This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antivirus 2009

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok cool! It didn't give me the option 4 again just closed on it's own Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Thu 11-13-2008 The current time is: 16:08:18.82 bak folders found ~~~~~~~~~~~ Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ end of report
reyadawnbringer,

We're OK. Let's move on.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    DirLook::
    c:\windows\RXJpYyBFeWxlcg
    c:\windows\ooow
    c:\program files\Common Files\ooow
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ok here we go :)

ComboFix 08-11-12.01 - Kim Eyler 2008-11-13 17:18:52.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.251 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kim Eyler\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-10-13 to 2008-11-13 )))))))))))))))))))))))))))))))
.

2008-11-13 13:13 . 2005-09-20 09:36 114,688 –a—— c:\windows\SYSTEM32\igfxpers.exe
2008-11-13 13:13 . 2005-09-20 09:35 94,208 –a—— c:\windows\SYSTEM32\igfxtray.exe
2008-11-13 13:13 . 2005-09-20 09:32 77,824 –a—— c:\windows\SYSTEM32\hkcmd.exe
2008-11-13 10:59 . 2008-11-13 10:59 578,560 –a—— c:\windows\SYSTEM32\DLLCACHE\user32.dll
2008-11-13 10:54 . 2008-11-13 10:54 d——– c:\windows\ERUNT
2008-11-13 10:52 . 2008-11-13 11:36 d—-c— C:\SDFix
2008-11-13 00:07 . 2008-11-13 00:07 d——– c:\documents and settings\LocalService\Application Data\McAfee
2008-11-12 23:30 . 2008-11-12 23:31 d——– c:\documents and settings\Kim Eyler\SmitfraudFix
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\documents and settings\Kim Eyler\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-11-12 23:13 d—-c— c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-10-22 16:10 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-11-12 23:13 . 2008-10-22 16:10 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-11-12 06:26 . 2008-11-12 06:26 1,393 –a—— c:\windows\imsins.BAK
2008-11-12 06:16 . 2008-10-24 06:21 455,296 ——— c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-11-12 06:15 . 2008-09-04 12:15 1,106,944 ——— c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2008-11-11 17:33 . 2008-11-11 18:41 d—-c— C:\SDAT
2008-11-11 17:30 . 2008-11-11 17:25 95,253,636 –a–c— C:\sdat5430.exe
2008-11-10 18:07 . 2008-11-12 23:32 2,568 –a—— c:\windows\SYSTEM32\tmp.reg
2008-11-10 16:41 . 2005-03-16 14:21 0 –ah-c— c:\documents and settings\Administrator\hpothb07.dat
2008-11-10 16:40 . 2005-03-02 00:57 d—-c— c:\documents and settings\Administrator\Application Data\Jasc Software Inc
2008-11-10 16:40 . 2005-03-02 00:57 d–h-c— c:\documents and settings\Administrator\Application Data\Gtek
2008-11-10 16:40 . 2008-11-10 16:41 d—-c— c:\documents and settings\Administrator
2008-11-10 16:33 . 2008-11-10 16:33 d——– c:\program files\Trend Micro
2008-11-10 16:28 . 2008-11-10 16:28 d——– c:\program files\CCleaner
2008-11-10 13:53 . 2008-11-10 16:48 d—-c— c:\documents and settings\All Users\Application Data\avg8
2008-11-09 09:50 . 2008-11-09 09:50 9,662 –a—— c:\windows\SYSTEM32\ZoneAlarmIconUS.ico
2008-11-09 09:50 . 2008-11-09 09:50 4,286 –a—— c:\windows\SYSTEM32\Jamster.ico
2008-11-09 09:34 . 2008-11-10 13:39 d–hs—- c:\windows\RXJpYyBFeWxlcg
2008-11-09 09:29 . 2008-11-09 09:29 d——– c:\windows\ooow
2008-11-09 09:29 . 2008-11-10 13:36 d——– c:\program files\Common Files\ooow
2008-11-08 09:03 . 2008-11-08 11:36 58 –a—— c:\windows\SYSTEM32\winwp.bmp
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DRIVERS\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DLLCACHE\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DRIVERS\null.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DLLCACHE\null.sys
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\windows\SYSTEM32\sX3i19
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\temp\PRE45
2008-11-08 08:57 . 2008-11-08 08:57 150,528 –a—— c:\windows\SYSTEM32\mkrnl.exe
2008-11-08 08:56 . 2008-11-08 08:56 34,816 –a—— c:\windows\SYSTEM32\prun.exe
2008-11-06 06:29 . 2008-11-06 06:29 6,144 –ahsc— C:\Thumbs.db
2008-11-04 07:11 . 2008-11-04 07:11 d——– C:\MSI
2008-11-04 07:11 . 2008-11-04 07:11 52 –a—— c:\windows\FPRINCE.INI
2008-11-03 19:46 . 2008-11-03 19:46 d——– c:\windows\Reader Rabbit Creative Studio
2008-11-03 19:46 . 2000-12-21 07:43 194,048 –a—— c:\windows\RRPW.pol
2008-11-03 19:35 . 2008-11-03 19:35 d——– c:\program files\Disney Interactive
2008-11-03 19:33 . 2008-11-03 19:35 1,259 –a—— c:\windows\disney.ini
2008-11-03 19:22 . 2008-11-03 19:22 d——– c:\windows\WNBackup
2008-11-03 19:22 . 2008-11-11 17:31 d——– C:\KA
2008-11-03 19:22 . 1998-09-24 18:31 270,848 –a—— c:\windows\unwise.exe
2008-11-03 19:22 . 2008-11-03 19:22 218 –a—— c:\windows\KA.INI
2008-11-03 19:22 . 2008-11-03 19:22 60 –a—— c:\windows\SIERRA.INI
2008-11-03 19:12 . 2008-11-06 06:36 d——– c:\program files\The Learning Company
2008-10-31 15:50 . 2008-10-31 15:50 0 –a—— c:\windows\SETUP32.INI
2008-10-26 08:55 . 2008-10-15 11:34 337,408 ——— c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-15 02:11 . 2008-09-08 05:41 333,824 ——— c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-10-15 02:10 . 2008-08-14 05:11 2,189,184 ——— c:\windows\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-10-15 02:10 . 2008-08-14 05:09 2,145,280 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,066,048 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,023,936 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrpamp.exe
2008-10-15 02:10 . 2008-09-15 07:12 1,846,400 ——— c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2008-10-14 09:42 . 2008-10-14 09:42 d–hs—- c:\windows\ftpcache
2008-10-14 09:41 . 2004-03-29 15:23 90,112 –a—— c:\windows\unvise32.exe
2008-10-14 09:38 . 2008-10-14 09:38 d——– c:\program files\Hooked on Phonics Learning

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-13 20:18 ——— d—–w c:\program files\QuickTime
2008-11-13 20:18 ——— d—–w c:\program files\Lexmark Fax Solutions
2008-11-13 20:18 ——— d—–w c:\program files\Lexmark 2300 Series
2008-11-13 20:18 ——— d—–w c:\program files\Dell Support
2008-11-11 21:51 ——— d—–w c:\documents and settings\Kim Eyler\Application Data\McAfee
2008-11-11 15:20 ——— dc—-w c:\documents and settings\All Users\Application Data\McAfee
2008-11-10 23:25 ——— d—–w c:\program files\Audible
2008-11-08 12:17 ——— d—–w c:\program files\Lx_cats
2008-11-06 13:04 ——— d—–w c:\program files\GamingSquared
2008-11-06 12:50 ——— d—–w c:\program files\Broderbund
2008-11-06 11:40 ——— d—–w c:\program files\Real
2008-11-06 11:39 ——— d—–w c:\program files\Kids Cam Show and Share Creativity Center
2008-11-06 11:38 ——— d—–w c:\program files\Dell Games
2008-11-06 11:33 ——— d—–w c:\program files\_uninstallation_info
2008-11-06 11:32 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-06 11:32 ——— d—–w c:\program files\PopCap Games
2008-11-06 11:31 ——— d—–w c:\program files\GameFiesta
2008-11-06 11:31 ——— d—–w c:\program files\Free Offers from Freeze.com
2008-11-04 00:35 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-09-18 10:58 ——— d—–w c:\program files\Blubster
2008-09-13 19:08 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-09-13 18:42 ——— d—–w c:\program files\Shockwave.com
2008-09-13 18:40 ——— d—–w c:\program files\RealArcade
2008-09-13 18:39 ——— d—–w c:\program files\Family Feud
2008-09-13 18:39 ——— d—–w c:\program files\Chuzzle Deluxe
2008-09-13 18:37 ——— d—–w c:\program files\AOL Games
2008-09-07 02:09 0 -c–a-w c:\program files\temp01
2006-02-02 14:59 322 -c-ha-w c:\documents and settings\Kim Eyler\hpothb07.dat
2006-02-02 14:56 169 -c-ha-w c:\documents and settings\NetworkService\hpothb07.dat
2005-08-14 15:55 0 -c-ha-w c:\documents and settings\LocalService\hpothb07.dat
2005-07-16 12:04 70,076 -c–a-w c:\documents and settings\Eric Eyler\Winsock2.reg
2005-03-16 19:21 368 -c-ha-w c:\documents and settings\Kim Eyler\Application Data\hpothb07.dat
2005-03-16 19:21 164 -c-ha-w c:\documents and settings\All Users\hpothb07.dat
2005-03-16 19:21 0 -c-ha-w c:\documents and settings\Default User\hpothb07.dat
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of c:\program files\Common Files\ooow —-

2008-11-10 12:17 1536 –a—— c:\program files\Common Files\ooow\ooowh
2008-11-09 09:30 0 –a—— c:\program files\Common Files\ooow\ooowl.lck
2008-11-09 09:29 0 –a—— c:\program files\Common Files\ooow\ooowm.lck
2008-11-09 09:29 0 –a—— c:\program files\Common Files\ooow\ooowa.lck
2004-04-19 21:26 4933375 –a—— c:\program files\Common Files\ooow\ooowd\class-barrel
2004-04-19 21:26 1234193 –a—— c:\program files\Common Files\ooow\ooowd\vocabulary

—- Directory of c:\windows\ooow —-

2008-11-09 09:32 4427 –a—— c:\windows\ooow\ooow.dat
2002-07-26 17:02 153088 –a—— c:\windows\ooow\wu

—- Directory of c:\windows\RXJpYyBFeWxlcg —-



((((((((((((((((((((((((((((( snapshot@2008-11-13_ 1.33.47.75 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2008-11-13 15:54:37 6,643,712 —-a-w c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-11-13 15:54:37 114,688 —-a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-11-13 15:54:21 6,643,712 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-11-13 15:54:21 114,688 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-11-13 01:45:17 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2008-11-13 20:19:05 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2008-11-13 01:45:17 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-13 20:19:05 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Name of App"="c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe" [2006-03-10 667735]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-03-02 98304]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.CDVC"= cdvccodc.dll
"VIDC.NTN1"= NUVision.ax

[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak easyshare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aim6]
–a—— 2008-08-06 10:21 50472 c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe"=
"c:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Blubster\\Blubster.exe"=
"c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020

R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310v.sys [2006-07-18 99840]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd30d845-872b-11db-8a57-001111e20b6d}]
\Shell\AutoRun\command - E:\SH-S182M(TS-H652M).exe
.
Contents of the 'Scheduled Tasks' folder

2008-11-08 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\RUNDLL32.EXE [2008-04-13 19:12]

2008-11-07 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (MAIN-Kim Eyler).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []

2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-gadcom - c:\documents and settings\Kim Eyler\Application Data\gadcom\gadcom.exe



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 17:32:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Name of App = c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe??|P???????P??????? ?B?????Kim Eyler?y?l?e?r???(??????|@??|????=??|Y??|????????x???x?????C?x???P??????? ?B?????????????????????061210122311500?2?3?1?1?5?0?0???????????????????????????????????????0???(?????G

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\McAfee\MBK\MBackMonitor.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Logitech\MouseWare\system\EM_EXEC.EXE
c:\program files\AIM6\aolsoftware.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-11-13 17:44:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-13 22:44:08
ComboFix2.txt 2008-11-13 06:37:05

Pre-Run: 22,370,394,112 bytes free
Post-Run: 22,523,985,920 bytes free

259 — E O F — 2008-11-12 11:28:56
reyadawnbringer,

Do any of these file/programs mean anything to you? I'm having trouble figuring out what they are.
—- Directory of c:\program files\Common Files\ooow —-

2008-11-10 12:17 1536 –a—— c:\program files\Common Files\ooow\ooowh
2008-11-09 09:30 0 –a—— c:\program files\Common Files\ooow\ooowl.lck
2008-11-09 09:29 0 –a—— c:\program files\Common Files\ooow\ooowm.lck
2008-11-09 09:29 0 –a—— c:\program files\Common Files\ooow\ooowa.lck
2004-04-19 21:26 4933375 –a—— c:\program files\Common Files\ooow\ooowd\class-barrel
2004-04-19 21:26 1234193 –a—— c:\program files\Common Files\ooow\ooowd\vocabulary

—- Directory of c:\windows\ooow —-

2008-11-09 09:32 4427 –a—— c:\windows\ooow\ooow.dat
2002-07-26 17:02 153088 –a—— c:\windows\ooow\wu

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 7.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u7-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

Then

Now that your able to get connected on the internet, please start Mbam again, update it, and run a new scan.

Post back here with any information you have about those programs,
The new Mbam report
A new HijackThis log.
Ok I have done everything so far except Mbam is still running. I was able to update it :woot: The bad news is it says it has found 3 infections already :( :smack: The java update went well :) I will post the report and the new hijack as soon as all of these scans are done :) Thank you again SOOOO much! :notworthy:
Sorry about those odd program names, they don't mean anything to me. I saw them before when scanning and thought they seemed odd. Ok here are the results of the Mbam Malwarebytes' Anti-Malware 1.30 Database version: 1396 Windows 5.1.2600 Service Pack 3 11-13-2008 8:10:30 PM mbam-log-2008-11-13 (20-10-30).txt Scan type: Quick Scan Objects scanned: 57549 Time elapsed: 7 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c1-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e596df5f-4239-4d40-8367-ebadf0165917} (Rogue.Installer) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\SYSTEM32\mkrnl.exe (Rogue.Installer) -> Quarantined and deleted successfully. About to run hijack this now :)
ok I let it remove the items and then ran hijack this

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:14:03, on 11-13-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\AIM6\aolsoftware.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} (Keynote Connector Launcher 2) - http://webeffective.keynote.com/applicatio…torLauncher.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag4716.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} (Rite Aid One Hour Photo Online Control) - https://photos.riteaid.com/control/RiteAidO…PhotoOnline.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 9597 bytes



I have to put my little one to bed and then I'll check back in again :thumbup:
reyadawnbringer,

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.



Viewpoint Manager is considered as foistware instead of malware since it is often installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
It is STRONGLY recommended that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove the Viewpoint component
  • Do the same for each Viewpoint component.

There is also signs of Party Poker and some other poker sites. Please see here. I'd bet that at least some of your adware came from these sites.

While we're at it, I'm going to delete those strange named folders. I don't know what they are and they creep me out. :)

Disable your protection programs as we did before.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - (no file)
      O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
      O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
      O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
      O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
      O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
      O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)

  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    Folder::
    c:\program files\Common Files\ooow
    c:\windows\ooow
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan. Be advised that this scan will take a couple hours. You might want to let it run while you sleep.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
here is the combofix log, I am going to run the Kapersky thing and head to bed and let it crunch. See you tomorrow. Thanks again :)


ComboFix 08-11-12.01 - Kim Eyler 2008-11-13 22:58:52.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.148 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kim Eyler\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\ooow
c:\program files\Common Files\ooow\ooowa.lck
c:\program files\Common Files\ooow\ooowd\class-barrel
c:\program files\Common Files\ooow\ooowd\vocabulary
c:\program files\Common Files\ooow\ooowh
c:\program files\Common Files\ooow\ooowl.lck
c:\program files\Common Files\ooow\ooowm.lck
c:\windows\ooow
c:\windows\ooow\ooow.dat
c:\windows\ooow\wu

.
((((((((((((((((((((((((( Files Created from 2008-10-14 to 2008-11-14 )))))))))))))))))))))))))))))))
.

2008-11-13 19:40 . 2008-06-10 02:32 73,728 –a—— c:\windows\SYSTEM32\javacpl.cpl
2008-11-13 19:39 . 2008-11-13 19:39 d——– c:\program files\Common Files\Java
2008-11-13 13:13 . 2005-09-20 09:36 114,688 –a—— c:\windows\SYSTEM32\igfxpers.exe
2008-11-13 13:13 . 2005-09-20 09:35 94,208 –a—— c:\windows\SYSTEM32\igfxtray.exe
2008-11-13 13:13 . 2005-09-20 09:32 77,824 –a—— c:\windows\SYSTEM32\hkcmd.exe
2008-11-13 10:59 . 2008-11-13 10:59 578,560 –a—— c:\windows\SYSTEM32\DLLCACHE\user32.dll
2008-11-13 10:54 . 2008-11-13 10:54 d——– c:\windows\ERUNT
2008-11-13 10:52 . 2008-11-13 11:36 d—-c— C:\SDFix
2008-11-13 00:07 . 2008-11-13 00:07 d——– c:\documents and settings\LocalService\Application Data\McAfee
2008-11-12 23:30 . 2008-11-12 23:31 d——– c:\documents and settings\Kim Eyler\SmitfraudFix
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-12 23:13 . 2008-11-12 23:13 d——– c:\documents and settings\Kim Eyler\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-11-12 23:13 d—-c— c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-12 23:13 . 2008-10-22 16:10 38,496 –a—— c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-11-12 23:13 . 2008-10-22 16:10 15,504 –a—— c:\windows\SYSTEM32\DRIVERS\mbam.sys
2008-11-12 06:26 . 2008-11-12 06:26 1,393 –a—— c:\windows\imsins.BAK
2008-11-12 06:16 . 2008-10-24 06:21 455,296 ——— c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2008-11-12 06:15 . 2008-09-04 12:15 1,106,944 ——— c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2008-11-11 17:33 . 2008-11-11 18:41 d—-c— C:\SDAT
2008-11-11 17:30 . 2008-11-11 17:25 95,253,636 –a–c— C:\sdat5430.exe
2008-11-10 18:07 . 2008-11-12 23:32 2,568 –a—— c:\windows\SYSTEM32\tmp.reg
2008-11-10 16:41 . 2005-03-16 14:21 0 –ah-c— c:\documents and settings\Administrator\hpothb07.dat
2008-11-10 16:40 . 2005-03-02 00:57 d—-c— c:\documents and settings\Administrator\Application Data\Jasc Software Inc
2008-11-10 16:40 . 2005-03-02 00:57 d–h-c— c:\documents and settings\Administrator\Application Data\Gtek
2008-11-10 16:40 . 2008-11-10 16:41 d—-c— c:\documents and settings\Administrator
2008-11-10 16:33 . 2008-11-10 16:33 d——– c:\program files\Trend Micro
2008-11-10 16:28 . 2008-11-10 16:28 d——– c:\program files\CCleaner
2008-11-10 13:53 . 2008-11-10 16:48 d—-c— c:\documents and settings\All Users\Application Data\avg8
2008-11-09 09:50 . 2008-11-09 09:50 9,662 –a—— c:\windows\SYSTEM32\ZoneAlarmIconUS.ico
2008-11-09 09:50 . 2008-11-09 09:50 4,286 –a—— c:\windows\SYSTEM32\Jamster.ico
2008-11-09 09:34 . 2008-11-10 13:39 d–hs—- c:\windows\RXJpYyBFeWxlcg
2008-11-08 09:03 . 2008-11-08 11:36 58 –a—— c:\windows\SYSTEM32\winwp.bmp
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DRIVERS\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 4,224 –a—— c:\windows\SYSTEM32\DLLCACHE\beep.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DRIVERS\null.sys
2008-11-08 08:58 . 2004-08-04 06:00 2,944 –a—— c:\windows\SYSTEM32\DLLCACHE\null.sys
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\windows\SYSTEM32\sX3i19
2008-11-08 08:57 . 2008-11-08 08:57 d——– c:\temp\PRE45
2008-11-06 06:29 . 2008-11-06 06:29 6,144 –ahsc— C:\Thumbs.db
2008-11-04 07:11 . 2008-11-04 07:11 d——– C:\MSI
2008-11-04 07:11 . 2008-11-04 07:11 52 –a—— c:\windows\FPRINCE.INI
2008-11-03 19:46 . 2008-11-03 19:46 d——– c:\windows\Reader Rabbit Creative Studio
2008-11-03 19:46 . 2000-12-21 07:43 194,048 –a—— c:\windows\RRPW.pol
2008-11-03 19:35 . 2008-11-03 19:35 d——– c:\program files\Disney Interactive
2008-11-03 19:33 . 2008-11-03 19:35 1,259 –a—— c:\windows\disney.ini
2008-11-03 19:22 . 2008-11-03 19:22 d——– c:\windows\WNBackup
2008-11-03 19:22 . 2008-11-11 17:31 d——– C:\KA
2008-11-03 19:22 . 1998-09-24 18:31 270,848 –a—— c:\windows\unwise.exe
2008-11-03 19:22 . 2008-11-03 19:22 218 –a—— c:\windows\KA.INI
2008-11-03 19:22 . 2008-11-03 19:22 60 –a—— c:\windows\SIERRA.INI
2008-11-03 19:12 . 2008-11-06 06:36 d——– c:\program files\The Learning Company
2008-10-31 15:50 . 2008-10-31 15:50 0 –a—— c:\windows\SETUP32.INI
2008-10-26 08:55 . 2008-10-15 11:34 337,408 ——— c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2008-10-15 02:11 . 2008-09-08 05:41 333,824 ——— c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-10-15 02:10 . 2008-08-14 05:11 2,189,184 ——— c:\windows\SYSTEM32\DLLCACHE\ntoskrnl.exe
2008-10-15 02:10 . 2008-08-14 05:09 2,145,280 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,066,048 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2008-10-15 02:10 . 2008-08-14 04:33 2,023,936 ——— c:\windows\SYSTEM32\DLLCACHE\ntkrpamp.exe
2008-10-15 02:10 . 2008-09-15 07:12 1,846,400 ——— c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2008-10-14 09:42 . 2008-10-14 09:42 d–hs—- c:\windows\ftpcache
2008-10-14 09:41 . 2004-03-29 15:23 90,112 –a—— c:\windows\unvise32.exe
2008-10-14 09:38 . 2008-10-14 09:38 d——– c:\program files\Hooked on Phonics Learning

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 03:48 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-14 00:40 ——— d—–w c:\program files\Java
2008-11-13 20:18 ——— d—–w c:\program files\QuickTime
2008-11-13 20:18 ——— d—–w c:\program files\Lexmark Fax Solutions
2008-11-13 20:18 ——— d—–w c:\program files\Lexmark 2300 Series
2008-11-13 20:18 ——— d—–w c:\program files\Dell Support
2008-11-11 21:51 ——— d—–w c:\documents and settings\Kim Eyler\Application Data\McAfee
2008-11-11 15:20 ——— dc—-w c:\documents and settings\All Users\Application Data\McAfee
2008-11-10 23:25 ——— d—–w c:\program files\Audible
2008-11-08 12:17 ——— d—–w c:\program files\Lx_cats
2008-11-06 13:04 ——— d—–w c:\program files\GamingSquared
2008-11-06 12:50 ——— d—–w c:\program files\Broderbund
2008-11-06 11:40 ——— d—–w c:\program files\Real
2008-11-06 11:39 ——— d—–w c:\program files\Kids Cam Show and Share Creativity Center
2008-11-06 11:38 ——— d—–w c:\program files\Dell Games
2008-11-06 11:33 ——— d—–w c:\program files\_uninstallation_info
2008-11-06 11:32 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-06 11:32 ——— d—–w c:\program files\PopCap Games
2008-11-06 11:31 ——— d—–w c:\program files\GameFiesta
2008-11-06 11:31 ——— d—–w c:\program files\Free Offers from Freeze.com
2008-11-04 00:35 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-09-18 10:58 ——— d—–w c:\program files\Blubster
2008-09-07 02:09 0 -c–a-w c:\program files\temp01
2006-02-02 14:59 322 -c-ha-w c:\documents and settings\Kim Eyler\hpothb07.dat
2006-02-02 14:56 169 -c-ha-w c:\documents and settings\NetworkService\hpothb07.dat
2005-08-14 15:55 0 -c-ha-w c:\documents and settings\LocalService\hpothb07.dat
2005-07-16 12:04 70,076 -c–a-w c:\documents and settings\Eric Eyler\Winsock2.reg
2005-03-16 19:21 368 -c-ha-w c:\documents and settings\Kim Eyler\Application Data\hpothb07.dat
2005-03-16 19:21 164 -c-ha-w c:\documents and settings\All Users\hpothb07.dat
2005-03-16 19:21 0 -c-ha-w c:\documents and settings\Default User\hpothb07.dat
.

((((((((((((((((((((((((((((( snapshot@2008-11-13_ 1.33.47.75 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2008-11-13 15:54:37 6,643,712 —-a-w c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-11-13 15:54:37 114,688 —-a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-11-13 15:54:21 6,643,712 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-11-13 15:54:21 114,688 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-11-13 01:45:17 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2008-11-14 00:19:02 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2008-11-13 01:45:17 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-14 00:19:02 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-11-13 01:45:17 32,768 -c–a-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-14 00:19:02 32,768 –sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2005-11-10 16:27:06 49,248 -c–a-w c:\windows\SYSTEM32\java.exe
+ 2008-06-10 06:21:01 135,168 —-a-w c:\windows\SYSTEM32\java.exe
- 2005-11-10 16:27:16 49,250 -c–a-w c:\windows\SYSTEM32\javaw.exe
+ 2008-06-10 06:21:04 135,168 —-a-w c:\windows\SYSTEM32\javaw.exe
- 2005-11-10 18:03:54 127,078 -c–a-w c:\windows\SYSTEM32\javaws.exe
+ 2008-06-10 07:32:34 139,264 —-a-w c:\windows\SYSTEM32\javaws.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-08-06 50472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Name of App"="c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe" [2006-03-10 667735]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-03-02 98304]
"LXCGCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 73728]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Logitech Utility"="Logi_MwX.Exe" [2003-11-07 c:\windows\LOGI_MWX.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.CDVC"= cdvccodc.dll
"VIDC.NTN1"= NUVision.ax

[HKLM\~\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak easyshare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aim6]
–a—— 2008-08-06 10:21 50472 c:\program files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\KODAK\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1135353641\\ee\\aim6.exe"=
"c:\\WINDOWS\\SYSTEM32\\lxcgcoms.exe"=
"c:\\WINDOWS\\SYSTEM32\\SPOOL\\DRIVERS\\W32X86\\3\\lxcgpswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Blubster\\Blubster.exe"=
"c:\\WINDOWS\\SYSTEM32\\DPVSETUP.EXE"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020

S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310v.sys [2006-07-18 99840]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd30d845-872b-11db-8a57-001111e20b6d}]
\Shell\AutoRun\command - E:\SH-S182M(TS-H652M).exe
.
Contents of the 'Scheduled Tasks' folder

2008-11-08 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\RUNDLL32.EXE [2008-04-13 19:12]

2008-11-07 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (MAIN-Kim Eyler).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []

2008-10-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2008-11-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 23:07:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Name of App = c:\program files\SAMSUNG\FW LiveUpdate\Liveupdate.exe??| ??????? ??????? ?B?????Kim Eyler?y?l?e?r???(??????|@??|????=??|Y??|????????@???x?????C?@??? ??????? ?B?????????????????????061210122311500?2?3?1?1?5?0?0???????????????????????????????????????????(?????G

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Logitech\MouseWare\system\EM_EXEC.EXE
c:\windows\SYSTEM32\CTSVCCDA.EXE
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\McAfee\MBK\MBackMonitor.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\AIM6\aolsoftware.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-11-13 23:20:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-14 04:19:46
ComboFix2.txt 2008-11-13 22:44:22
ComboFix3.txt 2008-11-13 06:37:05

Pre-Run: 22,289,358,848 bytes free
Post-Run: 22,291,251,200 bytes free

260 — E O F — 2008-11-12 11:28:56
Thanks, hope you got a good nights sleep as well

Ok here is the Kaspersky Scan


——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, November 14, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, November 13, 2008 18:50:55
Records in database: 1383528
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 150269
Threat name: 8
Infected objects: 15
Suspicious objects: 0
Duration of the scan: 02:46:07


File name / Threat name / Threats count
C:\Documents and Settings\Kim Eyler\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Kim Eyler\Desktop\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\AD Balster.zip Infected: not-a-virus:AdWare.Win32.Megap.a 1
C:\Documents and Settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\Cool System Tools.zip Infected: not-a-virus:Monitor.Win32.KeyKey.121 5
C:\Documents and Settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\Easy JAVA Pop Up.zip Infected: Trojan-Downloader.Win32.Agent.ksh 1
C:\Documents and Settings\Kim Eyler\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\msupdate.exe.vir Infected: Trojan.Win32.FraudPack.guu 1
C:\WINDOWS\SYSTEM32\cinstaller_xp.msi Infected: not-a-virus:Server-Proxy.Win32.MarketScore.s 2
C:\WINDOWS\SYSTEM32\cinstaller_xp.msi Infected: not-a-virus:AdWare.Win32.RK.m 1
C:\WINDOWS\SYSTEM32\cinstaller_xp.msi Infected: not-a-virus:AdWare.Win32.RK.k 1

The selected area was scanned.





and here is the new Hijack this scan


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:33:06, on 11-14-2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\Liveupdate.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by24fd.bay24.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} (Keynote Connector Launcher 2) - http://webeffective.keynote.com/applicatio…torLauncher.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag4716.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} (Rite Aid One Hour Photo Online Control) - https://photos.riteaid.com/control/RiteAidO…PhotoOnline.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

–
End of file - 8475 bytes


Ok on a side note, last night when I was removing java and such I noticed a program called GamesPackMy I tried to uninstall and it says something about could not remove install file exe I was going to repeat it word for word but not the add/remove program is locked. It shows it was last used today and obviously it wasn't. My daughter hasn't been on this computer to play and of the games she downloaded since at least last weekend? :blush: Is this likely viral?

Also, the computer is still set on military time and when I double click it to change it, it shows EST time but I can't get it to change to a regular time :pullhair:
One more thing, my McAfee also ran a scan last night and found 13 infections. I did a print screen to show you what it says, 📎mcafeescan.JPG should I check the boxes and go forward with removal or quarantine or will we be taking care of those from the Kaspersky scan?
reyadawnbringer,

You say you saw the gamespackmy thing. Where? In your Add/Remove programs panel?

We will take care of your clock as part of our cleanup. ComboFix did it.
Those files mcAfee found appear to be in your system restore files that we will be cleaning out. There is no problem letting McAfee remove them.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\Documents and Settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\AD Balster.zip
    C:\Documents and Settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\Cool System Tools.zip
    C:\Documents and Settings\Kim Eyler\My Documents\Ebay Downloads\My eBooks\Software\Easy JAVA Pop Up.zip
    C:\WINDOWS\SYSTEM32\cinstaller_xp.msi
    E:\SH-S182M(TS-H652M).exe
    
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd30d845-872b-11db-8a57-001111e20b6d}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI