Thank you for your response - before applying these fixes I'd noticed the problems only persist after restarting my computer - so I've left my compute running the last few days to get the work done needed for my wedding - I will restart and check the status in a few days but before then here are the logs you requested - Hijack this was unable to fix
O20 - AppInit_DLLs: C:\WINDOWS\system32\systp.dll
O20 - Winlogon Notify: rbsldad - C:\WINDOWS\SYSTEM32\rbsldad.dll
The error given is posted below
thanks again
Brent
ComboFix 08-05-09.1 - bforrest 2008-05-14 18:10:51.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1536 [GMT -4:00]
Running from: C:\Documents and Settings\bforrest\Desktop\system Helpers\ComboFix.exe
Command switches used :: C:\Documents and Settings\bforrest\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-04-14 to 2008-05-14 )))))))))))))))))))))))))))))))
.
2008-05-14 03:00 . 2008-05-14 03:00 <DIR> d-------- C:\WINDOWS\LastGood
2008-05-12 16:38 . 2008-05-12 16:38 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-12 16:38 . 2008-05-12 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-12 15:28 . 2008-05-12 15:28 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-10 10:11 . 2008-05-10 10:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-10 10:11 . 2008-05-10 10:11 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-10 03:00 . 2008-05-10 03:00 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-09 22:20 . 2008-05-09 22:20 <DIR> d-------- C:\Program Files\eRightSoft
2008-05-09 22:20 . 2008-05-09 22:20 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-05-09 22:08 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-09 22:08 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-05-09 22:08 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-05-09 21:49 . 2008-05-09 21:49 21,504 --a------ C:\WINDOWS\system32\rbsldad.dll
2008-05-09 00:57 . 2008-05-09 00:57 <DIR> d-------- C:\Program Files\Registrar Registry Manager
2008-05-09 00:57 . 2008-02-09 11:20 31,280 --a------ C:\WINDOWS\system32\rrMon.sys
2008-05-08 22:01 . 2008-05-08 22:01 <DIR> d-------- C:\Program Files\Alwil Software
2008-05-07 23:58 . 2008-05-12 16:38 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-07 20:14 . 2008-05-12 15:35 196,608 --a------ C:\WINDOWS\system32\Rsox.exe
2008-05-07 20:14 . 2008-05-12 15:35 135,168 --a------ C:\WINDOWS\system32\MiRD.dll
2008-05-07 20:14 . 2008-05-12 15:35 106,496 --a------ C:\WINDOWS\system32\BuYw.dll
2008-05-07 20:14 . 2008-05-07 20:14 81,920 --a------ C:\WINDOWS\system32\WiIW.dll
2008-05-07 20:14 . 2008-05-07 20:14 73,728 --a------ C:\WINDOWS\system32\WLXlyt.dll
2008-05-07 20:09 . 2008-05-07 20:09 123,392 --a------ C:\WINDOWS\system32\drivers\qandr.sys
2008-05-07 20:09 . 2008-05-07 20:09 29 --a------ C:\WINDOWS\system32\yfeyhioh.tmp
2008-05-06 17:56 . 2008-05-06 17:56 192,512 --a------ C:\WINDOWS\system32\cbOCR.dll
2008-05-06 17:08 . 2008-05-06 17:08 10,752 -rah----- C:\WINDOWS\system32\svchsh.exe
2008-05-06 17:03 . 2008-05-07 20:34 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-05-06 17:03 . 2008-05-06 17:03 <DIR> d-------- C:\Documents and Settings\bforrest\Application Data\CyberLink
2008-05-06 17:03 . 2008-05-06 17:03 <DIR> d-------- C:\Documents and Settings\bforrest\Application Data\AVS4YOU
2008-05-06 17:03 . 2008-05-06 17:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-05-06 17:02 . 2008-05-07 20:34 <DIR> d-------- C:\Program Files\AVS4YOU
2008-05-06 16:34 . 2008-05-06 16:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Cyberlink
2008-05-06 16:34 . 2006-06-04 15:48 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-05-06 16:34 . 2006-06-04 15:48 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-05-06 16:33 . 2008-05-06 16:39 <DIR> d-------- C:\Program Files\CyberLink
2008-05-06 16:33 . 2008-05-06 16:33 <DIR> d-------- C:\MyWorks
2008-05-06 16:33 . 2006-06-04 15:48 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-05-06 16:33 . 2006-06-04 15:48 1,047,552 --a------ C:\WINDOWS\system32\MFC71u.dll
2008-05-06 16:33 . 2006-06-04 15:48 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-05-06 16:33 . 2006-06-04 15:48 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-05-06 16:33 . 2006-06-04 15:48 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-04-18 19:57 . 2008-04-18 19:57 <DIR> d-------- C:\Program Files\Snapshot Viewer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-14 02:42 --------- d-----w C:\Documents and Settings\bforrest\Application Data\OpenOffice.org2
2008-05-14 00:26 --------- d-----w C:\Documents and Settings\bforrest\Application Data\WTablet
2008-05-13 22:19 --------- d-----w C:\Documents and Settings\LocalService\Application Data\WTablet
2008-05-12 23:54 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-06 20:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-06 20:33 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-02 01:49 --------- d-----w C:\Program Files\Java
2008-04-11 02:50 --------- d-----w C:\Documents and Settings\bforrest\Application Data\Lexmark Productivity Studio
2008-04-09 03:16 --------- d-----w C:\Program Files\Lexmark 6500 Series
2008-04-01 00:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 12:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
.
((((((((((((((((((((((((((((( snapshot_2008-05-12_15.34.57.89 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-23 04:56:21 554,008 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\dao360.dll
+ 2007-12-10 12:41:11 518,944 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexch40.dll
+ 2007-12-10 12:41:11 326,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msexcl40.dll
+ 2007-12-10 12:41:11 1,516,568 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjet40.dll
+ 2007-12-10 12:41:11 355,112 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjetol1.dll
+ 2008-03-27 07:39:13 151,583 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjint40.dll
+ 2007-12-10 12:41:12 60,192 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjter40.dll
+ 2007-12-10 12:41:12 248,608 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msjtes40.dll
+ 2007-12-10 12:41:12 219,936 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msltus40.dll
+ 2007-12-10 12:41:12 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mspbde40.dll
+ 2007-12-10 12:41:13 432,928 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd2x40.dll
+ 2007-12-10 12:41:13 322,336 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrd3x40.dll
+ 2007-12-10 12:41:13 559,904 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msrepl40.dll
+ 2007-12-10 12:41:13 264,992 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mstext40.dll
+ 2007-12-10 12:41:13 838,432 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswdat10.dll
+ 2007-12-10 12:41:14 621,344 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\mswstr10.dll
+ 2007-12-10 12:41:14 355,104 ----a-w C:\WINDOWS\$hf_mig$\KB950749\SP2QFE\msxbde40.dll
+ 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spmsg.dll
+ 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB950749\spuninst.exe
+ 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\update.exe
+ 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB950749\update\updspapi.dll
- 2008-05-12 19:24:00 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-14 00:25:55 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-12 20:38:38 1,038,336 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC.exe
+ 2008-05-12 20:38:38 178,688 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\Icon0E6AB9FC1.exe
+ 2008-05-12 20:38:38 171,008 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B.exe
+ 2008-05-12 20:38:38 8,704 ----a-r C:\WINDOWS\Installer\{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}\IconDED53B0B1.exe
- 2006-02-28 12:00:00 561,179 -c--a-w C:\WINDOWS\system32\dllcache\dao360.dll
+ 2008-03-25 04:50:25 554,008 -c--a-w C:\WINDOWS\system32\dllcache\dao360.dll
- 2006-02-28 12:00:00 512,029 -c--a-w C:\WINDOWS\system32\dllcache\msexch40.dll
+ 2008-03-25 04:50:28 518,944 -c--a-w C:\WINDOWS\system32\dllcache\msexch40.dll
- 2006-02-28 12:00:00 319,517 -c--a-w C:\WINDOWS\system32\dllcache\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 -c--a-w C:\WINDOWS\system32\dllcache\msexcl40.dll
- 2006-02-28 12:00:00 1,507,356 -c--a-w C:\WINDOWS\system32\dllcache\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 -c--a-w C:\WINDOWS\system32\dllcache\msjet40.dll
- 2006-02-28 12:00:00 358,976 -c--a-w C:\WINDOWS\system32\dllcache\msjetol1.dll
+ 2008-03-25 04:50:40 355,112 -c--a-w C:\WINDOWS\system32\dllcache\msjetol1.dll
- 2006-02-28 12:00:00 151,583 -c--a-w C:\WINDOWS\system32\dllcache\msjint40.dll
+ 2008-03-27 08:12:54 151,583 -c--a-w C:\WINDOWS\system32\dllcache\msjint40.dll
- 2006-02-28 12:00:00 53,279 -c--a-w C:\WINDOWS\system32\dllcache\msjter40.dll
+ 2008-03-25 04:50:42 60,192 -c--a-w C:\WINDOWS\system32\dllcache\msjter40.dll
- 2006-02-28 12:00:00 241,693 -c--a-w C:\WINDOWS\system32\dllcache\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 -c--a-w C:\WINDOWS\system32\dllcache\msjtes40.dll
- 2006-02-28 12:00:00 213,023 -c--a-w C:\WINDOWS\system32\dllcache\msltus40.dll
+ 2008-03-25 04:50:44 219,936 -c--a-w C:\WINDOWS\system32\dllcache\msltus40.dll
- 2006-02-28 12:00:00 348,189 -c--a-w C:\WINDOWS\system32\dllcache\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 -c--a-w C:\WINDOWS\system32\dllcache\mspbde40.dll
- 2006-02-28 12:00:00 421,919 -c--a-w C:\WINDOWS\system32\dllcache\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 -c--a-w C:\WINDOWS\system32\dllcache\msrd2x40.dll
- 2006-02-28 12:00:00 315,423 -c--a-w C:\WINDOWS\system32\dllcache\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 -c--a-w C:\WINDOWS\system32\dllcache\msrd3x40.dll
- 2006-02-28 12:00:00 552,989 -c--a-w C:\WINDOWS\system32\dllcache\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 -c--a-w C:\WINDOWS\system32\dllcache\msrepl40.dll
- 2006-02-28 12:00:00 258,077 -c--a-w C:\WINDOWS\system32\dllcache\mstext40.dll
+ 2008-03-25 04:50:55 264,992 -c--a-w C:\WINDOWS\system32\dllcache\mstext40.dll
- 2006-02-28 12:00:00 831,519 -c--a-w C:\WINDOWS\system32\dllcache\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 -c--a-w C:\WINDOWS\system32\dllcache\mswdat10.dll
- 2006-02-28 12:00:00 614,429 -c--a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 -c--a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
- 2006-02-28 12:00:00 348,189 -c--a-w C:\WINDOWS\system32\dllcache\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 -c--a-w C:\WINDOWS\system32\dllcache\msxbde40.dll
+ 2007-07-11 18:37:26 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
+ 2007-08-07 17:58:08 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
+ 2007-08-07 17:56:58 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
- 2006-02-28 12:00:00 512,029 ----a-w C:\WINDOWS\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 ----a-w C:\WINDOWS\system32\msexch40.dll
- 2006-02-28 12:00:00 319,517 ----a-w C:\WINDOWS\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 ----a-w C:\WINDOWS\system32\msexcl40.dll
- 2006-02-28 12:00:00 1,507,356 ----a-w C:\WINDOWS\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 ----a-w C:\WINDOWS\system32\msjet40.dll
- 2006-02-28 12:00:00 358,976 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
- 2006-02-28 12:00:00 53,279 ----a-w C:\WINDOWS\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 ----a-w C:\WINDOWS\system32\msjter40.dll
- 2006-02-28 12:00:00 241,693 ----a-w C:\WINDOWS\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 ----a-w C:\WINDOWS\system32\msjtes40.dll
- 2006-02-28 12:00:00 213,023 ----a-w C:\WINDOWS\system32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
- 2006-02-28 12:00:00 348,189 ----a-w C:\WINDOWS\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 ----a-w C:\WINDOWS\system32\mspbde40.dll
- 2006-02-28 12:00:00 421,919 ----a-w C:\WINDOWS\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 ----a-w C:\WINDOWS\system32\msrd2x40.dll
- 2006-02-28 12:00:00 315,423 ----a-w C:\WINDOWS\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 ----a-w C:\WINDOWS\system32\msrd3x40.dll
- 2006-02-28 12:00:00 552,989 ----a-w C:\WINDOWS\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 ----a-w C:\WINDOWS\system32\msrepl40.dll
- 2006-02-28 12:00:00 258,077 ----a-w C:\WINDOWS\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 ----a-w C:\WINDOWS\system32\mstext40.dll
- 2006-02-28 12:00:00 831,519 ----a-w C:\WINDOWS\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 ----a-w C:\WINDOWS\system32\mswdat10.dll
- 2006-02-28 12:00:00 614,429 ----a-w C:\WINDOWS\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
- 2006-02-28 12:00:00 348,189 ----a-w C:\WINDOWS\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 ----a-w C:\WINDOWS\system32\msxbde40.dll
+ 2008-05-14 00:56:21 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_53c.dat
+ 2008-05-14 00:26:01 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5b8.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 06:06 79224]
C:\Documents and Settings\bforrest\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50 113664]
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 17:45:48 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rbsldad]
rbsldad.dll 2008-05-09 21:49 21504 C:\WINDOWS\system32\rbsldad.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlxlyt]
WLXlyt.dll 2008-05-07 20:14 73728 C:\WINDOWS\system32\WLXlyt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\systp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"SENTINEL"= snti386.dll
"vidc.yv12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Autodesk\\Maya8.5\\bin\\maya.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Lexmark 6500 Series\\lxdfamon.exe"=
"C:\\Program Files\\Lexmark 6500 Series\\FRun.exe"=
"C:\\Program Files\\Lexmark 6500 Series\\lxdfmon.exe"=
"C:\\WINDOWS\\system32\\lxdfcfg.exe"=
"C:\\WINDOWS\\system32\\lxdfcoms.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdfpswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdftime.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdfjswx.exe"=
"C:\\Program Files\\Lexmark 6500 Series\\Wireless\\lxdfwpss.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 lxdf_device;lxdf_device;C:\WINDOWS\system32\lxdfcoms.exe [2007-05-29 06:06]
R2 TabletServiceWacom;TabletServiceWacom;C:\WINDOWS\system32\Wacom_Tablet.exe [2007-09-07 12:40]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-07-28 00:28]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 12:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 11:30]
R3 WacomVKHid;Virtual Keyboard Driver;C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-15 17:11]
S2 lxdfCATSCustConnectService;lxdfCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdfserv.exe [2007-05-29 06:06]
S2 qandr;qandr;C:\WINDOWS\system32\drivers\qandr.sys [2008-05-07 20:09]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-14 18:11:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\DiagnosticScan]
"ImagePath"="\??\C:\Program Files\Adware Away\DiagnosticScan.SYS"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\WLXlyt.dll
-> C:\WINDOWS\system32\rbsldad.dll
-> C:\WINDOWS\system32\WiIW.dll
.
Completion time: 2008-05-14 18:11:43
ComboFix-quarantined-files.txt 2008-05-14 22:11:32
ComboFix2.txt 2008-05-14 02:42:00
ComboFix3.txt 2008-05-14 00:29:45
ComboFix4.txt 2008-05-13 01:18:01
ComboFix5.txt 2008-05-12 19:35:19
Pre-Run: 236,353,191,936 bytes free
Post-Run: 236,325,601,280 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
****************************
O20 - AppInit_DLLs: C:\WINDOWS\system32\systp.dll
O20 - Winlogon Notify: rbsldad - C:\WINDOWS\SYSTEM32\rbsldad.dll
were present but got this error:
261 --- E O F --- 2008-05-14 07:00:38
An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: C:\WINDOWS\system32\systp.dll)
Error #5 - Invalid procedure call or argument
Please email me at merijn@spywareinfo.com, reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible
Windows version: Windows NT 5.01.2600
MSIE version: 7.0.5730.11
HijackThis version: 1.99.1
This message has been copied to your clipboard.
Click OK to continue the rest of the scan.
****************************************
ComboFix 08-05-09.1 - bforrest 2008-05-14 18:16:59.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1533 [GMT -4:00]
Running from: C:\Documents and Settings\bforrest\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\bforrest\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\BuYw.dll
C:\WINDOWS\system32\cbOCR.dll
C:\WINDOWS\system32\MiRD.dll
C:\WINDOWS\system32\Rsox.exe
C:\WINDOWS\system32\svchsh.exe
C:\WINDOWS\system32\WiIW.dll
C:\WINDOWS\system32\WLXlyt.dll
C:\WINDOWS\system32\yfeyhioh.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\BuYw.dll
C:\WINDOWS\system32\cbOCR.dll
C:\WINDOWS\system32\MiRD.dll
C:\WINDOWS\system32\Rsox.exe
C:\WINDOWS\system32\svchsh.exe
C:\WINDOWS\system32\WiIW.dll
C:\WINDOWS\system32\WLXlyt.dll
C:\WINDOWS\system32\yfeyhioh.tmp
.
((((((((((((((((((((((((( Files Created from 2008-04-14 to 2008-05-14 )))))))))))))))))))))))))))))))
.
2008-05-12 16:38 . 2008-05-12 16:38 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-12 16:38 . 2008-05-12 19:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-12 15:28 . 2008-05-12 15:28 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-10 10:11 . 2008-05-10 10:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-10 10:11 . 2008-05-10 10:11 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-10 03:00 . 2008-05-10 03:00 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-09 22:20 . 2008-05-09 22:20 <DIR> d-------- C:\Program Files\eRightSoft
2008-05-09 22:20 . 2008-05-09 22:20 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-05-09 22:08 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-09 22:08 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-05-09 22:08 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-05-09 21:49 . 2008-05-09 21:49 21,504 --a------ C:\WINDOWS\system32\rbsldad.dll
2008-05-09 00:57 . 2008-05-09 00:57 <DIR> d-------- C:\Program Files\Registrar Registry Manager
2008-05-09 00:57 . 2008-02-09 11:20 31,280 --a------ C:\WINDOWS\system32\rrMon.sys
2008-05-08 22:01 . 2008-05-08 22:01 <DIR> d-------- C:\Program Files\Alwil Software
2008-05-07 23:58 . 2008-05-12 16:38 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-07 20:09 . 2008-05-07 20:09 123,392 --a------ C:\WINDOWS\system32\drivers\qandr.sys
2008-05-06 17:03 . 2008-05-07 20:34 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2008-05-06 17:03 . 2008-05-06 17:03 <DIR> d-------- C:\Documents and Settings\bforrest\Application Data\CyberLink
2008-05-06 17:03 . 2008-05-06 17:03 <DIR> d-------- C:\Documents and Settings\bforrest\Application Data\AVS4YOU
2008-05-06 17:03 . 2008-05-06 17:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-05-06 17:02 . 2008-05-07 20:34 <DIR> d-------- C:\Program Files\AVS4YOU
2008-05-06 16:34 . 2008-05-06 16:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Cyberlink
2008-05-06 16:34 . 2006-06-04 15:48 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-05-06 16:34 . 2006-06-04 15:48 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-05-06 16:33 . 2008-05-06 16:39 <DIR> d-------- C:\Program Files\CyberLink
2008-05-06 16:33 . 2008-05-06 16:33 <DIR> d-------- C:\MyWorks
2008-05-06 16:33 . 2006-06-04 15:48 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-05-06 16:33 . 2006-06-04 15:48 1,047,552 --a------ C:\WINDOWS\system32\MFC71u.dll
2008-05-06 16:33 . 2006-06-04 15:48 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-05-06 16:33 . 2006-06-04 15:48 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-05-06 16:33 . 2006-06-04 15:48 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-04-18 19:57 . 2008-04-18 19:57 <DIR> d-------- C:\Program Files\Snapshot Viewer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-14 22:19 --------- d-----w C:\Documents and Settings\bforrest\Application Data\WTablet
2008-05-14 22:19 --------- d-----w C:\Documents and Settings\bforrest\Application Data\OpenOffice.org2
2008-05-13 22:19 --------- d-----w C:\Documents and Settings\LocalService\Application Data\WTablet
2008-05-06 20:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-06 20:33 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-02 01:49 --------- d-----w C:\Program Files\Java
2008-04-11 02:50 --------- d-----w C:\Documents and Settings\bforrest\Application Data\Lexmark Productivity Studio
2008-04-09 03:16 --------- d-----w C:\Program Files\Lexmark 6500 Series
2008-04-01 00:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2007-12-17 12:43 27,648 --sh--w C:\WINDOWS\system32\Smab0.dll
.
((((((((((((((((((((((((((((( snapshot_2008-05-14_18.11.28.26 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-14 00:25:55 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-14 22:18:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-14 22:18:44 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5c0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 02:41 8523776]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 06:06 79224]
C:\Documents and Settings\bforrest\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50 113664]
OpenOffice.org 2.1.lnk - C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe [2006-11-27 17:45:48 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"SENTINEL"= snti386.dll
"vidc.yv12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Autodesk\\Maya8.5\\bin\\maya.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Lexmark 6500 Series\\lxdfamon.exe"=
"C:\\Program Files\\Lexmark 6500 Series\\FRun.exe"=
"C:\\Program Files\\Lexmark 6500 Series\\lxdfmon.exe"=
"C:\\WINDOWS\\system32\\lxdfcfg.exe"=
"C:\\WINDOWS\\system32\\lxdfcoms.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdfpswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdftime.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdfjswx.exe"=
"C:\\Program Files\\Lexmark 6500 Series\\Wireless\\lxdfwpss.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 lxdf_device;lxdf_device;C:\WINDOWS\system32\lxdfcoms.exe [2007-05-29 06:06]
R2 TabletServiceWacom;TabletServiceWacom;C:\WINDOWS\system32\Wacom_Tablet.exe [2007-09-07 12:40]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-07-28 00:28]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 12:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 11:30]
R3 WacomVKHid;Virtual Keyboard Driver;C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-15 17:11]
S2 lxdfCATSCustConnectService;lxdfCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdfserv.exe [2007-05-29 06:06]
S2 qandr;qandr;C:\WINDOWS\system32\drivers\qandr.sys [2008-05-07 20:09]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-14 18:19:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.bin
.
**************************************************************************
.
Completion time: 2008-05-14 18:21:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-14 22:21:51
ComboFix2.txt 2008-05-14 22:11:44
ComboFix3.txt 2008-05-14 02:42:00
ComboFix4.txt 2008-05-14 00:29:45
ComboFix5.txt 2008-05-13 01:18:01
Pre-Run: 236,324,028,416 bytes free
Post-Run: 236,313,350,144 bytes free
164 --- E O F --- 2008-05-14 07:00:38
Malwarebytes' Anti-Malware 1.12
Database version: 750
Scan type: Full Scan (C:\|)
Objects scanned: 106262
Time elapsed: 13 minute(s), 32 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 21
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\qandr (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\qandr (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\qandr (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\bforrest\Desktop\cbOCR.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\bqzpas.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\cbOCR.dll.vir (Trojan.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\fccaBTKC.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\geBtUkhi.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\svchsh.exe.vir (Backdoor.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\tcpsr.sys.vir (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP76\A0005516.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP76\A0005525.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP77\A0005829.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP77\A0005840.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP77\A0005847.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP77\A0005864.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP77\A0005884.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP78\A0005904.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP78\A0005909.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP78\A0005910.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP78\A0005922.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP83\A0006902.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4CBCCC4B-4DFC-4503-AC9B-1320A341E9AE}\RP83\A0006905.exe (Backdoor.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\qandr.sys (Rootkit.Agent) -> Quarantined and deleted successfully.