3104542651-628290857-1008\Dc10015\ZuneLauncher .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-02 18:14 15360]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent .exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:56 64512]
"CTHelper"="CTHELPER.EXE" [2004-03-11 14:50 28672 C:\WINDOWS\system32\CTHELPER.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-02-04 22:35 166304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]

C:\Documents and Settings\Mathew Z\Start Menu\Programs\Startup\
PowerReg Scheduler V3 .exe [2008-02-04 21:17:20 575488]
PowerReg Scheduler V3.exe [2008-02-03 20:07:56 575488]

C:\Documents and Settings\Mike Z\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2002-08-09 17:36:20 299008]

C:\Documents and Settings\Emily Z\Start Menu\Programs\Startup\
Yahoo! Widget Engine.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe [2007-07-20 11:57:16 2913584]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-07-30 01:52:00 217195]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\digital imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-01-04 18:18:27 724992]
Wireless USB 2.0 WLAN Card Utility.lnk - C:\Program Files\Dell Wireless\PRISMCFG.exe [2005-09-03 16:31:02 917611]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R2 DVRMSFileWatcherService;DVRMSFileWatcherService;c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe [2007-02-27 20:53]
R2 NwSapAgent;SAP Agent;C:\WINDOWS\system32\svchost.exe [2004-08-10 04:00]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 15:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 17:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 17:54]
R3 Angel;Angel MPEG Device;C:\WINDOWS\system32\DRIVERS\Angel.sys [2005-02-24 23:20]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2004-11-02 14:12]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 17:54]
S4 PRISMSVC;PRISMSVC;C:\WINDOWS\system32\PRISMSVC.EXE [2004-10-04 13:12]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{884f971f-9572-11dc-aff0-0014a535f203}]
\Shell\AutoRun\command - F:\RCAMemoryMgr.exe
\Shell\Manage your videos\command - F:\RCAMemoryMgr.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-05 21:37:00 C:\WINDOWS\Tasks\HP Usg Daily FY04.job"
- c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe
"2008-02-05 21:46:11 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-05 16:24:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2008-02-05 16:30:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-05 22:30:49
ComboFix2.txt 2008-02-05 01:45:44
ComboFix3.txt 2008-02-03 07:33:12
ComboFix4.txt 2008-01-31 03:36:18
.
2008-01-28 09:10:31 — E O F —




_____________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 4:31:46 PM, on 2/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/support/downloads/…amp;appindex=ds
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134969474508
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147219792931
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2B17EEE-FF68-437A-B73D-5B20BC0072AD}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DVRMSFileWatcherService - - c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Well looks like we got the infection that time any way…

so this is infecting my aim6 and windows live messenger also, correct? I reinstalled them because they never work after combofix…how smart of me…ha

any way to get them back without the trojan?

That's what the renv:: section of combofix is trying to do, get legit programs back. But sometimes that is not possible with this file infecter. So yes, you have to re-install the programs.

Let's continue…

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.
the log was too big to post–i just uploaded it, it seemed easier.

http://www.freewebs.com/emilygeog/report.txt

and hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 4:01:30 PM, on 2/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/support/downloads/…amp;appindex=ds
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/2…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134969474508
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147219792931
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DVRMSFileWatcherService - - c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Some of your valid programs still have infected .exe files. You will likely need to re-install the programs and we need to remove the files.

We need to make sure all hidden files are showing so please:
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.


Using Windows Explorer delete the following files:

C:\Documents and Settings\Mathew Zniewski\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Mathew Zniewski\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
C:\Program Files\Dell Support\DSAgnt(2).exe
C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06(2).exe
C:\Program Files\iTunes\iTunesHelper(2).exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\ehome\ehtray.exe.tmp
C:\WINDOWS\system32\dla\tfswctrl(2).exe
C:\WINDOWS\system32\hphmon06(2).exe
C:\WINDOWS\system32\RCXB54.tmp


So it looks like you will need to re-install the following:

Dell support software
Itunes
Quicktime
AnyDVD

The rest are probably not needed and/or will not affect anything.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Update Java Runtime:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 4.
  • Go to the Sun Java Website
  • Click on the download button next to Java Runtime Environment (JRE) 6 Update 4
  • Select your Operating System and language, then check the box next to I agree to the Java SE Runtime Environment 6 License Agreement and click Continue.
  • Click on the link under Windows Offline Installation and save the downloaded file to your hard disk.
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 2 Runtime Environment, JRE or JSE)
  • Reboot your computer
  • Delete the folder C:\Program Files\Java if present
  • Install the new version by running the newly-downloaded file, and follow the on-screen instructions.
  • Reboot your computer

Post a new Hijackthis log and let me know how it's running.
Everything seems much better. Is it okay for me to reinstall AIM and Windows Live Messenger? Or will it reinfect? Also, any ideas on how to fix the Zune program? I'm going to try from the startup disc this time…




Logfile of HijackThis v1.99.1
Scan saved at 7:44:44 PM, on 2/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://support.dell.com/support/downloads/…amp;appindex=ds
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent .exe" –force_start_minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/2…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1134969474508
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147219792931
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DVRMSFileWatcherService - - c:\program files\dvrmstoolbox\dvrmsfilewatcherservice.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

Is it okay for me to reinstall AIM and Windows Live Messenger?
Or will it reinfect?

You should be fine to re-install those or any other programs you need to.

Also, any ideas on how to fix the Zune program?

You will probably need to either re-install or repair install it. I assume you have the disk for it? You may also need to uninstall it first using Add or Remove Programs. Then do a new install.

Let me know how you make out.
Dave
Ok, the Windows Live and AIM messengers are fine….But I got the original Zune disc and re-installed it, of course it was the old version, and when it tried to update I ended up with the same error message :( any other ideas? Thanks soooooo much for your help!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI