This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE browser hijacked

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For the past few days, my browser has been hijacked with numerous websites, some "Zeno…" thing looking like a malicious search engine, tried running Spybot & Super Antispyware loaded by my PC repair shop, quarantined, but something still running. Have spent at least 7 hr. researching, trying to solve, etc. and thankfully found you!
Your help is sincerely appreciated!!!!

Here is HJTlog:

Logfile of HijackThis v1.99.1
Scan saved at 1:19:35 PM, on 10/7/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\qcntltdl.exe
C:\windows\system32\rmwnw64k.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
c:\program files\mcafee.com\vso\mcvsescn.exe
C:\Program Files\VnrBlock\VnrBlock21.exe
C:\Program Files\GetPack\GetPack21.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antwrp.gsfc.nasa.gov/apod/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5400
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *update.microsoft.com;*windowsupdate.com;download.microsoft.com;codecs.microsoft
.com;activex.microsoft.com;liveupdate.symantecliveupdate.com;liveupdate.symantec.
com;download.mcafee.com;*.phobos.apple.com;update.adobe.com;mail.google.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: banneradsgalore browser optimizer - {40b59abe-62e6-6731-fb2a-8a530199cd01} - C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\SlipStream Web Accelerator\PBHelper.dll
O2 - BHO: DrFlex IE Helper - {8EEB2711-9D21-4f9c-99A1-B7FC5A8CA56A} - C:\Program Files\QdrDrive\QdrDrive20.dll
O2 - BHO: mysidesearch search enhancer - {a83dcfb6-5aea-da93-6f88-4585d113d937} - C:\WINDOWS\system32\talueajxdeezlgk.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{88df1262-e41f-2709-de3f-c5c9193fe257}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll" DllStart
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\qcntltdl.exe DWrvg
O4 - HKLM\..\Run: [{93-36-64-41-DW}] C:\windows\system32\rmwnw64k.exe DWrvg
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [VnrPack20] "C:\Program Files\VnrPack\VnrPack20.exe"
O4 - HKCU\..\Run: [VnrBlock21] "C:\Program Files\VnrBlock\VnrBlock21.exe"
O4 - HKCU\..\Run: [GetPack21] "C:\Program Files\GetPack\GetPack21.exe"
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\qcntltdl.exe
O4 - Startup: DW_START.LNK = C:\WINDOWS\system32\RMWNW64K.EXE
O8 - Extra context menu item: Show All Original Images - res://C:\Program Files\SlipStream Web Accelerator\slipaccel.exe/250
O8 - Extra context menu item: Show Original Image - res://C:\Program Files\SlipStream Web Accelerator\slipaccel.exe/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A66967C6-F8F9-4412-9F86-F0BE9BDB2635}: NameServer = 207.164.234.193 207.164.234.129
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
Good evening

Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
Thank you so much for your help Rorschach, here are the logs, ComboFix 1st:
ComboFix 08-10-07.06 - User 2008-10-08 8:20:01.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\User\Start Menu\Programs\Startup\Deewoo.lnk
C:\Documents and Settings\User\Start Menu\Programs\Startup\DW_Start.lnk
C:\Program Files\AntiSpywareMaster
C:\Program Files\AntiSpywareMaster\asm.exe
C:\Program Files\GetPack
C:\Program Files\GetPack\dictame.gz
C:\Program Files\GetPack\GETPACK21.EXE
C:\Program Files\GetPack\trgtame.gz
C:\Program Files\iCheck
C:\Program Files\iCheck\Uninstall.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QDRDRIVE20.DLL
C:\Program Files\VnrBlock
C:\Program Files\VnrBlock\VnrBlock21.exe
C:\Program Files\VnrBlock\xtarga.gz
C:\WINDOWS\84.exe
C:\WINDOWS\system32\gside.exe
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\RMWNW64K.EXE
C:\WINDOWS\system32\RMWNW64R.EXE
C:\WINDOWS\system32\rwwnw64d.exe
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\system32\zxdnt3d.cfg

.
((((((((((((((((((((((((( Files Created from 2008-09-08 to 2008-10-08 )))))))))))))))))))))))))))))))
.

2008-10-07 11:50 . 2008-05-26 07:10 366,080 –a—— C:\WINDOWS\system32\{23AE2067-CB6E-02DC-393D-44A78B449D7F}.DLL
2008-10-04 16:28 . 2008-10-03 09:01 49,152 –a—— C:\WINDOWS\DW611.EXE
2008-10-03 09:07 . 2008-10-03 09:12 548,928 –a—— C:\WINDOWS\system32\qcntltdl.exe
2008-10-03 09:07 . 2008-10-03 09:07 90,915 –a—— C:\WINDOWS\system32\talueajxdeezlgk.dll-uninst.exe
2008-10-03 09:01 . 2008-10-03 09:01 d——– C:\unzipped
2008-10-03 09:01 . 2008-10-03 09:01 223,076 –a—— C:\WINDOWS\ism611.exe
2008-10-03 09:01 . 2008-10-03 09:01 178,616 –a—— C:\WINDOWS\plate611.exe
2008-10-03 09:01 . 2008-10-03 09:12 63,904 –a—— C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll-uninst.exe
2008-09-19 20:38 . 2004-04-27 04:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-06 02:51 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-10-06 02:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-08 01:23 ——— d—–w C:\Program Files\DVDMagic
2008-08-21 14:20 ——— d—–w C:\Documents and Settings\User\Application Data\AdobeUM
2008-08-13 17:28 ——— d—–w C:\Program Files\LimeWire
2008-07-19 03:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 03:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 03:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 03:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 03:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 03:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 03:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 03:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
1998-08-24 16:09 10,000 -c–a-w C:\WINDOWS\inf\unregpn.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40b59abe-62e6-6731-fb2a-8a530199cd01}]
2008-05-26 07:10 366080 –a—— C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a83dcfb6-5aea-da93-6f88-4585d113d937}]
2008-07-03 10:49 364544 –a—— C:\WINDOWS\system32\talueajxdeezlgk.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 163840]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"{88df1262-e41f-2709-de3f-c5c9193fe257}"="C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll" [2008-05-26 366080]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 C:\WINDOWS\SOUNDMAN.EXE]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
"msvideo7"= STV680tg.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2005-10-05 18:47 684032 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-14 05:42 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a—— 2002-06-17 07:41 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memorex Button Manager]
–a—— 2007-04-20 14:58 376832 C:\Program Files\Memorex Button Manager\MmrBtnMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-01 15:57 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
–a—— 2002-04-11 03:19 69632 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-08-26 17:14 36975 C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
–a—— 2008-05-28 10:33 1506544 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-09-16 07:39 69632 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
-ra—— 2004-01-15 07:33 49152 C:\WINDOWS\system32\VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=


*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2007-05-11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 14:21]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-VnrPack20 - C:\Program Files\VnrPack\VnrPack20.exe
HKCU-Run-VnrBlock21 - C:\Program Files\VnrBlock\VnrBlock21.exe
HKCU-Run-GetPack21 - C:\Program Files\GetPack\GetPack21.exe
HKLM-Run-{93-36-64-41-DW} - C:\windows\system32\rmwnw64k.exe
Notify-NavLogon - (no file)
Notify-WgaLogon - (no file)
MSConfigStartUp-!AVG Anti-Spyware - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
MSConfigStartUp-ZoneAlarm Client - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
MSConfigStartUp-Cmaudio - cmicnfg.cpl


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://antwrp.gsfc.nasa.gov/apod/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 08:22:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-08 8:24:30
ComboFix-quarantined-files.txt 2008-10-08 13:24:26

Pre-Run: 71,142,916,096 bytes free
Post-Run: 71,132,852,224 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

170 — E O F — 2008-07-17 20:55:03

HijackThis Scan:
Logfile of HijackThis v1.99.1
Scan saved at 8:31:21 AM, on 10/8/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
c:\program files\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antwrp.gsfc.nasa.gov/apod/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: banneradsgalore browser optimizer - {40b59abe-62e6-6731-fb2a-8a530199cd01} - C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\SlipStream Web Accelerator\PBHelper.dll
O2 - BHO: mysidesearch search enhancer - {a83dcfb6-5aea-da93-6f88-4585d113d937} - C:\WINDOWS\system32\talueajxdeezlgk.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{88df1262-e41f-2709-de3f-c5c9193fe257}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll" DllStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
Hello

Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/IE_browser_hijacked_t95936.html

Collect::
C:\WINDOWS\system32\{23AE2067-CB6E-02DC-393D-44A78B449D7F}.DLL
C:\WINDOWS\DW611.EXE
C:\WINDOWS\system32\qcntltdl.exe
C:\WINDOWS\system32\talueajxdeezlgk.dll-uninst.exe
C:\unzipped
C:\WINDOWS\ism611.exe
C:\WINDOWS\plate611.exe
C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll-uninst.exe

Sysrst::

Suspect::
Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions to copy/paste/send the requested file.
Attempted running scan 3 times - McAfee security pop ups throughout despite disabling & exiting McAfee, which leads me to believe McAfee anti-virus compromised with this as well, awfully nasty. During second attempt, connection setting on IE changed, happens all the time since loading Service Pack 3. 3rd attempt did not get pop up with auto file transfer to Bleeping Computer. So I'm attached the txt file here, hope you can assist, this problem is driving me crazy :-)

Attachments:

OK, here it is:
ComboFix 08-10-07.06 - User 2008-10-08 20:24:57.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\WINDOWS\DW611.EXE
C:\WINDOWS\ism611.exe
C:\WINDOWS\plate611.exe
C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll-uninst.exe
C:\WINDOWS\system32\{23AE2067-CB6E-02DC-393D-44A78B449D7F}.DLL
C:\WINDOWS\system32\qcntltdl.exe
C:\WINDOWS\system32\talueajxdeezlgk.dll-uninst.exe

.
((((((((((((((((((((((((( Files Created from 2008-09-09 to 2008-10-09 )))))))))))))))))))))))))))))))
.

2008-10-03 09:01 . 2008-10-03 09:01 d——– C:\unzipped
2008-09-19 20:38 . 2004-04-27 04:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-06 02:51 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-10-06 02:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-08 01:23 ——— d—–w C:\Program Files\DVDMagic
2008-08-21 14:20 ——— d—–w C:\Documents and Settings\User\Application Data\AdobeUM
2008-08-13 17:28 ——— d—–w C:\Program Files\LimeWire
2008-07-19 03:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 03:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 03:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 03:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 03:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 03:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 03:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 03:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
1998-08-24 16:09 10,000 -c–a-w C:\WINDOWS\inf\unregpn.exe
.

((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.

2008-04-14 05:42 26624 C:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
{6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP680\A0123850.dllC:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2008-04-14 05:42 26624 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP688\A0126520.dll

C:\Program Files\AntiSpywareMaster\asm.exe
2008-10-05 14:12 467920 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP699\A0133126.exe

C:\Program Files\GETPACK\GETPACK21.EXE
2008-09-12 08:44 350208 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP699\A0133127.EXE

C:\Program Files\iCheck\Uninstall.exe
2008-10-04 14:22 32077 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP699\A0133128.exe

C:\Program Files\ISM\ism.exe
2008-04-04 05:02 237568 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP696\A0126888.exe

C:\Program Files\ISM\Uninstall.exe
2008-10-03 09:01 32799 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP696\A0126889.exe

C:\Program Files\QDRDRIVE\QDRDRIVE20.DLL
2008-07-23 08:02 147456 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP699\A0133129.DLL

C:\Program Files\VnrBlock\VnrBlock21.exe
2008-09-18 18:16 364032 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP699\A0133130.exe

C:\Program Files\VnrPack\uhberupd.exe
2008-10-03 09:06 151586 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP695\A0126807.exe
2008-10-03 17:37 94646 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP696\A0126874.exe

C:\Program Files\Zone Labs\ZoneAlarm\expert.dll
2007-09-06 16:13 189928 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126374.dll

C:\Program Files\Zone Labs\ZoneAlarm\framewrk.dll
2007-09-06 16:13 1209832 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126375.dll

C:\Program Files\Zone Labs\ZoneAlarm\instmtdr.exe
2007-05-22 23:07 8274968 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126376.exe

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\AddinMon.exe
2003-03-14 15:27 74112 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126240.exe

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\ASDUtil.dll
2007-05-11 07:50 50712 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126244.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\crsrpt.dll
2007-05-11 07:50 91672 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126246.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\dbghelp.dll
2004-08-04 04:00 640000 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126241.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
2007-05-11 07:50 804376 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126245.exe

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll
2007-05-11 07:50 12312 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126247.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfOE.dll
2007-05-11 07:50 685592 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126248.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mlfoshim.dll
2007-05-11 07:50 726552 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126249.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\msvcp70.dll
2002-01-05 00:40 487424 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126242.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\msvcr70.dll
2002-01-05 00:37 344064 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126243.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mtdsdk.dll
2007-05-11 07:50 230936 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126250.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\10secure.dll
2007-05-11 07:50 169496 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126251.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\15hdrs.dll
2007-05-11 07:51 157208 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126252.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\20addrbk.dll
2007-05-11 07:51 165400 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126253.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\26fgn.dll
2007-05-11 07:51 194072 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126254.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\27prolab.dll
2007-05-11 07:51 382488 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126255.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\31rules.dll
2007-05-11 07:51 1607192 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126256.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\50collab.dll
2007-05-11 07:51 624152 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126257.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\55bfraud.dll
2007-05-11 07:51 1447448 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126260.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\70challn.dll
2007-05-11 07:51 513560 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126258.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\plugins\90logger.dll
2007-05-11 07:51 157208 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126259.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbmfdeu.dll
2007-05-11 07:50 316952 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126261.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbmfenu.dll
2007-05-11 07:50 345624 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126262.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbmfesp.dll
2007-05-11 07:50 357912 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126263.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbmffra.dll
2007-05-11 07:50 345624 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126264.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbmfita.dll
2007-05-11 07:50 341528 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126265.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbmfjpn.dll
2007-05-11 07:50 341528 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126266.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbzadeu.dll
2007-05-11 07:50 288280 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126267.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbzaenu.dll
2007-05-11 07:50 284184 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126268.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbzaesp.dll
2007-05-11 07:50 304664 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126269.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbzafra.dll
2007-05-11 07:50 292376 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126270.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbzaita.dll
2007-05-11 07:50 288280 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126271.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\mbzajpn.dll
2007-05-11 07:50 284184 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126272.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oemfdeu.dll
2007-05-11 07:50 43544 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126273.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oemfenu.dll
2007-05-11 07:50 41496 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126274.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oemfesp.dll
2007-05-11 07:50 43544 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126275.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oemffra.dll
2007-05-11 07:50 54808 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126276.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oemfita.dll
2007-05-11 07:50 43032 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126277.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oemfjpn.dll
2007-05-11 07:50 37400 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126278.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oezadeu.dll
2007-05-11 07:50 49176 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126279.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oezaenu.dll
2007-05-11 07:50 58904 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126280.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oezaesp.dll
2007-05-11 07:50 49688 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126281.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oezafra.dll
2007-05-11 07:50 50200 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126282.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oezaita.dll
2007-05-11 07:50 58904 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126283.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\oezajpn.dll
2007-05-11 07:50 43032 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126284.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otmfdeu.dll
2007-05-11 07:50 41496 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126285.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otmfenu.dll
2007-05-11 07:50 39960 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126286.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otmfesp.dll
2007-05-11 07:50 42520 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126287.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otmffra.dll
2007-05-11 07:50 42520 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126288.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otmfita.dll
2007-05-11 07:50 41496 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126289.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otmfjpn.dll
2007-05-11 07:50 37912 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126290.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otzadeu.dll
2007-05-11 07:50 54808 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126291.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otzaenu.dll
2007-05-11 07:50 43032 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126292.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otzaesp.dll
2007-05-11 07:50 45592 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126293.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otzafra.dll
2007-05-11 07:50 45592 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126294.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otzaita.dll
2007-05-11 07:50 54808 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126295.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\resources\otzajpn.dll
2007-05-11 07:50 40984 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126296.dll

C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\UNWISE.EXE
2002-07-26 17:02 153088 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126298.EXE

C:\Program Files\Zone Labs\ZoneAlarm\multiscan.exe
2007-09-06 16:14 26088 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126382.exe

C:\Program Files\Zone Labs\ZoneAlarm\repair\vsdb.dll
2007-09-06 16:14 79336 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126369.dll

C:\Program Files\Zone Labs\ZoneAlarm\repair\vsinit.dll
2007-09-06 16:14 157160 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126370.dll

C:\Program Files\Zone Labs\ZoneAlarm\repair\vsmon.exe
2007-09-06 16:14 75304 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126371.exe

C:\Program Files\Zone Labs\ZoneAlarm\repair\vsruledb.dll
2007-09-06 16:14 1345000 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126372.dll

C:\Program Files\Zone Labs\ZoneAlarm\repair\vsutil.dll
2007-09-06 16:14 472552 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126373.dll

C:\Program Files\Zone Labs\ZoneAlarm\zatutor.exe
2007-09-06 16:14 71144 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126377.exe

C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe
2007-09-10 13:52 666000 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126378.exe

C:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll
2007-09-06 16:14 50664 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126381.dll

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
2007-09-06 16:14 919016 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126380.exe

C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
2007-09-06 16:14 50664 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP687\A0126379.exe

2008-10-03 09:00 987136 C:\Richard\downloads-limeware\amv\MIXVIBES-PRO-5–KEYGEN—MIX-VIBES.EXE
2008-10-03 09:00 987136 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP696\A0126890.exe

C:\WINDOWS\84.exe
2008-10-03 09:01 399944 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP699\A0133140.exe

C:\WINDOWS\dw611.exe
2008-10-03 09:01 49152 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP696\A0126884.exe

C:\WINDOWS\DW611.EXE
2008-10-03 09:01 49152 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP700\A0133234.EXE

C:\WINDOWS\ism611.exe
2008-10-03 09:01 223076 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP700\A0133235.exe

C:\WINDOWS\LastGood.Tmp\system32\cdm.dll
2007-07-30 18:19 92504 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP685\A0126107.dll

C:\WINDOWS\LastGood.Tmp\system32\wuapi.dll
2007-07-30 18:19 549720 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP685\A0126108.dll

C:\WINDOWS\LastGood.Tmp\system32\wuauclt.exe
2007-07-30 18:19 53080 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP685\A0126109.exe

C:\WINDOWS\LastGood.Tmp\system32\wuaueng.dll
2007-07-30 18:19 1712984 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP685\A0126111.dll

C:\WINDOWS\LastGood.Tmp\system32\wucltui.dll
2007-07-30 18:19 325976 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP685\A0126112.dll

C:\WINDOWS\LastGood.Tmp\system32\wups.dll
2007-07-30 18:18 33624 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP685\A0126113.dll

C:\WINDOWS\LastGood.Tmp\system32\wups2.dll
2007-07-30 18:19 43352 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP685\A0126114.dll

C:\WINDOWS\LastGood.Tmp\system32\wuweb.dll
2007-07-30 18:19 203096 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP685\A0126115.dll

C:\WINDOWS\plate611.exe
2008-10-03 09:01 178616 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP700\A0133236.exe

C:\WINDOWS\system32\_{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll
2008-04-17 06:55 328704 {6CEDCFF8-DD90-4AE3-AC76-AD49E69AF4E9}\RP695\A0126800.dll

C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll-uninst
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a83dcfb6-5aea-da93-6f88-4585d113d937}]
2008-07-03 10:49 364544 –a—— C:\WINDOWS\system32\talueajxdeezlgk.dll

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
"msvideo7"= STV680tg.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2005-10-05 18:47 684032 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-14 05:42 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a—— 2002-06-17 07:41 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memorex Button Manager]
–a—— 2007-04-20 14:58 376832 C:\Program Files\Memorex Button Manager\MmrBtnMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-01 15:57 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
–a—— 2002-04-11 03:19 69632 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-08-26 17:14 36975 C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
–a—— 2008-05-28 10:33 1506544 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-09-16 07:39 69632 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
-ra—— 2004-01-15 07:33 49152 C:\WINDOWS\system32\VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

.
Contents of the 'Scheduled Tasks' folder

2007-05-11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 14:21]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 20:26:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-08 20:28:56
ComboFix-quarantined-files.txt 2008-10-09 01:28:47
ComboFix2.txt 2008-10-08 13:24:32

Pre-Run: 71,108,366,336 bytes free
Post-Run: 71,083,081,728 bytes free

310 — E O F — 2008-07-17 20:55:03
Hi Rorschach, Also getting XP RUNDLL error pop up:
“Error loading C:\ WINDOWS\system32\ (23as2067-cb6e-02dc-393d-44a78b449d7f).dll
The specified module could not be found.”

file appears to be deleted by CFScript in log:
ComboFix 08-10-07.06 - User 2008-10-08 20:24:57.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\WINDOWS\DW611.EXE
C:\WINDOWS\ism611.exe
C:\WINDOWS\plate611.exe
C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll-uninst.exe
Hello

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\unzipped
C:\Richard\downloads-limeware\amv\MIXVIBES-PRO-5–KEYGEN—MIX-VIBES.EXE

Folder::

DirLook::
C:\Richard\downloads-limeware

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    • C:\WINDOWS\inf\unregpn.exe
  • Click on the Upload button
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Hi Rorschach, followed instructions. Despite disabling McAfee AntiVirus & exiting program in Task Bar, McAfee pop ups still happened during ComboFix, as each time before, have no explanation for that! Can only uninstall if this is critical. These pop ups occurred at the following steps in the ComboFix scan:
- ComboFix clock setting
- Stage 1 & 2
- The last few seconds Preparing the log report
Here’s all the info, ComboFix log 1st, VirSCAN following. Still getting dll error on each boot up. However, no more IE hijacking, working fine, some usual sites bit slow, after 1.5hr surfing!

ComboFix 08-10-07.06 - User 2008-10-09 11:16:22.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.203 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Richard\downloads-limeware\amv\MIXVIBES-PRO-5–KEYGEN—MIX-VIBES.EXE
C:\unzipped
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Richard\downloads-limeware\amv\MIXVIBES-PRO-5–KEYGEN—MIX-VIBES.EXE

.
((((((((((((((((((((((((( Files Created from 2008-09-09 to 2008-10-09 )))))))))))))))))))))))))))))))
.

2008-10-08 20:45 . 2008-10-08 20:45 90,891 –a—— C:\WINDOWS\system32\talueajxdeezlgk.dll-uninst.exe
2008-10-08 04:28 . 2008-10-08 04:28 479,232 –a—— C:\WINDOWS\system32\talueajxdeezlgk.dll
2008-10-03 09:01 . 2008-10-03 09:01 d——– C:\unzipped
2008-09-19 20:38 . 2004-04-27 04:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-06 02:51 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-10-06 02:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-08 01:23 ——— d—–w C:\Program Files\DVDMagic
2008-08-21 14:20 ——— d—–w C:\Documents and Settings\User\Application Data\AdobeUM
2008-08-13 17:28 ——— d—–w C:\Program Files\LimeWire
2008-07-19 03:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 03:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 03:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 03:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 03:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 03:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 03:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 03:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
1998-08-24 16:09 10,000 -c–a-w C:\WINDOWS\inf\unregpn.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Richard\downloads-limeware —-

2008-10-03 09:00 987136 –a—— C:\Richard\downloads-limeware\amv\MIXVIBES-PRO-5–KEYGEN—MIX-VIBES.EXE
2008-07-19 14:11 805944 –a—— C:\Richard\downloads-limeware\MixVibes-Pro-5–KeyGen—MIX-VIBES.zip
2008-07-11 23:37 4898144 –a—— C:\Richard\downloads-limeware\LimeWireWin.exe
2008-07-04 14:44 975890 –a—— C:\Richard\downloads-limeware\amv\setup.exe
2007-12-18 18:55 7473662 –a—— C:\Richard\downloads-limeware\amv\AMV_Convert_400.zip
2007-11-27 20:17 17408 –ahs—- C:\Richard\downloads-limeware\Thumbs.db
2007-08-28 19:33 3378248 –a—— C:\Richard\downloads-limeware\amv\LimeWireWin.exe
2006-03-14 02:06 134144 –a—— C:\Richard\downloads-limeware\amv\MP3 Player Utilities 4.00\Msien.msi
2006-03-14 02:02 7312909 –a—— C:\Richard\downloads-limeware\amv\MP3 Player Utilities 4.00\MSI.CAB
2006-02-18 02:44 315392 –a—— C:\Richard\downloads-limeware\amv\MP3 Player Utilities 4.00\SETUP.EXE


((((((((((((((((((((((((((((( snapshot@2008-10-08_ 8.23.51.45 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a83dcfb6-5aea-da93-6f88-4585d113d937}]
2008-10-08 04:28 479232 –a—— C:\WINDOWS\system32\talueajxdeezlgk.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 163840]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"{88df1262-e41f-2709-de3f-c5c9193fe257}"="C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll" [BU]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 C:\WINDOWS\SOUNDMAN.EXE]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
"msvideo7"= STV680tg.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2005-10-05 18:47 684032 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-14 05:42 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a—— 2002-06-17 07:41 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memorex Button Manager]
–a—— 2007-04-20 14:58 376832 C:\Program Files\Memorex Button Manager\MmrBtnMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-01 15:57 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
–a—— 2002-04-11 03:19 69632 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-08-26 17:14 36975 C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
–a—— 2008-05-28 10:33 1506544 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-09-16 07:39 69632 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
-ra—— 2004-01-15 07:33 49152 C:\WINDOWS\system32\VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2008-06-25 43520]
S1 cdudf;cdudf;C:\WINDOWS\system32\drivers\cdudf.sys [2001-05-17 229664]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310v.sys [2006-07-10 99840]
S3 MTK;Media Technology Kernel Driver;C:\WINDOWS\system32\Drivers\mtk.sys [ ]
.
Contents of the 'Scheduled Tasks' folder

2007-05-11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 14:21]
.
- - - - ORPHANS REMOVED - - - -

BHO-{40b59abe-62e6-6731-fb2a-8a530199cd01} - C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-09 11:18:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-09 11:20:24
ComboFix-quarantined-files.txt 2008-10-09 16:20:20
ComboFix2.txt 2008-10-09 01:28:57
ComboFix3.txt 2008-10-08 13:24:32

Pre-Run: 71,041,511,424 bytes free
Post-Run: 71,016,517,632 bytes free

144 — E O F — 2008-07-17 20:55:03


VirSCAN.org Scanned Report :
Scanned time : 2008/10/09 10:35:17 (CDT)
Scanner results: All Scanners reported not find malware!
File Name : unregpn.exe
File Size : 10000 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : e1c5598ba8ff913905b0df0a17196478
SHA1 : bfb68317b46255dc10c47161c97e480b94cf9ffb
Online report : http://virscan.org/report/e26e0891cc9c9574…e7ba15430a.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.16 2008.10.08 2008-10-08 1.42 -
AhnLab V3 2008.10.09.03 2008.10.09 2008-10-09 0.94 -
AntiVir 7.8.1.34 7.0.7.19 2008-10-09 2.40 -
Antiy 2.0.18 20081008.1461687 2008-10-08 0.12 -
Arcavir 1.0.5 200810091141 2008-10-09 1.20 -
Authentium 5.1.1 200810012118 2008-10-01 1.04 -
AVAST! 3.0.1 081009-0 2008-10-09 0.00 -
AVG 7.5.52.442 270.7.6/1715 2008-10-08 1.65 -
BitDefender 7.60825.1853513 7.21206 2008-10-09 3.12 -
CA (VET) 9.0.0.143 31.6.6137 2008-10-09 4.36 -
ClamAV 0.94 8399 2008-10-09 0.01 -
Comodo 2.11 2.0.0.671 2008-10-09 0.98 -
CP Secure 1.1.0.715 2008.10.09 2008-10-09 6.05 -
Dr.Web 4.44.0.9170 2008.10.09 2008-10-09 3.28 -
ewido 4.0.0.2 2008.10.09 2008-10-09 2.96 -
F-Prot 4.4.4.56 20081008 2008-10-08 1.03 -
F-Secure 5.51.6100 2008.10.09.09 2008-10-09 0.05 -
Fortinet 2.81-3.113 9.627 2008-10-09 0.18 -
ViRobot 20081009 2008.10.09 2008-10-09 0.40 -
Ikarus T3.1.01.34 2008.10.09.71611 2008-10-09 3.48 -
JiangMin 11.0.706 2008.10.09 2008-10-09 1.26 -
Kaspersky 5.5.10 2008.10.09 2008-10-09 0.05 -
KingSoft 2008.9.8.18 2008.10.9.17 2008-10-09 0.68 -
McAfee 5.3.00 5401 2008-10-08 2.07 -
Microsoft 1.4005 2008.10.09 2008-10-09 4.51 -
mks_vir 2.01 2008.10.09 2008-10-09 1.87 -
Norman 5.93.01 5.93.00 2008-10-08 5.19 -
Panda 9.05.01 2008.10.08 2008-10-08 2.02 -
Trend Micro 8.700-1004 5.590.15 2008-10-09 0.03 -
Quick Heal 9.50 2008.10.08 2008-10-08 1.80 -
Rising 20.0 20.65.32.00 2008-10-09 0.76 -
Sophos 2.79.0 4.34 2008-10-09 1.79 -
Sunbelt 3.1.1708.1 2293 2008-10-08 0.63 -
Symantec 1.3.0.24 20081008.003 2008-10-08 0.05 -
nProtect 2008-10-09.00 2219711 2008-10-09 4.44 -
The Hacker [removed] v00103 2008-10-07 0.43 -
VBA32 3.12.8.6 20081008.2118 2008-10-08 1.36 -
VirusBuster 4.5.11.10 10.89.12/634150 2008-10-09 0.82 -
Hello


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\talueajxdeezlgk.dll-uninst.exe
C:\WINDOWS\system32\talueajxdeezlgk.dll
C:\Richard\downloads-limeware\amv\MIXVIBES-PRO-5–KEYGEN—MIX-VIBES.EXE
C:\Richard\downloads-limeware\MixVibes-Pro-5–KeyGen—MIX-VIBES.zip

Folder::
C:\unzipped

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Please do an online scan with Kaspersky WebScanner

Make sure you are using Internet Explorer for this. Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Hi Rorschach, before I continue with your new instructions, please tell me if I need to uninstall McAfee to eliminate the anti-virus warnings (see my previous reply). Would you be able to give me an idea of what the culprit is/was? Since IE appears to be no longer hijacked, could you provide some insight with what's going on & the need to continue further please? many thanks
Hi Rorschach, Thanks for the info on Vundo, was able to run MBAM, below are ComboFix & MBMA logs.
Went to Kaspersky, promoted for missing Java, installed Java v.6 thru link from Kaspersky, but unable to run their scan, continue to get prompt stating Java needed yet Java site confirms installed at: http://www.java.com/en/download/windows_ie…m:80&bhcp=1

However, now getting what appears to be Windows "Updates" button with "Turn Off" PC, also getting Windows pop up approx. every 15min. installing these "updates" - haven't attempted to download any updates from Microsoft unless Recovery Console did that - never had this before. Any ideas?

Please advise what to do, here's the other logs:

ComboFix 08-10-07.06 - User 2008-10-09 15:27:22.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.193 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Richard\downloads-limeware\amv\MIXVIBES-PRO-5–KEYGEN—MIX-VIBES.EXE
C:\Richard\downloads-limeware\MixVibes-Pro-5–KeyGen—MIX-VIBES.zip
C:\WINDOWS\system32\talueajxdeezlgk.dll
C:\WINDOWS\system32\talueajxdeezlgk.dll-uninst.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Richard\downloads-limeware\MixVibes-Pro-5–KeyGen—MIX-VIBES.zip
C:\unzipped
C:\unzipped\MixVibes-Pro-5–KeyGen—MIX-VIBES\MixVibes-Pro-5–KeyGen—MIX-VIBES.exe
C:\WINDOWS\system32\talueajxdeezlgk.dll-uninst.exe
C:\WINDOWS\system32\talueajxdeezlgk.dll

.
((((((((((((((((((((((((( Files Created from 2008-09-09 to 2008-10-09 )))))))))))))))))))))))))))))))
.

2008-10-09 09:49 . 2008-05-01 09:33 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-19 20:38 . 2004-04-27 04:40 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-06 02:51 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-10-06 02:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-08 01:23 ——— d—–w C:\Program Files\DVDMagic
2008-08-21 14:20 ——— d—–w C:\Documents and Settings\User\Application Data\AdobeUM
2008-08-13 17:28 ——— d—–w C:\Program Files\LimeWire
2008-07-19 03:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 03:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 03:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 03:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 03:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 03:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 03:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 03:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
1998-08-24 16:09 10,000 -c–a-w C:\WINDOWS\inf\unregpn.exe
.

((((((((((((((((((((((((((((( snapshot@2008-10-08_ 8.23.51.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-24 16:43:16 74,240 -c—-w C:\WINDOWS\system32\dllcache\mscms.dll
- 2006-10-19 02:47:16 414,208 -c–a-w C:\WINDOWS\system32\dllcache\msscp.dll
+ 2006-12-04 21:21:50 414,720 -c–a-w C:\WINDOWS\system32\dllcache\msscp.dll
- 2008-04-14 10:42:00 73,728 —-a-w C:\WINDOWS\system32\mscms.dll
+ 2008-06-24 16:43:16 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
- 2006-10-19 02:47:16 414,208 —-a-w C:\WINDOWS\system32\msscp.dll
+ 2006-12-04 21:21:50 414,720 —-a-w C:\WINDOWS\system32\msscp.dll
- 2008-03-27 10:40:24 60,416 ——w C:\WINDOWS\system32\tzchange.exe
+ 2008-07-11 12:42:28 62,976 ——w C:\WINDOWS\system32\tzchange.exe
- 2006-10-19 02:47:20 295,936 ——w C:\WINDOWS\system32\wmpeffects.dll
+ 2008-06-24 23:12:58 295,936 ——w C:\WINDOWS\system32\wmpeffects.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 163840]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"{88df1262-e41f-2709-de3f-c5c9193fe257}"="C:\WINDOWS\system32\{23ae2067-cb6e-02dc-393d-44a78b449d7f}.dll" [BU]
"SoundMan"="SOUNDMAN.EXE" [2004-09-16 C:\WINDOWS\SOUNDMAN.EXE]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
"msvideo7"= STV680tg.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2005-10-05 18:47 684032 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-14 05:42 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
–a—— 2002-06-17 07:41 188416 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Memorex Button Manager]
–a—— 2007-04-20 14:58 376832 C:\Program Files\Memorex Button Manager\MmrBtnMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-01 15:57 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
–a—— 2002-04-11 03:19 69632 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-08-26 17:14 36975 C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
–a—— 2008-05-28 10:33 1506544 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2004-09-16 07:39 69632 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
-ra—— 2004-01-15 07:33 49152 C:\WINDOWS\system32\VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=

R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2008-06-25 43520]
S1 cdudf;cdudf;C:\WINDOWS\system32\drivers\cdudf.sys [2001-05-17 229664]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310v.sys [2006-07-10 99840]
S3 MTK;Media Technology Kernel Driver;C:\WINDOWS\system32\Drivers\mtk.sys [ ]
.
Contents of the 'Scheduled Tasks' folder

2007-05-11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 14:21]
.
- - - - ORPHANS REMOVED - - - -

BHO-{a83dcfb6-5aea-da93-6f88-4585d113d937} - C:\WINDOWS\system32\talueajxdeezlgk.dll



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-09 15:29:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-09 15:31:51
ComboFix-quarantined-files.txt 2008-10-09 20:31:45
ComboFix2.txt 2008-10-09 01:28:57
ComboFix3.txt 2008-10-08 13:24:32

Pre-Run: 70,966,603,776 bytes free
Post-Run: 70,941,462,528 bytes free

144 — E O F — 2008-10-09 18:13:28

Malwarebytes' Anti-Malware 1.27
Database version: 1127
Windows 5.1.2600 Service Pack 3

10/9/2008 7:26:42 PM
mbam-log-2008-10-09 (19-26-42).txt

Scan type: Quick Scan
Objects scanned: 41312
Time elapsed: 4 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\banneradsgalore (Adware.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{88df1262-e41f-2709-de3f-c5c9193fe257} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI