This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HijackThis log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My friend had what seemed like a browser hijack on her Windows Vista computer but after the problems started she couldn't get online at all, even trying 3 different browsers (internet explorer, firefox, netscape). She was running 2 firewalls and I replaced those with PC Tools Firewall, and replaced mcafee antivirus with Avast. I ran ATF Cleaner, CCleaner, and SuperAntiSpyware (neither ATF Cleaner nor SuperAntiSpyware found any problems). I ran a hard disk error check and then got logs for both HijackThis and ComboFix, which I will post here. After all of this, she decided to try and get online, and it actually seems to be working now, but I want to make sure there's nothing nasty left in here.

Thanks in advance!



Logfile of HijackThis v1.99.1
Scan saved at 15:50, on 2008-06-26
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…DTP&M;=T5234
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…DTP&M;=T5234
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Spare Backup] "C:\Program Files\Spare Backup\SpareBackup.exe" /silent
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup
O4 - HKLM\..\Run: [lxctmon.exe] "C:\Program Files\Lexmark 5400 Series\lxctmon.exe"
O4 - HKLM\..\Run: [Lexmark 5400 Series Fax Server] "C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 5400 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXCTCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O8 - Extra context menu item: Display All Images with Full Quality - "res://C:\Program Files\NetZero\qsacc\appres.dll/228"
O8 - Extra context menu item: Display Image with Full Quality - "res://C:\Program Files\NetZero\qsacc\appres.dll/227"
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O15 - Trusted Zone: *.netzero.com
O15 - Trusted Zone: *.netzero.net
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxbc_device - - C:\Windows\system32\lxbccoms.exe
O23 - Service: lxct_device - - C:\Windows\system32\lxctcoms.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ThreatFire - Unknown owner - C:\Program Files\ThreatFire\TFService.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe



ComboFix 08-06-20.4 - Ron Koch 2008-06-26 18:51:34.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.240 [GMT -7:00]Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.

2008-06-26 09:43 . 2008-06-26 09:43 376 –a—— C:\Windows\ODBC.INI
2008-06-26 09:43 . 2008-06-26 09:43 112 –a—— C:\Windows\win.ini
2008-06-26 09:42 . 2008-06-26 09:42 d——– C:\Program Files\Microsoft ActiveSync
2008-06-26 09:42 . 2008-06-26 09:42 d——– C:\Program Files\Common Files\L&H;
2008-06-25 21:07 . 2008-06-25 21:07 d——– C:\Program Files\Alwil Software
2008-06-25 21:07 . 2008-05-15 16:18 50,768 –a—— C:\Windows\System32\drivers\aswMonFlt.sys
2008-06-25 20:51 . 2008-06-25 20:51 d——– C:\Program Files\CCleaner
2008-06-25 20:42 . 2008-06-25 20:42 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-06-25 20:42 . 2008-06-25 20:42 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-06-25 20:41 . 2008-06-25 20:41 d——– C:\Users\Ron Koch\AppData\Roaming\SUPERAntiSpyware.com
2008-06-25 20:41 . 2008-06-25 20:41 d——– C:\Program Files\SUPERAntiSpyware
2008-06-25 20:40 . 2008-06-25 20:40 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-25 20:40 . 2008-06-25 20:40 d——– C:\fixwareout
2008-06-25 18:41 . 2008-06-25 18:41 d——– C:\Users\Ron Koch\AppData\Roaming\Netscape
2008-06-25 18:40 . 2008-06-25 18:40 d——– C:\Program Files\Netscape
2008-06-24 21:28 . 2008-06-24 21:28 d——– C:\Users\All Users\NetZero
2008-06-24 21:28 . 2008-06-24 21:28 d——– C:\ProgramData\NetZero
2008-06-22 18:20 . 2008-06-22 18:20 d——– C:\Program Files\SpyGuarder
2008-06-14 08:10 . 2008-04-22 21:27 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-06-14 08:10 . 2008-04-22 21:27 428,032 –a—— C:\Windows\System32\EncDec.dll
2008-06-14 08:10 . 2008-04-22 21:27 292,352 –a—— C:\Windows\System32\psisdecd.dll
2008-06-14 08:10 . 2008-04-22 21:26 218,624 –a—— C:\Windows\System32\psisrndr.ax
2008-06-14 08:10 . 2008-04-22 21:26 80,896 –a—— C:\Windows\System32\MSNP.ax
2008-06-14 08:10 . 2008-04-22 21:26 68,608 –a—— C:\Windows\System32\Mpeg2Data.ax
2008-06-14 08:10 . 2008-04-22 21:26 57,856 –a—— C:\Windows\System32\MSDvbNP.ax
2008-06-12 12:51 . 2003-06-18 17:31 17,920 –a—— C:\Windows\System32\mdimon.dll
2008-06-11 07:35 . 2008-04-26 01:02 1,327,104 –a—— C:\Windows\System32\quartz.dll
2008-06-11 07:35 . 2008-05-09 18:21 113,664 –a—— C:\Windows\System32\drivers\rmcast.sys
2008-06-11 07:35 . 2008-05-09 20:30 14,848 –a—— C:\Windows\System32\wshrm.dll
2008-05-27 22:16 . 2008-03-07 17:37 4,247,552 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-05-27 22:16 . 2008-03-07 21:30 1,686,528 –a—— C:\Windows\System32\gameux.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 01:51 ——— d—–w C:\Users\Ron Koch\AppData\Roaming\Spare Backup
2008-06-27 01:50 ——— d—–w C:\Program Files\Lx_cats
2008-06-26 05:50 7,930 —-a-w C:\Users\Ron Koch\AppData\Roaming\wklnhst.dat
2008-06-26 05:36 ——— d—–w C:\ProgramData\McAfee
2008-06-26 04:24 ——— d—–w C:\Program Files\ThreatFire
2008-06-26 04:22 ——— d—a-w C:\ProgramData\TEMP
2008-06-26 04:08 ——— d—–w C:\ProgramData\SiteAdvisor
2008-06-25 05:30 ——— d—–w C:\ProgramData\Microsoft Help
2008-06-25 04:29 ——— d—–w C:\Program Files\NetZero
2008-06-25 03:50 ——— d—–w C:\Program Files\PokerStars
2008-06-25 03:29 ——— d—–w C:\Program Files\Google
2008-06-12 15:03 ——— d—–w C:\Program Files\Windows Mail
2008-05-13 20:34 ——— d—–w C:\Program Files\Full Tilt Poker
2008-05-07 06:05 ——— d—–w C:\Program Files\MOV to AVI MPEG WMV Converter
2008-05-05 01:30 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-05-05 01:27 ——— d—–w C:\Program Files\eBay
2008-05-03 05:17 ——— d—–w C:\Users\Ron Koch\AppData\Roaming\Move Networks
2008-04-25 04:23 826,368 —-a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 —-a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2007-10-03 20:20 174 –sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 18:43 4670704]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 05:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 05:36 201728]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 00:51 4435968 C:\Windows\RtHDVCpl.exe]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-09 21:21 240640]
"Spare Backup"="C:\Program Files\Spare Backup\SpareBackup.exe" [2007-07-05 20:38 5252936]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2006-09-06 12:12 323216]
"BigFix"="c:\program files\Bigfix\bigfix.exe" [2006-11-16 16:04 2348584]
"lxctmon.exe"="C:\Program Files\Lexmark 5400 Series\lxctmon.exe" [2006-06-20 06:37 286720]
"Lexmark 5400 Series Fax Server"="C:\Program Files\Lexmark 5400 Series\fm3032.exe" [2006-07-10 16:30 294912]
"EzPrint"="C:\Program Files\Lexmark 5400 Series\ezprint.exe" [2006-06-06 20:05 98304]
"LXCTCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-06-07 05:09 106496]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 06:28 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 06:28 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 06:28 81920]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 16:19 79224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="C:\Windows\SMINST\launcher.exe" [2007-07-03 17:31 40072]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-08-09 21:48:43 2348584]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BC85D0F8-42C4-4DA3-9520-7A37C650D5A1}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B9570AC-E59D-4B59-881D-C396CB027822}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8E27AD47-BBEF-4B24-89C1-ACCEC6108625}"= UDP:C:\Windows\System32\lxctcoms.exe:Lexmark Communications System
"{F67934AF-0D95-4D4F-A964-735FD44E759C}"= TCP:C:\Windows\System32\lxctcoms.exe:Lexmark Communications System
"{5B84CFCF-2871-47F6-B103-B3FCEB55B830}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{7AD87AB7-CF7E-4E4A-9A72-0BAC3EC41E0E}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{0875C7E8-961B-4470-A7FB-4F829DE1E9E5}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{6E8C6AFB-EE4C-429A-A5E8-FD615C46DEA7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{097526AA-4674-4DD5-ABFA-8502267D98E4}"= UDP:C:\Windows\System32\lxbccoms.exe:Lexmark Communications System
"{292D7013-8245-4C6B-AE4A-EB08AC4B07DD}"= TCP:C:\Windows\System32\lxbccoms.exe:Lexmark Communications System
"{016CBAC2-187F-4DA6-8694-B7D1F513253D}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbcpswx.exe:Printer Status Window
"{A11C6663-C2C1-47F5-801B-DBC0865A9229}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbcpswx.exe:Printer Status Window
"TCP Query User{94F92911-B979-4680-93A4-6D2BE30B0765}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{C3F57ABE-6287-4AC0-A1C7-405F929A034A}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{EC24C2BD-24C3-486D-9B82-D42334872331}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{69861FF6-1786-4913-91AE-62A02C60A1D1}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-15 16:20]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-15 16:16]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-15 16:18]
R2 lxbc_device;lxbc_device;C:\Windows\system32\lxbccoms.exe [2007-03-16 02:24]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 10:51]
R3 ZG760_XP;ZyXEL 802.11g XG762 1211 Driver;C:\Windows\system32\DRIVERS\WlanGZXP.sys [2006-08-16 19:04]
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 00:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rsmsvcs REG_MULTI_SZ ntmssvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22802c1b-c84f-11dc-a397-001bb9a85c48}]
\shell\AutoRun\command - L:\LaunchU3.exe -a

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-26 18:55:03
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCTCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-26 18:56:26
ComboFix-quarantined-files.txt 2008-06-27 01:56:19
ComboFix2.txt 2008-06-27 01:47:46

Pre-Run: 242,625,396,736 bytes free
Post-Run: 242,598,993,920 bytes free

154 — E O F — 2008-06-26 02:10:50
Hi, and Welcome to WhatTheTech :)

So sorry for the delays :(

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
As I am still training, my posts to you will be checked by an Expert member. This will ensure that all advice and instructions I give you are accurate and safe. This may mean that my replies may take a little longer.

jpshortstuff
Hi

Please remove your version of HijackThis as it is outdated. Should we need to use HijackThis at any point we will download the newest version later.

Please post the contents of this report:
C:\QooBox\ComboFix2.txt
in your next reply.

Remove Poker programs
From your log I can see you've installed poker programs. A lot of poker programs are infected/can infect you with malware.
I would advise you to go to Add/Remove programs and uninstall your poker programs, namely these ones:
PartyPoker

You already have PokerStars installed which is regarded safe for use.

Thanks.
Okay, we've removed two poker programs (including PartyPoker) and left PokerStars. Thank you for your help!

Here is the new combofix log:



ComboFix 08-07-10.1 - Ron Koch 2008-07-10 16:57:16.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.218 [GMT -7:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\SpyGuarder
C:\Program Files\SpyGuarder\Buy.url
C:\Program Files\SpyGuarder\Help.url
C:\Program Files\SpyGuarder\HowToBuy.txt
C:\Program Files\SpyGuarder\License.txt

.
((((((((((((((((((((((((( Files Created from 2008-06-10 to 2008-07-10 )))))))))))))))))))))))))))))))
.

2008-06-28 10:35 . 2008-06-28 10:35 d——– C:\Users\Ron Koch\AppData\Roaming\Leadertech
2008-06-27 13:52 . 2008-07-10 16:22 d——– C:\TEMP
2008-06-27 09:24 . 2008-06-26 19:32 6,715,200 –a—— C:\fwinstall.exe
2008-06-26 19:37 . 2008-06-26 19:37 d——– C:\Users\Ron Koch\AppData\Roaming\PCToolsFirewallPlus
2008-06-26 19:33 . 2008-06-26 19:45 d——– C:\Program Files\PC Tools Firewall Plus
2008-06-26 19:33 . 2008-06-26 19:33 d——– C:\Program Files\Common Files\PC Tools
2008-06-26 19:33 . 2008-03-12 09:30 159,896 –a—— C:\Windows\System32\drivers\pctfw2.sys
2008-06-26 19:33 . 2008-02-25 16:38 93,440 –a—— C:\Windows\System32\drivers\pctfw.sys
2008-06-26 19:33 . 2008-02-21 08:56 40,856 –a—— C:\Windows\System32\drivers\pctmp.sys
2008-06-26 19:33 . 2008-02-21 08:56 18,328 –a—— C:\Windows\System32\drivers\pctssipc.sys
2008-06-26 19:23 . 2004-10-15 18:17 60,496 –a—— C:\Windows\System32\drivers\Teefer.sys
2008-06-26 19:23 . 2004-10-15 18:18 21,075 –a—— C:\Windows\System32\drivers\wpsdrvnt.sys
2008-06-26 19:23 . 2004-10-15 18:32 14,568 –a—— C:\Windows\System32\drivers\wg6n.sys
2008-06-26 19:23 . 2004-10-15 18:32 14,568 –a—— C:\Windows\System32\drivers\wg5n.sys
2008-06-26 19:23 . 2004-10-15 18:32 14,568 –a—— C:\Windows\System32\drivers\wg4n.sys
2008-06-26 19:23 . 2004-10-15 18:32 14,568 –a—— C:\Windows\System32\drivers\wg3n.sys
2008-06-26 19:21 . 2004-10-15 18:32 83,096 –a—— C:\Windows\System32\SSSensor.dll
2008-06-26 09:43 . 2008-06-26 09:43 376 –a—— C:\Windows\ODBC.INI
2008-06-26 09:43 . 2008-06-26 09:43 112 –a—— C:\Windows\win.ini
2008-06-26 09:42 . 2008-06-26 09:42 d——– C:\Program Files\Microsoft ActiveSync
2008-06-26 09:42 . 2008-06-26 09:42 d——– C:\Program Files\Common Files\L&H;
2008-06-25 21:07 . 2008-06-25 21:07 d——– C:\Program Files\Alwil Software
2008-06-25 21:07 . 2008-05-15 16:18 50,768 –a—— C:\Windows\System32\drivers\aswMonFlt.sys
2008-06-25 20:51 . 2008-06-25 20:51 d——– C:\Program Files\CCleaner
2008-06-25 20:42 . 2008-06-25 20:42 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-06-25 20:42 . 2008-06-25 20:42 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-06-25 20:41 . 2008-06-25 20:41 d——– C:\Users\Ron Koch\AppData\Roaming\SUPERAntiSpyware.com
2008-06-25 20:41 . 2008-06-25 20:41 d——– C:\Program Files\SUPERAntiSpyware
2008-06-25 20:40 . 2008-06-26 19:20 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-25 20:40 . 2008-06-25 20:40 d——– C:\fixwareout
2008-06-25 18:41 . 2008-06-25 18:41 d——– C:\Users\Ron Koch\AppData\Roaming\Netscape
2008-06-25 18:40 . 2008-06-25 18:40 d——– C:\Program Files\Netscape
2008-06-24 21:28 . 2008-06-24 21:28 d——– C:\Users\All Users\NetZero
2008-06-24 21:28 . 2008-06-24 21:28 d——– C:\ProgramData\NetZero
2008-06-14 08:10 . 2008-04-22 21:27 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2008-06-14 08:10 . 2008-04-22 21:27 428,032 –a—— C:\Windows\System32\EncDec.dll
2008-06-14 08:10 . 2008-04-22 21:27 292,352 –a—— C:\Windows\System32\psisdecd.dll
2008-06-14 08:10 . 2008-04-22 21:26 218,624 –a—— C:\Windows\System32\psisrndr.ax
2008-06-14 08:10 . 2008-04-22 21:26 80,896 –a—— C:\Windows\System32\MSNP.ax
2008-06-14 08:10 . 2008-04-22 21:26 68,608 –a—— C:\Windows\System32\Mpeg2Data.ax
2008-06-14 08:10 . 2008-04-22 21:26 57,856 –a—— C:\Windows\System32\MSDvbNP.ax
2008-06-12 12:51 . 2003-06-18 17:31 17,920 –a—— C:\Windows\System32\mdimon.dll
2008-06-11 07:35 . 2008-04-26 01:02 1,327,104 –a—— C:\Windows\System32\quartz.dll
2008-06-11 07:35 . 2008-05-09 18:21 113,664 –a—— C:\Windows\System32\drivers\rmcast.sys
2008-06-11 07:35 . 2008-05-09 20:30 14,848 –a—— C:\Windows\System32\wshrm.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-10 23:49 ——— d—–w C:\Users\Ron Koch\AppData\Roaming\Spare Backup
2008-07-10 23:48 ——— d—a-w C:\ProgramData\TEMP
2008-07-10 23:47 ——— d—–w C:\Program Files\Lx_cats
2008-07-10 23:47 ——— d—–w C:\Program Files\Full Tilt Poker
2008-07-10 22:58 9,728 —-a-w C:\Users\Ron Koch\AppData\Roaming\wklnhst.dat
2008-07-09 20:05 174 –sha-w C:\Program Files\desktop.ini
2008-07-09 19:51 ——— d—–w C:\Program Files\Windows Mail
2008-06-30 01:23 ——— d—–w C:\Program Files\PokerStars
2008-06-27 04:10 ——— d—–w C:\ProgramData\Microsoft Help
2008-06-26 05:36 ——— d—–w C:\ProgramData\McAfee
2008-06-26 04:24 ——— d—–w C:\Program Files\ThreatFire
2008-06-26 04:08 ——— d—–w C:\ProgramData\SiteAdvisor
2008-06-25 04:29 ——— d—–w C:\Program Files\NetZero
2008-06-25 03:29 ——— d—–w C:\Program Files\Google
2008-04-25 04:23 826,368 —-a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 —-a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2008-04-02 23:13 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008040220080403\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-06-26_18.55.57.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 15:03:28 51,200 —-a-w C:\Windows\inf\infpub.dat
+ 2008-06-27 02:33:55 51,200 —-a-w C:\Windows\inf\infpub.dat
- 2008-06-12 15:03:27 86,016 —-a-w C:\Windows\inf\infstor.dat
+ 2008-06-27 02:33:54 86,016 —-a-w C:\Windows\inf\infstor.dat
- 2008-06-12 15:03:27 86,016 —-a-w C:\Windows\inf\infstrng.dat
+ 2008-06-27 02:33:54 86,016 —-a-w C:\Windows\inf\infstrng.dat
+ 2003-07-07 20:36:00 2,058,343 —-a-r C:\Windows\Installer\$PatchCache$\Managed\9040AC1900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DAT
+ 2003-07-08 18:48:00 115,288 —-a-r C:\Windows\Installer\$PatchCache$\Managed\9040AC1900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DLL
- 2008-06-25 05:30:42 217,864 —-a-r C:\Windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-06-27 04:08:22 217,864 —-a-r C:\Windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2008-06-25 05:29:29 20,240 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-06-27 04:09:09 20,240 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-06-25 05:29:29 184,080 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-06-27 04:09:09 184,080 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2008-06-25 05:29:29 217,864 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2008-06-27 04:09:09 217,864 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2008-06-25 05:29:29 18,704 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-06-27 04:09:09 18,704 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-06-25 05:29:29 35,088 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-06-27 04:09:09 35,088 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-06-25 05:29:29 922,384 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-06-27 04:09:09 922,384 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2008-06-25 05:29:29 888,080 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-06-27 04:09:09 888,080 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-06-25 05:29:29 1,172,240 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-06-27 04:09:09 1,172,240 —-a-r C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-06-26 16:43:28 12,288 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-07-09 19:52:40 12,288 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-06-26 16:43:28 135,168 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-07-09 19:52:39 135,168 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-06-26 16:43:28 11,264 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-07-09 19:52:40 11,264 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-06-26 16:43:28 27,136 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-07-09 19:52:40 27,136 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-06-26 16:43:28 4,096 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-07-09 19:52:40 4,096 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-06-26 16:43:28 794,624 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-07-09 19:52:40 794,624 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-06-26 16:43:28 249,856 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-07-09 19:52:40 249,856 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-06-26 16:43:28 61,440 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-07-09 19:52:39 61,440 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-06-26 16:43:28 23,040 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-07-09 19:52:40 23,040 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-06-26 16:43:28 286,720 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-07-09 19:52:39 286,720 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-06-26 16:43:28 409,600 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-07-09 19:52:39 409,600 —-a-r C:\Windows\Installer\{91CA0409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-06-27 02:21:44 4,608 —-a-r C:\Windows\Installer\{F34D9A5F-484A-4E31-A9D3-908CB265B289}\IconC989D247.exe
- 2008-06-27 01:49:35 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-07-10 12:52:39 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-06-27 01:49:35 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-07-10 12:52:39 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-06-27 01:51:15 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-07-10 12:53:56 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-07-10 12:53:56 262,144 —ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-05-03 05:24:17 1,021,069 -c–a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
+ 2008-07-09 20:05:32 1,021,069 -c–a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareLicensing\tokens.dat
- 2008-06-27 01:51:10 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-07-10 12:54:26 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-07-10 12:54:26 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-06-27 01:50:43 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-07-10 20:54:23 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-06-27 01:50:43 229,376 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-10 20:54:23 229,376 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-27 01:50:43 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-07-10 20:54:23 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-06-26 04:12:33 262,144 —-a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-07-10 23:57:11 262,144 —-a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-02-25 23:38:36 93,440 —-a-w C:\Windows\System32\DriverStore\FileRepository\pctdriver.inf_f16961b3\pctfw.sys
- 2008-06-27 01:25:10 383,464 —-a-w C:\Windows\System32\FNTCACHE.DAT
+ 2008-06-27 04:14:18 385,456 —-a-w C:\Windows\System32\FNTCACHE.DAT
+ 2004-10-16 01:31:58 99,480 —-a-w C:\Windows\System32\FwsVpn.dll
+ 2008-03-25 03:21:18 2,889,088 —-a-w C:\Windows\System32\Macromed\Flash\NPSWF32.dll
+ 2008-03-25 03:21:20 218,496 —-a-w C:\Windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-06-27 02:56:57 70,264 —-a-w C:\Windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2004-10-16 01:31:56 218,264 —-a-w C:\Windows\System32\SetAid.dll
- 2007-10-03 19:41:55 11,315,200 —-a-w C:\Windows\System32\shell32.dll
+ 2008-04-24 04:51:39 11,315,712 —-a-w C:\Windows\System32\shell32.dll
- 2008-06-25 05:35:57 6,291,456 —-a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
+ 2008-07-10 04:48:23 6,291,456 —-a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
- 2008-06-27 01:52:10 15,256 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-637420621-908585155-2948939581-1000_UserData.bin
+ 2008-07-10 12:55:02 16,074 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-637420621-908585155-2948939581-1000_UserData.bin
- 2008-06-27 01:52:09 65,958 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-07-10 12:55:02 69,726 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-06-27 01:51:31 52,668 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-07-10 12:54:56 54,744 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-06-09 22:40:17 2,413,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16699_none_f0498ecc6e94a1be\OESpamFilter.dat
+ 2008-06-09 22:37:40 2,413,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20855_none_f0fa6c058795698f\OESpamFilter.dat
+ 2008-06-11 00:28:21 2,413,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18088_none_f2399d146bb3fd67\OESpamFilter.dat
+ 2008-06-09 22:36:23 2,413,032 —-a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22200_none_f311b8d58497f018\OESpamFilter.dat
+ 2008-04-24 04:51:39 11,315,712 —-a-w C:\Windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6000.16680_none_69ec6cd815163c56\shell32.dll
+ 2008-04-24 04:40:28 11,319,808 —-a-w C:\Windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6000.20822_none_6ab8eba52e01644f\shell32.dll
+ 2008-04-24 04:58:20 11,580,416 —-a-w C:\Windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6001.18062_none_6bea4bea122ac813\shell32.dll
+ 2008-04-24 04:45:45 11,581,440 —-a-w C:\Windows\winsxs\x86_microsoft-windows-shell32_31bf3856ad364e35_6.0.6001.22166_none_6c77e9dd2b44cd39\shell32.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 18:43 4670704]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 05:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 05:36 201728]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-09 21:21 240640]
"Spare Backup"="C:\Program Files\Spare Backup\SpareBackup.exe" [2007-07-05 20:38 5252936]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2006-09-06 12:12 323216]
"BigFix"="c:\program files\Bigfix\bigfix.exe" [2006-11-16 16:04 2348584]
"lxctmon.exe"="C:\Program Files\Lexmark 5400 Series\lxctmon.exe" [2006-06-20 06:37 286720]
"Lexmark 5400 Series Fax Server"="C:\Program Files\Lexmark 5400 Series\fm3032.exe" [2006-07-10 16:30 294912]
"EzPrint"="C:\Program Files\Lexmark 5400 Series\ezprint.exe" [2006-06-06 20:05 98304]
"LXCTCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-06-07 05:09 106496]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 06:28 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 06:28 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 06:28 81920]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 16:19 79224]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2008-03-28 14:37 2598808]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 00:51 4435968 C:\Windows\RtHDVCpl.exe]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-08-09 21:48:43 2348584]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BC85D0F8-42C4-4DA3-9520-7A37C650D5A1}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B9570AC-E59D-4B59-881D-C396CB027822}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8E27AD47-BBEF-4B24-89C1-ACCEC6108625}"= UDP:C:\Windows\System32\lxctcoms.exe:Lexmark Communications System
"{F67934AF-0D95-4D4F-A964-735FD44E759C}"= TCP:C:\Windows\System32\lxctcoms.exe:Lexmark Communications System
"{5B84CFCF-2871-47F6-B103-B3FCEB55B830}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{7AD87AB7-CF7E-4E4A-9A72-0BAC3EC41E0E}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{0875C7E8-961B-4470-A7FB-4F829DE1E9E5}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{6E8C6AFB-EE4C-429A-A5E8-FD615C46DEA7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{097526AA-4674-4DD5-ABFA-8502267D98E4}"= UDP:C:\Windows\System32\lxbccoms.exe:Lexmark Communications System
"{292D7013-8245-4C6B-AE4A-EB08AC4B07DD}"= TCP:C:\Windows\System32\lxbccoms.exe:Lexmark Communications System
"{016CBAC2-187F-4DA6-8694-B7D1F513253D}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbcpswx.exe:Printer Status Window
"{A11C6663-C2C1-47F5-801B-DBC0865A9229}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbcpswx.exe:Printer Status Window
"TCP Query User{94F92911-B979-4680-93A4-6D2BE30B0765}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{C3F57ABE-6287-4AC0-A1C7-405F929A034A}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{EC24C2BD-24C3-486D-9B82-D42334872331}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{69861FF6-1786-4913-91AE-62A02C60A1D1}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"{88619E2B-98D0-46F8-BC78-29D24B0E5E18}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C1B35ADC-3769-446B-A600-FF13B273084F}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-15 16:20]
R1 pctfw2;pctfw2;C:\Windows\System32\drivers\pctfw2.sys [2008-03-12 09:30]
R1 pctmp;PC Tools Firewall Memory Protection Driver;C:\Windows\system32\drivers\pctmp.sys [2008-02-21 08:56]
R1 pctssipc;PC Tools Security Suite IPC Driver;C:\Windows\system32\drivers\pctssipc.sys [2008-02-21 08:56]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-15 16:16]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-15 16:18]
R2 lxbc_device;lxbc_device;C:\Windows\system32\lxbccoms.exe [2007-03-16 02:24]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 10:51]
R3 ZG760_XP;ZyXEL 802.11g XG762 1211 Driver;C:\Windows\system32\DRIVERS\WlanGZXP.sys [2006-08-16 19:04]
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 00:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rsmsvcs REG_MULTI_SZ ntmssvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22802c1b-c84f-11dc-a397-001bb9a85c48}]
\shell\AutoRun\command - L:\LaunchU3.exe -a

.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SmcService - C:\PROGRA~1\Sygate\SPF\smc.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-10 17:00:34
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCTCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-07-10 17:02:36
ComboFix-quarantined-files.txt 2008-07-11 00:02:29
ComboFix2.txt 2008-06-27 01:56:27
ComboFix3.txt 2008-06-27 01:47:46

Pre-Run: 239,757,733,888 bytes free
Post-Run: 239,801,737,216 bytes free

288 — E O F — 2008-07-09 19:52:58
Hi

Please do not run ComboFix without instruction to by a helper

I did not ask for a new ComboFix log, I asked for an existing one. Since you ran CF again, the name of this log has changed. Please open the following file in notepad:
C:\QooBox\ComboFix3.txt
and then post the contents in a new reply. Do not touch ComboFix unless I instruct you to.

You appear to have downloaded and ran a new copy of the ComboFix. Are you receiving help elsewhere?

Please right click Internet Explorer on your desktop and then select "Run As Administrator". Next, go to Kaspersky website and perform an online antivirus scan.

NOTE: Internet Explorer will temporarily have administrator privileges, this is required for the scan but dangerous for normal surfing so do NOT open any other websites in IE until after the scan has finished and this window has been closed.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Thanks.
I'm sorry; I misunderstood about ComboFix. I'm not getting help anywhere else but I followed this tutorial for using ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Here is the log from C:\QooBox\ComboFix3.txt :


ComboFix 08-06-20.4 - Ron Koch 2008-06-26 18:39:59.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.536 [GMT -7:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\FunWebProducts
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Users\Ron Koch\AppData\Roaming\SpyGuarder
C:\Users\Ron Koch\AppData\Roaming\SpyGuarder\base.dat
C:\Users\Ron Koch\AppData\Roaming\SpyGuarder\base2.dat
C:\Users\Ron Koch\AppData\Roaming\SpyGuarder\Desc.dat
C:\Users\Ron Koch\AppData\Roaming\SpyGuarder\spline.dat
C:\Windows\Downloaded Program Files\setup.inf
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-05-27 to 2008-06-27 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 01:19 ——— d—–w C:\Users\Ron Koch\AppData\Roaming\Spare Backup
2008-06-27 01:19 ——— d—–w C:\Program Files\Lx_cats
2008-06-26 16:42 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-06-26 16:42 ——— d—–w C:\Program Files\Common Files\L&H;
2008-06-26 05:50 7,930 —-a-w C:\Users\Ron Koch\AppData\Roaming\wklnhst.dat
2008-06-26 05:36 ——— d—–w C:\ProgramData\McAfee
2008-06-26 04:24 ——— d—–w C:\Program Files\ThreatFire
2008-06-26 04:22 ——— d—a-w C:\ProgramData\TEMP
2008-06-26 04:08 ——— d—–w C:\ProgramData\SiteAdvisor
2008-06-26 04:07 ——— d—–w C:\Program Files\Alwil Software
2008-06-26 03:51 ——— d—–w C:\Program Files\CCleaner
2008-06-26 03:42 ——— d—–w C:\ProgramData\SUPERAntiSpyware.com
2008-06-26 03:41 ——— d—–w C:\Users\Ron Koch\AppData\Roaming\SUPERAntiSpyware.com
2008-06-26 03:41 ——— d—–w C:\Program Files\SUPERAntiSpyware
2008-06-26 03:40 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-26 01:41 ——— d—–w C:\Users\Ron Koch\AppData\Roaming\Netscape
2008-06-26 01:40 ——— d—–w C:\Program Files\Netscape
2008-06-25 05:30 ——— d—–w C:\ProgramData\Microsoft Help
2008-06-25 04:29 ——— d—–w C:\Program Files\NetZero
2008-06-25 04:28 ——— d—–w C:\ProgramData\NetZero
2008-06-25 03:50 ——— d—–w C:\Program Files\PokerStars
2008-06-25 03:29 ——— d—–w C:\Program Files\Google
2008-06-23 01:20 ——— d—–w C:\Program Files\SpyGuarder
2008-06-12 15:03 ——— d—–w C:\Program Files\Windows Mail
2008-05-15 23:18 50,768 —-a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-05-13 20:34 ——— d—–w C:\Program Files\Full Tilt Poker
2008-05-10 03:30 14,848 —-a-w C:\Windows\System32\wshrm.dll
2008-05-10 01:21 113,664 —-a-w C:\Windows\system32\drivers\rmcast.sys
2008-05-07 06:05 ——— d—–w C:\Program Files\MOV to AVI MPEG WMV Converter
2008-05-05 01:30 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-05-05 01:27 ——— d—–w C:\Program Files\eBay
2008-05-03 05:17 ——— d—–w C:\Users\Ron Koch\AppData\Roaming\Move Networks
2008-04-26 08:02 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2008-04-25 04:23 826,368 —-a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 —-a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2008-04-23 04:27 428,032 —-a-w C:\Windows\System32\EncDec.dll
2008-04-23 04:27 292,352 —-a-w C:\Windows\System32\psisdecd.dll
2008-04-23 04:27 1,244,672 —-a-w C:\Windows\System32\mcmde.dll
2007-10-03 20:20 174 –sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 18:43 4670704]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 05:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 05:36 201728]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 00:51 4435968 C:\Windows\RtHDVCpl.exe]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-09 21:21 240640]
"Spare Backup"="C:\Program Files\Spare Backup\SpareBackup.exe" [2007-07-05 20:38 5252936]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2006-09-06 12:12 323216]
"BigFix"="c:\program files\Bigfix\bigfix.exe" [2006-11-16 16:04 2348584]
"lxctmon.exe"="C:\Program Files\Lexmark 5400 Series\lxctmon.exe" [2006-06-20 06:37 286720]
"Lexmark 5400 Series Fax Server"="C:\Program Files\Lexmark 5400 Series\fm3032.exe" [2006-07-10 16:30 294912]
"EzPrint"="C:\Program Files\Lexmark 5400 Series\ezprint.exe" [2006-06-06 20:05 98304]
"LXCTCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-06-07 05:09 106496]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 06:28 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 06:28 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 06:28 81920]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 12:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 16:19 79224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="C:\Windows\SMINST\launcher.exe" [2007-07-03 17:31 40072]
""="" []
"GrpConv"="grpconv -o" []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-08-09 21:48:43 2348584]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BC85D0F8-42C4-4DA3-9520-7A37C650D5A1}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0B9570AC-E59D-4B59-881D-C396CB027822}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8E27AD47-BBEF-4B24-89C1-ACCEC6108625}"= UDP:C:\Windows\System32\lxctcoms.exe:Lexmark Communications System
"{F67934AF-0D95-4D4F-A964-735FD44E759C}"= TCP:C:\Windows\System32\lxctcoms.exe:Lexmark Communications System
"{5B84CFCF-2871-47F6-B103-B3FCEB55B830}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{7AD87AB7-CF7E-4E4A-9A72-0BAC3EC41E0E}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{0875C7E8-961B-4470-A7FB-4F829DE1E9E5}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{6E8C6AFB-EE4C-429A-A5E8-FD615C46DEA7}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{097526AA-4674-4DD5-ABFA-8502267D98E4}"= UDP:C:\Windows\System32\lxbccoms.exe:Lexmark Communications System
"{292D7013-8245-4C6B-AE4A-EB08AC4B07DD}"= TCP:C:\Windows\System32\lxbccoms.exe:Lexmark Communications System
"{016CBAC2-187F-4DA6-8694-B7D1F513253D}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbcpswx.exe:Printer Status Window
"{A11C6663-C2C1-47F5-801B-DBC0865A9229}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbcpswx.exe:Printer Status Window
"TCP Query User{94F92911-B979-4680-93A4-6D2BE30B0765}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{C3F57ABE-6287-4AC0-A1C7-405F929A034A}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{EC24C2BD-24C3-486D-9B82-D42334872331}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{69861FF6-1786-4913-91AE-62A02C60A1D1}C:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:C:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

S1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-15 16:20]
S2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-15 16:16]
S2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-15 16:18]
S2 lxbc_device;lxbc_device;C:\Windows\system32\lxbccoms.exe [2007-03-16 02:24]
S2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service []
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 00:30]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 10:51]
S3 ZG760_XP;ZyXEL 802.11g XG762 1211 Driver;C:\Windows\system32\DRIVERS\WlanGZXP.sys [2006-08-16 19:04]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
rsmsvcs REG_MULTI_SZ ntmssvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\shell\AutoRun\command - L:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22802c1b-c84f-11dc-a397-001bb9a85c48}]
\shell\AutoRun\command - L:\LaunchU3.exe -a

*Newly Created Service* - CATCHME
*Newly Created Service* - ECACHE
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-26 18:46:43
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCTCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-26 18:47:46
ComboFix-quarantined-files.txt 2008-06-27 01:47:21

The system cannot find message text for message number 0x2379 in the message file for Application.
The system cannot find message text for message number 0x2379 in the message file for Application.

160 — E O F — 2008-06-26 02:10:50





Here is the log from the Kaspersky scan:


Kaspersky Online Scanner 7 Your computer is infected
Information
Update
Scan
Critical Areas
My Computer
Folder…
File…

Scan Report
Support
Help
SettingsUpdateNew viruses and other threats appear frequently.
Updating the database keeps your scans up-to-date. Database information

Database publishedFriday, July 11, 2008 21:34:09

Records in database943267

Downloading and installing the program(100%)

Update size:1 KB
Transferred size:1 KB
The program components have been downloaded and installed, and the program
has started.
Updating the database(100%)


Update size:26434 KB
Transferred size:26434 KB
Last start:11/07/2008 15:30:23
Status:complete
Program is starting. Please wait…
Update source selected: http://www.kaspersky.com
Downloading file: packages/kos-bin-winnt-redist.jar
Downloading file: packages/kos-bin-winnt-engine.jar
Downloading file: packages/kos-bin-winnt.jar
Downloading file: packages/kos-extras.jar
Program has started.

Program database is being updated. Please wait…
Update source selected: http://downloads2.kaspersky-labs.com/
Downloading file: index/master.xml.klz
Downloading file: bases/five/avc/kavset.xml.klz
Downloading file: bases/five/patches/soft.xml.klz
Downloading file: bases/five/patches/soft.xml
Downloading file: bases/five/updcfg.xml
Downloading file: bases/five/avc/black.lst
Downloading file: bases/five/avc/kernel.avc
Downloading file: bases/five/avc/krnun001.avc
Downloading file: bases/five/avc/krnun002.avc
Downloading file: bases/five/avc/krnun003.avc
Downloading file: bases/five/avc/krnun004.avc
Downloading file: bases/five/avc/krnexe.avc
Downloading file: bases/five/avc/krnmacro.avc
Downloading file: bases/five/avc/krnjava.avc
Downloading file: bases/five/avc/krndos.avc
Downloading file: bases/five/avc/krngen.avc
Downloading file: bases/five/avc/krnexe32.avc
Downloading file: bases/five/avc/krnengn.avc
Downloading file: bases/five/avc/krn001.avc
Downloading file: bases/five/avc/krn002.avc
Downloading file: bases/five/avc/krn003.avc
Downloading file: bases/five/avc/krn004.avc
Downloading file: bases/five/avc/krn005.avc
Downloading file: bases/five/avc/smart.avc
Downloading file: bases/five/avc/ocr.avc
Downloading file: bases/five/avc/chuka.avc
Downloading file: bases/five/avc/fa001.avc
Downloading file: bases/five/avc/base001c.avc
Downloading file: bases/five/avc/base002c.avc
Downloading file: bases/five/avc/base003c.avc
Downloading file: bases/five/avc/base004c.avc
Downloading file: bases/five/avc/base005c.avc
Downloading file: bases/five/avc/base006c.avc
Downloading file: bases/five/avc/base007c.avc
Downloading file: bases/five/avc/base008c.avc
Downloading file: bases/five/avc/base009c.avc
Downloading file: bases/five/avc/base010c.avc
Downloading file: bases/five/avc/base011c.avc
Downloading file: bases/five/avc/base012c.avc
Downloading file: bases/five/avc/base013c.avc
Downloading file: bases/five/avc/base014c.avc
Downloading file: bases/five/avc/base015c.avc
Downloading file: bases/five/avc/base016c.avc
Downloading file: bases/five/avc/base017c.avc
Downloading file: bases/five/avc/base018c.avc
Downloading file: bases/five/avc/base019c.avc
Downloading file: bases/five/avc/base020c.avc
Downloading file: bases/five/avc/base021c.avc
Downloading file: bases/five/avc/base022c.avc
Downloading file: bases/five/avc/base023c.avc
Downloading file: bases/five/avc/base024c.avc
Downloading file: bases/five/avc/base025c.avc
Downloading file: bases/five/avc/base026c.avc
Downloading file: bases/five/avc/base027c.avc
Downloading file: bases/five/avc/base028c.avc
Downloading file: bases/five/avc/base029c.avc
Downloading file: bases/five/avc/base030c.avc
Downloading file: bases/five/avc/base031c.avc
Downloading file: bases/five/avc/base032c.avc
Downloading file: bases/five/avc/base033c.avc
Downloading file: bases/five/avc/base034c.avc
Downloading file: bases/five/avc/base035c.avc
Downloading file: bases/five/avc/base036c.avc
Downloading file: bases/five/avc/base037c.avc
Downloading file: bases/five/avc/base038c.avc
Downloading file: bases/five/avc/base039c.avc
Downloading file: bases/five/avc/base040c.avc
Downloading file: bases/five/avc/base041c.avc
Downloading file: bases/five/avc/base042c.avc
Downloading file: bases/five/avc/base043c.avc
Downloading file: bases/five/avc/base044c.avc
Downloading file: bases/five/avc/base045c.avc
Downloading file: bases/five/avc/base046c.avc
Downloading file: bases/five/avc/base047c.avc
Downloading file: bases/five/avc/base048c.avc
Downloading file: bases/five/avc/base049c.avc
Downloading file: bases/five/avc/base050c.avc
Downloading file: bases/five/avc/base051c.avc
Downloading file: bases/five/avc/base052c.avc
Downloading file: bases/five/avc/base053c.avc
Downloading file: bases/five/avc/base054c.avc
Downloading file: bases/five/avc/base055c.avc
Downloading file: bases/five/avc/base056c.avc
Downloading file: bases/five/avc/base057c.avc
Downloading file: bases/five/avc/base058c.avc
Downloading file: bases/five/avc/base059c.avc
Downloading file: bases/five/avc/base060c.avc
Downloading file: bases/five/avc/base061c.avc
Downloading file: bases/five/avc/base062c.avc
Downloading file: bases/five/avc/base063c.avc
Downloading file: bases/five/avc/base064c.avc
Downloading file: bases/five/avc/base065c.avc
Downloading file: bases/five/avc/base066c.avc
Downloading file: bases/five/avc/base067c.avc
Downloading file: bases/five/avc/base068c.avc
Downloading file: bases/five/avc/base069c.avc
Downloading file: bases/five/avc/base070c.avc
Downloading file: bases/five/avc/base071c.avc
Downloading file: bases/five/avc/base072c.avc
Downloading file: bases/five/avc/base073c.avc
Downloading file: bases/five/avc/base074c.avc
Downloading file: bases/five/avc/base075c.avc
Downloading file: bases/five/avc/base076c.avc
Downloading file: bases/five/avc/base077c.avc
Downloading file: bases/five/avc/base078c.avc
Downloading file: bases/five/avc/base079c.avc
Downloading file: bases/five/avc/base080c.avc
Downloading file: bases/five/avc/base081c.avc
Downloading file: bases/five/avc/base082c.avc
Downloading file: bases/five/avc/base083c.avc
Downloading file: bases/five/avc/base084c.avc
Downloading file: bases/five/avc/base085c.avc
Downloading file: bases/five/avc/base086c.avc
Downloading file: bases/five/avc/base087c.avc
Downloading file: bases/five/avc/base088c.avc
Downloading file: bases/five/avc/base089c.avc
Downloading file: bases/five/avc/base090c.avc
Downloading file: bases/five/avc/base091c.avc
Downloading file: bases/five/avc/base092c.avc
Downloading file: bases/five/avc/base093c.avc
Downloading file: bases/five/avc/base094c.avc
Downloading file: bases/five/avc/base095c.avc
Downloading file: bases/five/avc/base096c.avc
Downloading file: bases/five/avc/base097c.avc
Downloading file: bases/five/avc/base098c.avc
Downloading file: bases/five/avc/base099c.avc
Downloading file: bases/five/avc/base100c.avc
Downloading file: bases/five/avc/base101c.avc
Downloading file: bases/five/avc/base102c.avc
Downloading file: bases/five/avc/base103c.avc
Downloading file: bases/five/avc/base104c.avc
Downloading file: bases/five/avc/base105c.avc
Downloading file: bases/five/avc/base106c.avc
Downloading file: bases/five/avc/base107c.avc
Downloading file: bases/five/avc/base108c.avc
Downloading file: bases/five/avc/base109c.avc
Downloading file: bases/five/avc/base110c.avc
Downloading file: bases/five/avc/base111c.avc
Downloading file: bases/five/avc/base112c.avc
Downloading file: bases/five/avc/base113c.avc
Downloading file: bases/five/avc/base114c.avc
Downloading file: bases/five/avc/base115c.avc
Downloading file: bases/five/avc/base116c.avc
Downloading file: bases/five/avc/base117c.avc
Downloading file: bases/five/avc/base118c.avc
Downloading file: bases/five/avc/base119c.avc
Downloading file: bases/five/avc/base120c.avc
Downloading file: bases/five/avc/base121c.avc
Downloading file: bases/five/avc/base122c.avc
Downloading file: bases/five/avc/base123c.avc
Downloading file: bases/five/avc/base124c.avc
Downloading file: bases/five/avc/base125c.avc
Downloading file: bases/five/avc/base126c.avc
Downloading file: bases/five/avc/base127c.avc
Downloading file: bases/five/avc/base128c.avc
Downloading file: bases/five/avc/base129c.avc
Downloading file: bases/five/avc/base130c.avc
Downloading file: bases/five/avc/base131c.avc
Downloading file: bases/five/avc/base132c.avc
Downloading file: bases/five/avc/base133c.avc
Downloading file: bases/five/avc/base134c.avc
Downloading file: bases/five/avc/base135c.avc
Downloading file: bases/five/avc/base136c.avc
Downloading file: bases/five/avc/base137c.avc
Downloading file: bases/five/avc/base138c.avc
Downloading file: bases/five/avc/base139c.avc
Downloading file: bases/five/avc/base140c.avc
Downloading file: bases/five/avc/base141c.avc
Downloading file: bases/five/avc/base142c.avc
Downloading file: bases/five/avc/base143c.avc
Downloading file: bases/five/avc/base144c.avc
Downloading file: bases/five/avc/base145c.avc
Downloading file: bases/five/avc/base146c.avc
Downloading file: bases/five/avc/base147c.avc
Downloading file: bases/five/avc/base148c.avc
Downloading file: bases/five/avc/base149c.avc
Downloading file: bases/five/avc/base150c.avc
Downloading file: bases/five/avc/base151c.avc
Downloading file: bases/five/avc/base152c.avc
Downloading file: bases/five/avc/base153c.avc
Downloading file: bases/five/avc/base154c.avc
Downloading file: bases/five/avc/base155c.avc
Downloading file: bases/five/avc/base156c.avc
Downloading file: bases/five/avc/base157c.avc
Downloading file: bases/five/avc/base158c.avc
Downloading file: bases/five/avc/base159c.avc
Downloading file: bases/five/avc/base160c.avc
Downloading file: bases/five/avc/base161c.avc
Downloading file: bases/five/avc/base162c.avc
Downloading file: bases/five/avc/base163c.avc
Downloading file: bases/five/avc/base164c.avc
Downloading file: bases/five/avc/base165c.avc
Downloading file: bases/five/avc/base166c.avc
Downloading file: bases/five/avc/base167c.avc
Downloading file: bases/five/avc/base168c.avc
Downloading file: bases/five/avc/base169c.avc
Downloading file: bases/five/avc/base170c.avc
Downloading file: bases/five/avc/base171c.avc
Downloading file: bases/five/avc/base172c.avc
Downloading file: bases/five/avc/base173c.avc
Downloading file: bases/five/avc/base174c.avc
Downloading file: bases/five/avc/base175c.avc
Downloading file: bases/five/avc/base176c.avc
Downloading file: bases/five/avc/base177c.avc
Downloading file: bases/five/avc/base178c.avc
Downloading file: bases/five/avc/base179c.avc
Downloading file: bases/five/avc/base180c.avc
Downloading file: bases/five/avc/base181c.avc
Downloading file: bases/five/avc/base182c.avc
Downloading file: bases/five/avc/base183c.avc
Downloading file: bases/five/avc/base184c.avc
Downloading file: bases/five/avc/base185c.avc
Downloading file: bases/five/avc/base186c.avc
Downloading file: bases/five/avc/base187c.avc
Downloading file: bases/five/avc/base188c.avc
Downloading file: bases/five/avc/base189c.avc
Downloading file: bases/five/avc/base190c.avc
Downloading file: bases/five/avc/base191c.avc
Downloading file: bases/five/avc/base192c.avc
Downloading file: bases/five/avc/base193c.avc
Downloading file: bases/five/avc/base194c.avc
Downloading file: bases/five/avc/base195c.avc
Downloading file: bases/five/avc/base196c.avc
Downloading file: bases/five/avc/base197c.avc
Downloading file: bases/five/avc/base198c.avc
Downloading file: bases/five/avc/base199c.avc
Downloading file: bases/five/avc/base200c.avc
Downloading file: bases/five/avc/base201c.avc
Downloading file: bases/five/avc/base202c.avc
Downloading file: bases/five/avc/base203c.avc
Downloading file: bases/five/avc/base204c.avc
Downloading file: bases/five/avc/base205c.avc
Downloading file: bases/five/avc/base206c.avc
Downloading file: bases/five/avc/base207c.avc
Downloading file: bases/five/avc/base208c.avc
Downloading file: bases/five/avc/base209c.avc
Downloading file: bases/five/avc/base210c.avc
Downloading file: bases/five/avc/base211c.avc
Downloading file: bases/five/avc/base212c.avc
Downloading file: bases/five/avc/base213c.avc
Downloading file: bases/five/avc/base214c.avc
Downloading file: bases/five/avc/base215c.avc
Downloading file: bases/five/avc/base216c.avc
Downloading file: bases/five/avc/base217c.avc
Downloading file: bases/five/avc/base218c.avc
Downloading file: bases/five/avc/base219c.avc
Downloading file: bases/five/avc/base220c.avc
Downloading file: bases/five/avc/base221c.avc
Downloading file: bases/five/avc/base222c.avc
Downloading file: bases/five/avc/base223c.avc
Downloading file: bases/five/avc/base224c.avc
Downloading file: bases/five/avc/base225c.avc
Downloading file: bases/five/avc/base226c.avc
Downloading file: bases/five/avc/base227c.avc
Downloading file: bases/five/avc/base228c.avc
Downloading file: bases/five/avc/base229c.avc
Downloading file: bases/five/avc/base230c.avc
Downloading file: bases/five/avc/base231c.avc
Downloading file: bases/five/avc/base232c.avc
Downloading file: bases/five/avc/base233c.avc
Downloading file: bases/five/avc/base234c.avc
Downloading file: bases/five/avc/base235c.avc
Downloading file: bases/five/avc/base236c.avc
Downloading file: bases/five/avc/base237c.avc
Downloading file: bases/five/avc/base238c.avc
Downloading file: bases/five/avc/base239c.avc
Downloading file: bases/five/avc/base240c.avc
Downloading file: bases/five/avc/base241c.avc
Downloading file: bases/five/avc/base242c.avc
Downloading file: bases/five/avc/base243c.avc
Downloading file: bases/five/avc/base244c.avc
Downloading file: bases/five/avc/base245c.avc
Downloading file: bases/five/avc/base246c.avc
Downloading file: bases/five/avc/base247c.avc
Downloading file: bases/five/avc/base248c.avc
Downloading file: bases/five/avc/base249c.avc
Downloading file: bases/five/avc/base250c.avc
Downloading file: bases/five/avc/base251c.avc
Downloading file: bases/five/avc/base252c.avc
Downloading file: bases/five/avc/base253c.avc
Downloading file: bases/five/avc/base254c.avc
Downloading file: bases/five/avc/base255c.avc
Downloading file: bases/five/avc/base256c.avc
Downloading file: bases/five/avc/base257c.avc
Downloading file: bases/five/avc/base258c.avc
Downloading file: bases/five/avc/dailyc.avc
Downloading file: bases/five/avc/ext001c.avc
Downloading file: bases/five/avc/ext002c.avc
Downloading file: bases/five/avc/ext003c.avc
Downloading file: bases/five/avc/ext004c.avc
Downloading file: bases/five/avc/ext005c.avc
Downloading file: bases/five/avc/ext006c.avc
Downloading file: bases/five/avc/ext007c.avc
Downloading file: bases/five/avc/ext008c.avc
Downloading file: bases/five/avc/ext009c.avc
Downloading file: bases/five/avc/ext010c.avc
Downloading file: bases/five/avc/ext011c.avc
Downloading file: bases/five/avc/ext012c.avc
Downloading file: bases/five/avc/ext013c.avc
Downloading file: bases/five/avc/ext014c.avc
Downloading file: bases/five/avc/ext015c.avc
Downloading file: bases/five/avc/ext016c.avc
Downloading file: bases/five/avc/ext017c.avc
Downloading file: bases/five/avc/ext018c.avc
Downloading file: bases/five/avc/ext019c.avc
Downloading file: bases/five/avc/ext020c.avc
Downloading file: bases/five/avc/ext021c.avc
Downloading file: bases/five/avc/ext022c.avc
Downloading file: bases/five/avc/ext023c.avc
Downloading file: bases/five/avc/ext024c.avc
Downloading file: bases/five/avc/ext025c.avc
Downloading file: bases/five/avc/ext026c.avc
Downloading file: bases/five/avc/ext027c.avc
Downloading file: bases/five/avc/ext028c.avc
Downloading file: bases/five/avc/ext029c.avc
Downloading file: bases/five/avc/ext030c.avc
Downloading file: bases/five/avc/ext031c.avc
Downloading file: bases/five/avc/ext032c.avc
Downloading file: bases/five/avc/ext033c.avc
Downloading file: bases/five/avc/ext034c.avc
Downloading file: bases/five/avc/ext035c.avc
Downloading file: bases/five/avc/ext036c.avc
Downloading file: bases/five/avc/ext037c.avc
Downloading file: bases/five/avc/ext038c.avc
Downloading file: bases/five/avc/ext039c.avc
Downloading file: bases/five/avc/ext040c.avc
Downloading file: bases/five/avc/ext041c.avc
Downloading file: bases/five/avc/ext042c.avc
Downloading file: bases/five/avc/daily-ec.avc
Downloading file: bases/five/avc/base001.avc
Downloading file: bases/five/avc/base002.avc
Downloading file: bases/five/avc/base003.avc
Downloading file: bases/five/avc/base004.avc
Downloading file: bases/five/avc/base005.avc
Downloading file: bases/five/avc/base006.avc
Downloading file: bases/five/avc/base007.avc
Downloading file: bases/five/avc/base008.avc
Downloading file: bases/five/avc/base009.avc
Downloading file: bases/five/avc/base010.avc
Downloading file: bases/five/avc/base011.avc
Downloading file: bases/five/avc/base012.avc
Downloading file: bases/five/avc/base013.avc
Downloading file: bases/five/avc/base014.avc
Downloading file: bases/five/avc/base015.avc
Downloading file: bases/five/avc/base016.avc
Downloading file: bases/five/avc/base017.avc
Downloading file: bases/five/avc/base018.avc
Downloading file: bases/five/avc/base019.avc
Downloading file: bases/five/avc/base020.avc
Downloading file: bases/five/avc/base021.avc
Downloading file: bases/five/avc/base022.avc
Downloading file: bases/five/avc/base023.avc
Downloading file: bases/five/avc/base024.avc
Downloading file: bases/five/avc/base025.avc
Downloading file: bases/five/avc/base026.avc
Downloading file: bases/five/avc/base027.avc
Downloading file: bases/five/avc/base028.avc
Downloading file: bases/five/avc/base029.avc
Downloading file: bases/five/avc/base030.avc
Downloading file: bases/five/avc/base031.avc
Downloading file: bases/five/avc/base032.avc
Downloading file: bases/five/avc/base033.avc
Downloading file: bases/five/avc/base034.avc
Downloading file: bases/five/avc/base035.avc
Downloading file: bases/five/avc/base036.avc
Downloading file: bases/five/avc/base037.avc
Downloading file: bases/five/avc/base038.avc
Downloading file: bases/five/avc/base039.avc
Downloading file: bases/five/avc/base040.avc
Downloading file: bases/five/avc/base041.avc
Downloading file: bases/five/avc/base042.avc
Downloading file: bases/five/avc/base043.avc
Downloading file: bases/five/avc/base044.avc
Downloading file: bases/five/avc/base045.avc
Downloading file: bases/five/avc/base046.avc
Downloading file: bases/five/avc/base047.avc
Downloading file: bases/five/avc/base048.avc
Downloading file: bases/five/avc/base049.avc
Downloading file: bases/five/avc/base050.avc
Downloading file: bases/five/avc/base051.avc
Downloading file: bases/five/avc/base052.avc
Downloading file: bases/five/avc/base053.avc
Downloading file: bases/five/avc/base054.avc
Downloading file: bases/five/avc/base055.avc
Downloading file: bases/five/avc/base056.avc
Downloading file: bases/five/avc/base057.avc
Downloading file: bases/five/avc/base058.avc
Downloading file: bases/five/avc/base059.avc
Downloading file: bases/five/avc/base060.avc
Downloading file: bases/five/avc/base061.avc
Downloading file: bases/five/avc/base062.avc
Downloading file: bases/five/avc/base063.avc
Downloading file: bases/five/avc/base064.avc
Downloading file: bases/five/avc/base065.avc
Downloading file: bases/five/avc/base066.avc
Downloading file: bases/five/avc/base067.avc
Downloading file: bases/five/avc/base068.avc
Downloading file: bases/five/avc/base069.avc
Downloading file: bases/five/avc/base070.avc
Downloading file: bases/five/avc/base071.avc
Downloading file: bases/five/avc/base072.avc
Downloading file: bases/five/avc/base073.avc
Downloading file: bases/five/avc/base074.avc
Downloading file: bases/five/avc/base075.avc
Downloading file: bases/five/avc/base076.avc
Downloading file: bases/five/avc/base077.avc
Downloading file: bases/five/avc/base078.avc
Downloading file: bases/five/avc/base079.avc
Downloading file: bases/five/avc/base080.avc
Downloading file: bases/five/avc/base081.avc
Downloading file: bases/five/avc/base082.avc
Downloading file: bases/five/avc/base083.avc
Downloading file: bases/five/avc/base084.avc
Downloading file: bases/five/avc/base085.avc
Downloading file: bases/five/avc/base086.avc
Downloading file: bases/five/avc/base087.avc
Downloading file: bases/five/avc/base088.avc
Downloading file: bases/five/avc/base089.avc
Downloading file: bases/five/avc/base090.avc
Downloading file: bases/five/avc/base091.avc
Downloading file: bases/five/avc/base092.avc
Downloading file: bases/five/avc/base093.avc
Downloading file: bases/five/avc/base094.avc
Downloading file: bases/five/avc/base095.avc
Downloading file: bases/five/avc/base096.avc
Downloading file: bases/five/avc/base097.avc
Downloading file: bases/five/avc/base098.avc
Downloading file: bases/five/avc/base099.avc
Downloading file: bases/five/avc/base100.avc
Downloading file: bases/five/avc/base101.avc
Downloading file: bases/five/avc/base102.avc
Downloading file: bases/five/avc/base103.avc
Downloading file: bases/five/avc/base104.avc
Downloading file: bases/five/avc/base105.avc
Downloading file: bases/five/avc/base106.avc
Downloading file: bases/five/avc/base107.avc
Downloading file: bases/five/avc/base108.avc
Downloading file: bases/five/avc/base109.avc
Downloading file: bases/five/avc/base110.avc
Downloading file: bases/five/avc/base111.avc
Downloading file: bases/five/avc/base112.avc
Downloading file: bases/five/avc/base113.avc
Downloading file: bases/five/avc/base114.avc
Downloading file: bases/five/avc/base115.avc
Downloading file: bases/five/avc/base116.avc
Downloading file: bases/five/avc/base117.avc
Downloading file: bases/five/avc/base118.avc
Downloading file: bases/five/avc/base119.avc
Downloading file: bases/five/avc/base120.avc
Downloading file: bases/five/avc/base121.avc
Downloading file: bases/five/avc/base122.avc
Downloading file: bases/five/avc/base123.avc
Downloading file: bases/five/avc/base124.avc
Downloading file: bases/five/avc/base125.avc
Downloading file: bases/five/avc/base126.avc
Downloading file: bases/five/avc/base127.avc
Downloading file: bases/five/avc/base128.avc
Downloading file: bases/five/avc/base129.avc
Downloading file: bases/five/avc/base130.avc
Downloading file: bases/five/avc/base131.avc
Downloading file: bases/five/avc/base132.avc
Downloading file: bases/five/avc/base133.avc
Downloading file: bases/five/avc/base134.avc
Downloading file: bases/five/avc/base135.avc
Downloading file: bases/five/avc/base136.avc
Downloading file: bases/five/avc/base137.avc
Downloading file: bases/five/avc/base138.avc
Downloading file: bases/five/avc/base139.avc
Downloading file: bases/five/avc/base140.avc
Downloading file: bases/five/avc/base141.avc
Downloading file: bases/five/avc/base142.avc
Downloading file: bases/five/avc/base143.avc
Downloading file: bases/five/avc/base144.avc
Downloading file: bases/five/avc/base145.avc
Downloading file: bases/five/avc/base146.avc
Downloading file: bases/five/avc/base147.avc
Downloading file: bases/five/avc/base148.avc
Downloading file: bases/five/avc/base149.avc
Downloading file: bases/five/avc/base150.avc
Downloading file: bases/five/avc/base151.avc
Downloading file: bases/five/avc/base152.avc
Downloading file: bases/five/avc/base153.avc
Downloading file: bases/five/avc/base154.avc
Downloading file: bases/five/avc/base155.avc
Downloading file: bases/five/avc/base156.avc
Downloading file: bases/five/avc/base157.avc
Downloading file: bases/five/avc/base158.avc
Downloading file: bases/five/avc/base159.avc
Downloading file: bases/five/avc/base160.avc
Downloading file: bases/five/avc/base161.avc
Downloading file: bases/five/avc/base162.avc
Downloading file: bases/five/avc/base163.avc
Downloading file: bases/five/avc/base164.avc
Downloading file: bases/five/avc/base999.avc
Downloading file: bases/five/avc/unp000.avc
Downloading file: bases/five/avc/unp001.avc
Downloading file: bases/five/avc/unp002.avc
Downloading file: bases/five/avc/unp003.avc
Downloading file: bases/five/avc/unp004.avc
Downloading file: bases/five/avc/unp005.avc
Downloading file: bases/five/avc/unp006.avc
Downloading file: bases/five/avc/unp007.avc
Downloading file: bases/five/avc/unp008.avc
Downloading file: bases/five/avc/unp009.avc
Downloading file: bases/five/avc/unp010.avc
Downloading file: bases/five/avc/unp011.avc
Downloading file: bases/five/avc/unp012.avc
Downloading file: bases/five/avc/unp013.avc
Downloading file: bases/five/avc/unp014.avc
Downloading file: bases/five/avc/unp015.avc
Downloading file: bases/five/avc/unp016.avc
Downloading file: bases/five/avc/unp017.avc
Downloading file: bases/five/avc/unp018.avc
Downloading file: bases/five/avc/unp019.avc
Downloading file: bases/five/avc/unp020.avc
Downloading file: bases/five/avc/unp021.avc
Downloading file: bases/five/avc/unp022.avc
Downloading file: bases/five/avc/unp023.avc
Downloading file: bases/five/avc/unp024.avc
Downloading file: bases/five/avc/unp025.avc
Downloading file: bases/five/avc/unp026.avc
Downloading file: bases/five/avc/unp027.avc
Downloading file: bases/five/avc/unp028.avc
Downloading file: bases/five/avc/unp029.avc
Downloading file: bases/five/avc/unp030.avc
Downloading file: bases/five/avc/unp031.avc
Downloading file: bases/five/avc/unp032.avc
Downloading file: bases/five/avc/unp033.avc
Downloading file: bases/five/avc/unp034.avc
Downloading file: bases/five/avc/unp035.avc
Downloading file: bases/five/avc/unp036.avc
Downloading file: bases/five/avc/unp037.avc
Downloading file: bases/five/avc/unp038.avc
Downloading file: bases/five/avc/unp039.avc
Downloading file: bases/five/avc/unp040.avc
Downloading file: bases/five/avc/unp041.avc
Downloading file: bases/five/avc/daily.avc
Downloading file: bases/five/avc/daily-ex.avc
Downloading file: bases/five/avc/urgent.avc
Downloading file: bases/five/avc/mail.avc
Downloading file: bases/five/avc/ext001.avc
Downloading file: bases/five/avc/ext002.avc
Downloading file: bases/five/avc/ext003.avc
Downloading file: bases/five/avc/ext004.avc
Downloading file: bases/five/avc/ext005.avc
Downloading file: bases/five/avc/ext006.avc
Downloading file: bases/five/avc/ext007.avc
Downloading file: bases/five/avc/ext008.avc
Downloading file: bases/five/avc/ext009.avc
Downloading file: bases/five/avc/ext999.avc
Downloading file: bases/five/avc/gen001.avc
Downloading file: bases/five/avc/gen002.avc
Downloading file: bases/five/avc/gen003.avc
Downloading file: bases/five/avc/gen004.avc
Downloading file: bases/five/avc/gen005.avc
Downloading file: bases/five/avc/gen999.avc
Downloading file: bases/five/avc/ca001.avc
Downloading file: bases/five/avc/ca002.avc
Downloading file: bases/five/avc/ca003.avc
Downloading file: bases/five/avc/fa.avc
Downloading file: bases/five/avc/eicar.avc
Downloading file: bases/five/avc/verdicts.ini
Downloading file: bases/five/avc/engine.dt
Downloading file: bases/five/avc/engine.cfg
Downloading file: bases/five/avc/avcmhk5.mhk
Downloading file: bases/five/avc/avp.set
Downloading file: bases/five/avc/avp_ext.set
Downloading file: bases/five/avc/avp_x.set
Downloading file: bases/five/avc/avp.vnd
Downloading file: bases/five/avc/avp.klb
Downloading file: bases/five/patches/soft.ver
Database is updated. Ready to scan.Scan My ComputerScan statistics

Files scanned139651

Threat names1

Infected objects3

Suspicious objects0

Duration of the scan02:10:52
Start scan
Scan is running (44%)

Click the area that you want to scan in left part of the window. The scan
will start automatically as soon as you select a scan area.

Last start:7/11/2008 15:32:14
Status:complete
Please wait, the scan may take a long time depending on the size of the
selected scan area. You can continue browsing in a new Web browser window.

Now scanning:
Location:
Settings | View scan report | Stop scan
Attention: Kaspersky Online Scanner 7.0 may not run successfully while any other
antivirus program is running. If you have another antivirus program installed,
please turn it off before running Kaspersky Online Scanner 7.0. Scan ReportThe
scan report displays information about threats detected
on your computer. - Infected object - Suspicious object
InformationWelcome to Kaspersky Online Scanner 7.0! Use the program to check
your computer for viruses and other malware for free.
Benefits:

Kaspersky Lab exceptional detection rates and thorough scan
Hourly database updates available
Heuristic analysis to detect unknown malware
One-click installation


Requirements and limitations:

In Microsoft Windows Vista, you must open the Web browser using the Run as
Administrator command.
To begin using the program, you need to download and install the program files
and the database of malware definitions. (The size of the program files
depends on your operating system.) Later, Kaspersky Online Scanner 7.0 checks
for the program and database updates every time you open or update the program
window and, if available, downloads and installs them automatically.
In Linux, Kaspersky Online Scanner 7.0 does not scan RAM, boot sectors and
MBRs, so it cannot detect malicious programs located in these areas.
In Microsoft Windows Vista, if the language you use has a character set and
fonts different from English, make sure that the language selected for your
default system locale and the language to display dates, times, currency, and
measurements (Current format) are the same as the language you use.
Kaspersky Online Scanner 7.0 only detects malicious code that have already
penetrated into your computer, so that you can delete them manually. It
neither protects your computer against malicious code, nor prevents future
infections. We recommend that you install a full-featured antivirus solution
to protect your computer.
SupportIf you have questions, comments, or suggestions related to
Kaspersky Online Scanner 7.0, please contact us. About Kaspersky Online Scanner
7.0

Version7.0.25.0

Database publishedFriday, July 11, 2008 21:34:09

Operating systemMicrosoft Windows Vista Home Premium Edition, 32-bit
(build 6000)

User Forum
Go to the Kaspersky Lab Forum.
Malware information
Find news and information about viruses and other threats at
Viruslist.com.
View information
Warning

Kaspersky Online Scanner 7.0 is already running in another window.
SettingsDetect malicious programs of the following categories:
Viruses, Worms, Trojan Horses, Rootkits
Spyware, Adware, Dialers, and other potentially dangerous programs

Scan compound files (doesn't apply to the File scan area):
Archives
Mail databases
Hi

I'm afraid you didn't quite complete the steps I provided for the Kaspersky scan.

Please run it again, but take careful note of each of these:

  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

You must wait until the scan is finished. The Save Report As… button will be available once the scan is complete, and you can find it after clicking View Scan Report (these buttons are on the webpage, not in the browser).

Thanks.
Sorry about the mistakes. Here is the Kaspersky scan text: ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Tuesday, July 15, 2008 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Tuesday, July 15, 2008 19:30:26 Records in database: 957023 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ Scan statistics: Files scanned: 140147 Threat name: 1 Infected objects: 3 Suspicious objects: 0 Duration of the scan: 01:45:00 File name / Threat name / Threats count C:\Program Files\eMachines Games\Diner Dash\Diner Dash.exe Infected: Trojan.Win32.Patched.cj 1 D:\i386\Apps\App001374\wtsetup.exe Infected: Trojan.Win32.Patched.cj 2 The selected area was scanned.
Hi

Please Right Click your Start button, and click Explore.
Next, locate and delete the following file (if present):

File:
D:\i386\Apps\App001374\wtsetup.exe <

If you have a problem deleting it then please let me know.


We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\Program Files\eMachines Games\Diner Dash\Diner Dash.exe

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.


How is the computer running at the moment, any problems?

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI