This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] sinowal and virtumonde

136 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First post. I am new to this forum but not to tech (been in tech for 10 years on the client side, and worked closely with engineers and consultants).

My IBM Thinkpad running Win XP Pro was infected with Sinowal and now with Virtumonde. To date I have d/l and used many AV products trying to find the one that will crush both. Am in my 3rd week of finding and using applications, running scans, deleting weak trial apps, etc. This may be my last hope before I heave my Thinkpad at the door of the local Microsoft office and go get a MAC.

Briefly, nothing's worked. I get close and the infections laugh, then stay one keystroke out of reach.

I started with Ad-aware, AVG 7.5, and went thru most of the free trial AV products. Currently I again have installed Malewarebyte, Spybot and Webroot's Spysweeper. All discover different trojans and variants.

I have elevated the fight and started in safe mode the past 2 days, with the timer set in the bootini file to a full 999 seconds so I could complete a scan via Malewarebytes and still have time to delete, quarantine or change the infected registry files. Every time the scan discovered one specific file (myway.mywebsearch or something similar) it stopped the scan and shut the PC.

I tried to get to the infections in safe mode by running the fixes against previous scan results in these AV/AS apps. Didn't work.

FYI, many free apps offer a d/l, be advised most trials are SCAN ONLY, you have to purchase the app to scrub/fix or do any remediation.

However, Spybot and Malewarebytes offer a free fix, so they're my attack dogs. Webroot is installed for the shields.

None of my tactics in safe mode worked to get to the infections in the registry and temporary files. I do know that cloaking is engaged, so scans will not see the temporary internet files folder, where many variants return due to system restore.

Today I shut off system restore, planning to do a sweep and finally win the day. When I ran Malewarebytes the infections were not removed or quarantined. When I ran Spybot the application refused to open whether I clicked on the icon or went to Windows Explorer and clicked on the application's main .exe.

No problem, I'll re-install. I did so twice from two different sources. All the .dll's in the plugins folder refused to d/l both times. Is virtumonde and sinowal superhuman, like kudzu?

On the site of the latest d/l I saw the free scan from Trend Micro's Hijack This. I knew several Trend guys and respect their quality (note: Housecall, which may have previously been known as PC Cillin, did not work on these.). I d/l Hijack This and opted for a free scan. Here I am, battered, dirty and mad as hell. But determined to win this fight.

My head hurts, but here is the scan result if anyone wants to get into this fight. Many sincere thanks in advance.

Paul



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:45:46 PM, on 12/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
c:\sdwork\issimsvc.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\drivers\trcboot.exe
C:\Program Files\Personal Communications\PCS_AGNT.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\WRTService.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\spider.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [TrackPointSrv] "C:\WINDOWS\system32\tp4serv.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TPHOTKEY] "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe"
O4 - HKLM\..\Run: [TP4EX] "C:\WINDOWS\system32\tp4ex.exe"
O4 - HKLM\..\Run: [EZEJMNAP] "C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe"
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] "C:\WINDOWS\system32\dla\tfswctrl.exe"
O4 - HKLM\..\Run: [IBMPRC] "C:\IBMTOOLS\UTILS\ibmprc.exe"
O4 - HKLM\..\Run: [QCWLICON] "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE"
O4 - HKLM\..\Run: [BMMGAG] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [Motive SmartBridge] "C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] "C:\Program Files\Iomega\Common\ImgStart.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [stgclean] "c:\sdwork\w32main2.exe" /cleanup
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QCTray] "C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Iomega Active Disk] "C:\Program Files\Iomega\AutoDisk\AD2KClient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1201959414343
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://www-1.ibm.com/sametime/stmeetingroo…STJNILoader.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://regatta.mcsgroup.com/dwa7W.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mlmeetings.webex.com/client/v_myweb…ent/ieatgpc.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O20 - AppInit_DLLs: lwsmwc.dll
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: ISSI EZUpdate (ISSIMon) - IBM Global Services - c:\sdwork\issimsvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrcBoot - Unknown owner - C:\WINDOWS\System32\drivers\trcboot.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: WRT Service (WRTService) - Unknown owner - C:\WINDOWS\WRTService.exe

–
End of file - 12276 bytes
:welcome:

My name is BHowett and I will be helping you to get sorted. If for any reason you do not understand any of the instructions, or are just unsure then please do not guess , simply post back with your question, and we will go through it again.

this sounds like a fun one mind if I have a go at it…. please do the following…

ComboFix

Please ownload ComboFix from Here or Here

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt, and a fresh Hijackthis log in your next reply.

Do not mouse-click Combofix's window while it is running. That may cause it to stall.


also please post any logs you have from Malewarebytes, so I can take a look at them as well.
BHowett, thank you and welcome to the fray. Glad to have you here.

Roger that action plan. Am about to shut off all AV/AS apps and run combo.

Yea, let's have some fun with this.

Here are two Malwarebytes logs, in reverse order: the first is from this morning (28 Dec), the latter is from the very first scan on 17 Dec. There may be some benefit for you in this data. e.g., I immediately noticed the huge difference in the amount of scanned objects.



Malwarebytes' Anti-Malware 1.31
Database version: 1514
Windows 5.1.2600 Service Pack 3

12/28/2008 9:41:13 AM
mbam-log-2008-12-28 (09-41-13).txt

Scan type: Quick Scan
Objects scanned: 57751

Time elapsed: 11 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




Malwarebytes' Anti-Malware 1.31
Database version: 1512
Windows 5.1.2600 Service Pack 3

12/17/2008 6:36:32 PM
mbam-log-2008-12-17 (18-36-32).txt

Scan type: Full Scan (C:\|)
Objects scanned: 118849
Time elapsed: 1 hour(s), 11 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 18
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Adware.AskSBAR) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{f0d4b230-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d4b23a-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d4b23c-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b15fd82e-85bc-430d-90cb-65db1b030510} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f0d4b231-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f0d4b23b-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f0d4b23b-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{def85c80-216a-43ab-af70-1665edbe2780} (Spyware.Sinowal) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa} (Adware.AskSBAR) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL (Adware.AskSBAR) -> Delete on reboot.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP839\A0210252.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5D527826-05BD-4A83-8416-28ACDDA14001}\RP840\A0212329.dll (Trojan.Vundo) -> Quarantined and d
BHowett,

Note that during the process Webroot kept popping up approve/deny windows re changes to various registry files. Based on brief descriptions I approved or denied.

Note that Combo failed to open one .temp file. Let me know if you see anything in the following Combo log that suggests I should approve or deny something if we run combo again.

Top off yer mug, this one is long.

thx.
Paul





ComboFix 08-12-28.01 - Paul A. Parone 2008-12-28 14:09:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.709 [GMT -5:00]
Running from: c:\program files\ComboFix.exe
AV: Webroot AntiVirus with AntiSpyware *On-access scanning disabled* (Updated)
FW: Webroot Internet Security Essentials *disabled*
FW: Integrity Flex Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\AutoRun.inf
c:\windows\Tasks\zavbmmse.job
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-28 )))))))))))))))))))))))))))))))
.

2008-12-28 13:56 . 2008-12-28 13:55 2,888,402 -ra—— c:\program files\ComboFix.exe
2008-12-24 07:36 . 2008-12-24 07:36 d——– c:\documents and settings\Paul A. Parone\.java
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\documents and settings\Paul A. Parone\Application Data\Malwarebytes
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-17 17:05 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-17 17:05 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-15 16:37 . 2008-12-25 10:34 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\program files\Webroot
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\program files\AskSBar
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\documents and settings\Paul A. Parone\Application Data\Webroot
2008-12-14 14:51 . 2008-12-14 15:05 d——– c:\documents and settings\All Users\Application Data\Webroot
2008-12-14 14:51 . 2008-12-14 14:51 d——– C:\Binaries
2008-12-14 14:51 . 2008-11-13 17:11 1,553,272 –a—— c:\windows\WRSetup.dll
2008-12-14 14:46 . 2008-12-14 14:46 164 –a—— C:\install.dat
2008-12-13 20:51 . 2008-12-13 20:51 4,474 –a—— c:\windows\GATHER.KM
2008-12-13 20:42 . 2008-12-13 20:42 d——– c:\program files\Kaspersky Lab
2008-12-13 19:59 . 2008-12-13 19:59 27 –a—— c:\windows\sssTbarV2.ini
2008-12-13 18:19 . 2008-12-13 20:31 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-13 17:36 . 2008-12-13 17:36 73 –a—— c:\windows\st_affiliate.ini
2008-12-13 15:37 . 2008-02-02 07:43 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-12-11 09:25 . 2008-12-11 09:25 d——– c:\program files\Alwil Software
2008-12-10 14:29 . 2008-12-27 18:48 d——– c:\program files\Spybot - Search & Destroy
2008-12-10 14:29 . 2008-12-28 07:18 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-10 09:12 . 2008-12-10 09:12 1,621,656 —hs—- c:\windows\system32\qnbukjdd.tmp
2008-12-10 08:14 . 2008-12-10 08:14 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-10 08:13 . 2008-12-10 14:22 d——– c:\program files\SUPERAntiSpyware
2008-12-10 08:13 . 2008-12-10 14:22 d——– c:\documents and settings\Paul A. Parone\Application Data\SUPERAntiSpyware.com
2008-12-07 21:35 . 2008-12-07 21:35 d–h—– c:\windows\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 19:14 4,194,150 —-a-w c:\windows\Internet Logs\tvDebug.Zip
2008-12-27 22:20 ——— d—–w c:\program files\Trend Micro
2008-12-26 21:15 90,112 —-a-w c:\windows\DUMP3170.tmp
2008-12-26 11:46 4,396,032 —-a-w c:\windows\Internet Logs\xDB4E.tmp
2008-12-24 12:17 4,392,960 —-a-w c:\windows\Internet Logs\xDB4D.tmp
2008-12-23 17:24 53,248 —-a-w c:\windows\Internet Logs\xDB4C.tmp
2008-12-23 17:24 4,392,448 —-a-w c:\windows\Internet Logs\xDB4B.tmp
2008-12-22 18:33 4,391,424 —-a-w c:\windows\Internet Logs\xDB49.tmp
2008-12-22 18:21 23,552 —-a-w c:\windows\Internet Logs\xDB4A.tmp
2008-12-22 15:03 4,391,424 —-a-w c:\windows\Internet Logs\xDB47.tmp
2008-12-22 13:49 47,616 —-a-w c:\windows\Internet Logs\xDB48.tmp
2008-12-20 16:00 200,704 —-a-w c:\windows\Internet Logs\xDB46.tmp
2008-12-20 15:36 4,390,912 —-a-w c:\windows\Internet Logs\xDB45.tmp
2008-12-16 17:42 4,388,352 —-a-w c:\windows\Internet Logs\xDB43.tmp
2008-12-16 17:40 366,080 —-a-w c:\windows\Internet Logs\xDB44.tmp
2008-12-14 01:34 ——— d—–w c:\documents and settings\Paul A. Parone\Application Data\AVG7
2008-12-14 01:34 ——— d—–w c:\documents and settings\All Users\Application Data\Avg7
2008-12-13 06:40 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-10 12:54 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-09 20:46 156,160 —-a-w c:\windows\Internet Logs\xDB42.tmp
2008-12-09 20:36 4,376,064 —-a-w c:\windows\Internet Logs\xDB41.tmp
2008-11-25 13:13 35,840 —-a-w c:\windows\Internet Logs\xDB40.tmp
2008-11-25 13:12 4,363,264 —-a-w c:\windows\Internet Logs\xDB3F.tmp
2008-11-23 11:23 18,432 —-a-w c:\windows\Internet Logs\xDB3E.tmp
2008-11-23 11:20 4,361,216 —-a-w c:\windows\Internet Logs\xDB3D.tmp
2008-11-23 10:43 4,361,216 —-a-w c:\windows\Internet Logs\xDB3B.tmp
2008-11-22 21:07 40,960 —-a-w c:\windows\Internet Logs\xDB3C.tmp
2008-11-20 20:35 4,359,680 —-a-w c:\windows\Internet Logs\xDB37.tmp
2008-11-20 20:35 26,112 —-a-w c:\windows\Internet Logs\xDB3A.tmp
2008-11-20 18:03 4,359,168 —-a-w c:\windows\Internet Logs\xDB36.tmp
2008-11-20 17:56 154,112 —-a-w c:\windows\Internet Logs\xDB38.tmp
2008-11-12 21:02 29,808 —-a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 21:02 23,152 —-a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 21:02 170,608 —-a-w c:\windows\system32\drivers\ssidrv.sys
2008-11-12 13:11 4,349,952 —-a-w c:\windows\Internet Logs\xDB34.tmp
2008-11-12 13:11 36,352 —-a-w c:\windows\Internet Logs\xDB35.tmp
2008-11-12 11:41 ——— d—–w c:\program files\NOS
2008-11-12 11:41 ——— d—–w c:\documents and settings\All Users\Application Data\NOS
2008-11-11 17:14 ——— d—–w c:\program files\Common Files\Adobe AIR
2008-11-10 21:34 4,349,440 —-a-w c:\windows\Internet Logs\xDB32.tmp
2008-11-10 21:32 20,480 —-a-w c:\windows\Internet Logs\xDB33.tmp
2008-11-10 20:57 4,349,440 —-a-w c:\windows\Internet Logs\xDB31.tmp
2008-11-10 20:27 61,440 —-a-w c:\windows\Internet Logs\xDB39.tmp
2008-11-07 21:45 2,174,976 ——w c:\windows\system32\dllcache\WMVCore.dll
2008-11-07 12:12 24,576 —-a-w c:\windows\Internet Logs\xDB30.tmp
2008-11-07 12:07 4,346,368 —-a-w c:\windows\Internet Logs\xDB2F.tmp
2008-11-06 18:26 4,345,856 —-a-w c:\windows\Internet Logs\xDB2D.tmp
2008-11-06 18:26 24,576 —-a-w c:\windows\Internet Logs\xDB2E.tmp
2008-11-06 15:26 4,345,856 —-a-w c:\windows\Internet Logs\xDB2B.tmp
2008-11-06 15:21 64,512 —-a-w c:\windows\Internet Logs\xDB2C.tmp
2008-11-02 17:09 4,342,272 —-a-w c:\windows\Internet Logs\xDB27.tmp
2008-11-02 16:38 983,552 —-a-w c:\windows\Internet Logs\xDB29.tmp
2008-10-24 11:21 455,296 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ——w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-01-02 23:20 389,120 -c–a-w c:\documents and settings\Paul A. Parone\stas75_20060810.0001.dll
2007-09-30 15:29 21,300,224 -c–a-w c:\program files\antivir_workstation_win7u_en_h.exe
2006-07-27 19:39 28,672 -c–a-w c:\documents and settings\Paul A. Parone\atwbxdet.dll
2000-12-12 16:17 100,432 -c—-w c:\program files\Win2000PPAHotfix.exe
2004-02-04 19:33 9,060,352 -c–a-w c:\program files\internet explorer\plugins\axbqv32.dll
2008-08-24 11:24 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082420080825\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-12-14 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-12-14 14:51 66912 –a—— c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\program files\IBM\Messages By IBM\ibmmessages.exe" [2004-07-22 442368]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Iomega Active Disk"="c:\program files\Iomega\AutoDisk\AD2KClient.exe" [2001-09-13 45056]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"="c:\windows\system32\tp4serv.exe" [2003-11-13 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-30 118784]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 897024]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-08-06 94208]
"TP4EX"="c:\windows\system32\tp4ex.exe" [2002-09-04 53248]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2003-12-25 208896]
"UC_Start"="c:\program files\IBM\Updater\\ucstartup.exe" [2004-07-14 36864]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-09-02 127035]
"IBMPRC"="c:\ibmtools\UTILS\ibmprc.exe" [2004-03-19 90112]
"QCWLICON"="c:\program files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2004-08-18 81920]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-08-25 110592]
"BMMLREF"="c:\program files\ThinkPad\Utilities\BMMLREF.EXE" [2004-08-25 20480]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-08-25 395776]
"Motive SmartBridge"="c:\progra~1\VERIZO~1\SMARTB~1\MotiveSB.exe" [2002-05-18 327680]
"Zone Labs Client"="c:\program files\CheckPoint\Integrity Client\iclient.exe" [2005-05-10 931584]
"Iomega Startup Options"="c:\program files\Iomega\Common\ImgStart.exe" [2001-01-17 45056]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2001-09-12 61440]
"ISSI EZUpdate Service"="c:\sdwork\issimsvc.exe" [2006-12-05 203264]
"stgclean"="c:\sdwork\w32main2.exe" [2006-12-13 260608]
"QCTray"="c:\progra~1\ThinkPad\CONNEC~1\QCTray.exe" [2004-08-18 708608]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-10-07 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-09-11 972064]
Verizon Online Support Center.lnk - c:\program files\Verizon Online\bin\matcli.exe [2005-10-29 204800]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
2004-08-18 05:30 258048 c:\windows\system32\QConGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lwsmwc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli pwdmon

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AT&T Network Client\\NetClient.exe"=
"c:\\sdwork\\w32main2.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IBM\\Updater\\ucsmb.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-11-12 29808]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.SYS [2005-10-07 11520]
R1 ASMBATT;ASMBATT;c:\windows\system32\drivers\ASMBATT.SYS [2005-10-07 4992]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2005-10-07 2432]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\Tppwr.sys [2005-10-07 16384]
R2 ibmfilter;ibmfilter;\??\c:\windows\system32\drivers\ibmfilter.sys [2004-09-23 64256]
R2 NsTrcNT;NsTrcNT;c:\windows\system32\drivers\nstrcnt.sys [2005-10-31 10816]
R2 pcscoax;3270 Coax Driver;c:\windows\system32\drivers\pcscoax.sys [2005-10-31 30720]
R2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" [2008-12-14 1086840]
R2 WRTService;WRT Service;c:\windows\WRTService.exe [2005-12-04 77824]
R3 ABVPN2K;Net Firewall Miniport Interface;c:\windows\system32\DRIVERS\abvpn2k.sys [2005-10-31 164224]
R3 avpnnic;AGN Virtual Network Adapter;c:\windows\system32\DRIVERS\avpnnic.sys [2005-10-31 13952]
R3 KLOGNT;KLOGNT;c:\windows\system32\drivers\klognt.sys [2005-10-31 22504]
R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\DRIVERS\tp4track.sys [1980-01-01 13904]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.SYS [2005-10-07 12288]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c70791ae-a9aa-11dc-ac77-0014a43bba3f}]
\Shell\AutoRun\command - F:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2008-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]

2005-10-07 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2004-08-25 03:37]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SSC_UserPrompt - c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
HKLM-Run-vptray - c:\progra~1\SYMANT~1\VPTray.exe
HKLM-Run-UC_SMB - (no file)
HKLM-Run- - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com/
uSearch Bar = hxxp://safesearch.cyberdefender.com/smallsearch.html
uInternet Settings,ProxyOverride = 127.0.0.1;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\system32\stfm31.dll - c:\windows\system32\stsm31.dll
c:\windows\system32\stas31.dll
c:\windows\Downloaded Program Files\STJNILoader.ocx
O16 -: {7261EE42-318E-490A-AE8F-77649DBA1ECA}
hxxps://www-1.ibm.com/sametime/stmeetingroomclient/STJNILoader.cab
c:\windows\Downloaded Program Files\STJNILoader.inf

c:\windows\Downloaded Program Files\LNWebAssist.dll - O16 -: {9519B2A2-6592-4E41-8290-D0298459270C}
hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-28 14:23:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(1420)
c:\windows\system32\pwdmon.dll

- - - - - - - > 'explorer.exe'(3380)
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
c:\program files\Iomega\DriveIcons\IMGHOOK.DLL
c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\progra~1\Iomega\System32\ActivityDisk.exe
c:\program files\lotus\notes\ntmulti.exe
c:\progra~1\AT&TNE~1\NetCfgSv.EXE
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\system32\QCONSVC.EXE
c:\windows\system32\TpKmpSvc.exe
c:\windows\system32\drivers\trcboot.exe
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Personal Communications\pcs_agnt.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\windows\system32\acs.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\Verizon Online\bin\mpbtn.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Webroot\WebrootSecurity\SSU.exe
.
**************************************************************************
.
Completion time: 2008-12-28 14:42:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-28 19:41:55

Pre-Run: 20,261,859,328 bytes free
Post-Run: 20,116,680,704 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect

323 — E O F — 2008-12-20 00:20:49
Monday morning, early and dark.

BHowett, what with my mixed "approve" or "deny" choices into Spybot re changes in the registry values after the first combofix scan, I ran it again last night. When it completed and after it rebooted, Spybot popped up the approve/deny windows again. This time I approved all of them. Below is the data file for your review. Unless you state otherwise, I'll run it again this afternoon but deny all changes, so we can see that effect in the data config.

Note that neither the first nor second combofix scan killed either sinowal or virtumonde. Webroot still sees both, and I can confirm that because I am unable to see the "temporary internet files" folder in my directory tree. You may recall I saw that cloaking was enabled to mask the files hosting the bugs in a log file dated November 2006.

Had a hunch it wasn't going to be real easy. Many thanks for your time and assistance.

PAP






ComboFix 08-12-28.01 - Paul A. Parone 2008-12-28 22:08:12.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.563 [GMT -5:00]
Running from: c:\program files\ComboFix.exe
AV: Webroot AntiVirus with AntiSpyware *On-access scanning disabled* (Updated)
FW: Webroot Internet Security Essentials *disabled*
FW: Integrity Flex Firewall *disabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

F:\AUTORUN.INF

.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.

2008-12-28 13:56 . 2008-12-28 13:55 2,888,402 -ra—— c:\program files\ComboFix.exe
2008-12-24 07:36 . 2008-12-24 07:36 d——– c:\documents and settings\Paul A. Parone\.java
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\documents and settings\Paul A. Parone\Application Data\Malwarebytes
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-17 17:05 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-17 17:05 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-15 16:37 . 2008-12-25 10:34 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\program files\Webroot
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\program files\AskSBar
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\documents and settings\Paul A. Parone\Application Data\Webroot
2008-12-14 14:51 . 2008-12-14 15:05 d——– c:\documents and settings\All Users\Application Data\Webroot
2008-12-14 14:51 . 2008-12-14 14:51 d——– C:\Binaries
2008-12-14 14:51 . 2008-11-13 17:11 1,553,272 –a—— c:\windows\WRSetup.dll
2008-12-14 14:46 . 2008-12-14 14:46 164 –a—— C:\install.dat
2008-12-13 20:51 . 2008-12-13 20:51 4,474 –a—— c:\windows\GATHER.KM
2008-12-13 20:42 . 2008-12-13 20:42 d——– c:\program files\Kaspersky Lab
2008-12-13 19:59 . 2008-12-13 19:59 27 –a—— c:\windows\sssTbarV2.ini
2008-12-13 18:19 . 2008-12-13 20:31 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-13 17:36 . 2008-12-13 17:36 73 –a—— c:\windows\st_affiliate.ini
2008-12-13 15:37 . 2008-02-02 07:43 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-12-11 09:25 . 2008-12-11 09:25 d——– c:\program files\Alwil Software
2008-12-10 14:29 . 2008-12-27 18:48 d——– c:\program files\Spybot - Search & Destroy
2008-12-10 14:29 . 2008-12-28 07:18 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-10 09:12 . 2008-12-10 09:12 1,621,656 —hs—- c:\windows\system32\qnbukjdd.tmp
2008-12-10 08:14 . 2008-12-10 08:14 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-10 08:13 . 2008-12-10 14:22 d——– c:\program files\SUPERAntiSpyware
2008-12-10 08:13 . 2008-12-10 14:22 d——– c:\documents and settings\Paul A. Parone\Application Data\SUPERAntiSpyware.com
2008-12-07 21:35 . 2008-12-07 21:35 d–h—– c:\windows\PIF

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 03:13 4,460,452 —-a-w c:\windows\Internet Logs\tvDebug.Zip
2008-12-27 22:20 ——— d—–w c:\program files\Trend Micro
2008-12-26 21:15 90,112 —-a-w c:\windows\DUMP3170.tmp
2008-12-26 11:46 4,396,032 —-a-w c:\windows\Internet Logs\xDB4E.tmp
2008-12-24 12:17 4,392,960 —-a-w c:\windows\Internet Logs\xDB4D.tmp
2008-12-23 17:24 53,248 —-a-w c:\windows\Internet Logs\xDB4C.tmp
2008-12-23 17:24 4,392,448 —-a-w c:\windows\Internet Logs\xDB4B.tmp
2008-12-22 18:33 4,391,424 —-a-w c:\windows\Internet Logs\xDB49.tmp
2008-12-22 18:21 23,552 —-a-w c:\windows\Internet Logs\xDB4A.tmp
2008-12-22 15:03 4,391,424 —-a-w c:\windows\Internet Logs\xDB47.tmp
2008-12-22 13:49 47,616 —-a-w c:\windows\Internet Logs\xDB48.tmp
2008-12-20 16:00 200,704 —-a-w c:\windows\Internet Logs\xDB46.tmp
2008-12-20 15:36 4,390,912 —-a-w c:\windows\Internet Logs\xDB45.tmp
2008-12-16 17:42 4,388,352 —-a-w c:\windows\Internet Logs\xDB43.tmp
2008-12-16 17:40 366,080 —-a-w c:\windows\Internet Logs\xDB44.tmp
2008-12-14 01:34 ——— d—–w c:\documents and settings\Paul A. Parone\Application Data\AVG7
2008-12-14 01:34 ——— d—–w c:\documents and settings\All Users\Application Data\Avg7
2008-12-13 06:40 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-10 12:54 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-09 20:46 156,160 —-a-w c:\windows\Internet Logs\xDB42.tmp
2008-12-09 20:36 4,376,064 —-a-w c:\windows\Internet Logs\xDB41.tmp
2008-11-25 13:13 35,840 —-a-w c:\windows\Internet Logs\xDB40.tmp
2008-11-25 13:12 4,363,264 —-a-w c:\windows\Internet Logs\xDB3F.tmp
2008-11-23 11:23 18,432 —-a-w c:\windows\Internet Logs\xDB3E.tmp
2008-11-23 11:20 4,361,216 —-a-w c:\windows\Internet Logs\xDB3D.tmp
2008-11-23 10:43 4,361,216 —-a-w c:\windows\Internet Logs\xDB3B.tmp
2008-11-22 21:07 40,960 —-a-w c:\windows\Internet Logs\xDB3C.tmp
2008-11-20 20:35 4,359,680 —-a-w c:\windows\Internet Logs\xDB37.tmp
2008-11-20 20:35 26,112 —-a-w c:\windows\Internet Logs\xDB3A.tmp
2008-11-20 18:03 4,359,168 —-a-w c:\windows\Internet Logs\xDB36.tmp
2008-11-20 17:56 154,112 —-a-w c:\windows\Internet Logs\xDB38.tmp
2008-11-12 21:02 29,808 —-a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 21:02 23,152 —-a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 21:02 170,608 —-a-w c:\windows\system32\drivers\ssidrv.sys
2008-11-12 13:11 4,349,952 —-a-w c:\windows\Internet Logs\xDB34.tmp
2008-11-12 13:11 36,352 —-a-w c:\windows\Internet Logs\xDB35.tmp
2008-11-12 11:41 ——— d—–w c:\program files\NOS
2008-11-12 11:41 ——— d—–w c:\documents and settings\All Users\Application Data\NOS
2008-11-11 17:14 ——— d—–w c:\program files\Common Files\Adobe AIR
2008-11-10 21:34 4,349,440 —-a-w c:\windows\Internet Logs\xDB32.tmp
2008-11-10 21:32 20,480 —-a-w c:\windows\Internet Logs\xDB33.tmp
2008-11-10 20:57 4,349,440 —-a-w c:\windows\Internet Logs\xDB31.tmp
2008-11-10 20:27 61,440 —-a-w c:\windows\Internet Logs\xDB39.tmp
2008-11-07 21:45 2,174,976 ——w c:\windows\system32\dllcache\WMVCore.dll
2008-11-07 12:12 24,576 —-a-w c:\windows\Internet Logs\xDB30.tmp
2008-11-07 12:07 4,346,368 —-a-w c:\windows\Internet Logs\xDB2F.tmp
2008-11-06 18:26 4,345,856 —-a-w c:\windows\Internet Logs\xDB2D.tmp
2008-11-06 18:26 24,576 —-a-w c:\windows\Internet Logs\xDB2E.tmp
2008-11-06 15:26 4,345,856 —-a-w c:\windows\Internet Logs\xDB2B.tmp
2008-11-06 15:21 64,512 —-a-w c:\windows\Internet Logs\xDB2C.tmp
2008-11-02 17:09 4,342,272 —-a-w c:\windows\Internet Logs\xDB27.tmp
2008-11-02 16:38 983,552 —-a-w c:\windows\Internet Logs\xDB29.tmp
2008-10-24 11:21 455,296 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ——w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-01-02 23:20 389,120 -c–a-w c:\documents and settings\Paul A. Parone\stas75_20060810.0001.dll
2007-09-30 15:29 21,300,224 -c–a-w c:\program files\antivir_workstation_win7u_en_h.exe
2006-07-27 19:39 28,672 -c–a-w c:\documents and settings\Paul A. Parone\atwbxdet.dll
2000-12-12 16:17 100,432 -c—-w c:\program files\Win2000PPAHotfix.exe
2004-02-04 19:33 9,060,352 -c–a-w c:\program files\internet explorer\plugins\axbqv32.dll
2008-08-24 11:24 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082420080825\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-12-28_14.32.42.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-28 10:08:48 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-28 19:14:38 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-28 10:08:48 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-28 19:14:38 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-28 10:08:48 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-28 19:14:38 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-28 19:23:59 4,150 —-a-w c:\windows\Temp\wrstemp\S-1-5-18.dat
+ 2008-12-29 03:15:59 4,150 —-a-w c:\windows\Temp\wrstemp\S-1-5-18.dat
- 2008-12-28 19:23:59 4,182 —-a-w c:\windows\Temp\wrstemp\S-1-5-19.dat
+ 2008-12-29 03:15:59 4,182 —-a-w c:\windows\Temp\wrstemp\S-1-5-19.dat
- 2008-12-28 19:23:59 4,250 —-a-w c:\windows\Temp\wrstemp\S-1-5-20.dat
+ 2008-12-29 03:15:59 4,250 —-a-w c:\windows\Temp\wrstemp\S-1-5-20.dat
- 2008-12-28 19:25:34 5,512 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-1005.dat
+ 2008-12-29 03:17:49 5,526 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-1005.dat
- 2008-12-28 19:23:59 4,710 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-500.dat
+ 2008-12-29 03:15:59 4,710 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-500.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-12-14 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-12-14 14:51 66912 –a—— c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\program files\IBM\Messages By IBM\ibmmessages.exe" [2004-07-22 442368]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Iomega Active Disk"="c:\program files\Iomega\AutoDisk\AD2KClient.exe" [2001-09-13 45056]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"="c:\windows\system32\tp4serv.exe" [2003-11-13 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-30 118784]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 897024]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-08-06 94208]
"TP4EX"="c:\windows\system32\tp4ex.exe" [2002-09-04 53248]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2003-12-25 208896]
"UC_Start"="c:\program files\IBM\Updater\\ucstartup.exe" [2004-07-14 36864]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-09-02 127035]
"IBMPRC"="c:\ibmtools\UTILS\ibmprc.exe" [2004-03-19 90112]
"QCWLICON"="c:\program files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2004-08-18 81920]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-08-25 110592]
"BMMLREF"="c:\program files\ThinkPad\Utilities\BMMLREF.EXE" [2004-08-25 20480]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-08-25 395776]
"Motive SmartBridge"="c:\progra~1\VERIZO~1\SMARTB~1\MotiveSB.exe" [2002-05-18 327680]
"Zone Labs Client"="c:\program files\CheckPoint\Integrity Client\iclient.exe" [2005-05-10 931584]
"Iomega Startup Options"="c:\program files\Iomega\Common\ImgStart.exe" [2001-01-17 45056]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2001-09-12 61440]
"ISSI EZUpdate Service"="c:\sdwork\issimsvc.exe" [2006-12-05 203264]
"stgclean"="c:\sdwork\w32main2.exe" [2006-12-13 260608]
"QCTray"="c:\progra~1\ThinkPad\CONNEC~1\QCTray.exe" [2004-08-18 708608]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]
"UC_SMB"="" [BU]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-10-07 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-09-11 972064]
Verizon Online Support Center.lnk - c:\program files\Verizon Online\bin\matcli.exe [2005-10-29 204800]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
2004-08-18 05:30 258048 c:\windows\system32\QConGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=lwsmwc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli pwdmon

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AT&T Network Client\\NetClient.exe"=
"c:\\sdwork\\w32main2.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IBM\\Updater\\ucsmb.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-11-12 29808]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.SYS [2005-10-07 11520]
R1 ASMBATT;ASMBATT;c:\windows\system32\drivers\ASMBATT.SYS [2005-10-07 4992]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2005-10-07 2432]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\Tppwr.sys [2005-10-07 16384]
R2 ibmfilter;ibmfilter;\??\c:\windows\system32\drivers\ibmfilter.sys [2004-09-23 64256]
R2 NsTrcNT;NsTrcNT;c:\windows\system32\drivers\nstrcnt.sys [2005-10-31 10816]
R2 pcscoax;3270 Coax Driver;c:\windows\system32\drivers\pcscoax.sys [2005-10-31 30720]
R2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" [2008-12-14 1086840]
R2 WRTService;WRT Service;c:\windows\WRTService.exe [2005-12-04 77824]
R3 ABVPN2K;Net Firewall Miniport Interface;c:\windows\system32\DRIVERS\abvpn2k.sys [2005-10-31 164224]
R3 avpnnic;AGN Virtual Network Adapter;c:\windows\system32\DRIVERS\avpnnic.sys [2005-10-31 13952]
R3 KLOGNT;KLOGNT;c:\windows\system32\drivers\klognt.sys [2005-10-31 22504]
R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\DRIVERS\tp4track.sys [1980-01-01 13904]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.SYS [2005-10-07 12288]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]

2005-10-07 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2004-08-25 03:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com/
uSearch Bar = hxxp://safesearch.cyberdefender.com/smallsearch.html
uInternet Settings,ProxyOverride = 127.0.0.1;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\system32\stfm31.dll - c:\windows\system32\stsm31.dll
c:\windows\system32\stas31.dll
c:\windows\Downloaded Program Files\STJNILoader.ocx
O16 -: {7261EE42-318E-490A-AE8F-77649DBA1ECA}
hxxps://www-1.ibm.com/sametime/stmeetingroomclient/STJNILoader.cab
c:\windows\Downloaded Program Files\STJNILoader.inf

c:\windows\Downloaded Program Files\LNWebAssist.dll - O16 -: {9519B2A2-6592-4E41-8290-D0298459270C}
hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-28 22:14:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(1420)
c:\windows\system32\pwdmon.dll

- - - - - - - > 'explorer.exe'(2980)
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
c:\program files\Iomega\DriveIcons\IMGHOOK.DLL
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\progra~1\Iomega\System32\ActivityDisk.exe
c:\program files\lotus\notes\ntmulti.exe
c:\progra~1\AT&TNE~1\NetCfgSv.EXE
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\system32\QCONSVC.EXE
c:\windows\system32\TpKmpSvc.exe
c:\windows\system32\drivers\trcboot.exe
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Personal Communications\pcs_agnt.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\windows\system32\acs.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\Verizon Online\bin\mpbtn.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Webroot\WebrootSecurity\SSU.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-12-28 22:33:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-29 03:32:16
ComboFix2.txt 2008-12-28 19:43:20

Pre-Run: 20,178,239,488 bytes free
Post-Run: 20,115,136,512 bytes free

328 — E O F — 2008-12-20 00:20:49
Hi no need to keep running Combofix, I will put together a script for you as soon as I get back from my morning coffee run to 7-11 :) your AV will continue to pick it up until we are done, and do the clean up, because its still in the quarantine / restore files. I will post back shortly.
Hi paultpa,

Please do the following steps in the order as they are posted….

I need to make sure that you have an updated copy of Combofix, and just allow it to make any changes when you run it.

ComboFix Removal
Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]
===============================================

ComboFix

Please download ComboFix from Here or Here

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Combofix Script.txt
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\windows\system32\qnbukjdd.tmp
Folder::
c:\windows\Internet Logs
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c70791ae-a9aa-11dc-ac77-0014a43bba3f}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

===============================================

Norton Removal Tool

It looks like you still have some parts of Norton still running on your system. Please visit Symantec support by clicking HERE

Choose the Norton product you had installed.

Then follow the steps listed on the page that opens.

===============================================

ATF Cleaner

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

===============================================

Kaspersky WebScanner
please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
===============================================

Needed in your next reply:

Combofix log
Kaspersky WebScanner results
Fresh HijackThis log

And let me know how things are running now :thumbup:
G'day BHowett,

new info for you, an item of note, and a concern.

First, the logs you requested are below. I ran the ComboFix update, went down the punch list in your reply to me, clicked on the Symantec link to remove lingering files or Symantec processes, and got totally locked up. Note that upon reboot I lost the ComboFix report, so ran another this morning after I ran Kaspersky's overnight. I'll try the Symantec link and deletion again later.

The removals from ATF's Atribune were overpowering . . . 22.xMB! That's quite a bonus to this, as I clean all cache files before every shutdown (except Java, never knew it was there).

BTW, what is a prefetch, and do I need to keep them? rsvp if you have an extra minute.

The concern is that after running ComboFix I receive a stream of requests from both my Checkpoint Integrity firewall and also Spybot asking for approvals to allow applications and access. I allow all, following your suggestion. But I am in an awkward position, as some are suggested by Spybot as shady, like ctfmon.exe. Since I see that ComboFix still cannot access tempfile01, am I letting the problems back in?

Finally, here are the logs you requested. Note the times and dates on the scans.

Next steps?

thx,
paultpa




ComboFix 08-12-29.01 - Paul A. Parone 2008-12-30 7:23:57.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.640 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Paul A. Parone\Desktop\CFScript.txt.txt
AV: Webroot AntiVirus with AntiSpyware *On-access scanning enabled* (Updated)
FW: Webroot Internet Security Essentials *disabled*
FW: Integrity Flex Firewall *enabled*
* Created a new restore point

FILE ::
c:\windows\system32\qnbukjdd.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Internet Logs\IAMDB.RDB
c:\windows\Internet Logs\IBM-546DEA067E3.ldb
c:\windows\Internet Logs\xDB1.tmp
c:\windows\Internet Logs\xDB2.tmp
c:\windows\Internet Logs\ZALog.txt
c:\windows\Internet Logs . . . . failed to delete
c:\windows\Internet Logs\fwdbglog.txt . . . . failed to delete
c:\windows\Internet Logs\fwpktlog.txt . . . . failed to delete
c:\windows\Internet Logs\tvDebug.log . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-30 )))))))))))))))))))))))))))))))
.

2008-12-30 07:19 . 2008-12-30 07:20 d——– C:\32788R22FWJFW
2008-12-29 20:09 . 2008-12-30 07:37 d——– c:\windows\Internet Logs
2008-12-28 13:56 . 2008-12-28 13:55 2,888,402 -ra—— c:\program files\ComboFix.exe
2008-12-24 07:36 . 2008-12-24 07:36 d——– c:\documents and settings\Paul A. Parone\.java
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\documents and settings\Paul A. Parone\Application Data\Malwarebytes
2008-12-17 17:05 . 2008-12-17 17:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-17 17:05 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-17 17:05 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-15 16:37 . 2008-12-25 10:34 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\program files\Webroot
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\program files\AskSBar
2008-12-14 14:51 . 2008-12-14 14:51 d——– c:\documents and settings\Paul A. Parone\Application Data\Webroot
2008-12-14 14:51 . 2008-12-14 15:05 d——– c:\documents and settings\All Users\Application Data\Webroot
2008-12-14 14:51 . 2008-12-14 14:51 d——– C:\Binaries
2008-12-14 14:51 . 2008-11-13 17:11 1,553,272 –a—— c:\windows\WRSetup.dll
2008-12-14 14:46 . 2008-12-14 14:46 164 –a—— C:\install.dat
2008-12-13 20:51 . 2008-12-13 20:51 4,474 –a—— c:\windows\GATHER.KM
2008-12-13 20:42 . 2008-12-13 20:42 d——– c:\program files\Kaspersky Lab
2008-12-13 19:59 . 2008-12-13 19:59 27 –a—— c:\windows\sssTbarV2.ini
2008-12-13 18:19 . 2008-12-13 20:31 d——– c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-12-13 17:36 . 2008-12-13 17:36 73 –a—— c:\windows\st_affiliate.ini
2008-12-13 15:37 . 2008-02-02 07:43 102,664 –a—— c:\windows\system32\drivers\tmcomm.sys
2008-12-11 09:25 . 2008-12-11 09:25 d——– c:\program files\Alwil Software
2008-12-10 14:29 . 2008-12-27 18:48 d——– c:\program files\Spybot - Search & Destroy
2008-12-10 14:29 . 2008-12-28 07:18 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-10 08:14 . 2008-12-10 08:14 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-10 08:13 . 2008-12-10 14:22 d——– c:\program files\SUPERAntiSpyware
2008-12-10 08:13 . 2008-12-10 14:22 d——– c:\documents and settings\Paul A. Parone\Application Data\SUPERAntiSpyware.com
2008-12-09 08:02 . 2008-12-09 08:02 d——– c:\windows\system32\config\systemprofile\Application Data\HPAppData
2008-12-07 21:35 . 2008-12-07 21:35 d–h—– c:\windows\PIF
2008-11-12 16:02 . 2008-11-12 16:02 170,608 –a—— c:\windows\system32\drivers\ssidrv.sys
2008-11-12 16:02 . 2008-11-12 16:02 29,808 –a—— c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 16:02 . 2008-11-12 16:02 23,152 –a—— c:\windows\system32\drivers\sshrmd.sys
2008-11-12 06:45 . 2008-09-04 12:15 1,106,944 ——— c:\windows\system32\dllcache\msxml3.dll
2008-11-12 06:45 . 2008-10-24 06:21 455,296 ——— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 12:14 . 2008-11-11 12:14 d——– c:\program files\Common Files\Adobe AIR
2008-11-11 12:12 . 2008-11-12 06:41 d——– c:\program files\NOS
2008-11-11 12:12 . 2008-11-12 06:41 d——– c:\documents and settings\All Users\Application Data\NOS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-27 22:20 ——— d—–w c:\program files\Trend Micro
2008-12-26 21:15 90,112 —-a-w c:\windows\DUMP3170.tmp
2008-12-14 01:34 ——— d—–w c:\documents and settings\Paul A. Parone\Application Data\AVG7
2008-12-14 01:34 ——— d—–w c:\documents and settings\All Users\Application Data\Avg7
2008-12-13 06:40 3,593,216 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-10 12:54 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-07 21:45 2,174,976 ——w c:\windows\system32\dllcache\WMVCore.dll
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ——w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 —-a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-03 10:02 247,326 —-a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 21:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 —-a-w c:\windows\system32\win32k.sys
2008-09-15 12:12 1,846,400 ——w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:14 1,307,648 ——w c:\windows\system32\msxml6.dll
2008-09-10 01:14 1,307,648 ——w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 10:41 333,824 ——w c:\windows\system32\dllcache\srv.sys
2008-09-06 03:30 241,704 ——w c:\windows\system32\dllcache\wgaLogon.dll
2008-09-06 03:29 917,032 ——w c:\windows\system32\dllcache\WgaTray.exe
2008-09-04 17:15 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-01-02 23:20 389,120 -c–a-w c:\documents and settings\Paul A. Parone\stas75_20060810.0001.dll
2007-09-30 15:29 21,300,224 -c–a-w c:\program files\antivir_workstation_win7u_en_h.exe
2006-07-27 19:39 28,672 -c–a-w c:\documents and settings\Paul A. Parone\atwbxdet.dll
2000-12-12 16:17 100,432 -c—-w c:\program files\Win2000PPAHotfix.exe
2004-02-04 19:33 9,060,352 -c–a-w c:\program files\internet explorer\plugins\axbqv32.dll
2008-08-24 11:24 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082420080825\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-12-29_20.18.53.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-29 20:41:36 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-30 01:40:43 32,768 -c–a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-29 20:41:36 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-30 01:40:43 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-29 20:41:36 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-30 01:40:43 32,768 -c–a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-30 01:11:26 3,940 —-a-w c:\windows\Temp\wrstemp\S-1-5-18.dat
+ 2008-12-30 12:36:30 3,940 —-a-w c:\windows\Temp\wrstemp\S-1-5-18.dat
- 2008-12-30 01:11:26 4,182 —-a-w c:\windows\Temp\wrstemp\S-1-5-19.dat
+ 2008-12-30 12:36:30 4,182 —-a-w c:\windows\Temp\wrstemp\S-1-5-19.dat
- 2008-12-30 01:11:26 4,250 —-a-w c:\windows\Temp\wrstemp\S-1-5-20.dat
+ 2008-12-30 12:36:30 4,250 —-a-w c:\windows\Temp\wrstemp\S-1-5-20.dat
- 2008-12-30 01:14:06 5,526 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-1005.dat
+ 2008-12-30 12:38:12 5,526 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-1005.dat
- 2008-12-30 01:11:26 4,710 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-500.dat
+ 2008-12-30 12:36:30 4,710 —-a-w c:\windows\Temp\wrstemp\S-1-5-21-3249066861-508329706-4179432153-500.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-12-14 66912]

[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-12-14 14:51 66912 –a—— c:\program files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\program files\IBM\Messages By IBM\ibmmessages.exe" [2004-07-22 442368]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Iomega Active Disk"="c:\program files\Iomega\AutoDisk\AD2KClient.exe" [2001-09-13 45056]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrackPointSrv"="c:\windows\system32\tp4serv.exe" [2003-11-13 94208]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-07-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-07-30 118784]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 897024]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2004-08-06 94208]
"TP4EX"="c:\windows\system32\tp4ex.exe" [2002-09-04 53248]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2003-12-25 208896]
"UC_Start"="c:\program files\IBM\Updater\\ucstartup.exe" [2004-07-14 36864]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-09-02 127035]
"IBMPRC"="c:\ibmtools\UTILS\ibmprc.exe" [2004-03-19 90112]
"QCWLICON"="c:\program files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2004-08-18 81920]
"BMMGAG"="c:\progra~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2004-08-25 110592]
"BMMLREF"="c:\program files\ThinkPad\Utilities\BMMLREF.EXE" [2004-08-25 20480]
"BMMMONWND"="c:\progra~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2004-08-25 395776]
"Motive SmartBridge"="c:\progra~1\VERIZO~1\SMARTB~1\MotiveSB.exe" [2002-05-18 327680]
"Zone Labs Client"="c:\program files\CheckPoint\Integrity Client\iclient.exe" [2005-05-10 931584]
"Iomega Startup Options"="c:\program files\Iomega\Common\ImgStart.exe" [2001-01-17 45056]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2001-09-12 61440]
"ISSI EZUpdate Service"="c:\sdwork\issimsvc.exe" [2006-12-05 203264]
"stgclean"="c:\sdwork\w32main2.exe" [2006-12-13 260608]
"QCTray"="c:\progra~1\ThinkPad\CONNEC~1\QCTray.exe" [2004-08-18 708608]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-10-07 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-09-11 972064]
Verizon Online Support Center.lnk - c:\program files\Verizon Online\bin\matcli.exe [2005-10-29 204800]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
2004-08-18 05:30 258048 c:\windows\system32\QConGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli pwdmon

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AT&T Network Client\\NetClient.exe"=
"c:\\sdwork\\w32main2.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IBM\\Updater\\ucsmb.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\Microsoft Office\\Live Meeting 8\\Console\\PWConsole.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\English\\setup.exe"=

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\DRIVERS\ssfs0bbc.sys [2008-11-12 29808]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.SYS [2005-10-07 11520]
R1 ASMBATT;ASMBATT;c:\windows\system32\drivers\ASMBATT.SYS [2005-10-07 4992]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2005-10-07 2432]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\Tppwr.sys [2005-10-07 16384]
R2 ibmfilter;ibmfilter;\??\c:\windows\system32\drivers\ibmfilter.sys [2004-09-23 64256]
R2 NsTrcNT;NsTrcNT;c:\windows\system32\drivers\nstrcnt.sys [2005-10-31 10816]
R2 pcscoax;3270 Coax Driver;c:\windows\system32\drivers\pcscoax.sys [2005-10-31 30720]
R2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" [2008-12-14 1086840]
R2 WRTService;WRT Service;c:\windows\WRTService.exe [2005-12-04 77824]
R3 ABVPN2K;Net Firewall Miniport Interface;c:\windows\system32\DRIVERS\abvpn2k.sys [2005-10-31 164224]
R3 avpnnic;AGN Virtual Network Adapter;c:\windows\system32\DRIVERS\avpnnic.sys [2005-10-31 13952]
R3 KLOGNT;KLOGNT;c:\windows\system32\drivers\klognt.sys [2005-10-31 22504]
R3 Tp4Track;IBM PS/2 TrackPoint Driver;c:\windows\system32\DRIVERS\tp4track.sys [1980-01-01 13904]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.SYS [2005-10-07 12288]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-12-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]

2005-10-07 c:\windows\Tasks\BMMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\BMMTASK.EXE [2004-08-25 03:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.cnn.com/
uSearch Bar = hxxp://safesearch.cyberdefender.com/smallsearch.html
uInternet Settings,ProxyOverride = 127.0.0.1;
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\system32\stfm31.dll - c:\windows\system32\stsm31.dll
c:\windows\system32\stas31.dll
c:\windows\Downloaded Program Files\STJNILoader.ocx
O16 -: {7261EE42-318E-490A-AE8F-77649DBA1ECA}
hxxps://www-1.ibm.com/sametime/stmeetingroomclient/STJNILoader.cab
c:\windows\Downloaded Program Files\STJNILoader.inf

c:\windows\Downloaded Program Files\LNWebAssist.dll - O16 -: {9519B2A2-6592-4E41-8290-D0298459270C}
hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-30 07:33:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\TEMP\wrstemp\SSMS276BBE60-1062-4F0E-ABBB-E13F309CC52D.tmp 7995392 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(1428)
c:\windows\system32\pwdmon.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\progra~1\Iomega\System32\ActivityDisk.exe
c:\program files\lotus\notes\ntmulti.exe
c:\progra~1\AT&TNE~1\NetCfgSv.EXE
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\system32\QCONSVC.EXE
c:\windows\system32\TpKmpSvc.exe
c:\windows\system32\drivers\trcboot.exe
c:\windows\system32\ZoneLabs\vsmon.exe
c:\program files\Personal Communications\pcs_agnt.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\windows\system32\acs.exe
c:\windows\system32\wscntfy.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\IBM\Updater\jre\bin\javaw.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Verizon Online\bin\mpbtn.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Webroot\WebrootSecurity\SSU.exe
.
**************************************************************************
.
Completion time: 2008-12-30 7:44:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-30 12:43:54
ComboFix2.txt 2008-12-30 01:21:19

Pre-Run: 20,123,889,664 bytes free
Post-Run: 20,144,500,736 bytes free

308 — E O F — 2008-12-20 00:20:49





KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, December 30, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, December 29, 2008 20:15:59
Records in database: 1529651
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 70196
Threat name: 1
Infected objects: 7
Suspicious objects: 0
Duration of the scan: 02:35:28


File name / Threat name / Threats count
C:\Program Files\IBM\checker\pskill.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\Siebel\checkerv2inst.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1141842822796\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1141842856781\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1141842880671\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1141842905140\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1
C:\temp\Checker1161874666453\checkerv2inst270.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1

The selected area was scanned.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:01:23 AM, on 12/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
c:\sdwork\issimsvc.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\System32\drivers\trcboot.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Personal Communications\PCS_AGNT.EXE
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\WRTService.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\tp4serv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\IBM\Updater\jre\bin\javaw.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\CheckPoint\Integrity Client\iclient.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Iomega\AutoDisk\AD2KClient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [TrackPointSrv] "C:\WINDOWS\system32\tp4serv.exe"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [TPKMAPHELPER] "C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" -helper
O4 - HKLM\..\Run: [TPHOTKEY] "C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe"
O4 - HKLM\..\Run: [TP4EX] "C:\WINDOWS\system32\tp4ex.exe"
O4 - HKLM\..\Run: [EZEJMNAP] "C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe"
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] "C:\WINDOWS\system32\dla\tfswctrl.exe"
O4 - HKLM\..\Run: [IBMPRC] "C:\IBMTOOLS\UTILS\ibmprc.exe"
O4 - HKLM\..\Run: [QCWLICON] "C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE"
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] "C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE"
O4 - HKLM\..\Run: [BMMMONWND] "C:\WINDOWS\system32\rundll32.exe" C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [Motive SmartBridge] "C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] "C:\Program Files\Iomega\Common\ImgStart.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [stgclean] "c:\sdwork\w32main2.exe" /cleanup
O4 - HKLM\..\Run: [QCTray] "C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ibmmessages] "C:\Program Files\IBM\Messages By IBM\ibmmessages.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Iomega Active Disk] "C:\Program Files\Iomega\AutoDisk\AD2KClient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1201959414343
O16 - DPF: {7261EE42-318E-490A-AE8F-77649DBA1ECA} (JNILoader Control) - https://www-1.ibm.com/sametime/stmeetingroo…STJNILoader.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://regatta.mcsgroup.com/dwa7W.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mlmeetings.webex.com/client/v_myweb…ent/ieatgpc.cab
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Iomega Activity Disk2 - Iomega Corporation - C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
O23 - Service: ISSI EZUpdate (ISSIMon) - IBM Global Services - c:\sdwork\issimsvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TNE~1\NetCfgSv.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrcBoot - Unknown owner - C:\WINDOWS\System32\drivers\trcboot.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
O23 - Service: WRT Service (WRTService) - Unknown owner - C:\WINDOWS\WRTService.exe

–
End of file - 11770 bytes
BHowett, Am not sure what Symantec app IBM installed on this laptop. Any ideas on how to find that out? I used "remove software" in control panel to uninstall Symantec some time ago and never got CDs with the product. paultpa
Hi paultpa,

BTW, what is a prefetch, and do I need to keep them? rsvp if you have an extra minute.

When a Windows system boots, a large number of files need to be read into memory and processed. Often, this includes loading different segments of the same file at different times. As a result, a significant amount of time is spent opening and accessing files multiple times, where a single access would be more efficient. The prefetcher works by watching what code and data is accessed during the boot process (including reads of the NTFS Master File Table), and recording a trace file of this activity. Future boots can then use the information recorded in this trace file to load code and data in a more optimal fashion. The boot prefetcher will continue to watch for such activity until 30 seconds after the user's shell has started, or until 60 seconds after all services have finished initializing, or until 120 seconds after the system has booted, whichever elapses first.

The Prefetch folder is self cleaning at 128 entries by Windows. When the 128 limit is reached Windows will keep the 32 most used prefetch files. Cleaning the folder before this will actually hurt your Windows load and all application load times because the files will no longer be available for the prefetch.

Am not sure what Symantec app IBM installed on this laptop. Any ideas on how to find that out?

I'm not quite sure what you mean here, did you see something in you add/remove programs?


anyway your logs look good, how are things runnng now? Any problems?
BHowett, The logs may look fine but I see that Virtumonde is still installed and actice, according to a Malewarebytes scan last night. Below is a log from a scan this morning (31 Dec 08). In addition, I still cannot see my Temporary Internet Files folder. Our work is not done yet. Re your question, you mentioned earlier that you still see traces of Symantec on my system, and posted a link. That site asks me to identify the Symantec product that is installed. I do not know as that was installed by IBM when they configured the PC. I have since used uninstall on Symantec. Thought you might have a way to identify what was installed before so I could make the right choice. Standing by. thx, paultpa Malwarebytes' Anti-Malware 1.31 Database version: 1514 Windows 5.1.2600 Service Pack 3 12/31/2008 7:52:08 AM mbam-log-2008-12-31 (07-52-08).txt Scan type: Quick Scan Objects scanned: 58181 Time elapsed: 5 minute(s), 51 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi paultpa,

Re your question, you mentioned earlier that you still see traces of Symantec on my system, and posted a link. That site asks me to identify the Symantec product that is installed. I do not know as that was installed by IBM when they configured the PC. I have since used uninstall on Symantec. Thought you might have a way to identify what was installed before so I could make the right choice.


Oh I see what you mean…. I can not really tell what one it was, so we will yank it out the old way :)

Delete an NT Service

  • Open HiJackThis
  • Click on the "Config…" button on the bottom right
  • Click on the tab "Misc Tools"
  • click on "delete an NT service"
  • Copy and paste this in: CLTNetCnService
  • Click "ok", then reboot

===========================================================

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)


Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):

Symantec or anything that says Norton

Please note any other programs that you don’t recognize in that list in your next response

Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present):

C:\Program Files\Common Files\Symantec Shared

After that, Reboot.

===========================================================

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 2 (Fix + Hosts)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)

===========================================================

And let take a deeper look at some things…

  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
===========================================================

Needed in your next reply:

Lop S&D.exe log
RSIT log

And as always let me know how things are running :thumbup:
BHowett, good to see you. Before I follow your lastest advice here is the latest Kaspersky scan. Seems it missed the virtumonde infection in one of my registry keys that showed on Malewarebytes earlier: KASPERSKY ONLINE SCANNER 7 REPORT Wednesday, December 31, 2008 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, December 31, 2008 09:22:08 Records in database: 1537300 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ F:\ Scan statistics: Files scanned: 78449 Threat name: 1 Infected objects: 7 Suspicious objects: 0 Duration of the scan: 02:52:51 File name / Threat name / Threats count C:\Program Files\IBM\checker\pskill.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1 C:\Siebel\checkerv2inst.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1 C:\temp\Checker1141842822796\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1 C:\temp\Checker1141842856781\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1 C:\temp\Checker1141842880671\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1 C:\temp\Checker1141842905140\checkerv2inst250.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1 C:\temp\Checker1161874666453\checkerv2inst270.exe Infected: not-a-virus:NetTool.Win32.PsKill.a 1 The selected area was scanned.
BHowett, Your first suggestion re "deleting an NT Service" is not responding as you explained. After pasting "CLTNetCnService" in the window and clicking "OK" I get a popup that says "the service is enabled or running. Delete it first, using Hijack This itself (from the scan results) or the Services Misc window." Decision? paultpa
Hi paultpa,

Sorry I forgot the step to stop it first, so we will knock it out another way…

Delete bad services
Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the quote to Notepad. Save it as "All Files" and name it FixServices.bat Please save it on your desktop.

@echo off
sc stop CLTNetCnService
sc delete CLTNetCnService
exit



Double click FixServices.bat. A window will open and close. This is normal.



After that just follow the rest of the steps…

The Kaspersky scan seems fine, it looks like Malewarebytes took care of that entry.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI