[Resolved] Antivirus 2009
41 min read
Hopefully, by the time you read this, your log has appeared. If it doesn't:
- Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
- Click on Explore
- Click on Local Disk (C:) in the left-hand window pane
- Look for ComboFix.txt in the right-hand window pane and right click on it
- Put your cursor (arrow) on Open With
- Move your cursor to the new menu that opens and click on Choose Program…
- Click on Notepad
When file opens, Copy/Paste text here
You're doing good here but, I'm tired. I'm going to be. I'll review your log in 7 or 8 hours.
ComboFix 08-11-11.01 - Kim Eyler 2008-11-13 1:10:22.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.229 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Kim Eyler\Application Data\gadcom
c:\documents and settings\NetworkService\Local Settings\Temporary Internet Files\hpothb07.dat
c:\documents and settings\NetworkService\Local Settings\Temporary Internet Files\hpothb07.tif
c:\program files\icroso~1
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\AdCache
c:\windows\system32\AdCache\B_329_0_0_106800.htm
c:\windows\system32\AdCache\B_329_0_0_107400.htm
c:\windows\system32\AdCache\B_329_1_0_449200.gif
c:\windows\system32\AdCache\B_329_1_0_449600.gif
c:\windows\system32\AdCache\B_329_1_0_454300.gif
c:\windows\system32\AdCache\B_329_2_0_106800.htm
c:\windows\system32\AdCache\B_329_2_0_107400.htm
c:\windows\system32\AdCache\B_329_3_0_106800.htm
c:\windows\system32\AdCache\B_329_3_0_107400.htm
c:\windows\system32\AdCache\B_329_4_0_111600.htm
c:\windows\system32\AdCache\B_329_4_0_152400.htm
c:\windows\system32\AdCache\B_329_4_0_155300.htm
c:\windows\system32\AdCache\B_329_4_0_164100.htm
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_0_106800.htm
c:\windows\system32\cache329\B_329_0_0_107400.htm
c:\windows\system32\cache329\B_329_1_0_449200.gif
c:\windows\system32\cache329\B_329_1_0_449600.gif
c:\windows\system32\cache329\B_329_1_0_454300.gif
c:\windows\system32\cache329\B_329_2_0_106800.htm
c:\windows\system32\cache329\B_329_2_0_107400.htm
c:\windows\system32\cache329\B_329_3_0_106800.htm
c:\windows\system32\cache329\B_329_3_0_107400.htm
c:\windows\system32\cache329\B_329_4_0_111600.htm
c:\windows\system32\cache329\B_329_4_0_152400.htm
c:\windows\system32\cache329\B_329_4_0_155300.htm
c:\windows\system32\cache329\B_329_4_0_164100.htm
c:\windows\system32\cache329\t_B_329_0_0_106800.htm
c:\windows\system32\cache329\t_B_329_0_0_107400.htm
c:\windows\system32\cache329\t_B_329_2_0_106800.htm
c:\windows\system32\cache329\t_B_329_2_0_107400.htm
c:\windows\system32\cache329\t_B_329_3_0_106800.htm
c:\windows\system32\cache329\t_B_329_3_0_107400.htm
c:\windows\system32\cache329\t_B_329_4_0_111600.htm
c:\windows\system32\cache329\t_B_329_4_0_152400.htm
c:\windows\system32\cache329\t_B_329_4_0_155300.htm
c:\windows\system32\cache329\t_B_329_4_0_164100.htm
c:\windows\system32\MSINET.oca
c:\windows\system32\msupdate.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-10-13 to 2008-11-13 )))))))))))))))))))))))))))))))
.
2008-11-13 00:07 . 2008-11-13 00:07 d——– c:\documents and settings\LocalService\Application Data\McAfee
2008-11-12 23:30 . 2008-11-12 23:31 d——– c:\documents and settings\Kim Eyler\SmitfraudFix
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\documents and settings\Kim Eyler\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-11-12 23:13 d—-c— c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-10-22 16:10 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-11-12 23:13 . 2008-10-22 16:10 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-11-12 06:26 . 2008-11-12 06:26 1,393 –a—— c:\windows\imsins.BAK
2008-11-12 06:16 . 2008-10-24 06:21 455,296 ——— c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-11-12 06:15 . 2008-09-04 12:15 1,106,944 ——— c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2008-11-11 17:33 . 2008-11-11 18:41 d—-c— C:\SDAT
2008-11-11 17:30 . 2008-11-11 17:25 95,253,636 –a–c— C:\sdat5430.exe
2008-11-10 18:07 . 2008-11-12 23:32 2,568 –a—— c:\windows\SYSTEM32\tmp.reg
2008-11-10 16:41 . 2005-03-16 14:21 0 –ah-c— c:\documents and settings\Administrator\hpothb07.dat
2008-11-10 16:40 . 2005-03-02 00:57 d—-c— c:\documents and settings\Administrator\Application Data\Jasc Software Inc
2008-11-10 16:40 . 2005-03-02 00:57 d–h-c— c:\documents and settings\Administrator\Application Data\Gtek
2008-11-10 16:40 . 2008-11-10 16:41 d—-c— c:\documents and settings\Administrator
2008-11-10 16:33 . 2008-11-10 16:33 d——– c:\program files\Trend Micro
2008-11-10 16:28 . 2008-11-10 16:28 d——– c:\program files\CCleaner
2008-11-10 13:53 . 2008-11-10 16:48 d—-c— c:\documents and settings\All Users\Application Data\avg8
2008-11-09 09:50 . 2008-11-09 09:50 9,662 –a—— c:\windows\SYSTEM32\ZoneAlarmIconUS.ico
2008-11-09 09:50 . 2008-11-09 09:50 4,286 –a—— c:\windows\SYSTEM32\Jamster.ico
2008-11-09 09:34 . 2008-11-10 13:39 d–hs—- c:\windows\RXJpYyBFeWxlcg
2008-11-09 09:29 . 2008-11-09 09:29 d——– c:\windows\ooow
2008-11-09 09:29 . 2008-11-10 13:36 d——– c:\program files\Common Files\ooow
2008-11-08 12:11 . 2008-11-09 12:11 527 –a—— c:\windows\SYSTEM32\TDSSpaxt.dat
2008-11-08 09:03 . 2008-11-08 11:36 58 –a—— c:\windows\SYSTEM32\winwp.bmp
2008-11-08 08:59 . 2008-11-08 08:59 527 –a—— c:\windows\SYSTEM32\TDSSosvd.dat
2008-11-08 08:58 . 2008-11-08 08:58 10,000 –a—— c:\windows\SYSTEM32\jsne87fidgf.dll
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DRIVERS\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DLLCACHE\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DRIVERS\null.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DLLCACHE\null.sys
2008-11-08 08:58 . 2008-11-08 08:58 2 –a–c— C:\-1463443965
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\windows\SYSTEM32\sX3i19
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\temp\PRE45
2008-11-08 08:57 . 2008-11-08 08:57 150,528 –a—— c:\windows\SYSTEM32\mkrnl.exe
2008-11-08 08:56 . 2008-11-08 08:56 34,816 –a—— c:\windows\SYSTEM32\prun.exe
2008-11-06 06:29 . 2008-11-06 06:29 6,144 –ahsc— C:\Thumbs.db
2008-11-04 07:11 . 2008-11-04 07:11 d——– C:\MSI
2008-11-04 07:11 . 2008-11-04 07:11 52 –a—— c:\windows\FPRINCE.INI
2008-11-03 19:46 . 2008-11-03 19:46 d——– c:\windows\Reader Rabbit Creative Studio
2008-11-03 19:46 . 2000-12-21 07:43 194,048 –a—— c:\windows\RRPW.pol
2008-11-03 19:35 . 2008-11-03 19:35 d——– c:\program files\Disney Interactive
2008-11-03 19:33 . 2008-11-03 19:35 1,259 –a—— c:\windows\disney.ini
2008-11-03 19:22 . 2008-11-03 19:22 d——– c:\windows\WNBackup
2008-11-03 19:22 . 2008-11-11 17:31 d——– C:\KA
2008-11-03 19:22 . 1998-09-24 18:31 270,848 –a—— c:\windows\unwise.exe
2008-11-03 19:22 . 2008-11-03 19:22 218 –a—— c:\windows\KA.INI
2008-11-03 19:22 . 2008-11-03 19:22 60 –a—— c:\windows\SIERRA.INI
2008-11-03 19:12 . 2008-11-06 06:36 d——– c:\program files\The Learning Company
2008-10-31 15:50 . 2008-10-31 15:50 0 –a—— c:\windows\SETUP32.INI
2008-10-26 08:55 . 2008-10-15 11:34 337,408 ——— c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-15 02:11 . 2008-09-08 05:41 333,824 ——— c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-10-15 02:10 . 2008-08-14 05:11 2,189,184 ——— c:\windows\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-10-15 02:10 . 2008-08-14 05:09 2,145,280 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,066,048 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,023,936 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrpamp.exe
2008-10-15 02:10 . 2008-09-15 07:12 1,846,400 ——— c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2008-10-14 09:42 . 2008-10-14 09:42 d–hs—- c:\windows\ftpcache
2008-10-14 09:41 . 2004-03-29 15:23 90,112 –a—— c:\windows\unvise32.exe
2008-10-14 09:38 . 2008-10-14 09:38 d——– c:\program files\Hooked on Phonics Learning
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 21:51 ——— d—–w c:\documents and settings\Kim Eyler\Application Data\McAfee
2008-11-11 15:20 ——— dc—-w c:\documents and settings\All Users\Application Data\McAfee
2008-11-10 23:25 ——— d—–w c:\program files\Audible
2008-11-08 12:17 ——— d—–w c:\program files\Lx_cats
2008-11-06 13:04 ——— d—–w c:\program files\GamingSquared
2008-11-06 12:50 ——— d—–w c:\program files\Broderbund
2008-11-06 11:40 ——— d—–w c:\program files\Real
2008-11-06 11:39 ——— d—–w c:\program files\Kids Cam Show and Share Creativity Center
2008-11-06 11:38 ——— d—–w c:\program files\Dell Games
2008-11-06 11:33 ——— d—–w c:\program files\_uninstallation_info
2008-11-06 11:32 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-06 11:32 ——— d—–w c:\program files\PopCap Games
2008-11-06 11:31 ——— d—–w c:\program files\GameFiesta
2008-11-06 11:31 ——— d—–w c:\program files\Free Offers from Freeze.com
2008-11-04 00:35 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-09-18 10:58 ——— d—–w c:\program files\Blubster
2008-09-13 19:08 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-09-13 18:42 ——— d—–w c:\program files\Shockwave.com
2008-09-13 18:40 ——— d—–w c:\program files\RealArcade
2008-09-13 18:39 ——— d—–w c:\program files\Family Feud
2008-09-13 18:39 ——— d—–w c:\program files\Chuzzle Deluxe
2008-09-13 18:37 ——— d—–w c:\program files\AOL Games
2008-09-07 02:09 0 -c–a-w c:\program files\temp01
2006-02-02 14:59 322 -c-ha-w c:\documents and settings\Kim Eyler\hpothb07.dat
2006-02-02 14:56 169 -c-ha-w c:\documents and settings\NetworkService\hpothb07.dat
2005-08-14 15:55 0 -c-ha-w c:\documents and settings\LocalService\hpothb07.dat
2005-07-16 12:04 70,076 -c–a-w c:\documents and settings\Eric Eyler\Winsock2.reg
2005-03-16 19:21 368 -c-ha-w c:\documents and settings\Kim Eyler\Application Data\hpothb07.dat
2005-03-16 19:21 164 -c-ha-w c:\documents and settings\All Users\hpothb07.dat
2005-03-16 19:21 0 -c-ha-w c:\documents and settings\Default User\hpothb07.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c–a-w 408,576 2004-10-31 11:21:32 c:\dell\bak\PreODM.EXE
-c–a-w 307,200 2005-10-24 20:53:40 c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
-c–a-w 1,404,928 2004-10-14 21:42:54 c:\program files\Analog Devices\Core\bak\smax4pnp.exe
-c–a-w 429,568 2001-03-26 04:35:20 c:\program files\Browser Mouse\Browser Mouse\1.0\bak\lwbwheel.exe
-c–a-w 50,792 2006-04-20 17:10:13 c:\program files\Common Files\AOL\1135353641\ee\bak\AOLSoftware.exe
—-a-w 50,760 2006-05-10 00:24:16 c:\program files\Common Files\AOL\1135353641\ee\AOLSoftware.exe
-c–a-w 180,269 2005-03-05 02:07:39 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
-c–a-w 290,816 2004-04-12 02:15:14 c:\program files\Dell\Media Experience\bak\PCMService.exe
-c–a-w 306,688 2004-07-19 13:51:24 c:\program files\Dell Support\bak\DSAgnt.exe
-c–a-w 69,632 2002-04-11 09:19:34 c:\program files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe
-c–a-w 221,184 2003-09-04 02:12:44 c:\program files\Intel\Modem Event Monitor\bak\IntelMEM.exe
-c–a-w 36,975 2005-11-10 18:03:52 c:\program files\Java\jre1.5.0_06\bin\bak\jusched.exe
-c–a-w 94,208 2005-08-01 12:05:04 c:\program files\Lexmark 2300 Series\bak\ezprint.exe
-c–a-w 200,704 2005-07-21 06:07:22 c:\program files\Lexmark 2300 Series\bak\lxcgmon.exe
-c–a-w 299,008 2005-07-12 13:36:32 c:\program files\Lexmark Fax Solutions\bak\fm3032.exe
-c–a-w 892,928 2003-12-01 16:38:16 c:\program files\Logitech\iTouch\bak\iTouch.exe
-c–a-w 98,304 2005-03-02 06:01:57 c:\program files\QuickTime\bak\qttask.exe
—-a-w 282,624 2006-10-25 23:58:18 c:\program files\QuickTime\qttask.exe
-c–a-w 77,824 2005-09-20 14:32:24 c:\windows\SYSTEM32\bak\hkcmd.exe
-c–a-w 114,688 2005-09-20 14:36:20 c:\windows\SYSTEM32\bak\igfxpers.exe
-c–a-w 94,208 2005-09-20 14:35:40 c:\windows\SYSTEM32\bak\igfxtray.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Name of App"="c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe" [2006-03-10 667735]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.CDVC"= cdvccodc.dll
"VIDC.NTN1"= NUVision.ax
[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak easyshare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aim6]
–a—— 2008-08-06 10:21 50472 c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gadcom]
c:\documents and settings\Kim Eyler\Application Data\gadcom\gadcom.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe"=
"c:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Blubster\\Blubster.exe"=
"c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310v.sys [2006-07-18 99840]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd30d845-872b-11db-8a57-001111e20b6d}]
\Shell\AutoRun\command - E:\SH-S182M(TS-H652M).exe
.
Contents of the 'Scheduled Tasks' folder
2008-11-08 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\RUNDLL32.EXE [2008-04-13 19:12]
2008-11-07 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (MAIN-Kim Eyler).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []
2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{74891e76-ce67-4171-9676-ab71285d320a} - (no file)
WebBrowser-{74891E76-CE67-4171-9676-AB71285D320A} - (no file)
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Kim Eyler\Application Data\Mozilla\Firefox\Profiles\cpimp2gf.default\
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF -: plugin - c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 01:16:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Name of App = c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe??| ??????? ??????? ?B?????Kim Eyler?y?l?e?r???(??????|@??|????=??|Y??|????????@???x?????C?@??? ??????? ?B?????????????????????061210122311500?2?3?1?1?5?0?0???????????????????????????????????????????(?????G
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Logitech\MouseWare\system\EM_EXEC.EXE
c:\windows\SYSTEM32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\McAfee\MBK\MBackMonitor.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\AIM6\aolsoftware.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
c:\windows\SYSTEM32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-11-13 1:36:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-13 06:36:30
Pre-Run: 18,718,834,688 bytes free
Post-Run: 19,133,571,072 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
332 — E O F — 2008-11-12 11:28:56
Absolutely. Do it immediately.Should Windows Firewall be turned on?
I can't tell where you got infected. All I can tell you for sure is you don't have "this" virus. You've got at least half a dozen of various types. I'd say we are in the middle of fixing things. I believe I know most of the problems. The trick is to now fix them.
Please download SDFix and save it to your Desktop.
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
- Instead of Windows loading as normal, a menu with options should appear;
- Select the first option, to run Windows in Safe Mode, then press "Enter".
- Choose your usual user account.
- Open the SDFix folder and double click on RunThis.bat to start the script.
- Type Y and press Enter to begin the script.
- It will start cleaning your PC and then prompt you to press any key to Reboot.
- Press any key to restart the PC.
- Your system will take longer than normal to restart as the fixtool will be removing files.
- When the desktop loads the Fixtool will complete the removal and display Finished.
- Press any key to end the script and to load your desktop icons.
- A text file should automatically open, so please copy the contents and post them here.
Then
FindAWF
Click here to download FindAWF.exe and save it to your desktop.
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to Press any key to continue.
- Press 1 and then Enter, and the FindAWF tool will begin scanning your computer for the infected AWF files and the backups the trojan created.
- It may take a few minutes to complete so be patient.
- When it is complete, it will open a text file in notepad called AWF.txt which will automatically be saved to your desktop or to the same location as FindAWF.exe.
- Copy and paste the contents of the AWF.txt file in your next reply.
I did the first scan and here are the results
SDFix: Version 1.240
Run by [removed] on Thu 11-13-2008 at 11:01
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\-14634~1 - Deleted
C:\WINDOWS\SYSTEM32\TDSSOSVD.dat - Deleted
C:\WINDOWS\SYSTEM32\TDSSPAXT.dat - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 11:31:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe"="C:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe:*:Enabled:2300 Series Server"
"C:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe"="C:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe:*:Enabled:2300 Series Printer Status"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Blubster\\Blubster.exe"="C:\\Program Files\\Blubster\\Blubster.exe:*:Enabled:Blubster"
"C:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"="C:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"="C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Tue 24 Aug 2004 155,648 A..H. — "C:\DELL\PRIMOSDK.DLL"
Tue 24 Aug 2004 360,448 A..H. — "C:\DELL\PX.DLL"
Wed 28 Jul 2004 56,832 A..H. — "C:\DELL\PXCPYA64.EXE"
Wed 28 Jul 2004 108,544 A..H. — "C:\DELL\PXCPYI64.EXE"
Wed 18 Aug 2004 389,120 A..H. — "C:\DELL\PXDRV.DLL"
Mon 2 Aug 2004 20,576 A..H. — "C:\DELL\PXHELP20.SYS"
Mon 2 Aug 2004 54,976 A..H. — "C:\DELL\PXHELP64.SYS"
Mon 2 Aug 2004 32,272 A..H. — "C:\DELL\PXHELPER.SYS"
Mon 2 Aug 2004 26,720 A..H. — "C:\DELL\PXHLPA64.SYS"
Mon 2 Aug 2004 57,344 A..H. — "C:\DELL\PXHPINST.EXE"
Mon 2 Aug 2004 53,760 A..H. — "C:\DELL\PXINSA64.EXE"
Mon 2 Aug 2004 104,960 A..H. — "C:\DELL\PXINSI64.EXE"
Tue 24 Aug 2004 159,744 A..H. — "C:\DELL\PXMAS.DLL"
Wed 28 Jul 2004 57,344 A..H. — "C:\DELL\PXSETUP.EXE"
Tue 24 Aug 2004 339,968 A..H. — "C:\DELL\PXWAVE.DLL"
Thu 20 May 2004 28,672 A..H. — "C:\DELL\VXBLOCK.DLL"
Wed 12 Sep 2007 31 A..H. — "C:\WINDOWS\uccspecc.sys"
Tue 24 Aug 2004 155,648 A..H. — "C:\DELL\MEDIAEXE\PRIMOSDK.DLL"
Tue 24 Aug 2004 360,448 A..H. — "C:\DELL\MEDIAEXE\PX.DLL"
Wed 28 Jul 2004 56,832 A..H. — "C:\DELL\MEDIAEXE\PXCPYA64.EXE"
Wed 28 Jul 2004 108,544 A..H. — "C:\DELL\MEDIAEXE\PXCPYI64.EXE"
Wed 18 Aug 2004 389,120 A..H. — "C:\DELL\MEDIAEXE\PXDRV.DLL"
Mon 2 Aug 2004 20,576 A..H. — "C:\DELL\MEDIAEXE\PXHELP20.SYS"
Mon 2 Aug 2004 54,976 A..H. — "C:\DELL\MEDIAEXE\PXHELP64.SYS"
Mon 2 Aug 2004 32,272 A..H. — "C:\DELL\MEDIAEXE\PXHELPER.SYS"
Mon 2 Aug 2004 26,720 A..H. — "C:\DELL\MEDIAEXE\PXHLPA64.SYS"
Mon 2 Aug 2004 57,344 A..H. — "C:\DELL\MEDIAEXE\PXHPINST.EXE"
Mon 2 Aug 2004 53,760 A..H. — "C:\DELL\MEDIAEXE\PXINSA64.EXE"
Mon 2 Aug 2004 104,960 A..H. — "C:\DELL\MEDIAEXE\PXINSI64.EXE"
Tue 24 Aug 2004 159,744 A..H. — "C:\DELL\MEDIAEXE\PXMAS.DLL"
Wed 28 Jul 2004 57,344 A..H. — "C:\DELL\MEDIAEXE\PXSETUP.EXE"
Tue 24 Aug 2004 339,968 A..H. — "C:\DELL\MEDIAEXE\PXWAVE.DLL"
Thu 20 May 2004 28,672 A..H. — "C:\DELL\MEDIAEXE\VXBLOCK.DLL"
Wed 29 Oct 2008 848 A.SH. — "C:\WINDOWS\SYSTEM32\KGyGaAvL.sys"
Sat 9 Jul 2005 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 12 Sep 2008 20,487 A.SHR — "C:\Program Files\McAfee\MQC\MRU.bak"
Fri 12 Sep 2008 265 A.SHR — "C:\Program Files\McAfee\MQC\qcconf.bak"
Thu 17 Apr 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv03.tmp"
Sat 9 Jul 2005 4,348 A..H. — "C:\Documents and Settings\Kim Eyler\My Documents\My Music\License Backup\drmv1key.bak"
Sat 17 Sep 2005 20 A..H. — "C:\Documents and Settings\Kim Eyler\My Documents\My Music\License Backup\drmv1lic.bak"
Sat 9 Jul 2005 400 A.SH. — "C:\Documents and Settings\Kim Eyler\My Documents\My Music\License Backup\drmv2key.bak"
Wed 9 Mar 2005 88 A..H. — "C:\Documents and Settings\Kim Eyler\Application Data\GlobalSCAPE\CuteFTP\5.0\cuteftp.sys"
Sat 9 Jul 2005 4,348 …H. — "C:\Documents and Settings\Kim Eyler\Application Data\Real\Rhapsody\wmlicbackup\drmv1key.bak"
Sat 2 Dec 2006 20 A..H. — "C:\Documents and Settings\Kim Eyler\Application Data\Real\Rhapsody\wmlicbackup\drmv1lic.bak"
Sat 9 Jul 2005 400 A.SH. — "C:\Documents and Settings\Kim Eyler\Application Data\Real\Rhapsody\wmlicbackup\drmv2key.bak"
Wed 2 Mar 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Wed 2 Mar 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Fri 4 Mar 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Fri 4 Mar 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"
Mon 25 Apr 2005 8 A..H. — "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Finished!
off to run the next scan now.
Thanks for your answers to my questions, I appreciate you taking the time.
Be back after the next scan
Fix AWF Infection Step 2
Copy the file paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
EXAMPLE >>"C:\DELL\bak\PreODM.EXE"
"C:\Program Files\Dell Support\bak\DSAgnt.exe"
"C:\Program Files\Lexmark 2300 Series\bak\ezprint.exe"
"C:\Program Files\Lexmark 2300 Series\bak\lxcgmon.exe"
"C:\Program Files\Lexmark Fax Solutions\bak\fm3032.exe"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
"C:\WINDOWS\SYSTEM32\bak\igfxpers.exe"
"C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
"C:\Program Files\Analog Devices\Core\bak\smax4pnp.exe"
"C:\Program Files\Dell\Media Experience\bak\PCMService.exe"
"C:\Program Files\Hewlett-Packard\HP Share-to-Web\bak\hpgs2wnd.exe"
"C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe"
"C:\Program Files\Logitech\iTouch\bak\iTouch.exe"
"C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe"
"C:\Program Files\Browser Mouse\Browser Mouse\1.0\bak\lwbwheel.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
"C:\Program Files\Java\jre1.5.0_06\bin\bak\jusched.exe"
"C:\Program Files\Common Files\AOL\1135353641\ee\bak\AOLSoftware.exe"
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to "Press any key to continue".
- Press 2 then Enter
- Notepad will open a file named FindAWF.txt. It will appear with instructions to click below the line and paste the list of files to be restored.
- Right click below this line and select Edit, Paste, to paste the list of files copied to the clipboard earlier. Save and close the document.
- The program will proceed to move the legit files and will perform another scan for bak folders.
- It may take a few minutes to complete, so please be patient.
- When it is complete, it will open a text file in Notepad called AWF.txt.
- Please copy and paste the contents of the AWF.txt file in your next reply.
Fix AWF Infection Step 3
Copy the paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
EXAMPLE >>C:\DELL\bak
C:\Program Files\Dell Support\bak
C:\Program Files\Lexmark 2300 Series\bak
C:\Program Files\Lexmark 2300 Series\bak
C:\Program Files\Lexmark Fax Solutions\bak
C:\Program Files\QuickTime\bak
C:\WINDOWS\SYSTEM32\bak
C:\WINDOWS\SYSTEM32\bak
C:\WINDOWS\SYSTEM32\bak
C:\Program Files\Analog Devices\Core\bak
C:\Program Files\Dell\Media Experience\bak
C:\Program Files\Hewlett-Packard\HP Share-to-Web\bak
C:\Program Files\Intel\Modem Event Monitor\bak
C:\Program Files\Logitech\iTouch\bak
C:\Program Files\Adobe\Acrobat 7.0\Reader\bak
C:\Program Files\Browser Mouse\Browser Mouse\1.0\bak
C:\Program Files\Common Files\Real\Update_OB\bak
C:\Program Files\Java\jre1.5.0_06\bin\bak
C:\Program Files\Common Files\AOL\1135353641\ee\bak
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to "Press any key to continue".
- Select Option 3 from the menu and press Enter.
- Press any key to continue.
- A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
- Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
- The program will proceed to remove the folders and will perform another scan for bak folders.
- It may take a few minutes to complete so be patient.
- When it is complete, it will open a text file in Notepad called AWF.txt.
- Please copy and paste the contents of the AWF.txt file in your next reply.
When it's finished the tool will return to the main menu.
Press E to close FindAWF.
That's because I screwed up your script. The word example shouldn't be there.
We need to do that again without the errors
Fix AWF Infection Step 3
Copy the paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\DELL\bak
- Double-click on the FindAWF.exe file to run it.
- It will open a command prompt and ask you to "Press any key to continue".
- Select Option 3 from the menu and press Enter.
- Press any key to continue.
- A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of folders to be removed.
- Right click below this line and select Paste, to paste the list of folders copied to the clipboard earlier. Save and close the document.
- The program will proceed to remove the folders and will perform another scan for bak folders.
- It may take a few minutes to complete so be patient.
- When it is complete, it will open a text file in Notepad called AWF.txt.
- Please copy and paste the contents of the AWF.txt file in your next reply.
When it's finished the tool will return to the main menu.
Press E to close FindAWF.
Yesso THAT is all I am supposed to copy and paste into there?
Nope. You are correct that I screwed up my directions but I got away with it that time.also step 2 had the word example in it will we need to do that step again also?
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI