This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hijackthis log, norton can't fix?

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here are the combofix and hijackthis logs. Ill let you know how norton scan works out.

ComboFix 08-02-18.1 - fior garcia 2008-02-19 20:18:10.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.242 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\fior garcia\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-20 to 2008-02-20 )))))))))))))))))))))))))))))))
.

2008-02-19 19:56 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-19 19:55 . 2008-02-19 19:55 d——– C:\Program Files\Common Files\Java
2008-02-19 17:47 . 2008-02-19 17:47 d——– C:\Documents and Settings\fior garcia\Application Data\Malwarebytes
2008-02-19 17:46 . 2008-02-19 17:46 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-19 17:46 . 2008-02-19 17:46 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-18 20:18 . 2008-02-18 20:18 d——– C:\Documents and Settings\fior garcia\Application Data\Apple Computer
2008-02-18 08:16 . 2008-02-18 08:16 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-18 08:16 . 2008-02-18 09:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-17 15:02 . 2008-02-17 15:02 d——– C:\Program Files\Windows Sidebar
2008-02-17 15:02 . 2008-02-17 22:11 d——– C:\Program Files\Norton AntiVirus
2008-02-17 15:01 . 2008-02-17 22:07 123,952 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2008-02-17 15:01 . 2008-02-17 22:07 60,800 –a—— C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2008-02-17 15:01 . 2008-02-17 22:07 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2008-02-17 15:01 . 2008-02-17 22:07 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2008-02-17 15:00 . 2008-02-17 22:07 d——– C:\Program Files\Symantec
2008-02-17 14:42 . 2008-02-17 22:01 d——– C:\Program Files\Common Files\Symantec Shared
2008-02-17 12:58 . 2008-02-17 14:00 d——– C:\Documents and Settings\Administrator\Application Data\AOL
2008-02-17 12:43 . 2008-02-17 14:57 174,592 –a—— C:\WINDOWS\SYSTEM32\lexpps .exe
2008-02-17 12:25 . 2008-02-17 14:03 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-02-17 12:09 . 2007-12-06 20:21 6,066,176 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-02-17 12:09 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-02-17 12:09 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-02-17 12:09 . 2007-12-06 20:21 459,264 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-02-17 12:09 . 2007-12-06 20:21 383,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-02-17 12:09 . 2007-12-06 20:21 267,776 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-02-17 12:09 . 2007-12-06 20:21 63,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-02-17 12:09 . 2007-12-06 20:21 52,224 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-02-17 12:09 . 2007-12-06 05:00 13,824 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-02-17 11:54 . 2007-08-13 18:54 33,792 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
2008-02-17 11:38 . 2006-08-21 03:14 128,896 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\fltmgr.sys
2008-02-17 11:38 . 2006-08-21 03:14 23,040 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\fltmc.exe
2008-02-17 11:38 . 2006-08-21 06:21 16,896 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\fltlib.dll
2008-02-17 11:23 . 2007-07-09 07:09 584,192 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\rpcrt4.dll
2008-02-16 21:01 . 2004-08-21 02:31 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-16 21:01 . 2004-08-21 02:27 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2008-02-16 21:01 . 2004-08-21 02:30 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-02-16 20:22 . 2008-02-16 20:22 d——– C:\Program Files\Lavasoft
2008-02-16 20:22 . 2008-02-16 20:27 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 18:51 . 2004-08-04 01:56 221,184 –a—— C:\WINDOWS\SYSTEM32\wmpns.dll
2008-02-16 18:46 . 2008-02-16 18:46 d——– C:\WINDOWS\provisioning
2008-02-16 18:46 . 2008-02-16 18:46 d——– C:\WINDOWS\peernet
2008-02-16 18:42 . 2008-02-16 18:42 d——– C:\WINDOWS\ServicePackFiles
2008-02-16 18:30 . 2008-02-16 18:30 d——– C:\WINDOWS\EHome

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-20 01:56 ——— d—–w C:\Program Files\Java
2008-02-20 01:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-18 15:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-18 03:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-18 03:14 ——— d—–w C:\Program Files\Google
2008-02-17 22:25 ——— d—–w C:\Program Files\QuickTime
2008-02-17 22:25 ——— d—–w C:\Program Files\DellSupport
2008-02-17 21:19 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\Symantec
2008-02-17 20:00 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-17 18:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 18:57 ——— d—–w C:\Program Files\Common Files\aolshare
2008-02-17 18:56 ——— d—–w C:\Program Files\Dell
2008-02-17 02:20 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-17 00:16 ——— d—–w C:\Documents and Settings\fior garcia\Application Data\MSN6
2008-01-15 15:54 10,537 —-a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 11:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 02:22 ——— d—–w C:\Program Files\Wal-Mart Music Downloads Store
2008-01-13 01:43 ——— d—–w C:\Program Files\Citrix
2008-01-13 01:35 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\Viewpoint
2008-01-13 01:02 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\MSN6
2008-01-13 00:52 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\BLSTOOLBAR
2008-01-13 00:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-23 17:25 ——— d—–w C:\Documents and Settings\fior garcia\Application Data\BLSTOOLBAR
2007-12-23 14:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-23 06:01 ——— d—–w C:\Documents and Settings\LocalService\Application Data\BLSTOOLBAR
2007-12-20 22:54 13,918 —-a-w C:\Documents and Settings\juan moronta\Application Data\wklnhst.dat
2007-12-20 03:55 80,704 —-a-w C:\Documents and Settings\juan moronta\Application Data\GDIPFONTCACHEV1.DAT
2007-11-08 00:26 720 —-a-w C:\Documents and Settings\Giancarlo\Application Data\wklnhst.dat
2007-08-31 21:36 60,968 —-a-w C:\Documents and Settings\juan moronta\GoToAssistDownloadHelper.exe
2007-08-17 22:38 6,947,971 —-a-w C:\Documents and Settings\juan moronta\HC4Installer.exe
2007-05-05 19:22 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-02-22 19:26 66,792 —-a-w C:\Documents and Settings\Giancarlo\Application Data\GDIPFONTCACHEV1.DAT
2007-02-21 01:32 66,269 —-a-w C:\Program Files\INSTALL.LOG
2006-07-08 01:29 580 —-a-w C:\Documents and Settings\fior garcia\Application Data\wklnhst.dat
.
—-a-w		   487,424 2008-02-17 00:08:44  C:\Program Files\Dell\QuickSet\quickset .exe
—-a-w			68,856 2008-02-17 20:59:40  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,694,208 2008-02-17 20:59:44  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   200,704 2008-02-17 20:59:26  C:\Program Files\Microsoft Money\System\mnyexpr .exe
—-a-w		   131,072 2008-02-17 20:58:42  C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray .exe
—-a-w		   282,624 2008-02-17 22:32:45  C:\Program Files\QuickTime\qttask				.exe
—-a-w		   282,624 2008-02-17 23:11:56  C:\Program Files\QuickTime\qttask			   .exe
—-a-w		   282,624 2008-02-17 23:11:57  C:\Program Files\QuickTime\qttask			  .exe
—-a-w		   282,624 2008-02-17 23:11:58  C:\Program Files\QuickTime\qttask			 .exe
—-a-w		   282,624 2008-02-17 23:11:59  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   282,624 2008-02-17 23:12:00  C:\Program Files\QuickTime\qttask		   .exe
—-a-w		   282,624 2008-02-17 23:12:01  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2008-02-17 23:12:02  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-02-17 23:12:03  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-02-17 23:12:04  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-02-17 23:12:05  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-02-17 23:12:06  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-02-17 23:12:07  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-02-17 23:12:08  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-02-17 23:11:30  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-02-17 23:11:31  C:\Program Files\QuickTime\qttask .exe
—-a-w			15,360 2008-02-17 20:03:29  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   174,592 2008-02-17 20:57:30  C:\WINDOWS\SYSTEM32\lexpps .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-02-17 18:20 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-17 16:32 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-02-17 16:32 282624]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-17 16:32 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-02-17 16:32 714608]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ,

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^juan moronta^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\juan moronta\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 04:59 122880 C:\WINDOWS\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
–a—— 2004-04-15 02:32 270336 C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2008-02-17 16:32 460784 C:\Program Files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
——— 2004-04-11 10:43 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HelpCenter]
–a—— 2006-10-30 11:00 192512 C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
–a—— 2006-07-12 23:22 57344 C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
——— 2003-12-05 21:08 50688 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-04-19 13:45 53248 c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2004-01-08 14:26 4866048 C:\WINDOWS\System32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2004-01-08 14:26 323584 C:\WINDOWS\SYSTEM32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
–a—— 2006-12-01 20:28 95800 C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
——— 2004-04-11 19:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2004-08-21 02:22 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
–a—— 2007-09-20 08:23 132624 C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-24 23:07]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 00:04]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 02:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - juan moronta.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
"2008-01-13 00:47:52 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-19 20:24:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
.
**************************************************************************
.
Completion time: 2008-02-19 20:27:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-20 02:27:49
ComboFix2.txt 2008-02-19 01:51:03
ComboFix3.txt 2008-02-18 21:30:45
.
2008-02-18 18:07:49 — E O F —




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:29, on 2008-02-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\fior garcia\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &Search - ?p=ZKxdm021YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1188597418891
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9B5FA7C-2755-4D1F-B69C-D00421001E55}: Domain = broward.k12.fl.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 6983 bytes
Well you have 2 programs or parts of programs that are damaged or not functioning the way they should. That in fact is pretty good considering the infection.

You will have to UNINSTALL then reinstall the following programs:

QuickTime
Bell South Help Center



How is your system now running? If everything is OK, we can proceed with the final cleanup procedures.

Trevuren
I've add/removed those programs away and the system is running fine but I can tell I'm still being hijacked because my homepage is set for yahoo.com but I am not directed to yahoo when I first open IE.. I get some runonce MSN webpage attempt that never actually loads, just stays in partial load mode. Also, I am getting these IE script errors when trying to access user accounts in control panel or access some other add/remove programs. I have a screenprint of the error if you need to see it. I'm ready for the next steps when you are available, thanks! Btw, i tried running that kaspeskyonline scan, still didn't allow me to run it yet.
A. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper

  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.
  • Finally, RUN Hijackthis again and produce a new HJT log. Post it in this thread so we can check how everything looks now. In addition, please tell me if there are any more malware problems that you are aware of.


B. We will check for missing or damaged critical system files:

1. Please go to Start -> Run -> type cmd and press Enter.

2. At the command prompt type sfc /scannow, making sure to put a space between the "c" and the slash, and then press Enter. This will run the System File Checker.

3. Follow the prompts, and insert your Windows installation CD if requested.

4. Then please REBOOT your computer.


C. Post the screenshot and tell me if there has been any improvement.
I guess when I removed the bellsouth stuff, it took that problem away because when I ran a hijack this scan it didn't have an R04 anymore? Here is the hijack this log. Ill run the scannow now and let you know what it says,


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:04, on 2008-02-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lexpps.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\fior garcia\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &Search - ?p=ZKxdm021YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1188597418891
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9B5FA7C-2755-4D1F-B69C-D00421001E55}: Domain = broward.k12.fl.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 6292 bytes
I was having lots of probs with the new IE 7 so I uninstalled it.. I ran kasperskyonline scan and the log is shown below. It seems even after I clear some of these things they stay on the system. Haven't had much lucky reinstalling IE 7.. Doesn't seem to stick but at least I can run these scans now. Here's the log: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT 2008-02-21 22:49 Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 22/02/2008 Kaspersky Anti-Virus database records: 575350 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 76833 Number of viruses found: 5 Number of infected objects: 18 Number of suspicious objects: 0 Duration of the scan process: 01:21:16 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a6e9f96152b273667e3e08051204bbf_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\56069bcb64d7d5af27f1dfb1d36388d4_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8acb85df9a7dc7a667aa699f1a895a92_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f928912c3cab8f2b48d3c743a9208c10_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.DAT Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\volatile.DAT Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{9A6A4D8A-1BC3-4074-BF3A-921EDA719208}.DAT Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-02-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{D071D4DA-D5B6-4FFA-8F73-8D6E9C0EAB73}.ldb Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{D071D4DA-D5B6-4FFA-8F73-8D6E9C0EAB73}.sds Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\9C48AB83.TMP Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped C:\Documents and Settings\fior garcia\Cookies\index.dat Object is locked skipped C:\Documents and Settings\fior garcia\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\fior garcia\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\fior garcia\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\fior garcia\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\fior garcia\ntuser.dat Object is locked skipped C:\Documents and Settings\fior garcia\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-1667963-TOTALLY HIP TRACK.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-2706948-07 Track 7 (broken).wma Infected: Trojan-Downloader.WMA.Wimad.l skipped C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3045692-01 Track 1.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3200824-07 Track 7.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3566386-06 Track 6.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped C:\Documents and Settings\Giancarlo\Shared\07 Track 7.wma Infected: Trojan-Downloader.WMA.Wimad.l skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\CA\PPRT\logs\2008-02-21.csv Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped C:\QooBox\Quarantine\C\Program Files\MSN Gaming Zone\rtejezas.html.vir Infected: Trojan-Clicker.HTML.IFrame.dn skipped C:\QooBox\Quarantine\C\Program Files\page.html.vir Infected: Trojan-Clicker.HTML.IFrame.dn skipped C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hjaigoia.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\mhyblxhk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP18\change.log Object is locked skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000010.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000011.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Installer\{16b66887-823a-41e3-ad94-01407d4c0a4d}\RamDrv.dll Infected: Trojan.Win32.Agent.fhg skipped C:\WINDOWS\Installer\{1c4d71fa-8393-4e82-85b3-0e81c1244e0e}\AvpRom.dll Infected: Trojan.Win32.Agent.fhg skipped C:\WINDOWS\Installer\{4e7d5280-6baa-4aa8-919c-09d951afdaf0}\zip.dll Infected: Trojan-Downloader.Win32.BHO.ct skipped C:\WINDOWS\Installer\{86e87156-8ae6-48f4-8604-cb0738e770eb}\UnknownAvp.dll Infected: Trojan.Win32.Agent.fhg skipped C:\WINDOWS\Installer\{9d7ddbce-52fa-4f06-91da-9b91975f5614}\zip.dll Infected: Trojan-Downloader.Win32.BHO.ct skipped C:\WINDOWS\Installer\{fb9bc3d9-82d2-4642-973c-5136bf3528ab}\zip.dll Infected: Trojan-Downloader.Win32.BHO.ct skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{21CFCE7E-B4C7-4E99-A57E-74716545C47C}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\JETCA16.tmp Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_71c.dat Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.

I was having lots of probs with the new IE 7 so I uninstalled it.


I ended up by doing the same on my XP machine. I just could not get things the way I wanted it.



1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-1667963-TOTALLY HIP TRACK.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-2706948-07 Track 7 (broken).wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3045692-01 Track 1.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3200824-07 Track 7.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3566386-06 Track 6.wma
C:\Documents and Settings\Giancarlo\Shared\07 Track 7.wma
C:\WINDOWS\Installer\{16b66887-823a-41e3-ad94-01407d4c0a4d}\RamDrv.dll
C:\WINDOWS\Installer\{1c4d71fa-8393-4e82-85b3-0e81c1244e0e}\AvpRom.dll
C:\WINDOWS\Installer\{4e7d5280-6baa-4aa8-919c-09d951afdaf0}\zip.dll
C:\WINDOWS\Installer\{86e87156-8ae6-48f4-8604-cb0738e770eb}\UnknownAvp.dll
C:\WINDOWS\Installer\{9d7ddbce-52fa-4f06-91da-9b91975f5614}\zip.dll
C:\WINDOWS\Installer\{fb9bc3d9-82d2-4642-973c-5136bf3528ab}\zip.dll

Folder::
C:\Documents and Settings\juan moronta\Application Data\Viewpoint
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-02-18.1 - fior garcia 2008-02-23 8:15:10.4 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\fior garcia\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-1667963-TOTALLY HIP TRACK.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-2706948-07 Track 7 (broken).wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3045692-01 Track 1.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3200824-07 Track 7.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3566386-06 Track 6.wma
C:\Documents and Settings\Giancarlo\Shared\07 Track 7.wma
C:\WINDOWS\Installer\{16b66887-823a-41e3-ad94-01407d4c0a4d}\RamDrv.dll
C:\WINDOWS\Installer\{1c4d71fa-8393-4e82-85b3-0e81c1244e0e}\AvpRom.dll
C:\WINDOWS\Installer\{4e7d5280-6baa-4aa8-919c-09d951afdaf0}\zip.dll
C:\WINDOWS\Installer\{86e87156-8ae6-48f4-8604-cb0738e770eb}\UnknownAvp.dll
C:\WINDOWS\Installer\{9d7ddbce-52fa-4f06-91da-9b91975f5614}\zip.dll
C:\WINDOWS\Installer\{fb9bc3d9-82d2-4642-973c-5136bf3528ab}\zip.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-1667963-TOTALLY HIP TRACK.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-2706948-07 Track 7 (broken).wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3045692-01 Track 1.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3200824-07 Track 7.wma
C:\Documents and Settings\Giancarlo\Incomplete\Preview-T-3566386-06 Track 6.wma
C:\Documents and Settings\Giancarlo\Shared\07 Track 7.wma
C:\Documents and Settings\juan moronta\Application Data\Viewpoint
C:\WINDOWS\Installer\{16b66887-823a-41e3-ad94-01407d4c0a4d}\RamDrv.dll
C:\WINDOWS\Installer\{1c4d71fa-8393-4e82-85b3-0e81c1244e0e}\AvpRom.dll
C:\WINDOWS\Installer\{4e7d5280-6baa-4aa8-919c-09d951afdaf0}\zip.dll
C:\WINDOWS\Installer\{86e87156-8ae6-48f4-8604-cb0738e770eb}\UnknownAvp.dll
C:\WINDOWS\Installer\{9d7ddbce-52fa-4f06-91da-9b91975f5614}\zip.dll
C:\WINDOWS\Installer\{fb9bc3d9-82d2-4642-973c-5136bf3528ab}\zip.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
.

2008-02-21 21:12 . 2008-02-21 21:12 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-02-21 21:12 . 2008-02-21 21:12 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-20 21:38 . 2008-02-20 21:38 230 –a—— C:\WINDOWS\SYSTEM32\spupdsvc.inf
2008-02-20 20:21 . 2001-08-17 13:28 794,654 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usr1801.sys
2008-02-20 20:20 . 2001-08-17 22:36 525,568 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\tridxp.dll
2008-02-20 20:19 . 2001-08-17 22:36 495,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\sblfx.dll
2008-02-20 20:18 . 2001-08-17 13:28 899,146 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\r2mdkxga.sys
2008-02-20 20:17 . 2001-08-17 14:05 351,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\ovcodek2.sys
2008-02-20 20:16 . 2002-08-29 04:00 1,875,968 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.lex
2008-02-20 20:15 . 2002-08-29 04:00 1,158,818 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\korwbrkr.lex
2008-02-20 20:14 . 2002-08-29 04:00 13,463,552 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\hwxjpn.dll
2008-02-20 20:13 . 2001-08-17 14:56 1,733,120 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\g400d.dll
2008-02-20 20:12 . 2001-08-17 12:14 952,007 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\diwan.sys
2008-02-20 20:11 . 2002-08-29 04:00 1,677,824 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\chsbrkr.dll
2008-02-20 20:10 . 2001-08-17 13:28 714,698 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\cbmdmkxx.sys
2008-02-20 20:09 . 2001-08-17 13:28 871,388 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\bcmdm.sys
2008-02-20 20:08 . 2001-08-17 14:56 66,048 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\s3legacy.dll
2008-02-19 19:56 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-19 19:55 . 2008-02-19 19:55 d——– C:\Program Files\Common Files\Java
2008-02-19 18:53 . 2008-02-19 18:53 d——– C:\Deckard
2008-02-19 17:47 . 2008-02-19 17:47 d——– C:\Documents and Settings\fior garcia\Application Data\Malwarebytes
2008-02-19 17:46 . 2008-02-19 17:46 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-19 17:46 . 2008-02-19 17:46 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-18 20:18 . 2008-02-18 20:18 d——– C:\Documents and Settings\fior garcia\Application Data\Apple Computer
2008-02-18 08:16 . 2008-02-18 08:16 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-18 08:16 . 2008-02-18 09:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-17 15:02 . 2008-02-17 15:02 d——– C:\Program Files\Windows Sidebar
2008-02-17 15:02 . 2008-02-17 22:11 d——– C:\Program Files\Norton AntiVirus
2008-02-17 15:01 . 2008-02-17 22:07 123,952 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2008-02-17 15:01 . 2008-02-17 22:07 60,800 –a—— C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2008-02-17 15:01 . 2008-02-17 22:07 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2008-02-17 15:01 . 2008-02-17 22:07 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2008-02-17 15:00 . 2008-02-17 22:07 d——– C:\Program Files\Symantec
2008-02-17 14:42 . 2008-02-21 21:23 d——– C:\Program Files\Common Files\Symantec Shared
2008-02-17 12:58 . 2008-02-17 14:00 d——– C:\Documents and Settings\Administrator\Application Data\AOL
2008-02-17 12:43 . 2008-02-17 14:57 174,592 –a—— C:\WINDOWS\SYSTEM32\lexpps .exe
2008-02-17 12:25 . 2008-02-17 14:03 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-02-17 12:09 . 2007-12-06 20:21 6,066,176 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-02-17 12:09 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-02-17 12:09 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-02-17 12:09 . 2007-12-06 20:21 459,264 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-02-17 12:09 . 2007-12-06 20:21 383,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-02-17 12:09 . 2007-12-06 20:21 267,776 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-02-17 12:09 . 2007-12-06 20:21 63,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-02-17 12:09 . 2007-12-06 20:21 52,224 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-02-17 12:09 . 2007-12-06 05:00 13,824 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-02-16 21:01 . 2004-08-21 02:31 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-16 21:01 . 2004-08-21 02:27 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2008-02-16 21:01 . 2004-08-21 02:30 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-02-16 20:22 . 2008-02-16 20:22 d——– C:\Program Files\Lavasoft
2008-02-16 20:22 . 2008-02-16 20:27 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 18:51 . 2004-08-04 01:56 221,184 –a—— C:\WINDOWS\SYSTEM32\wmpns.dll
2008-02-16 18:46 . 2008-02-16 18:46 d——– C:\WINDOWS\provisioning
2008-02-16 18:46 . 2008-02-16 18:46 d——– C:\WINDOWS\peernet
2008-02-16 18:42 . 2008-02-16 18:42 d——– C:\WINDOWS\ServicePackFiles
2008-02-16 18:30 . 2008-02-16 18:30 d——– C:\WINDOWS\EHome

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-21 00:55 716 —-a-w C:\Documents and Settings\fior garcia\Application Data\wklnhst.dat
2008-02-21 00:46 ——— d—–w C:\Program Files\QuickTime
2008-02-21 00:45 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-21 00:39 66,469 —-a-w C:\Program Files\INSTALL.LOG
2008-02-21 00:39 ——— d—–w C:\Program Files\BellSouth
2008-02-20 01:56 ——— d—–w C:\Program Files\Java
2008-02-20 01:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-18 15:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-18 03:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-18 03:14 ——— d—–w C:\Program Files\Google
2008-02-17 22:25 ——— d—–w C:\Program Files\DellSupport
2008-02-17 21:19 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\Symantec
2008-02-17 20:00 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-17 18:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 18:57 ——— d—–w C:\Program Files\Common Files\aolshare
2008-02-17 18:56 ——— d—–w C:\Program Files\Dell
2008-02-17 02:20 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-17 00:16 ——— d—–w C:\Documents and Settings\fior garcia\Application Data\MSN6
2008-01-15 15:54 10,537 —-a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 11:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 02:22 ——— d—–w C:\Program Files\Wal-Mart Music Downloads Store
2008-01-13 01:43 ——— d—–w C:\Program Files\Citrix
2008-01-13 01:02 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\MSN6
2008-01-13 00:52 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\BLSTOOLBAR
2008-01-13 00:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-23 17:25 ——— d—–w C:\Documents and Settings\fior garcia\Application Data\BLSTOOLBAR
2007-12-23 14:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-23 06:01 ——— d—–w C:\Documents and Settings\LocalService\Application Data\BLSTOOLBAR
2007-12-20 22:54 13,918 —-a-w C:\Documents and Settings\juan moronta\Application Data\wklnhst.dat
2007-12-20 03:55 80,704 —-a-w C:\Documents and Settings\juan moronta\Application Data\GDIPFONTCACHEV1.DAT
2007-11-08 00:26 720 —-a-w C:\Documents and Settings\Giancarlo\Application Data\wklnhst.dat
2007-08-31 21:36 60,968 —-a-w C:\Documents and Settings\juan moronta\GoToAssistDownloadHelper.exe
2007-08-17 22:38 6,947,971 —-a-w C:\Documents and Settings\juan moronta\HC4Installer.exe
2007-05-05 19:22 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-02-22 19:26 66,792 —-a-w C:\Documents and Settings\Giancarlo\Application Data\GDIPFONTCACHEV1.DAT
.
—-a-w		   487,424 2008-02-17 00:08:44  C:\Program Files\Dell\QuickSet\quickset .exe
—-a-w			68,856 2008-02-17 20:59:40  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,694,208 2008-02-17 20:59:44  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   200,704 2008-02-17 20:59:26  C:\Program Files\Microsoft Money\System\mnyexpr .exe
—-a-w		   131,072 2008-02-17 20:58:42  C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray .exe
—-a-w		   282,624 2008-02-17 22:32:45  C:\Program Files\QuickTime\qttask				.exe
—-a-w		   282,624 2008-02-17 23:11:56  C:\Program Files\QuickTime\qttask			   .exe
—-a-w		   282,624 2008-02-17 23:11:57  C:\Program Files\QuickTime\qttask			  .exe
—-a-w		   282,624 2008-02-17 23:11:58  C:\Program Files\QuickTime\qttask			 .exe
—-a-w		   282,624 2008-02-17 23:11:59  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   282,624 2008-02-17 23:12:00  C:\Program Files\QuickTime\qttask		   .exe
—-a-w		   282,624 2008-02-17 23:12:01  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2008-02-17 23:12:02  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-02-17 23:12:03  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-02-17 23:12:04  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-02-17 23:12:05  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-02-17 23:12:06  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-02-17 23:12:07  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-02-17 23:12:08  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-02-17 23:11:30  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-02-17 23:11:31  C:\Program Files\QuickTime\qttask .exe
—-a-w			15,360 2008-02-17 20:03:29  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   174,592 2008-02-17 20:57:30  C:\WINDOWS\SYSTEM32\lexpps .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-02-17 18:20 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-17 16:32 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ,

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^juan moronta^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\juan moronta\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 04:59 122880 C:\WINDOWS\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
–a—— 2004-04-15 02:32 270336 C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2008-02-17 16:32 460784 C:\Program Files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
——— 2004-04-11 10:43 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HelpCenter]
C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
–a—— 2006-07-12 23:22 57344 C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
——— 2003-12-05 21:08 50688 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-04-19 13:45 53248 c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2004-01-08 14:26 4866048 C:\WINDOWS\System32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2004-01-08 14:26 323584 C:\WINDOWS\SYSTEM32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
–a—— 2006-12-01 20:28 95800 C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
——— 2004-04-11 19:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2004-08-21 02:22 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
–a—— 2007-09-20 08:23 132624 C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-24 23:07]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 00:04]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-19 02:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - juan moronta.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
"2008-01-13 00:47:52 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 08:21:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
.
**************************************************************************
.
Completion time: 2008-02-23 8:24:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-23 14:24:44
ComboFix2.txt 2008-02-20 02:27:54
ComboFix3.txt 2008-02-19 01:51:03
ComboFix4.txt 2008-02-18 21:30:45
.
2008-02-22 03:07:00 — E O F —



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:27, on 2008-02-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\fior garcia\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &Search - ?p=ZKxdm021YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1188597418891
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9B5FA7C-2755-4D1F-B69C-D00421001E55}: Domain = broward.k12.fl.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 6192 bytes
Aside from the wierd inability to install internet explorer 7.0, the system seems fine. After removing IE 7, I no longer get the script error and can run online scanners, etc.. I think something messed up the ie 7 install on my first attempt and it caused a lot of problems. Now I even after I go through the install procedure for 7.0, after reboot, it still stays as IE 6.0.. kinda wierd. I tried uninstalling and installing a new quicktime, it installs, just doesn't work.. The movies are all scrambled. I dont have a printer to test.
1. DELETE your current copy of ComboFix.exe from your desktop.

2. DELETE the following folder and all its content: C:\ComboFix

3. NORTON ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Disable Auto-Protect."
  • select a duration of 5 hours (this assures no interference with the cleanup of your pc)
  • click "Ok."
  • a popup will warn that protection will now be disabled and the sign will now look like this: [external image: Posted Image]
You succesfully disabled the Norton Antivirus Guard.

4. Download Combofix from the link below. You must rename it before saving it. Save it to your desktop. I suggest that you rename it to Combo-Fix.exe. The tool will suggest that name as default any way.

Link


[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results"
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards.
2. Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
Notes:
  • Do not mouseclick combofix's window while it's running. That may cause it to stall
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-02-15.1 - fior garcia 2008-02-23 13:02:29.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.243 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
.

2008-02-23 12:18 . 2008-02-23 12:18 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-23 12:18 . 2008-02-23 12:18 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-23 12:16 . 2008-02-23 12:16 d——– C:\Program Files\Apple Software Update
2008-02-23 12:16 . 2008-02-23 12:16 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-02-21 21:12 . 2008-02-21 21:12 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-02-21 21:12 . 2008-02-21 21:12 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-20 21:38 . 2008-02-20 21:38 230 –a—— C:\WINDOWS\SYSTEM32\spupdsvc.inf
2008-02-20 20:21 . 2001-08-17 13:28 794,654 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usr1801.sys
2008-02-20 20:20 . 2001-08-17 22:36 525,568 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\tridxp.dll
2008-02-20 20:19 . 2001-08-17 22:36 495,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\sblfx.dll
2008-02-20 20:18 . 2001-08-17 13:28 899,146 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\r2mdkxga.sys
2008-02-20 20:17 . 2001-08-17 14:05 351,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\ovcodek2.sys
2008-02-20 20:16 . 2002-08-29 04:00 1,875,968 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.lex
2008-02-20 20:15 . 2002-08-29 04:00 1,158,818 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\korwbrkr.lex
2008-02-20 20:14 . 2002-08-29 04:00 13,463,552 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\hwxjpn.dll
2008-02-20 20:13 . 2001-08-17 14:56 1,733,120 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\g400d.dll
2008-02-20 20:12 . 2001-08-17 12:14 952,007 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\diwan.sys
2008-02-20 20:11 . 2002-08-29 04:00 1,677,824 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\chsbrkr.dll
2008-02-20 20:10 . 2001-08-17 13:28 714,698 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\cbmdmkxx.sys
2008-02-20 20:09 . 2001-08-17 13:28 871,388 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\bcmdm.sys
2008-02-20 20:08 . 2001-08-17 14:56 66,048 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\s3legacy.dll
2008-02-19 19:56 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-19 19:55 . 2008-02-19 19:55 d——– C:\Program Files\Common Files\Java
2008-02-19 17:47 . 2008-02-19 17:47 d——– C:\Documents and Settings\fior garcia\Application Data\Malwarebytes
2008-02-19 17:46 . 2008-02-19 17:46 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-19 17:46 . 2008-02-19 17:46 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-18 20:18 . 2008-02-18 20:18 d——– C:\Documents and Settings\fior garcia\Application Data\Apple Computer
2008-02-18 08:16 . 2008-02-18 08:16 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-18 08:16 . 2008-02-18 09:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-17 15:02 . 2008-02-17 15:02 d——– C:\Program Files\Windows Sidebar
2008-02-17 15:02 . 2008-02-17 22:11 d——– C:\Program Files\Norton AntiVirus
2008-02-17 15:01 . 2008-02-17 22:07 123,952 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2008-02-17 15:01 . 2008-02-17 22:07 60,800 –a—— C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2008-02-17 15:01 . 2008-02-17 22:07 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2008-02-17 15:01 . 2008-02-17 22:07 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2008-02-17 15:00 . 2008-02-17 22:07 d——– C:\Program Files\Symantec
2008-02-17 14:42 . 2008-02-21 21:23 d——– C:\Program Files\Common Files\Symantec Shared
2008-02-17 12:58 . 2008-02-17 14:00 d——– C:\Documents and Settings\Administrator\Application Data\AOL
2008-02-17 12:43 . 2008-02-17 14:57 174,592 –a—— C:\WINDOWS\SYSTEM32\lexpps .exe
2008-02-17 12:25 . 2008-02-17 14:03 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-02-17 12:09 . 2007-12-06 20:21 6,066,176 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-02-17 12:09 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-02-17 12:09 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-02-17 12:09 . 2007-12-06 20:21 459,264 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-02-17 12:09 . 2007-12-06 20:21 383,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-02-17 12:09 . 2007-12-06 20:21 267,776 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-02-17 12:09 . 2007-12-06 20:21 63,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-02-17 12:09 . 2007-12-06 20:21 52,224 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-02-17 12:09 . 2007-12-06 05:00 13,824 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-02-16 21:01 . 2004-08-21 02:31 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-16 21:01 . 2004-08-21 02:27 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2008-02-16 21:01 . 2004-08-21 02:30 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-02-16 20:22 . 2008-02-16 20:22 d——– C:\Program Files\Lavasoft
2008-02-16 20:22 . 2008-02-16 20:27 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 18:51 . 2004-08-04 01:56 221,184 –a—— C:\WINDOWS\SYSTEM32\wmpns.dll
2008-02-16 18:46 . 2008-02-16 18:46 d——– C:\WINDOWS\provisioning
2008-02-16 18:46 . 2008-02-16 18:46 d——– C:\WINDOWS\peernet
2008-02-16 18:42 . 2008-02-16 18:42 d——– C:\WINDOWS\ServicePackFiles
2008-02-16 18:30 . 2008-02-16 18:30 d——– C:\WINDOWS\EHome
2008-01-31 23:13 . 2008-01-31 23:13 90,112 –a—— C:\WINDOWS\SYSTEM32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 –a—— C:\WINDOWS\SYSTEM32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 18:17 ——— d—–w C:\Program Files\QuickTime
2008-02-23 18:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-21 00:55 716 —-a-w C:\Documents and Settings\fior garcia\Application Data\wklnhst.dat
2008-02-21 00:39 66,469 —-a-w C:\Program Files\INSTALL.LOG
2008-02-21 00:39 ——— d—–w C:\Program Files\BellSouth
2008-02-20 01:56 ——— d—–w C:\Program Files\Java
2008-02-20 01:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-18 15:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-18 03:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-18 03:14 ——— d—–w C:\Program Files\Google
2008-02-17 22:32 15,360 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\ctfmon.exe
2008-02-17 22:32 15,360 —-a-w C:\WINDOWS\SYSTEM32\ctfmon.exe
2008-02-17 22:25 ——— d—–w C:\Program Files\DellSupport
2008-02-17 21:19 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\Symantec
2008-02-17 21:17 174,592 —-a-w C:\WINDOWS\SYSTEM32\lexpps.exe
2008-02-17 20:00 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-17 18:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 18:57 ——— d—–w C:\Program Files\Common Files\aolshare
2008-02-17 18:56 ——— d—–w C:\Program Files\Dell
2008-02-17 02:20 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-17 00:16 ——— d—–w C:\Documents and Settings\fior garcia\Application Data\MSN6
2008-01-15 15:54 10,537 —-a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 11:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 02:22 ——— d—–w C:\Program Files\Wal-Mart Music Downloads Store
2008-01-13 01:43 ——— d—–w C:\Program Files\Citrix
2008-01-13 01:02 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\MSN6
2008-01-13 00:52 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\BLSTOOLBAR
2008-01-13 00:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-23 17:25 ——— d—–w C:\Documents and Settings\fior garcia\Application Data\BLSTOOLBAR
2007-12-23 14:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-23 06:01 ——— d—–w C:\Documents and Settings\LocalService\Application Data\BLSTOOLBAR
2007-12-20 22:54 13,918 —-a-w C:\Documents and Settings\juan moronta\Application Data\wklnhst.dat
2007-12-20 03:55 80,704 —-a-w C:\Documents and Settings\juan moronta\Application Data\GDIPFONTCACHEV1.DAT
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mrxdav.sys
2007-12-14 17:32 12,632 —-a-w C:\WINDOWS\SYSTEM32\lsdelete.exe
2007-12-07 00:44 96,256 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\inseng.dll
2007-12-07 00:44 666,112 —-a-w C:\WINDOWS\SYSTEM32\wininet.dll
2007-12-07 00:44 666,112 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-12-07 00:44 617,984 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-12-07 00:44 55,808 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-12-07 00:44 532,480 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-12-07 00:44 474,112 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\shlwapi.dll
2007-12-07 00:44 449,024 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-12-07 00:44 39,424 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
2007-12-07 00:44 357,888 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
2007-12-07 00:44 3,066,368 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-12-07 00:44 251,904 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iepeers.dll
2007-12-07 00:44 205,824 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-12-07 00:44 16,384 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-12-07 00:44 151,040 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdfview.dll
2007-12-07 00:44 146,432 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-12-07 00:44 1,499,136 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shdocvw.dll
2007-12-07 00:44 1,054,208 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\danim.dll
2007-12-07 00:44 1,024,000 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\browseui.dll
2007-12-06 10:05 18,432 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\SYSTEM32\oleaut32.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\oleaut32.dll
2007-11-08 00:26 720 —-a-w C:\Documents and Settings\Giancarlo\Application Data\wklnhst.dat
2007-08-31 21:36 60,968 —-a-w C:\Documents and Settings\juan moronta\GoToAssistDownloadHelper.exe
2007-08-17 22:38 6,947,971 —-a-w C:\Documents and Settings\juan moronta\HC4Installer.exe
2007-05-05 19:22 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-02-22 19:26 66,792 —-a-w C:\Documents and Settings\Giancarlo\Application Data\GDIPFONTCACHEV1.DAT
.
—-a-w		   487,424 2008-02-17 00:08:44  C:\Program Files\Dell\QuickSet\quickset .exe
—-a-w			68,856 2008-02-17 20:59:40  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,694,208 2008-02-17 20:59:44  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   200,704 2008-02-17 20:59:26  C:\Program Files\Microsoft Money\System\mnyexpr .exe
—-a-w		   131,072 2008-02-17 20:58:42  C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray .exe
—-a-w		   282,624 2008-02-17 22:32:45  C:\Program Files\QuickTime\qttask				.exe
—-a-w		   282,624 2008-02-17 23:11:56  C:\Program Files\QuickTime\qttask			   .exe
—-a-w		   282,624 2008-02-17 23:11:57  C:\Program Files\QuickTime\qttask			  .exe
—-a-w		   282,624 2008-02-17 23:11:58  C:\Program Files\QuickTime\qttask			 .exe
—-a-w		   282,624 2008-02-17 23:11:59  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   282,624 2008-02-17 23:12:00  C:\Program Files\QuickTime\qttask		   .exe
—-a-w		   282,624 2008-02-17 23:12:01  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2008-02-17 23:12:02  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-02-17 23:12:03  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-02-17 23:12:04  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-02-17 23:12:05  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-02-17 23:12:06  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-02-17 23:12:07  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-02-17 23:12:08  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-02-17 23:11:30  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-02-17 23:11:31  C:\Program Files\QuickTime\qttask .exe
—-a-w			15,360 2008-02-17 20:03:29  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   174,592 2008-02-17 20:57:30  C:\WINDOWS\SYSTEM32\lexpps .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-02-17 18:20 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-17 16:32 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 23:13 385024]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-17 16:32 51048]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ,

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^juan moronta^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\juan moronta\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 04:59 122880 C:\WINDOWS\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
–a—— 2004-04-15 02:32 270336 C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2008-02-17 16:32 460784 C:\Program Files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
——— 2004-04-11 10:43 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HelpCenter]
C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
–a—— 2006-07-12 23:22 57344 C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
——— 2003-12-05 21:08 50688 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-04-19 13:45 53248 c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2004-01-08 14:26 4866048 C:\WINDOWS\System32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2004-01-08 14:26 323584 C:\WINDOWS\SYSTEM32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
–a—— 2006-12-01 20:28 95800 C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
——— 2004-04-11 19:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2004-08-21 02:22 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
–a—— 2007-09-20 08:23 132624 C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-24 23:07]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 00:04]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-23 18:16:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-19 02:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - juan moronta.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
"2008-01-13 00:47:52 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 13:04:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-23 13:05:41
ComboFix-quarantined-files.txt 2008-02-23 19:05:19
.
2008-02-22 03:07:00 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:07, on 2008-02-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\fior garcia\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &Search - ?p=ZKxdm021YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1188597418891
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9B5FA7C-2755-4D1F-B69C-D00421001E55}: Domain = broward.k12.fl.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 6442 bytes
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

RenV::
—-a-w		   487,424 2008-02-17 00:08:44  C:\Program Files\Dell\QuickSet\quickset .exe
—-a-w			68,856 2008-02-17 20:59:40  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,694,208 2008-02-17 20:59:44  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   200,704 2008-02-17 20:59:26  C:\Program Files\Microsoft Money\System\mnyexpr .exe
—-a-w		   131,072 2008-02-17 20:58:42  C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray .exe
—-a-w		   282,624 2008-02-17 22:32:45  C:\Program Files\QuickTime\qttask				.exe
—-a-w		   282,624 2008-02-17 23:11:56  C:\Program Files\QuickTime\qttask			   .exe
—-a-w		   282,624 2008-02-17 23:11:57  C:\Program Files\QuickTime\qttask			  .exe
—-a-w		   282,624 2008-02-17 23:11:58  C:\Program Files\QuickTime\qttask			 .exe
—-a-w		   282,624 2008-02-17 23:11:59  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   282,624 2008-02-17 23:12:00  C:\Program Files\QuickTime\qttask		   .exe
—-a-w		   282,624 2008-02-17 23:12:01  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   282,624 2008-02-17 23:12:02  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   282,624 2008-02-17 23:12:03  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   282,624 2008-02-17 23:12:04  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   282,624 2008-02-17 23:12:05  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   282,624 2008-02-17 23:12:06  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   282,624 2008-02-17 23:12:07  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   282,624 2008-02-17 23:12:08  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   282,624 2008-02-17 23:11:30  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   282,624 2008-02-17 23:11:31  C:\Program Files\QuickTime\qttask .exe
—-a-w			15,360 2008-02-17 20:03:29  C:\WINDOWS\SYSTEM32\ctfmon .exe
—-a-w		   174,592 2008-02-17 20:57:30  C:\WINDOWS\SYSTEM32\lexpps .exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HelpCenter]

KillAll::
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-02-15.1 - fior garcia 2008-02-23 13:28:28.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.224 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\fior garcia\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
.

2008-02-23 12:18 . 2008-02-23 12:18 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-02-23 12:18 . 2008-02-23 12:18 1,409 –a—— C:\WINDOWS\QTFont.for
2008-02-23 12:16 . 2008-02-23 12:16 d——– C:\Program Files\Apple Software Update
2008-02-23 12:16 . 2008-02-23 12:16 d——– C:\Documents and Settings\All Users\Application Data\Apple
2008-02-21 21:12 . 2008-02-21 21:12 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-02-21 21:12 . 2008-02-21 21:12 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-20 21:38 . 2008-02-20 21:38 230 –a—— C:\WINDOWS\SYSTEM32\spupdsvc.inf
2008-02-20 20:21 . 2001-08-17 13:28 794,654 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usr1801.sys
2008-02-20 20:20 . 2001-08-17 22:36 525,568 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\tridxp.dll
2008-02-20 20:19 . 2001-08-17 22:36 495,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\sblfx.dll
2008-02-20 20:18 . 2001-08-17 13:28 899,146 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\r2mdkxga.sys
2008-02-20 20:17 . 2001-08-17 14:05 351,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\ovcodek2.sys
2008-02-20 20:16 . 2002-08-29 04:00 1,875,968 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.lex
2008-02-20 20:15 . 2002-08-29 04:00 1,158,818 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\korwbrkr.lex
2008-02-20 20:14 . 2002-08-29 04:00 13,463,552 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\hwxjpn.dll
2008-02-20 20:13 . 2001-08-17 14:56 1,733,120 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\g400d.dll
2008-02-20 20:12 . 2001-08-17 12:14 952,007 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\diwan.sys
2008-02-20 20:11 . 2002-08-29 04:00 1,677,824 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\chsbrkr.dll
2008-02-20 20:10 . 2001-08-17 13:28 714,698 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\cbmdmkxx.sys
2008-02-20 20:09 . 2001-08-17 13:28 871,388 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\bcmdm.sys
2008-02-20 20:08 . 2001-08-17 14:56 66,048 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\s3legacy.dll
2008-02-19 19:56 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-02-19 19:55 . 2008-02-19 19:55 d——– C:\Program Files\Common Files\Java
2008-02-19 17:47 . 2008-02-19 17:47 d——– C:\Documents and Settings\fior garcia\Application Data\Malwarebytes
2008-02-19 17:46 . 2008-02-19 17:46 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-02-19 17:46 . 2008-02-19 17:46 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-02-18 20:18 . 2008-02-18 20:18 d——– C:\Documents and Settings\fior garcia\Application Data\Apple Computer
2008-02-18 08:16 . 2008-02-18 08:16 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-18 08:16 . 2008-02-18 09:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-17 15:02 . 2008-02-17 15:02 d——– C:\Program Files\Windows Sidebar
2008-02-17 15:02 . 2008-02-17 22:11 d——– C:\Program Files\Norton AntiVirus
2008-02-17 15:01 . 2008-02-17 22:07 123,952 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2008-02-17 15:01 . 2008-02-17 22:07 60,800 –a—— C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2008-02-17 15:01 . 2008-02-17 22:07 10,740 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.CAT
2008-02-17 15:01 . 2008-02-17 22:07 805 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.INF
2008-02-17 15:00 . 2008-02-17 22:07 d——– C:\Program Files\Symantec
2008-02-17 14:42 . 2008-02-21 21:23 d——– C:\Program Files\Common Files\Symantec Shared
2008-02-17 12:58 . 2008-02-17 14:00 d——– C:\Documents and Settings\Administrator\Application Data\AOL
2008-02-17 12:25 . 2008-02-17 14:03 15,360 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\ctfmon.exe
2008-02-17 12:25 . 2008-02-17 14:03 15,360 –a—— C:\WINDOWS\SYSTEM32\ctfmon.exe
2008-02-17 12:09 . 2007-12-06 20:21 6,066,176 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2008-02-17 12:09 . 2007-06-30 21:31 2,455,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2008-02-17 12:09 . 2007-06-30 21:36 991,232 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll.mui
2008-02-17 12:09 . 2007-12-06 20:21 459,264 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2008-02-17 12:09 . 2007-12-06 20:21 383,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2008-02-17 12:09 . 2007-12-06 20:21 267,776 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2008-02-17 12:09 . 2007-12-06 20:21 63,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2008-02-17 12:09 . 2007-12-06 20:21 52,224 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2008-02-17 12:09 . 2007-12-06 05:00 13,824 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-02-16 21:01 . 2004-08-21 02:31 d——– C:\Documents and Settings\Administrator\Application Data\Symantec
2008-02-16 21:01 . 2004-08-21 02:27 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2008-02-16 21:01 . 2004-08-21 02:30 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-02-16 20:22 . 2008-02-16 20:22 d——– C:\Program Files\Lavasoft
2008-02-16 20:22 . 2008-02-16 20:27 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-16 18:51 . 2004-08-04 01:56 221,184 –a—— C:\WINDOWS\SYSTEM32\wmpns.dll
2008-02-16 18:46 . 2008-02-16 18:46 d——– C:\WINDOWS\provisioning
2008-02-16 18:46 . 2008-02-16 18:46 d——– C:\WINDOWS\peernet
2008-02-16 18:42 . 2008-02-16 18:42 d——– C:\WINDOWS\ServicePackFiles
2008-02-16 18:30 . 2008-02-16 18:30 d——– C:\WINDOWS\EHome
2008-01-31 23:13 . 2008-01-31 23:13 90,112 –a—— C:\WINDOWS\SYSTEM32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 –a—— C:\WINDOWS\SYSTEM32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 19:28 ——— d—–w C:\Program Files\QuickTime
2008-02-23 18:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-21 00:55 716 —-a-w C:\Documents and Settings\fior garcia\Application Data\wklnhst.dat
2008-02-21 00:39 66,469 —-a-w C:\Program Files\INSTALL.LOG
2008-02-21 00:39 ——— d—–w C:\Program Files\BellSouth
2008-02-20 01:56 ——— d—–w C:\Program Files\Java
2008-02-20 01:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-18 15:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-18 03:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-18 03:14 ——— d—–w C:\Program Files\Google
2008-02-17 22:25 ——— d—–w C:\Program Files\DellSupport
2008-02-17 21:19 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\Symantec
2008-02-17 20:00 ——— d—–w C:\Program Files\Common Files\AOL
2008-02-17 18:58 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-17 18:57 ——— d—–w C:\Program Files\Common Files\aolshare
2008-02-17 18:56 ——— d—–w C:\Program Files\Dell
2008-02-17 02:20 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-17 00:16 ——— d—–w C:\Documents and Settings\fior garcia\Application Data\MSN6
2008-01-15 15:54 10,537 —-a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-01-15 11:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 02:22 ——— d—–w C:\Program Files\Wal-Mart Music Downloads Store
2008-01-13 01:43 ——— d—–w C:\Program Files\Citrix
2008-01-13 01:02 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\MSN6
2008-01-13 00:52 ——— d—–w C:\Documents and Settings\juan moronta\Application Data\BLSTOOLBAR
2008-01-13 00:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-12-23 17:25 ——— d—–w C:\Documents and Settings\fior garcia\Application Data\BLSTOOLBAR
2007-12-23 14:48 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-23 06:01 ——— d—–w C:\Documents and Settings\LocalService\Application Data\BLSTOOLBAR
2007-12-20 22:54 13,918 —-a-w C:\Documents and Settings\juan moronta\Application Data\wklnhst.dat
2007-12-20 03:55 80,704 —-a-w C:\Documents and Settings\juan moronta\Application Data\GDIPFONTCACHEV1.DAT
2007-11-08 00:26 720 —-a-w C:\Documents and Settings\Giancarlo\Application Data\wklnhst.dat
2007-08-31 21:36 60,968 —-a-w C:\Documents and Settings\juan moronta\GoToAssistDownloadHelper.exe
2007-08-17 22:38 6,947,971 —-a-w C:\Documents and Settings\juan moronta\HC4Installer.exe
2007-05-05 19:22 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-02-22 19:26 66,792 —-a-w C:\Documents and Settings\Giancarlo\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-02-17 18:20 116088 –a—— C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-02-17 14:03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-17 17:11 282624]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-17 16:32 51048]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ,

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^juan moronta^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\juan moronta\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 04:59 122880 C:\WINDOWS\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
–a—— 2004-04-15 02:32 270336 C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2008-02-17 16:32 460784 C:\Program Files\DellSupport\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
——— 2004-04-11 10:43 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 1200 Series]
–a—— 2006-07-12 23:22 57344 C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
——— 2003-12-05 21:08 50688 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-04-19 13:45 53248 c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2004-01-08 14:26 4866048 C:\WINDOWS\System32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2004-01-08 14:26 323584 C:\WINDOWS\SYSTEM32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
–a—— 2006-12-01 20:28 95800 C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
——— 2004-04-11 19:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2004-08-21 02:22 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
–a—— 2007-09-20 08:23 132624 C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe

R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-24 23:07]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-01-12 18:32]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 18:27]
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 00:04]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-23 18:16:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-19 02:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - juan moronta.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
"2008-01-13 00:47:52 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 13:32:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
.
**************************************************************************
.
Completion time: 2008-02-23 13:35:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-23 19:35:48
ComboFix2.txt 2008-02-23 19:05:42
.
2008-02-22 03:07:00 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:37, on 2008-02-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\fior garcia\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &Search - ?p=ZKxdm021YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1188597418891
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A9B5FA7C-2755-4D1F-B69C-D00421001E55}: Domain = broward.k12.fl.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = broward.k12.fl.us
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 6393 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI