This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] TROJAN HOURSE VUNDO.J

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I saw the post by member Heather yesterday and experienced the same problems as she did. I downloaded the trend micro file and copied my log. It is as follows.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:34:13 AM, on 6/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Xpress Mail\Personal Edition\XpressMailDesktopClient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\STOPzilla!\SZOptions.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070412
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [787bcf54] rundll32.exe "C:\WINDOWS\system32\iqdecjnp.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Xpress Mail Personal Edition.lnk = C:\Program Files\Xpress Mail\Personal Edition\XpressMailDesktopClient.exe
O4 - Global Startup: Xpress Mail Professional Edition.lnk = C:\Program Files\Xpress Mail\Personal Edition\XpressMailDesktopClient.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} (Rite Aid One Hour Photo Online Control) - https://photos.riteaid.com/control/RiteAidO…PhotoOnline.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab?
O17 - HKLM\System\CCS\Services\Tcpip\..\{05DC98C9-866F-47BD-A134-EEB948965D55}: NameServer = 24.116.0.201,24.116.0.202,192.168.1.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB49DF0E-13A7-464F-8AB2-CF33F53305C5}: NameServer = 24.116.0.201,24.116.0.202,192.168.1.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{05DC98C9-866F-47BD-A134-EEB948965D55}: NameServer = 24.116.0.201,24.116.0.202,192.168.1.5
O17 - HKLM\System\CS3\Services\Tcpip\..\{05DC98C9-866F-47BD-A134-EEB948965D55}: NameServer = 24.116.0.201,24.116.0.202,192.168.1.5
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Xpress Mail Professional Edition Service (SevenConnectionService) - Unknown owner - C:\Program Files\Xpress Mail\Personal Edition\ConnectionService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 12843 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

jpshortstuff
JP…… My PC is slow as cant be…….Running XP Pro PEntium Dual Cores 4 gb Ram…..Ever since this started Wednesday its worse.
Sorry Kfow. I am just waiting for my fix to you to be approved by a classroom teacher. They do not usually take this long, but the forums have been very busy these last few days. Sorry for the delays, and thanks for your patience.
Hi

Sorry for the delays, it should be much quicker now we've started.

Viewpoint Manager is often installed without the users permission. If you didn't install it, or if you did but you no longer use it, I recommend you get rid of it.

Please click Start >> Control Panel >> Add or Remove Programs.
Find the item below on the list and click Remove.
Viewpoint Manager
Let me know how it goes.


Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Symantec Internet Security
  • Please have a look at this link and follow its instructions.
  • Protection will now be disabled.
Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

I need to see another log from HijackThis.
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Thanks.
JP…Here is the combo fix log…

ComboFix 08-06-15.4 - Kevin Fowler 2008-06-16 10:48:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1303 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Kevin Fowler\Application Data\inst.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\afgfmksa.ini
C:\WINDOWS\system32\askmfgfa.dll
C:\WINDOWS\system32\geBRhGYQ.dll
C:\WINDOWS\system32\nnnnoPiI.dll
C:\WINDOWS\system32\pnjcedqi.ini
C:\WINDOWS\system32\QYGhRBeg.ini
C:\WINDOWS\system32\QYGhRBeg.ini2
F:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-05-16 to 2008-06-16 )))))))))))))))))))))))))))))))
.

2008-06-16 10:54 . 2008-06-16 10:54 344 –a—— C:\WINDOWS\system32\drivers\kgpfr2.cfg
2008-06-12 15:10 . 2008-06-13 10:12 d——– C:\Documents and Settings\Kevin Fowler\Application Data\HouseCall 6.6
2008-06-12 09:33 . 2008-06-12 09:33 d——– C:\Program Files\Trend Micro
2008-06-11 15:40 . 2008-06-11 15:39 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-11 15:39 . 2008-06-11 15:41 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-06-11 15:30 . 2008-06-11 15:30 d——– C:\Documents and Settings\Administrator\Application Data\TmpRecentIcons
2008-06-11 14:50 . 2008-06-11 14:50 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-11 14:09 . 2008-06-11 14:09 d——– C:\Program Files\Lavasoft
2008-06-11 14:09 . 2008-06-11 14:50 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-11 13:34 . 2008-06-16 10:33 d——– C:\Documents and Settings\All Users\Application Data\SITEguard
2008-06-11 13:34 . 2008-06-16 10:54 8,440 –a—— C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-06-11 13:33 . 2008-06-11 13:33 d——– C:\Program Files\STOPzilla!
2008-06-11 13:33 . 2008-06-11 13:33 d——– C:\Program Files\Common Files\iS3
2008-06-11 13:33 . 2008-06-16 10:58 d——– C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-06-11 13:08 . 2008-06-11 11:35 94,208 –a—— C:\WINDOWS\eawl.exe
2008-06-11 13:08 . 2008-06-11 11:35 81,920 –a—— C:\WINDOWS\pebgkxwq.exe
2008-06-10 23:35 . 2008-04-14 06:01 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 23:35 . 2008-04-14 06:01 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 17:59 . 2008-06-09 17:59 401,408 -ra—— C:\WINDOWS\system32\SZComp5.dll
2008-06-09 17:59 . 2008-06-09 17:59 258,048 -ra—— C:\WINDOWS\system32\SZBase5.dll
2008-06-05 09:01 . 2008-06-05 09:15 d——– C:\Documents and Settings\Kevin Fowler\Application Data\Move Networks
2008-06-03 14:43 . 2008-06-03 14:43 364,544 -ra—— C:\WINDOWS\system32\IS3DBA5.dll
2008-06-03 14:43 . 2008-06-03 14:43 126,976 -ra—— C:\WINDOWS\system32\IS3HTUI5.dll
2008-06-03 14:42 . 2008-06-03 14:42 372,736 -ra—— C:\WINDOWS\system32\IS3UI5.dll
2008-06-03 14:42 . 2008-06-03 14:42 61,440 -ra—— C:\WINDOWS\system32\IS3Hks5.dll
2008-06-03 14:42 . 2008-06-03 14:42 23,040 -ra—— C:\WINDOWS\system32\IS3XDat5.dll
2008-06-03 14:41 . 2008-06-03 14:41 196,608 -ra—— C:\WINDOWS\system32\IS3Win325.dll
2008-06-03 14:41 . 2008-06-03 14:41 94,208 -ra—— C:\WINDOWS\system32\IS3Inet5.dll
2008-06-03 14:40 . 2008-06-03 14:40 90,112 -ra—— C:\WINDOWS\system32\IS3Svc5.dll
2008-06-03 14:37 . 2008-06-03 14:37 708,608 -ra—— C:\WINDOWS\system32\IS3Base5.dll
2008-05-16 11:58 . 2008-05-16 11:58 12,632 –a—— C:\WINDOWS\system32\lsdelete.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-16 15:54 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-06-16 15:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-16 15:39 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-06-16 13:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-11 18:21 ——— d—–w C:\Program Files\MagicDVDCopier
2008-06-10 19:38 ——— d—–w C:\Documents and Settings\Kevin Fowler\Application Data\U3
2008-05-14 14:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-14 08:00 ——— d—–w C:\Program Files\MSXML 4.0
2008-05-13 16:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\vsosdk
2008-05-13 16:11 47,360 —-a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-05-13 16:11 47,360 —-a-w C:\Documents and Settings\Kevin Fowler\Application Data\pcouffin.sys
2008-05-13 16:11 ——— d—–w C:\Documents and Settings\Kevin Fowler\Application Data\Vso
2008-05-13 15:57 ——— d—–w C:\Program Files\DVD Decrypter
2008-05-13 15:52 ——— d—–w C:\Program Files\DVDneXtCOPY2
2008-05-13 15:52 ——— d—–w C:\Program Files\Common Files\DVDnextCOPY2
2008-05-13 15:52 ——— d—–w C:\Program Files\Common Files\DistributeShield
2008-05-13 15:03 34,432 —-a-r C:\WINDOWS\system32\drivers\SZKG.sys
2008-05-08 14:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 19:51 ——— d—–w C:\Program Files\Lexmark_HostCD
2008-05-06 16:16 ——— d—–w C:\Program Files\TOSHIBA
2008-04-30 18:10 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-04-29 16:20 15,648 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 16:19 15,648 —-a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 16:19 12,960 —-a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-19 22:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03 36975]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 15:52 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-04-17 12:30 85184]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 00:08 49152]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-06-12 17:29:50 622653]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-04-12 07:52:13 24576]
Xpress Mail Personal Edition.lnk - C:\Program Files\Xpress Mail\Personal Edition\XpressMailDesktopClient.exe [2007-07-17 11:15:56 3082352]
Xpress Mail Professional Edition.lnk - C:\Program Files\Xpress Mail\Personal Edition\XpressMailDesktopClient.exe [2007-07-17 11:15:56 3082352]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wined12.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winrm81.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SetPoint.lnk
backup=C:\WINDOWS\pss\SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
–a—— 2007-05-10 22:46 624248 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
–a—— 2007-07-17 12:51 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2007-12-18 14:04 50528 C:\Program Files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2006-01-02 17:41 45056 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2006-08-28 21:57 395776 C:\Program Files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
——— 2005-12-09 20:29 49152 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
–a—— 2007-04-12 07:55 227328 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech BT Wizard]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
–a—— 2005-12-20 17:38 28160 C:\WINDOWS\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2006-05-01 08:07 843776 C:\Program Files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Xpress Mail\\Personal Edition\\XpressMailDesktopClient.exe"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 10:03]
R2 ASFIPmon;Broadcom ASF IP Monitor;"C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" -service []
R3 EraserUtilDrv10741;EraserUtilDrv10741;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10741.sys [2008-01-18 04:00]
S0 Winrm81;Winrm81;C:\WINDOWS\system32\Drivers\Winrm81.sys []
S3 SevenConnectionService;Xpress Mail Professional Edition Service;C:\Program Files\Xpress Mail\Personal Edition\ConnectionService.exe [2007-05-17 18:09]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0b61266f-33b8-11dc-87ab-0019b9362036}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-06-13 15:22:25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-16 10:57:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Xpress Mail\Personal Edition\Connection.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-06-16 11:04:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-16 16:04:39

Pre-Run: 134,338,936,832 bytes free
Post-Run: 134,573,576,192 bytes free

213 — E O F — 2008-06-11 08:01:29
JP…Here is the Hijack Log… d-Aware Adobe Acrobat 8.1.1 Standard Adobe Flash Player ActiveX Adobe Flash Player Plugin AFPL Ghostscript 8.54 AFPL Ghostscript Fonts AIM 6 Apple Software Update ATI Catalyst Control Center ATI Display Driver Broadcom ASF Management Applications Broadcom Management Programs Compatibility Pack for the 2007 Office system Conexant D850 56K V.9x DFVc Modem Crystal Reports Basic Runtime for Visual Studio 2008 Crystal_10_Installer Crystal_10_Installer_2005 Dell ETS Factory Installation Dell Support 3.2.1 Digital Line Detect DVD Decrypter (Remove Only) DVDneXtCOPY Pro Google Desktop Google Earth Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer Google Updater High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB909394) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) HouseCall 6.6 HP Deskjet 6900 series HP Extended Capabilities 6.0 HP Imaging Device Functions 6.0 HP Photosmart Essential HP Software Update HP Solution Center and Imaging Support Tools 6.0 J2SE Runtime Environment 5.0 Update 6 Lexmark Software Uninstall LiveUpdate 2.6 (Symantec Corporation) Magic DVD Copier Version 4.8 build 4 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5 Microsoft ActiveSync Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional 2007 Microsoft Office Professional 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft User-Mode Driver Framework Feature Pack 1.0 Modem Helper Mozilla Firefox (3.0) Mozilla Thunderbird (2.0.0.14) MSXML 4.0 SP2 (KB936181) MSXML 6.0 Parser (KB933579) NetWaiting PowerDVD 5.7 Roxio DLA Roxio Express Labeler Roxio RecordNow Audio Roxio RecordNow Copy Roxio RecordNow Data Sacs Housing Software (Net) 1.0 SearchAssist SecondLife (remove only) Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Excel 2007 (KB946974) Security Update for Microsoft Office Publisher 2007 (KB950114) Security Update for Microsoft Office system 2007 (KB951808) Security Update for Microsoft Office Word 2007 (KB950113) Security Update for Office 2007 (KB947801) Security Update for Outlook 2007 (KB946983) Security Update for Step By Step Interactive Training (KB923723) Security Update for Visio 2007 (KB947590) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) SetPoint Sonic Update Manager STOPzilla Symantec AntiVirus TOSHIBA e-STUDIO AddressBook Viewer TOSHIBA e-STUDIO File Downloader TOSHIBA e-STUDIO Remote Scan Driver TOSHIBA e-STUDIO TWAIN Driver Update for Office 2007 (KB946691) Update for Outlook 2007 Junk Email Filter (kb950378) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB925720) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) URL Assistant WD Diagnostics WIDCOMM Bluetooth Software Windows Imaging Component Windows Internet Explorer 7 Windows Live installer Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Writer Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 WorldCard Mobile Xpress Mail Professional Edition Yahoo! Browser Services Yahoo! Install Manager Yahoo! Messenger
Hi

Please disable Symantec as before.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\eawl.exe
C:\WINDOWS\pebgkxwq.exe

Folder::
C:\Documents and Settings\All Users\Application Data\Viewpoint

Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"=-

Driver::
Winrm81

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt

Please run this online scan:

Panda Activescan

  • Once you are on the Panda site, click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log


We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\WINDOWS\system32\drivers\kgpfr2.cfg

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.

Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems.

Thanks.
When you first run notepad it should be empty. Then, you copy and paste the code that I have provided into notepad. Save the file as I posted and then drag this file onto ComboFix.

Is this what you meant?
combofix.txt

ComboFix 08-06-15.4 - Kevin Fowler 2008-06-17 9:45:44.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1245 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Kevin Fowler\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\eawl.exe
C:\WINDOWS\pebgkxwq.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Viewpoint

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_Winrm81


((((((((((((((((((((((((( Files Created from 2008-05-17 to 2008-06-17 )))))))))))))))))))))))))))))))
.

2008-06-17 09:49 . 2008-06-17 09:49 344 –a—— C:\WINDOWS\system32\drivers\kgpfr2.cfg
2008-06-16 15:40 . 2008-06-16 15:47 1,256 –a—— C:\WINDOWS\system32\tmp.reg
2008-06-16 15:35 . 2008-06-17 00:40 d–h—– C:\$AVG8.VAULT$
2008-06-16 15:28 . 2008-06-16 15:30 d——– C:\WINDOWS\system32\drivers\Avg
2008-06-16 15:28 . 2008-06-16 15:28 d——– C:\Program Files\AVG
2008-06-16 15:28 . 2008-06-16 15:28 d——– C:\Documents and Settings\All Users\Application Data\avg8
2008-06-16 15:28 . 2008-06-16 15:28 96,520 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-16 15:28 . 2008-06-16 15:28 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll
2008-06-16 15:27 . 2008-06-16 15:27 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-16 15:25 . 2008-06-16 15:26 d——– C:\Program Files\CCleaner
2008-06-16 15:10 . 2008-06-16 15:19 d——– C:\Documents and Settings\Guest
2008-06-12 15:10 . 2008-06-13 10:12 d——– C:\Documents and Settings\Kevin Fowler\Application Data\HouseCall 6.6
2008-06-12 09:33 . 2008-06-12 09:33 d——– C:\Program Files\Trend Micro
2008-06-11 15:40 . 2008-06-11 15:39 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-11 15:39 . 2008-06-11 15:41 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-06-11 15:30 . 2008-06-11 15:30 d——– C:\Documents and Settings\Administrator\Application Data\TmpRecentIcons
2008-06-11 14:50 . 2008-06-11 14:50 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-11 14:09 . 2008-06-11 14:09 d——– C:\Program Files\Lavasoft
2008-06-11 14:09 . 2008-06-11 14:50 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-11 13:34 . 2008-06-16 22:42 d——– C:\Documents and Settings\All Users\Application Data\SITEguard
2008-06-11 13:34 . 2008-06-17 09:49 12,392 –a—— C:\WINDOWS\system32\drivers\kgpcpy.cfg
2008-06-11 13:33 . 2008-06-11 13:33 d——– C:\Program Files\STOPzilla!
2008-06-11 13:33 . 2008-06-11 13:33 d——– C:\Program Files\Common Files\iS3
2008-06-11 13:33 . 2008-06-17 09:54 d——– C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-06-10 23:35 . 2008-04-14 06:01 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 23:35 . 2008-04-14 06:01 272,128 ——— C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 17:59 . 2008-06-09 17:59 401,408 -ra—— C:\WINDOWS\system32\SZComp5.dll
2008-06-09 17:59 . 2008-06-09 17:59 258,048 -ra—— C:\WINDOWS\system32\SZBase5.dll
2008-06-05 09:01 . 2008-06-05 09:15 d——– C:\Documents and Settings\Kevin Fowler\Application Data\Move Networks
2008-06-03 14:43 . 2008-06-03 14:43 364,544 -ra—— C:\WINDOWS\system32\IS3DBA5.dll
2008-06-03 14:43 . 2008-06-03 14:43 126,976 -ra—— C:\WINDOWS\system32\IS3HTUI5.dll
2008-06-03 14:42 . 2008-06-03 14:42 372,736 -ra—— C:\WINDOWS\system32\IS3UI5.dll
2008-06-03 14:42 . 2008-06-03 14:42 61,440 -ra—— C:\WINDOWS\system32\IS3Hks5.dll
2008-06-03 14:42 . 2008-06-03 14:42 23,040 -ra—— C:\WINDOWS\system32\IS3XDat5.dll
2008-06-03 14:41 . 2008-06-03 14:41 196,608 -ra—— C:\WINDOWS\system32\IS3Win325.dll
2008-06-03 14:41 . 2008-06-03 14:41 94,208 -ra—— C:\WINDOWS\system32\IS3Inet5.dll
2008-06-03 14:40 . 2008-06-03 14:40 90,112 -ra—— C:\WINDOWS\system32\IS3Svc5.dll
2008-06-03 14:37 . 2008-06-03 14:37 708,608 -ra—— C:\WINDOWS\system32\IS3Base5.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-17 14:51 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-06-17 14:35 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-06-17 14:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-16 20:25 ——— d—–w C:\Program Files\Yahoo!
2008-06-11 18:21 ——— d—–w C:\Program Files\MagicDVDCopier
2008-06-10 19:38 ——— d—–w C:\Documents and Settings\Kevin Fowler\Application Data\U3
2008-05-14 14:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-14 08:00 ——— d—–w C:\Program Files\MSXML 4.0
2008-05-13 16:39 ——— d—–w C:\Documents and Settings\All Users\Application Data\vsosdk
2008-05-13 16:11 47,360 —-a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-05-13 16:11 47,360 —-a-w C:\Documents and Settings\Kevin Fowler\Application Data\pcouffin.sys
2008-05-13 16:11 ——— d—–w C:\Documents and Settings\Kevin Fowler\Application Data\Vso
2008-05-13 15:57 ——— d—–w C:\Program Files\DVD Decrypter
2008-05-13 15:52 ——— d—–w C:\Program Files\DVDneXtCOPY2
2008-05-13 15:52 ——— d—–w C:\Program Files\Common Files\DVDnextCOPY2
2008-05-13 15:52 ——— d—–w C:\Program Files\Common Files\DistributeShield
2008-05-13 15:03 34,432 —-a-r C:\WINDOWS\system32\drivers\SZKG.sys
2008-05-08 14:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 19:51 ——— d—–w C:\Program Files\Lexmark_HostCD
2008-05-06 16:16 ——— d—–w C:\Program Files\TOSHIBA
2008-04-30 18:10 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-04-29 16:20 15,648 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 16:19 15,648 —-a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 16:19 12,960 —-a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-19 22:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
.

((((((((((((((((((((((((((((( snapshot@2008-06-16_11.04.22.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-16 15:54:13 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-17 14:49:34 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-16 20:28:35 26,184 —-a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
- 2008-04-10 14:59:15 280,536 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-06-16 20:57:51 275,760 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2006-12-02 05:46:44 65,536 —-a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 21:57 395776]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-12-18 14:04 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03 36975]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 15:52 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-04-17 12:30 85184]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 00:08 49152]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-16 15:28 1177368]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 08:07 843776]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-12-20 17:38 28160 C:\WINDOWS\KHALMNPR.Exe]
"Logitech BT Wizard"="LBTWiz.exe" []
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-04-12 07:55 227328]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 20:29 49152]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41 45056]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-06-12 17:29:50 622653]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-04-12 07:52:13 24576]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-01 09:49:43 124400]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-09-24 00:28:44 282624]
SetPoint.lnk - C:\Program Files\SetPoint\SetPoint.exe [2007-04-12 07:53:06 532480]
Xpress Mail Personal Edition.lnk - C:\Program Files\Xpress Mail\Personal Edition\XpressMailDesktopClient.exe [2007-07-17 11:15:56 3082352]
Xpress Mail Professional Edition.lnk - C:\Program Files\Xpress Mail\Personal Edition\XpressMailDesktopClient.exe [2007-07-17 11:15:56 3082352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wined12.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winrm81.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Xpress Mail\\Personal Edition\\XpressMailDesktopClient.exe"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 10:03]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-16 15:28]
R2 ASFIPmon;Broadcom ASF IP Monitor;"C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe" -service []
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-16 15:28]
R3 EraserUtilDrv10741;EraserUtilDrv10741;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10741.sys [2008-01-18 04:00]
S3 SevenConnectionService;Xpress Mail Professional Edition Service;C:\Program Files\Xpress Mail\Personal Edition\ConnectionService.exe [2007-05-17 18:09]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0b61266f-33b8-11dc-87ab-0019b9362036}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-06-13 15:22:25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-17 09:51:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\SetPoint\LBTWiz.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Xpress Mail\Personal Edition\Connection.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
.
**************************************************************************
.
Completion time: 2008-06-17 10:01:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-17 15:01:04
ComboFix2.txt 2008-06-16 16:04:44

Pre-Run: 134,433,288,192 bytes free
Post-Run: 134,433,738,752 bytes free

220 — E O F — 2008-06-11 08:01:29
panda scan ;******************************************************************************* ********************************************************************************* ******************* ANALYSIS: 2008-06-17 13:36:33 PROTECTIONS: 2 MALWARE: 15 SUSPECTS: 0 ;******************************************************************************* ********************************************************************************* ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================= =================== AVG Anti-Virus Free 8.0 Yes Yes Symantec AntiVirus Corporate Edition 10.0.0.359 Yes Yes ;=============================================================================== ================================================================================= =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================= =================== 00046761 adware/xupiter Adware No 0 Yes No c:\documents and settings\kevin fowler\favorites\inernet 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Desktop\ATT 8925\Program Files\Minimo\profile\Mozilla\minimo\cookies.txt[.doubleclick.net/] 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt 00139535 Application/Processor HackTools No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000147.exe 00139535 Application/Processor HackTools No 0 Yes No C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Process.exe 00139535 Application/Processor HackTools No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP5\A0000400.exe 00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt 00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Guest\Cookies\guest@com[1].txt 00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Desktop\ATT 8925\Program Files\Minimo\profile\Mozilla\minimo\cookies.txt[server.iad.liveperson.net/hc/54341825] 00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Desktop\ATT 8925\Program Files\Minimo\profile\Mozilla\minimo\cookies.txt[server.iad.liveperson.net/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Desktop\ATT 8925\Program Files\Minimo\profile\Mozilla\minimo\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Desktop\ATT 8925\Program Files\Minimo\profile\Mozilla\minimo\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Desktop\ATT 8925\Program Files\Minimo\profile\Mozilla\minimo\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Desktop\ATT 8925\Program Files\Minimo\profile\Mozilla\minimo\cookies.txt[.advertising.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Cookies\[removed][1].txt 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Guest\Cookies\[removed][1].txt 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Cookies\kevin_fowler@questionmarket[1].txt 00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Kevin Fowler\Desktop\ATT 8925\Program Files\Minimo\profile\Mozilla\minimo\cookies.txt[.atwola.com/] 01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\Documents and Settings\Kevin Fowler\Desktop\ComboFix.exe[327882R2FWJFW\NirCmdC.cfexe] 01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000161.EXE 01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP5\A0000414.EXE 02197130 Trj/Rebooter.J Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000148.exe 02197130 Trj/Rebooter.J Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP5\A0000401.exe 02197130 Trj/Rebooter.J Virus/Trojan No 1 Yes No C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP3\A0000112.sys 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\WINDOWS\system32\drivers\Combo-Fix.sys.szcpf 02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP5\A0000372.sys ;=============================================================================== ================================================================================= =================== SUSPECTS Sent Location L ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= =================== VULNERABILITIES Id Severity Description L ;=============================================================================== ================================================================================= =================== ;=============================================================================== ================================================================================= ===================

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI