This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] rundll

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having bother accessisng the internet. after some research i believe it is because of a rundll32.exe file that starts on start up. i have deativated it on msconfig but it just activates itself. when i stop it in task manager it just starts again. plz help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:48:36, on 17/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P50 "Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP" /O21 "\\JENSLAPTOP\EPSONSty" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX620 Series on DAVIDS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P46 "Auto EPSON Stylus Photo RX620 Series on DAVIDS" /O16 "\\DAVIDS\Printer" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [BM0bd97de8] Rundll32.exe "C:\WINDOWS\system32\frgknaod.dll",s
O4 - HKLM\..\Run: [08ea4e74] rundll32.exe "C:\WINDOWS\system32\crhykgtl.dll",b
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O20 - AppInit_DLLs: hlqgzh.dll xmfjcq.dll mygzms.dll

–
End of file - 4277 bytes
:welcome:

It's not actually the rundll32 that's the problem, it's what is being injected into it. You have a nasty Vundo infection. Let's start with combofix.

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
COMBO FIX LOG:

ComboFix 08-09-16.05 - Administrator 2008-09-19 14:14:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.716 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Cookies\[removed][1].txt
C:\WINDOWS\BM0bd97de8.txt
C:\WINDOWS\BM0bd97de8.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aaowqujw.dll
C:\WINDOWS\system32\aggadrhs.ini
C:\WINDOWS\system32\cjuhymne.ini
C:\WINDOWS\system32\ebeedccdf6_d.dll
C:\WINDOWS\system32\ebgduaxj.dll
C:\WINDOWS\system32\enmyhujc.dll
C:\WINDOWS\system32\etujolsq.dll
C:\WINDOWS\system32\euqhvjia.dll
C:\WINDOWS\system32\frgknaod.dll
C:\WINDOWS\system32\hkaawcnq.dll
C:\WINDOWS\system32\kbeoordc.ini
C:\WINDOWS\system32\lsernpfr.ini
C:\WINDOWS\system32\ltgkyhrc.ini
C:\WINDOWS\system32\lVwFLkkj.ini
C:\WINDOWS\system32\lVwFLkkj.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nljwhgjr.dll
C:\WINDOWS\system32\olsmodye.ini
C:\WINDOWS\system32\onmblqkj.dll
C:\WINDOWS\system32\oseyiclp.dll
C:\WINDOWS\system32\pulnlxkq.ini
C:\WINDOWS\system32\qncwaakh.ini
C:\WINDOWS\system32\rpfapu.dll
C:\WINDOWS\system32\shrdagga.dll
C:\WINDOWS\system32\thivwtqc.dll
C:\WINDOWS\system32\tliqxabs.dll
C:\WINDOWS\system32\vpvxce.dll
C:\WINDOWS\system32\xxyvvTmN.dll
C:\WINDOWS\system32\ygdemnwf.ini
C:\WINDOWS\system32\ynkqyf.dll

.
((((((((((((((((((((((((( Files Created from 2008-08-19 to 2008-09-19 )))))))))))))))))))))))))))))))
.

2008-09-18 00:11 . 2004-08-04 13:00 605,696 –a—— C:\WINDOWS\system32\dllcache\getuname.dll
2008-09-18 00:11 . 2004-08-04 13:00 343,040 –a—— C:\WINDOWS\system32\dllcache\mspaint.exe
2008-09-18 00:11 . 2004-08-04 13:00 214,528 –a—— C:\WINDOWS\system32\dllcache\wordpad.exe
2008-09-18 00:11 . 2004-08-04 13:00 114,688 –a—— C:\WINDOWS\system32\dllcache\calc.exe
2008-09-18 00:11 . 2004-08-04 13:00 102,912 –a—— C:\WINDOWS\system32\dllcache\clipbrd.exe
2008-09-18 00:11 . 2004-08-04 13:00 80,384 –a—— C:\WINDOWS\system32\dllcache\charmap.exe
2008-09-18 00:11 . 2004-08-04 13:00 5,632 –a—— C:\WINDOWS\system32\dllcache\write.exe
2008-09-17 23:53 . 2008-09-17 23:59 96,976 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-09-17 23:53 . 2008-09-17 23:59 87,855 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-09-17 23:52 . 2008-09-19 14:17 2,195,232 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-17 23:52 . 2008-09-19 14:17 40,992 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-17 23:52 . 2008-09-19 14:17 8,564 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-17 23:52 . 2008-09-19 14:17 2,516 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-17 23:46 . 2008-09-17 23:46 d——– C:\Program Files\Trend Micro
2008-09-17 23:32 . 2008-09-17 23:32 d——– C:\Program Files\DAEMON Tools Toolbar
2008-09-17 23:32 . 2008-09-17 23:32 d——– C:\Program Files\DAEMON Tools Lite
2008-09-17 23:27 . 2008-09-17 23:27 113,152 –a—— C:\WINDOWS\system32\qfhwamim.dll
2008-09-17 23:27 . 2008-09-17 23:27 113,152 –a—— C:\WINDOWS\system32\mygzms.dll
2008-09-17 22:00 . 2008-09-17 22:01 d——– C:\$WIN_NT$.~BT
2008-09-17 17:49 . 2004-08-04 13:00 472,007 -ra—— C:\txtsetup.sif
2008-09-17 17:49 . 2004-08-04 13:00 260,272 -ra—— C:\$LDR$
2008-09-17 17:09 . 2008-09-17 17:09 d——– C:\My Documents
2008-09-17 14:54 . 2008-09-17 14:54 d——– C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-09-17 12:42 . 2008-09-17 12:42 113,152 –a—— C:\WINDOWS\system32\xmfjcq.dll
2008-09-17 12:42 . 2008-09-17 12:42 113,152 –a—— C:\WINDOWS\system32\mnllpisv.dll
2008-09-17 12:24 . 2008-09-17 12:24 113,152 –a—— C:\WINDOWS\system32\onuvlvpg.dll
2008-09-17 12:24 . 2008-09-17 12:24 113,152 –a—— C:\WINDOWS\system32\hlqgzh.dll
2008-09-16 20:01 . 2008-09-16 20:01 d——– C:\Program Files\BillP Studios
2008-09-16 20:01 . 2008-09-16 20:01 d——– C:\Documents and Settings\Administrator\Application Data\WinPatrol
2008-09-16 12:16 . 2008-09-16 12:16 113,152 –a—— C:\WINDOWS\system32\vouzoc.dll
2008-09-16 12:16 . 2008-09-16 12:16 113,152 –a—— C:\WINDOWS\system32\viqbbvce.dll
2008-09-16 12:00 . 2008-09-16 12:01 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-14 12:19 . 2008-09-14 12:19 111,616 –a—— C:\WINDOWS\system32\wzzqif.dll
2008-09-14 12:19 . 2008-09-14 12:19 111,616 –a—— C:\WINDOWS\system32\ourgidvg.dll
2008-09-13 20:23 . 2008-09-13 20:23 d——– C:\Documents and Settings\Administrator\Application Data\MSNInstaller
2008-09-12 12:11 . 2008-09-19 14:13 112,640 –a—— C:\WINDOWS\system32\jdmhoj.dll
2008-09-12 12:11 . 2008-09-19 14:13 112,640 –a—— C:\WINDOWS\system32\arkmrhxq.dll
2008-09-11 03:05 . 2008-09-18 00:14 4,566 –a—— C:\WINDOWS\imsins.BAK
2008-09-09 17:33 . 2008-09-10 23:19 d——– C:\Program Files\Zylom Games
2008-09-09 17:33 . 2008-09-09 17:33 d——– C:\Documents and Settings\All Users\Application Data\Zylom
2008-09-08 17:37 . 2008-09-08 17:37 319 –a—— C:\WINDOWS\game.ini
2008-09-08 17:15 . 2008-09-08 17:15 d–hs—- C:\WINDOWS\ftpcache
2008-09-06 21:48 . 2008-09-06 21:48 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-06 20:41 . 2008-09-10 23:20 d——– C:\Program Files\Yahoo!
2008-09-06 20:41 . 2008-09-06 20:41 23 –a—— C:\WINDOWS\system32\dfadddac9_d.ocx
2008-09-05 20:10 . 2008-09-06 21:50 d——– C:\Program Files\Kaspersky Lab
2008-09-05 20:10 . 2008-09-19 14:09 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-05 19:47 . 2008-09-05 19:47 d——– C:\Program Files\Microsoft ActiveSync
2008-09-05 19:47 . 2005-10-21 02:47 30,592 ——— C:\WINDOWS\system32\drivers\rndismpx.sys
2008-09-05 19:47 . 2005-10-21 02:47 12,800 ——— C:\WINDOWS\system32\drivers\usb8023x.sys
2008-09-05 19:05 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-09-05 19:05 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-09-05 18:55 . 2006-11-06 18:04 28,672 –a—— C:\WINDOWS\system32\drivers\wceusbsh.sys
2008-09-05 18:55 . 2006-11-06 18:04 28,672 –a—— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-09-05 11:51 . 2008-09-05 11:54 8,260 –a—— C:\WINDOWS\system32\EPPICResdb0001
2008-09-05 11:49 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-05 11:49 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-05 11:30 . 2008-09-05 11:30 d——– C:\EPSON
2008-09-04 12:27 . 2008-09-06 13:52 d——– C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-09-01 18:34 . 2008-09-01 18:34 d——– C:\Program Files\ProtectDisc Driver Installer
2008-09-01 14:42 . 2008-09-01 14:42 d——– C:\Program Files\Trymedia
2008-09-01 14:42 . 2008-09-01 14:42 d——– C:\Documents and Settings\All Users\Application Data\Ludia
2008-08-31 23:44 . 2008-08-31 23:44 d——– C:\WINDOWS\95FC26FB19FD4A96BBB1B1062E8648F5.TMP
2008-08-29 22:43 . 2008-09-18 19:54 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-27 18:49 . 2008-08-31 11:55 d——– C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-08-27 18:48 . 2008-08-27 18:48 22,328 –a—— C:\Documents and Settings\Administrator\Application Data\PnkBstrK.sys
2008-08-24 11:43 . 2003-03-24 16:52 94,208 –a—— C:\WINDOWS\system32\dllcache\fpencode.dll
2008-08-24 11:43 . 2008-08-24 11:43 376 –a—— C:\WINDOWS\ODBC.INI
2008-08-24 11:42 . 2008-08-24 11:42 d——– C:\WINDOWS\ShellNew
2008-08-24 11:41 . 2008-08-24 11:41 d——– C:\Documents and Settings\Administrator\Application Data\Microsoft Web Folders
2008-08-21 12:30 . 2008-08-21 12:30 dr-h—– C:\Documents and Settings\Administrator\Application Data\SecuROM
2008-08-21 12:05 . 2008-08-31 11:55 d——– C:\Program Files\Ubisoft
2008-08-20 01:17 . 2008-08-20 01:17 d——– C:\Program Files\Common Files\DirectX
2008-08-19 15:06 . 2008-08-20 07:53 d——– C:\Program Files\Crazy Machines II Demo
2008-08-19 15:02 . 2008-08-19 15:02 d——– C:\WINDOWS\EFC1B35CFFF241D8A70ACE6037F8040B.TMP
2008-08-19 15:02 . 2008-08-19 15:02 d——– C:\Program Files\OpenAL
2008-08-19 15:02 . 2008-08-31 20:29 418,480 –a—— C:\WINDOWS\system32\wrap_oal.dll
2008-08-19 15:02 . 2008-08-31 20:29 115,432 –a—— C:\WINDOWS\system32\OpenAL32.dll
2008-08-19 14:17 . 2008-08-19 14:55 d——– C:\Documents and Settings\All Users\Application Data\Firefly Studios
2008-08-19 14:16 . 2008-08-19 15:37 107,888 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2008-08-19 14:15 . 2008-08-19 14:15 d——– C:\WINDOWS\8AFFD400A2D54216A1AC62EC637F73EE.TMP
2008-08-19 14:09 . 2008-08-19 14:09 d——– C:\WINDOWS\system32\AGEIA
2008-08-19 14:09 . 2008-09-17 21:09 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-08-19 14:09 . 2008-08-19 14:09 d——– C:\Program Files\AGEIA Technologies

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 23:05 112,144 —-a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-09-17 22:34 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-17 20:10 ——— d—–w C:\Program Files\Intel
2008-09-17 17:55 ——— d—–w C:\Program Files\Windows Live
2008-09-17 17:16 ——— d—–w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-09-07 00:36 ——— d—–w C:\Program Files\Rockstar Games
2008-09-05 10:34 ——— d—–w C:\Program Files\epson
2008-08-24 10:34 ——— d—–w C:\Program Files\microsoft frontpage
2008-08-21 11:12 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-21 11:11 ——— d—–w C:\Program Files\Google
2008-08-18 21:58 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-08-18 21:56 ——— d—–w C:\Documents and Settings\Administrator\Application Data\SystemRequirementsLab
2008-08-18 10:32 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Sonic
2008-08-15 21:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-08-12 10:38 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Template
2008-08-11 20:57 ——— d—–w C:\Program Files\NOS
2008-08-11 20:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\NOS
2008-08-10 21:28 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-08-10 21:27 ——— d—–w C:\Program Files\QuickTime
2008-08-10 21:27 ——— d—–w C:\Program Files\Apple Software Update
2008-08-10 21:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-10 21:26 ——— d—–w C:\Program Files\Common Files\Apple
2008-08-10 21:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-08 11:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Entriq
2008-08-03 22:04 ——— d—–w C:\Program Files\WinZip Self-Extractor
2008-08-03 22:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZipSE
2008-08-03 21:58 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-08-03 21:57 ——— d—–w C:\Documents and Settings\Administrator\Application Data\DAEMON Tools
2008-08-02 17:50 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-02 17:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-01 16:43 ——— d—–w C:\Program Files\Paradox Interactive
2008-07-31 13:43 ——— d—–w C:\Program Files\Kontiki
2008-07-31 13:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-07-31 13:37 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-07-28 19:52 ——— d—–w C:\Program Files\FirstClass
2008-07-28 19:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\FirstClass
2008-07-28 19:52 ——— d—–w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-27 14:40 ——— d—–w C:\Documents and Settings\Administrator\Application Data\ArcSoft
2008-07-19 12:52 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Smart Panel
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54d0ab77-24ca-4c48-9980-9a34591b6785}]
2008-09-17 23:27 113152 –a—— C:\WINDOWS\system32\mygzms.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo RX620 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]
"Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]
"Auto EPSON Stylus Photo RX620 Series on DAVIDS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-26 218376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ATI CATALYST System Tray.lnk
backup=C:\WINDOWS\pss\ATI CATALYST System Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
backup=C:\WINDOWS\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
–a—— 2008-07-22 20:42 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2005-05-13 00:23 32768 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2005-05-12 21:05 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 08:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
–a—— 2008-08-08 13:11 490952 C:\Program Files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
–a—— 2005-02-25 05:33 127037 C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 13:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a—— 2004-07-27 16:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
–a—— 2000-07-13 21:00 311350 C:\Program Files\Microsoft Works\wkssb.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
–a—— 2000-07-13 21:00 28739 C:\Program Files\Microsoft Works\WkDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2008-05-16 14:01 13529088 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2008-05-16 14:01 86016 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
–a—— 2005-03-07 04:52 276480 C:\Program Files\PDF Complete\pdfsty.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
–a—— 2005-04-08 19:08 73728 C:\Program Files\HPQ\HP ProtectTools Security Manager\pthosttr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
–a—— 2000-07-13 21:00 24576 C:\Program Files\Microsoft Works\wkfud.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
–a—— 2005-01-08 01:07 61952 C:\WINDOWS\system32\HdAShCut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2005-07-13 11:37 14679552 C:\WINDOWS\RTHDCPL.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"pdfcDispatcher"=2 (0x2)
"LightScribeService"=2 (0x2)
"KService"=2 (0x2)
"iPod Service"=3 (0x3)
"hpqwmi"=3 (0x3)
"getPlus® Helper"=3 (0x3)
"ATI Smart"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"NVSvc"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\FirstClass\\fcc32.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Disabled:ActiveSync Service

R2 acedrv11;acedrv11;C:\WINDOWS\system32\drivers\acedrv11.sys [2008-01-23 501560]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 24344]
S4 getPlus® Helper;getPlus® Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-06-26 31592]
S4 pdfcDispatcher;PDF Document Manager;C:\Program Files\PDF Complete\pdfsvc.exe [2005-03-07 476160]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\Setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bea14416-557a-11dd-a6f9-001560a20bd7}]
\Shell\AutoRun\command - G:\qa8sywva.cmd
\Shell\explore\Command - G:\qa8sywva.cmd
\Shell\open\Command - G:\qa8sywva.cmd
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

BHO-{DABB1C43-1596-49C4-9E4D-51AE7A1518BB} - C:\WINDOWS\system32\jkkHaBsT.dll
HKLM-Run-08ea4e74 - C:\WINDOWS\system32\crhykgtl.dll
ShellExecuteHooks-{DABB1C43-1596-49C4-9E4D-51AE7A1518BB} - C:\WINDOWS\system32\jkkHaBsT.dll
Notify-jkkHaBsT - jkkHaBsT.dll
MSConfigStartUp-08ea4e74 - C:\WINDOWS\system32\hkaawcnq.dll
MSConfigStartUp-BM0bd97de8 - C:\WINDOWS\system32\ebgduaxj.dll
MSConfigStartUp-iTunesHelper - C:\Program Files\iTunes\iTunesHelper.exe
MSConfigStartUp-uTorrent - C:\Program Files\uTorrent\uTorrent.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\f55pz7gc.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.co.uk/
FF -: plugin - C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJPI150.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-19 14:18:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="C:\Program Files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-09-19 14:21:04 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-19 13:21:00

Pre-Run: 114,917,072,896 bytes free
Post-Run: 136,623,468,544 bytes free

340 — E O F — 2008-09-18 18:46:04

NEW HIJACKTHIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:24:22, on 19/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: {5876b195-43a9-0899-84c4-ac4277ba0d45} - {54d0ab77-24ca-4c48-9980-9a34591b6785} - C:\WINDOWS\system32\mygzms.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P50 "Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP" /O21 "\\JENSLAPTOP\EPSONSty" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX620 Series on DAVIDS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P46 "Auto EPSON Stylus Photo RX620 Series on DAVIDS" /O16 "\\DAVIDS\Printer" /M "Stylus Photo RX620"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

–
End of file - 4429 bytes
Getting better, as you can see combofix did fix quite a bit. More work to do though…

1. Open Notepad

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\qfhwamim.dll
C:\WINDOWS\system32\mygzms.dll
C:\WINDOWS\system32\xmfjcq.dll
C:\WINDOWS\system32\mnllpisv.dll
C:\WINDOWS\system32\onuvlvpg.dll
C:\WINDOWS\system32\hlqgzh.dll
C:\WINDOWS\system32\vouzoc.dll
C:\WINDOWS\system32\viqbbvce.dll
C:\WINDOWS\system32\wzzqif.dll
C:\WINDOWS\system32\ourgidvg.dll
C:\WINDOWS\system32\jdmhoj.dll
C:\WINDOWS\system32\arkmrhxq.dll
G:\qa8sywva.cmd

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54d0ab77-24ca-4c48-9980-9a34591b6785}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bea14416-557a-11dd-a6f9-001560a20bd7}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Pc is running so much better.
here is the new combofix log:

ComboFix 08-09-16.05 - Administrator 2008-09-20 18:36:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.757 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\hlqgzh.dll
C:\WINDOWS\system32\mnllpisv.dll
C:\WINDOWS\system32\mygzms.dll
C:\WINDOWS\system32\onuvlvpg.dll
C:\WINDOWS\system32\ourgidvg.dll
C:\WINDOWS\system32\qfhwamim.dll
C:\WINDOWS\system32\viqbbvce.dll
C:\WINDOWS\system32\vouzoc.dll
C:\WINDOWS\system32\wzzqif.dll
C:\WINDOWS\system32\xmfjcq.dll

.
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.

2008-09-18 00:11 . 2004-08-04 13:00 605,696 –a—— C:\WINDOWS\system32\dllcache\getuname.dll
2008-09-18 00:11 . 2004-08-04 13:00 343,040 –a—— C:\WINDOWS\system32\dllcache\mspaint.exe
2008-09-18 00:11 . 2004-08-04 13:00 214,528 –a—— C:\WINDOWS\system32\dllcache\wordpad.exe
2008-09-18 00:11 . 2004-08-04 13:00 114,688 –a—— C:\WINDOWS\system32\dllcache\calc.exe
2008-09-18 00:11 . 2004-08-04 13:00 102,912 –a—— C:\WINDOWS\system32\dllcache\clipbrd.exe
2008-09-18 00:11 . 2004-08-04 13:00 80,384 –a—— C:\WINDOWS\system32\dllcache\charmap.exe
2008-09-18 00:11 . 2004-08-04 13:00 5,632 –a—— C:\WINDOWS\system32\dllcache\write.exe
2008-09-17 23:53 . 2008-09-17 23:59 96,976 –a—— C:\WINDOWS\system32\drivers\klin.dat
2008-09-17 23:53 . 2008-09-17 23:59 87,855 –a—— C:\WINDOWS\system32\drivers\klick.dat
2008-09-17 23:52 . 2008-09-20 18:33 2,195,232 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-17 23:52 . 2008-09-20 18:33 40,992 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-17 23:52 . 2008-09-20 18:33 10,868 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-17 23:52 . 2008-09-20 18:33 3,044 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-17 23:46 . 2008-09-17 23:46 d——– C:\Program Files\Trend Micro
2008-09-17 23:32 . 2008-09-17 23:32 d——– C:\Program Files\DAEMON Tools Toolbar
2008-09-17 23:32 . 2008-09-17 23:32 d——– C:\Program Files\DAEMON Tools Lite
2008-09-17 22:00 . 2008-09-17 22:01 d——– C:\$WIN_NT$.~BT
2008-09-17 17:49 . 2004-08-04 13:00 472,007 -ra—— C:\txtsetup.sif
2008-09-17 17:49 . 2004-08-04 13:00 260,272 -ra—— C:\$LDR$
2008-09-17 17:09 . 2008-09-17 17:09 d——– C:\My Documents
2008-09-17 14:54 . 2008-09-17 14:54 d——– C:\Documents and Settings\Administrator\Application Data\Leadertech
2008-09-16 20:01 . 2008-09-16 20:01 d——– C:\Program Files\BillP Studios
2008-09-16 20:01 . 2008-09-16 20:01 d——– C:\Documents and Settings\Administrator\Application Data\WinPatrol
2008-09-16 12:00 . 2008-09-16 12:01 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-13 20:23 . 2008-09-13 20:23 d——– C:\Documents and Settings\Administrator\Application Data\MSNInstaller
2008-09-11 03:05 . 2008-09-18 00:14 4,566 –a—— C:\WINDOWS\imsins.BAK
2008-09-09 17:33 . 2008-09-10 23:19 d——– C:\Program Files\Zylom Games
2008-09-09 17:33 . 2008-09-09 17:33 d——– C:\Documents and Settings\All Users\Application Data\Zylom
2008-09-08 17:37 . 2008-09-08 17:37 319 –a—— C:\WINDOWS\game.ini
2008-09-08 17:15 . 2008-09-08 17:15 d–hs—- C:\WINDOWS\ftpcache
2008-09-06 21:48 . 2008-09-06 21:48 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-06 20:41 . 2008-09-10 23:20 d——– C:\Program Files\Yahoo!
2008-09-06 20:41 . 2008-09-06 20:41 23 –a—— C:\WINDOWS\system32\dfadddac9_d.ocx
2008-09-05 20:10 . 2008-09-06 21:50 d——– C:\Program Files\Kaspersky Lab
2008-09-05 20:10 . 2008-09-20 18:35 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-05 19:47 . 2008-09-05 19:47 d——– C:\Program Files\Microsoft ActiveSync
2008-09-05 19:47 . 2005-10-21 02:47 30,592 ——— C:\WINDOWS\system32\drivers\rndismpx.sys
2008-09-05 19:47 . 2005-10-21 02:47 12,800 ——— C:\WINDOWS\system32\drivers\usb8023x.sys
2008-09-05 19:05 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2008-09-05 19:05 . 2004-08-03 22:58 14,848 –a—— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-09-05 18:55 . 2006-11-06 18:04 28,672 –a—— C:\WINDOWS\system32\drivers\wceusbsh.sys
2008-09-05 18:55 . 2006-11-06 18:04 28,672 –a—— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-09-05 11:51 . 2008-09-05 11:54 8,260 –a—— C:\WINDOWS\system32\EPPICResdb0001
2008-09-05 11:49 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-05 11:49 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-05 11:30 . 2008-09-05 11:30 d——– C:\EPSON
2008-09-04 12:27 . 2008-09-06 13:52 d——– C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-09-01 18:34 . 2008-09-01 18:34 d——– C:\Program Files\ProtectDisc Driver Installer
2008-09-01 14:42 . 2008-09-01 14:42 d——– C:\Program Files\Trymedia
2008-09-01 14:42 . 2008-09-01 14:42 d——– C:\Documents and Settings\All Users\Application Data\Ludia
2008-08-31 23:44 . 2008-08-31 23:44 d——– C:\WINDOWS\95FC26FB19FD4A96BBB1B1062E8648F5.TMP
2008-08-29 22:43 . 2008-09-18 19:54 d——– C:\WINDOWS\system32\CatRoot_bak
2008-08-27 18:49 . 2008-08-31 11:55 d——– C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-08-27 18:48 . 2008-08-27 18:48 22,328 –a—— C:\Documents and Settings\Administrator\Application Data\PnkBstrK.sys
2008-08-24 11:43 . 2003-03-24 16:52 94,208 –a—— C:\WINDOWS\system32\dllcache\fpencode.dll
2008-08-24 11:43 . 2008-08-24 11:43 376 –a—— C:\WINDOWS\ODBC.INI
2008-08-24 11:42 . 2008-08-24 11:42 d——– C:\WINDOWS\ShellNew
2008-08-24 11:41 . 2008-08-24 11:41 d——– C:\Documents and Settings\Administrator\Application Data\Microsoft Web Folders
2008-08-21 12:30 . 2008-08-21 12:30 dr-h—– C:\Documents and Settings\Administrator\Application Data\SecuROM
2008-08-21 12:05 . 2008-08-31 11:55 d——– C:\Program Files\Ubisoft
2008-08-20 01:17 . 2008-08-20 01:17 d——– C:\Program Files\Common Files\DirectX

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 23:05 112,144 —-a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-09-17 22:34 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-17 20:10 ——— d—–w C:\Program Files\Intel
2008-09-17 20:09 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-17 17:55 ——— d—–w C:\Program Files\Windows Live
2008-09-17 17:16 ——— d—–w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-09-07 00:36 ——— d—–w C:\Program Files\Rockstar Games
2008-09-05 10:34 ——— d—–w C:\Program Files\epson
2008-08-31 19:29 418,480 —-a-w C:\WINDOWS\system32\wrap_oal.dll
2008-08-31 19:29 115,432 —-a-w C:\WINDOWS\system32\OpenAL32.dll
2008-08-24 10:34 ——— d—–w C:\Program Files\microsoft frontpage
2008-08-21 11:12 ——— d—–w C:\Program Files\Windows Live Toolbar
2008-08-21 11:11 ——— d—–w C:\Program Files\Google
2008-08-20 06:53 ——— d—–w C:\Program Files\Crazy Machines II Demo
2008-08-19 14:37 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-08-19 14:02 ——— d—–w C:\Program Files\OpenAL
2008-08-19 13:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Firefly Studios
2008-08-19 13:09 ——— d—–w C:\Program Files\AGEIA Technologies
2008-08-18 21:58 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-08-18 21:56 ——— d—–w C:\Documents and Settings\Administrator\Application Data\SystemRequirementsLab
2008-08-18 10:32 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Sonic
2008-08-15 21:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-08-12 10:38 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Template
2008-08-11 20:57 ——— d—–w C:\Program Files\NOS
2008-08-11 20:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\NOS
2008-08-10 21:28 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-08-10 21:27 ——— d—–w C:\Program Files\QuickTime
2008-08-10 21:27 ——— d—–w C:\Program Files\Apple Software Update
2008-08-10 21:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-10 21:26 ——— d—–w C:\Program Files\Common Files\Apple
2008-08-10 21:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-08 11:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Entriq
2008-08-03 22:04 ——— d—–w C:\Program Files\WinZip Self-Extractor
2008-08-03 22:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZipSE
2008-08-03 21:58 717,296 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-08-03 21:57 ——— d—–w C:\Documents and Settings\Administrator\Application Data\DAEMON Tools
2008-08-02 17:50 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-02 17:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-01 16:43 ——— d—–w C:\Program Files\Paradox Interactive
2008-07-31 13:43 ——— d—–w C:\Program Files\Kontiki
2008-07-31 13:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-07-31 13:37 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-07-28 19:52 ——— d—–w C:\Program Files\FirstClass
2008-07-28 19:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\FirstClass
2008-07-28 19:52 ——— d—–w C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-07-27 14:40 ——— d—–w C:\Documents and Settings\Administrator\Application Data\ArcSoft
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 21:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 205,000 —-a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 21:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 21:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 09:45 70,936 —-a-w C:\WINDOWS\system32\PhysXLoader.dll
2008-07-17 10:32 4,608 —-a-w C:\WINDOWS\system32\w95inf32.dll
2008-07-17 10:32 2,272 —-a-w C:\WINDOWS\system32\w95inf16.dll
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ——w C:\WINDOWS\system32\dllcache\es.dll
2008-07-04 06:33 3,230,720 —-a-w C:\WINDOWS\system32\dllcache\ati2mtag.sys
2008-07-04 03:48 9,490,432 —-a-w C:\WINDOWS\system32\atioglx2.dll
2008-07-04 03:25 421,888 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-07-04 03:23 309,248 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2008-07-04 03:14 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-07-04 03:14 184,320 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2008-07-04 03:14 143,360 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2008-07-04 03:13 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2008-07-04 03:13 139,264 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2008-07-04 03:12 561,152 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2008-07-04 03:10 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-07-04 03:06 253,952 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2008-07-04 03:00 3,786,144 —-a-w C:\WINDOWS\system32\ati3duag.dll
2008-07-04 02:55 307,200 —-a-w C:\WINDOWS\system32\atiiiexx.dll
2008-07-04 02:49 2,140,672 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2008-07-04 02:34 48,640 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2008-07-04 02:30 348,160 —-a-w C:\WINDOWS\system32\atikvmag.dll
2008-07-04 02:29 32,768 —-a-w C:\WINDOWS\system32\atiadlxx.dll
2008-07-04 02:28 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2008-07-04 02:25 5,439,488 —-a-w C:\WINDOWS\system32\atioglxx.dll
2008-07-04 02:22 565,248 —-a-w C:\WINDOWS\system32\ati2cqag.dll
2008-07-03 20:05 593,920 ——w C:\WINDOWS\system32\ati2sgag.exe
2008-06-24 17:12 295,936 ——w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 ——w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 09:57 3,592,192 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:20 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:20 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:36 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:36 245,248 ——w C:\WINDOWS\system32\dllcache\mswsock.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo RX620 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]
"Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]
"Auto EPSON Stylus Photo RX620 Series on DAVIDS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE" [2004-05-19 98304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ATI CATALYST System Tray.lnk
backup=C:\WINDOWS\pss\ATI CATALYST System Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
backup=C:\WINDOWS\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
–a—— 2008-07-22 20:42 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2005-05-13 00:23 32768 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
–a—— 2005-05-12 21:05 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2004-08-04 08:56 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
–a—— 2008-08-08 13:11 490952 C:\Program Files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
–a—— 2005-02-25 05:33 127037 C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
–a—— 2006-11-13 13:39 1289000 C:\Program Files\Microsoft ActiveSync\wcescomm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a—— 2004-07-27 16:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
–a—— 2000-07-13 21:00 311350 C:\Program Files\Microsoft Works\wkssb.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
–a—— 2000-07-13 21:00 28739 C:\Program Files\Microsoft Works\WkDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2008-05-16 14:01 13529088 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2008-05-16 14:01 86016 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF Complete]
–a—— 2005-03-07 04:52 276480 C:\Program Files\PDF Complete\pdfsty.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTHOSTTR]
–a—— 2005-04-08 19:08 73728 C:\Program Files\HPQ\HP ProtectTools Security Manager\pthosttr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
–a—— 2000-07-13 21:00 24576 C:\Program Files\Microsoft Works\wkfud.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
–a—— 2005-01-08 01:07 61952 C:\WINDOWS\system32\HdAShCut.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2005-07-13 11:37 14679552 C:\WINDOWS\RTHDCPL.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"pdfcDispatcher"=2 (0x2)
"LightScribeService"=2 (0x2)
"KService"=2 (0x2)
"iPod Service"=3 (0x3)
"hpqwmi"=3 (0x3)
"getPlus® Helper"=3 (0x3)
"ATI Smart"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"NVSvc"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\FirstClass\\fcc32.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Disabled:ActiveSync Service

R2 acedrv11;acedrv11;C:\WINDOWS\system32\drivers\acedrv11.sys [2008-01-23 501560]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 24344]
S4 getPlus® Helper;getPlus® Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-06-26 31592]
S4 pdfcDispatcher;PDF Document Manager;C:\Program Files\PDF Complete\pdfsvc.exe [2005-03-07 476160]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\Setup.exe
.
Contents of the 'Scheduled Tasks' folder
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-20 18:38:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="C:\Program Files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
Completion time: 2008-09-20 18:39:41
ComboFix-quarantined-files.txt 2008-09-20 17:39:38
ComboFix2.txt 2008-09-19 13:21:05

Pre-Run: 136,614,727,680 bytes free
Post-Run: 136,599,179,264 bytes free

316 — E O F — 2008-09-18 18:46:04
First, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Also post a new HJT log and let me know how it's running.
Malwarebytes' Anti-Malware 1.28
Database version: 1182
Windows 5.1.2600 Service Pack 2

20/09/2008 20:17:31
mbam-log-2008-09-20 (20-17-31).txt

Scan type: Quick Scan
Objects scanned: 41323
Time elapsed: 3 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\sin (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolie.bho (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f1eeddd-13c7-4ad3-821c-b116295d08d2} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9ef67fcc-5b6c-474c-9e6c-1307ec42dfe6} (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

HIJACKTHIS


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:23:53, on 20/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P50 "Auto EPSON Stylus Photo RX620 Series on JENSLAPTOP" /O21 "\\JENSLAPTOP\EPSONSty" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX620 Series on DAVIDS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P46 "Auto EPSON Stylus Photo RX620 Series on DAVIDS" /O16 "\\DAVIDS\Printer" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

–
End of file - 4403 bytes
I assume everything is all set here, let me know if not. Just some final cleanup and words of wisdom.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~

In addition to updating and using what you currently have you may want to consider the following:

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. Here are some free and evalutation versions that provide
better security than the Windows Firewall. Comodo
Outpost Firewall
For a tutorial on Firewalls and a listing of some other available ones see the link below:
Understanding and Using Firewalls

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install SpywareGuard - SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.
A tutorial on installing & using this product can be found here:
Using SpywareGuard to protect your computer from Spyware and Malware

Use Zoned Out -
Zoned Out will block access to malicious websites so you cannot be redirected to them from an infected site or email. Instructions for set up and use can be found at the website.

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

I'll leave the thread open a few days in case you have questions or issues.

Regards,
Dave
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI