This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware infection: outerinfo, webbuying, maybe more

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

having some serious problems here. pop ups, slow processing overall, IE pretty much does not work. I know I have outerinfo and webbuying that have somehow been installed, and I cannot remove them via traditional routes. Also, command.exe was on here but I do not see it in any obvious place anymore for some reason. Below is my HijackThis log. Please help! Thank you.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:35:36 AM, on 2/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\PPPATC~1\userinit.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Digsby\digsby.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netvibes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [f0b935a9] rundll32.exe "C:\WINDOWS\system32\oqoeyghl.dll",b
O4 - HKLM\..\Run: [BMf38a0635] Rundll32.exe "C:\WINDOWS\system32\kpfsagko.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tair] "C:\PROGRA~1\PPPATC~1\userinit.exe" -vt yazb
O4 - Startup: Digsby.lnk = C:\Program Files\Digsby\digsby.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.34/uploader2.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/…oUploader3.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr…?1199301478109
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://javadl-esd.sun.com/update/1.4…ndows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge…sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E82C3F3-908E-4BCF-8C37-05C2B7302E1F}: NameServer = 192.168.18.254
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 6394 bytes
hi,

1. please post a uninstall list using hjt;
start hjt click on "open misc tools section"
click on 'open uninstall manager"
click on "save list"

save the list so you can find it, then post the list in next reply.

2. Download combofix from one of these links and save it to Desktop:

http://subs.geekstogo.com/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

as a precaution, before using combofix:

Note:Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

* Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
* Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
* Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.

* IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
* If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.


3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review and the uninstall list


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
when i click Save List in HijackThis it just closes the application and does nothing else. i tried repeatedly with the same result. i even uninstalled the app and reinstalled. any ideas? thanks for your help.
hi, ok hold off on the uninstall list. come to think of it i dont know for sure if combofix will run on windows 2000. try it, it will let you know if there is a problem. member TomK pointed out to me you have XP, dont know how I got windows 2000. please disregard. shelf life
sorry about that. for some reason i typed windows 2000 my profile. it is actually XP. here are the logs:

Combo Fix:

ComboFix 08-02-23.2 - matthew robinson 2008-02-23 10:58:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.602 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\matthew robinson\My Documents\DOBE~1
C:\Documents and Settings\matthew robinson\My Documents\DOBE~1\r?ndll.exe
C:\Documents and Settings\matthew robinson\Start Menu\Programs\Outerinfo
C:\Documents and Settings\matthew robinson\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\matthew robinson\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\MSN Gaming Zone\lawu.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\Outlook Express\suwi89104.dll
C:\Program Files\pppatc~1
C:\Program Files\pppatc~1\?ppPatch\
C:\Program Files\pppatc~1\userinit.exe
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.8\wbuninst.exe
C:\Program Files\web buying\v1.8.8\webbuying.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\system32\biwghnm.dll
C:\WINDOWS\system32\ddcyv.dll
C:\WINDOWS\system32\faephxfu.dll
C:\WINDOWS\system32\faephxfu.dllbox
C:\WINDOWS\system32\jruyirjn.dll
C:\WINDOWS\system32\kpfsagko.dll
C:\WINDOWS\system32\lhgyeoqo.ini
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
C:\WINDOWS\system32\oqoeyghl.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rarc.dll
C:\WINDOWS\system32\rqrpmkk.dll
C:\WINDOWS\system32\sxpluehl.dll
C:\WINDOWS\system32\vpllajpc.dll
C:\WINDOWS\system32\vycdd.ini
C:\WINDOWS\system32\vycdd.ini2
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\yabyxur.dll
C:\WINDOWS\tk58.exe
C:\WINDOWS\uninstall_nmon.vbs

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR


((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
.

2008-02-22 09:15 . 2008-02-22 09:15 d——– C:\Program Files\Trend Micro
2008-02-22 08:16 . 2008-02-23 10:34 70,686 –a—— C:\WINDOWS\BMf38a0635.xml
2008-02-22 08:16 . 2008-02-22 09:31 22 –a—— C:\WINDOWS\pskt.ini
2008-02-22 00:35 . 2008-02-22 00:35 d——– C:\Program Files\Lavasoft
2008-02-22 00:35 . 2008-02-22 00:35 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-21 19:36 . 2008-02-21 19:36 d——– C:\Program Files\Enigma Software Group
2008-02-21 19:09 . 2008-02-22 09:29 d–hs—- C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg
2008-02-21 19:08 . 2008-02-21 19:08 d——– C:\WINDOWS\system32\xb8
2008-02-21 19:08 . 2008-02-22 00:40 d——– C:\WINDOWS\system32\ff3
2008-02-21 19:08 . 2008-02-22 09:29 d——– C:\WINDOWS\system32\ez2
2008-02-21 19:08 . 2008-02-21 19:08 d——– C:\WINDOWS\system32\cms4
2008-02-21 19:08 . 2008-02-21 19:08 36,864 –a—— C:\WINDOWS\mrofinu572.exe.tmp
2008-02-19 16:38 . 2008-02-19 16:38 d——– C:\Documents and Settings\matthew robinson\Application Data\Digsby
2008-02-19 16:36 . 2008-02-20 22:36 d——– C:\Program Files\Digsby
2008-02-13 13:52 . 2008-02-13 14:15 d——– C:\Documents and Settings\matthew robinson\Application Data\DivX
2008-02-13 13:41 . 2008-01-04 16:58 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-02-13 13:41 . 2008-01-04 16:58 120,056 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-02-13 13:41 . 2008-01-04 16:58 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-02-08 14:15 . 2008-02-08 14:15 d——– C:\Program Files\Windows Media Connect 2
2008-02-08 14:13 . 2008-02-08 14:14 d——– C:\WINDOWS\system32\drivers\UMDF
2008-02-08 14:04 . 2008-02-08 14:04 d——– C:\Program Files\Netflix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 18:34 ——— d—–w C:\Program Files\Picasa2
2008-02-22 05:34 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:44 ——— d—–w C:\Program Files\Trillian
2008-02-13 18:41 ——— d—–w C:\Program Files\DivX
2008-01-20 17:50 ——— d—–w C:\Program Files\iTunes
2008-01-20 17:50 ——— d—–w C:\Program Files\iPod
2008-01-20 17:49 ——— d—–w C:\Program Files\QuickTime
2008-01-17 15:32 ——— d—–w C:\Program Files\AskPBar
2008-01-17 14:57 ——— d—–w C:\Program Files\Google
2008-01-17 13:26 ——— d—–w C:\Documents and Settings\matthew robinson\Application Data\Arcsoft
2008-01-15 15:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2008-01-15 15:53 ——— d—–w C:\Program Files\JustZIPit
2008-01-04 21:58 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-01-04 01:33 ——— d—–w C:\Program Files\Java
2008-01-04 01:32 ——— d—–w C:\Program Files\Common Files\Java
2008-01-02 19:48 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2005-07-29 21:24 472 –sha-r C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg\nqIXx315xV1mvZLDvBhSv0.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"Tair"="C:\PROGRA~1\PPPATC~1\userinit.exe" [ ]
"Kvubjuhs"="C:\Documents and Settings\matthew robinson\My Documents\?dobe\r?ndll.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-03-30 20:00 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-03-30 20:00 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-03-30 19:59 138008]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-03-16 18:10 1392640]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 10:22 405504]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 15:49 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]

C:\Documents and Settings\matthew robinson\Start Menu\Programs\Startup\
Digsby.lnk - C:\Program Files\Digsby\digsby.exe [2008-02-15 18:30:48 115712]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 19:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Program Files\\iTunes\\iTunes.exe"=


.
Contents of the 'Scheduled Tasks' folder
"2008-01-26 23:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 11:07:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-23 11:09:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-23 16:09:17
.
2008-02-14 08:06:16 — E O F —


HiJackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:17 AM, on 2/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Digsby\digsby.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netvibes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tair] "C:\PROGRA~1\PPPATC~1\userinit.exe" -vt yazb
O4 - HKCU\..\Run: [Kvubjuhs] "C:\Documents and Settings\matthew robinson\My Documents\?dobe\r?ndll.exe"
O4 - Startup: Digsby.lnk = C:\Program Files\Digsby\digsby.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.34/uploader2.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1199301478109
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E82C3F3-908E-4BCF-8C37-05C2B7302E1F}: NameServer = 192.168.18.254
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 6333 bytes
fyi…the problem apps and the problems that i had noticed seem to be fixed. i appreciate your help very much. if there is anything else you see that i need to do please let me know. matthew
hi,

i typed windows 2000 my profile

so thats where i saw it, iam not going nuts (yet).

first we will use hjt, then combofix again;

start HJT, click the "Scan" button. check the items below, close any open windows, then click "Fixed checked"

O4 - HKCU\..\Run: [Tair] "C:\PROGRA~1\PPPATC~1\userinit.exe" -vt yazb
O4 - HKCU\..\Run: [Kvubjuhs] "C:\Documents and Settings\matthew robinson\My Documents\?dobe\r?ndll.exe"

Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:


File::
C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg\nqIXx315xV1mvZLDvBhSv0.vbs

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tair"=-
"Kvubjuhs"=-

Name the Notepad file CFScript.txt and Save it to your desktop.
now locate the both file you just saved and the combofix icon

using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log
please post the new combofix log and a new hjt log.

shelf life
thanks again. here is the stuff.

hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:33 AM, on 2/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Digsby\digsby.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netvibes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Digsby.lnk = C:\Program Files\Digsby\digsby.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.34/uploader2.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1199301478109
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E82C3F3-908E-4BCF-8C37-05C2B7302E1F}: NameServer = 192.168.18.254
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 6123 bytes


combofix log

ComboFix 08-02-23.2 - matthew robinson 2008-02-24 11:00:03.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.513 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\matthew robinson\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg\nqIXx315xV1mvZLDvBhSv0.vbs
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg\nqIXx315xV1mvZLDvBhSv0.vbs

.
((((((((((((((((((((((((( Files Created from 2008-01-24 to 2008-02-24 )))))))))))))))))))))))))))))))
.

2008-02-22 09:15 . 2008-02-22 09:15 d——– C:\Program Files\Trend Micro
2008-02-22 08:16 . 2008-02-23 10:34 70,686 –a—— C:\WINDOWS\BMf38a0635.xml
2008-02-22 08:16 . 2008-02-22 09:31 22 –a—— C:\WINDOWS\pskt.ini
2008-02-22 00:35 . 2008-02-22 00:35 d——– C:\Program Files\Lavasoft
2008-02-22 00:35 . 2008-02-22 00:35 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-21 19:36 . 2008-02-21 19:36 d——– C:\Program Files\Enigma Software Group
2008-02-21 19:09 . 2008-02-24 11:00 d–hs—- C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg
2008-02-21 19:08 . 2008-02-21 19:08 d——– C:\WINDOWS\system32\xb8
2008-02-21 19:08 . 2008-02-22 00:40 d——– C:\WINDOWS\system32\ff3
2008-02-21 19:08 . 2008-02-22 09:29 d——– C:\WINDOWS\system32\ez2
2008-02-21 19:08 . 2008-02-21 19:08 d——– C:\WINDOWS\system32\cms4
2008-02-21 19:08 . 2008-02-21 19:08 36,864 –a—— C:\WINDOWS\mrofinu572.exe.tmp
2008-02-19 16:38 . 2008-02-19 16:38 d——– C:\Documents and Settings\matthew robinson\Application Data\Digsby
2008-02-19 16:36 . 2008-02-20 22:36 d——– C:\Program Files\Digsby
2008-02-13 13:52 . 2008-02-13 14:15 d——– C:\Documents and Settings\matthew robinson\Application Data\DivX
2008-02-13 13:41 . 2008-01-04 16:58 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-02-13 13:41 . 2008-01-04 16:58 120,056 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-02-13 13:41 . 2008-01-04 16:58 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-02-08 14:15 . 2008-02-08 14:15 d——– C:\Program Files\Windows Media Connect 2
2008-02-08 14:13 . 2008-02-08 14:14 d——– C:\WINDOWS\system32\drivers\UMDF
2008-02-08 14:04 . 2008-02-08 14:04 d——– C:\Program Files\Netflix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 18:34 ——— d—–w C:\Program Files\Picasa2
2008-02-22 05:34 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:44 ——— d—–w C:\Program Files\Trillian
2008-02-13 18:41 ——— d—–w C:\Program Files\DivX
2008-01-20 17:50 ——— d—–w C:\Program Files\iTunes
2008-01-20 17:50 ——— d—–w C:\Program Files\iPod
2008-01-20 17:49 ——— d—–w C:\Program Files\QuickTime
2008-01-17 15:32 ——— d—–w C:\Program Files\AskPBar
2008-01-17 14:57 ——— d—–w C:\Program Files\Google
2008-01-17 13:26 ——— d—–w C:\Documents and Settings\matthew robinson\Application Data\Arcsoft
2008-01-15 15:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2008-01-15 15:53 ——— d—–w C:\Program Files\JustZIPit
2008-01-04 21:59 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-04 21:58 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-01-04 21:58 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 21:58 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-04 21:58 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-01-04 21:57 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-04 21:57 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-04 21:57 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-01-04 21:57 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-04 21:57 682,496 —-a-w C:\WINDOWS\system32\DivX.dll
2008-01-04 21:57 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-01-04 21:57 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2008-01-04 21:57 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-01-04 21:57 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2008-01-04 21:57 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2008-01-04 21:57 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2008-01-04 21:57 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2008-01-04 21:56 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-01-04 01:33 ——— d—–w C:\Program Files\Java
2008-01-04 01:32 ——— d—–w C:\Program Files\Common Files\Java
2008-01-02 19:48 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-14 16:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-03-30 20:00 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-03-30 20:00 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-03-30 19:59 138008]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-03-16 18:10 1392640]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 10:22 405504]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 15:49 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]

C:\Documents and Settings\matthew robinson\Start Menu\Programs\Startup\
Digsby.lnk - C:\Program Files\Digsby\digsby.exe [2008-02-15 18:30:48 115712]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 19:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Program Files\\iTunes\\iTunes.exe"=


.
Contents of the 'Scheduled Tasks' folder
"2008-01-26 23:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 11:01:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-24 11:01:56
ComboFix-quarantined-files.txt 2008-02-24 16:01:54
ComboFix2.txt 2008-02-23 16:09:21
.
2008-02-14 08:06:16 — E O F —
hi,

thanks for the info. i missed one. do the same thing before with combofix except use this:

File::
C:\WINDOWS\mrofinu572.exe.tmp

hows it looking on your end?

shelf life
hi,

sorry, i just want to be sure

no problem, you got it right.


Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:

File::
C:\WINDOWS\mrofinu572.exe.tmp

Name the Notepad file CFScript.txt and Save it to your desktop.
now locate the both file you just saved and the combofix icon

using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log
please post the new combofix log and a new hjt log.
thanks again.

combofix log:

ComboFix 08-02-23.2 - matthew robinson 2008-02-25 22:47:30.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.152 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\matthew robinson\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\mrofinu572.exe.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\mrofinu572.exe.tmp

.
((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.

2008-02-22 09:15 . 2008-02-22 09:15 d——– C:\Program Files\Trend Micro
2008-02-22 08:16 . 2008-02-23 10:34 70,686 –a—— C:\WINDOWS\BMf38a0635.xml
2008-02-22 08:16 . 2008-02-22 09:31 22 –a—— C:\WINDOWS\pskt.ini
2008-02-22 00:35 . 2008-02-22 00:35 d——– C:\Program Files\Lavasoft
2008-02-22 00:35 . 2008-02-22 00:35 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-21 19:36 . 2008-02-21 19:36 d——– C:\Program Files\Enigma Software Group
2008-02-21 19:09 . 2008-02-24 11:00 d–hs—- C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg
2008-02-21 19:08 . 2008-02-21 19:08 d——– C:\WINDOWS\system32\xb8
2008-02-21 19:08 . 2008-02-22 00:40 d——– C:\WINDOWS\system32\ff3
2008-02-21 19:08 . 2008-02-22 09:29 d——– C:\WINDOWS\system32\ez2
2008-02-21 19:08 . 2008-02-21 19:08 d——– C:\WINDOWS\system32\cms4
2008-02-19 16:38 . 2008-02-19 16:38 d——– C:\Documents and Settings\matthew robinson\Application Data\Digsby
2008-02-19 16:36 . 2008-02-20 22:36 d——– C:\Program Files\Digsby
2008-02-13 13:52 . 2008-02-13 14:15 d——– C:\Documents and Settings\matthew robinson\Application Data\DivX
2008-02-13 13:41 . 2008-01-04 16:58 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-02-13 13:41 . 2008-01-04 16:58 120,056 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-02-13 13:41 . 2008-01-04 16:58 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-02-08 14:15 . 2008-02-08 14:15 d——– C:\Program Files\Windows Media Connect 2
2008-02-08 14:13 . 2008-02-08 14:14 d——– C:\WINDOWS\system32\drivers\UMDF
2008-02-08 14:04 . 2008-02-08 14:04 d——– C:\Program Files\Netflix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 18:34 ——— d—–w C:\Program Files\Picasa2
2008-02-22 05:34 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:44 ——— d—–w C:\Program Files\Trillian
2008-02-13 18:41 ——— d—–w C:\Program Files\DivX
2008-01-20 17:50 ——— d—–w C:\Program Files\iTunes
2008-01-20 17:50 ——— d—–w C:\Program Files\iPod
2008-01-20 17:49 ——— d—–w C:\Program Files\QuickTime
2008-01-17 15:32 ——— d—–w C:\Program Files\AskPBar
2008-01-17 14:57 ——— d—–w C:\Program Files\Google
2008-01-17 13:26 ——— d—–w C:\Documents and Settings\matthew robinson\Application Data\Arcsoft
2008-01-15 15:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2008-01-15 15:53 ——— d—–w C:\Program Files\JustZIPit
2008-01-04 21:59 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-04 21:58 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-01-04 21:58 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 21:58 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-04 21:58 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-01-04 21:57 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-04 21:57 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-04 21:57 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-01-04 21:57 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-04 21:57 682,496 —-a-w C:\WINDOWS\system32\DivX.dll
2008-01-04 21:57 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-01-04 21:57 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2008-01-04 21:57 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-01-04 21:57 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2008-01-04 21:57 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2008-01-04 21:57 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2008-01-04 21:57 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2008-01-04 21:56 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-01-04 01:33 ——— d—–w C:\Program Files\Java
2008-01-04 01:32 ——— d—–w C:\Program Files\Common Files\Java
2008-01-02 19:48 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-14 16:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-03-30 20:00 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-03-30 20:00 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-03-30 19:59 138008]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-03-16 18:10 1392640]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 10:22 405504]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 15:49 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]

C:\Documents and Settings\matthew robinson\Start Menu\Programs\Startup\
Digsby.lnk - C:\Program Files\Digsby\digsby.exe [2008-02-15 18:30:48 115712]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 19:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Program Files\\iTunes\\iTunes.exe"=


.
Contents of the 'Scheduled Tasks' folder
"2008-01-26 23:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 22:49:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-25 22:49:55
ComboFix-quarantined-files.txt 2008-02-26 03:49:47
ComboFix2.txt 2008-02-24 16:01:56
ComboFix3.txt 2008-02-23 16:09:21
.
2008-02-14 08:06:16 — E O F —


hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52:44 PM, on 2/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Digsby\digsby.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netvibes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Digsby.lnk = C:\Program Files\Digsby\digsby.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.34/uploader2.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1199301478109
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E82C3F3-908E-4BCF-8C37-05C2B7302E1F}: NameServer = 192.168.18.254
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 6172 bytes
hi,

ok good. after some thought you can get rid of these also. you know the routine by now:


Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:

Folder::
C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg
C:\WINDOWS\system32\xb8
C:\WINDOWS\system32\ff3
C:\WINDOWS\system32\ez2
C:\WINDOWS\system32\cms4

File::
C:\WINDOWS\pskt.ini
C:\WINDOWS\BMf38a0635.xml

Name the Notepad file CFScript.txt and Save it to your desktop.
now locate the both file you just saved and the combofix icon

using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log
please post the new combofix log and a new hjt log.

shelf life
combix log:

ComboFix 08-02-23.2 - matthew robinson 2008-02-27 17:45:55.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.177 [GMT -5:00]Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\matthew robinson\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\BMf38a0635.xml
C:\WINDOWS\pskt.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BMf38a0635.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cms4
C:\WINDOWS\system32\cms4\kipon89104.exe
C:\WINDOWS\system32\ez2
C:\WINDOWS\system32\ff3
C:\WINDOWS\system32\xb8
C:\WINDOWS\system32\xb8\yula4403.exe
C:\WINDOWS\TWF0dGhldyBSb2JpbnNvbg

.
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.

2008-02-22 09:15 . 2008-02-22 09:15 d——– C:\Program Files\Trend Micro
2008-02-22 00:35 . 2008-02-22 00:35 d——– C:\Program Files\Lavasoft
2008-02-22 00:35 . 2008-02-22 00:35 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-21 19:36 . 2008-02-21 19:36 d——– C:\Program Files\Enigma Software Group
2008-02-19 16:38 . 2008-02-19 16:38 d——– C:\Documents and Settings\matthew robinson\Application Data\Digsby
2008-02-19 16:36 . 2008-02-20 22:36 d——– C:\Program Files\Digsby
2008-02-13 13:52 . 2008-02-13 14:15 d——– C:\Documents and Settings\matthew robinson\Application Data\DivX
2008-02-13 13:41 . 2008-01-04 16:58 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-02-13 13:41 . 2008-01-04 16:58 120,056 –a—— C:\WINDOWS\system32\pxcpyi64.exe
2008-02-13 13:41 . 2008-01-04 16:58 118,520 –a—— C:\WINDOWS\system32\pxinsi64.exe
2008-02-08 14:15 . 2008-02-08 14:15 d——– C:\Program Files\Windows Media Connect 2
2008-02-08 14:13 . 2008-02-08 14:14 d——– C:\WINDOWS\system32\drivers\UMDF
2008-02-08 14:04 . 2008-02-08 14:04 d——– C:\Program Files\Netflix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 18:34 ——— d—–w C:\Program Files\Picasa2
2008-02-22 05:34 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:44 ——— d—–w C:\Program Files\Trillian
2008-02-13 18:41 ——— d—–w C:\Program Files\DivX
2008-01-20 17:50 ——— d—–w C:\Program Files\iTunes
2008-01-20 17:50 ——— d—–w C:\Program Files\iPod
2008-01-20 17:49 ——— d—–w C:\Program Files\QuickTime
2008-01-17 15:32 ——— d—–w C:\Program Files\AskPBar
2008-01-17 14:57 ——— d—–w C:\Program Files\Google
2008-01-17 13:26 ——— d—–w C:\Documents and Settings\matthew robinson\Application Data\Arcsoft
2008-01-15 15:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2008-01-15 15:53 ——— d—–w C:\Program Files\JustZIPit
2008-01-04 21:59 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-04 21:58 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-01-04 21:58 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 21:58 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-04 21:58 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-01-04 21:57 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-04 21:57 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-04 21:57 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-01-04 21:57 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-04 21:57 682,496 —-a-w C:\WINDOWS\system32\DivX.dll
2008-01-04 21:57 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-01-04 21:57 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2008-01-04 21:57 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-01-04 21:57 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2008-01-04 21:57 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2008-01-04 21:57 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2008-01-04 21:57 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2008-01-04 21:56 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-01-04 01:33 ——— d—–w C:\Program Files\Java
2008-01-04 01:32 ——— d—–w C:\Program Files\Common Files\Java
2008-01-02 19:48 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-14 16:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-03-30 20:00 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-03-30 20:00 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-03-30 19:59 138008]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-03-16 18:10 1392640]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 10:22 405504]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 15:49 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]

C:\Documents and Settings\matthew robinson\Start Menu\Programs\Startup\
Digsby.lnk - C:\Program Files\Digsby\digsby.exe [2008-02-15 18:30:48 115712]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 19:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Program Files\\iTunes\\iTunes.exe"=


.
Contents of the 'Scheduled Tasks' folder
"2008-01-26 23:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-27 17:48:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-27 17:49:13
ComboFix-quarantined-files.txt 2008-02-27 22:49:03
ComboFix2.txt 2008-02-26 03:49:56
ComboFix3.txt 2008-02-24 16:01:56
ComboFix4.txt 2008-02-23 16:09:21
.
2008-02-14 08:06:16 — E O F —


hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:51:21 PM, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Digsby\digsby.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netvibes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Digsby.lnk = C:\Program Files\Digsby\digsby.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.34/uploader2.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1199301478109
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://javadl-esd.sun.com/update/1.4.2/jin…indows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3E82C3F3-908E-4BCF-8C37-05C2B7302E1F}: NameServer = 192.168.18.254
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 6181 bytes


thanks.
hi,

ok good. hows it looking on your end now? logs look ok as far as malware goes.

java version needs updating;

Vulnerabilities/exploits in old versions of Sun Java may be partly responsible for some malware infections via your browser.

It is very important not only to keep Sun Java up to date but also to remove older versions which have security holes and can be exploited by malware.

* 1. Uninstall old versions of Sun Java via Add/Remove Programs.

* 2. Click the Remove or Change/Remove button

* 3. Reboot your PC if prompted.

Download the latest version:

Java Runtime Environment (JRE) 6 Update ??
The full internal version number for this update release is 1.6.0_03-b05 ("b" means "build"). The external version number is 6u5.

Download from:
http://java.sun.com/javase/downloads/index.jsp

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI