PDA

View Full Version : malware alerts / www.savetheinformation.com



boomerang2
2007-08-22, 00:54
as reported in other posts I am getting malware alerts from Windows and also pop up alerts saying i am infected. Some windows pop up and redirect me to the savetheinformation domain.
To cut to the chase, here is the HJT log and further below is the Combo log

++++++++++++++++++
Logfile of HijackThis v1.97.7
Scan saved at 22:42:19, on 21/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\program files\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\DOCUME~1\Mark\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default.aspx?c=uk&l=en&s=gen
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=1070512
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\qoclqtpl.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\qoclqtpl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter (HKLM)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.co.uk/s/v/22.18/uploader2.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

++++++++++++++++++ Combo log to follow

boomerang2
2007-08-22, 01:06
ComboFix 07-08-17.2 - "Mark" 2007-08-21 22:59:15.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.329 [GMT 1:00]


((((((((((((((((((((((((( Files Created from 2007-07-21 to 2007-08-21 )))))))))))))))))))))))))))))))


2007-08-21 22:17 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-21 22:11 <DIR> d-------- C:\WINDOWS\LastGood
2007-08-21 22:11 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-08-21 21:13 <DIR> d-------- C:\DOCUME~1\Mark\APPLIC~1\Sunbelt Software
2007-08-21 20:51 0 --a------ C:\WINDOWS\system32\SBRC.dat
2007-08-21 20:51 0 --a------ C:\WINDOWS\system32\SBFC.dat
2007-08-21 20:50 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Sunbelt Software
2007-08-21 20:21 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\APPLIC~1\Gtek
2007-08-21 20:21 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\ATI
2007-08-21 20:20 1,835,008 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-21 20:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sunbelt Software
2007-08-21 20:00 <DIR> d-------- C:\Program Files\Sunbelt Software
2007-08-20 21:27 <DIR> d-------- C:\WINDOWS\pss
2007-08-20 20:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-18 13:28 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
2007-08-18 13:28 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-08-18 13:28 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-08-18 13:28 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-08-18 13:28 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-08-18 13:28 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
2007-08-18 13:28 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-08-18 13:28 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-08-18 13:27 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-08-18 13:27 <DIR> d-------- C:\Program Files\Ahead
2007-08-17 23:42 131,680 --a------ C:\WINDOWS\system32\qoclqtpl.dll
2007-08-15 16:15 <DIR> d-------- C:\DOCUME~1\Mark\APPLIC~1\InterVideo
2007-08-15 16:12 <DIR> d-------- C:\Program Files\InterActual
2007-08-15 16:10 831,600 --a------ C:\WINDOWS\system32\Ctaa1.dat
2007-08-15 16:10 77,824 --a------ C:\WINDOWS\system32\ctdvda32.dll
2007-08-15 16:10 333,600 --a------ C:\WINDOWS\system32\drivers\ctdvda2k.sys
2007-08-15 16:10 204,800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2007-08-15 16:10 200,704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2007-08-15 16:10 20,480 --a------ C:\WINDOWS\system32\IVIresize.dll
2007-08-15 16:10 192,512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
2007-08-15 16:10 192,512 --a------ C:\WINDOWS\system32\IVIresizeM6.dll
2007-08-15 16:10 188,416 --a------ C:\WINDOWS\system32\IVIresizePX.dll
2007-08-15 16:10 122,880 --a------ C:\WINDOWS\system32\cddvdint.dll
2007-08-15 16:10 <DIR> d-------- C:\Program Files\InterVideo
2007-08-15 16:10 <DIR> d-------- C:\Program Files\Creative
2007-08-15 16:10 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2007-08-15 11:16 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2007-08-15 11:16 15,360 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2007-08-15 11:14 <DIR> d-------- C:\Program Files\adaptec
2007-08-15 11:02 <DIR> d-------- C:\Program Files\MP3 Workshop
2007-08-15 10:53 <DIR> d-------- C:\DOCUME~1\Mark\APPLIC~1\Help
2007-08-15 09:56 <DIR> d-------- C:\Program Files\MightyDAC 1.3.3
2007-08-15 09:26 299,520 --a------ C:\WINDOWS\uninst.exe
2007-08-15 09:03 <DIR> d-------- C:\Program Files\audiograbber
2007-08-14 20:43 <DIR> d-------- C:\Program Files\Winamp
2007-08-14 20:36 <DIR> d-------- C:\TempDVD
2007-08-14 20:36 <DIR> d-------- C:\Program Files\dvdSanta
2007-07-30 22:18 <DIR> d-------- C:\DOCUME~1\Mark\APPLIC~1\DivX
2007-07-30 22:17 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-07-30 22:17 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-07-30 22:17 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-07-28 22:33 <DIR> d-------- C:\DOCUME~1\Mark\APPLIC~1\Skype
2007-07-28 22:10 <DIR> d-------- C:\Program Files\Skype
2007-07-28 22:10 <DIR> d-------- C:\Program Files\Common Files\Skype
2007-07-28 22:10 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
2007-07-28 22:06 <DIR> d-------- C:\WINDOWS\system32\runtime
2007-07-28 21:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-21 20:01 --------- d-------- C:\Program Files\Ace Utilities
2007-08-21 19:55 --------- d-------- C:\DOCUME~1\Mark\APPLIC~1\MailWasherPro
2007-08-20 20:30 --------- d-------- C:\Program Files\eMule
2007-08-15 16:10 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-30 22:17 --------- d-------- C:\Program Files\DivX
2007-07-28 22:06 --------- d-------- C:\Program Files\Google
2007-07-21 20:00 --------- d-------- C:\Program Files\Picasa2
2007-07-09 20:07 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-07-09 20:07 36624 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-07-09 20:07 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-09 20:07 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-09 20:07 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-09 20:05 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-07-09 20:05 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-07-09 20:05 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-07-09 20:05 740442 --a------ C:\WINDOWS\system32\DivX.dll
2007-07-09 20:05 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-07-09 20:05 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-07-09 20:05 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-07-09 20:05 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-07-09 20:05 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-07-09 20:05 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-07-09 20:05 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-07-09 20:05 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-07-09 20:05 124472 --a------ C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-07-09 20:05 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-06-26 07:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 07:08 1104896 --------- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-24 22:12 --------- d-------- C:\DOCUME~1\Mark\APPLIC~1\Template
2007-06-24 21:29 --------- d-------- C:\Program Files\Windows Media Connect 2
2007-06-15 14:37 27376 --a------ C:\WINDOWS\system32\SBBD.exe
2007-06-13 11:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-13 11:23 1033216 --------- C:\WINDOWS\system32\dllcache\explorer.exe
2007-05-21 21:53 98816 --a------ C:\WINDOWS\system\cddriver.dll
2007-05-21 21:53 253952 --a------ C:\WINDOWS\system\ntvideo.dll
2007-05-21 21:53 211456 --a------ C:\WINDOWS\system\ntsound.dll
2007-05-21 21:53 207414 --a------ C:\WINDOWS\system\jiaowin.dll
2007-05-21 21:53 155136 --a------ C:\WINDOWS\system\jiaocd.dll
2007-05-21 21:53 122368 --a------ C:\WINDOWS\system\jiaompeg.dll
2007-05-20 20:40:16 88 --sh--r C:\WINDOWS\system32\BDCEAB0D12.sys
2007-05-20 20:40:16 2,672 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-08-17 23:42 131680 --a------ C:\WINDOWS\system32\qoclqtpl.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\qoclqtpl.dll [2007-08-17 23:42 131680]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"SigmatelSysTrayApp"="stsystra.exe" [2006-09-22 11:06 C:\WINDOWS\stsystra.exe]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 10:12]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-09-22 11:47]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-08-23 16:14]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 04:48]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 20:29]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 12:05]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 14:49]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 10:26]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe" [2006-08-14 14:20]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2005-08-10 12:49]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 17:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-21 22:28]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-06-16 00:15]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [2005-05-31 01:04]
"SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-06-15 15:17]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 02:24]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-05-11 13:20]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-07-28 21:58:01]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-08-15 16:10:47]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-05-12 04:48:08]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qoclqtpl]
qoclqtpl.dll 2007-08-17 23:42 131680 C:\WINDOWS\system32\qoclqtpl.dll


*Newly Created Service* - CATCHME

Contents of the 'Scheduled Tasks' folder
2007-08-21 21:05:40 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (BOOMERANG2-Mark).job - c:\program files\mcafee.com\vso\mcmnhdlr.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-21 23:03:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

**************************************************************************

Completion time: 2007-08-21 23:05:04
C:\ComboFix2.txt ... 2007-08-21 22:28

--- E O F ---

...that i can no longer launch outlook successfully

and that the problems came after i visited a serials web site (i know, naughty naughty)

i also get the same symptoms when in safe mode and or disconnected from internet

tashi
2007-08-23, 20:52
Hello.

Appears you missed our forum sticky topics:

"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Please Post ONLY The Logs We Ask For, (http://forums.spybot.info/showthread.php?t=16806)

I merged two of your posts, but just in case:
The Waiting Room: Post here if waiting for help longer than four days (http://forums.spybot.info/forumdisplay.php?f=37)

Best regards. :)

tashi
2007-08-28, 02:35
This topic has been moved to archives.

If you need the thread re-opened, please send me a private message (pm) and provide a link.

Applies only to the original poster, anyone else with similar problems please start your own topic.