This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

help TROJAN.Vundo removal!

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Need some help making computer RIGHT again:

alwarebytes' Anti-Malware 1.12
Database version: 768

Scan type: Quick Scan
Objects scanned: 37879
Time elapsed: 4 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\ljJYrqrs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\srqrYJjl.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mlJAqnKa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\core.cache.dsk (Malware.Trace) -> Delete on reboot.


Hijack this log:
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:57 AM, on 5/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Shield\shdserv.exe
C:\WINDOWS\system32\STacSV.exe
C:\Program Files\Shield\shieldclnt.exe
C:\WINDOWS\sttray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Shield\shieldtray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\cpd2000\W32MKDE.EXE
C:\cpd2000\CPD2000n.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iland.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.248.160.18:80
O2 - BHO: (no name) - {0F0F0AD5-2AB7-4351-AC75-4003857305CD} - (no file)
O2 - BHO: (no name) - {1ad449cb-5a66-406b-9f38-2960030a39b6} - (no file)
O2 - BHO: (no name) - {26906BB1-F7BE-499C-B8FB-4B4D9CA1F4B4} - C:\WINDOWS\system32\vtUnnLDw.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8691F860-96E4-4FB3-8D35-531C0D1B0AC1} - (no file)
O2 - BHO: (no name) - {993a96bd-8de7-432b-8419-15db3cc46dda} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [shield] C:\Program Files\Shield\shieldtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\CPD USER\lsass.exe
O4 - HKLM\..\Run: [dbar_starter] C:\Documents and Settings\CPD USER\Application Data\Deskbar_{081614EE-2951-41e2-935C-925F38945AF0}\starter.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Anti-Virus&Trojan.lnk = C:\Program Files\Anti-Virus&Trojan\Anti-Virus&Trojan.exe
O4 - Global Startup: CPD Fax.LNK = C:\cpdfax\CpdFax32.exe
O4 - Global Startup: CPD Net XP.LNK = C:\cpd2000\CPD2000n.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1210883551687
O16 - DPF: {73A8D51E-578B-4E4E-8FF8-112E51DBFBE3} (ADPConn Class) - http://caf.oeconnection.com/ActiveX/DMSISM.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://snap-on.webex.com/client/T26L10NSP4…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS3\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SHDSERV - Unknown owner - C:\Program Files\Shield\shdserv.exe
O23 - Service: Shield Client Service (ShieldClientService) - Unknown owner - C:\Program Files\Shield\shieldclnt.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe

–
End of file - 7691 bytes
hi btorok,

a download to run:

Download SDFix and save it to your Desktop.


http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, the Advanced Options Menu should appear;
* Select the first option, to run Windows in Safe Mode, then press Enter.
* Choose your usual account.


* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
* Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).

* Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Heres what we got after running SDFix:



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\Temp\1cb\syscheck.log - Deleted
C:\Temp\tmpvc14\dllvc.log - Deleted
C:\WINDOWS\system32\drivers\core.cache(2).dsk - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\TCPIP66.sys - Deleted



Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed
Folder C:\Temp\tmpvc14 - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-20 10:14:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\WINDOWS\\system32\\mmc.exe"="C:\\WINDOWS\\system32\\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\SDFix\backups\backups.zip

Files with Hidden Attributes :

Mon 28 Jan 2008 1,404,240 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR — "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR — "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Fri 16 May 2008 1,773,426 A.SH. — "C:\WINDOWS\system32\jeunmrof.tmp"
Thu 15 Nov 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

Finished!


Now my HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:11 AM, on 5/20/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Shield\shdserv.exe
C:\WINDOWS\system32\STacSV.exe
C:\Program Files\Shield\shieldclnt.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sttray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Shield\shieldtray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\cpd2000\CPD2000n.exe
C:\cpd2000\W32MKDE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iland.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.248.160.18:80
O2 - BHO: (no name) - {0F0F0AD5-2AB7-4351-AC75-4003857305CD} - (no file)
O2 - BHO: (no name) - {1ad449cb-5a66-406b-9f38-2960030a39b6} - (no file)
O2 - BHO: (no name) - {26906BB1-F7BE-499C-B8FB-4B4D9CA1F4B4} - C:\WINDOWS\system32\vtUnnLDw.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8691F860-96E4-4FB3-8D35-531C0D1B0AC1} - (no file)
O2 - BHO: (no name) - {993a96bd-8de7-432b-8419-15db3cc46dda} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [shield] C:\Program Files\Shield\shieldtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Anti-Virus&Trojan.lnk = C:\Program Files\Anti-Virus&Trojan\Anti-Virus&Trojan.exe
O4 - Global Startup: CPD Fax.LNK = C:\cpdfax\CpdFax32.exe
O4 - Global Startup: CPD Net XP.LNK = C:\cpd2000\CPD2000n.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1210883551687
O16 - DPF: {73A8D51E-578B-4E4E-8FF8-112E51DBFBE3} (ADPConn Class) - http://caf.oeconnection.com/ActiveX/DMSISM.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://snap-on.webex.com/client/T26L10NSP4…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS3\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SHDSERV - Unknown owner - C:\Program Files\Shield\shdserv.exe
O23 - Service: Shield Client Service (ShieldClientService) - Unknown owner - C:\Program Files\Shield\shieldclnt.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe

–
End of file - 7583 bytes

Thanks,
Bob
hi btorok,

ok good thanks for the info. we will use hjt. but first need to disable spybots tea timer as a precaution;

1. Run Spybot-S&D in Advanced Mode.
2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
3. On the left hand side, Click on Tools
4. Then click on the Resident Icon in the List
5. Uncheck "Resident TeaTimer" and OK any prompts.
6. Restart your computer.
—————————-
hjt:

start HJT, click the "Scan" button. check the items below, close any open windows, then click "Fixed checked"

O2 - BHO: (no name) - {0F0F0AD5-2AB7-4351-AC75-4003857305CD} - (no file)
O2 - BHO: (no name) - {1ad449cb-5a66-406b-9f38-2960030a39b6} - (no file)
O2 - BHO: (no name) - {26906BB1-F7BE-499C-B8FB-4B4D9CA1F4B4} - C:\WINDOWS\system32\vtUnnLDw.dll (file missing)
O2 - BHO: (no name) - {8691F860-96E4-4FB3-8D35-531C0D1B0AC1} - (no file)
O2 - BHO: (no name) - {993a96bd-8de7-432b-8419-15db3cc46dda} - (no file)

O4 - Global Startup: CPD Fax.LNK = C:\cpdfax\CpdFax32.exe
O4 - Global Startup: CPD Net XP.LNK = C:\cpd2000\CPD2000n.exe
——————————–
is this something you downloaded and installed?>>C:\Program Files\Anti-Virus&Trojan

do you have any idea what these could be? Two folders with .exe inside?

C:\cpd2000\CPD2000n.exe
C:\cpd2000\W32MKDE.EXE

you can go to this website below, browse for one of the .exe inside the folder and click the send button to upload the .exe
you can copy/paste the result in your reply
http://www.virustotal.com/
——————————————-
do another scan with malwarebytes also.
post the malwarebytes log and one more hjt log please and the results of that .exe scan

re-enable spybots tea timer.
Ok here is what we've got now. Also the two C:\cpd2000.exe files are good, they have to do with my parts look up software for work, so I did not upload them. Here are my logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:57:21 AM, on 5/21/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Shield\shdserv.exe
C:\WINDOWS\system32\STacSV.exe
C:\Program Files\Shield\shieldclnt.exe
C:\WINDOWS\sttray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Shield\shieldtray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iland.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.248.160.18:80
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [shield] C:\Program Files\Shield\shieldtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: CPD Fax.LNK = C:\cpdfax\CpdFax32.exe
O4 - Global Startup: CPD Net XP.LNK = C:\cpd2000\CPD2000n.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1210883551687
O16 - DPF: {73A8D51E-578B-4E4E-8FF8-112E51DBFBE3} (ADPConn Class) - http://caf.oeconnection.com/ActiveX/DMSISM.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://snap-on.webex.com/client/T26L10NSP4…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS3\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SHDSERV - Unknown owner - C:\Program Files\Shield\shdserv.exe
O23 - Service: Shield Client Service (ShieldClientService) - Unknown owner - C:\Program Files\Shield\shieldclnt.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe

–
End of file - 6870 bytes

And the malwarebytes log:


Malwarebytes' Anti-Malware 1.12
Database version: 774

Scan type: Quick Scan
Objects scanned: 44980
Time elapsed: 7 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 4
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\WINDOWS\system32\polX (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\GUI2 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\binR (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\3036a (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\gside.exe (Trojan.Agent) -> Quarantined and deleted successfully.


I also did get rid of the C:prog files\anti-virus&Trojan

Thanks again as always! You guys are the best!
hi btorok,

ok thanks for the info. one more download to use, which should wrap things up.

1. Download combofix from any of these links and save it to Desktop:

http://subs.geekstogo.com/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

**Note: It is important that it is saved directly to your desktop**

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you (C:\ComboFix.txt). Post that log in your next reply

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall

please post the combofix log.
Here is the combofix report:

ComboFix 08-05-21.2 - CPD USER 2008-05-22 8:50:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2571 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BMefbdb84e.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bnskawie.ini
C:\WINDOWS\system32\jeunmrof.ini
C:\WINDOWS\system32\jeunmrof.ini2
C:\WINDOWS\system32\jeunmrof.tmp
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\wDLnnUtv.ini
C:\WINDOWS\system32\wDLnnUtv.ini2
C:\WINDOWS\winhelp.ini

.
((((((((((((((((((((((((( Files Created from 2008-04-22 to 2008-05-22 )))))))))))))))))))))))))))))))
.

2008-05-22 08:50 . 2008-05-22 08:50 d——– C:\quarantine
2008-05-20 10:00 . 2008-05-20 10:00 d——– C:\WINDOWS\ERUNT
2008-05-20 09:56 . 2008-05-20 09:56 d——– C:\SDFix
2008-05-19 13:53 . 2008-05-21 12:13 d–h—– C:\$AVG8.VAULT$
2008-05-19 12:00 . 2008-05-22 08:55 d——– C:\WINDOWS\system32\drivers\Avg
2008-05-19 12:00 . 2008-05-19 12:00 d——– C:\Program Files\AVG
2008-05-19 12:00 . 2008-05-19 12:00 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-05-19 12:00 . 2008-05-19 12:00 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-19 12:00 . 2008-05-19 12:00 75,272 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-19 12:00 . 2008-05-19 12:00 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Documents and Settings\CPD USER\Application Data\Malwarebytes
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-19 11:04 . 2008-05-05 20:46 27,048 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-19 11:04 . 2008-05-05 20:46 15,864 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-05-19 08:10 . 2008-05-19 08:10 109,056 –a—— C:\WINDOWS\system32\skbllqxx.dll
2008-05-19 07:59 . 2008-05-19 07:59 109,056 –a—— C:\WINDOWS\system32\huiktdlf.dll
2008-05-16 15:27 . 2008-05-19 07:54 553 –a—— C:\$bootcln.sch
2008-05-16 11:49 . 2008-05-16 11:49 108,544 –a—— C:\WINDOWS\system32\jmunimmj.dll
2008-05-16 08:24 . 2008-05-16 08:24 294 –a—— C:\WINDOWS\system32\MRT.INI
2008-05-16 08:05 . 2008-05-16 08:05 d——– C:\Program Files\Windows Defender
2008-05-16 07:38 . 2008-05-16 07:38 d——– C:\Program Files\Trend Micro
2008-05-15 15:19 . 2008-05-20 07:54 556 –a—— C:\WINDOWS\wininit.ini
2008-05-15 13:28 . 2008-05-19 12:01 8,192 –a—— C:\Documents and Settings\sbsuser
2008-05-15 13:22 . 2008-05-15 13:22 d——– C:\Program Files\Spybot - Search & Destroy
2008-05-15 13:22 . 2008-05-15 13:28 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-15 12:25 . 2008-05-15 12:25 d–h—– C:\WINDOWS\system32\GroupPolicy
2008-05-15 10:27 . 2001-08-17 12:48 17,664 –a—— C:\WINDOWS\system32\drivers\sermouse.sys
2008-05-15 10:27 . 2001-08-17 12:48 17,664 –a–c— C:\WINDOWS\system32\dllcache\sermouse.sys
2008-05-15 10:13 . 2008-05-15 10:13 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2008-05-15 10:00 . 2008-05-19 14:07 d–hs—- C:\WINDOWS\U0JTVXNlcg
2008-05-15 10:00 . 2008-05-15 14:37 d——– C:\WINDOWS\system32\dFrnx18
2008-05-15 10:00 . 2008-05-20 10:14 d——– C:\Temp
2008-05-15 09:40 . 2008-05-15 09:40 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-05-14 15:52 . 2008-05-14 15:52 d——– C:\Program Files\insiderbaseball 2008
2008-05-14 15:48 . 2008-05-20 11:14 d——– C:\Documents and Settings\CPD USER\Application Data\LimeWire
2008-05-14 15:42 . 2008-05-14 15:42 d——– C:\WINDOWS\Sun
2008-05-14 15:42 . 2008-02-22 02:33 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-05-14 15:41 . 2008-05-14 15:42 d——– C:\Program Files\Java
2008-05-14 15:39 . 2008-05-14 15:39 d——– C:\Program Files\Common Files\Java
2008-05-14 15:36 . 2008-05-20 11:14 d——– C:\Program Files\LimeWire
2008-05-13 07:56 . 2008-05-13 07:56 d——– C:\cpdfax
2008-05-13 07:56 . 2002-03-14 14:46 339,968 –a—— C:\WINDOWS\system32\imgman32.dll
2008-05-13 07:56 . 2001-04-03 07:10 249,856 –a—— C:\WINDOWS\system32\dtidb.dll
2008-05-13 07:56 . 2001-06-26 08:28 208,896 –a—— C:\WINDOWS\system32\fm3032.exe
2008-05-13 07:56 . 2001-06-26 08:25 77,824 –a—— C:\WINDOWS\system32\fm3032d.dll
2008-05-13 07:56 . 2001-06-26 08:30 53,248 -ra—— C:\WINDOWS\system32\im32xfax.del
2008-05-13 07:56 . 2001-06-26 08:31 47,300 -ra—— C:\WINDOWS\system32\dtmon.dll
2008-05-13 07:56 . 2003-06-02 10:53 3,020 -ra—— C:\WINDOWS\system32\cover2.pg
2008-05-13 07:56 . 2008-05-13 07:56 35 –a—— C:\WINDOWS\CPDFAX32.INI
2008-05-08 10:01 . 2008-05-15 08:49 d——– C:\WINDOWS\SxsCaPendDel
2008-05-08 09:22 . 2008-05-21 10:49 1,024 –a—— C:\WINDOWS\MKDEWE.TRN
2008-05-08 09:22 . 2008-05-20 09:55 432 –a—— C:\WINDOWS\TERMINAL.INI
2008-05-08 09:19 . 2008-05-21 08:42 878 –a—— C:\WINDOWS\CPD2000n.INI
2008-05-08 09:14 . 2006-08-23 09:50 9,467 ——— C:\WINDOWS\updcpd32.ini
2008-05-08 09:14 . 1997-07-29 14:39 1,072 ——— C:\WINDOWS\cpd2000.ini
2008-05-08 09:11 . 2001-01-12 10:04 764 ——— C:\WINDOWS\bti.ini
2008-05-08 09:09 . 2002-05-15 14:24 9,962 –a—— C:\WINDOWS\system32\OEMLOGO.BMP
2008-05-08 09:09 . 2005-07-13 17:09 860 –a—— C:\WINDOWS\system32\OEMINFO.INI
2008-05-08 09:08 . 2008-05-08 09:08 d——– C:\WINDOWS\system32\RNBOSENT
2008-05-08 09:08 . 2008-05-08 09:08 d——– C:\UCC
2008-05-08 09:08 . 2008-05-08 09:11 d——– C:\cpddata
2008-05-08 09:08 . 2008-05-07 09:29 d——– C:\cpd2000
2008-05-08 09:08 . 2008-05-21 08:11 d——– C:\common
2008-05-08 09:08 . 1999-07-20 04:38 73,216 –a—— C:\WINDOWS\system32\drivers\SENTINEL.SYS
2008-05-08 09:08 . 1999-07-20 04:38 47,616 –a—— C:\WINDOWS\system32\SNTI386.DLL
2008-05-08 09:08 . 1999-07-20 04:38 17,920 –a—— C:\WINDOWS\system32\RNBOVDD.DLL
2008-05-08 09:08 . 1999-07-20 04:38 9,949 –a—— C:\WINDOWS\system32\SENTINEL.HLP
2008-05-08 09:05 . 2001-08-17 12:57 16,128 –a—— C:\WINDOWS\system32\drivers\MODEMCSA.sys
2008-05-08 09:05 . 2001-08-17 12:57 16,128 –a–c— C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-05-08 08:42 . 2008-05-08 08:42 d——– C:\WINDOWS\system32\CatRoot_bak
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\scripting
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\en
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\bits
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\l2schemas
2008-05-08 08:15 . 2008-05-08 08:15 d——– C:\WINDOWS\ServicePackFiles
2008-05-07 17:06 . 2004-07-17 21:55 129,045 –a—— C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-05-07 16:38 . 2007-11-15 19:11 d—s—- C:\Documents and Settings\cpduser1\UserData
2008-05-07 16:38 . 2008-05-19 12:01 d——– C:\Documents and Settings\cpduser1
2008-05-07 16:09 . 2008-05-07 16:09 d——– C:\WINDOWS\system32\configfix
2008-05-07 16:09 . 2007-11-15 19:11 d—s—- C:\WINDOWS\system32\config\systemprofile\UserData
2008-05-07 16:09 . 2008-05-07 16:12 d——– C:\Program Files\Shield
2008-05-07 16:03 . 2001-08-17 12:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-05-07 16:03 . 2008-04-13 13:45 10,368 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-05-07 15:59 . 2008-03-19 17:26 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-05-07 15:59 . 2008-03-19 17:29 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-05-07 15:58 . 2008-05-07 15:58 d——– C:\WINDOWS\system32\Adobe
2008-05-07 15:17 . 2008-05-07 15:17 dr-h—– C:\MSOCache
2008-05-07 15:13 . 2007-11-15 19:11 d–hs—- C:\Documents and Settings\CPD USER\UserData
2008-05-07 15:13 . 2008-05-20 09:08 d——– C:\Documents and Settings\CPD USER
2008-05-07 14:45 . 2008-05-07 14:45 d——– C:\Documents and Settings\cpduser1\Application Data\webex
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Program Files\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Program Files\Common Files\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Documents and Settings\All Users\Application Data\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Documents and Settings\All Users\Application Data\IBM
2008-05-07 14:37 . 2008-05-07 14:37 110 –a—— C:\WINDOWS\{34B85F58-4EA1-40F2-A658-DA3CE5D19820}_WiseFW.ini
2008-05-07 14:01 . 2008-05-20 16:11 110 –a—— C:\Hist10.hst
2008-05-07 14:00 . 2008-05-20 16:09 83 –a—— C:\Hist9.hst
2008-05-07 13:59 . 2008-05-20 16:10 111 –a—— C:\Hist6.hst
2008-05-07 13:59 . 2008-05-20 16:11 110 –a—— C:\Hist8.hst
2008-05-07 13:59 . 2008-05-20 16:11 110 –a—— C:\Hist7.hst
2008-05-07 13:56 . 2008-05-20 16:11 81 –a—— C:\Hist5.hst
2008-05-07 13:55 . 2008-05-20 16:09 95 –a—— C:\Hist4.hst
2008-05-07 13:55 . 2008-05-20 16:12 78 –a—— C:\Hist3.hst
2008-05-07 13:44 . 2008-05-20 16:12 111 –a—— C:\Hist2.hst
2008-05-07 13:44 . 2008-05-20 16:09 102 –a—— C:\Hist1.hst

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-08 15:02 ——— d—–w C:\Program Files\Common Files\Adobe
2008-05-07 21:09 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-04-14 00:13 40,840 —-a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 21,896 —-a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 —-a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,040 —-a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:12 69,120 —-a-w C:\WINDOWS\notepad.exe
2008-04-14 00:12 50,688 —-a-w C:\WINDOWS\twain_32.dll
2008-04-14 00:12 34,816 —-a-w C:\WINDOWS\Help\sniffpol.dll
2008-04-14 00:12 33,280 —-a-w C:\WINDOWS\Help\sstub.dll
2008-04-14 00:12 32,866 ——w C:\WINDOWS\slrundll.exe
2008-04-14 00:12 3,901 —-a-w C:\WINDOWS\system32\drivers\siint5.dll
2008-04-14 00:12 283,648 —-a-w C:\WINDOWS\winhlp32.exe
2008-04-14 00:12 279,040 —-a-w C:\WINDOWS\Help\tshoot.dll
2008-04-14 00:12 146,432 —-a-w C:\WINDOWS\regedit.exe
2008-04-14 00:12 11,325 —-a-w C:\WINDOWS\system32\drivers\vchnt5.dll
2008-04-14 00:12 10,752 —-a-w C:\WINDOWS\hh.exe
2008-04-14 00:12 1,033,728 —-a-w C:\WINDOWS\explorer.exe
2008-04-13 19:28 175,744 —-a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:21 162,816 —-a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 —-a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 —-a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 —-a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 —-a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 —-a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 —-a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 —-a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 —-a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 —-a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 —-a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 —-a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 —-a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 —-a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 19:15 60,800 —-a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 —-a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 —-a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 —-a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 30,080 —-a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 19:00 225,664 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 —-a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 —-a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 —-a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 —-a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 —-a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 —-a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 —-a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 —-a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 —-a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 —-a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 —-a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 —-a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 —-a-w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 30,592 —-a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 12,800 —-a-w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,800 —-a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,288 —-a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 18:55 14,592 —-a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:54 11,264 —-a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 —-a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 —-a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 18:53 36,608 —-a-w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 18:53 264,832 —-a-w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 18:51 61,824 —-a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 18:51 60,800 —-a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 18:51 59,904 —-a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 18:51 55,808 —-a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 18:51 101,120 —-a-w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 18:46 59,136 —-a-w C:\WINDOWS\system32\drivers\rfcomm.sys
2008-04-13 18:46 37,888 —-a-w C:\WINDOWS\system32\drivers\bthmodem.sys
2008-04-13 18:46 36,480 —-a-w C:\WINDOWS\system32\drivers\bthprint.sys
2008-04-13 18:46 273,024 —-a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-13 18:46 25,600 —-a-w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-13 18:46 25,344 —-a-w C:\WINDOWS\system32\drivers\sonydcam.sys
2008-04-13 18:46 18,944 —-a-w C:\WINDOWS\system32\drivers\bthusb.sys
2008-04-13 18:46 17,024 —-a-w C:\WINDOWS\system32\drivers\bthenum.sys
2008-04-13 18:46 121,984 —-a-w C:\WINDOWS\system32\drivers\usbvideo.sys
2008-04-13 18:44 81,664 —-a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 18:44 799,744 —-a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 18:44 20,992 —-a-w C:\WINDOWS\system32\drivers\vga.sys
2008-04-13 18:44 153,344 —-a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 18:43 14,208 —-a-w C:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 18:43 12,672 —-a-w C:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 18:41 52,352 —-a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 18:39 92,544 —-a-w C:\WINDOWS\system32\drivers\mqac.sys
2008-04-13 18:39 7,552 —-a-w C:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 18:39 5,376 —-a-w C:\WINDOWS\system32\drivers\mspclock.sys
2008-04-13 18:39 42,368 —-a-w C:\WINDOWS\system32\drivers\mountmgr.sys
2008-04-13 18:39 4,992 —-a-w C:\WINDOWS\system32\drivers\mspqm.sys
2008-04-13 18:39 4,352 —-a-w C:\WINDOWS\system32\drivers\swenum.sys
2008-04-13 18:39 384,768 —-a-w C:\WINDOWS\system32\drivers\update.sys
2008-04-13 18:39 24,576 —-a-w C:\WINDOWS\system32\drivers\kbdclass.sys
2008-04-13 18:39 23,040 —-a-w C:\WINDOWS\system32\drivers\mouclass.sys
2008-04-13 18:38 71,168 —-a-w C:\WINDOWS\system32\drivers\dxg.sys
2008-04-13 18:34 163,584 —-a-w C:\WINDOWS\system32\drivers\nwrdr.sys
2008-04-13 18:33 44,544 —-a-w C:\WINDOWS\system32\drivers\fips.sys
2008-04-13 18:32 66,048 —-a-w C:\WINDOWS\system32\drivers\udfs.sys
2005-07-29 21:24 472 –sha-r C:\WINDOWS\U0JTVXNlcg\oXLnprh5w0.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F0F0AD5-2AB7-4351-AC75-4003857305CD}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1ad449cb-5a66-406b-9f38-2960030a39b6}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{26906BB1-F7BE-499C-B8FB-4B4D9CA1F4B4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8691F860-96E4-4FB3-8D35-531C0D1B0AC1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{993a96bd-8de7-432b-8419-15db3cc46dda}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 10:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 10:58 282624 C:\WINDOWS\sttray.exe]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 20:00 94208]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50 139320]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" [2003-10-07 09:48 147514]
"shield"="C:\Program Files\Shield\shieldtray.exe" [2007-08-23 13:53 3358720]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-19 12:00 1177368]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
CPD Fax.LNK - C:\cpdfax\CpdFax32.exe [2008-05-13 07:56:39 163840]
CPD Net XP.LNK - C:\cpd2000\CPD2000n.exe [2007-10-09 09:09:26 987136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 shdbus;shdbus;C:\WINDOWS\system32\drivers\shdbus.sys [2007-08-23 13:51]
R0 Shield;Shield;C:\WINDOWS\system32\drivers\Shield.sys [2007-08-23 13:51]
R0 Shieldf;Shieldf;C:\WINDOWS\system32\drivers\Shieldf.sys [2007-08-23 13:51]
R0 shieldm;shieldm;C:\WINDOWS\system32\drivers\shieldm.sys [2007-08-23 13:51]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-19 12:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-19 12:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-19 12:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-19 12:00]
R2 ShieldClientService;Shield Client Service;C:\Program Files\Shield\shieldclnt.exe [2007-08-23 13:50]

*Newly Created Service* - ENTDRV51
.
Contents of the 'Scheduled Tasks' folder
"2008-05-22 13:56:28 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-22 08:54:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\Program Files\Shield\SHDSERV.exe
C:\WINDOWS\system32\stacsv.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\cpd2000\W32mkde.exe
.
**************************************************************************
.
Completion time: 2008-05-22 8:56:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-22 13:56:39

Pre-Run: 52,082,909,184 bytes free
Post-Run: 51,983,753,216 bytes free

322 — E O F — 2008-05-21 01:27:23
hi,

we will use combofix again:

Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:

File::
C:\WINDOWS\system32\skbllqxx.dll
C:\WINDOWS\system32\huiktdlf.dll
C:\WINDOWS\system32\jmunimmj.dll
C:\WINDOWS\system32\dFrnx18

Registry:
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F0F0AD5-2AB7-4351-AC75-4003857305CD}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1ad449cb-5a66-406b-9f38-2960030a39b6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{26906BB1-F7BE-499C-B8FB-4B4D9CA1F4B4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8691F860-96E4-4FB3-8D35-531C0D1B0AC1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{993a96bd-8de7-432b-8419-15db3cc46dda}]


Name the Notepad file CFScript.txt and Save it to your desktop.
now locate the file you just saved and the combofix icon, both on your desktop–
using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log
please post the new combofix log and a new hjt log.
Here is what we got:

Combofix log:

ComboFix 08-05-21.2 - CPD USER 2008-05-23 8:43:11.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2467 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\CPD USER\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\dFrnx18
C:\WINDOWS\system32\huiktdlf.dll
C:\WINDOWS\system32\jmunimmj.dll
C:\WINDOWS\system32\skbllqxx.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\huiktdlf.dll
C:\WINDOWS\system32\jmunimmj.dll
C:\WINDOWS\system32\skbllqxx.dll

.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.

2008-05-22 08:50 . 2008-05-23 08:43 d——– C:\quarantine
2008-05-20 10:00 . 2008-05-20 10:00 d——– C:\WINDOWS\ERUNT
2008-05-20 09:56 . 2008-05-20 09:56 d——– C:\SDFix
2008-05-19 13:53 . 2008-05-23 07:49 d–h—– C:\$AVG8.VAULT$
2008-05-19 12:00 . 2008-05-22 17:02 d——– C:\WINDOWS\system32\drivers\Avg
2008-05-19 12:00 . 2008-05-19 12:00 d——– C:\Program Files\AVG
2008-05-19 12:00 . 2008-05-19 12:00 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-05-19 12:00 . 2008-05-19 12:00 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-19 12:00 . 2008-05-19 12:00 75,272 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-19 12:00 . 2008-05-19 12:00 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Documents and Settings\CPD USER\Application Data\Malwarebytes
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-19 11:04 . 2008-05-05 20:46 27,048 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-19 11:04 . 2008-05-05 20:46 15,864 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-05-16 15:27 . 2008-05-19 07:54 553 –a—— C:\$bootcln.sch
2008-05-16 08:24 . 2008-05-16 08:24 294 –a—— C:\WINDOWS\system32\MRT.INI
2008-05-16 08:05 . 2008-05-16 08:05 d——– C:\Program Files\Windows Defender
2008-05-16 07:38 . 2008-05-16 07:38 d——– C:\Program Files\Trend Micro
2008-05-15 15:19 . 2008-05-20 07:54 556 –a—— C:\WINDOWS\wininit.ini
2008-05-15 13:28 . 2008-05-19 12:01 8,192 –a—— C:\Documents and Settings\sbsuser
2008-05-15 13:22 . 2008-05-15 13:22 d——– C:\Program Files\Spybot - Search & Destroy
2008-05-15 13:22 . 2008-05-15 13:28 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-15 12:25 . 2008-05-15 12:25 d–h—– C:\WINDOWS\system32\GroupPolicy
2008-05-15 10:27 . 2001-08-17 12:48 17,664 –a—— C:\WINDOWS\system32\drivers\sermouse.sys
2008-05-15 10:27 . 2001-08-17 12:48 17,664 –a–c— C:\WINDOWS\system32\dllcache\sermouse.sys
2008-05-15 10:13 . 2008-05-15 10:13 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2008-05-15 10:00 . 2008-05-19 14:07 d–hs—- C:\WINDOWS\U0JTVXNlcg
2008-05-15 10:00 . 2008-05-15 14:37 d——– C:\WINDOWS\system32\dFrnx18
2008-05-15 10:00 . 2008-05-20 10:14 d——– C:\Temp
2008-05-15 09:40 . 2008-05-15 09:40 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-05-14 15:52 . 2008-05-14 15:52 d——– C:\Program Files\insiderbaseball 2008
2008-05-14 15:48 . 2008-05-20 11:14 d——– C:\Documents and Settings\CPD USER\Application Data\LimeWire
2008-05-14 15:42 . 2008-05-14 15:42 d——– C:\WINDOWS\Sun
2008-05-14 15:42 . 2008-02-22 02:33 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-05-14 15:41 . 2008-05-14 15:42 d——– C:\Program Files\Java
2008-05-14 15:39 . 2008-05-14 15:39 d——– C:\Program Files\Common Files\Java
2008-05-14 15:36 . 2008-05-20 11:14 d——– C:\Program Files\LimeWire
2008-05-13 07:56 . 2008-05-13 07:56 d——– C:\cpdfax
2008-05-13 07:56 . 2002-03-14 14:46 339,968 –a—— C:\WINDOWS\system32\imgman32.dll
2008-05-13 07:56 . 2001-04-03 07:10 249,856 –a—— C:\WINDOWS\system32\dtidb.dll
2008-05-13 07:56 . 2001-06-26 08:28 208,896 –a—— C:\WINDOWS\system32\fm3032.exe
2008-05-13 07:56 . 2001-06-26 08:25 77,824 –a—— C:\WINDOWS\system32\fm3032d.dll
2008-05-13 07:56 . 2001-06-26 08:30 53,248 -ra—— C:\WINDOWS\system32\im32xfax.del
2008-05-13 07:56 . 2001-06-26 08:31 47,300 -ra—— C:\WINDOWS\system32\dtmon.dll
2008-05-13 07:56 . 2003-06-02 10:53 3,020 -ra—— C:\WINDOWS\system32\cover2.pg
2008-05-13 07:56 . 2008-05-13 07:56 35 –a—— C:\WINDOWS\CPDFAX32.INI
2008-05-08 10:01 . 2008-05-15 08:49 d——– C:\WINDOWS\SxsCaPendDel
2008-05-08 09:22 . 2008-05-22 09:04 1,024 –a—— C:\WINDOWS\MKDEWE.TRN
2008-05-08 09:22 . 2008-05-22 10:37 432 –a—— C:\WINDOWS\TERMINAL.INI
2008-05-08 09:19 . 2008-05-23 08:08 857 –a—— C:\WINDOWS\CPD2000n.INI
2008-05-08 09:14 . 2006-08-23 09:50 9,467 ——— C:\WINDOWS\updcpd32.ini
2008-05-08 09:14 . 1997-07-29 14:39 1,072 ——— C:\WINDOWS\cpd2000.ini
2008-05-08 09:11 . 2001-01-12 10:04 764 ——— C:\WINDOWS\bti.ini
2008-05-08 09:09 . 2002-05-15 14:24 9,962 –a—— C:\WINDOWS\system32\OEMLOGO.BMP
2008-05-08 09:09 . 2005-07-13 17:09 860 –a—— C:\WINDOWS\system32\OEMINFO.INI
2008-05-08 09:08 . 2008-05-08 09:08 d——– C:\WINDOWS\system32\RNBOSENT
2008-05-08 09:08 . 2008-05-08 09:08 d——– C:\UCC
2008-05-08 09:08 . 2008-05-08 09:11 d——– C:\cpddata
2008-05-08 09:08 . 2008-05-07 09:29 d——– C:\cpd2000
2008-05-08 09:08 . 2008-05-22 13:16 d——– C:\common
2008-05-08 09:08 . 1999-07-20 04:38 73,216 –a—— C:\WINDOWS\system32\drivers\SENTINEL.SYS
2008-05-08 09:08 . 1999-07-20 04:38 47,616 –a—— C:\WINDOWS\system32\SNTI386.DLL
2008-05-08 09:08 . 1999-07-20 04:38 17,920 –a—— C:\WINDOWS\system32\RNBOVDD.DLL
2008-05-08 09:08 . 1999-07-20 04:38 9,949 –a—— C:\WINDOWS\system32\SENTINEL.HLP
2008-05-08 09:05 . 2001-08-17 12:57 16,128 –a—— C:\WINDOWS\system32\drivers\MODEMCSA.sys
2008-05-08 09:05 . 2001-08-17 12:57 16,128 –a–c— C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-05-08 08:42 . 2008-05-08 08:42 d——– C:\WINDOWS\system32\CatRoot_bak
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\scripting
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\en
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\bits
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\l2schemas
2008-05-08 08:15 . 2008-05-08 08:15 d——– C:\WINDOWS\ServicePackFiles
2008-05-07 17:06 . 2004-07-17 21:55 129,045 –a—— C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-05-07 16:38 . 2007-11-15 19:11 d—s—- C:\Documents and Settings\cpduser1\UserData
2008-05-07 16:38 . 2008-05-19 12:01 d——– C:\Documents and Settings\cpduser1
2008-05-07 16:09 . 2008-05-07 16:09 d——– C:\WINDOWS\system32\configfix
2008-05-07 16:09 . 2007-11-15 19:11 d—s—- C:\WINDOWS\system32\config\systemprofile\UserData
2008-05-07 16:09 . 2008-05-07 16:12 d——– C:\Program Files\Shield
2008-05-07 16:03 . 2001-08-17 12:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-05-07 16:03 . 2008-04-13 13:45 10,368 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-05-07 15:59 . 2008-03-19 17:26 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-05-07 15:59 . 2008-03-19 17:29 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-05-07 15:58 . 2008-05-07 15:58 d——– C:\WINDOWS\system32\Adobe
2008-05-07 15:17 . 2008-05-07 15:17 dr-h—– C:\MSOCache
2008-05-07 15:13 . 2007-11-15 19:11 d–hs—- C:\Documents and Settings\CPD USER\UserData
2008-05-07 15:13 . 2008-05-20 09:08 d——– C:\Documents and Settings\CPD USER
2008-05-07 14:45 . 2008-05-07 14:45 d——– C:\Documents and Settings\cpduser1\Application Data\webex
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Program Files\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Program Files\Common Files\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Documents and Settings\All Users\Application Data\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Documents and Settings\All Users\Application Data\IBM
2008-05-07 14:37 . 2008-05-07 14:37 110 –a—— C:\WINDOWS\{34B85F58-4EA1-40F2-A658-DA3CE5D19820}_WiseFW.ini
2008-05-07 14:01 . 2008-05-23 08:07 97 –a—— C:\Hist10.hst
2008-05-07 14:00 . 2008-05-23 08:08 596 –a—— C:\Hist9.hst
2008-05-07 13:59 . 2008-05-22 13:26 632 –a—— C:\Hist8.hst
2008-05-07 13:59 . 2008-05-22 13:18 631 –a—— C:\Hist6.hst
2008-05-07 13:59 . 2008-05-22 15:19 103 –a—— C:\Hist7.hst
2008-05-07 13:56 . 2008-05-22 16:02 104 –a—— C:\Hist5.hst
2008-05-07 13:55 . 2008-05-22 13:28 631 –a—— C:\Hist4.hst
2008-05-07 13:55 . 2008-05-23 08:06 70 –a—— C:\Hist3.hst
2008-05-07 13:44 . 2008-05-22 13:15 586 –a—— C:\Hist1.hst
2008-05-07 13:44 . 2008-05-23 08:06 70 –a—— C:\Hist2.hst

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-08 15:02 ——— d—–w C:\Program Files\Common Files\Adobe
2008-05-07 21:09 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-04-14 09:42 985,088 —-a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 09:42 11,264 —-a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 09:41 423,936 —-a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 —-a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 —-a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 —-a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 —-a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 40,840 —-a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 21,896 —-a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 —-a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,168 —-a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:13 12,040 —-a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:11 997,376 —-a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 —-a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 —-a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 —-a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 19:30 1,845,632 —-a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:28 175,744 —-a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:24 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 19:21 162,816 —-a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 —-a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 —-a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 —-a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 —-a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 —-a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 —-a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 —-a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 —-a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 —-a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 —-a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 —-a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 —-a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 —-a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 19:15 60,800 —-a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 —-a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 —-a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 —-a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 30,080 —-a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 19:00 225,664 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 —-a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 —-a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 —-a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 —-a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 —-a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 —-a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 —-a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 —-a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 —-a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 —-a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 —-a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 —-a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 —-a-w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 30,592 —-a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 12,800 —-a-w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,800 —-a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,288 —-a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 18:55 14,592 —-a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:54 11,264 —-a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 —-a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 —-a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 18:53 36,608 —-a-w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 18:53 264,832 —-a-w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 18:51 61,824 —-a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 18:51 60,800 —-a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 18:51 59,904 —-a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 18:51 55,808 —-a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 18:51 101,120 —-a-w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 18:46 59,136 —-a-w C:\WINDOWS\system32\drivers\rfcomm.sys
2008-04-13 18:46 37,888 —-a-w C:\WINDOWS\system32\drivers\bthmodem.sys
2008-04-13 18:46 36,480 —-a-w C:\WINDOWS\system32\drivers\bthprint.sys
2008-04-13 18:46 273,024 —-a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-13 18:46 25,600 —-a-w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-13 18:46 25,344 —-a-w C:\WINDOWS\system32\drivers\sonydcam.sys
2008-04-13 18:46 18,944 —-a-w C:\WINDOWS\system32\drivers\bthusb.sys
2008-04-13 18:46 17,024 —-a-w C:\WINDOWS\system32\drivers\bthenum.sys
2008-04-13 18:46 121,984 —-a-w C:\WINDOWS\system32\drivers\usbvideo.sys
2008-04-13 18:44 81,664 —-a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 18:44 799,744 —-a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 18:44 20,992 —-a-w C:\WINDOWS\system32\drivers\vga.sys
2008-04-13 18:44 17,664 —-a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:44 153,344 —-a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 18:43 9,728 —-a-w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 14,208 —-a-w C:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 18:43 12,800 —-a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:43 12,672 —-a-w C:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 18:41 52,352 —-a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 18:39 92,544 —-a-w C:\WINDOWS\system32\drivers\mqac.sys
2008-04-13 18:39 7,552 —-a-w C:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 18:39 5,376 —-a-w C:\WINDOWS\system32\drivers\mspclock.sys
2008-04-13 18:39 42,368 —-a-w C:\WINDOWS\system32\drivers\mountmgr.sys
2008-04-13 18:39 4,992 —-a-w C:\WINDOWS\system32\drivers\mspqm.sys
2008-04-13 18:39 4,352 —-a-w C:\WINDOWS\system32\drivers\swenum.sys
2008-04-13 18:39 384,768 —-a-w C:\WINDOWS\system32\drivers\update.sys
2008-04-13 18:39 24,576 —-a-w C:\WINDOWS\system32\drivers\kbdclass.sys
2005-07-29 21:24 472 –sha-r C:\WINDOWS\U0JTVXNlcg\oXLnprh5w0.vbs
.

((((((((((((((((((((((((((((( snapshot@2008-05-22_ 8.56.27.89 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 10:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 10:58 282624 C:\WINDOWS\sttray.exe]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 20:00 94208]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50 139320]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" [2003-10-07 09:48 147514]
"shield"="C:\Program Files\Shield\shieldtray.exe" [2007-08-23 13:53 3358720]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-19 12:00 1177368]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
CPD Fax.LNK - C:\cpdfax\CpdFax32.exe [2008-05-13 07:56:39 163840]
CPD Net XP.LNK - C:\cpd2000\CPD2000n.exe [2007-10-09 09:09:26 987136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 shdbus;shdbus;C:\WINDOWS\system32\drivers\shdbus.sys [2007-08-23 13:51]
R0 Shield;Shield;C:\WINDOWS\system32\drivers\Shield.sys [2007-08-23 13:51]
R0 Shieldf;Shieldf;C:\WINDOWS\system32\drivers\Shieldf.sys [2007-08-23 13:51]
R0 shieldm;shieldm;C:\WINDOWS\system32\drivers\shieldm.sys [2007-08-23 13:51]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-19 12:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-19 12:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-19 12:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-19 12:00]
R2 ShieldClientService;Shield Client Service;C:\Program Files\Shield\shieldclnt.exe [2007-08-23 13:50]

*Newly Created Service* - ENTDRV51
.
Contents of the 'Scheduled Tasks' folder
"2008-05-23 06:49:32 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-23 08:44:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-23 8:44:43
ComboFix-quarantined-files.txt 2008-05-23 13:44:41
ComboFix2.txt 2008-05-22 13:56:43

Pre-Run: 51,796,123,648 bytes free
Post-Run: 51,795,406,848 bytes free

301 — E O F — 2008-05-21 01:27:23

Here is the Hjt log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:46:49 AM, on 5/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Shield\shdserv.exe
C:\WINDOWS\system32\STacSV.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Shield\shieldclnt.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\sttray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Shield\shieldtray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\cpd2000\CPD2000n.exe
C:\cpd2000\W32MKDE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iland.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.248.160.18:80
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [shield] C:\Program Files\Shield\shieldtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: CPD Fax.LNK = C:\cpdfax\CpdFax32.exe
O4 - Global Startup: CPD Net XP.LNK = C:\cpd2000\CPD2000n.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1210883551687
O16 - DPF: {73A8D51E-578B-4E4E-8FF8-112E51DBFBE3} (ADPConn Class) - http://caf.oeconnection.com/ActiveX/DMSISM.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://snap-on.webex.com/client/T26L10NSP4…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS2\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O17 - HKLM\System\CS3\Services\Tcpip\..\{4B456834-7A37-4B80-A872-E8289A8A4F1A}: NameServer = 198.6.1.3,198.6.1.4
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SHDSERV - Unknown owner - C:\Program Files\Shield\shdserv.exe
O23 - Service: Shield Client Service (ShieldClientService) - Unknown owner - C:\Program Files\Shield\shieldclnt.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe

–
End of file - 7022 bytes
hi,

thanks for the info. we will use combofix again, like last time:

Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:

Folder::
C:\WINDOWS\system32\dFrnx18

File::
C:\WINDOWS\system32\vbzip10.dll

please check for updates and scan once more with malwarebytes and post the log
Sorry 4 the delay. Its my computer at work. Heres the two logs:

Combo…

ComboFix 08-05-21.2 - CPD USER 2008-05-27 11:07:05.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2416 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\CPD USER\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\vbzip10.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\dFrnx18
C:\WINDOWS\system32\vbzip10.dll

.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.

2008-05-23 08:54 . 2008-05-23 08:54 d——– C:\Program Files\CyberLink
2008-05-23 08:54 . 2008-05-23 08:54 d——– C:\Documents and Settings\All Users\Application Data\CyberLink
2008-05-22 08:50 . 2008-05-27 11:07 d——– C:\quarantine
2008-05-20 10:00 . 2008-05-20 10:00 d——– C:\WINDOWS\ERUNT
2008-05-20 09:56 . 2008-05-20 09:56 d——– C:\SDFix
2008-05-19 13:53 . 2008-05-23 12:08 d–h—– C:\$AVG8.VAULT$
2008-05-19 12:00 . 2008-05-27 09:59 d——– C:\WINDOWS\system32\drivers\Avg
2008-05-19 12:00 . 2008-05-19 12:00 d——– C:\Program Files\AVG
2008-05-19 12:00 . 2008-05-19 12:00 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-05-19 12:00 . 2008-05-19 12:00 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-19 12:00 . 2008-05-19 12:00 75,272 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-19 12:00 . 2008-05-19 12:00 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Documents and Settings\CPD USER\Application Data\Malwarebytes
2008-05-19 11:04 . 2008-05-19 11:04 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-19 11:04 . 2008-05-05 20:46 27,048 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-19 11:04 . 2008-05-05 20:46 15,864 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-05-16 15:27 . 2008-05-19 07:54 553 –a—— C:\$bootcln.sch
2008-05-16 08:24 . 2008-05-16 08:24 294 –a—— C:\WINDOWS\system32\MRT.INI
2008-05-16 08:05 . 2008-05-16 08:05 d——– C:\Program Files\Windows Defender
2008-05-16 07:38 . 2008-05-16 07:38 d——– C:\Program Files\Trend Micro
2008-05-15 15:19 . 2008-05-20 07:54 556 –a—— C:\WINDOWS\wininit.ini
2008-05-15 13:28 . 2008-05-19 12:01 8,192 –a—— C:\Documents and Settings\sbsuser
2008-05-15 13:22 . 2008-05-15 13:22 d——– C:\Program Files\Spybot - Search & Destroy
2008-05-15 13:22 . 2008-05-15 13:28 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-15 12:25 . 2008-05-15 12:25 d–h—– C:\WINDOWS\system32\GroupPolicy
2008-05-15 10:27 . 2001-08-17 12:48 17,664 –a—— C:\WINDOWS\system32\drivers\sermouse.sys
2008-05-15 10:27 . 2001-08-17 12:48 17,664 –a–c— C:\WINDOWS\system32\dllcache\sermouse.sys
2008-05-15 10:00 . 2008-05-19 14:07 d–hs—- C:\WINDOWS\U0JTVXNlcg
2008-05-15 10:00 . 2008-05-20 10:14 d——– C:\Temp
2008-05-15 09:40 . 2008-05-15 09:40 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-05-14 15:52 . 2008-05-14 15:52 d——– C:\Program Files\insiderbaseball 2008
2008-05-14 15:48 . 2008-05-23 15:46 d——– C:\Documents and Settings\CPD USER\Application Data\LimeWire
2008-05-14 15:42 . 2008-05-14 15:42 d——– C:\WINDOWS\Sun
2008-05-14 15:42 . 2008-02-22 02:33 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-05-14 15:41 . 2008-05-14 15:42 d——– C:\Program Files\Java
2008-05-14 15:39 . 2008-05-14 15:39 d——– C:\Program Files\Common Files\Java
2008-05-14 15:36 . 2008-05-20 11:14 d——– C:\Program Files\LimeWire
2008-05-13 07:56 . 2008-05-13 07:56 d——– C:\cpdfax
2008-05-13 07:56 . 2002-03-14 14:46 339,968 –a—— C:\WINDOWS\system32\imgman32.dll
2008-05-13 07:56 . 2001-04-03 07:10 249,856 –a—— C:\WINDOWS\system32\dtidb.dll
2008-05-13 07:56 . 2001-06-26 08:28 208,896 –a—— C:\WINDOWS\system32\fm3032.exe
2008-05-13 07:56 . 2001-06-26 08:25 77,824 –a—— C:\WINDOWS\system32\fm3032d.dll
2008-05-13 07:56 . 2001-06-26 08:30 53,248 -ra—— C:\WINDOWS\system32\im32xfax.del
2008-05-13 07:56 . 2001-06-26 08:31 47,300 -ra—— C:\WINDOWS\system32\dtmon.dll
2008-05-13 07:56 . 2003-06-02 10:53 3,020 -ra—— C:\WINDOWS\system32\cover2.pg
2008-05-13 07:56 . 2008-05-13 07:56 35 –a—— C:\WINDOWS\CPDFAX32.INI
2008-05-08 10:01 . 2008-05-15 08:49 d——– C:\WINDOWS\SxsCaPendDel
2008-05-08 09:22 . 2008-05-22 09:04 1,024 –a—— C:\WINDOWS\MKDEWE.TRN
2008-05-08 09:22 . 2008-05-22 10:37 432 –a—— C:\WINDOWS\TERMINAL.INI
2008-05-08 09:19 . 2008-05-27 09:26 907 –a—— C:\WINDOWS\CPD2000n.INI
2008-05-08 09:14 . 2006-08-23 09:50 9,467 ——— C:\WINDOWS\updcpd32.ini
2008-05-08 09:14 . 1997-07-29 14:39 1,072 ——— C:\WINDOWS\cpd2000.ini
2008-05-08 09:11 . 2001-01-12 10:04 764 ——— C:\WINDOWS\bti.ini
2008-05-08 09:09 . 2002-05-15 14:24 9,962 –a—— C:\WINDOWS\system32\OEMLOGO.BMP
2008-05-08 09:09 . 2005-07-13 17:09 860 –a—— C:\WINDOWS\system32\OEMINFO.INI
2008-05-08 09:08 . 2008-05-08 09:08 d——– C:\WINDOWS\system32\RNBOSENT
2008-05-08 09:08 . 2008-05-08 09:08 d——– C:\UCC
2008-05-08 09:08 . 2008-05-08 09:11 d——– C:\cpddata
2008-05-08 09:08 . 2008-05-07 09:29 d——– C:\cpd2000
2008-05-08 09:08 . 2008-05-22 13:16 d——– C:\common
2008-05-08 09:08 . 1999-07-20 04:38 73,216 –a—— C:\WINDOWS\system32\drivers\SENTINEL.SYS
2008-05-08 09:08 . 1999-07-20 04:38 47,616 –a—— C:\WINDOWS\system32\SNTI386.DLL
2008-05-08 09:08 . 1999-07-20 04:38 17,920 –a—— C:\WINDOWS\system32\RNBOVDD.DLL
2008-05-08 09:08 . 1999-07-20 04:38 9,949 –a—— C:\WINDOWS\system32\SENTINEL.HLP
2008-05-08 09:05 . 2001-08-17 12:57 16,128 –a—— C:\WINDOWS\system32\drivers\MODEMCSA.sys
2008-05-08 09:05 . 2001-08-17 12:57 16,128 –a–c— C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-05-08 08:42 . 2008-05-08 08:42 d——– C:\WINDOWS\system32\CatRoot_bak
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\scripting
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\en
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\system32\bits
2008-05-08 08:17 . 2008-05-08 08:17 d——– C:\WINDOWS\l2schemas
2008-05-08 08:15 . 2008-05-08 08:15 d——– C:\WINDOWS\ServicePackFiles
2008-05-07 17:06 . 2004-07-17 21:55 129,045 –a—— C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-05-07 16:38 . 2007-11-15 19:11 d—s—- C:\Documents and Settings\cpduser1\UserData
2008-05-07 16:38 . 2008-05-19 12:01 d——– C:\Documents and Settings\cpduser1
2008-05-07 16:09 . 2008-05-07 16:09 d——– C:\WINDOWS\system32\configfix
2008-05-07 16:09 . 2007-11-15 19:11 d—s—- C:\WINDOWS\system32\config\systemprofile\UserData
2008-05-07 16:09 . 2008-05-07 16:12 d——– C:\Program Files\Shield
2008-05-07 16:03 . 2001-08-17 12:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-05-07 16:03 . 2008-04-13 13:45 10,368 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-05-07 15:59 . 2008-03-19 17:26 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-05-07 15:59 . 2008-03-19 17:29 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-05-07 15:58 . 2008-05-07 15:58 d——– C:\WINDOWS\system32\Adobe
2008-05-07 15:17 . 2008-05-07 15:17 dr-h—– C:\MSOCache
2008-05-07 15:13 . 2007-11-15 19:11 d–hs—- C:\Documents and Settings\CPD USER\UserData
2008-05-07 15:13 . 2008-05-20 09:08 d——– C:\Documents and Settings\CPD USER
2008-05-07 14:45 . 2008-05-07 14:45 d——– C:\Documents and Settings\cpduser1\Application Data\webex
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Program Files\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Program Files\Common Files\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Documents and Settings\All Users\Application Data\Reynolds
2008-05-07 14:37 . 2008-05-07 14:37 d——– C:\Documents and Settings\All Users\Application Data\IBM
2008-05-07 14:37 . 2008-05-07 14:37 110 –a—— C:\WINDOWS\{34B85F58-4EA1-40F2-A658-DA3CE5D19820}_WiseFW.ini
2008-05-07 14:01 . 2008-05-23 08:07 97 –a—— C:\Hist10.hst
2008-05-07 14:00 . 2008-05-23 08:08 596 –a—— C:\Hist9.hst
2008-05-07 13:59 . 2008-05-23 13:10 549 –a—— C:\Hist8.hst
2008-05-07 13:59 . 2008-05-23 13:09 503 –a—— C:\Hist6.hst
2008-05-07 13:59 . 2008-05-23 14:20 65 –a—— C:\Hist7.hst
2008-05-07 13:56 . 2008-05-23 14:20 95 –a—— C:\Hist5.hst
2008-05-07 13:55 . 2008-05-23 13:10 519 –a—— C:\Hist4.hst
2008-05-07 13:55 . 2008-05-23 14:43 103 –a—— C:\Hist3.hst
2008-05-07 13:44 . 2008-05-23 13:09 68 –a—— C:\Hist1.hst
2008-05-07 13:44 . 2008-05-27 09:26 65 –a—— C:\Hist2.hst

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-23 13:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-23 13:54 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-05-08 15:02 ——— d—–w C:\Program Files\Common Files\Adobe
2008-04-14 09:42 985,088 —-a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 09:42 11,264 —-a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 09:41 423,936 —-a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 —-a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 —-a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 —-a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 —-a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 40,840 —-a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 21,896 —-a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 —-a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,168 —-a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:13 12,040 —-a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:11 997,376 —-a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 —-a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 —-a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 —-a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 19:30 1,845,632 —-a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:28 175,744 —-a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:24 2,145,280 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 19:21 162,816 —-a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 —-a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 —-a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 —-a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 —-a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 —-a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 —-a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 —-a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 —-a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 —-a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 —-a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 —-a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 —-a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 —-a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 19:15 60,800 —-a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 —-a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 —-a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 —-a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 30,080 —-a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 19:00 225,664 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 —-a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 —-a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 —-a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 —-a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 —-a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 —-a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 —-a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 —-a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 —-a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 —-a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 —-a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 —-a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 —-a-w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 30,592 —-a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 12,800 —-a-w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,800 —-a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,288 —-a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 18:55 14,592 —-a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:54 11,264 —-a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 —-a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 —-a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 18:53 36,608 —-a-w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 18:53 264,832 —-a-w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 18:51 61,824 —-a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 18:51 60,800 —-a-w C:\WINDOWS\system32\drivers\arp1394.sys
2008-04-13 18:51 59,904 —-a-w C:\WINDOWS\system32\drivers\atmarpc.sys
2008-04-13 18:51 55,808 —-a-w C:\WINDOWS\system32\drivers\atmlane.sys
2008-04-13 18:51 101,120 —-a-w C:\WINDOWS\system32\drivers\bthpan.sys
2008-04-13 18:46 59,136 —-a-w C:\WINDOWS\system32\drivers\rfcomm.sys
2008-04-13 18:46 37,888 —-a-w C:\WINDOWS\system32\drivers\bthmodem.sys
2008-04-13 18:46 36,480 —-a-w C:\WINDOWS\system32\drivers\bthprint.sys
2008-04-13 18:46 273,024 —-a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-13 18:46 25,600 —-a-w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-13 18:46 25,344 —-a-w C:\WINDOWS\system32\drivers\sonydcam.sys
2008-04-13 18:46 18,944 —-a-w C:\WINDOWS\system32\drivers\bthusb.sys
2008-04-13 18:46 17,024 —-a-w C:\WINDOWS\system32\drivers\bthenum.sys
2008-04-13 18:46 121,984 —-a-w C:\WINDOWS\system32\drivers\usbvideo.sys
2008-04-13 18:44 81,664 —-a-w C:\WINDOWS\system32\drivers\videoprt.sys
2008-04-13 18:44 799,744 —-a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 18:44 20,992 —-a-w C:\WINDOWS\system32\drivers\vga.sys
2008-04-13 18:44 17,664 —-a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:44 153,344 —-a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 18:43 9,728 —-a-w C:\WINDOWS\system32\comsdupd.exe
2008-04-13 18:43 14,208 —-a-w C:\WINDOWS\system32\drivers\wacompen.sys
2008-04-13 18:43 12,800 —-a-w C:\WINDOWS\system32\spiisupd.exe
2008-04-13 18:43 12,672 —-a-w C:\WINDOWS\system32\drivers\mutohpen.sys
2008-04-13 18:41 52,352 —-a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 18:39 92,544 —-a-w C:\WINDOWS\system32\drivers\mqac.sys
2008-04-13 18:39 7,552 —-a-w C:\WINDOWS\system32\drivers\mskssrv.sys
2008-04-13 18:39 5,376 —-a-w C:\WINDOWS\system32\drivers\mspclock.sys
2008-04-13 18:39 42,368 —-a-w C:\WINDOWS\system32\drivers\mountmgr.sys
2008-04-13 18:39 4,992 —-a-w C:\WINDOWS\system32\drivers\mspqm.sys
2008-04-13 18:39 4,352 —-a-w C:\WINDOWS\system32\drivers\swenum.sys
2008-04-13 18:39 384,768 —-a-w C:\WINDOWS\system32\drivers\update.sys
2005-07-29 21:24 472 –sha-r C:\WINDOWS\U0JTVXNlcg\oXLnprh5w0.vbs
.

((((((((((((((((((((((((((((( snapshot@2008-05-22_ 8.56.27.89 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 10:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 10:58 282624 C:\WINDOWS\sttray.exe]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 20:00 94208]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50 139320]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" [2003-10-07 09:48 147514]
"shield"="C:\Program Files\Shield\shieldtray.exe" [2007-08-23 13:53 3358720]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-19 12:00 1177368]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
CPD Fax.LNK - C:\cpdfax\CpdFax32.exe [2008-05-13 07:56:39 163840]
CPD Net XP.LNK - C:\cpd2000\CPD2000n.exe [2007-10-09 09:09:26 987136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Reynolds\\ERALink\\wIntegSM.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 shdbus;shdbus;C:\WINDOWS\system32\drivers\shdbus.sys [2007-08-23 13:51]
R0 Shield;Shield;C:\WINDOWS\system32\drivers\Shield.sys [2007-08-23 13:51]
R0 Shieldf;Shieldf;C:\WINDOWS\system32\drivers\Shieldf.sys [2007-08-23 13:51]
R0 shieldm;shieldm;C:\WINDOWS\system32\drivers\shieldm.sys [2007-08-23 13:51]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-19 12:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-19 12:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-19 12:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-19 12:00]
R2 ShieldClientService;Shield Client Service;C:\Program Files\Shield\shieldclnt.exe [2007-08-23 13:50]

*Newly Created Service* - ENTDRV51
.
Contents of the 'Scheduled Tasks' folder
"2008-05-27 06:49:15 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-27 11:08:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-05-27 11:08:39
ComboFix-quarantined-files.txt 2008-05-27 16:08:36
ComboFix2.txt 2008-05-23 13:44:44
ComboFix3.txt 2008-05-22 13:56:43

Pre-Run: 51,711,631,360 bytes free
Post-Run: 51,691,421,696 bytes free

299 — E O F — 2008-05-21 01:27:23

Malware:

Malwarebytes' Anti-Malware 1.12
Database version: 791

Scan type: Quick Scan
Objects scanned: 38517
Time elapsed: 2 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
hi,

Sorry 4 the delay. Its my computer at work


ok no problem except one thing, i dont like supporting work place computers. sometimes there are tip offs in the hjt log you can spot.

why? because most likely its not your computer or network. malware can also spread via networked computers. Some places might have there own in house IT also that should be able to help you.
anyway the good news is all looks ok. hows it looking on your end now. if all is good we can finish up.
Everything has been running great! Were a little different here as in having IT support. Were a new car dealership and the service manager is the IT support. Hes been using the same old fixes for the last 5-10 years so he appriciates any help in the computer fixing. He thanks you for the Malwarebytes program. Plus I've had you guys fix my home computer, so i no you guys are top notch.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI