G'day BHowett,
new info for you, an item of note, and a concern.
First, the logs you requested are below. I ran the ComboFix update, went down the punch list in your reply to me, clicked on the Symantec link to remove lingering files or Symantec processes, and got totally locked up. Note that upon reboot I lost the ComboFix report, so ran another this morning after I ran Kaspersky's overnight. I'll try the Symantec link and deletion again later.
The removals from ATF's Atribune were overpowering . . . 22.xMB! That's quite a bonus to this, as I clean all cache files before every shutdown (except Java, never knew it was there).
BTW, what is a prefetch, and do I need to keep them? rsvp if you have an extra minute.
The concern is that after running ComboFix I receive a stream of requests from both my Checkpoint Integrity firewall and also Spybot asking for approvals to allow applications and access. I allow all, following your suggestion. But I am in an awkward position, as some are suggested by Spybot as shady, like ctfmon.exe. Since I see that ComboFix still cannot access tempfile01, am I letting the problems back in?
Finally, here are the logs you requested. Note the times and dates on the scans.
Next steps?
thx,
paultpa
ComboFix 08-12-29.01 - Paul A. Parone 2008-12-30 7:23:57.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.640 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Paul A. Parone\Desktop\CFScript.txt.txt
AV: Webroot AntiVirus with AntiSpyware *On-access scanning enabled* (Updated)
FW: Webroot Internet Security Essentials *disabled*
FW: Integrity Flex Firewall *enabled*
* Created a new restore point
FILE ::
c:\windows\system32\qnbukjdd.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Internet Logs\IAMDB.RDB
c:\windows\Internet Logs\IBM-546DEA067E3.ldb
c:\windows\Internet Logs\xDB1.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\ZALog.txt
c:\windows\Internet Logs . . . . failed to delete
c:\windows\Internet Logs\fwdbglog.txt . . . . failed to delete
c:\windows\Internet Logs\fwpktlog.txt . . . . failed to delete
c:\windows\Internet Logs\tvDebug.log . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-30 )))))))))))))))))))))))))))))))
.
2008-12-30 07:19 . 2008-12-30 07:20 d——– C:\32788R22FWJFW
2008-12-29 20:09 . 2008-12-30 07:37 d——– c:\windows\Internet Logs
2008-12-28 13:56 . 2008-12-28 13:55 2,888,402 -ra—— c:\program files\ComboFix.exe
2008-12-24 07:36 . 2008-12-24 07:36 d——– c:\documents and settings\Paul A. Parone\.java
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\documents and settings\Paul A. Parone\Application Data\Malwarebytes
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-17 17:05 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-17 17:05 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-15 16:37 . 2008-12-25 10:34 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\program files\Webroot
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\program files\AskSBar
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\documents and settings\Paul A. Parone\Application Data\Webroot
2008-12-14 14:51 . 2008-12-14 15:05 d——– c:\documents and settings\All Users\Application Data\Webroot
2008-12-14 14:51 . 2008-12-14 14:51 d——– C:\Binaries
2008-12-14 14:51 . 2008-11-13 17:11 1,553,272 –a—— c:\windows\WRSetup.dll
2008-12-14 14:46 . 2008-12-14 14:46 164 –a—— C:\install.dat
2008-12-13 20:51 . 2008-12-13 20:51 4,474 –a—— c:\windows\GATHER.KM
2008-12-13 20:42 . 2008-12-13 20:42 d——– c:\program files\Kaspersky Lab
2008-12-13 19:59 . 2008-12-13 19:59 27 –a—— c:\windows\sssTbarV2.ini
2008-12-13 18:19 . 2008-12-13 20:31 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-13 17:36 . 2008-12-13 17:36 73 –a—— c:\windows\st_affiliate.ini
2008-12-13 15:37 . 2008-02-02 07:43 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-12-11 09:25 . 2008-12-11 09:25 d——– c:\program files\Alwil Software
2008-12-10 14:29 . 2008-12-27 18:48 d——– c:\program files\Spybot - Search & Destroy
2008-12-10 14:29 . 2008-12-28 07:18 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-10 08:14 . 2008-12-10 08:14 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-10 08:13 . 2008-12-10 14:22 d——– c:\program files\SUPERAntiSpyware
2008-12-10 08:13 . 2008-12-10 14:22 d——– c:\documents and settings\Paul A. Parone\Application Data\SUPERAntiSpyware.com
2008-12-09 08:02 . 2008-12-09 08:02 d——– c:\windows\system32\config\systemprofile\Application Data\HPAppData
2008-12-07 21:35 . 2008-12-07 21:35 d–h—– c:\windows\PIF
2008-11-12 16:02 . 2008-11-12 16:02 170,608 –a—— c:\windows\system32\drivers\ssidrv.sys
2008-11-12 16:02 . 2008-11-12 16:02 29,808 –a—— c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 16:02 . 2008-11-12 16:02 23,152 –a—— c:\windows\system32\drivers\sshrmd.sys
2008-11-12 06:45 . 2008-09-04 12:15 1,106,944 ——— c:\windows\system32\dllcache\msxml3.dll
2008-11-12 06:45 . 2008-10-24 06:21 455,296 ——— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 12:14 . 2008-11-11 12:14 d——– c:\program files\Common Files\Adobe AIR
2008-11-11 12:12 . 2008-11-12 06:41 d——– c:\program files\NOS
2008-11-11 12:12 . 2008-11-12 06:41 d——– c:\documents and settings\All Users\Application Data\NOS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 22:20 ——— d—–w c:\program files\Trend Micro
2008-12-26 21:15 90,112 —-a-w c:\windows\DUMP3170.tmp
2008-12-14 01:34 ——— d—–w c:\documents and settings\Paul A. Parone\Application Data\AVG7
2008-12-14 01:34 ——— d—–w c:\documents and settings\All Users\Application Data\Avg7
2008-12-13 06:40 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-10 12:54 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-07 21:45 2,174,976 ——w c:\windows\system32\dllcache\WMVCore.dll
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ——w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 —-a-w c:\windows\system32\win32k.sys
2008-09-15 12:12 1,846,400 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:14 1,307,648 ——w c:\windows\system32\msxml6.dll
2008-09-10 01:14 1,307,648 ——w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 10:41 333,824 ——w c:\windows\system32\dllcache\srv.sys
2008-09-06 03:30 241,704 ——w c:\windows\system32\dllcache\wgaLogon.dll
2008-09-06 03:29 917,032 ——w c:\windows\system32\dllcache\WgaTray.exe
2008-09-04 17:15 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-01-02 23:20 389,120 -c–a-w c:\documents and settings\Paul A. Parone\stas75_20060810.0001.dll
2007-09-30 15:29 21,300,224 -c–a-w c:\program files\antivir_workstation_win7u_en_h.exe
2006-07-27 19:39 28,672 -c–a-w c:\documents and settings\Paul A. Parone\atwbxdet.dll
2000-12-12 16:17 100,432 -c—-w c:\program files\Win2000PPAHotfix.exe
2004-02-04 19:33 9,060,352 -c–a-w c:\program files\internet explorer\plugins\axbqv32.dll
2008-08-24 11:24 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082420080825\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-12-29_20.18.53.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-29 20:41:36 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-30 01:40:43 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-29 20:41:36 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-30 01:40:43 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-29 20:41:36 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-30 01:40:43 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-30 01:11:26 3,940 —-a-w c:\windows\Temp\wrstemp\S-1-5-18.dat
+ 2008-12-30 12:36:30 3,940 —-a-w c:\windows\Temp\wrstemp\S-1-5-18.dat
- 2008-12-30 01:11:26 4,182 —-a-w c:\windows\Temp\wrstemp\S-1-5-19.dat
+ 2008-12-30 12:36:30 4,182 —-a-w c:\windows\Temp\wrstemp\S-1-5-19.dat
- 2008-12-30 01:11:26 4,250 —-a-w c:\windows\Temp\wrstemp\S-1-5-20.dat
+ 2008-12-30 12:36:30 4,250 —-a-w c:\windows\Temp\wrstemp\S-1-5-20.dat
- 2008-12-30 01:14:06 5,526 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-1005.dat
+ 2008-12-30 12:38:12 5,526 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-1005.dat
- 2008-12-30 01:11:26 4,710 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-500.dat
+ 2008-12-30 12:36:30 4,710 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-500.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-12-14 66912]
[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-12-14 14:51 66912 –a—— c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\program files\IBM\Messages By IBM\ibmmessages.exe" [2004-07-22 442368]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Iomega Active Disk"="c:\program files\Iomega\AutoDisk\AD2KClient.exe" [2001-09-13 45056]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"="c:\windows\system32\tp4serv.exe" [2003-11-13 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-30 118784]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 897024]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-08-06 94208]
"TP4EX"="c:\windows\system32\tp4ex.exe" [2002-09-04 53248]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2003-12-25 208896]
"UC_Start"="c:\program files\IBM\Updater\\ucstartup.exe" [2004-07-14 36864]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-09-02 127035]
"IBMPRC"="c:\ibmtools\UTILS\ibmprc.exe" [2004-03-19 90112]
"QCWLICON"="c:\program files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2004-08-18 81920]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-08-25 110592]
"BMMLREF"="c:\program files\ThinkPad\Utilities\BMMLREF.EXE" [2004-08-25 20480]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-08-25 395776]
"Motive SmartBridge"="c:\progra~1\VERIZO~1\SMARTB~1\MotiveSB.exe" [2002-05-18 327680]
"Zone Labs Client"="c:\program files\CheckPoint\Integrity Client\iclient.exe" [2005-05-10 931584]
"Iomega Startup Options"="c:\program files\Iomega\Common\ImgStart.exe" [2001-01-17 45056]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2001-09-12 61440]
"ISSI EZUpdate Service"="c:\sdwork\issimsvc.exe" [2006-12-05 203264]
"stgclean"="c:\sdwork\w32main2.exe" [2006-12-13 260608]
"QCTray"="c:\progra~1\ThinkPad\CONNEC~1\QCTray.exe" [2004-08-18 708608]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-10-07 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-09-11 972064]
Verizon Online Support Center.lnk - c:\program files\Verizon Online\bin\matcli.exe [2005-10-29 204800]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
2004-08-18 05:30 258048 c:\windows\system32\QConGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli pwdmon
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AT&T Network Client\\NetClient.exe"=
"c:\\sdwork\\w32main2.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IBM\\Updater\\ucsmb.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-11-12 29808]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.SYS [2005-10-07 11520]
R1 ASMBATT;ASMBATT;c:\windows\system32\drivers\ASMBATT.SYS [2005-10-07 4992]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2005-10-07 2432]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\Tppwr.sys [2005-10-07 16384]
R2 ibmfilter;ibmfilter;\??\c:\windows\system32\drivers\ibmfilter.sys [2004-09-23 64256]
R2 NsTrcNT;NsTrcNT;c:\windows\system32\drivers\nstrcnt.sys [2005-10-31 10816]
R2 pcscoax;3270 Coax Driver;c:\windows\system32\drivers\pcscoax.sys [2005-10-31 30720]
R2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" [2008-12-14 1086840]
R2 WRTService;WRT Service;c:\windows\WRTService.exe [2005-12-04 77824]
R3 ABVPN2K;Net Firewall Miniport Interface;c:\windows\system32\DRIVERS\abvpn2k.sys [2005-10-31 164224]
R3 avpnnic;AGN Virtual Network Adapter;c:\windows\system32\DRIVERS\avpnnic.sys [2005-10-31 13952]
R3 KLOGNT;KLOGNT;c:\windows\system32\drivers\klognt.sys [2005-10-31 22504]
R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\DRIVERS\tp4track.sys [1980-01-01 13904]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.SYS [2005-10-07 12288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]
2005-10-07 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2004-08-25 03:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com/
uSearch Bar = hxxp://safesearch.cyberdefender.com/smallsearch.html
uInternet Settings,ProxyOverride = 127.0.0.1;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\system32\stfm31.dll - c:\windows\system32\stsm31.dll
c:\windows\system32\stas31.dll
c:\windows\Downloaded Program Files\STJNILoader.ocx
O16 -: {7261EE42-318E-490A-AE8F-77649DBA1ECA}
hxxps://www-1.ibm.com/sametime/stmeetingroomclient/STJNILoader.cab
c:\windows\Downloaded Program Files\STJNILoader.inf
c:\windows\Downloaded Program Files\LNWebAssist.dll - O16 -: {9519B2A2-6592-4E41-8290-D0298459270C}
hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-30 07:33:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\windows\TEMP\wrstemp\SSMS276BBE60-1062-4F0E-ABBB-E13F309CC52D.tmp 7995392 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(1428)
c:\windows\system32\pwdmon.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\progra~1\Iomega\System32\ActivityDisk.exe
c:\program files\lotus\notes\ntmulti.exe
c:\progra~1\AT&TNE~1\NetCfgSv.EXE
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\system32\QCONSVC.EXE
c:\windows\system32\TpKmpSvc.exe
c:\windows\system32\drivers\trcboot.exe
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Personal Communications\pcs_agnt.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\windows\system32\acs.exe
c:\windows\system32\wscntfy.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\IBM\Updater\jre\bin\javaw.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Verizon Online\bin\mpbtn.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Webroot\WebrootSecurity\SSU.exe
.
**************************************************************************
.
Completion time: 2008-12-30 7:44:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-30 12:43:54
ComboFix2.txt 2008-12-30 01:21:19
Pre-Run: 20,123,889,664 bytes free
Post-Run: 20,144,500,736 bytes free
308 — E O F — 2008-12-20 00:20:49
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, December 30, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, December 29, 2008 20:15:59
Records in database: 1529651
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
Scan statistics:
Files scanned: 70196
Threat name: 1
Infected objects: 7
Suspicious objects: 0
Duration of the scan: 02:35:28
File name / Threat name / Threats count
C:\Program Files\IBM\checker\pskill.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\Siebel\checkerv2inst.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1141842822796\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1141842856781\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1141842880671\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1141842905140\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1161874666453\checkerv2inst270.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
The selected area was scanned.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:01:23 AM, on 12/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
c:\sdwork\issimsvc.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Personal Communications\PCS_AGNT.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\WRTService.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\IBM\Updater\jre\bin\javaw.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\CheckPoint\Integrity Client\iclient.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [TrackPointSrv] "C:\WINDOWS\system32\tp4serv.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TPHOTKEY] "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe"
O4 - HKLM\..\Run: [TP4EX] "C:\WINDOWS\system32\tp4ex.exe"
O4 - HKLM\..\Run: [EZEJMNAP] "C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe"
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] "C:\WINDOWS\system32\dla\tfswctrl.exe"
O4 - HKLM\..\Run: [IBMPRC] "C:\IBMTOOLS\UTILS\ibmprc.exe"
O4 - HKLM\..\Run: [QCWLICON] "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE"
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [Motive SmartBridge] "C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] "C:\Program Files\Iomega\Common\ImgStart.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [stgclean] "c:\sdwork\w32main2.exe" /cleanup
O4 - HKLM\..\Run: [QCTray] "C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ibmmessages] "C:\Program Files\IBM\Messages By IBM\ibmmessages.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Iomega Active Disk] "C:\Program Files\Iomega\AutoDisk\AD2KClient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1201959414343
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) -
https://www-1.ibm.com/sametime/stmeetingroo…STJNILoader.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) -
http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) -
http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) -
https://regatta.mcsgroup.com/dwa7W.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://mlmeetings.webex.com/client/v_myweb…ent/ieatgpc.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: ISSI EZUpdate (ISSIMon) - IBM Global Services - c:\sdwork\issimsvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrcBoot - Unknown owner - C:\WINDOWS\System32\drivers\trcboot.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: WRT Service (WRTService) - Unknown owner - C:\WINDOWS\WRTService.exe
–
End of file - 11770 bytes