This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Stumped on Virus

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all. I would appreciate some help.

Having some issues with virii/trojans. Ran Kaspersky AntiVirus and SpyBot. Still having problems. Very slow computer right now. I just restarted and ran HijackThis.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:27:07 PM, on 2/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\?ecurity\?serinit.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\WINDOWS\System32\hkcmd .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Zune\ZuneLauncher .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\WINDOWS\System32\logon.scr
C:\Documents and Settings\Mary\Desktop\HiJackThis.exe
C:\WINDOWS\PPPATC~1\spool32.exe
C:\WINDOWS\PPPATC~1\spool32 .exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [042cf1bd] rundll32.exe "C:\WINDOWS\system32\tswrgrre.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\PPPATC~1\spool32.exe" -vt ndrv
O4 - HKCU\..\Run: [Dcftjyh] C:\WINDOWS\?ecurity\?serinit.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303307750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303296640
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://clubgames.pogo.com/online2/pogop/be…aploader_v6.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7709 bytes


Once again, any help is most appreciated.

Did I do this wrong?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:40:19 PM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\hkcmd .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\Program Files\Zune\ZuneLauncher .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Documents and Settings\Mary\Desktop\HiJackThis.exe
C:\WINDOWS\PPPATC~1\spool32.exe
C:\WINDOWS\PPPATC~1\spool32 .exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [042cf1bd] rundll32.exe "C:\WINDOWS\system32\lptxjxst.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\PPPATC~1\spool32.exe" -vt ndrv
O4 - HKCU\..\Run: [Dcftjyh] C:\WINDOWS\?ecurity\?serinit.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303307750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303296640
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://clubgames.pogo.com/online2/pogop/be…aploader_v6.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7759 bytes
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!

1. Download Combo fix from one of these locations.
* IMPORTANT !!! Place combofix.exe on your Desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from comboFix
bob4, things are picking up nicely! here's what you asked for!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:06:27 PM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Documents and Settings\Mary\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {404ECBB5-560D-4FDA-0211-2B00C9C68FBB} - C:\WINDOWS\system32\zdorwjw.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Dcftjyh] C:\WINDOWS\?ecurity\?serinit.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303307750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303296640
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://clubgames.pogo.com/online2/pogop/be…aploader_v6.cab
O20 - Winlogon Notify: opnoomm - opnoomm.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7041 bytes


ComboFix 08-02-14.2 - Mary 2008-02-14 18:22:08.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.431 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\ddccd.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\outerinfo
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\kernInst.exe
C:\Program Files\ymbols~1
C:\Program Files\ymbols~1\wuauclt .exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\ecurit~1
C:\WINDOWS\ecurit~1\?serinit.exe
C:\WINDOWS\pppatc~1
C:\WINDOWS\pppatc~1\?ppPatch\
C:\WINDOWS\pppatc~1\spool32 .exe
C:\WINDOWS\pppatc~1\spool32.exe
C:\WINDOWS\system32\bqgwrkyw.dll
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\SYSTEM32\dccdd.ini
C:\WINDOWS\SYSTEM32\dccdd.ini2
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\ddccd.exe
C:\WINDOWS\system32\dfuluhgs.dll
C:\WINDOWS\SYSTEM32\dgstincx.ini
C:\WINDOWS\system32\dnncpxbk.dll
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\duuqvpxg.dll
C:\WINDOWS\system32\frphyjwc.dll
C:\WINDOWS\SYSTEM32\harpbsee.ini
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\SYSTEM32\kjtdkhrr.ini
C:\WINDOWS\system32\lptxjxst.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mjioyerg.dll
C:\WINDOWS\SYSTEM32\nikltyhb.ini
C:\WINDOWS\system32\nmixfjxn.dll
C:\WINDOWS\SYSTEM32\nsnycfby.ini
C:\WINDOWS\system32\pnyijtnt.dll
C:\WINDOWS\system32\sevgjwij.dll
C:\WINDOWS\SYSTEM32\stirherj.ini
C:\WINDOWS\SYSTEM32\tcvbekdp.ini
C:\WINDOWS\SYSTEM32\tsxjxtpl.ini
C:\WINDOWS\SYSTEM32\tsxjxtpl.ini2
C:\WINDOWS\SYSTEM32\tsxjxtpl.tmp
C:\WINDOWS\SYSTEM32\upokjlmk.ini
C:\WINDOWS\system32\uthxbegm.dll
C:\WINDOWS\system32\wbdkygrw.dll
C:\WINDOWS\SYSTEM32\wrloscmc.ini
C:\WINDOWS\system32\wryfwplm.dll
C:\WINDOWS\system32\xbdiwfmn.dll
C:\WINDOWS\system32\xtjdbtje.dll
C:\WINDOWS\system32\yprlbibt.dll

—– BITS: Possible infected sites —–

hxxp://resources.zune.net

.
((((((((((((((((((((((((( Files Created from 2008-01-14 to 2008-02-14 )))))))))))))))))))))))))))))))
.

2008-02-10 21:11 . 2008-02-10 21:12 3,097,152 –ahs—- C:\WINDOWS\SYSTEM32\qeqxvakt.ini
2008-02-10 10:42 . 2008-02-10 10:42 91,492 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\klin.dat
2008-02-10 10:42 . 2008-02-10 10:42 85,860 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\klick.dat
2008-02-10 10:34 . 2008-02-10 10:34 d——– C:\Program Files\Kaspersky Lab
2008-02-10 10:34 . 2008-02-10 15:27 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-10 10:34 . 2008-02-14 18:49 1,516,064 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2008-02-10 10:34 . 2008-02-14 18:48 21,356 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
2008-02-10 10:33 . 2008-02-14 18:48 12,064 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.dat
2008-02-10 10:33 . 2008-02-14 18:48 2,180 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.idx
2008-02-10 10:28 . 2008-02-10 10:28 d——– C:\kav
2008-02-10 10:27 . 2008-02-14 18:41 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-10 10:27 . 2008-02-10 13:22 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 08:46 . 2008-02-10 20:03 3,097,092 –ahs—- C:\WINDOWS\SYSTEM32\errgrwst.ini
2008-02-10 08:43 . 2008-02-10 08:44 3,097,696 –ahs—- C:\WINDOWS\SYSTEM32\yjlunkpj.ini
2008-02-09 09:45 . 2008-02-09 23:04 d——– C:\Documents and Settings\Mary\Application Data\HouseCall 6.6
2008-02-09 08:44 . 2008-02-10 07:51 3,098,968 –ahs—- C:\WINDOWS\SYSTEM32\sdysyphs.ini
2008-02-09 08:36 . 2008-02-10 01:59 d——– C:\Program Files\RcvSystem
2008-02-04 00:07 . 2008-02-04 00:07 4,286 –a—— C:\WINDOWS\SYSTEM32\everybodybets.32x32.4.ico
2008-02-03 08:00 . 2008-02-03 08:02 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-03 07:59 . 2008-02-03 07:59 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-03 06:47 . 2008-02-14 17:13 155,648 –a—— C:\WINDOWS\SYSTEM32\igfxtray .exe
2008-02-03 06:47 . 2008-02-14 17:14 114,688 –a—— C:\WINDOWS\SYSTEM32\hkcmd .exe
2008-02-03 06:47 . 2008-02-14 17:14 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-02-03 06:21 . 2008-02-03 06:21 270,698 –a—— C:\WINDOWS\SYSTEM32\LC890.tmp
2008-02-03 06:14 . 2008-02-14 18:41 d——– C:\Program Files\Dot1XCfg
2008-02-03 06:10 . 2008-02-03 06:10 270,698 –a—— C:\WINDOWS\SYSTEM32\L9EE0.tmp
2008-02-03 06:10 . 2008-02-10 01:59 36,864 –a—— C:\WINDOWS\mrofinu72.exe.tmp
2008-01-28 00:29 . 2008-01-28 00:29 dr-h—– C:\Documents and Settings\Mary\Application Data\yahoo!
2008-01-19 16:19 . 2008-01-19 16:19 d——– C:\WINDOWS\dog2 dir
2008-01-19 16:19 . 2008-01-19 16:19 471,040 –a—— C:\WINDOWS\dog2.scr
2008-01-19 16:19 . 2008-01-19 16:19 12,288 –a—— C:\WINDOWS\impborl.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-14 23:41 ——— d—–w C:\Program Files\Zune
2008-02-14 23:41 ——— d—–w C:\Program Files\QuickTime
2008-02-09 11:43 ——— d—–w C:\Program Files\THQ
2008-02-09 11:42 ——— d—–w C:\Program Files\Toy Factory
2008-02-09 11:41 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-03 13:01 ——— d—–w C:\Program Files\Lavasoft
2008-02-03 13:01 ——— d—–w C:\Documents and Settings\Mary\Application Data\Lavasoft
2008-02-02 03:12 ——— d—–w C:\Program Files\Soulseek1
2008-01-30 01:58 ——— d—–w C:\Documents and Settings\Mary\Application Data\Intuit
2008-01-30 01:56 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-30 01:49 ——— d—–w C:\Program Files\TurboTax
2008-01-28 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-26 23:44 ——— d—–w C:\Program Files\U.B. Funkeys
2007-12-18 05:43 23,396 —-a-w C:\WINDOWS\system32\drivers\klopp.dat
2003-05-12 17:52 207,759 —-a-w C:\Program Files\INSTALL.LOG
.
—-a-w		   151,597 2008-02-14 22:14:03  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			61,440 2008-02-14 22:14:22  C:\Program Files\Dot1XCfg\Dot1XCfg .exe
—-a-w			49,152 2008-02-14 22:14:04  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		   132,496 2008-02-14 22:14:08  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w		   227,856 2008-02-14 23:49:15  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
—-a-w		 1,667,584 2008-02-14 22:14:18  C:\Program Files\Messenger\MSMSGS .EXE
—-a-w		   650,752 2008-02-14 22:13:17  C:\Program Files\QuickTime\qttask					  .exe
—-a-w		   650,752 2008-02-14 22:08:04  C:\Program Files\QuickTime\qttask					 .exe
—-a-w		   650,752 2008-02-12 00:52:36  C:\Program Files\QuickTime\qttask					.exe
—-a-w		   650,752 2008-02-11 14:41:30  C:\Program Files\QuickTime\qttask				   .exe
—-a-w		   650,752 2008-02-11 10:12:00  C:\Program Files\QuickTime\qttask				  .exe
—-a-w		   650,752 2008-02-11 00:57:46  C:\Program Files\QuickTime\qttask				 .exe
—-a-w		   650,752 2008-02-11 00:49:49  C:\Program Files\QuickTime\qttask				.exe
—-a-w		   650,752 2008-02-10 23:18:31  C:\Program Files\QuickTime\qttask			   .exe
—-a-w		   650,752 2008-02-10 22:50:19  C:\Program Files\QuickTime\qttask			  .exe
—-a-w		   650,752 2008-02-10 20:23:14  C:\Program Files\QuickTime\qttask			 .exe
—-a-w		   650,752 2008-02-10 15:58:38  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   650,752 2008-02-10 15:49:31  C:\Program Files\QuickTime\qttask		   .exe
—-a-w		   650,752 2008-02-10 14:59:56  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   650,752 2008-02-10 07:09:48  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-02-10 06:59:21  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-02-10 06:59:23  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-02-10 06:59:23  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-02-10 06:59:23  C:\Program Files\QuickTime\qttask .exe
—-a-w		 2,097,488 2008-02-14 22:14:47  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w			24,104 2008-02-14 22:14:05  C:\Program Files\Zune\ZuneLauncher .exe
—-a-w		   158,208 2008-02-04 03:54:03  C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe
—-a-w			15,360 2008-02-14 22:14:14  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   114,688 2008-02-14 22:14:01  C:\WINDOWS\SYSTEM32\hkcmd .exe
—-a-w		   155,648 2008-02-14 22:13:59  C:\WINDOWS\SYSTEM32\igfxtray .exe


– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{404ECBB5-560D-4FDA-0211-2B00C9C68FBB}]
C:\WINDOWS\system32\zdorwjw.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [ ]
"Dcftjyh"="C:\WINDOWS\?ecurity\?serinit.exe" [ ]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [ ]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnoomm]
opnoomm.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\\WINDOWS\\system32\\ddccd

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2002-12-17 12:28 684032 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 02:56 15360 C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\ddccd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-02-10 01:59 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-03-04 03:36 36975 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2004-11-22 09:18 307200 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\program files\mcafee.com\vso\mcvsshld.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
S3 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-02-14 18:49]

.
Contents of the 'Scheduled Tasks' folder
"2003-05-21 22:05:43 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-14 18:49:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2008-02-14 18:56:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-14 23:56:45
THIS IS IMPORTANT !!
You are running HJT directly from the desktop.
Create a folder called HJT either in C: or My documents or some place convienient and place the
hijackthis.exe in there.
This will ensure we have back ups made and it doesn't get deleted .








______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked



O4 - HKCU\..\Run: [Dcftjyh] C:\WINDOWS\?ecurity\?serinit.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://clubgames.pogo.com/online2/pogop/be…aploader_v6.cab
O20 - Winlogon Notify: opnoomm - opnoomm.dll (file missing)


Close that.




________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\SYSTEM32\qeqxvakt.ini
C:\WINDOWS\SYSTEM32\errgrwst.ini
C:\WINDOWS\SYSTEM32\yjlunkpj.ini
C:\WINDOWS\SYSTEM32\sdysyphs.ini



Renv::

C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Messenger\MSMSGS .EXE
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\Program Files\Zune\ZuneLauncher .exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe
C:\WINDOWS\SYSTEM32\ctfmon .exe
C:\WINDOWS\SYSTEM32\hkcmd .exe
C:\WINDOWS\SYSTEM32\igfxtray .exe


Folder::
C:\Program Files\Dot1XCfg
C:\Program Files\RcvSystem


Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnoomm]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{404ECBB5-560D-4FDA-0211-2B00C9C68FBB}]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.




______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


_________________________________

Using Internet explorer (firefox will not work)
Please do an online scan with Kaspersky Online Scanner
Click accept on the first page.

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer


Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from comboFix
  • The report from Kasperskys
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:10 PM, on 2/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\Mary\My Documents\HJT\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3e8a7701-d125-4529-a1b0-06acf2a3fc64} - (no file)
O2 - BHO: (no name) - {4E5551B6-5F86-4907-9165-2A94FCDCF764} - (no file)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL; Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303307750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303296640
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 9853 bytes


ComboFix 08-02-14.2 - Mary 2008-02-14 20:28:52.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.435 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mary\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\SYSTEM32\errgrwst.ini
C:\WINDOWS\SYSTEM32\qeqxvakt.ini
C:\WINDOWS\SYSTEM32\sdysyphs.ini
C:\WINDOWS\SYSTEM32\yjlunkpj.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Dot1XCfg
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\RcvSystem
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\SYSTEM32\errgrwst.ini
C:\WINDOWS\SYSTEM32\qeqxvakt.ini
C:\WINDOWS\SYSTEM32\sdysyphs.ini
C:\WINDOWS\SYSTEM32\yjlunkpj.ini

.
((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.

2008-02-10 10:42 . 2008-02-10 10:42 91,492 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\klin.dat
2008-02-10 10:42 . 2008-02-10 10:42 85,860 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\klick.dat
2008-02-10 10:34 . 2008-02-10 10:34 d——– C:\Program Files\Kaspersky Lab
2008-02-10 10:34 . 2008-02-10 15:27 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-10 10:34 . 2008-02-14 20:40 1,723,936 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2008-02-10 10:34 . 2008-02-14 20:39 24,116 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
2008-02-10 10:33 . 2008-02-14 20:40 17,696 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.dat
2008-02-10 10:33 . 2008-02-14 20:39 2,684 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.idx
2008-02-10 10:28 . 2008-02-10 10:28 d——– C:\kav
2008-02-10 10:27 . 2008-02-14 20:28 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-10 10:27 . 2008-02-10 13:22 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-09 09:45 . 2008-02-09 23:04 d——– C:\Documents and Settings\Mary\Application Data\HouseCall 6.6
2008-02-04 00:07 . 2008-02-04 00:07 4,286 –a—— C:\WINDOWS\SYSTEM32\everybodybets.32x32.4.ico
2008-02-03 22:54 . 2008-02-03 22:54 158,208 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msconfig.exe
2008-02-03 08:00 . 2008-02-03 08:02 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-03 07:59 . 2008-02-03 07:59 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-03 06:47 . 2008-02-14 17:13 155,648 –a—— C:\WINDOWS\SYSTEM32\igfxtray.exe
2008-02-03 06:47 . 2008-02-14 17:14 114,688 –a—— C:\WINDOWS\SYSTEM32\hkcmd.exe
2008-02-03 06:21 . 2008-02-03 06:21 270,698 –a—— C:\WINDOWS\SYSTEM32\LC890.tmp
2008-02-03 06:10 . 2008-02-03 06:10 270,698 –a—— C:\WINDOWS\SYSTEM32\L9EE0.tmp
2008-02-03 06:10 . 2008-02-10 01:59 36,864 –a—— C:\WINDOWS\mrofinu72.exe.tmp
2008-01-28 00:29 . 2008-01-28 00:29 dr-h—– C:\Documents and Settings\Mary\Application Data\yahoo!
2008-01-19 16:19 . 2008-01-19 16:19 d——– C:\WINDOWS\dog2 dir
2008-01-19 16:19 . 2008-01-19 16:19 471,040 –a—— C:\WINDOWS\dog2.scr
2008-01-19 16:19 . 2008-01-19 16:19 12,288 –a—— C:\WINDOWS\impborl.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 01:28 ——— d—–w C:\Program Files\Zune
2008-02-15 01:28 ——— d—–w C:\Program Files\QuickTime
2008-02-09 11:43 ——— d—–w C:\Program Files\THQ
2008-02-09 11:42 ——— d—–w C:\Program Files\Toy Factory
2008-02-09 11:41 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-03 13:01 ——— d—–w C:\Program Files\Lavasoft
2008-02-03 13:01 ——— d—–w C:\Documents and Settings\Mary\Application Data\Lavasoft
2008-02-02 03:12 ——— d—–w C:\Program Files\Soulseek1
2008-01-30 01:58 ——— d—–w C:\Documents and Settings\Mary\Application Data\Intuit
2008-01-30 01:56 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-30 01:49 ——— d—–w C:\Program Files\TurboTax
2008-01-28 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-26 23:44 ——— d—–w C:\Program Files\U.B. Funkeys
2007-12-18 05:43 23,396 —-a-w C:\WINDOWS\system32\drivers\klopp.dat
2003-05-12 17:52 207,759 —-a-w C:\Program Files\INSTALL.LOG
.
—-a-w		   227,856 2008-02-15 01:40:01  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
—-a-w		   650,752 2008-02-14 22:13:17  C:\Program Files\QuickTime\qttask					  .exe
—-a-w		   650,752 2008-02-14 22:08:04  C:\Program Files\QuickTime\qttask					 .exe
—-a-w		   650,752 2008-02-12 00:52:36  C:\Program Files\QuickTime\qttask					.exe
—-a-w		   650,752 2008-02-11 14:41:30  C:\Program Files\QuickTime\qttask				   .exe
—-a-w		   650,752 2008-02-11 10:12:00  C:\Program Files\QuickTime\qttask				  .exe
—-a-w		   650,752 2008-02-11 00:57:46  C:\Program Files\QuickTime\qttask				 .exe
—-a-w		   650,752 2008-02-11 00:49:49  C:\Program Files\QuickTime\qttask				.exe
—-a-w		   650,752 2008-02-10 23:18:31  C:\Program Files\QuickTime\qttask			   .exe
—-a-w		   650,752 2008-02-10 22:50:19  C:\Program Files\QuickTime\qttask			  .exe
—-a-w		   650,752 2008-02-10 20:23:14  C:\Program Files\QuickTime\qttask			 .exe
—-a-w		   650,752 2008-02-10 15:58:38  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   650,752 2008-02-10 15:49:31  C:\Program Files\QuickTime\qttask		   .exe
—-a-w		   650,752 2008-02-10 14:59:56  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   650,752 2008-02-10 07:09:48  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-02-10 06:59:21  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-02-10 06:59:23  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-02-10 06:59:23  C:\Program Files\QuickTime\qttask  .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3e8a7701-d125-4529-a1b0-06acf2a3fc64}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{404ECBB5-560D-4FDA-0211-2B00C9C68FBB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E5551B6-5F86-4907-9165-2A94FCDCF764}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2008-02-14 17:14 1667584]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-02-14 17:14 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2008-02-14 17:13 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2008-02-14 17:14 114688]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-14 17:14 151597]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2008-02-14 17:14 49152]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2008-02-14 17:14 24104]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-02-14 17:14 132496]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnoomm]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\\WINDOWS\\system32\\ddccd

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2002-12-17 12:28 684032 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 02:56 15360 C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-02-10 01:59 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-03-04 03:36 36975 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-02-14 17:14 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2004-11-22 09:18 307200 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\program files\mcafee.com\vso\mcvsshld.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
S3 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-02-14 20:40]

.
Contents of the 'Scheduled Tasks' folder
"2003-05-21 22:05:43 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-14 20:40:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\imapi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-02-14 20:46:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-15 01:46:31
ComboFix2.txt 2008-02-14 23:56:57


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, February 14, 2008 11:19:54 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/02/2008
Kaspersky Anti-Virus database records: 567256
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 66056
Number of viruses found: 11
Number of infected objects: 112
Number of suspicious objects: 0
Duration of the scan process: 01:10:32

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\00b0_File_Monitoring_eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\00b1_pdm_eventcritlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\00b1_pdm_eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\detected.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\detected.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\report.rpt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\!update-4495[1].0000.bac_a00480 Infected: Trojan-Downloader.Win32.PurityScan.fk skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\!update.exe.bac_a00480 Infected: Trojan-Downloader.Win32.PurityScan.fk skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\17PHolmes[1].cmt.bac_a00480 Infected: Trojan-Downloader.Win32.Agent.idv skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\b122.exe.bac_a00480 Infected: Trojan-Downloader.Win32.Agent.hvj skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\ddccd.exe.bac_a00480 Infected: Virus.Win32.Trats.d skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\Dot1XCfg .exe.bac_a00480 Infected: Trojan-Downloader.Win32.Adload.pr skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\mrofinu72.exe.bac_a00480 Infected: Trojan-Downloader.Win32.Agent.idv skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\TMP1DE.tmp.bac_a00480 Infected: Trojan-Downloader.Win32.Adload.pr skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\TMP1F7.tmp.bac_a00480 Infected: Trojan-Downloader.Win32.Agent.idv skipped
C:\Documents and Settings\Mary\.housecall6.6\Quarantine\zdorwjw.dll.bac_a00480 Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\Documents and Settings\Mary\Application Data\Aim\enilydde\xgoatlordsx\cert8.db Object is locked skipped
C:\Documents and Settings\Mary\Application Data\Aim\enilydde\xgoatlordsx\key3.db Object is locked skipped
C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\cert8.db Object is locked skipped
C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\history.dat Object is locked skipped
C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\key3.db Object is locked skipped
C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\parent.lock Object is locked skipped
C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Mary\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Mary\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\Application Data\Mozilla\Firefox\Profiles\u8tzuva8.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\History\History.IE5\MSHist012008021420080215\index.dat Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Mary\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mary\My Documents\HJT\backups\backup-20080214-202531-670.dll Infected: not-a-virus:Downloader.Win32.PopCap.a skipped
C:\Documents and Settings\Mary\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Mary\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\Program Files\QuickTime\qttask .exe Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\Common Files\Real\Update_OB\realsched.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\Dot1XCfg\Dot1XCfg .exe.vir Infected: Trojan-Downloader.Win32.Adload.pr skipped
C:\QooBox\Quarantine\C\Program Files\Dot1XCfg\Dot1XCfg.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\HP\HP Software Update\HPWuSchd2.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin\jusched.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\Messenger\MSMSGS.EXE.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\Spybot - Search & Destroy\TeaTimer.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\Temporary\kernInst.exe.vir Infected: Trojan.Win32.Agent.edq skipped
C:\QooBox\Quarantine\C\Program Files\YMBOLS~1\wuauclt .exe.vir Infected: Trojan-Downloader.Win32.PurityScan.fn skipped
C:\QooBox\Quarantine\C\Program Files\Zune\ZuneLauncher.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\WINDOWS\ECURIT~1\υserinit.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.gw skipped
C:\QooBox\Quarantine\C\WINDOWS\PPPATC~1\spool32 .exe.vir Infected: Trojan-Downloader.Win32.PurityScan.fn skipped
C:\QooBox\Quarantine\C\WINDOWS\PPPATC~1\spool32.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\bqgwrkyw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ctfmon.exe.tmp.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ddccd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ddccd.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\dfuluhgs.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\dnncpxbk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\duuqvpxg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\frphyjwc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hkcmd.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\igfxtray.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\lptxjxst.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\mjioyerg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\nmixfjxn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\pnyijtnt.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\sevgjwij.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\wbdkygrw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\wryfwplm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\xbdiwfmn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\xtjdbtje.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\yprlbibt.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-02-14_184914.84.zip/ddccd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-02-14_184914.84.zip ZIP: infected - 1 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000003.exe Infected: Trojan-Downloader.Win32.PurityScan.fn skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000006.exe Infected: Trojan-Downloader.Win32.PurityScan.fn skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000011.EXE Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000012.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000013.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000014.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000015.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000017.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000019.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000021.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000022.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000023.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000024.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000025.exe Infected: Trojan-Downloader.Win32.PurityScan.fn skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000028.exe Infected: Trojan.Win32.Agent.edq skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000029.exe Infected: Trojan-Downloader.Win32.PurityScan.fn skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000030.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000031.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000035.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000036.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000037.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000038.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000039.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000040.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000041.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000042.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000043.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000044.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000045.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000047.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000048.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000049.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000050.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000051.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000062.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000063.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000064.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000065.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000066.EXE Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000067.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000068.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000069.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000070.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000071.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000077.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP4\A0000168.exe Infected: Trojan-Downloader.Win32.Adload.pr skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP4\A0000173.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP4\A0000190.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP4\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\mrofinu72.exe.tmp Infected: Trojan-Downloader.Win32.Agent.idv skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\ddccd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.dat Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.idx Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
First.
These 2 programs have to be uninstalled then reinstalled as they were damaged by the file infecter you have.
Go to add remove programs and uninstall them first.
Quick time
Kasperskys internet security


Then navigate to and delete these folders before reinstalling to be certain we get rid of the bad files.

C:\Program Files\quicktime

C:\Program Files\Kaspersky Lab

Then reinstall both.





____________________________
Navigate to and delete the contents of this folder

C:\Documents and Settings\Mary\.housecall6.6\Quarantine << Just delete the contents not the folder itself.

________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3e8a7701-d125-4529-a1b0-06acf2a3fc64}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{404ECBB5-560D-4FDA-0211-2B00C9C68FBB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E5551B6-5F86-4907-9165-2A94FCDCF764}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnoomm]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.



________________________________________
You need to update SunJava for security reasons.
Updating Java:
Download the latest version of
Java Runtime Environment (JRE) 6 Update 4

  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 4
    … allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe
    to install the newest version.


_________________________________
Adobe Acrobat Reader update

You are using an older vulnerable version of the free Adobe Acrobat Reader {7.0}. Please go here to download Adobe Acrobat Reader 8…



When you have finished installing the Acrobat Reader, please go to Add/Remove Programs and verify that there are no versions listed other than Acrobat Reader 8. If you find older versions, remove them.

When finished, reboot your computer.


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Combofix
  • Let me know how things seem to be running now.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:20, on 2008-02-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Documents and Settings\Mary\My Documents\HJT\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {A80064A8-88FD-429F-8EFC-57B4FC61B3AD} - C:\WINDOWS\system32\ddccd.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\kmd.exe /c C:\ComboFix\Combobatch.bat
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303307750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303296640
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 6474 bytes


ComboFix 08-02-14.2 - Mary 2008-02-14 20:28:52.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.435 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mary\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\SYSTEM32\errgrwst.ini
C:\WINDOWS\SYSTEM32\qeqxvakt.ini
C:\WINDOWS\SYSTEM32\sdysyphs.ini
C:\WINDOWS\SYSTEM32\yjlunkpj.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Dot1XCfg
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\RcvSystem
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\SYSTEM32\errgrwst.ini
C:\WINDOWS\SYSTEM32\qeqxvakt.ini
C:\WINDOWS\SYSTEM32\sdysyphs.ini
C:\WINDOWS\SYSTEM32\yjlunkpj.ini

.
((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.

2008-02-10 10:42 . 2008-02-10 10:42 91,492 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\klin.dat
2008-02-10 10:42 . 2008-02-10 10:42 85,860 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\klick.dat
2008-02-10 10:34 . 2008-02-10 10:34 d——– C:\Program Files\Kaspersky Lab
2008-02-10 10:34 . 2008-02-10 15:27 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-10 10:34 . 2008-02-14 20:40 1,723,936 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2008-02-10 10:34 . 2008-02-14 20:39 24,116 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
2008-02-10 10:33 . 2008-02-14 20:40 17,696 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.dat
2008-02-10 10:33 . 2008-02-14 20:39 2,684 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.idx
2008-02-10 10:28 . 2008-02-10 10:28 d——– C:\kav
2008-02-10 10:27 . 2008-02-14 20:28 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-10 10:27 . 2008-02-10 13:22 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-09 09:45 . 2008-02-09 23:04 d——– C:\Documents and Settings\Mary\Application Data\HouseCall 6.6
2008-02-04 00:07 . 2008-02-04 00:07 4,286 –a—— C:\WINDOWS\SYSTEM32\everybodybets.32x32.4.ico
2008-02-03 22:54 . 2008-02-03 22:54 158,208 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msconfig.exe
2008-02-03 08:00 . 2008-02-03 08:02 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-03 07:59 . 2008-02-03 07:59 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-03 06:47 . 2008-02-14 17:13 155,648 –a—— C:\WINDOWS\SYSTEM32\igfxtray.exe
2008-02-03 06:47 . 2008-02-14 17:14 114,688 –a—— C:\WINDOWS\SYSTEM32\hkcmd.exe
2008-02-03 06:21 . 2008-02-03 06:21 270,698 –a—— C:\WINDOWS\SYSTEM32\LC890.tmp
2008-02-03 06:10 . 2008-02-03 06:10 270,698 –a—— C:\WINDOWS\SYSTEM32\L9EE0.tmp
2008-02-03 06:10 . 2008-02-10 01:59 36,864 –a—— C:\WINDOWS\mrofinu72.exe.tmp
2008-01-28 00:29 . 2008-01-28 00:29 dr-h—– C:\Documents and Settings\Mary\Application Data\yahoo!
2008-01-19 16:19 . 2008-01-19 16:19 d——– C:\WINDOWS\dog2 dir
2008-01-19 16:19 . 2008-01-19 16:19 471,040 –a—— C:\WINDOWS\dog2.scr
2008-01-19 16:19 . 2008-01-19 16:19 12,288 –a—— C:\WINDOWS\impborl.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 01:28 ——— d—–w C:\Program Files\Zune
2008-02-15 01:28 ——— d—–w C:\Program Files\QuickTime
2008-02-09 11:43 ——— d—–w C:\Program Files\THQ
2008-02-09 11:42 ——— d—–w C:\Program Files\Toy Factory
2008-02-09 11:41 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-03 13:01 ——— d—–w C:\Program Files\Lavasoft
2008-02-03 13:01 ——— d—–w C:\Documents and Settings\Mary\Application Data\Lavasoft
2008-02-02 03:12 ——— d—–w C:\Program Files\Soulseek1
2008-01-30 01:58 ——— d—–w C:\Documents and Settings\Mary\Application Data\Intuit
2008-01-30 01:56 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-30 01:49 ——— d—–w C:\Program Files\TurboTax
2008-01-28 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-26 23:44 ——— d—–w C:\Program Files\U.B. Funkeys
2007-12-18 05:43 23,396 —-a-w C:\WINDOWS\system32\drivers\klopp.dat
2003-05-12 17:52 207,759 —-a-w C:\Program Files\INSTALL.LOG
.
—-a-w		   227,856 2008-02-15 01:40:01  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe
—-a-w		   650,752 2008-02-14 22:13:17  C:\Program Files\QuickTime\qttask					  .exe
—-a-w		   650,752 2008-02-14 22:08:04  C:\Program Files\QuickTime\qttask					 .exe
—-a-w		   650,752 2008-02-12 00:52:36  C:\Program Files\QuickTime\qttask					.exe
—-a-w		   650,752 2008-02-11 14:41:30  C:\Program Files\QuickTime\qttask				   .exe
—-a-w		   650,752 2008-02-11 10:12:00  C:\Program Files\QuickTime\qttask				  .exe
—-a-w		   650,752 2008-02-11 00:57:46  C:\Program Files\QuickTime\qttask				 .exe
—-a-w		   650,752 2008-02-11 00:49:49  C:\Program Files\QuickTime\qttask				.exe
—-a-w		   650,752 2008-02-10 23:18:31  C:\Program Files\QuickTime\qttask			   .exe
—-a-w		   650,752 2008-02-10 22:50:19  C:\Program Files\QuickTime\qttask			  .exe
—-a-w		   650,752 2008-02-10 20:23:14  C:\Program Files\QuickTime\qttask			 .exe
—-a-w		   650,752 2008-02-10 15:58:38  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   650,752 2008-02-10 15:49:31  C:\Program Files\QuickTime\qttask		   .exe
—-a-w		   650,752 2008-02-10 14:59:56  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   650,752 2008-02-10 07:09:48  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-02-10 06:59:21  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-02-10 06:59:22  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-02-10 06:59:23  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-02-10 06:59:23  C:\Program Files\QuickTime\qttask  .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3e8a7701-d125-4529-a1b0-06acf2a3fc64}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{404ECBB5-560D-4FDA-0211-2B00C9C68FBB}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E5551B6-5F86-4907-9165-2A94FCDCF764}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2008-02-14 17:14 1667584]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-02-14 17:14 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2008-02-14 17:13 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2008-02-14 17:14 114688]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-14 17:14 151597]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2008-02-14 17:14 49152]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2008-02-14 17:14 24104]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-02-14 17:14 132496]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnoomm]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\\WINDOWS\\system32\\ddccd

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2002-12-17 12:28 684032 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 02:56 15360 C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-02-10 01:59 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-03-04 03:36 36975 C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-02-14 17:14 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2004-11-22 09:18 307200 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\program files\mcafee.com\vso\mcvsshld.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
S3 avp ;avp ;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" [2008-02-14 20:40]

.
Contents of the 'Scheduled Tasks' folder
"2003-05-21 22:05:43 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-14 20:40:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\imapi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-02-14 20:46:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-15 01:46:31
ComboFix2.txt 2008-02-14 23:56:57


The machine is running way better than before, but I don't really have a clue if it's clean or not. I know that every time i reboot, dos window opens up with kmd.exe. Also, HPProduct Assistant keeps trying to load something and catchme.zip has shown up on the desktop.

Thanks,
wes
Have you removed both quicktime and Kasperskys ?
If you have I don't see an antiVirus program running.

If you plan to put Kasperskys back in please do so.
If not I will list 2 free anti virus programs please just install and update one of them right away.


AVG FREE

Avast

Avira AntiVir Personal Edition Classic



_________________________________________
There are just a few registry entries left I can't seem to remove.


Please submit the catchme.zip file to this site.
http://www.bleepingcomputer.com/submit-malware.php?channel=4

The creator of the comboFix collects files for anaylasys.
Once you have done that you may delete that file.

__________________________________


Now let's see why comboFix is not doing what I ask.



______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O2 - BHO: (no name) - {A80064A8-88FD-429F-8EFC-57B4FC61B3AD} - C:\WINDOWS\system32\ddccd.dll (file missing
O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\kmd.exe /c C:\ComboFix\Combobatch.bat
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -

Close that.


___________________________________

This is going to remove the old combofix and we are going to grab the latest version.



Go to start > run and copy and paste this in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.


_____________________________________



1. Download Combo fix from one of these locations. ( Please save it to your desktop )
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe





________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnoomm]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3e8a7701-d125-4529-a1b0-06acf2a3fc64}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{404ECBB5-560D-4FDA-0211-2B00C9C68FBB}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E5551B6-5F86-4907-9165-2A94FCDCF764}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B}]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.

__________________________________________

Next reply
  • A new HJT log
  • The report from ComboFix
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:15, on 2008-02-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Documents and Settings\Mary\My Documents\HJT\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303307750
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1192303296640
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 7079 bytes


ComboFix 08-02-16.2 - Mary 2008-02-16 9:07:42.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.489 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mary\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.

2008-02-16 08:57 . 2008-02-16 08:57 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-15 18:08 . 2008-02-15 18:08 d——– C:\Program Files\Java
2008-02-15 18:08 . 2008-02-15 18:08 d——– C:\Program Files\Common Files\Java
2008-02-15 18:08 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-15 17:56 . 2008-02-15 18:00 d——– C:\Documents and Settings\Mary\.SunDownloadManager
2008-02-15 07:54 . 2004-08-04 02:56 388,608 –a—— C:\kmd.exe
2008-02-15 07:38 . 2008-02-15 07:38 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-15 07:38 . 2008-02-15 07:38 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-15 05:11 . 2008-02-15 05:11 5,461 –a—— C:\WINDOWS\BM071fc221.xml
2008-02-15 05:11 . 2008-02-15 08:09 21 –a—— C:\WINDOWS\pskt.ini
2008-02-15 05:09 . 2008-02-15 08:04 155,648 –a—— C:\WINDOWS\SYSTEM32\igfxtray .exe
2008-02-15 05:09 . 2008-02-15 08:04 114,688 –a—— C:\WINDOWS\SYSTEM32\hkcmd .exe
2008-02-15 05:09 . 2008-02-15 08:05 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-02-14 21:22 . 2008-02-14 21:22 d——– C:\Program Files\CCleaner
2008-02-10 10:28 . 2008-02-10 10:28 d——– C:\kav
2008-02-10 10:27 . 2008-02-15 08:11 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-10 10:27 . 2008-02-10 13:22 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-09 09:45 . 2008-02-09 23:04 d——– C:\Documents and Settings\Mary\Application Data\HouseCall 6.6
2008-02-04 00:07 . 2008-02-04 00:07 4,286 –a—— C:\WINDOWS\SYSTEM32\everybodybets.32x32.4.ico
2008-02-03 22:54 . 2008-02-03 22:54 158,208 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msconfig.exe
2008-02-03 08:00 . 2008-02-03 08:02 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-03 07:59 . 2008-02-03 07:59 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-03 06:21 . 2008-02-03 06:21 270,698 –a—— C:\WINDOWS\SYSTEM32\LC890.tmp
2008-02-03 06:10 . 2008-02-03 06:10 270,698 –a—— C:\WINDOWS\SYSTEM32\L9EE0.tmp
2008-02-03 06:10 . 2008-02-10 01:59 36,864 –a—— C:\WINDOWS\mrofinu72.exe.tmp
2008-01-28 00:29 . 2008-01-28 00:29 dr-h—– C:\Documents and Settings\Mary\Application Data\yahoo!
2008-01-19 16:19 . 2008-01-19 16:19 12,288 –a—— C:\WINDOWS\impborl.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 14:00 ——— d—–w C:\Documents and Settings\Mary\Application Data\AVG7
2008-02-16 13:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-16 13:55 44,288 —-a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-02-15 23:17 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-15 13:11 ——— d—–w C:\Program Files\Zune
2008-02-15 12:41 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-09 11:43 ——— d—–w C:\Program Files\THQ
2008-02-09 11:42 ——— d—–w C:\Program Files\Toy Factory
2008-02-04 03:54 158,208 —-a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
2008-02-03 13:01 ——— d—–w C:\Program Files\Lavasoft
2008-02-03 13:01 ——— d—–w C:\Documents and Settings\Mary\Application Data\Lavasoft
2008-02-02 03:12 ——— d—–w C:\Program Files\Soulseek1
2008-01-30 01:58 ——— d—–w C:\Documents and Settings\Mary\Application Data\Intuit
2008-01-30 01:56 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-30 01:49 ——— d—–w C:\Program Files\TurboTax
2008-01-28 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-26 23:44 ——— d—–w C:\Program Files\U.B. Funkeys
2007-12-14 16:32 12,632 —-a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
2003-05-12 17:52 207,759 —-a-w C:\Program Files\INSTALL.LOG
.
—-a-w		   151,597 2008-02-15 13:04:55  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			49,152 2008-02-15 13:04:54  C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
—-a-w		 1,667,584 2008-02-15 13:05:11  C:\Program Files\Messenger\MSMSGS .EXE
—-a-w		 2,097,488 2008-02-15 13:05:14  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w			24,104 2008-02-15 13:04:53  C:\Program Files\Zune\ZuneLauncher .exe
—-a-w			15,360 2008-02-15 13:05:01  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   114,688 2008-02-15 13:04:51  C:\WINDOWS\SYSTEM32\hkcmd .exe
—-a-w		   155,648 2008-02-15 13:04:51  C:\WINDOWS\SYSTEM32\igfxtray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [ ]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-16 08:59 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-16 08:57 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22 288472]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2002-12-17 12:28 684032 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 02:56 15360 C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\program files\mcafee.com\vso\mcvsshld.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]

*Newly Created Service* - AVG7ALRT
*Newly Created Service* - AVG7CORE
*Newly Created Service* - AVG7RSXP
*Newly Created Service* - AVG7UPDSVC
*Newly Created Service* - AVGCLEAN
*Newly Created Service* - AVGEMS
*Newly Created Service* - AVGTDI
.
Contents of the 'Scheduled Tasks' folder
"2003-05-21 22:05:43 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 09:10:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-16 9:10:46





The HP Product Assistant is continuing to try to install. I'm assuming it's for my printer, but I'm canceling it before it can finish. Should I just let it install?

Thanks.
Yes let the HP printer software install. I am going through your logs now. It looks better. There will be a few other programs that have to be uninstalled and reinstalled. HP software is NOT one of them so go ahead.
OK looks like comboFix is back on track.
Let's run this then in the next post I will let you know what programs have to be reinstalled.

________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\SYSTEM32\LC890.tmp
C:\WINDOWS\SYSTEM32\L9EE0.tmp
C:\WINDOWS\mrofinu72.exe.tmp
C:\WINDOWS\SYSTEM32\everybodybets.32x32.4.ico
C:\WINDOWS\mrofinu72.exe.tmp

Renv::
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\Messenger\MSMSGS .EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\Program Files\Zune\ZuneLauncher .exe
C:\WINDOWS\SYSTEM32\ctfmon .exe
C:\WINDOWS\SYSTEM32\hkcmd .exe
C:\WINDOWS\SYSTEM32\igfxtray .exe



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.
ComboFix 08-02-16.2 - Mary 2008-02-16 10:20:59.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.435 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mary\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\mrofinu72.exe.tmp
C:\WINDOWS\SYSTEM32\everybodybets.32x32.4.ico
C:\WINDOWS\SYSTEM32\L9EE0.tmp
C:\WINDOWS\SYSTEM32\LC890.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\mrofinu72.exe.tmp
C:\WINDOWS\SYSTEM32\everybodybets.32x32.4.ico
C:\WINDOWS\SYSTEM32\L9EE0.tmp
C:\WINDOWS\SYSTEM32\LC890.tmp

.
((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.

2008-02-16 08:57 . 2008-02-16 08:57 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-15 18:08 . 2008-02-15 18:08 d——– C:\Program Files\Java
2008-02-15 18:08 . 2008-02-15 18:08 d——– C:\Program Files\Common Files\Java
2008-02-15 18:08 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-15 17:56 . 2008-02-15 18:00 d——– C:\Documents and Settings\Mary\.SunDownloadManager
2008-02-15 07:54 . 2004-08-04 02:56 388,608 –a—— C:\kmd.exe
2008-02-15 07:38 . 2008-02-15 07:38 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-15 07:38 . 2008-02-15 07:38 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-15 05:11 . 2008-02-15 05:11 5,461 –a—— C:\WINDOWS\BM071fc221.xml
2008-02-15 05:11 . 2008-02-15 08:09 21 –a—— C:\WINDOWS\pskt.ini
2008-02-15 05:09 . 2008-02-15 08:04 155,648 –a—— C:\WINDOWS\SYSTEM32\igfxtray.exe
2008-02-15 05:09 . 2008-02-15 08:04 114,688 –a—— C:\WINDOWS\SYSTEM32\hkcmd.exe
2008-02-14 21:22 . 2008-02-14 21:22 d——– C:\Program Files\CCleaner
2008-02-10 10:28 . 2008-02-10 10:28 d——– C:\kav
2008-02-10 10:27 . 2008-02-16 10:20 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-10 10:27 . 2008-02-10 13:22 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-09 09:45 . 2008-02-09 23:04 d——– C:\Documents and Settings\Mary\Application Data\HouseCall 6.6
2008-02-03 22:54 . 2008-02-03 22:54 158,208 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msconfig.exe
2008-02-03 08:00 . 2008-02-03 08:02 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-03 07:59 . 2008-02-03 07:59 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-28 00:29 . 2008-01-28 00:29 dr-h—– C:\Documents and Settings\Mary\Application Data\yahoo!
2008-01-19 16:19 . 2008-01-19 16:19 12,288 –a—— C:\WINDOWS\impborl.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 15:20 ——— d—–w C:\Program Files\Zune
2008-02-16 14:00 ——— d—–w C:\Documents and Settings\Mary\Application Data\AVG7
2008-02-16 13:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-16 13:55 44,288 —-a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-02-15 23:17 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-15 12:41 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-09 11:43 ——— d—–w C:\Program Files\THQ
2008-02-09 11:42 ——— d—–w C:\Program Files\Toy Factory
2008-02-03 13:01 ——— d—–w C:\Program Files\Lavasoft
2008-02-03 13:01 ——— d—–w C:\Documents and Settings\Mary\Application Data\Lavasoft
2008-02-02 03:12 ——— d—–w C:\Program Files\Soulseek1
2008-01-30 01:58 ——— d—–w C:\Documents and Settings\Mary\Application Data\Intuit
2008-01-30 01:56 ——— d—–w C:\Program Files\Common Files\AnswerWorks 4.0
2008-01-30 01:49 ——— d—–w C:\Program Files\TurboTax
2008-01-28 05:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-12-26 23:44 ——— d—–w C:\Program Files\U.B. Funkeys
2003-05-12 17:52 207,759 —-a-w C:\Program Files\INSTALL.LOG
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3e8a7701-d125-4529-a1b0-06acf2a3fc64}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E5551B6-5F86-4907-9165-2A94FCDCF764}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51F77EC8-BEC1-4924-A160-B648FA23A380}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{82EA1A55-9CBC-404b-9D0C-E8BFB7EAAE9B}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A80064A8-88FD-429F-8EFC-57B4FC61B3AD}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2008-02-15 08:05 1667584]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-02-15 08:05 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2008-02-15 08:04 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2008-02-15 08:04 114688]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-15 08:04 151597]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2008-02-15 08:04 49152]
"Zune Launcher"="C:\Program Files\Zune\ZuneLauncher.exe" [2008-02-15 08:04 24104]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"BM071fc221"="C:\WINDOWS\system32\vqycwynx.dll" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-16 08:57 219136]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22 288472]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2002-12-17 12:28 684032 C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 02:56 15360 C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-02-15 08:04 151597 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\program files\mcafee.com\vso\mcvsshld.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]

.
Contents of the 'Scheduled Tasks' folder
"2003-05-21 22:05:43 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 10:24:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\imapi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2008-02-16 10:27:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-16 15:27:30
ComboFix2.txt 2008-02-16 14:10:46



Spybot opens everytime i restart and says there are things trying to change registry settings, i believe.
_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\system32\vqycwynx.dll


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html


Post the contents of the logs from either Jottis or Virus total

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI