This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected by Trojan Virtumonde and maybe other problems

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I hope I am doing this right. Just going off the instructions from the Topic "New Member, How To Get Help". Let me know if I need to post this somewhere else in case its wrong. But about a week ago when I did a Spyware Doctor scan it detected something called Trojan Virtumonde and when I ask it to fix it, it seemed like it did but when I keep running the scan its always there. I looked it up and I guess it goes after older versions of Java, and I had version 5 something, which seemed to be one of the versions affected, so I deleted that and reinstalled the lastest version of Java last night and did scans again, but the same things. Now my internet is super slow and I get popups coming up and random lag. My Windows Secruity Center seems to have shut itself off as well and I cant turn it back on (not sure if it was like that already or not, but I dont think so). I read some of the one on one help on this website for the same thing, so I hope you guys can help.

For any assistance I recieve it would be nice to know if when you want me to scan anything or do anything to the computer if I should be in Safe Mode or normal start up. Just so I am doing everything correctly to fix this problem. Thank you and thank you for any future assistance I will be recieving.


Logfile of HijackThis v1.99.1
Scan saved at 8:25:53 PM, on 9/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\System32\alg.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\system32\RUNDLL32.EXE
H:\PROGRA~1\SPYWAR~1\swdoctor.exe
H:\WINDOWS\system32\ctfmon.exe
H:\Program Files\NETGEAR\WG111v2\WG111v2.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\explorer.exe
H:\WINDOWS\system32\rundll32.exe
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/forums.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "H:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BM9fe4da89] Rundll32.exe "H:\WINDOWS\system32\slshvewf.dll",s
O4 - HKLM\..\Run: [000000af] rundll32.exe "H:\WINDOWS\system32\maqcqpud.dll",b
O4 - HKCU\..\Run: [Spyware Doctor] H:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - H:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - AppInit_DLLs: cjxjzy.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Program Files\Java\jre6\bin\jqs.exe" -service -config "H:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - H:\WINDOWS\system32\PnkBstrA.exe
Hi baggin3,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

For any assistance I recieve it would be nice to know if when you want me to scan anything or do anything to the computer if I should be in Safe Mode or normal start up.

Always normal mode unless specifically directed to use safe mode.

You aren't running Anti Virus Software

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network.
Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software (for personal use), from one these excellent vendors NOW:

1) Antivir PersonalEditionClassic
-Free anti-virus software for Windows.
-Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition
-Anti-virus program for Windows.
-The home edition is freeware for noncommercial user
3) AVG Anti-Virus Free Edition
- Free edition of the AVG anti-virus program for Windows.
- Available for single computer use for home and non commercial use.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

If you chose AVAST
Right click on the avast! icon in system tray (looks like this: [external image: Posted Image]) and choose (Stop On-Access Protection)

If you chose AVG
Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I will let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.

If you chose AVIRA ANTIVIR
Please navigate to the system tray on the bottom right hand corner and look for an open white umbrella on red background (looks to this: [external image: Posted Image] )
  • right click it-> untick the option AntiVir Guard enable.
  • You should now see a closed, white umbrella on a red background (looks to this: [external image: Posted Image] )
You succesfully disabled the AntiVir Guard.

SPYWARE DOCTOR
  • Click the Spyware Doctor icon in the System Tray.
  • Click Settings.
  • Click Startup Settings under Pick a Category.
  • Uncheck "Run at Windows startup".
  • Click Apply and Exit Spyware Doctor.
  • From within Spyware Doctor, click the "OnGuard" button on the left side.
  • Uncheck "Activate OnGuard".
  • (When we are done, you can reenable Spyware Doctor)

C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here are the ComboFix and Hijack this logs.

I downloaded Antivir, but I was just curious since I thought I had Symantec Antivirus Client. I know I didnt use it that often, I used Spyware Doctor more for regular scans, but I did use it this last week for this problem, and it detected stuff and said it fixed it, but like Spyware Doctor it came back. I will end up using Antivir from now on, so I doubt it even matters but was just curious why Symantec didnt detect, if it even matters. Maybe I should just remove Symantec? Let me know any thoughts you might have.

Also, should I be scanning with my antivirus and/or Spyware Doctor? If so, just let me know when. I wont assume anything, I will just follow whatever instructions you give me. Thank you.


ComboFix 08-09-26.06 - Sean 2008-09-27 10:21:20.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.211 [GMT -7:00]
Running from: H:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

H:\DOCUME~1\Sean\LOCALS~1\Temp\tmp2.tmp
H:\WINDOWS\BM9fe4da89.txt
H:\WINDOWS\BM9fe4da89.xml
H:\WINDOWS\Fonts\-
H:\WINDOWS\Fonts\acrsecB.fon
H:\WINDOWS\Fonts\acrsecI.fon
H:\WINDOWS\pskt.ini
H:\WINDOWS\system32\MSINET.oca

.
((((((((((((((((((((((((( Files Created from 2008-08-27 to 2008-09-27 )))))))))))))))))))))))))))))))
.

2008-09-27 10:10 . 2008-09-27 10:10 d——– H:\Program Files\Avira
2008-09-27 10:10 . 2008-09-27 10:10 d——– H:\Documents and Settings\All Users\Application Data\Avira
2008-09-26 20:20 . 2008-09-26 20:20 d——– H:\Program Files\ERUNT
2008-09-26 20:11 . 2008-09-26 20:11 988,531 –ahs—- H:\WINDOWS\system32\dupqcqam.ini
2008-09-26 20:11 . 2008-09-26 20:11 73,216 –a—— H:\WINDOWS\system32\maqcqpud.dll
2008-09-26 20:09 . 2008-09-26 20:09 115,200 –a—— H:\WINDOWS\system32\hdvwlegb.dll
2008-09-26 20:09 . 2008-09-26 20:09 115,200 –a—— H:\WINDOWS\system32\cjxjzy.dll
2008-09-26 20:07 . 2008-09-26 20:07 105,984 –a—— H:\WINDOWS\system32\slshvewf.dll
2008-09-25 20:53 . 2008-09-25 20:52 410,976 –a—— H:\WINDOWS\system32\deploytk.dll
2008-09-25 20:53 . 2008-09-25 20:52 73,728 –a—— H:\WINDOWS\system32\javacpl.cpl
2008-09-25 20:01 . 2008-09-26 20:11 988,531 –ahs—- H:\WINDOWS\system32\uxmosndk.ini
2008-09-25 20:01 . 2008-09-25 20:01 115,200 –a—— H:\WINDOWS\system32\zzuazh.dll
2008-09-25 20:01 . 2008-09-25 20:01 115,200 –a—— H:\WINDOWS\system32\jlxyqvdb.dll
2008-09-25 19:58 . 2008-09-25 19:58 105,472 –a—— H:\WINDOWS\system32\tsovvqlf.dll
2008-09-24 20:22 . 2008-09-25 20:57 d——– H:\WINDOWS\BDOSCAN8
2008-09-24 20:08 . 2008-09-24 20:08 d——– H:\VundoFix Backups
2008-09-24 19:59 . 2008-09-24 20:00 914,829 –ahs—- H:\WINDOWS\system32\qjfqwovw.ini
2008-09-24 19:59 . 2008-09-24 19:59 84,992 –a—— H:\WINDOWS\system32\wvowqfjq.dll
2008-09-24 19:56 . 2008-09-24 19:56 115,200 –a—— H:\WINDOWS\system32\fessvr.dll
2008-09-24 19:56 . 2008-09-24 19:56 115,200 –a—— H:\WINDOWS\system32\dngxkfkf.dll
2008-09-24 19:56 . 2008-09-24 19:56 105,472 –a—— H:\WINDOWS\system32\vcpmarkj.dll
2008-09-24 18:59 . 2008-09-24 18:59 115,200 –a—— H:\WINDOWS\system32\jgpcdfvs.dll
2008-09-24 18:59 . 2008-09-24 18:59 115,200 –a—— H:\WINDOWS\system32\dqhpmi.dll
2008-09-23 18:07 . 2008-09-23 18:07 115,200 –a—— H:\WINDOWS\system32\itntwwos.dll
2008-09-23 18:07 . 2008-09-23 18:07 115,200 –a—— H:\WINDOWS\system32\ccryzu.dll
2008-09-23 18:04 . 2008-09-24 19:24 898,333 –ahs—- H:\WINDOWS\system32\xoyredqh.ini
2008-09-23 18:04 . 2008-09-23 18:04 96,256 –a—— H:\WINDOWS\system32\hdwqdtqm.dll
2008-09-23 18:04 . 2008-09-23 18:04 85,504 –a—— H:\WINDOWS\system32\hqderyox.dll
2008-09-23 16:57 . 2008-09-23 16:57 d——– H:\Documents and Settings\Administrator\Application Data\PC Tools
2008-09-23 16:55 . 2008-09-23 21:58 d——– H:\Documents and Settings\Administrator
2008-09-22 17:02 . 2008-09-22 17:03 879,273 –ahs—- H:\WINDOWS\system32\sqedqumh.ini
2008-09-22 17:02 . 2008-09-22 17:02 85,504 –a—— H:\WINDOWS\system32\hmuqdeqs.dll
2008-09-22 16:59 . 2008-09-22 16:59 115,200 –a—— H:\WINDOWS\system32\huwuysxc.dll
2008-09-22 16:59 . 2008-09-22 16:59 115,200 –a—— H:\WINDOWS\system32\aeiwuv.dll
2008-09-22 16:57 . 2008-09-22 16:57 95,232 –a—— H:\WINDOWS\system32\tmwkxuma.dll
2008-09-18 21:47 . 2008-09-18 21:47 115,200 –a—— H:\WINDOWS\system32\jwsqta.dll
2008-09-18 21:47 . 2008-09-18 21:47 115,200 –a—— H:\WINDOWS\system32\fykltryw.dll
2008-09-18 21:44 . 2008-09-22 16:58 1,059,857 –ahs—- H:\WINDOWS\system32\OoUFgfii.ini
2008-09-18 21:44 . 2008-09-18 21:44 221,184 –a—— H:\WINDOWS\system32\ibapmyid.dll
2008-09-18 21:44 . 2008-09-18 21:44 108,544 –a—— H:\WINDOWS\system32\geBqNeFX.dll
2008-09-18 21:41 . 2008-09-18 21:41 95,744 –a—— H:\WINDOWS\system32\jeraqmkd.dll
2008-09-18 17:44 . 2008-09-18 21:44 1,001,024 –ahs—- H:\WINDOWS\system32\FMTAKRqr.ini
2008-09-18 17:44 . 2008-09-18 17:44 221,184 –a—— H:\WINDOWS\system32\vmhdprty.dll
2008-09-18 17:44 . 2008-09-18 17:44 115,200 –a—— H:\WINDOWS\system32\xwjlse.dll
2008-09-18 17:44 . 2008-09-18 17:44 115,200 –a—— H:\WINDOWS\system32\vaqaiweh.dll
2008-09-18 17:44 . 2008-09-18 17:44 108,544 –a—— H:\WINDOWS\system32\wvUnLFVM.dll
2008-09-18 17:43 . 2008-09-18 17:43 284,672 –a—— H:\WINDOWS\system32\fccyaAQk.dll
2008-09-18 17:43 . 2008-09-27 10:21 1,166 –ahs—- H:\WINDOWS\system32\kQAayccf.ini2
2008-09-18 17:43 . 2008-09-27 10:21 1,166 –ahs—- H:\WINDOWS\system32\kQAayccf.ini
2008-09-18 17:41 . 2008-09-18 17:41 147,456 –a—— H:\WINDOWS\system32\vbzip10.dll
2008-09-18 17:38 . 2008-09-18 22:53 d——– H:\WINDOWS\system32\mC02
2008-09-06 22:49 . 2008-09-06 22:49 d——– H:\Program Files\NETGEAR
2008-09-06 22:49 . 2008-09-06 22:49 d——– H:\Documents and Settings\Sean\Application Data\InstallShield
2008-09-06 22:49 . 2005-07-20 04:53 966,765 –a—— H:\WINDOWS\system32\acAuth.dll
2008-09-06 22:49 . 2007-12-25 11:24 344,064 –a—— H:\WINDOWS\system32\SCMLib.dll
2008-09-06 22:49 . 2007-12-26 10:47 272,128 –a—— H:\WINDOWS\system32\drivers\wg111v2.sys
2008-09-06 22:49 . 2005-01-25 14:30 143,360 –a—— H:\WINDOWS\system32\IpLib.dll
2008-09-06 22:32 . 2007-04-27 06:00 1,069,056 –a—— H:\WINDOWS\system32\libeay32.dll
2008-09-06 22:32 . 2007-12-18 15:46 266,240 –a—— H:\WINDOWS\system32\WG1v2lib.dll
2008-09-06 22:32 . 2006-07-27 14:26 36,864 –a—— H:\WINDOWS\system32\RtlGina2.dll
2008-09-06 22:32 . 2008-09-06 22:32 21,035 –a—— H:\WINDOWS\system32\drivers\AegisP.sys
2008-08-31 13:16 . 2008-08-31 13:16 d——– H:\Program Files\Bethesda Softworks

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-27 17:17 ——— d—–w H:\Program Files\Spyware Doctor
2008-09-27 16:46 ——— d—a-w H:\Documents and Settings\All Users\Application Data\TEMP
2008-09-26 03:52 ——— d—–w H:\Program Files\Java
2008-09-26 02:48 ——— d—–w H:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-19 01:09 ——— d—–w H:\Documents and Settings\Sean\Application Data\LimeWire
2008-08-07 04:23 ——— d—–w H:\Program Files\PokerStars.NET
2008-07-28 00:25 ——— d—–w H:\Program Files\DOSBox-0.71
2008-07-27 18:14 ——— d—–w H:\Program Files\Diablo II
2008-07-27 11:24 ——— d—–w H:\Program Files\PokerStars
2008-07-19 05:10 94,920 —-a-w H:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w H:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w H:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w H:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w H:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w H:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w H:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w H:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w H:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w H:\WINDOWS\system32\muweb.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{16B2B71B-AB01-4F02-9BC8-109A36BD118D}]
2008-09-18 17:43 284672 –a—— H:\WINDOWS\system32\fccyaAQk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d0e8020d-9637-48f6-8c61-34d91f3ec89a}]
2008-09-26 20:09 115200 –a—— H:\WINDOWS\system32\cjxjzy.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="H:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="H:\WINDOWS\system32\ctfmon.exe" [2004-10-08 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="H:\WINDOWS\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="H:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 81920]
"TkBellExe"="H:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-13 180269]
"QuickTime Task"="H:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="H:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-25 140696]
"000000af"="H:\WINDOWS\system32\maqcqpud.dll" [2008-09-26 73216]
"avgnt"="H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"BM9fe4da89"="H:\WINDOWS\system32\slshvewf.dll" [2008-09-26 105984]
"nwiz"="nwiz.exe" [2007-12-05 H:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="H:\Program Files\Spyware Doctor\swdoctor.exe" [2006-12-15 2115728]

H:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - H:\Program Files\NETGEAR\WG111v2\WG111v2.exe [2008-09-06 1261568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=cjxjzy.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=H:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=H:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=H:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=H:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
–a—— 2006-03-21 18:30 1191936 H:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 13:54 5674352 H:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-12-05 01:41 8523776 H:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
–a—— 2005-01-18 13:32 532480 H:\Program Files\NVIDIA Corporation\nTune\nTune.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-12-05 01:41 81920 H:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRaidService]
-ra—— 2005-02-25 14:27 83968 H:\WINDOWS\system32\nvraidservice.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 H:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
–a—— 2006-12-15 12:16 2115728 H:\PROGRA~1\SPYWAR~1\swdoctor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2006-07-13 10:53 180269 H:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
–a—— 2003-05-21 01:21 90112 H:\PROGRA~1\SYMANT~1\SYMANT~1\VPTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-12-05 01:41 1626112 H:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2005-02-25 14:26 67584 H:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"SDhelper"=2 (0x2)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"Norton AntiVirus Server"=2 (0x2)
"IDriverT"=3 (0x3)
"DefWatch"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"H:\\Program Files\\Messenger\\msmsgs.exe"=
"H:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"H:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"H:\\Program Files\\MSN Messenger\\livecall.exe"=
"H:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"H:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"H:\\Program Files\\World of Warcraft\\Launcher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader

R2 JavaQuickStarterService;Java Quick Starter;H:\Program Files\Java\jre6\bin\jqs.exe [2008-09-25 152984]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;H:\WINDOWS\system32\DRIVERS\wg111v2.sys [2007-12-26 272128]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\AutoRunMorrowind.exe
\Shell\install\command - G:\Setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4ab9820-05c7-11dd-9991-003018a43a73}]
\Shell\AutoRun\command - I:\setupSNK.exe

*Newly Created Service* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-SunJavaUpdateSched - H:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
MSConfigStartUp-Yahoo! Pager - H:\Program Files\Yahoo!\Messenger\YahooMessenger.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://forums.whatthetech.com/forums.html
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Search Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
O8 -: E&xport to Microsoft Excel - H:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 -: Easy-WebPrint Add To Print List - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 -: Easy-WebPrint High Speed Print - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 -: Easy-WebPrint Preview - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 -: Easy-WebPrint Print - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html

O16 -: Microsoft XML Parser for Java - file://H:\WINDOWS\Java\classes\xmldso.cab
H:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-27 10:26:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: H:\WINDOWS\system32\winlogon.exe
-> H:\WINDOWS\system32\NavLogon.dll
.
———————— Other Running Processes ————————
.
H:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\PnkBstrA.exe
H:\WINDOWS\system32\rundll32.exe
H:\WINDOWS\system32\rundll32.exe
H:\WINDOWS\system32\rundll32.exe
H:\WINDOWS\system32\wscntfy.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe
.
**************************************************************************
.
Completion time: 2008-09-27 10:33:39 - machine was rebooted [Sean]
ComboFix-quarantined-files.txt 2008-09-27 17:33:34

Pre-Run: 13,524,525,056 bytes free
Post-Run: 13,927,641,088 bytes free

253 — E O F — 2008-06-25 04:36:22



Logfile of HijackThis v1.99.1
Scan saved at 10:40:51 AM, on 9/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\PnkBstrA.exe
H:\WINDOWS\System32\alg.exe
H:\WINDOWS\system32\RUNDLL32.EXE
H:\Program Files\Common Files\Real\Update_OB\realsched.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Java\jre6\bin\jusched.exe
H:\WINDOWS\system32\rundll32.exe
H:\WINDOWS\system32\Rundll32.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
H:\Program Files\MSN Messenger\msnmsgr.exe
H:\WINDOWS\system32\ctfmon.exe
H:\WINDOWS\System32\svchost.exe
H:\Program Files\NETGEAR\WG111v2\WG111v2.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\explorer.exe
H:\WINDOWS\system32\notepad.exe
H:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\update\update.exe
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\PROGRA~1\SPYWAR~1\swdoctor.exe
H:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/forums.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {16B2B71B-AB01-4F02-9BC8-109A36BD118D} - H:\WINDOWS\system32\fccyaAQk.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - H:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - H:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: {a98ce3f1-9d43-16c8-6f84-7369d0208e0d} - {d0e8020d-9637-48f6-8c61-34d91f3ec89a} - H:\WINDOWS\system32\cjxjzy.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "H:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [000000af] rundll32.exe "H:\WINDOWS\system32\maqcqpud.dll",b
O4 - HKLM\..\Run: [avgnt] "H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [BM9fe4da89] Rundll32.exe "H:\WINDOWS\system32\slshvewf.dll",s
O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - H:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: cjxjzy.dll
O20 - Winlogon Notify: NavLogon - H:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - H:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - H:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Program Files\Java\jre6\bin\jqs.exe" -service -config "H:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - H:\WINDOWS\system32\PnkBstrA.exe
baggin3,

Disable your protection programs as we did before.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: (no name) - {16B2B71B-AB01-4F02-9BC8-109A36BD118D} - H:\WINDOWS\system32\fccyaAQk.dll (file missing)
      O2 - BHO: {a98ce3f1-9d43-16c8-6f84-7369d0208e0d} - {d0e8020d-9637-48f6-8c61-34d91f3ec89a} - H:\WINDOWS\system32\cjxjzy.dll
      O4 - HKLM\..\Run: [000000af] rundll32.exe "H:\WINDOWS\system32\maqcqpud.dll",b
      O4 - HKLM\..\Run: [BM9fe4da89] Rundll32.exe "H:\WINDOWS\system32\slshvewf.dll",s
      O20 - AppInit_DLLs: cjxjzy.dll
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    H:\WINDOWS\system32\maqcqpud.dll
    H:\WINDOWS\system32\hdvwlegb.dll
    H:\WINDOWS\system32\cjxjzy.dll
    H:\WINDOWS\system32\slshvewf.dll
    H:\WINDOWS\system32\zzuazh.dll
    H:\WINDOWS\system32\jlxyqvdb.dll
    H:\WINDOWS\system32\tsovvqlf.dll
    H:\WINDOWS\system32\wvowqfjq.dll
    H:\WINDOWS\system32\fessvr.dll
    H:\WINDOWS\system32\dngxkfkf.dll
    H:\WINDOWS\system32\vcpmarkj.dll
    H:\WINDOWS\system32\jgpcdfvs.dll
    H:\WINDOWS\system32\dqhpmi.dll
    H:\WINDOWS\system32\itntwwos.dll
    H:\WINDOWS\system32\ccryzu.dll
    H:\WINDOWS\system32\hdwqdtqm.dll
    H:\WINDOWS\system32\hqderyox.dll
    H:\WINDOWS\system32\hmuqdeqs.dll
    H:\WINDOWS\system32\huwuysxc.dll
    H:\WINDOWS\system32\aeiwuv.dll
    H:\WINDOWS\system32\tmwkxuma.dll
    H:\WINDOWS\system32\jwsqta.dll
    H:\WINDOWS\system32\fykltryw.dll
    H:\WINDOWS\system32\ibapmyid.dll
    H:\WINDOWS\system32\geBqNeFX.dll
    H:\WINDOWS\system32\jeraqmkd.dll
    H:\WINDOWS\system32\vmhdprty.dll
    H:\WINDOWS\system32\xwjlse.dll
    H:\WINDOWS\system32\vaqaiweh.dll
    H:\WINDOWS\system32\wvUnLFVM.dll
    H:\WINDOWS\system32\fccyaAQk.dll
    H:\WINDOWS\system32\vbzip10.dll
    
    Folder::
    H:\Program Files\PokerStars.NET
    H:\Program Files\PokerStars
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{16B2B71B-AB01-4F02-9BC8-109A36BD118D}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d0e8020d-9637-48f6-8c61-34d91f3ec89a}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "000000af"=-
    "BM9fe4da89"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
    
    Rootkit::
    H:\WINDOWS\system32\dupqcqam.ini
    H:\WINDOWS\system32\uxmosndk.ini
    H:\WINDOWS\system32\qjfqwovw.ini
    H:\WINDOWS\system32\xoyredqh.ini
    H:\WINDOWS\system32\sqedqumh.ini
    H:\WINDOWS\system32\OoUFgfii.ini
    H:\WINDOWS\system32\FMTAKRqr.ini
    H:\WINDOWS\system32\kQAayccf.ini2
    H:\WINDOWS\system32\kQAayccf.ini
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Tomk, Thanks for getting back to me so timely, I really appreciate it. I am currently at work and will not be back til this evening, so I will not be able to do anything until then, however, I wanted to let you know something else. After posting my scan results this morning. I noticed that my Windows Updater actually was showing up on the botton right of my screen. I have it set so that I have to approve the uploads, but I havent done it in a long time and when this problem started happening and I was reading up about how to fix it, it mentioned to make sure to keep your stuff up to date and to always download the updates that Windows provides. So I tried to do that earlier, but it never let me do it and I couldnt find it. So when I saw it this morning after the scans I had it update what was there, and it was about 28 different updates. Windows Security stuff, Microsoft Office Security stuff and all that. After I restarted I noticed it came up again and this time it said that I should install Service Pack 3 for Windows, but I didnt want to do that because I didnt know if that would mess up anything you would be doing since it seems kind of new, like the released it this past month. So I didnt know if you were all trained on it, so I didnt install that, but all those others I did install and afterwards I realized that it may have affected what help you were going to give me. Maybe some files got moved around or something, I dont know. So let me know if I need to run another Scan before I make those changes you had typed up for me or if its still okay to do the steps you had just posted. I really appreciate the help and Im sorry if it changed what you just posted, I was hoping to write this before you posted again, so you could take it in consideration, but I didnt realize you would get back to me so promptly, which I really appreciate that too. So please just let me know if I should just rescan Combo Fix and HijackThis and give you another set of logs or if I should just follow along with your recent post. Thanks so much.
baggin3, It is a little risky installing windows updates on an infected machine. However, I don't believe that you have done anything to cause us any problems. That was a good decision not to install SP3 (as well as the decision to advise me of what has happened). After we get you clean, I'll advise you to install the updates. Please just continue with instructions.
Okay, I tried doing the things you said, but ran into some problems. I ran the Hijack this scan and got rid of those 6 things. Next when I copied the text and put it into Combo Fix, it started to run and was removing all the stuff but after that, it just stopped and I was just left with my background image, since Combo Fix closed Explorer in order to run, so I restarted and ran Combo Fix on the restart and got the log. Also on that note, on start up, ComboFix asked me if I wanted to upgrade. I said no, just to get the scan. But if its okay to upgrade then I can do that too. Now the Kaspersky scan keeps freezing at 13%. It doesnt freeze up, it just doesnt seem to go past that point. Also it wont generate that report either. When I clicked the button to generate it, it will go to the screen but not show anything. There is a yellow triangle with an exclaimation point at the bottom left of the internet screen, like an error on page, dont know what is going on there. Since I was going to go to bed, I thought I would just give you the new ComboFix and Hijack this report and see what you can tell me about it.

ComboFix 08-09-26.06 - Sean 2008-09-27 18:47:54.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.147 [GMT -7:00]
Running from: H:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

H:\WINDOWS\BM9fe4da89.txt
H:\WINDOWS\BM9fe4da89.xml
H:\WINDOWS\pskt.ini

.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.

2008-09-27 10:34 . 2008-09-27 18:28 d——– H:\WINDOWS\system32\CatRoot_bak
2008-09-27 10:33 . 2008-06-13 06:10 272,128 ——— H:\WINDOWS\system32\drivers\bthport.sys
2008-09-27 10:33 . 2008-06-13 06:10 272,128 —–c— H:\WINDOWS\system32\dllcache\bthport.sys
2008-09-27 10:10 . 2008-09-27 10:10 d——– H:\Program Files\Avira
2008-09-27 10:10 . 2008-09-27 10:10 d——– H:\Documents and Settings\All Users\Application Data\Avira
2008-09-26 20:20 . 2008-09-26 20:20 d——– H:\Program Files\ERUNT
2008-09-26 20:11 . 2008-09-26 20:11 988,531 –ahs—- H:\WINDOWS\system32\dupqcqam.ini
2008-09-26 20:11 . 2008-09-26 20:11 73,216 –a—— H:\WINDOWS\system32\maqcqpud.dll
2008-09-26 20:09 . 2008-09-26 20:09 115,200 –a—— H:\WINDOWS\system32\hdvwlegb.dll
2008-09-26 20:09 . 2008-09-26 20:09 115,200 –a—— H:\WINDOWS\system32\cjxjzy.dll
2008-09-26 20:07 . 2008-09-26 20:07 105,984 –a—— H:\WINDOWS\system32\slshvewf.dll
2008-09-25 20:53 . 2008-09-25 20:52 410,976 –a—— H:\WINDOWS\system32\deploytk.dll
2008-09-25 20:53 . 2008-09-25 20:52 73,728 –a—— H:\WINDOWS\system32\javacpl.cpl
2008-09-25 20:01 . 2008-09-26 20:11 988,531 –ahs—- H:\WINDOWS\system32\uxmosndk.ini
2008-09-25 20:01 . 2008-09-25 20:01 115,200 –a—— H:\WINDOWS\system32\zzuazh.dll
2008-09-25 20:01 . 2008-09-25 20:01 115,200 –a—— H:\WINDOWS\system32\jlxyqvdb.dll
2008-09-25 19:58 . 2008-09-25 19:58 105,472 –a—— H:\WINDOWS\system32\tsovvqlf.dll
2008-09-24 20:22 . 2008-09-25 20:57 d——– H:\WINDOWS\BDOSCAN8
2008-09-24 20:08 . 2008-09-24 20:08 d——– H:\VundoFix Backups
2008-09-24 19:59 . 2008-09-24 20:00 914,829 –ahs—- H:\WINDOWS\system32\qjfqwovw.ini
2008-09-24 19:59 . 2008-09-24 19:59 84,992 –a—— H:\WINDOWS\system32\wvowqfjq.dll
2008-09-24 19:56 . 2008-09-24 19:56 115,200 –a—— H:\WINDOWS\system32\fessvr.dll
2008-09-24 19:56 . 2008-09-24 19:56 115,200 –a—— H:\WINDOWS\system32\dngxkfkf.dll
2008-09-24 18:59 . 2008-09-24 18:59 115,200 –a—— H:\WINDOWS\system32\jgpcdfvs.dll
2008-09-23 18:07 . 2008-09-23 18:07 115,200 –a—— H:\WINDOWS\system32\itntwwos.dll
2008-09-23 18:04 . 2008-09-24 19:24 898,333 –ahs—- H:\WINDOWS\system32\xoyredqh.ini
2008-09-23 16:57 . 2008-09-23 16:57 d——– H:\Documents and Settings\Administrator\Application Data\PC Tools
2008-09-23 16:55 . 2008-09-23 21:58 d——– H:\Documents and Settings\Administrator
2008-09-22 17:02 . 2008-09-22 17:03 879,273 –ahs—- H:\WINDOWS\system32\sqedqumh.ini
2008-09-22 17:02 . 2008-09-22 17:02 85,504 –a—— H:\WINDOWS\system32\hmuqdeqs.dll
2008-09-22 16:59 . 2008-09-22 16:59 115,200 –a—— H:\WINDOWS\system32\huwuysxc.dll
2008-09-22 16:59 . 2008-09-22 16:59 115,200 –a—— H:\WINDOWS\system32\aeiwuv.dll
2008-09-22 16:57 . 2008-09-22 16:57 95,232 –a—— H:\WINDOWS\system32\tmwkxuma.dll
2008-09-18 21:47 . 2008-09-18 21:47 115,200 –a—— H:\WINDOWS\system32\fykltryw.dll
2008-09-18 21:44 . 2008-09-22 16:58 1,059,857 –ahs—- H:\WINDOWS\system32\OoUFgfii.ini
2008-09-18 21:44 . 2008-09-18 21:44 221,184 –a—— H:\WINDOWS\system32\ibapmyid.dll
2008-09-18 21:44 . 2008-09-18 21:44 108,544 –a—— H:\WINDOWS\system32\geBqNeFX.dll
2008-09-18 21:41 . 2008-09-18 21:41 95,744 –a—— H:\WINDOWS\system32\jeraqmkd.dll
2008-09-18 17:44 . 2008-09-18 21:44 1,001,024 –ahs—- H:\WINDOWS\system32\FMTAKRqr.ini
2008-09-18 17:44 . 2008-09-18 17:44 221,184 –a—— H:\WINDOWS\system32\vmhdprty.dll
2008-09-18 17:44 . 2008-09-18 17:44 115,200 –a—— H:\WINDOWS\system32\vaqaiweh.dll
2008-09-18 17:44 . 2008-09-18 17:44 108,544 –a—— H:\WINDOWS\system32\wvUnLFVM.dll
2008-09-18 17:43 . 2008-09-27 10:21 1,166 –ahs—- H:\WINDOWS\system32\kQAayccf.ini2
2008-09-18 17:43 . 2008-09-27 10:21 1,166 –ahs—- H:\WINDOWS\system32\kQAayccf.ini
2008-09-18 17:41 . 2008-09-18 17:41 147,456 –a—— H:\WINDOWS\system32\vbzip10.dll
2008-09-18 17:38 . 2008-09-18 22:53 d——– H:\WINDOWS\system32\mC02
2008-09-06 22:49 . 2008-09-06 22:49 d——– H:\Program Files\NETGEAR
2008-09-06 22:49 . 2008-09-06 22:49 d——– H:\Documents and Settings\Sean\Application Data\InstallShield
2008-09-06 22:49 . 2005-07-20 04:53 966,765 –a—— H:\WINDOWS\system32\acAuth.dll
2008-09-06 22:49 . 2007-12-25 11:24 344,064 –a—— H:\WINDOWS\system32\SCMLib.dll
2008-09-06 22:49 . 2007-12-26 10:47 272,128 –a—— H:\WINDOWS\system32\drivers\wg111v2.sys
2008-09-06 22:49 . 2005-01-25 14:30 143,360 –a—— H:\WINDOWS\system32\IpLib.dll
2008-09-06 22:32 . 2007-04-27 06:00 1,069,056 –a—— H:\WINDOWS\system32\libeay32.dll
2008-09-06 22:32 . 2007-12-18 15:46 266,240 –a—— H:\WINDOWS\system32\WG1v2lib.dll
2008-09-06 22:32 . 2006-07-27 14:26 36,864 –a—— H:\WINDOWS\system32\RtlGina2.dll
2008-09-06 22:32 . 2008-09-06 22:32 21,035 –a—— H:\WINDOWS\system32\drivers\AegisP.sys
2008-08-31 13:16 . 2008-08-31 13:16 d——– H:\Program Files\Bethesda Softworks

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 01:44 ——— d—a-w H:\Documents and Settings\All Users\Application Data\TEMP
2008-09-28 01:35 ——— d—–w H:\Program Files\PokerStars.NET
2008-09-27 17:17 ——— d—–w H:\Program Files\Spyware Doctor
2008-09-26 03:52 ——— d—–w H:\Program Files\Java
2008-09-26 02:48 ——— d—–w H:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-19 01:09 ——— d—–w H:\Documents and Settings\Sean\Application Data\LimeWire
2008-07-28 00:25 ——— d—–w H:\Program Files\DOSBox-0.71
2008-07-19 05:10 94,920 —-a-w H:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w H:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w H:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w H:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w H:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w H:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w H:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w H:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w H:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w H:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 —-a-w H:\WINDOWS\system32\es.dll
.

((((((((((((((((((((((((((((( snapshot@2008-09-27_10.33.11.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-13 13:10:50 272,128 ——w H:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2007-03-06 01:22:41 213,216 -c—-w H:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w H:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 02:54:10 765,952 -c—-w H:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2007-03-06 01:22:39 213,216 -c—-w H:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c—-w H:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
+ 2007-07-12 23:31:54 765,952 -c—-w H:\WINDOWS\ie7updates\KB938127-v2-IE7\vgx.dll
+ 2007-12-07 02:21:45 124,928 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
+ 2007-12-19 23:01:06 347,136 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
+ 2007-12-07 02:21:45 214,528 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
+ 2007-12-07 02:21:45 133,120 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
+ 2007-12-07 02:21:45 63,488 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\icardie.dll
+ 2007-12-06 11:00:57 70,656 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
+ 2007-12-07 02:21:45 153,088 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
+ 2007-12-07 02:21:45 230,400 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
+ 2007-12-06 04:59:51 161,792 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
+ 2007-12-07 02:21:45 383,488 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieapfltr.dll
+ 2007-12-07 02:21:45 384,512 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
+ 2007-12-07 02:21:46 6,066,176 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieframe.dll
+ 2007-12-07 02:21:46 44,544 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
+ 2007-12-07 02:21:46 267,776 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\iertutil.dll
+ 2007-12-06 11:00:58 13,824 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
+ 2007-12-06 11:01:25 625,664 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
+ 2007-12-07 02:21:47 27,648 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
+ 2007-12-07 02:21:47 459,264 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\msfeeds.dll
+ 2007-12-07 02:21:47 52,224 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\msfeedsbs.dll
+ 2007-12-08 18:51:48 3,592,192 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
+ 2007-12-07 02:21:47 478,208 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
+ 2007-12-07 02:21:48 193,024 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
+ 2007-12-07 02:21:48 671,232 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
+ 2007-12-07 02:21:48 102,912 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
+ 2008-01-11 05:53:32 44,544 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\spuninst\updspapi.dll
+ 2007-12-07 02:21:48 105,984 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\url.dll
+ 2007-12-07 02:21:48 1,159,680 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
+ 2007-12-07 02:21:48 233,472 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
+ 2007-12-07 02:21:48 824,832 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
+ 2007-05-31 20:41:06 10,352,472 —-a-r H:\WINDOWS\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\EXCEL.EXE
+ 2007-04-19 21:09:30 167,256 —-a-r H:\WINDOWS\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\IETAG.DLL
+ 2007-06-19 00:16:32 12,259,160 —-a-r H:\WINDOWS\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSO.DLL
+ 2007-05-31 20:35:22 6,420,320 —-a-r H:\WINDOWS\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
- 2008-06-25 04:35:58 12,288 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-09-27 18:49:45 12,288 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-06-25 04:35:58 135,168 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-09-27 18:49:45 135,168 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-06-25 04:35:58 11,264 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-09-27 18:49:45 11,264 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-06-25 04:35:58 27,136 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-09-27 18:49:45 27,136 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-06-25 04:35:58 4,096 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-09-27 18:49:45 4,096 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-06-25 04:35:58 794,624 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-09-27 18:49:45 794,624 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-06-25 04:35:58 249,856 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-09-27 18:49:45 249,856 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-06-25 04:35:58 23,040 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-09-27 18:49:45 23,040 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-06-25 04:35:58 286,720 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-09-27 18:49:45 286,720 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-06-25 04:35:58 409,600 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-09-27 18:49:45 409,600 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2007-12-07 02:21:45 124,928 —-a-w H:\WINDOWS\system32\advpack.dll
+ 2008-06-23 16:57:27 124,928 —-a-w H:\WINDOWS\system32\advpack.dll
- 2007-12-07 02:21:45 124,928 -c—-w H:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-06-23 16:57:27 124,928 -c—-w H:\WINDOWS\system32\dllcache\advpack.dll
- 2004-10-08 12:01:47 138,496 -c–a-w H:\WINDOWS\system32\dllcache\afd.sys
+ 2008-06-20 10:44:38 138,368 -c–a-w H:\WINDOWS\system32\dllcache\afd.sys
- 2004-10-08 12:01:47 561,179 -c–a-w H:\WINDOWS\system32\dllcache\dao360.dll
+ 2008-03-25 04:50:25 554,008 -c–a-w H:\WINDOWS\system32\dllcache\dao360.dll
- 2006-06-26 17:37:10 148,480 -c–a-w H:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 -c–a-w H:\WINDOWS\system32\dllcache\dnsapi.dll
- 2007-12-19 23:01:06 347,136 -c—-w H:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-06-23 16:57:27 347,136 -c—-w H:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-12-07 02:21:45 214,528 -c—-w H:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-06-23 16:57:27 214,528 -c—-w H:\WINDOWS\system32\dllcache\dxtrans.dll
- 2005-07-26 04:39:45 243,200 -c–a-w H:\WINDOWS\system32\dllcache\es.dll
+ 2008-07-07 20:32:22 253,952 -c–a-w H:\WINDOWS\system32\dllcache\es.dll
- 2007-12-07 02:21:45 133,120 -c—-w H:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-06-23 16:57:27 133,120 -c—-w H:\WINDOWS\system32\dllcache\extmgr.dll
- 2007-12-07 02:21:45 63,488 -c—-w H:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-06-23 16:57:28 63,488 -c—-w H:\WINDOWS\system32\dllcache\icardie.dll
- 2007-12-06 11:00:57 70,656 -c—-w H:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-06-23 09:20:25 70,656 -c—-w H:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2007-12-07 02:21:45 153,088 -c—-w H:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-06-23 16:57:29 153,088 -c—-w H:\WINDOWS\system32\dllcache\ieakeng.dll
- 2007-12-07 02:21:45 230,400 -c—-w H:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-06-23 16:57:29 230,400 -c—-w H:\WINDOWS\system32\dllcache\ieaksie.dll
- 2007-12-06 04:59:51 161,792 -c—-w H:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-06-21 05:23:54 161,792 -c—-w H:\WINDOWS\system32\dllcache\ieakui.dll
- 2007-12-07 02:21:45 383,488 -c—-w H:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-06-23 16:57:29 383,488 -c—-w H:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2007-12-07 02:21:45 384,512 -c—-w H:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-06-23 16:57:29 384,512 -c—-w H:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2007-12-07 02:21:46 6,066,176 -c—-w H:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-06-23 16:57:33 6,066,176 -c—-w H:\WINDOWS\system32\dllcache\ieframe.dll
- 2007-12-07 02:21:46 44,544 -c—-w H:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-06-23 16:57:33 44,544 -c—-w H:\WINDOWS\system32\dllcache\iernonce.dll
- 2007-12-07 02:21:46 267,776 -c—-w H:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-06-23 16:57:34 267,776 -c—-w H:\WINDOWS\system32\dllcache\iertutil.dll
- 2007-12-06 11:00:58 13,824 -c—-w H:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-06-23 09:20:26 13,824 -c—-w H:\WINDOWS\system32\dllcache\ieudinit.exe
- 2007-12-06 11:01:25 625,664 -c—-w H:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-06-23 09:20:52 625,664 -c—-w H:\WINDOWS\system32\dllcache\iexplore.exe
- 2007-08-21 06:15:44 683,520 -c–a-w H:\WINDOWS\system32\dllcache\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 -c–a-w H:\WINDOWS\system32\dllcache\inetcomm.dll
- 2007-12-07 02:21:47 27,648 -c—-w H:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-06-23 16:57:35 27,648 -c—-w H:\WINDOWS\system32\dllcache\jsproxy.dll
- 2004-10-08 12:01:47 331,776 -c–a-w H:\WINDOWS\system32\dllcache\msadce.dll
+ 2008-05-01 14:30:33 331,776 -c–a-w H:\WINDOWS\system32\dllcache\msadce.dll
- 2005-06-29 01:46:00 74,240 -c–a-w H:\WINDOWS\system32\dllcache\mscms.dll
+ 2008-06-24 16:23:05 74,240 -c–a-w H:\WINDOWS\system32\dllcache\mscms.dll
- 2004-10-08 12:01:47 294,400 -c–a-w H:\WINDOWS\system32\dllcache\msctf.dll
+ 2008-02-26 11:59:50 294,912 -c–a-w H:\WINDOWS\system32\dllcache\msctf.dll
- 2004-10-08 12:01:47 512,029 -c–a-w H:\WINDOWS\system32\dllcache\msexch40.dll
+ 2008-03-25 04:50:28 518,944 -c–a-w H:\WINDOWS\system32\dllcache\msexch40.dll
- 2004-10-08 12:01:47 319,517 -c–a-w H:\WINDOWS\system32\dllcache\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 -c–a-w H:\WINDOWS\system32\dllcache\msexcl40.dll
- 2007-12-07 02:21:47 459,264 -c—-w H:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-06-23 16:57:36 459,264 -c—-w H:\WINDOWS\system32\dllcache\msfeeds.dll
- 2007-12-07 02:21:47 52,224 -c—-w H:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-06-23 16:57:36 52,224 -c—-w H:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2007-12-08 18:51:48 3,592,192 -c—-w H:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-06-24 17:57:40 3,592,192 -c—-w H:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-12-07 02:21:47 478,208 -c—-w H:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-06-23 16:57:39 477,696 -c—-w H:\WINDOWS\system32\dllcache\mshtmled.dll
- 2004-10-08 12:01:47 1,507,356 -c–a-w H:\WINDOWS\system32\dllcache\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 -c–a-w H:\WINDOWS\system32\dllcache\msjet40.dll
- 2004-10-08 12:01:47 358,976 -c–a-w H:\WINDOWS\system32\dllcache\msjetol1.dll
+ 2008-03-25 04:50:40 355,112 -c–a-w H:\WINDOWS\system32\dllcache\msjetol1.dll
- 2004-10-08 12:01:47 151,583 -c–a-w H:\WINDOWS\system32\dllcache\msjint40.dll
+ 2008-03-27 08:12:54 151,583 -c–a-w H:\WINDOWS\system32\dllcache\msjint40.dll
- 2004-10-08 12:01:47 53,279 -c–a-w H:\WINDOWS\system32\dllcache\msjter40.dll
+ 2008-03-25 04:50:42 60,192 -c–a-w H:\WINDOWS\system32\dllcache\msjter40.dll
- 2004-10-08 12:01:47 241,693 -c–a-w H:\WINDOWS\system32\dllcache\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 -c–a-w H:\WINDOWS\system32\dllcache\msjtes40.dll
- 2004-10-08 12:01:47 213,023 -c–a-w H:\WINDOWS\system32\dllcache\msltus40.dll
+ 2008-03-25 04:50:44 219,936 -c–a-w H:\WINDOWS\system32\dllcache\msltus40.dll
- 2004-10-08 12:01:47 348,189 -c–a-w H:\WINDOWS\system32\dllcache\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 -c–a-w H:\WINDOWS\system32\dllcache\mspbde40.dll
- 2007-12-07 02:21:48 193,024 -c—-w H:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-06-23 16:57:39 193,024 -c—-w H:\WINDOWS\system32\dllcache\msrating.dll
- 2004-10-08 12:01:47 421,919 -c–a-w H:\WINDOWS\system32\dllcache\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 -c–a-w H:\WINDOWS\system32\dllcache\msrd2x40.dll
- 2004-10-08 12:01:47 315,423 -c–a-w H:\WINDOWS\system32\dllcache\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 -c–a-w H:\WINDOWS\system32\dllcache\msrd3x40.dll
- 2004-10-08 12:01:47 552,989 -c–a-w H:\WINDOWS\system32\dllcache\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 -c–a-w H:\WINDOWS\system32\dllcache\msrepl40.dll
- 2004-10-08 12:01:47 258,077 -c–a-w H:\WINDOWS\system32\dllcache\mstext40.dll
+ 2008-03-25 04:50:55 264,992 -c–a-w H:\WINDOWS\system32\dllcache\mstext40.dll
- 2007-12-07 02:21:48 671,232 -c—-w H:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-06-23 16:57:40 671,232 -c—-w H:\WINDOWS\system32\dllcache\mstime.dll
- 2004-10-08 12:01:47 831,519 -c–a-w H:\WINDOWS\system32\dllcache\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 -c–a-w H:\WINDOWS\system32\dllcache\mswdat10.dll
- 2004-10-08 12:01:47 245,248 -c–a-w H:\WINDOWS\system32\dllcache\mswsock.dll
+ 2008-06-20 17:41:10 245,248 -c–a-w H:\WINDOWS\system32\dllcache\mswsock.dll
- 2004-10-08 12:01:47 614,429 -c–a-w H:\WINDOWS\system32\dllcache\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 -c–a-w H:\WINDOWS\system32\dllcache\mswstr10.dll
- 2004-10-08 12:01:47 348,189 -c–a-w H:\WINDOWS\system32\dllcache\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 -c–a-w H:\WINDOWS\system32\dllcache\msxbde40.dll
- 2007-12-07 02:21:48 102,912 -c—-w H:\WINDOWS\system32\dllcache\occache.dll
+ 2008-06-23 16:57:40 102,912 -c—-w H:\WINDOWS\system32\dllcache\occache.dll
- 2008-01-11 05:53:32 44,544 -c—-w H:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-06-23 16:57:40 44,544 -c—-w H:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-10-29 22:43:03 1,287,680 -c–a-w H:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 -c–a-w H:\WINDOWS\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 -c–a-w H:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c–a-w H:\WINDOWS\system32\dllcache\rmcast.sys
- 2007-10-30 17:20:55 360,064 -c–a-w H:\WINDOWS\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 -c–a-w H:\WINDOWS\system32\dllcache\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c–a-w H:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 -c–a-w H:\WINDOWS\system32\dllcache\tcpip6.sys
- 2007-12-07 02:21:48 105,984 -c—-w H:\WINDOWS\system32\dllcache\url.dll
+ 2008-06-23 16:57:40 105,984 -c—-w H:\WINDOWS\system32\dllcache\url.dll
- 2007-12-07 02:21:48 1,159,680 -c—-w H:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-06-23 16:57:40 1,159,680 -c—-w H:\WINDOWS\system32\dllcache\urlmon.dll
- 2007-08-14 02:54:10 765,952 -c–a-w H:\WINDOWS\system32\dllcache\VGX.dll
+ 2008-05-27 17:23:58 765,952 -c–a-w H:\WINDOWS\system32\dllcache\vgx.dll
- 2007-12-07 02:21:48 233,472 -c—-w H:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-06-23 16:57:41 233,472 -c—-w H:\WINDOWS\system32\dllcache\webcheck.dll
- 2007-12-07 02:21:48 824,832 -c—-w H:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-06-23 16:57:41 826,368 -c—-w H:\WINDOWS\system32\dllcache\wininet.dll
- 2006-06-26 17:37:10 148,480 —-a-w H:\WINDOWS\system32\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 —-a-w H:\WINDOWS\system32\dnsapi.dll
- 2004-10-08 12:01:47 138,496 —-a-w H:\WINDOWS\system32\drivers\afd.sys
+ 2008-06-20 10:44:38 138,368 —-a-w H:\WINDOWS\system32\drivers\afd.sys
- 2006-07-13 08:48:58 202,240 —-a-w H:\WINDOWS\system32\drivers\rmcast.sys
+ 2008-05-08 12:28:49 202,752 —-a-w H:\WINDOWS\system32\drivers\rmcast.sys
- 2007-10-30 17:20:55 360,064 —-a-w H:\WINDOWS\system32\drivers\tcpip.sys
+ 2008-06-20 10:45:13 360,320 —-a-w H:\WINDOWS\system32\drivers\tcpip.sys
- 2006-08-16 09:37:30 225,664 —-a-w H:\WINDOWS\system32\drivers\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 —-a-w H:\WINDOWS\system32\drivers\tcpip6.sys
- 2007-12-19 23:01:06 347,136 —-a-w H:\WINDOWS\system32\dxtmsft.dll
+ 2008-06-23 16:57:27 347,136 —-a-w H:\WINDOWS\system32\dxtmsft.dll
- 2007-12-07 02:21:45 214,528 —-a-w H:\WINDOWS\system32\dxtrans.dll
+ 2008-06-23 16:57:27 214,528 —-a-w H:\WINDOWS\system32\dxtrans.dll
- 2007-12-07 02:21:45 133,120 —-a-w H:\WINDOWS\system32\extmgr.dll
+ 2008-06-23 16:57:27 133,120 —-a-w H:\WINDOWS\system32\extmgr.dll
- 2007-12-07 02:21:45 63,488 —-a-w H:\WINDOWS\system32\icardie.dll
+ 2008-06-23 16:57:28 63,488 —-a-w H:\WINDOWS\system32\icardie.dll
- 2007-12-06 11:00:57 70,656 —-a-w H:\WINDOWS\system32\ie4uinit.exe
+ 2008-06-23 09:20:25 70,656 —-a-w H:\WINDOWS\system32\ie4uinit.exe
- 2007-12-07 02:21:45 153,088 —-a-w H:\WINDOWS\system32\ieakeng.dll
+ 2008-06-23 16:57:29 153,088 —-a-w H:\WINDOWS\system32\ieakeng.dll
- 2007-12-07 02:21:45 230,400 —-a-w H:\WINDOWS\system32\ieaksie.dll
+ 2008-06-23 16:57:29 230,400 —-a-w H:\WINDOWS\system32\ieaksie.dll
- 2007-12-06 04:59:51 161,792 —-a-w H:\WINDOWS\system32\ieakui.dll
+ 2008-06-21 05:23:54 161,792 —-a-w H:\WINDOWS\system32\ieakui.dll
- 2007-12-07 02:21:45 383,488 —-a-w H:\WINDOWS\system32\ieapfltr.dll
+ 2008-06-23 16:57:29 383,488 —-a-w H:\WINDOWS\system32\ieapfltr.dll
- 2007-12-07 02:21:45 384,512 —-a-w H:\WINDOWS\system32\iedkcs32.dll
+ 2008-06-23 16:57:29 384,512 —-a-w H:\WINDOWS\system32\iedkcs32.dll
- 2007-12-07 02:21:46 6,066,176 —-a-w H:\WINDOWS\system32\ieframe.dll
+ 2008-06-23 16:57:33 6,066,176 —-a-w H:\WINDOWS\system32\ieframe.dll
- 2007-12-07 02:21:46 44,544 —-a-w H:\WINDOWS\system32\iernonce.dll
+ 2008-06-23 16:57:33 44,544 —-a-w H:\WINDOWS\system32\iernonce.dll
- 2007-12-07 02:21:46 267,776 —-a-w H:\WINDOWS\system32\iertutil.dll
+ 2008-06-23 16:57:34 267,776 —-a-w H:\WINDOWS\system32\iertutil.dll
- 2007-12-06 11:00:58 13,824 —-a-w H:\WINDOWS\system32\ieudinit.exe
+ 2008-06-23 09:20:26 13,824 —-a-w H:\WINDOWS\system32\ieudinit.exe
- 2007-08-21 06:15:44 683,520 —-a-w H:\WINDOWS\system32\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 —-a-w H:\WINDOWS\system32\inetcomm.dll
- 2007-12-07 02:21:47 27,648 —-a-w H:\WINDOWS\system32\jsproxy.dll
+ 2008-06-23 16:57:35 27,648 —-a-w H:\WINDOWS\system32\jsproxy.dll
- 2008-02-04 23:09:48 18,214,008 —-a-w H:\WINDOWS\system32\MRT.exe
+ 2008-08-26 20:28:14 16,208,504 —-a-w H:\WINDOWS\system32\MRT.exe
- 2005-06-29 01:46:00 74,240 —-a-w H:\WINDOWS\system32\mscms.dll
+ 2008-06-24 16:23:05 74,240 —-a-w H:\WINDOWS\system32\mscms.dll
- 2004-10-08 12:01:47 294,400 —-a-w H:\WINDOWS\system32\MSCTF.dll
+ 2008-02-26 11:59:50 294,912 —-a-w H:\WINDOWS\system32\msctf.dll
- 2004-10-08 12:01:47 512,029 —-a-w H:\WINDOWS\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 —-a-w H:\WINDOWS\system32\msexch40.dll
- 2004-10-08 12:01:47 319,517 —-a-w H:\WINDOWS\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 —-a-w H:\WINDOWS\system32\msexcl40.dll
- 2007-12-07 02:21:47 459,264 —-a-w H:\WINDOWS\system32\msfeeds.dll
+ 2008-06-23 16:57:36 459,264 —-a-w H:\WINDOWS\system32\msfeeds.dll
- 2007-12-07 02:21:47 52,224 —-a-w H:\WINDOWS\system32\msfeedsbs.dll
+ 2008-06-23 16:57:36 52,224 —-a-w H:\WINDOWS\system32\msfeedsbs.dll
- 2007-12-08 18:51:48 3,592,192 —-a-w H:\WINDOWS\system32\mshtml.dll
+ 2008-06-24 17:57:40 3,592,192 —-a-w H:\WINDOWS\system32\mshtml.dll
- 2007-12-07 02:21:47 478,208 —-a-w H:\WINDOWS\system32\mshtmled.dll
+ 2008-06-23 16:57:39 477,696 —-a-w H:\WINDOWS\system32\mshtmled.dll
- 2004-10-08 12:01:47 1,507,356 —-a-w H:\WINDOWS\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 —-a-w H:\WINDOWS\system32\msjet40.dll
- 2004-10-08 12:01:47 358,976 —-a-w H:\WINDOWS\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 —-a-w H:\WINDOWS\system32\msjetoledb40.dll
- 2004-10-08 12:01:47 151,583 —-a-w H:\WINDOWS\system32\msjint40.dll
+ 2008-03-27 08:12:54 151,583 —-a-w H:\WINDOWS\system32\msjint40.dll
- 2004-10-08 12:01:47 53,279 —-a-w H:\WINDOWS\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 —-a-w H:\WINDOWS\system32\msjter40.dll
- 2004-10-08 12:01:47 241,693 —-a-w H:\WINDOWS\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 —-a-w H:\WINDOWS\system32\msjtes40.dll
- 2004-10-08 12:01:47 213,023 —-a-w H:\WINDOWS\system32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 —-a-w H:\WINDOWS\system32\msltus40.dll
- 2004-10-08 12:01:47 348,189 —-a-w H:\WINDOWS\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 —-a-w H:\WINDOWS\system32\mspbde40.dll
- 2007-12-07 02:21:48 193,024 —-a-w H:\WINDOWS\system32\msrating.dll
+ 2008-06-23 16:57:39 193,024 —-a-w H:\WINDOWS\system32\msrating.dll
- 2004-10-08 12:01:47 421,919 —-a-w H:\WINDOWS\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 —-a-w H:\WINDOWS\system32\msrd2x40.dll
- 2004-10-08 12:01:47 315,423 —-a-w H:\WINDOWS\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 —-a-w H:\WINDOWS\system32\msrd3x40.dll
- 2004-10-08 12:01:47 552,989 —-a-w H:\WINDOWS\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 —-a-w H:\WINDOWS\system32\msrepl40.dll
- 2004-10-08 12:01:47 258,077 —-a-w H:\WINDOWS\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 —-a-w H:\WINDOWS\system32\mstext40.dll
- 2007-12-07 02:21:48 671,232 —-a-w H:\WINDOWS\system32\mstime.dll
+ 2008-06-23 16:57:40 671,232 —-a-w H:\WINDOWS\system32\mstime.dll
- 2004-10-08 12:01:47 831,519 —-a-w H:\WINDOWS\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 —-a-w H:\WINDOWS\system32\mswdat10.dll
- 2004-10-08 12:01:47 245,248 —-a-w H:\WINDOWS\system32\mswsock.dll
+ 2008-06-20 17:41:10 245,248 —-a-w H:\WINDOWS\system32\mswsock.dll
- 2004-10-08 12:01:47 614,429 —-a-w H:\WINDOWS\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 —-a-w H:\WINDOWS\system32\mswstr10.dll
- 2004-10-08 12:01:47 348,189 —-a-w H:\WINDOWS\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 —-a-w H:\WINDOWS\system32\msxbde40.dll
- 2007-12-07 02:21:48 102,912 —-a-w H:\WINDOWS\system32\occache.dll
+ 2008-06-23 16:57:40 102,912 —-a-w H:\WINDOWS\system32\occache.dll
- 2008-01-11 05:53:32 44,544 —-a-w H:\WINDOWS\system32\pngfilt.dll
+ 2008-06-23 16:57:40 44,544 —-a-w H:\WINDOWS\system32\pngfilt.dll
- 2007-10-29 22:43:03 1,287,680 —-a-w H:\WINDOWS\system32\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 —-a-w H:\WINDOWS\system32\quartz.dll
- 2006-09-26 00:58:48 14,640 —-a-w H:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ——w H:\WINDOWS\system32\spmsg.dll
- 2007-11-13 11:31:11 60,416 —-a-w H:\WINDOWS\system32\tzchange.exe
+ 2008-07-14 11:09:18 62,976 —-a-w H:\WINDOWS\system32\tzchange.exe
- 2007-12-07 02:21:48 105,984 —-a-w H:\WINDOWS\system32\url.dll
+ 2008-06-23 16:57:40 105,984 —-a-w H:\WINDOWS\system32\url.dll
- 2007-12-07 02:21:48 1,159,680 —-a-w H:\WINDOWS\system32\urlmon.dll
+ 2008-06-23 16:57:40 1,159,680 —-a-w H:\WINDOWS\system32\urlmon.dll
- 2007-12-07 02:21:48 233,472 —-a-w H:\WINDOWS\system32\webcheck.dll
+ 2008-06-23 16:57:41 233,472 —-a-w H:\WINDOWS\system32\webcheck.dll
- 2007-12-07 02:21:48 824,832 —-a-w H:\WINDOWS\system32\wininet.dll
+ 2008-06-23 16:57:41 826,368 —-a-w H:\WINDOWS\system32\wininet.dll
- 2006-10-19 04:47:20 295,936 —-a-w H:\WINDOWS\system32\wmpeffects.dll
+ 2008-06-25 01:12:58 295,936 —-a-w H:\WINDOWS\system32\wmpeffects.dll
+ 2008-09-28 01:43:30 16,384 —-atw H:\WINDOWS\temp\Perflib_Perfdata_61c.dat
+ 2008-04-15 17:54:19 1,724,416 —-a-w H:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="H:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="H:\WINDOWS\system32\ctfmon.exe" [2004-10-08 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="H:\WINDOWS\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="H:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 81920]
"TkBellExe"="H:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-13 180269]
"QuickTime Task"="H:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="H:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-25 140696]
"avgnt"="H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"BM9fe4da89"="H:\WINDOWS\system32\slshvewf.dll" [2008-09-26 105984]
"nwiz"="nwiz.exe" [2007-12-05 H:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="H:\Program Files\Spyware Doctor\swdoctor.exe" [2006-12-15 2115728]

H:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - H:\Program Files\NETGEAR\WG111v2\WG111v2.exe [2008-09-06 1261568]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=H:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=H:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=H:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=H:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
–a—— 2006-03-21 18:30 1191936 H:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 13:54 5674352 H:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-12-05 01:41 8523776 H:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
–a—— 2005-01-18 13:32 532480 H:\Program Files\NVIDIA Corporation\nTune\nTune.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-12-05 01:41 81920 H:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRaidService]
-ra—— 2005-02-25 14:27 83968 H:\WINDOWS\system32\nvraidservice.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 H:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
–a—— 2006-12-15 12:16 2115728 H:\PROGRA~1\SPYWAR~1\swdoctor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2006-07-13 10:53 180269 H:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
–a—— 2003-05-21 01:21 90112 H:\PROGRA~1\SYMANT~1\SYMANT~1\VPTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-12-05 01:41 1626112 H:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2005-02-25 14:26 67584 H:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"SDhelper"=2 (0x2)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"Norton AntiVirus Server"=2 (0x2)
"IDriverT"=3 (0x3)
"DefWatch"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"H:\\Program Files\\Messenger\\msmsgs.exe"=
"H:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"H:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"H:\\Program Files\\MSN Messenger\\livecall.exe"=
"H:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"H:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"H:\\Program Files\\World of Warcraft\\Launcher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader

R2 JavaQuickStarterService;Java Quick Starter;H:\Program Files\Java\jre6\bin\jqs.exe [2008-09-25 152984]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;H:\WINDOWS\system32\DRIVERS\wg111v2.sys [2007-12-26 272128]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\AutoRunMorrowind.exe
\Shell\install\command - G:\Setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4ab9820-05c7-11dd-9991-003018a43a73}]
\Shell\AutoRun\command - I:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://forums.whatthetech.com/forums.html
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Search Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
O8 -: E&xport to Microsoft Excel - H:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 -: Easy-WebPrint Add To Print List - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 -: Easy-WebPrint High Speed Print - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 -: Easy-WebPrint Preview - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 -: Easy-WebPrint Print - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html

O16 -: Microsoft XML Parser for Java - file://H:\WINDOWS\Java\classes\xmldso.cab
H:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-27 18:50:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\H:\DOCUME~1\Sean\LOCALS~1\Temp\mc21.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: H:\WINDOWS\system32\winlogon.exe
-> H:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-09-27 18:52:42
ComboFix-quarantined-files.txt 2008-09-28 01:52:39
ComboFix2.txt 2008-09-27 17:33:40

Pre-Run: 12,964,773,888 bytes free
Post-Run: 12,954,935,296 bytes free

521 — E O F — 2008-09-27 18:54:35



Logfile of HijackThis v1.99.1
Scan saved at 10:21:05 PM, on 9/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\PnkBstrA.exe
H:\WINDOWS\System32\alg.exe
H:\Program Files\Common Files\Real\Update_OB\realsched.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Java\jre6\bin\jusched.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
H:\WINDOWS\system32\ctfmon.exe
H:\WINDOWS\System32\svchost.exe
H:\PROGRA~1\SPYWAR~1\swdoctor.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\explorer.exe
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.whatthetech.com/forums.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - H:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - H:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "H:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [BM9fe4da89] Rundll32.exe "H:\WINDOWS\system32\slshvewf.dll",s
O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - H:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - H:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - H:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - H:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Program Files\Java\jre6\bin\jqs.exe" -service -config "H:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - H:\WINDOWS\system32\PnkBstrA.exe
baggin3, Let's try a fresh copy of ComboFix. Drag the icon on your desktop to the recycle bin. Then download a fresh copy as you did before (the program is updated quite often). Make the CFscript.txt and drag into the new icon. If it appears to hang, give it 20 minutes before restarting. There is a good chance that your infection is keeping Kaspersky from running. Because the script didn't run on ComboFix, the infection wasn't killed. If the script works, Kaspersky's probably will also.
Okay so it happened again with ComboFix crashing or whatever is happening. I deleted the old one. Downloaded the new one. Recopied the Script and put it into ComboFix. It started to delete the items again. During the scan, and this happened the same as last time, it starts deleting slowly at first. It starts with PokerStars and goes through the files pretty slowly, but consistantly, then about 2/3 of the way through PokerStars it just jumps and goes super fast, like I cant even read it anymore. It finishes PokerStars and then goes to the other lines that were under it (again, doing this fast), and then it displays a message a couple of times, but it went by so fast I couldnt read it all, and then it crashes or stops and I just end up with the desktop image and no explorer. I waited 20-25 minutes and nothing ever happened, so I just restarted. The message that I couldnt read says something like "Unable to do…" or "Cant continue…" Something like that. I only get a chance to get the first couple of words, but I cant exactly remember it, but it was along the lines of it cant finish or cant continue or something like that. I could probably uninstall PokerStars from the add/remove section so it can do those scans faster or something. I dont know. I havent done a virus scan with Avira yet, I didnt know if I was supposed to since you never said. Maybe I could do that if Kaspersky isnt working. Just let me know whatever you think I should do. Thanks.
baggin3,

OK lets try it from another angle.

Using Add/remove programs in your control panel, uninstall Pokerstars, and/or Pokerstars.net.

Then

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
——————–\\ Lop S&D 4.2.4-4 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon™ 64 Processor 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Sean ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Not Activated)
A:\ (USB)
C:\ (USB)
D:\ (USB)
E:\ (USB)
F:\ (USB)
G:\ (CD or DVD) - CDFS - Total : 0 Go Free : 0 Go
H:\ (Local Disk) - NTFS - Total : 68 Go Free : 12 Go

"H:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 2008-09-28|11:04 )

——————–\\ Listing folders in APPLIC~1

[2008-09-23|21:59] H:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[2008-09-23|16:57] H:\DOCUME~1\ADMINI~1\APPLIC~1\PC Tools

[2006-11-15|11:13] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2008-06-04|17:35] H:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[2008-06-04|17:37] H:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[2008-07-01|18:56] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2008-07-01|18:58] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2008-09-27|10:10] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[2007-10-14|12:46] H:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[2006-04-03|19:27] H:\DOCUME~1\ALLUSE~1\APPLIC~1\InterVideo
[2006-05-26|13:39] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-08-29|18:06] H:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[2007-05-01|17:16] H:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[2006-08-18|10:56] H:\DOCUME~1\ALLUSE~1\APPLIC~1\SonyPicturesGames
[2005-10-29|16:08] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2008-09-28|10:08] H:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2008-09-25|19:48] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[2005-10-29|18:35] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2006-08-22|13:07] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!

[2005-10-29|15:50] H:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[2007-07-09|21:59] H:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[2006-06-11|15:13] H:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[2008-07-14|22:26] H:\DOCUME~1\Sean\APPLIC~1\.bittorrent
[2008-02-25|00:13] H:\DOCUME~1\Sean\APPLIC~1\Adobe
[2006-08-02|18:52] H:\DOCUME~1\Sean\APPLIC~1\AdobeUM
[2008-01-30|00:39] H:\DOCUME~1\Sean\APPLIC~1\Aim
[2006-04-26|23:16] H:\DOCUME~1\Sean\APPLIC~1\Apple Computer
[2006-01-27|16:30] H:\DOCUME~1\Sean\APPLIC~1\Help
[2005-10-29|15:57] H:\DOCUME~1\Sean\APPLIC~1\Identities
[2008-09-06|22:49] H:\DOCUME~1\Sean\APPLIC~1\InstallShield
[2006-04-03|19:41] H:\DOCUME~1\Sean\APPLIC~1\Intervideo
[2007-06-08|13:46] H:\DOCUME~1\Sean\APPLIC~1\Kazaa Lite
[2006-05-26|13:23] H:\DOCUME~1\Sean\APPLIC~1\Lavasoft
[2006-02-11|22:47] H:\DOCUME~1\Sean\APPLIC~1\Leadertech
[2008-09-18|18:09] H:\DOCUME~1\Sean\APPLIC~1\LimeWire
[2005-11-19|16:04] H:\DOCUME~1\Sean\APPLIC~1\Macromedia
[2007-08-16|21:33] H:\DOCUME~1\Sean\APPLIC~1\Microsoft
[2007-07-07|11:43] H:\DOCUME~1\Sean\APPLIC~1\MySpace
[2006-06-28|00:43] H:\DOCUME~1\Sean\APPLIC~1\PC Tools
[2007-05-01|17:16] H:\DOCUME~1\Sean\APPLIC~1\PlayFirst
[2008-08-12|17:22] H:\DOCUME~1\Sean\APPLIC~1\Real
[2006-10-25|15:21] H:\DOCUME~1\Sean\APPLIC~1\Sun
[2008-05-05|21:00] H:\DOCUME~1\Sean\APPLIC~1\Ventrilo
[2006-04-22|16:53] H:\DOCUME~1\Sean\APPLIC~1\Wildfire
[2007-08-24|20:05] H:\DOCUME~1\Sean\APPLIC~1\WinRAR

——————–\\ Scheduled Tasks located in H:\WINDOWS\Tasks

[2008-07-16 08:02][–a——] H:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-09-28 10:07][–ah—–] H:\WINDOWS\tasks\SA.DAT
[2004-10-08 05:01][-r-h—–] H:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in H:\Program Files

[2006-01-14|11:10] H:\Program Files\3DO
[2006-02-11|18:41] H:\Program Files\Activision Value
[2006-06-11|16:02] H:\Program Files\Adobe
[2006-10-07|16:02] H:\Program Files\Anarchy
[2008-09-27|10:10] H:\Program Files\Avira
[2005-10-29|17:47] H:\Program Files\AvRack
[2008-08-31|13:16] H:\Program Files\Bethesda Softworks
[2005-10-30|20:49] H:\Program Files\Black Isle
[2008-03-15|22:52] H:\Program Files\Call of Duty
[2007-10-14|12:48] H:\Program Files\Canon
[2007-10-14|12:45] H:\Program Files\CanonBJ
[2008-09-27|18:49] H:\Program Files\Common Files
[2005-10-29|15:49] H:\Program Files\ComPlus Applications
[2008-07-16|21:25] H:\Program Files\D2-1.12A-enUS
[2008-07-16|22:22] H:\Program Files\D2LOD-1.12A-enUS
[2008-07-27|11:14] H:\Program Files\Diablo II
[2008-07-27|17:25] H:\Program Files\DOSBox-0.71
[2008-03-08|14:16] H:\Program Files\EA GAMES
[2008-09-26|20:20] H:\Program Files\ERUNT
[2006-03-30|20:14] H:\Program Files\Hasbro Interactive
[2008-09-27|22:20] H:\Program Files\Hijackthis
[2005-11-18|12:37] H:\Program Files\IGN
[2008-04-08|17:03] H:\Program Files\InstallShield Installation Information
[2008-09-27|11:44] H:\Program Files\Internet Explorer
[2006-04-03|19:35] H:\Program Files\InterVideo
[2008-09-25|20:52] H:\Program Files\Java
[2005-10-29|16:10] H:\Program Files\Lavasoft
[2007-10-13|13:23] H:\Program Files\LucasArts
[2006-10-11|18:42] H:\Program Files\Maxis
[2008-09-27|11:48] H:\Program Files\Messenger
[2005-11-03|10:24] H:\Program Files\Microsoft ActiveSync
[2006-05-26|13:39] H:\Program Files\Microsoft AntiSpyware
[2005-10-29|15:51] H:\Program Files\microsoft frontpage
[2006-04-18|17:24] H:\Program Files\Microsoft Games
[2005-11-03|10:23] H:\Program Files\Microsoft Office
[2005-10-29|15:56] H:\Program Files\Movie Maker
[2006-12-12|15:14] H:\Program Files\MSN
[2005-12-10|16:32] H:\Program Files\MSN Gaming Zone
[2007-03-03|12:52] H:\Program Files\MSN Messenger
[2005-11-10|23:57] H:\Program Files\MsnMusic
[2007-07-09|21:59] H:\Program Files\MTV Networks
[2008-09-06|22:49] H:\Program Files\NETGEAR
[2005-10-29|15:49] H:\Program Files\NetMeeting
[2005-10-30|20:21] H:\Program Files\NVIDIA Corporation
[2005-11-03|10:43] H:\Program Files\OfficeUpdate11
[2005-10-29|15:50] H:\Program Files\Online Services
[2007-06-12|22:56] H:\Program Files\Outlook Express
[2007-04-18|15:15] H:\Program Files\PCFriendly
[2008-07-01|18:59] H:\Program Files\QuickTime
[2007-09-20|17:38] H:\Program Files\Raven
[2006-07-13|10:53] H:\Program Files\Real
[2005-10-29|17:47] H:\Program Files\Realtek Sound Manager
[2007-04-24|19:56] H:\Program Files\Sierra
[2006-06-23|11:01] H:\Program Files\Sierra On-Line
[2008-09-27|10:17] H:\Program Files\Spyware Doctor
[2008-01-05|13:03] H:\Program Files\Starcraft
[2008-07-19|23:33] H:\Program Files\Steam
[2007-06-06|17:58] H:\Program Files\SupportSoft
[2005-10-29|16:08] H:\Program Files\Symantec
[2005-10-29|16:08] H:\Program Files\Symantec_Client_Security
[2006-11-07|16:58] H:\Program Files\Ubisoft
[2005-10-29|15:57] H:\Program Files\Uninstall Information
[2008-01-03|21:31] H:\Program Files\Ventrilo
[2008-04-29|14:22] H:\Program Files\Warcraft III
[2007-07-09|20:55] H:\Program Files\Windows Media Connect 2
[2008-07-05|20:56] H:\Program Files\Windows Media Player
[2005-10-29|15:48] H:\Program Files\Windows NT
[2005-10-29|15:50] H:\Program Files\WindowsUpdate
[2007-08-24|20:05] H:\Program Files\WinRAR
[2007-02-25|20:04] H:\Program Files\WON
[2008-05-08|11:12] H:\Program Files\World of Warcraft
[2005-10-29|15:51] H:\Program Files\xerox
[2006-12-18|20:03] H:\Program Files\Yahoo!

——————–\\ Listing Folders in H:\Program Files\Common Files

[2006-01-14|11:10] H:\Program Files\Common Files\3DO Shared
[2006-06-11|16:03] H:\Program Files\Common Files\Adobe
[2008-07-16|21:29] H:\Program Files\Common Files\Blizzard Entertainment
[2005-11-03|10:24] H:\Program Files\Common Files\DESIGNER
[2005-10-29|17:47] H:\Program Files\Common Files\InstallShield
[2008-06-24|21:35] H:\Program Files\Common Files\Microsoft Shared
[2005-10-29|15:49] H:\Program Files\Common Files\MSSoap
[2005-10-29|08:39] H:\Program Files\Common Files\ODBC
[2006-07-13|10:54] H:\Program Files\Common Files\Real
[2005-10-29|15:49] H:\Program Files\Common Files\Services
[2005-10-29|08:39] H:\Program Files\Common Files\SpeechEngines
[2005-10-29|16:08] H:\Program Files\Common Files\Symantec Shared
[2007-06-12|22:56] H:\Program Files\Common Files\System
[2008-01-03|21:30] H:\Program Files\Common Files\Wise Installation Wizard
[2006-07-13|10:54] H:\Program Files\Common Files\xing shared

——————–\\ Process

( 37 Processes )

IEXPLORE.EXE ~ [PID:240]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 11:05:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

H:\WINDOWS\system32\kQAayccf.ini
H:\WINDOWS\system32\kQAayccf.ini2
==> VUNDO <==



[F:835][D:12]-> H:\DOCUME~1\Sean\LOCALS~1\Temp
[F:63][D:0]-> H:\DOCUME~1\Sean\Cookies
[F:285][D:4]-> H:\DOCUME~1\Sean\LOCALS~1\TEMPOR~1\content.IE5

1 - "H:\Lop SD\LopR_1.txt" - 2008-09-28|11:06 - Option : [1]

——————–\\ Scan completed at 11:06:37
——————–\\ Lop S&D 4.2.4-4 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon™ 64 Processor 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Sean ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Not Activated)
A:\ (USB)
C:\ (USB)
D:\ (USB)
E:\ (USB)
F:\ (USB)
G:\ (CD or DVD) - CDFS - Total : 0 Go Free : 0 Go
H:\ (Local Disk) - NTFS - Total : 68 Go Free : 12 Go

"H:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [1] ( 2008-09-28|11:04 )

——————–\\ Listing folders in APPLIC~1

[2008-09-23|21:59] H:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[2008-09-23|16:57] H:\DOCUME~1\ADMINI~1\APPLIC~1\PC Tools

[2006-11-15|11:13] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2008-06-04|17:35] H:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[2008-06-04|17:37] H:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[2008-07-01|18:56] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2008-07-01|18:58] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2008-09-27|10:10] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[2007-10-14|12:46] H:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[2006-04-03|19:27] H:\DOCUME~1\ALLUSE~1\APPLIC~1\InterVideo
[2006-05-26|13:39] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-08-29|18:06] H:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[2007-05-01|17:16] H:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[2006-08-18|10:56] H:\DOCUME~1\ALLUSE~1\APPLIC~1\SonyPicturesGames
[2005-10-29|16:08] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2008-09-28|10:08] H:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2008-09-25|19:48] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
[2005-10-29|18:35] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2006-08-22|13:07] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!

[2005-10-29|15:50] H:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[2007-07-09|21:59] H:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[2006-06-11|15:13] H:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[2008-07-14|22:26] H:\DOCUME~1\Sean\APPLIC~1\.bittorrent
[2008-02-25|00:13] H:\DOCUME~1\Sean\APPLIC~1\Adobe
[2006-08-02|18:52] H:\DOCUME~1\Sean\APPLIC~1\AdobeUM
[2008-01-30|00:39] H:\DOCUME~1\Sean\APPLIC~1\Aim
[2006-04-26|23:16] H:\DOCUME~1\Sean\APPLIC~1\Apple Computer
[2006-01-27|16:30] H:\DOCUME~1\Sean\APPLIC~1\Help
[2005-10-29|15:57] H:\DOCUME~1\Sean\APPLIC~1\Identities
[2008-09-06|22:49] H:\DOCUME~1\Sean\APPLIC~1\InstallShield
[2006-04-03|19:41] H:\DOCUME~1\Sean\APPLIC~1\Intervideo
[2007-06-08|13:46] H:\DOCUME~1\Sean\APPLIC~1\Kazaa Lite
[2006-05-26|13:23] H:\DOCUME~1\Sean\APPLIC~1\Lavasoft
[2006-02-11|22:47] H:\DOCUME~1\Sean\APPLIC~1\Leadertech
[2008-09-18|18:09] H:\DOCUME~1\Sean\APPLIC~1\LimeWire
[2005-11-19|16:04] H:\DOCUME~1\Sean\APPLIC~1\Macromedia
[2007-08-16|21:33] H:\DOCUME~1\Sean\APPLIC~1\Microsoft
[2007-07-07|11:43] H:\DOCUME~1\Sean\APPLIC~1\MySpace
[2006-06-28|00:43] H:\DOCUME~1\Sean\APPLIC~1\PC Tools
[2007-05-01|17:16] H:\DOCUME~1\Sean\APPLIC~1\PlayFirst
[2008-08-12|17:22] H:\DOCUME~1\Sean\APPLIC~1\Real
[2006-10-25|15:21] H:\DOCUME~1\Sean\APPLIC~1\Sun
[2008-05-05|21:00] H:\DOCUME~1\Sean\APPLIC~1\Ventrilo
[2006-04-22|16:53] H:\DOCUME~1\Sean\APPLIC~1\Wildfire
[2007-08-24|20:05] H:\DOCUME~1\Sean\APPLIC~1\WinRAR

——————–\\ Scheduled Tasks located in H:\WINDOWS\Tasks

[2008-07-16 08:02][–a——] H:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-09-28 10:07][–ah—–] H:\WINDOWS\tasks\SA.DAT
[2004-10-08 05:01][-r-h—–] H:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in H:\Program Files

[2006-01-14|11:10] H:\Program Files\3DO
[2006-02-11|18:41] H:\Program Files\Activision Value
[2006-06-11|16:02] H:\Program Files\Adobe
[2006-10-07|16:02] H:\Program Files\Anarchy
[2008-09-27|10:10] H:\Program Files\Avira
[2005-10-29|17:47] H:\Program Files\AvRack
[2008-08-31|13:16] H:\Program Files\Bethesda Softworks
[2005-10-30|20:49] H:\Program Files\Black Isle
[2008-03-15|22:52] H:\Program Files\Call of Duty
[2007-10-14|12:48] H:\Program Files\Canon
[2007-10-14|12:45] H:\Program Files\CanonBJ
[2008-09-27|18:49] H:\Program Files\Common Files
[2005-10-29|15:49] H:\Program Files\ComPlus Applications
[2008-07-16|21:25] H:\Program Files\D2-1.12A-enUS
[2008-07-16|22:22] H:\Program Files\D2LOD-1.12A-enUS
[2008-07-27|11:14] H:\Program Files\Diablo II
[2008-07-27|17:25] H:\Program Files\DOSBox-0.71
[2008-03-08|14:16] H:\Program Files\EA GAMES
[2008-09-26|20:20] H:\Program Files\ERUNT
[2006-03-30|20:14] H:\Program Files\Hasbro Interactive
[2008-09-27|22:20] H:\Program Files\Hijackthis
[2005-11-18|12:37] H:\Program Files\IGN
[2008-04-08|17:03] H:\Program Files\InstallShield Installation Information
[2008-09-27|11:44] H:\Program Files\Internet Explorer
[2006-04-03|19:35] H:\Program Files\InterVideo
[2008-09-25|20:52] H:\Program Files\Java
[2005-10-29|16:10] H:\Program Files\Lavasoft
[2007-10-13|13:23] H:\Program Files\LucasArts
[2006-10-11|18:42] H:\Program Files\Maxis
[2008-09-27|11:48] H:\Program Files\Messenger
[2005-11-03|10:24] H:\Program Files\Microsoft ActiveSync
[2006-05-26|13:39] H:\Program Files\Microsoft AntiSpyware
[2005-10-29|15:51] H:\Program Files\microsoft frontpage
[2006-04-18|17:24] H:\Program Files\Microsoft Games
[2005-11-03|10:23] H:\Program Files\Microsoft Office
[2005-10-29|15:56] H:\Program Files\Movie Maker
[2006-12-12|15:14] H:\Program Files\MSN
[2005-12-10|16:32] H:\Program Files\MSN Gaming Zone
[2007-03-03|12:52] H:\Program Files\MSN Messenger
[2005-11-10|23:57] H:\Program Files\MsnMusic
[2007-07-09|21:59] H:\Program Files\MTV Networks
[2008-09-06|22:49] H:\Program Files\NETGEAR
[2005-10-29|15:49] H:\Program Files\NetMeeting
[2005-10-30|20:21] H:\Program Files\NVIDIA Corporation
[2005-11-03|10:43] H:\Program Files\OfficeUpdate11
[2005-10-29|15:50] H:\Program Files\Online Services
[2007-06-12|22:56] H:\Program Files\Outlook Express
[2007-04-18|15:15] H:\Program Files\PCFriendly
[2008-07-01|18:59] H:\Program Files\QuickTime
[2007-09-20|17:38] H:\Program Files\Raven
[2006-07-13|10:53] H:\Program Files\Real
[2005-10-29|17:47] H:\Program Files\Realtek Sound Manager
[2007-04-24|19:56] H:\Program Files\Sierra
[2006-06-23|11:01] H:\Program Files\Sierra On-Line
[2008-09-27|10:17] H:\Program Files\Spyware Doctor
[2008-01-05|13:03] H:\Program Files\Starcraft
[2008-07-19|23:33] H:\Program Files\Steam
[2007-06-06|17:58] H:\Program Files\SupportSoft
[2005-10-29|16:08] H:\Program Files\Symantec
[2005-10-29|16:08] H:\Program Files\Symantec_Client_Security
[2006-11-07|16:58] H:\Program Files\Ubisoft
[2005-10-29|15:57] H:\Program Files\Uninstall Information
[2008-01-03|21:31] H:\Program Files\Ventrilo
[2008-04-29|14:22] H:\Program Files\Warcraft III
[2007-07-09|20:55] H:\Program Files\Windows Media Connect 2
[2008-07-05|20:56] H:\Program Files\Windows Media Player
[2005-10-29|15:48] H:\Program Files\Windows NT
[2005-10-29|15:50] H:\Program Files\WindowsUpdate
[2007-08-24|20:05] H:\Program Files\WinRAR
[2007-02-25|20:04] H:\Program Files\WON
[2008-05-08|11:12] H:\Program Files\World of Warcraft
[2005-10-29|15:51] H:\Program Files\xerox
[2006-12-18|20:03] H:\Program Files\Yahoo!

——————–\\ Listing Folders in H:\Program Files\Common Files

[2006-01-14|11:10] H:\Program Files\Common Files\3DO Shared
[2006-06-11|16:03] H:\Program Files\Common Files\Adobe
[2008-07-16|21:29] H:\Program Files\Common Files\Blizzard Entertainment
[2005-11-03|10:24] H:\Program Files\Common Files\DESIGNER
[2005-10-29|17:47] H:\Program Files\Common Files\InstallShield
[2008-06-24|21:35] H:\Program Files\Common Files\Microsoft Shared
[2005-10-29|15:49] H:\Program Files\Common Files\MSSoap
[2005-10-29|08:39] H:\Program Files\Common Files\ODBC
[2006-07-13|10:54] H:\Program Files\Common Files\Real
[2005-10-29|15:49] H:\Program Files\Common Files\Services
[2005-10-29|08:39] H:\Program Files\Common Files\SpeechEngines
[2005-10-29|16:08] H:\Program Files\Common Files\Symantec Shared
[2007-06-12|22:56] H:\Program Files\Common Files\System
[2008-01-03|21:30] H:\Program Files\Common Files\Wise Installation Wizard
[2006-07-13|10:54] H:\Program Files\Common Files\xing shared

——————–\\ Process

( 37 Processes )

IEXPLORE.EXE ~ [PID:240]

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 11:05:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

H:\WINDOWS\system32\kQAayccf.ini
H:\WINDOWS\system32\kQAayccf.ini2
==> VUNDO <==



[F:835][D:12]-> H:\DOCUME~1\Sean\LOCALS~1\Temp
[F:63][D:0]-> H:\DOCUME~1\Sean\Cookies
[F:285][D:4]-> H:\DOCUME~1\Sean\LOCALS~1\TEMPOR~1\content.IE5

1 - "H:\Lop SD\LopR_1.txt" - 2008-09-28|11:06 - Option : [1]

——————–\\ Scan completed at 11:06:37
baggin3,

Select the entire area below, then right-click and choose Copy

H:\WINDOWS\system32\kQAayccf.ini
H:\WINDOWS\system32\kQAayccf.ini2

Restart Lop S&D
Choose Option 4 (LopScript)
A blank page will be opened, right-click it and choose Paste
Close the page, you'll be asked to save it, click [Save]
Don't close the windows during suppression!
Post the log which is created: (%SystemDrive%\lopR.txt)
——————–\\ Lop S&D 4.2.4-4 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : AMD Athlon™ 64 Processor 2800+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Sean ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Not Activated)
A:\ (USB)
C:\ (USB)
D:\ (USB)
E:\ (USB)
F:\ (USB)
G:\ (CD or DVD) - CDFS - Total : 0 Go Free : 0 Go
H:\ (Local Disk) - NTFS - Total : 68 Go Free : 12 Go

"H:\Lop SD" ( MAJ : 19-09-2008|22:20 )
Option : [4] ( 2008-09-28|12:54 )

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ Lop Script

H:\WINDOWS\system32\kQAayccf.ini
H:\WINDOWS\system32\kQAayccf.ini2


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

Deleted! - H:\WINDOWS\system32\kQAayccf.ini
Deleted! - H:\WINDOWS\system32\kQAayccf.ini2

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Deleted! - H:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


——————–\\ Listing folders in APPLIC~1

[2008-09-23|21:59] H:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[2008-09-23|16:57] H:\DOCUME~1\ADMINI~1\APPLIC~1\PC Tools

[2006-11-15|11:13] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2008-06-04|17:35] H:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
[2008-06-04|17:37] H:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
[2008-07-01|18:56] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2008-07-01|18:58] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2008-09-27|10:10] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[2007-10-14|12:46] H:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
[2006-04-03|19:27] H:\DOCUME~1\ALLUSE~1\APPLIC~1\InterVideo
[2006-05-26|13:39] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-08-29|18:06] H:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[2007-05-01|17:16] H:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
[2006-08-18|10:56] H:\DOCUME~1\ALLUSE~1\APPLIC~1\SonyPicturesGames
[2005-10-29|16:08] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2008-09-28|12:50] H:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2005-10-29|18:35] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2006-08-22|13:07] H:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!

[2005-10-29|15:50] H:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[2007-07-09|21:59] H:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[2006-06-11|15:13] H:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[2008-07-14|22:26] H:\DOCUME~1\Sean\APPLIC~1\.bittorrent
[2008-02-25|00:13] H:\DOCUME~1\Sean\APPLIC~1\Adobe
[2006-08-02|18:52] H:\DOCUME~1\Sean\APPLIC~1\AdobeUM
[2008-01-30|00:39] H:\DOCUME~1\Sean\APPLIC~1\Aim
[2006-04-26|23:16] H:\DOCUME~1\Sean\APPLIC~1\Apple Computer
[2006-01-27|16:30] H:\DOCUME~1\Sean\APPLIC~1\Help
[2005-10-29|15:57] H:\DOCUME~1\Sean\APPLIC~1\Identities
[2008-09-06|22:49] H:\DOCUME~1\Sean\APPLIC~1\InstallShield
[2006-04-03|19:41] H:\DOCUME~1\Sean\APPLIC~1\Intervideo
[2007-06-08|13:46] H:\DOCUME~1\Sean\APPLIC~1\Kazaa Lite
[2006-05-26|13:23] H:\DOCUME~1\Sean\APPLIC~1\Lavasoft
[2006-02-11|22:47] H:\DOCUME~1\Sean\APPLIC~1\Leadertech
[2008-09-18|18:09] H:\DOCUME~1\Sean\APPLIC~1\LimeWire
[2005-11-19|16:04] H:\DOCUME~1\Sean\APPLIC~1\Macromedia
[2007-08-16|21:33] H:\DOCUME~1\Sean\APPLIC~1\Microsoft
[2007-07-07|11:43] H:\DOCUME~1\Sean\APPLIC~1\MySpace
[2006-06-28|00:43] H:\DOCUME~1\Sean\APPLIC~1\PC Tools
[2007-05-01|17:16] H:\DOCUME~1\Sean\APPLIC~1\PlayFirst
[2008-08-12|17:22] H:\DOCUME~1\Sean\APPLIC~1\Real
[2006-10-25|15:21] H:\DOCUME~1\Sean\APPLIC~1\Sun
[2008-05-05|21:00] H:\DOCUME~1\Sean\APPLIC~1\Ventrilo
[2006-04-22|16:53] H:\DOCUME~1\Sean\APPLIC~1\Wildfire
[2007-08-24|20:05] H:\DOCUME~1\Sean\APPLIC~1\WinRAR

——————–\\ Scheduled Tasks located in H:\WINDOWS\Tasks

[2008-07-16 08:02][–a——] H:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-09-28 12:36][–ah—–] H:\WINDOWS\tasks\SA.DAT
[2004-10-08 05:01][-r-h—–] H:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in H:\Program Files

[2006-01-14|11:10] H:\Program Files\3DO
[2006-02-11|18:41] H:\Program Files\Activision Value
[2006-06-11|16:02] H:\Program Files\Adobe
[2006-10-07|16:02] H:\Program Files\Anarchy
[2008-09-27|10:10] H:\Program Files\Avira
[2005-10-29|17:47] H:\Program Files\AvRack
[2008-08-31|13:16] H:\Program Files\Bethesda Softworks
[2005-10-30|20:49] H:\Program Files\Black Isle
[2008-03-15|22:52] H:\Program Files\Call of Duty
[2007-10-14|12:48] H:\Program Files\Canon
[2007-10-14|12:45] H:\Program Files\CanonBJ
[2008-09-27|18:49] H:\Program Files\Common Files
[2005-10-29|15:49] H:\Program Files\ComPlus Applications
[2008-07-16|21:25] H:\Program Files\D2-1.12A-enUS
[2008-07-16|22:22] H:\Program Files\D2LOD-1.12A-enUS
[2008-07-27|11:14] H:\Program Files\Diablo II
[2008-07-27|17:25] H:\Program Files\DOSBox-0.71
[2008-03-08|14:16] H:\Program Files\EA GAMES
[2008-09-26|20:20] H:\Program Files\ERUNT
[2006-03-30|20:14] H:\Program Files\Hasbro Interactive
[2008-09-27|22:20] H:\Program Files\Hijackthis
[2005-11-18|12:37] H:\Program Files\IGN
[2008-04-08|17:03] H:\Program Files\InstallShield Installation Information
[2008-09-27|11:44] H:\Program Files\Internet Explorer
[2006-04-03|19:35] H:\Program Files\InterVideo
[2008-09-25|20:52] H:\Program Files\Java
[2005-10-29|16:10] H:\Program Files\Lavasoft
[2007-10-13|13:23] H:\Program Files\LucasArts
[2006-10-11|18:42] H:\Program Files\Maxis
[2008-09-27|11:48] H:\Program Files\Messenger
[2005-11-03|10:24] H:\Program Files\Microsoft ActiveSync
[2006-05-26|13:39] H:\Program Files\Microsoft AntiSpyware
[2005-10-29|15:51] H:\Program Files\microsoft frontpage
[2006-04-18|17:24] H:\Program Files\Microsoft Games
[2005-11-03|10:23] H:\Program Files\Microsoft Office
[2005-10-29|15:56] H:\Program Files\Movie Maker
[2006-12-12|15:14] H:\Program Files\MSN
[2005-12-10|16:32] H:\Program Files\MSN Gaming Zone
[2007-03-03|12:52] H:\Program Files\MSN Messenger
[2005-11-10|23:57] H:\Program Files\MsnMusic
[2007-07-09|21:59] H:\Program Files\MTV Networks
[2008-09-06|22:49] H:\Program Files\NETGEAR
[2005-10-29|15:49] H:\Program Files\NetMeeting
[2005-10-30|20:21] H:\Program Files\NVIDIA Corporation
[2005-11-03|10:43] H:\Program Files\OfficeUpdate11
[2005-10-29|15:50] H:\Program Files\Online Services
[2007-06-12|22:56] H:\Program Files\Outlook Express
[2007-04-18|15:15] H:\Program Files\PCFriendly
[2008-07-01|18:59] H:\Program Files\QuickTime
[2007-09-20|17:38] H:\Program Files\Raven
[2006-07-13|10:53] H:\Program Files\Real
[2005-10-29|17:47] H:\Program Files\Realtek Sound Manager
[2007-04-24|19:56] H:\Program Files\Sierra
[2006-06-23|11:01] H:\Program Files\Sierra On-Line
[2008-09-27|10:17] H:\Program Files\Spyware Doctor
[2008-01-05|13:03] H:\Program Files\Starcraft
[2008-07-19|23:33] H:\Program Files\Steam
[2007-06-06|17:58] H:\Program Files\SupportSoft
[2005-10-29|16:08] H:\Program Files\Symantec
[2005-10-29|16:08] H:\Program Files\Symantec_Client_Security
[2006-11-07|16:58] H:\Program Files\Ubisoft
[2005-10-29|15:57] H:\Program Files\Uninstall Information
[2008-01-03|21:31] H:\Program Files\Ventrilo
[2008-04-29|14:22] H:\Program Files\Warcraft III
[2007-07-09|20:55] H:\Program Files\Windows Media Connect 2
[2008-07-05|20:56] H:\Program Files\Windows Media Player
[2005-10-29|15:48] H:\Program Files\Windows NT
[2005-10-29|15:50] H:\Program Files\WindowsUpdate
[2007-08-24|20:05] H:\Program Files\WinRAR
[2007-02-25|20:04] H:\Program Files\WON
[2008-05-08|11:12] H:\Program Files\World of Warcraft
[2005-10-29|15:51] H:\Program Files\xerox
[2006-12-18|20:03] H:\Program Files\Yahoo!

——————–\\ Listing Folders in H:\Program Files\Common Files

[2006-01-14|11:10] H:\Program Files\Common Files\3DO Shared
[2006-06-11|16:03] H:\Program Files\Common Files\Adobe
[2008-07-16|21:29] H:\Program Files\Common Files\Blizzard Entertainment
[2005-11-03|10:24] H:\Program Files\Common Files\DESIGNER
[2005-10-29|17:47] H:\Program Files\Common Files\InstallShield
[2008-06-24|21:35] H:\Program Files\Common Files\Microsoft Shared
[2005-10-29|15:49] H:\Program Files\Common Files\MSSoap
[2005-10-29|08:39] H:\Program Files\Common Files\ODBC
[2006-07-13|10:54] H:\Program Files\Common Files\Real
[2005-10-29|15:49] H:\Program Files\Common Files\Services
[2005-10-29|08:39] H:\Program Files\Common Files\SpeechEngines
[2005-10-29|16:08] H:\Program Files\Common Files\Symantec Shared
[2007-06-12|22:56] H:\Program Files\Common Files\System
[2008-01-03|21:30] H:\Program Files\Common Files\Wise Installation Wizard
[2006-07-13|10:54] H:\Program Files\Common Files\xing shared

——————–\\ Process

( 35 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

No Lop folder found !

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 12:56:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections


No other infections found !

[F:835][D:12]-> H:\DOCUME~1\Sean\LOCALS~1\Temp
[F:63][D:0]-> H:\DOCUME~1\Sean\Cookies
[F:299][D:4]-> H:\DOCUME~1\Sean\LOCALS~1\TEMPOR~1\content.IE5

1 - "H:\Lop SD\LopR_1.txt" - 2008-09-28|11:06 - Option : [1]
2 - "H:\Lop SD\LopR_2.txt" - 2008-09-28|12:58 - Option : [4]

——————–\\ Scan completed at 12:58:17
baggin3, Alright. We did good. That killed some of the active infection. Now please run ComboFix again per instructions in post #2 (no script) and post results along with a new HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI