PDA

View Full Version : can't remove hldrrr.exe mdelk.exe



my5sons
2008-04-28, 23:02
1. I can't boot into Safe Mode. Each time I try, I get the Blue Screen.
2. So I ran Spybot Search & Destroy in Normal Mode. It found FirstRunRRR in the registry and I clicked Fix.
3. I rebooted, and get a popup window that says "Select File to Crack" and displays "My Documents"
4. I can't run the Online Virus Checker Kapersky. I click Accept, but nothing happens.
5. I found the files hldrrr.exe and mdelk.exe in windows/system32/drivers, I delete them and they reappear. I went to Trend Micro first, and they recommend that I turn off System Restore and run my Antivirus. No such luck there, so I am here now.
6. I can't find where the problem is, and why it keeps reappearing....

Here is my HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:49, on 2008-04-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\AdventNet\WebNMS\apache\bin\Apache.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
C:\Program Files\ISS\Proventia Desktop\vpatch.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.mot.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.mot.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.mot.com:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.mot.com;*.gi.com;<local>
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: RSAToolbar - {749F8452-7D28-4658-A903-9B047E5A2CE8} - C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [CSCAdvantage] "C:\Program Files\Help Desk\CSCAdv.exe" /s
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CSCLogonInfo] C:\WINDOWS\UsrLogon.exe
O4 - HKLM\..\Run: [SupportSoft_Amer_Motorola] "C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" /P SupportSoft_Amer_Motorola
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [URLy Warning] "C:\Program Files\URLy Warning\URLyWarning.exe" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-863651691-3918403040-59684098-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'sdm')
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://access.motorola.com/dana-cached/setup/JuniperSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\Software\..\Telephony: DomainName = ds.mot.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = am.mot.com,e1.bcs.mot.com,gic.gi.com,w1.bcs.mot.com,gi.com,corp.mot.com,ds.mot.com,mot.com,sps.mot.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = am.mot.com,e1.bcs.mot.com,gic.gi.com,w1.bcs.mot.com,gi.com,corp.mot.com,ds.mot.com,mot.com,sps.mot.com
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ApacheForSDM - Apache Software Foundation - C:\AdventNet\WebNMS\apache\bin\Apache.exe
O23 - Service: Adaptive Server Anywhere - WebNmsDB (ASANYs_WebNmsDB) - iAnywhere Solutions, Inc. - C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\blackd.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\RapApp.exe
O23 - Service: Reflection Line Printer Daemon - WRQ, Inc. - C:\Program Files\Reflection\lpdserv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Motorola SDM (SDM Service) - Unknown owner - C:\WINDOWS\JavaService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (supportsoft_amer_motorola) (sprtsvc_supportsoft_amer_motorola) - SupportSoft, Inc. - C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SupportSoft Repair Service (supportsoft_amer_motorola) (tgsrvc_supportsoft_amer_motorola) - SupportSoft, Inc. - C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
O23 - Service: ISS Buffer Overflow Exploit Prevention (VPatch) - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\vpatch.exe

--
End of file - 11322 bytes

Rorschach112
2008-04-28, 23:19
Hello

Please download ComboFix from Here (http://subs.geekstogo.com/ComboFix.exe) or Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

If you are using Firefox, make sure that your download settings are as follows:

Tools->Options->Main tab
Set to "Always ask me where to Save the files".

During the download, rename Combofix to Combo-Fix as follows:

http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_FF.gif

http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_rename.gif


It is important you rename Combofix during the download, but not after.
Please do not rename Combofix to other names, but only to the one indicated.
Close any open browsers.
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

-----------------------------------------------------------

Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Click on this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

-----------------------------------------------------------


Close any open browsers.
WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
If there is no internet connection after running Combofix, then restart your computer to restore back your connection.


-----------------------------------------------------------
Double click on combo-Fix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

my5sons
2008-04-28, 23:47
Thank you for the quick reply. I did as you said, renamed it to Combo-Fix.exe and closed/disabled all antivirus/spyware stuff. Here is the log.


ComboFix 08-04-27.3 - mgi2890 2008-04-28 17:34:59.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.546 [GMT -4:00]
Running from: D:\Profiles\MGI2890\Desktop\Combo-Fix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\mdelk.exe

.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-28 )))))))))))))))))))))))))))))))
.

2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- D:\Profiles\All Users\Application Data\Kaspersky Lab
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- C:\WINDOWS\LastGood
2008-04-28 15:24 . 2008-04-28 15:37 <DIR> d-------- D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2008-04-28 15:24 . 2008-04-28 15:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-28 15:23 . 2008-04-28 15:23 9,722,720 --a------ C:\spybotsd152.exe
2008-04-28 14:09 . 2008-04-28 15:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-28 01:32 . 2008-04-28 01:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-28 01:32 . 2008-04-28 01:32 812,344 --a------ C:\HJTInstall.exe
2008-04-28 00:50 . 2008-04-28 00:50 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-28 00:45 . 2008-04-27 20:49 <DIR> d-------- C:\SDFix
2008-04-27 23:32 . 2008-04-27 23:32 650,296 --a------ C:\PREVXCSIFREE(2).EXE
2008-04-27 23:12 . 2008-04-27 23:17 2,205,157 --a------ C:\IceSword122en.zip
2008-04-27 23:01 . 2008-04-27 23:01 650,296 --a------ C:\PREVXCSIFREE.EXE
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-27 22:39 . 2008-04-27 22:40 20,597,104 --a------ C:\aaw2007.exe
2008-04-25 22:05 . 2008-04-25 22:05 93,775 --a------ C:\2333.zip
2008-04-19 11:27 . 2008-04-19 11:27 <DIR> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-04-19 11:27 . 2008-04-24 12:21 275 --a------ C:\lxcjfire.csv
2008-04-19 11:27 . 2008-04-24 12:12 275 --a------ C:\lxcjfire.008
2008-04-19 11:27 . 2008-04-24 12:11 275 --a------ C:\lxcjfire.007
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.006
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.005
2008-04-19 11:27 . 2008-04-19 11:43 275 --a------ C:\lxcjfire.004
2008-04-19 11:27 . 2008-04-19 11:41 275 --a------ C:\lxcjfire.003
2008-04-19 11:27 . 2008-04-19 11:38 275 --a------ C:\lxcjfire.002
2008-04-19 11:27 . 2008-04-19 11:28 275 --a------ C:\lxcjfire.001
2008-04-19 11:27 . 2008-04-19 11:27 275 --a------ C:\lxcjfire.000
2008-04-19 11:22 . 2008-04-24 12:25 <DIR> d-------- C:\Lexmark
2008-04-17 18:20 . 2008-04-17 18:28 31,232 --a------ C:\proposedamendment(2).doc
2008-04-17 18:18 . 2008-04-17 18:18 23,552 --a------ C:\Proxy.doc
2008-04-17 18:18 . 2008-04-17 18:19 6,709 --a------ C:\proposedamendment.doc.part
2008-04-17 18:18 . 2008-04-17 18:18 0 --a------ C:\proposedamendment.doc
2008-04-17 18:15 . 2008-04-17 18:15 6,184 --a------ C:\Pheasant
2008-04-17 15:42 . 2008-04-27 23:07 8,704 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-15 09:45 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-15 09:45 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-08 20:50 . 2008-04-08 20:50 <DIR> d-------- D:\Profiles\All Users\Application Data\Office Genuine Advantage
2008-03-30 00:10 . 2008-03-30 00:10 732 --a------ C:\about_inc.php
2008-03-29 23:02 . 2008-03-29 23:02 <DIR> d-------- D:\Profiles\All Users\Application Data\FLEXnet
2008-03-29 22:01 . 2008-03-29 22:01 <DIR> d-------- D:\Profiles\NetworkService\Application Data\Juniper Networks
2008-03-29 02:02 . 2008-04-15 20:22 <DIR> d-------- C:\desktop

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-28 20:42 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-28 19:18 --------- d-----w C:\Program Files\Elaborate Bytes
2008-04-28 18:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 18:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 18:09 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-28 18:07 --------- d-----w C:\Program Files\Azureus
2008-04-28 18:05 --------- d-----w D:\Profiles\MGI2890\Application Data\Amazon
2008-04-28 18:05 --------- d-----w C:\Program Files\Amazon
2008-04-28 02:41 --------- d-----w D:\Profiles\All Users\Application Data\Lavasoft
2008-04-23 19:11 --------- d-----w D:\Profiles\MGI2890\Application Data\AdobeUM
2008-04-08 21:31 --------- d-----w D:\Profiles\MGI2890\Application Data\Vso
2008-03-28 19:08 --------- d-----w C:\Program Files\SlySoft
2008-03-27 02:11 --------- d-----w D:\Profiles\sdm.MGI2890-02\Application Data\Juniper Networks
2008-03-22 01:14 --------- d-----w C:\Program Files\MSECache
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 02:54 --------- d-----w D:\Profiles\MGI2890\Application Data\dvdcss
2008-03-18 19:46 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-03-16 01:43 --------- d-----w C:\Program Files\WS_FTP
2008-03-15 03:56 --------- d-----w D:\Profiles\MGI2890\Application Data\ZoomBrowser EX
2008-03-10 17:38 --------- d-----w C:\Program Files\Common Files\Canon
2008-03-08 02:09 --------- d-----w D:\Profiles\MGI2890\Application Data\Apple Computer
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-04 22:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2008-02-01 07:21 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2008-01-06 04:07 47,360 ----a-w D:\Profiles\MGI2890\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2008-04-28_ 0.37.27.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-28 04:29:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 20:39:17 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-28 04:50:45 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:46 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-28 04:50:43 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:43 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-26 20:41:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-28 19:10:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-21 04:29:56 1,516,240 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-28 19:42:36 1,515,504 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-04-28 20:43:18 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_a6c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{749F8452-7D28-4658-A903-9B047E5A2CE8}"= "C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll" [2006-06-08 04:20 2420736]

[HKEY_CLASSES_ROOT\clsid\{749f8452-7d28-4658-a903-9b047e5a2ce8}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{37686C62-D497-42E3-BAAB-78D89A74E151}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DBISQL9"="" []
"SybaseCentral43"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 14:39 1289000]
"URLy Warning"="C:\Program Files\URLy Warning\URLyWarning.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2006-06-04 05:08 679936]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 02:56 52896]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-06-04 05:08 679936]
"CSCAdvantage"="C:\Program Files\Help Desk\CSCAdv.exe" [2005-06-09 13:41 111403]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 10:11 1388544]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 13:41 860160]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 22:05 344064]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 14:24 290816]
"AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 15:12 88209 C:\WINDOWS\AGRSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"CSCLogonInfo"="C:\WINDOWS\UsrLogon.exe" [2006-12-12 17:28 127079]
"SupportSoft_Amer_Motorola"="C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" [2006-07-12 17:00 192512]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SDFix"="C:\SDFix\RunThis.bat /second" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-02-01 18:31 3900776]
"drvsyskit"="C:\WINDOWS\system32\drivers\hldrrr.exe" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
"LogonType"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoAutoTrayNotify"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-1086857\Scripts\Logon\0\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\0\0]
"Script"=wireless-qualification.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\1\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Netmeeting\\conf.exe"= C:\\Program Files\\Netmeeting\\conf.exe
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"113:TCP"= 113:TCP:10.176.1.190/199:enabled:bDNA
"497:TCP"= 497:TCP:10.0.38.5/10:enabled:bDNA2
"6000:TCP"= 6000:TCP:exceed
"135:TCP"= 135:TCP:10.160.5.8:enabled:foundscan
"137:TCP"= 137:TCP:10.197.24.2:enabled:foundscan2
"138:TCP"= 138:TCP:10.0.125.17:enabled:foundscan3
"139:TCP"= 139:TCP:10.0.125.20:enabled:foundscan4
"1503:TCP"= 1503:TCP:10.0.125.21:enabled:foundscan5
"1720:TCP"= 1720:TCP:10.1.250.11:enabled:foundscan6
"1761:TCP"= 1761:TCP:10.64.2.96:enabled:foundscan7
"2701:TCP"= 2701:TCP:10.128.132.49:enabled:iss1
"2702:TCP"= 2702:TCP:10.128.132.49:enabled:iss2
"43189:TCP"= 43189:TCP:10.160.9.87:enabled:iss3
"4445:TCP"= 4445:TCP:10.0.125.19:enabled:iss4
"6401:TCP"= 6401:TCP:192.168.30.7:enabled:iss5
"1023:UDP"= 1023:UDP:144.190.1.100:enabled:iss6
"445:TCP"= 445:TCP:10.0.125.15:enabled:nmap
"123:UDP"= 123:UDP:129.188.57.239:enabled:scanner1
"137:UDP"= 137:UDP:129.188.147.55:enabled:scanner2
"138:UDP"= 138:UDP:192.168.3.1:enabled:scanner3
"2233:UDP"= 2233:UDP:129.188.33.18:enabled:scanner4
"371:UDP"= 371:UDP:10.0.125.13:enabled:scanner5
"407:UDP"= 407:UDP:10.0.125.28:enabled:scanner6
"497:UDP"= 497:UDP:10.193.21.54:enabled:scanner7
"500:UDP"= 500:UDP:10.0.125.11:enabled:scanner8
"600:UDP"= 600:UDP:10.79.40.64:enabled:scanner9
"601:UDP"= 601:UDP:10.79.40.64:enabled:scanner10
"602:UDP"= 602:UDP:10.79.40.64:enabled:scanner11
"603:UDP"= 603:UDP:10.79.40.64:enabled:scanner12
"604:UDP"= 604:UDP:10.79.40.64:enabled:scanner13
"605:UDP"= 605:UDP:10.79.40.64:enabled:scanner14
"606:UDP"= 606:UDP:10.79.40.64:enabled:scanner15
"607:UDP"= 607:UDP:10.79.40.64:enabled:scanner16
"608:UDP"= 608:UDP:10.79.40.64:enabled:scanner17
"609:UDP"= 609:UDP:10.79.40.64:enabled:scanner18
"610:UDP"= 610:UDP:10.79.40.64:enabled:scanner19
"62514:UDP"= 62514:UDP:10.79.40.72,10.82.51.100,10.228.96.22/24,10.228.96.26,10.16.225.208,10.17.193.181,10.17.193.182:enabled:scanner20
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 1 (0x1)

R0 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-07-29 14:34]
R1 WrqDft;WrqDft;C:\WINDOWS\system32\drivers\WrqDft.sys [2002-07-29 09:50]
R1 WrqSDL;WrqSDL;C:\WINDOWS\system32\drivers\WrqSDL.sys [2002-07-29 09:50]
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2007-04-13 03:50]
R2 sprtsvc_supportsoft_amer_motorola;SupportSoft Sprocket Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe [2006-07-12 17:01]
R2 tgsrvc_supportsoft_amer_motorola;SupportSoft Repair Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe [2006-07-12 17:01]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2007-10-03 13:48]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 12:46]
R3 MakoNT;MakoNT;C:\WINDOWS\system32\drivers\isskboep.sys [2007-06-15 19:56]
R3 rap;rap;C:\WINDOWS\system32\drivers\RapDrv.sys [2007-10-29 13:44]
S0 black;black;C:\WINDOWS\system32\drivers\BlackCat.sys [2007-06-15 19:56]
S2 ApacheForSDM;ApacheForSDM;"C:\AdventNet\WebNMS\apache\bin\Apache.exe" -k runservice []
S2 VPatch;ISS Buffer Overflow Exploit Prevention;"C:\Program Files\ISS\Proventia Desktop\vpatch.exe" [2007-10-29 13:44]
S3 ASANYs_WebNmsDB;Adaptive Server Anywhere - WebNmsDB;C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [2005-02-25 11:27]
S3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys []
S3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2007-04-13 03:50]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{547d3cce-1543-11dd-b3e4-0015001d2d0c}]
\Shell\AutoRun\command - F:\Launch.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C10BF3A1-3FEC-4a94-AAAF-9D6A4B522F63}]
"C:\Program Files\WinZip\wzusr90.exe" /NOICON /NOTRAY
.
Contents of the 'Scheduled Tasks' folder
"2008-04-28 20:41:41 C:\WINDOWS\Tasks\CheckNetwork.job"
- C:\Program Files\Motorola\WirelessControl\NetStatus.vbs
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-28 17:39:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-28 17:44:32
ComboFix-quarantined-files.txt 2008-04-28 21:44:23
ComboFix2.txt 2008-04-28 05:56:25
ComboFix3.txt 2008-04-28 05:49:19
ComboFix4.txt 2008-04-28 04:38:41

Pre-Run: 7,954,817,024 bytes free
Post-Run: 7,915,376,640 bytes free

268

Rorschach112
2008-04-29, 01:14
Hello

Go to this site:
http://www.virustotal.com/
On top you'll find 'Browse'
Click the browse button and browse to the file:

C:\WINDOWS\system32\drivers\WrqDft.sys

Click open.
Then click the 'Send' button next to it.
This will scan the file. Please be patient.
Once scanned, copy and paste the results as well in your next reply.


And scan this file

C:\WINDOWS\2k3_USR.EXE



Do you recognise this zip file

C:\2333.zip



1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:


DirLook::
C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"drvsyskit"="C:\WINDOWS\system32\drivers\hldrrr.exe" [ ]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{547d3cce-1543-11dd-b3e4-0015001d2d0c}]

Driver::



Save this as CFScript.txt, in the same location as ComboFix.exe


http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

my5sons
2008-04-29, 01:29
sorry, but I am unable to browse to the system32/drivers directory. The only way I can access it, is by typing C:\Windows\system32\drivers

I tried to change the folder options to view all protected windows files, but I still can't access it since I received this worm.

Rorschach112
2008-04-29, 01:31
Ok go on and do the rest of the steps

my5sons
2008-04-29, 01:51
ok, I typed in the name in the browse window and I was able to run a virus scan on those 2 files. 0/32 for WrqDft.sys (I think this belongs to my WRQ Reflections program)

The second one (2k3_USR.exe) is a custom file from my IT department for Microsoft Office

2333.zip is a forum software file zipped up.

I ran the Comb-Fix.exe again with the .txt file and here are the results.

ComboFix 08-04-27.3 - mgi2890 2008-04-28 19:42:21.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.535 [GMT -4:00]
Running from: D:\Profiles\MGI2890\Desktop\Combo-Fix.exe
Command switches used :: D:\Profiles\MGI2890\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\mdelk.exe

.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-28 )))))))))))))))))))))))))))))))
.

2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- D:\Profiles\All Users\Application Data\Kaspersky Lab
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 15:24 . 2008-04-28 15:37 <DIR> d-------- D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2008-04-28 15:24 . 2008-04-28 15:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-28 15:23 . 2008-04-28 15:23 9,722,720 --a------ C:\spybotsd152.exe
2008-04-28 14:09 . 2008-04-28 15:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-28 01:32 . 2008-04-28 01:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-28 01:32 . 2008-04-28 01:32 812,344 --a------ C:\HJTInstall.exe
2008-04-28 00:50 . 2008-04-28 00:50 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-28 00:45 . 2008-04-27 20:49 <DIR> d-------- C:\SDFix
2008-04-27 23:32 . 2008-04-27 23:32 650,296 --a------ C:\PREVXCSIFREE(2).EXE
2008-04-27 23:12 . 2008-04-27 23:17 2,205,157 --a------ C:\IceSword122en.zip
2008-04-27 23:01 . 2008-04-27 23:01 650,296 --a------ C:\PREVXCSIFREE.EXE
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-27 22:39 . 2008-04-27 22:40 20,597,104 --a------ C:\aaw2007.exe
2008-04-25 22:05 . 2008-04-25 22:05 93,775 --a------ C:\2333.zip
2008-04-19 11:27 . 2008-04-19 11:27 <DIR> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-04-19 11:27 . 2008-04-24 12:21 275 --a------ C:\lxcjfire.csv
2008-04-19 11:27 . 2008-04-24 12:12 275 --a------ C:\lxcjfire.008
2008-04-19 11:27 . 2008-04-24 12:11 275 --a------ C:\lxcjfire.007
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.006
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.005
2008-04-19 11:27 . 2008-04-19 11:43 275 --a------ C:\lxcjfire.004
2008-04-19 11:27 . 2008-04-19 11:41 275 --a------ C:\lxcjfire.003
2008-04-19 11:27 . 2008-04-19 11:38 275 --a------ C:\lxcjfire.002
2008-04-19 11:27 . 2008-04-19 11:28 275 --a------ C:\lxcjfire.001
2008-04-19 11:27 . 2008-04-19 11:27 275 --a------ C:\lxcjfire.000
2008-04-19 11:22 . 2008-04-24 12:25 <DIR> d-------- C:\Lexmark
2008-04-17 18:20 . 2008-04-17 18:28 31,232 --a------ C:\proposedamendment(2).doc
2008-04-17 18:18 . 2008-04-17 18:18 23,552 --a------ C:\Proxy.doc
2008-04-17 18:18 . 2008-04-17 18:19 6,709 --a------ C:\proposedamendment.doc.part
2008-04-17 18:18 . 2008-04-17 18:18 0 --a------ C:\proposedamendment.doc
2008-04-17 18:15 . 2008-04-17 18:15 6,184 --a------ C:\Pheasant
2008-04-17 15:42 . 2008-04-27 23:07 8,704 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-15 09:45 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-15 09:45 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-08 20:50 . 2008-04-08 20:50 <DIR> d-------- D:\Profiles\All Users\Application Data\Office Genuine Advantage
2008-03-30 00:10 . 2008-03-30 00:10 732 --a------ C:\about_inc.php
2008-03-29 23:02 . 2008-03-29 23:02 <DIR> d-------- D:\Profiles\All Users\Application Data\FLEXnet
2008-03-29 22:01 . 2008-03-29 22:01 <DIR> d-------- D:\Profiles\NetworkService\Application Data\Juniper Networks
2008-03-29 02:02 . 2008-04-15 20:22 <DIR> d-------- C:\desktop

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-28 23:40 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-28 19:18 --------- d-----w C:\Program Files\Elaborate Bytes
2008-04-28 18:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 18:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 18:09 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-28 18:07 --------- d-----w C:\Program Files\Azureus
2008-04-28 18:05 --------- d-----w D:\Profiles\MGI2890\Application Data\Amazon
2008-04-28 18:05 --------- d-----w C:\Program Files\Amazon
2008-04-28 02:41 --------- d-----w D:\Profiles\All Users\Application Data\Lavasoft
2008-04-23 19:11 --------- d-----w D:\Profiles\MGI2890\Application Data\AdobeUM
2008-04-08 21:31 --------- d-----w D:\Profiles\MGI2890\Application Data\Vso
2008-03-28 19:08 --------- d-----w C:\Program Files\SlySoft
2008-03-27 02:11 --------- d-----w D:\Profiles\sdm.MGI2890-02\Application Data\Juniper Networks
2008-03-22 01:14 --------- d-----w C:\Program Files\MSECache
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 02:54 --------- d-----w D:\Profiles\MGI2890\Application Data\dvdcss
2008-03-18 19:46 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-03-16 01:43 --------- d-----w C:\Program Files\WS_FTP
2008-03-15 03:56 --------- d-----w D:\Profiles\MGI2890\Application Data\ZoomBrowser EX
2008-03-10 17:38 --------- d-----w C:\Program Files\Common Files\Canon
2008-03-08 02:09 --------- d-----w D:\Profiles\MGI2890\Application Data\Apple Computer
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-04 22:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2008-02-01 07:21 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2008-01-06 04:07 47,360 ----a-w D:\Profiles\MGI2890\Application Data\pcouffin.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15} ----

2006-05-11 09:11 170 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\APPINST.ISF
2006-05-11 09:01 1488037 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJHELP.HLP
2006-05-02 23:56 131072 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJJSWR.DLL
2006-05-02 23:56 106496 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJINSR.DLL
2006-05-02 23:55 196608 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJINSB.DLL
2006-05-02 23:55 155648 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJINS.DLL
2006-05-02 23:54 434176 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJUTIL.DLL
2005-07-26 11:09 217088 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJINST.EXE
2005-07-26 11:09 184320 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJUNST.EXE
2005-07-26 11:08 131072 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJFIRE.EXE
2005-07-21 14:47 195 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\BEUNST.ISF
2005-06-24 09:47 983092 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJGF.DLL
2005-06-10 08:12 2184 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJPROD.INI
2005-06-01 12:53 69632 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJCFG.DLL
2003-10-15 13:15 5598 --a------ C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\lxcj\LXCJEULA.TXT


((((((((((((((((((((((((((((( snapshot@2008-04-28_ 0.37.27.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-28 04:29:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 23:20:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-28 04:50:45 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:46 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-28 04:50:43 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:43 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-26 20:41:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-28 19:10:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-21 04:29:56 1,516,240 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-28 19:42:36 1,515,504 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-04-28 23:24:45 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_f5c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{749F8452-7D28-4658-A903-9B047E5A2CE8}"= "C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll" [2006-06-08 04:20 2420736]

[HKEY_CLASSES_ROOT\clsid\{749f8452-7d28-4658-a903-9b047e5a2ce8}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{37686C62-D497-42E3-BAAB-78D89A74E151}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DBISQL9"="" []
"SybaseCentral43"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 14:39 1289000]
"URLy Warning"="C:\Program Files\URLy Warning\URLyWarning.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2006-06-04 05:08 679936]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 02:56 52896]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-06-04 05:08 679936]
"CSCAdvantage"="C:\Program Files\Help Desk\CSCAdv.exe" [2005-06-09 13:41 111403]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 10:11 1388544]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 13:41 860160]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 22:05 344064]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 14:24 290816]
"AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 15:12 88209 C:\WINDOWS\AGRSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"CSCLogonInfo"="C:\WINDOWS\UsrLogon.exe" [2006-12-12 17:28 127079]
"SupportSoft_Amer_Motorola"="C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" [2006-07-12 17:00 192512]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SDFix"="C:\SDFix\RunThis.bat /second" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-02-01 18:31 3900776]
"drvsyskit"="C:\WINDOWS\system32\drivers\hldrrr.exe" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
"LogonType"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoAutoTrayNotify"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-1086857\Scripts\Logon\0\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\0\0]
"Script"=wireless-qualification.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\1\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Netmeeting\\conf.exe"= C:\\Program Files\\Netmeeting\\conf.exe
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"113:TCP"= 113:TCP:10.176.1.190/199:enabled:bDNA
"497:TCP"= 497:TCP:10.0.38.5/10:enabled:bDNA2
"6000:TCP"= 6000:TCP:exceed
"135:TCP"= 135:TCP:10.160.5.8:enabled:foundscan
"137:TCP"= 137:TCP:10.197.24.2:enabled:foundscan2
"138:TCP"= 138:TCP:10.0.125.17:enabled:foundscan3
"139:TCP"= 139:TCP:10.0.125.20:enabled:foundscan4
"1503:TCP"= 1503:TCP:10.0.125.21:enabled:foundscan5
"1720:TCP"= 1720:TCP:10.1.250.11:enabled:foundscan6
"1761:TCP"= 1761:TCP:10.64.2.96:enabled:foundscan7
"2701:TCP"= 2701:TCP:10.128.132.49:enabled:iss1
"2702:TCP"= 2702:TCP:10.128.132.49:enabled:iss2
"43189:TCP"= 43189:TCP:10.160.9.87:enabled:iss3
"4445:TCP"= 4445:TCP:10.0.125.19:enabled:iss4
"6401:TCP"= 6401:TCP:192.168.30.7:enabled:iss5
"1023:UDP"= 1023:UDP:144.190.1.100:enabled:iss6
"445:TCP"= 445:TCP:10.0.125.15:enabled:nmap
"123:UDP"= 123:UDP:129.188.57.239:enabled:scanner1
"137:UDP"= 137:UDP:129.188.147.55:enabled:scanner2
"138:UDP"= 138:UDP:192.168.3.1:enabled:scanner3
"2233:UDP"= 2233:UDP:129.188.33.18:enabled:scanner4
"371:UDP"= 371:UDP:10.0.125.13:enabled:scanner5
"407:UDP"= 407:UDP:10.0.125.28:enabled:scanner6
"497:UDP"= 497:UDP:10.193.21.54:enabled:scanner7
"500:UDP"= 500:UDP:10.0.125.11:enabled:scanner8
"600:UDP"= 600:UDP:10.79.40.64:enabled:scanner9
"601:UDP"= 601:UDP:10.79.40.64:enabled:scanner10
"602:UDP"= 602:UDP:10.79.40.64:enabled:scanner11
"603:UDP"= 603:UDP:10.79.40.64:enabled:scanner12
"604:UDP"= 604:UDP:10.79.40.64:enabled:scanner13
"605:UDP"= 605:UDP:10.79.40.64:enabled:scanner14
"606:UDP"= 606:UDP:10.79.40.64:enabled:scanner15
"607:UDP"= 607:UDP:10.79.40.64:enabled:scanner16
"608:UDP"= 608:UDP:10.79.40.64:enabled:scanner17
"609:UDP"= 609:UDP:10.79.40.64:enabled:scanner18
"610:UDP"= 610:UDP:10.79.40.64:enabled:scanner19
"62514:UDP"= 62514:UDP:10.79.40.72,10.82.51.100,10.228.96.22/24,10.228.96.26,10.16.225.208,10.17.193.181,10.17.193.182:enabled:scanner20
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 1 (0x1)

R0 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-07-29 14:34]
R1 WrqDft;WrqDft;C:\WINDOWS\system32\drivers\WrqDft.sys [2002-07-29 09:50]
R1 WrqSDL;WrqSDL;C:\WINDOWS\system32\drivers\WrqSDL.sys [2002-07-29 09:50]
R2 ApacheForSDM;ApacheForSDM;"C:\AdventNet\WebNMS\apache\bin\Apache.exe" -k runservice []
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2007-04-13 03:50]
R2 sprtsvc_supportsoft_amer_motorola;SupportSoft Sprocket Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe [2006-07-12 17:01]
R2 tgsrvc_supportsoft_amer_motorola;SupportSoft Repair Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe [2006-07-12 17:01]
R2 VPatch;ISS Buffer Overflow Exploit Prevention;"C:\Program Files\ISS\Proventia Desktop\vpatch.exe" [2007-10-29 13:44]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2007-10-03 13:48]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 12:46]
R3 MakoNT;MakoNT;C:\WINDOWS\system32\drivers\isskboep.sys [2007-06-15 19:56]
R3 rap;rap;C:\WINDOWS\system32\drivers\RapDrv.sys [2007-10-29 13:44]
S0 black;black;C:\WINDOWS\system32\drivers\BlackCat.sys [2007-06-15 19:56]
S3 ASANYs_WebNmsDB;Adaptive Server Anywhere - WebNmsDB;C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [2005-02-25 11:27]
S3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys []
S3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2007-04-13 03:50]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C10BF3A1-3FEC-4a94-AAAF-9D6A4B522F63}]
"C:\Program Files\WinZip\wzusr90.exe" /NOICON /NOTRAY
.
Contents of the 'Scheduled Tasks' folder
"2008-04-28 23:22:57 C:\WINDOWS\Tasks\CheckNetwork.job"
- C:\Program Files\Motorola\WirelessControl\NetStatus.vbs
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-28 19:44:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-28 19:48:10
ComboFix-quarantined-files.txt 2008-04-28 23:48:03
ComboFix2.txt 2008-04-28 21:44:35
ComboFix3.txt 2008-04-28 05:56:25
ComboFix4.txt 2008-04-28 05:49:19
ComboFix5.txt 2008-04-28 04:38:41

Pre-Run: 7,890,870,272 bytes free
Post-Run: 7,872,749,568 bytes free

285

Rorschach112
2008-04-29, 01:59
Hello

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:


File::

Folder::

Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"drvsyskit"=-

Driver::



Save this as CFScript.txt, in the same location as ComboFix.exe


http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Reboot and do this


Download NIAP (http://niapsoft.com/blog/uploads/2008/04/niap-05.zip) to your desktop and unzip it to it's own folder

Close all windows and run NIAP_XRay_FileMgr

Click the Log tab at the top and click Create System log. Check the boxes beside Autorun.inf file. and System Critical Files and click OK. Save the log to your desktop and let the program run.
Exit out of NIAP_XRay_FileMgr



Next run NIAP_XRay_Regedit

Click the Log tab then click on Get log. Once it is finished scanning, click Save and call the log NiapReg, then save it to your desktop
Exit out of NIAP_XRay_Regedit



Finally run NIAP_XRay_System

Click the Log tab and click Create log. Check all the boxes and click Log, save it to your desktop. Let the program run. Once it is done close the program and post the log back here along with the other two logs.

my5sons
2008-04-29, 02:08
Here is combofix log....rebooting now...



ComboFix 08-04-27.3 - mgi2890 2008-04-28 20:02:36.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.527 [GMT -4:00]
Running from: D:\Profiles\MGI2890\Desktop\Combo-Fix.exe
Command switches used :: D:\Profiles\MGI2890\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-29 )))))))))))))))))))))))))))))))
.

2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- D:\Profiles\All Users\Application Data\Kaspersky Lab
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 15:24 . 2008-04-28 15:37 <DIR> d-------- D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2008-04-28 15:24 . 2008-04-28 15:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-28 15:23 . 2008-04-28 15:23 9,722,720 --a------ C:\spybotsd152.exe
2008-04-28 14:09 . 2008-04-28 15:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-28 01:32 . 2008-04-28 01:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-28 01:32 . 2008-04-28 01:32 812,344 --a------ C:\HJTInstall.exe
2008-04-28 00:50 . 2008-04-28 00:50 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-28 00:45 . 2008-04-27 20:49 <DIR> d-------- C:\SDFix
2008-04-27 23:32 . 2008-04-27 23:32 650,296 --a------ C:\PREVXCSIFREE(2).EXE
2008-04-27 23:12 . 2008-04-27 23:17 2,205,157 --a------ C:\IceSword122en.zip
2008-04-27 23:01 . 2008-04-27 23:01 650,296 --a------ C:\PREVXCSIFREE.EXE
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-27 22:39 . 2008-04-27 22:40 20,597,104 --a------ C:\aaw2007.exe
2008-04-25 22:05 . 2008-04-25 22:05 93,775 --a------ C:\2333.zip
2008-04-19 11:27 . 2008-04-19 11:27 <DIR> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-04-19 11:27 . 2008-04-24 12:21 275 --a------ C:\lxcjfire.csv
2008-04-19 11:27 . 2008-04-24 12:12 275 --a------ C:\lxcjfire.008
2008-04-19 11:27 . 2008-04-24 12:11 275 --a------ C:\lxcjfire.007
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.006
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.005
2008-04-19 11:27 . 2008-04-19 11:43 275 --a------ C:\lxcjfire.004
2008-04-19 11:27 . 2008-04-19 11:41 275 --a------ C:\lxcjfire.003
2008-04-19 11:27 . 2008-04-19 11:38 275 --a------ C:\lxcjfire.002
2008-04-19 11:27 . 2008-04-19 11:28 275 --a------ C:\lxcjfire.001
2008-04-19 11:27 . 2008-04-19 11:27 275 --a------ C:\lxcjfire.000
2008-04-19 11:22 . 2008-04-24 12:25 <DIR> d-------- C:\Lexmark
2008-04-17 18:20 . 2008-04-17 18:28 31,232 --a------ C:\proposedamendment(2).doc
2008-04-17 18:18 . 2008-04-17 18:18 23,552 --a------ C:\Proxy.doc
2008-04-17 18:18 . 2008-04-17 18:19 6,709 --a------ C:\proposedamendment.doc.part
2008-04-17 18:18 . 2008-04-17 18:18 0 --a------ C:\proposedamendment.doc
2008-04-17 18:15 . 2008-04-17 18:15 6,184 --a------ C:\Pheasant
2008-04-17 15:42 . 2008-04-27 23:07 8,704 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-15 09:45 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-15 09:45 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-08 20:50 . 2008-04-08 20:50 <DIR> d-------- D:\Profiles\All Users\Application Data\Office Genuine Advantage
2008-03-30 00:10 . 2008-03-30 00:10 732 --a------ C:\about_inc.php
2008-03-29 23:02 . 2008-03-29 23:02 <DIR> d-------- D:\Profiles\All Users\Application Data\FLEXnet
2008-03-29 22:01 . 2008-03-29 22:01 <DIR> d-------- D:\Profiles\NetworkService\Application Data\Juniper Networks
2008-03-29 02:02 . 2008-04-15 20:22 <DIR> d-------- C:\desktop

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-28 23:40 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-28 19:18 --------- d-----w C:\Program Files\Elaborate Bytes
2008-04-28 18:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 18:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 18:09 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-28 18:07 --------- d-----w C:\Program Files\Azureus
2008-04-28 18:05 --------- d-----w D:\Profiles\MGI2890\Application Data\Amazon
2008-04-28 18:05 --------- d-----w C:\Program Files\Amazon
2008-04-28 02:41 --------- d-----w D:\Profiles\All Users\Application Data\Lavasoft
2008-04-23 19:11 --------- d-----w D:\Profiles\MGI2890\Application Data\AdobeUM
2008-04-08 21:31 --------- d-----w D:\Profiles\MGI2890\Application Data\Vso
2008-03-28 19:08 --------- d-----w C:\Program Files\SlySoft
2008-03-27 02:11 --------- d-----w D:\Profiles\sdm.MGI2890-02\Application Data\Juniper Networks
2008-03-22 01:14 --------- d-----w C:\Program Files\MSECache
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 02:54 --------- d-----w D:\Profiles\MGI2890\Application Data\dvdcss
2008-03-18 19:46 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-03-16 01:43 --------- d-----w C:\Program Files\WS_FTP
2008-03-15 03:56 --------- d-----w D:\Profiles\MGI2890\Application Data\ZoomBrowser EX
2008-03-10 17:38 --------- d-----w C:\Program Files\Common Files\Canon
2008-03-08 02:09 --------- d-----w D:\Profiles\MGI2890\Application Data\Apple Computer
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-04 22:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2008-02-01 07:21 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2008-01-06 04:07 47,360 ----a-w D:\Profiles\MGI2890\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2008-04-28_ 0.37.27.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-28 04:29:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 23:20:12 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-28 04:50:45 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:46 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-28 04:50:43 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:43 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-26 20:41:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-28 19:10:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-21 04:29:56 1,516,240 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-28 19:42:36 1,515,504 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-04-28 23:24:45 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_f5c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{749F8452-7D28-4658-A903-9B047E5A2CE8}"= "C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll" [2006-06-08 04:20 2420736]

[HKEY_CLASSES_ROOT\clsid\{749f8452-7d28-4658-a903-9b047e5a2ce8}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{37686C62-D497-42E3-BAAB-78D89A74E151}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DBISQL9"="" []
"SybaseCentral43"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 14:39 1289000]
"URLy Warning"="C:\Program Files\URLy Warning\URLyWarning.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2006-06-04 05:08 679936]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 02:56 52896]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-06-04 05:08 679936]
"CSCAdvantage"="C:\Program Files\Help Desk\CSCAdv.exe" [2005-06-09 13:41 111403]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 10:11 1388544]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 13:41 860160]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 22:05 344064]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 14:24 290816]
"AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 15:12 88209 C:\WINDOWS\AGRSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"CSCLogonInfo"="C:\WINDOWS\UsrLogon.exe" [2006-12-12 17:28 127079]
"SupportSoft_Amer_Motorola"="C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" [2006-07-12 17:00 192512]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SDFix"="C:\SDFix\RunThis.bat /second" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-02-01 18:31 3900776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
"LogonType"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoAutoTrayNotify"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-1086857\Scripts\Logon\0\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\0\0]
"Script"=wireless-qualification.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\1\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Netmeeting\\conf.exe"= C:\\Program Files\\Netmeeting\\conf.exe
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"113:TCP"= 113:TCP:10.176.1.190/199:enabled:bDNA
"497:TCP"= 497:TCP:10.0.38.5/10:enabled:bDNA2
"6000:TCP"= 6000:TCP:exceed
"135:TCP"= 135:TCP:10.160.5.8:enabled:foundscan
"137:TCP"= 137:TCP:10.197.24.2:enabled:foundscan2
"138:TCP"= 138:TCP:10.0.125.17:enabled:foundscan3
"139:TCP"= 139:TCP:10.0.125.20:enabled:foundscan4
"1503:TCP"= 1503:TCP:10.0.125.21:enabled:foundscan5
"1720:TCP"= 1720:TCP:10.1.250.11:enabled:foundscan6
"1761:TCP"= 1761:TCP:10.64.2.96:enabled:foundscan7
"2701:TCP"= 2701:TCP:10.128.132.49:enabled:iss1
"2702:TCP"= 2702:TCP:10.128.132.49:enabled:iss2
"43189:TCP"= 43189:TCP:10.160.9.87:enabled:iss3
"4445:TCP"= 4445:TCP:10.0.125.19:enabled:iss4
"6401:TCP"= 6401:TCP:192.168.30.7:enabled:iss5
"1023:UDP"= 1023:UDP:144.190.1.100:enabled:iss6
"445:TCP"= 445:TCP:10.0.125.15:enabled:nmap
"123:UDP"= 123:UDP:129.188.57.239:enabled:scanner1
"137:UDP"= 137:UDP:129.188.147.55:enabled:scanner2
"138:UDP"= 138:UDP:192.168.3.1:enabled:scanner3
"2233:UDP"= 2233:UDP:129.188.33.18:enabled:scanner4
"371:UDP"= 371:UDP:10.0.125.13:enabled:scanner5
"407:UDP"= 407:UDP:10.0.125.28:enabled:scanner6
"497:UDP"= 497:UDP:10.193.21.54:enabled:scanner7
"500:UDP"= 500:UDP:10.0.125.11:enabled:scanner8
"600:UDP"= 600:UDP:10.79.40.64:enabled:scanner9
"601:UDP"= 601:UDP:10.79.40.64:enabled:scanner10
"602:UDP"= 602:UDP:10.79.40.64:enabled:scanner11
"603:UDP"= 603:UDP:10.79.40.64:enabled:scanner12
"604:UDP"= 604:UDP:10.79.40.64:enabled:scanner13
"605:UDP"= 605:UDP:10.79.40.64:enabled:scanner14
"606:UDP"= 606:UDP:10.79.40.64:enabled:scanner15
"607:UDP"= 607:UDP:10.79.40.64:enabled:scanner16
"608:UDP"= 608:UDP:10.79.40.64:enabled:scanner17
"609:UDP"= 609:UDP:10.79.40.64:enabled:scanner18
"610:UDP"= 610:UDP:10.79.40.64:enabled:scanner19
"62514:UDP"= 62514:UDP:10.79.40.72,10.82.51.100,10.228.96.22/24,10.228.96.26,10.16.225.208,10.17.193.181,10.17.193.182:enabled:scanner20
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 1 (0x1)

R0 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-07-29 14:34]
R1 WrqDft;WrqDft;C:\WINDOWS\system32\drivers\WrqDft.sys [2002-07-29 09:50]
R1 WrqSDL;WrqSDL;C:\WINDOWS\system32\drivers\WrqSDL.sys [2002-07-29 09:50]
R2 ApacheForSDM;ApacheForSDM;"C:\AdventNet\WebNMS\apache\bin\Apache.exe" -k runservice []
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2007-04-13 03:50]
R2 sprtsvc_supportsoft_amer_motorola;SupportSoft Sprocket Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe [2006-07-12 17:01]
R2 tgsrvc_supportsoft_amer_motorola;SupportSoft Repair Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe [2006-07-12 17:01]
R2 VPatch;ISS Buffer Overflow Exploit Prevention;"C:\Program Files\ISS\Proventia Desktop\vpatch.exe" [2007-10-29 13:44]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2007-10-03 13:48]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 12:46]
R3 MakoNT;MakoNT;C:\WINDOWS\system32\drivers\isskboep.sys [2007-06-15 19:56]
R3 rap;rap;C:\WINDOWS\system32\drivers\RapDrv.sys [2007-10-29 13:44]
S0 black;black;C:\WINDOWS\system32\drivers\BlackCat.sys [2007-06-15 19:56]
S3 ASANYs_WebNmsDB;Adaptive Server Anywhere - WebNmsDB;C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [2005-02-25 11:27]
S3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys []
S3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2007-04-13 03:50]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C10BF3A1-3FEC-4a94-AAAF-9D6A4B522F63}]
"C:\Program Files\WinZip\wzusr90.exe" /NOICON /NOTRAY
.
Contents of the 'Scheduled Tasks' folder
"2008-04-28 23:22:57 C:\WINDOWS\Tasks\CheckNetwork.job"
- C:\Program Files\Motorola\WirelessControl\NetStatus.vbs
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-28 20:04:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-28 20:06:53
ComboFix-quarantined-files.txt 2008-04-29 00:06:39
ComboFix2.txt 2008-04-28 23:48:12
ComboFix3.txt 2008-04-28 21:44:35
ComboFix4.txt 2008-04-28 05:56:25
ComboFix5.txt 2008-04-28 05:49:19

Pre-Run: 7,849,701,376 bytes free
Post-Run: 7,835,987,968 bytes free

262

my5sons
2008-04-29, 04:01
Here are the NIAP logs.....


# NIAP_XRay_FileMgr.exe 0.0.0.4
# 2008-04-28 21:53:17
# ------------------------------------------------------------------------
# Scan Autorun.inf in: E:\
# Scan Autorun.inf in: D:\
# Not Found.

# Scan Autorun.inf in: C:\
# Not Found.

# Verify System Critical File
C:\WINDOWS\explorer.exe;OK
C:\WINDOWS\system32\win32k.sys;OK
C:\WINDOWS\system32\watchdog.sys;OK
C:\WINDOWS\system32\hal.dll;OK
C:\WINDOWS\system32\ntkrnlpa.exe;OK
C:\WINDOWS\system32\ntoskrnl.exe;OK
C:\WINDOWS\system32\smss.exe;OK
C:\WINDOWS\system32\csrss.exe;OK
C:\WINDOWS\system32\winlogon.exe;OK
C:\WINDOWS\system32\lsass.exe;OK
C:\WINDOWS\system32\services.exe;OK
C:\WINDOWS\system32\svchost.exe;OK
C:\WINDOWS\system32\userinit.exe;OK
C:\WINDOWS\system32\drivers\acpi.sys;OK
C:\WINDOWS\system32\drivers\atapi.sys;OK
C:\WINDOWS\system32\drivers\beep.sys;OK
C:\WINDOWS\system32\drivers\cdfs.sys;OK
C:\WINDOWS\system32\drivers\cdrom.sys;OK
C:\WINDOWS\system32\drivers\disk.sys;OK
C:\WINDOWS\system32\drivers\fastfat.sys;OK
C:\WINDOWS\system32\drivers\fs_rec.sys;OK
C:\WINDOWS\system32\drivers\ftdisk.sys;OK
C:\WINDOWS\system32\drivers\i8042prt.sys;OK
C:\WINDOWS\system32\drivers\kbdclass.sys;OK
C:\WINDOWS\system32\drivers\mouclass.sys;OK
C:\WINDOWS\system32\drivers\ndis.sys;OK
C:\WINDOWS\system32\drivers\ntfs.sys;OK
C:\WINDOWS\system32\drivers\null.sys;OK
C:\WINDOWS\system32\drivers\partmgr.sys;OK
C:\WINDOWS\system32\drivers\pci.sys;OK
C:\WINDOWS\system32\drivers\pciidex.sys;OK
C:\WINDOWS\system32\drivers\redbook.sys;OK
C:\WINDOWS\system32\drivers\scsiport.sys;OK
C:\WINDOWS\system32\drivers\sr.sys;OK
C:\WINDOWS\system32\drivers\termdd.sys;OK
C:\WINDOWS\system32\drivers\usbhub.sys;OK
C:\WINDOWS\system32\drivers\usbport.sys;OK
C:\WINDOWS\system32\drivers\volsnap.sys;OK
C:\WINDOWS\system32\drivers\tcpip.sys;OK
C:\WINDOWS\system32\drivers\tdi.sys;OK

-------------------------------

Report:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\:
Name:ccApp , Path:"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Name:vptray , Path:C:\PROGRA~1\SYMANT~1\VPTray.exe
Name:CSCAdvantage , Path:"C:\Program Files\Help Desk\CSCAdv.exe" /s
Name:SoundMAXPnP , Path:C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
Name:SoundMAX , Path:"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
Name:ATIPTA , Path:C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
Name:eabconfg.cpl , Path:C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
Name:AGRSMMSG , Path:AGRSMMSG.exe
Name:SynTPLpr , Path:C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
Name:SynTPEnh , Path:C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Name:CSCLogonInfo , Path:C:\WINDOWS\UsrLogon.exe
Name:SupportSoft_Amer_Motorola , Path:"C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" /P SupportSoft_Amer_Motorola
Name:iTunesHelper , Path:"C:\Program Files\iTunes\iTunesHelper.exe"
Name:QuickTime Task , Path:"C:\Program Files\QuickTime\qttask.exe" -atboottime
Name:Adobe Reader Speed Launcher , Path:"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
Name:SDFix , Path:C:\SDFix\RunThis.bat /second


HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\:
Name:DBISQL9 , Path:
Name:SybaseCentral43 , Path:
Name:H/PC Connection Agent , Path:"C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
Name:URLy Warning , Path:"C:\Program Files\URLy Warning\URLyWarning.exe" -quiet
Name:swg , Path:C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
Name:SpybotSD TeaTimer , Path:C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\:


HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\:


HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\:


HKCC\Software\Microsoft\Windows NT\CurrentVersion\Windows\[Load]:
Value: None

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\[Userinit]:
Value: C:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\[Shell]:
Value: Explorer.exe

HKLM\SYSTEM\ControlSet001\Control\Session Manager\[BootExecute]:
Value: autocheck autochk * lsdelete



BHO Items List:
{53707962-6F74-2D53-2644-206D7942484F}
InprocServer32:C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
ThreadingModel:Apartment
ProgID:None
Programmable:None
TypeLib:None
VersionIndependentProgID:None
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
InprocServer32:C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
ThreadingModel:Apartment
ProgID:None
Programmable:None
TypeLib:None
VersionIndependentProgID:None
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
InprocServer32:C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
ThreadingModel:Apartment
ProgID:protector_dll.ProtectorBho.1
Programmable:None
TypeLib:{C7CB459A-7261-4AE6-A87A-17041EE98A40}
VersionIndependentProgID:protector_dll.ProtectorBho

File Links List:
.txt: %SystemRoot%\system32\NOTEPAD.EXE %1
.exe: "%1" %*
.com: "%1" %*
.pif: "%1" %*
.bat: "%1" %*
.reg: regedit.exe "%1"
.chm: "C:\WINDOWS\hh.exe" %1
.hlp: %SystemRoot%\System32\winhlp32.exe %1
.ini: %SystemRoot%\System32\NOTEPAD.EXE %1
.inf: %SystemRoot%\System32\NOTEPAD.EXE %1
.vbs: %SystemRoot%\System32\WScript.exe "%1" %*
.js: %SystemRoot%\System32\WScript.exe "%1" %*
.lnk: CLSID: {00021401-0000-0000-C000-000000000046} shell32.dll

Image File Execution Options:
Your Image File Name Here without a path: ntsd -d

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\[AppInit_DLLs]:
Value:


ShellExecuteHooks:
{AEB6717E-7E19-11d0-97EE-00C04FD91972} : URL Exec Hook
InProcServer32:shell32.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug\[Debugger]:
Value: drwtsn32 -p %ld -e %ld -g

Kernel Drivers:
black
DisplayName:black
Description:None
ImagePath:System32\drivers\BlackCat.sys
ObjectName:None
Start:SERVICE_DISABLED(4)
Type:SERVICE_KERNEL_DRIVER(1)
btaudio
DisplayName:Bluetooth Audio Device
Description:None
ImagePath:system32\drivers\btaudio.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
BTDriver
DisplayName:Bluetooth Virtual Communications Driver
Description:None
ImagePath:system32\DRIVERS\btport.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
BTKRNL
DisplayName:Bluetooth Bus Enumerator
Description:None
ImagePath:system32\DRIVERS\btkrnl.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
BTWDNDIS
DisplayName:Bluetooth LAN Access Server
Description:None
ImagePath:system32\DRIVERS\btwdndis.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
BTWUSB
DisplayName:WIDCOMM USB Bluetooth Driver
Description:None
ImagePath:System32\Drivers\btwusb.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
catchme
DisplayName:None
Description:None
ImagePath:\??\C:\Combo-Fix\catchme.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
IPSECSHM
DisplayName:Nortel IPSECSHM Adapter
Description:Nortel IPSECSHM Adapter
ImagePath:system32\DRIVERS\ipsecw2k.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
MakoNT
DisplayName:MakoNT
Description:None
ImagePath:\SystemRoot\system32\drivers\isskboep.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
NIAPSafe
DisplayName:NIAPSafe
Description:None
ImagePath:\??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys
ObjectName:None
Start:SERVICE_DISABLED(4)
Type:SERVICE_KERNEL_DRIVER(1)
pcouffin
DisplayName:VSO Software pcouffin
Description:None
ImagePath:System32\Drivers\pcouffin.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
rap
DisplayName:rap
Description:None
ImagePath:System32\drivers\RapDrv.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
RapFile
DisplayName:RapFile
Description:None
ImagePath:\??\C:\WINDOWS\system32\drivers\RapFile.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
RapNet
DisplayName:RapNet
Description:None
ImagePath:\??\C:\WINDOWS\system32\drivers\RapNet.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
USBAAPL
DisplayName:Apple Mobile USB Driver
Description:None
ImagePath:System32\Drivers\usbaapl.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
VClone
DisplayName:None
Description:None
ImagePath:system32\DRIVERS\VClone.sys [File not found]
ObjectName:None
Start:SERVICE_SYSTEM_START(1)
Type:SERVICE_KERNEL_DRIVER(1)

Services:
Adobe LM Service
DisplayName:Adobe LM Service
Description:AdobeLM Service
ImagePath:"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
ApacheForSDM
DisplayName:ApacheForSDM
Description:Apache
ImagePath:"C:\AdventNet\WebNMS\apache\bin\Apache.exe" -k runservice
ObjectName:.\sdm
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
ASANYs_WebNmsDB
DisplayName:Adaptive Server Anywhere - WebNmsDB
Description:None
ImagePath:C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe -hvASANYs_WebNmsDB
ObjectName:.\sdm
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
BlackICE
DisplayName:BlackICE
Description:None
ImagePath:"C:\Program Files\ISS\Proventia Desktop\blackd.exe"
ObjectName:LocalSystem
Start:SERVICE_DISABLED(4)
Type:SERVICE_WIN32_OWN_PROCESS(16)
btwdins
DisplayName:Bluetooth Service
Description:Handles installation and removal of Bluetooth devices.
ImagePath:C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
hpqwmi
DisplayName:HP WMI Interface
Description:None
ImagePath:C:\Program Files\HPQ\SHARED\HPQWMI.exe
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
RapApp
DisplayName:RapApp
Description:Application Protection
ImagePath:"C:\Program Files\ISS\Proventia Desktop\RapApp.exe"
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:None
Reflection Line Printer Daemon
DisplayName:Reflection Line Printer Daemon
Description:Make your local printer available to other users
ImagePath:"C:\Program Files\Reflection\lpdserv.exe"
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:None
SDM Service
DisplayName:Motorola SDM
Description:Motorola SmartStream Device Manager
ImagePath:JavaService.exe [File not found]
ObjectName:.\sdm
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
SoundMAX Agent Service (default)
DisplayName:SoundMAX Agent Service
Description:None
ImagePath:C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
sprtsvc_supportsoft_amer_motorola
DisplayName:SupportSoft Sprocket Service (supportsoft_amer_motorola)
Description:SupportSoft Sprocket Service
ImagePath:C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe /service /p supportsoft_amer_motorola
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:None
tgsrvc_supportsoft_amer_motorola
DisplayName:SupportSoft Repair Service (supportsoft_amer_motorola)
Description:SupportSoft Repair Service
ImagePath:C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe /p supportsoft_amer_motorola
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:None
VPatch
DisplayName:ISS Buffer Overflow Exploit Prevention
Description:None
ImagePath:"C:\Program Files\ISS\Proventia Desktop\vpatch.exe"
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:None
Wuser32
DisplayName:SMS Remote Control Agent
Description:None
ImagePath:C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:None


------------------------------

NIAP_XRay_System Version 0.0.0.5 System log

Process:
PID | EPROCESS | Process Name | Module Path
00000004 86FC52C0 System
00000108 86EBC728 rapimgr.exe C:\PROGRA~1\MICROS~3\rapimgr.exe
00000150 85FE0DA0 SMAgent.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
00000160 85FD0020 sprtsvc.exe C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
00000180 85F1ADA0 hpqwmi.exe C:\Program Files\HPQ\SHARED\HPQWMI.exe
00000184 85FD72D8 svchost.exe C:\WINDOWS\system32\svchost.exe
00000190 85FCA2F0 tgsrvc.exe C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
000001AC 85FCB518 Vpatch.exe C:\Program Files\ISS\Proventia Desktop\vpatch.exe
000001D0 863BA998 smss.exe \SystemRoot\System32\smss.exe
000001F8 85FCCDA0 Wuser32.exe C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
00000208 86E05230 csrss.exe \??\C:\WINDOWS\system32\csrss.exe
00000220 86360848 winlogon.exe \??\C:\WINDOWS\system32\winlogon.exe
0000024C 86CC9438 services.exe C:\WINDOWS\system32\services.exe
00000260 86CBA890 lsass.exe C:\WINDOWS\system32\lsass.exe
000002E4 862FDB78 svchost.exe C:\WINDOWS\system32\svchost.exe
00000300 85FBCDA0 CcmExec.exe C:\WINDOWS\system32\CCM\CcmExec.exe
00000340 8634BB10 svchost.exe C:\WINDOWS\system32\svchost.exe
0000039C 86E07A38 svchost.exe C:\WINDOWS\System32\svchost.exe
000003CC 85E4CB00 NIAP_XRay_Syste D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAP_XRay_System.exe
000003F4 86CF8DA0 svchost.exe C:\WINDOWS\system32\svchost.exe
00000434 86416DA0 svchost.exe C:\WINDOWS\system32\svchost.exe
00000460 86E49B78 aawservice.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
000004F8 86393950 spoolsv.exe C:\WINDOWS\system32\spoolsv.exe
00000530 86307A78 scardsvr.exe C:\WINDOWS\System32\SCardSvr.exe
00000644 863ABDA0 Apache.exe C:\AdventNet\WebNMS\apache\bin\Apache.exe
00000658 86E3A990 btwdins.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
0000066C 8630CB28 dsNcService.exe C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
0000067C 85F49020 explorer.exe C:\WINDOWS\Explorer.EXE
0000069C 86259430 RapApp.exe C:\Program Files\ISS\Proventia Desktop\RapApp.exe
000006D0 86208500 Apache.exe C:\AdventNet\WebNMS\apache\bin\Apache.exe
00000828 85F40B90 RapUISvc.exe C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
00000834 85E438F0 notepad.exe C:\WINDOWS\system32\notepad.exe
00000848 8620A728 msiexec.exe C:\WINDOWS\system32\msiexec.exe
0000084C 85FAF900 wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe
000008F8 86F5F950 wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe
00000A4C 86D05AF8 wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe
00000B18 85FA2020 wmiprvse.exe C:\WINDOWS\system32\wbem\wmiprvse.exe
00000C20 85E8D918 iPodService.exe C:\Program Files\iPod\bin\iPodService.exe
00000C98 85F276D8 SMax4PNP.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
00000D00 85F26340 SMax4.exe C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
00000D1C 86ED1DA0 atiptaxx.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
00000D2C 86EBD950 eabservr.exe C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
00000D3C 85F153F0 AGRSMMSG.exe C:\WINDOWS\AGRSMMSG.exe
00000D50 86ED5750 SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
00000D6C 86EC7950 SynTPEnh.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
00000D80 85F16B80 sprtcmd.exe C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe
00000D88 85F0C7C8 iTunesHelper.ex C:\Program Files\iTunes\iTunesHelper.exe
00000E3C 85EFD908 wcescomm.exe C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
00000E70 85ED2020 TeaTimer.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
00000ED8 85EB6DA0 BTTray.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

Kernel Module:
EntryPoint | Module Base | Image Size | Module Path
806AC5CE 804D7000 00214500 ntoskrnl.exe \WINDOWS\system32\ntoskrnl.exe
807090BC 806EC000 00020380 hal.dll \WINDOWS\system32\hal.dll
F7B2ECE6 F7B2E000 00002000 kdcom.dll \WINDOWS\system32\KDCOM.DLL
F7A3F872 F7A3E000 00003000 BOOTVID.dll \WINDOWS\system32\BOOTVID.dll
F7608059 F75DF000 0002E000 ACPI.sys ACPI.sys
F7B30B80 F7B30000 00002000 WMILIB.SYS \WINDOWS\system32\DRIVERS\WMILIB.SYS
F75DC004 F75CE000 00011000 pci.sys pci.sys
F76353E4 F762E000 00009000 isapnp.sys isapnp.sys
F7A43A00 F7A42000 00003000 compbatt.sys compbatt.sys
F7A46F00 F7A46000 00004000 BATTC.SYS \WINDOWS\system32\DRIVERS\BATTC.SYS
F7BF661E F7BF6000 00001000 pciide.sys pciide.sys
F78B3205 F78AE000 00007000 PCIIDEX.SYS \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
F7B32B6E F7B32000 00002000 aliide.sys aliide.sys
F7B352F4 F7B34000 00002000 cmdide.sys cmdide.sys
F7B36A94 F7B36000 00002000 toside.sys toside.sys
F7B38E85 F7B38000 00002000 viaide.sys viaide.sys
F7B3AF05 F7B3A000 00002000 intelide.sys intelide.sys
F75CAB86 F75B0000 0001E000 pcmcia.sys pcmcia.sys
F76471B4 F763E000 0000B000 MountMgr.sys MountMgr.sys
F75AC4E2 F7591000 0001F000 ftdisk.sys ftdisk.sys
F7B3CBF6 F7B3C000 00002000 dmload.sys dmload.sys
F758CF05 F756B000 00026000 dmio.sys dmio.sys
F78B9880 F78B6000 00005000 PartMgr.sys PartMgr.sys
F7A4BD00 F7A4A000 00003000 ACPIEC.sys ACPIEC.sys
F7BF734A F7BF7000 00001000 OPRGHDLR.SYS \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
F7657D3E F764E000 0000D000 VolSnap.sys VolSnap.sys
F7A4E300 F7A4E000 00004000 cpqarray.sys cpqarray.sys
F7568039 F7553000 00018000 SCSIPORT.SYS \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
F7480692 F747D000 000D6000 iaStor.sys iaStor.sys
F747A5F7 F7465000 00018000 atapi.sys atapi.sys
F7A53BD2 F7A52000 00004000 aha154x.sys aha154x.sys
F78BEFEA F78BE000 00005000 sparrow.sys sparrow.sys
F7A58FF8 F7A56000 00004000 symc810.sys symc810.sys
F7669808 F765E000 0000E000 aic78xx.sys aic78xx.sys
F7A5CA38 F7A5A000 00004000 dac960nt.sys dac960nt.sys
F7670042 F766E000 00009000 ql10wnt.sys ql10wnt.sys
F7A60472 F7A5E000 00003000 amsint.sys amsint.sys
F78C7636 F78C6000 00007000 asc.sys asc.sys
F7A62F52 F7A62000 00004000 asc3550.sys asc3550.sys
F78CEA78 F78CE000 00005000 mraid35x.sys mraid35x.sys
F78D9F85 F78D6000 00005000 i2omp.sys i2omp.sys
F7A691D4 F7A66000 00004000 ini910u.sys ini910u.sys
F7680034 F767E000 0000A000 ql1240.sys ql1240.sys
F769999A F768E000 0000E000 aic78u2.sys aic78u2.sys
F78E3F86 F78DE000 00008000 symc8xx.sys symc8xx.sys
F78EBA66 F78E6000 00007000 sym_hi.sys sym_hi.sys
F78F4268 F78EE000 00008000 sym_u3.sys sym_u3.sys
F78F7642 F78F6000 00006000 ABP480N5.SYS ABP480N5.SYS
F78FEC3E F78FE000 00006000 asc3350p.sys asc3350p.sys
F7B3EA15 F7B3E000 00002000 cd20xrnt.sys cd20xrnt.sys
F76A3CE8 F769E000 00009000 ultra.sys ultra.sys
F74603C0 F744C000 00019000 adpu160m.sys adpu160m.sys
F7909E30 F7906000 00005000 dpti2o.sys dpti2o.sys
F76AFF9C F76AE000 0000A000 ql1080.sys ql1080.sys
F76C1BE8 F76BE000 0000C000 ql12160.sys ql12160.sys
F76D1C0A F76CE000 0000C000 ql1280.sys ql1280.sys
F791105A F790E000 00007000 perc2.sys perc2.sys
F7B40DC0 F7B40000 00002000 perc2hib.sys perc2hib.sys
F791905A F7916000 00007000 hpn.sys hpn.sys
F7A6CCE0 F7A6A000 00004000 cbidf2k.sys cbidf2k.sys
F742BB00 F7420000 0002C000 dac2w2k.sys dac2w2k.sys
F740B4C0 F7409000 00017000 symmpi.sys symmpi.sys
F73CC190 F73CB000 0003E000 a320raid.sys a320raid.sys
F76E58AB F76DE000 00009000 disk.sys disk.sys
F76F8E8F F76EE000 0000D000 CLASSPNP.SYS \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
F73C7C58 F73AB000 00020000 fltMgr.sys fltMgr.sys
F73A8FD4 F7399000 00012000 sr.sys sr.sys
F770391D F76FE000 00009000 PxHelp20.sys PxHelp20.sys
F7396E29 F7382000 00017000 KSecDD.sys KSecDD.sys
F737A204 F72F5000 0008D000 Ntfs.sys Ntfs.sys
F72F1205 F72C8000 0002D000 NDIS.sys NDIS.sys
F7716885 F770E000 0000B000 sisagp.sys sisagp.sys
F7726D05 F771E000 0000B000 viaagp.sys viaagp.sys
F72C4BFA F72AD000 0001B000 Mup.sys Mup.sys
F7736F85 F772E000 0000B000 alim1541.sys alim1541.sys
F7746F85 F773E000 0000B000 amdagp.sys amdagp.sys
F7756D85 F774E000 0000B000 agp440.sys agp440.sys
F7767705 F775E000 0000B000 agpCPQ.sys agpCPQ.sys
F7D152C6 F7D15000 00001000 idisw2km.sys \SystemRoot\system32\DRIVERS\idisw2km.sys
F719A310 F7189000 00014000 VIDEOPRT.SYS \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
F7B58BCC F7B58000 00002000 kbstuff5.sys \SystemRoot\system32\DRIVERS\kbstuff5.sys
F79A2610 F799E000 00006000 kbdclass.sys \SystemRoot\system32\DRIVERS\kbdclass.sys
F79AA035 F79A6000 00006000 mouclass.sys \SystemRoot\system32\DRIVERS\mouclass.sys
F7823885 F781E000 00009000 intelppm.sys \SystemRoot\system32\DRIVERS\intelppm.sys
F6FF28BA F6EE0000 00137000 ati2mtag.sys \SystemRoot\system32\DRIVERS\ati2mtag.sys
F79B2605 F79AE000 00005000 usbuhci.sys \SystemRoot\system32\DRIVERS\usbuhci.sys
F6EDD985 F6EBD000 00023000 USBPORT.SYS \SystemRoot\system32\DRIVERS\USBPORT.SYS
F79BBE05 F79B6000 00007000 usbehci.sys \SystemRoot\system32\DRIVERS\usbehci.sys
F6CA1610 F6CA1000 0021C000 w29n51.sys \SystemRoot\system32\DRIVERS\w29n51.sys
F6C9DDBF F6C79000 00028000 tifm21.sys \SystemRoot\system32\drivers\tifm21.sys
F6C7696C F6C68000 00011000 sdbus.sys \SystemRoot\system32\DRIVERS\sdbus.sys
F6C64A05 F6C52000 00016000 gtipci21.sys \SystemRoot\system32\DRIVERS\gtipci21.sys
F7AFCC00 F7AFA000 00004000 SMCLIB.SYS \SystemRoot\system32\DRIVERS\SMCLIB.SYS
F6C3CEB2 F6C12000 00040000 smwdm.sys \SystemRoot\system32\drivers\smwdm.sys
F6C0EC85 F6BEE000 00024000 portcls.sys \SystemRoot\system32\drivers\portcls.sys
F783BD85 F782E000 0000F000 drmk.sys \SystemRoot\system32\drivers\drmk.sys
F6BEAFB5 F6BCB000 00023000 ks.sys \SystemRoot\system32\drivers\ks.sys
F6BC84D6 F6BAB000 00020000 aeaudio.sys \SystemRoot\system32\drivers\aeaudio.sys
F6B9BC96 F6AA6000 00105000 AGRSM.sys \SystemRoot\system32\DRIVERS\AGRSM.sys
F79C3E6D F79BE000 00008000 Modem.SYS \SystemRoot\System32\Drivers\Modem.SYS
F784903B F783E000 00010000 serial.sys \SystemRoot\system32\DRIVERS\serial.sys
F7B08F69 F7B06000 00004000 serenum.sys \SystemRoot\system32\DRIVERS\serenum.sys
F7854000 F784E000 00009000 smcirda.sys \SystemRoot\system32\DRIVERS\smcirda.sys
F7B0C045 F7B0A000 00003000 irenum.sys \SystemRoot\system32\DRIVERS\irenum.sys
F6AA3705 F6A92000 00014000 parport.sys \SystemRoot\system32\DRIVERS\parport.sys
F7867385 F785E000 0000D000 i8042prt.sys \SystemRoot\system32\DRIVERS\i8042prt.sys
F6A8ED60 F6A64000 0002E000 SynTP.sys \SystemRoot\system32\DRIVERS\SynTP.sys
F7B5A300 F7B5A000 00002000 USBD.SYS \SystemRoot\system32\DRIVERS\USBD.SYS
F78769FB F786E000 0000B000 imapi.sys \SystemRoot\system32\DRIVERS\imapi.sys
F78886DA F787E000 0000D000 cdrom.sys \SystemRoot\system32\DRIVERS\cdrom.sys
F7899685 F788E000 0000F000 redbook.sys \SystemRoot\system32\DRIVERS\redbook.sys
F79CA000 F79C6000 00007000 GEARAspiWDM.sys \SystemRoot\System32\Drivers\GEARAspiWDM.sys
F7B18966 F7B16000 00004000 CmBatt.sys \SystemRoot\system32\DRIVERS\CmBatt.sys
F7B1B894 F7B1A000 00003000 wmiacpi.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys
F69980E0 F6858000 00144000 btkrnl.sys \SystemRoot\system32\DRIVERS\btkrnl.sys
F78A512C F789E000 0000A000 dsNcAdpt.sys \SystemRoot\system32\DRIVERS\dsNcAdpt.sys
F7D24600 F7D24000 00001000 audstub.sys \SystemRoot\system32\DRIVERS\audstub.sys
F79D1A80 F79CE000 00005000 rasirda.sys \SystemRoot\system32\DRIVERS\rasirda.sys
F79D9B05 F79D6000 00005000 TDI.SYS \SystemRoot\system32\DRIVERS\TDI.SYS
F7260505 F7255000 0000D000 rasl2tp.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys
F7B23A22 F7B22000 00003000 ndistapi.sys \SystemRoot\system32\DRIVERS\ndistapi.sys
F6855323 F6841000 00017000 ndiswan.sys \SystemRoot\system32\DRIVERS\ndiswan.sys
F724E165 F7245000 0000B000 raspppoe.sys \SystemRoot\system32\DRIVERS\raspppoe.sys
F723F905 F7235000 0000C000 raspptp.sys \SystemRoot\system32\DRIVERS\raspptp.sys
F79E14A2 F79DE000 00005000 ptilink.sys \SystemRoot\system32\DRIVERS\ptilink.sys
F79E9200 F79E6000 00005000 raspti.sys \SystemRoot\system32\DRIVERS\raspti.sys
F722F317 F7225000 0000C000 pcouffin.sys \SystemRoot\System32\Drivers\pcouffin.sys
F683B885 F6810000 00031000 rdpdr.sys \SystemRoot\system32\DRIVERS\rdpdr.sys
F721D657 F7215000 0000A000 termdd.sys \SystemRoot\system32\DRIVERS\termdd.sys
F7B5C8DD F7B5C000 00002000 swenum.sys \SystemRoot\system32\DRIVERS\swenum.sys
F680E048 F67DC000 00034000 update.sys \SystemRoot\system32\DRIVERS\update.sys
F727BBE6 F7279000 00004000 mssmbios.sys \SystemRoot\system32\DRIVERS\mssmbios.sys
F720CF20 F7205000 0000A000 NDProxy.SYS \SystemRoot\System32\Drivers\NDProxy.SYS
F71D1A05 F71C5000 0000F000 usbhub.sys \SystemRoot\system32\DRIVERS\usbhub.sys
F7B65785 F7B64000 00002000 i2omgmt.SYS \SystemRoot\System32\Drivers\i2omgmt.SYS
F46C6B70 F4674000 00058000 savrt.sys \??\C:\Program Files\Symantec AntiVirus\savrt.sys
F4670010 F4652000 00022000 SYMEVENT.SYS \??\C:\Program Files\Symantec\SYMEVENT.SYS
F464F070 F463E000 00014000 Savrtpel.sys \??\C:\Program Files\Symantec AntiVirus\Savrtpel.sys
F45AD960 F4565000 000D9000 navex15.sys \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080428.003\navex15.sys
F455333B F4552000 00013000 naveng.sys \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20080428.003\naveng.sys
F7B695E4 F7B68000 00002000 Fs_Rec.SYS \SystemRoot\System32\Drivers\Fs_Rec.SYS
F7C8759A F7C87000 00001000 Null.SYS \SystemRoot\System32\Drivers\Null.SYS
F7B6A66C F7B6A000 00002000 Beep.SYS \SystemRoot\System32\Drivers\Beep.SYS
F7A12642 F7A0E000 00006000 vga.sys \SystemRoot\System32\drivers\vga.sys
F7B6C646 F7B6C000 00002000 mnmdd.SYS \SystemRoot\System32\Drivers\mnmdd.SYS
F7B6E944 F7B6E000 00002000 RDPCDD.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys
F7A19BED F7A16000 00005000 Msfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS
F7A246D3 F7A1E000 00008000 Npfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS
F7AE766B F7AE6000 00003000 rasacd.sys \SystemRoot\system32\DRIVERS\rasacd.sys
F452F885 F451F000 00013000 ipsec.sys \SystemRoot\system32\DRIVERS\ipsec.sys
F77C5A85 F77BE000 00009000 msgpc.sys \SystemRoot\system32\DRIVERS\msgpc.sys
F4518516 F44C7000 00058000 tcpip.sys \SystemRoot\system32\DRIVERS\tcpip.sys
F44C2F85 F449F000 00028000 netbt.sys \SystemRoot\system32\DRIVERS\netbt.sys
F449AF40 F447D000 00022000 afd.sys \SystemRoot\System32\drivers\afd.sys
F77D54A9 F77CE000 00009000 netbios.sys \SystemRoot\system32\DRIVERS\netbios.sys
F77E2160 F77DE000 00009000 WrqDft.SYS \SystemRoot\System32\Drivers\WrqDft.SYS
F7A26430 F7A26000 00005000 WrqSDL.SYS \SystemRoot\System32\Drivers\WrqSDL.SYS
F4478EF8 F4452000 0002B000 rdbss.sys \SystemRoot\system32\DRIVERS\rdbss.sys
F444A803 F43E3000 0006F000 mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys
F77F2F2B F77EE000 00009000 Fips.SYS \SystemRoot\System32\Drivers\Fips.SYS
F7804FD6 F77FE000 00009000 wanarp.sys \SystemRoot\system32\DRIVERS\wanarp.sys
F435B07D F430B000 00060000 eeCtrl.sys \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
F430707E F42ED000 0001E000 EraserUtilRebootDrv.sys \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
F7B7030E F7B70000 00002000 EABFiltr.sys \??\C:\WINDOWS\system32\drivers\EABFiltr.sys
F6A61A85 F6A54000 00010000 Cdfs.SYS \SystemRoot\System32\Drivers\Cdfs.SYS
F42EA5F7 F42D5000 00018000 dump_atapi.sys \SystemRoot\System32\Drivers\dump_atapi.sys
F7B7AB80 F7B7A000 00002000 dump_WMILIB.SYS \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF9AFB6F BF800000 001C3000 win32k.sys \SystemRoot\System32\win32k.sys
F67C5E80 F67C4000 00003000 Dxapi.sys \SystemRoot\System32\drivers\Dxapi.sys
F7931890 F792E000 00005000 watchdog.sys \SystemRoot\System32\watchdog.sys
BF9D3090 BF9C3000 00012000 dxg.sys \SystemRoot\System32\drivers\dxg.sys
F7C07359 F7C07000 00001000 dxgthk.sys \SystemRoot\System32\drivers\dxgthk.sys
BF9F8348 BF9D5000 0003C000 ati2dvag.dll \SystemRoot\System32\ati2dvag.dll
BFA1B6A0 BFA11000 00033000 ati2cqag.dll \SystemRoot\System32\ati2cqag.dll
BFA57DE0 BFA44000 00033000 atikvmag.dll \SystemRoot\System32\atikvmag.dll
BFA77000 BFA77000 0023E000 ati3duag.dll \SystemRoot\System32\ati3duag.dll
BFCB5000 BFCB5000 00097000 ativvaxx.dll \SystemRoot\System32\ativvaxx.dll
BFFB3ADB BFFA0000 00046000 ATMFD.DLL \SystemRoot\System32\ATMFD.DLL
B8DF4AFB B8DE2000 00016000 irda.sys \SystemRoot\system32\DRIVERS\irda.sys
F7982685 F797E000 00006000 TDTCP.SYS \SystemRoot\System32\Drivers\TDTCP.SYS
B8C77F85 B8C57000 00023000 RDPWD.SYS \SystemRoot\System32\Drivers\RDPWD.SYS
B8B8AD85 B8B63000 0002C000 mrxdav.sys \SystemRoot\system32\DRIVERS\mrxdav.sys
B8A43D85 B89F9000 00052000 srv.sys \SystemRoot\system32\DRIVERS\srv.sys
B88B6D85 B88A4000 00015000 wdmaud.sys \SystemRoot\system32\drivers\wdmaud.sys
F47018E1 F46F4000 0000F000 sysaudio.sys \SystemRoot\system32\drivers\sysaudio.sys
B8A83D0A B8A7B000 0000D000 RapDrv.sys \SystemRoot\System32\drivers\RapDrv.sys
B8503C16 B84F2000 00014000 isskboep.sys \SystemRoot\system32\drivers\isskboep.sys
B7C74F50 B7C72000 0000E000 NIAPMirrorSystem.sys \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys
B7B3F105 B7B17000 0002B000 kmixer.sys \SystemRoot\system32\drivers\kmixer.sys
B7B01B50 B7AFD000 0001A000 NIAPRkDetect.sys \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPRkDetect.sys

SSDT:
ID | Current Function Address | Module Path | Source Function Address | Function Name
HOOK 00000025 B84F9C05 \SystemRoot\system32\drivers\isskboep.sys 8056FBF8 ZwCreateFile
HOOK 00000029 B8A80EA8 \SystemRoot\System32\drivers\RapDrv.sys 8056E7A9 ZwCreateKey
HOOK 0000002F B84F9C0C \SystemRoot\system32\drivers\isskboep.sys 805B0AA4 ZwCreateProcess
HOOK 00000030 B84F9C13 \SystemRoot\system32\drivers\isskboep.sys 80581E82 ZwCreateProcessEx
HOOK 00000039 B8A8084A \SystemRoot\System32\drivers\RapDrv.sys 80659301 ZwDebugActiveProcess
HOOK 00000077 B8A80FF2 \SystemRoot\System32\drivers\RapDrv.sys 80567CFB ZwOpenKey
HOOK 0000007A B8A8085C \SystemRoot\System32\drivers\RapDrv.sys 80572D06 ZwOpenProcess
HOOK 00000101 B8A806EC \SystemRoot\System32\drivers\RapDrv.sys 80584740 ZwTerminateProcess
HOOK 0000011C B7C74530 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys D763C355 -----
HOOK 0000011D B7C74590 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 71318D8B -----
HOOK 0000011E B7C745E0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 049B6FDF -----
HOOK 0000011F B7C74630 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 7FDD7024 -----
HOOK 00000120 B7C74680 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 9C50ABFF -----
HOOK 00000121 B7C746D0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 68618673 -----
HOOK 00000122 B7C74710 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 800E9FCF -----
HOOK 00000123 B7C74750 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 051D300B -----
HOOK 00000124 B7C747A0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 800D70D8 -----
HOOK 00000125 B7C747F0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 2329B38B -----
HOOK 00000126 B7C74850 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 7FED6008 -----
HOOK 00000127 B7C748A0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 813A23FF -----
HOOK 00000128 B7C748F0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 13987000 -----
HOOK 00000129 B7C74940 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 800D7134 -----
HOOK 0000012A B7C74980 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 9880FB52 -----
HOOK 0000012B B7C749E0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys ACB0F956 -----
HOOK 0000012C B7C74A30 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 030D7001 -----
HOOK 0000012D B7C74A80 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 7C9960E4 -----
HOOK 0000012E B7C74AC0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 821E5C81 -----
HOOK 0000012F B7C74B00 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 6E8E7000 -----
HOOK 00000130 B7C74B40 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 800D7210 -----
HOOK 00000131 B7C74BB0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 091BFBFA -----
HOOK 00000132 B7C74C00 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys CE98940C -----
HOOK 00000133 B7C74C40 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys A459F904 -----
HOOK 00000134 B7C74C80 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 885BFB04 -----
HOOK 00000135 B7C74CF0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 8831BC89 -----
HOOK 00000136 B7C74D40 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 0925BE8B -----
HOOK 00000137 B7C74D90 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 0B25944C -----
HOOK 00000138 B7C74DF0 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys 800F7C8E -----
HOOK 00000139 B7C74E50 \??\D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAPMirrorSystem.sys A499F900 -----

Shadow Table:
ID | Current Function Address | Module Path | Source Function Address | Function Name

System Callback:
Notify type | Address | Module Name | Module Path
Process Create/Terminate F465B280 SYMEVENT.SYS \??\C:\Program Files\Symantec\SYMEVENT.SYS
Process Create/Terminate B84FE4F4 isskboep.sys \SystemRoot\system32\drivers\isskboep.sys
Thread Create/Terminate F465B220 SYMEVENT.SYS \??\C:\Program Files\Symantec\SYMEVENT.SYS
LoadImage F465B020 SYMEVENT.SYS \??\C:\Program Files\Symantec\SYMEVENT.SYS

FSD Dispatch hook:
Driver Name | Major Function | Address | Module Path
HOOK \FileSystem\Ntfs IRP_MJ_CREATE 00000000 \SystemRoot\System32\drivers\RapDrv.sys
HOOK \FileSystem\Ntfs IRP_MJ_WRITE 00000000 \SystemRoot\System32\drivers\RapDrv.sys
HOOK \FileSystem\Ntfs IRP_MJ_SET_INFORMATION 00000000 \SystemRoot\System32\drivers\RapDrv.sys
HOOK \FileSystem\Ntfs IRP_MJ_CLEANUP 00000000 \SystemRoot\System32\drivers\RapDrv.sys

Kernel Mode Hook:
Module Name | Address | Hook Type | Memo

Windows Hook:
Process Name | IsGlobal | Function Address | Hook Type | Module Path
BTTray.exe Local 73DD50C7 WH_MSGFILTER C:\WINDOWS\system32\MFC42.DLL
BTTray.exe Global 000014C0 WH_KEYBOARD C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
BTTray.exe Global 000010A0 WH_KEYBOARD C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
BTTray.exe Local 00D634E0 WH_CALLWNDPROC C:\WINDOWS\system32\CSH.dll
BTTray.exe Local 73DD4EAA WH_CBT C:\WINDOWS\system32\MFC42.DLL
BTTray.exe Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
BTTray.exe Global 000010D0 WH_MOUSE C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
BTTray.exe Local 73DD50C7 WH_MSGFILTER C:\WINDOWS\system32\MFC42.DLL
TeaTimer.exe Global 000014C0 WH_KEYBOARD C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
TeaTimer.exe Global 5FFF10A0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\sdcidle.dll
TeaTimer.exe Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
TeaTimer.exe Global 5FFF10D0 WH_MOUSE C:\Program Files\SupportSoft_Amer_Motorola\bin\sdcidle.dll
wcescomm.exe Global 000014C0 WH_KEYBOARD C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
wcescomm.exe Global 000010A0 WH_KEYBOARD C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
wcescomm.exe Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
wcescomm.exe Global 000010D0 WH_MOUSE C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
iTunesHelper.ex Global 000014C0 WH_KEYBOARD C:\Program Files\iTunes\iTunesHelper.exe
iTunesHelper.ex Global 000010A0 WH_KEYBOARD C:\Program Files\iTunes\iTunesHelper.exe
iTunesHelper.ex Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
iTunesHelper.ex Global 000010D0 WH_MOUSE C:\Program Files\iTunes\iTunesHelper.exe
sprtcmd.exe Global 000014C0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe
sprtcmd.exe Global 000010A0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe
sprtcmd.exe Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
sprtcmd.exe Global 000010D0 WH_MOUSE C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe
SynTPEnh.exe Global 000014C0 WH_KEYBOARD C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
SynTPEnh.exe Global 000010A0 WH_KEYBOARD C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
SynTPEnh.exe Global 00001580 WH_CBT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
SynTPEnh.exe Global 000010D0 WH_MOUSE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
SynTPLpr.exe Global 000014C0 WH_KEYBOARD C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPLpr.exe Global 000010A0 WH_KEYBOARD C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPLpr.exe Global 00001580 WH_CBT C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPLpr.exe Global 000010D0 WH_MOUSE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
AGRSMMSG.exe Global 000014C0 WH_KEYBOARD C:\WINDOWS\AGRSMMSG.exe
AGRSMMSG.exe Global 000010A0 WH_KEYBOARD C:\WINDOWS\AGRSMMSG.exe
AGRSMMSG.exe Global 00001580 WH_CBT C:\WINDOWS\AGRSMMSG.exe
AGRSMMSG.exe Global 000010D0 WH_MOUSE C:\WINDOWS\AGRSMMSG.exe
eabservr.exe Global 000014C0 WH_KEYBOARD C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
eabservr.exe Global 000010A0 WH_KEYBOARD C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
eabservr.exe Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
eabservr.exe Global 000010D0 WH_MOUSE C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
atiptaxx.exe Global 000014C0 WH_KEYBOARD C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
atiptaxx.exe Global 000010A0 WH_KEYBOARD C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
atiptaxx.exe Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
atiptaxx.exe Global 000010D0 WH_MOUSE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
SMax4.exe Local 73DD50C7 WH_MSGFILTER C:\WINDOWS\system32\MFC42.DLL
SMax4.exe Global 000014C0 WH_KEYBOARD C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
SMax4.exe Global 000010A0 WH_KEYBOARD C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
SMax4.exe Global 00001580 WH_CBT C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
SMax4.exe Global 000010D0 WH_MOUSE C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
SMax4.exe Local 73DD50C7 WH_MSGFILTER C:\WINDOWS\system32\MFC42.DLL
SMax4.exe Local 73DD4EAA WH_CBT C:\WINDOWS\system32\MFC42.DLL
SMax4PNP.exe Local 73DD50C7 WH_MSGFILTER C:\WINDOWS\system32\MFC42.DLL
SMax4PNP.exe Global 000014C0 WH_KEYBOARD C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
SMax4PNP.exe Global 000010A0 WH_KEYBOARD C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
SMax4PNP.exe Local 73DD4EAA WH_CBT C:\WINDOWS\system32\MFC42.DLL
SMax4PNP.exe Global 00001580 WH_CBT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
SMax4PNP.exe Global 000010D0 WH_MOUSE C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
RapUISvc.exe Local 0044C5C5 WH_MSGFILTER C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
RapUISvc.exe Global 000014C0 WH_KEYBOARD C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
RapUISvc.exe Global 000010A0 WH_KEYBOARD C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
RapUISvc.exe Global 00001580 WH_CBT C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
RapUISvc.exe Global 000010D0 WH_MOUSE C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
RapApp.exe Local 0041C897 WH_MSGFILTER C:\Program Files\ISS\Proventia Desktop\RapApp.exe
RapApp.exe Global 000014C0 WH_KEYBOARD C:\Program Files\ISS\Proventia Desktop\RapApp.exe
RapApp.exe Global 000010A0 WH_KEYBOARD C:\Program Files\ISS\Proventia Desktop\RapApp.exe
RapApp.exe Global 00001580 WH_CBT C:\Program Files\ISS\Proventia Desktop\RapApp.exe
RapApp.exe Global 000010D0 WH_MOUSE C:\Program Files\ISS\Proventia Desktop\RapApp.exe
RapApp.exe Local 0041C897 WH_MSGFILTER C:\Program Files\ISS\Proventia Desktop\RapApp.exe
RapApp.exe Local 0041C897 WH_MSGFILTER C:\Program Files\ISS\Proventia Desktop\RapApp.exe
RapApp.exe Local 0044C5C5 WH_MSGFILTER C:\Program Files\ISS\Proventia Desktop\RapApp.exe
RapApp.exe Local 00443C3C WH_CBT C:\Program Files\ISS\Proventia Desktop\RapApp.exe
explorer.exe Global 000014C0 WH_KEYBOARD C:\WINDOWS\Explorer.EXE
explorer.exe Global 5FFF10A0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\sdcidle.dll
explorer.exe Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
explorer.exe Global 5FFF10D0 WH_MOUSE C:\Program Files\SupportSoft_Amer_Motorola\bin\sdcidle.dll
spoolsv.exe Global 000014C0 WH_KEYBOARD C:\WINDOWS\system32\spoolsv.exe
spoolsv.exe Global 000010A0 WH_KEYBOARD C:\WINDOWS\system32\spoolsv.exe
spoolsv.exe Global 00001580 WH_CBT C:\WINDOWS\system32\spoolsv.exe
spoolsv.exe Global 000010D0 WH_MOUSE C:\WINDOWS\system32\spoolsv.exe
aawservice.exe Global 000014C0 WH_KEYBOARD C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
aawservice.exe Global 000010A0 WH_KEYBOARD C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
aawservice.exe Global 00001580 WH_CBT C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
aawservice.exe Global 000010D0 WH_MOUSE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
NIAP_XRay_Syste Local 00431453 WH_MSGFILTER D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAP_XRay_System.exe
NIAP_XRay_Syste Global 000014C0 WH_KEYBOARD D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAP_XRay_System.exe
NIAP_XRay_Syste Global 5FFF10A0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\sdcidle.dll
NIAP_XRay_Syste Local 0041EB20 WH_CBT D:\Profiles\MGI2890\Desktop\NIAP 0.5\NIAP_XRay_System.exe
NIAP_XRay_Syste Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
NIAP_XRay_Syste Global 5FFF10D0 WH_MOUSE C:\Program Files\SupportSoft_Amer_Motorola\bin\sdcidle.dll
Wuser32.exe Global 000014C0 WH_KEYBOARD C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
Wuser32.exe Global 000010A0 WH_KEYBOARD C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
Wuser32.exe Global 00001580 WH_CBT C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
Wuser32.exe Global 000010D0 WH_MOUSE C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
Vpatch.exe Global 000014C0 WH_KEYBOARD C:\Program Files\ISS\Proventia Desktop\vpatch.exe
Vpatch.exe Global 000010A0 WH_KEYBOARD C:\Program Files\ISS\Proventia Desktop\vpatch.exe
Vpatch.exe Global 00001580 WH_CBT C:\Program Files\ISS\Proventia Desktop\vpatch.exe
Vpatch.exe Global 000010D0 WH_MOUSE C:\Program Files\ISS\Proventia Desktop\vpatch.exe
tgsrvc.exe Global 000014C0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
tgsrvc.exe Global 000010A0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
tgsrvc.exe Global 00001580 WH_CBT C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
tgsrvc.exe Global 000010D0 WH_MOUSE C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
sprtsvc.exe Global 000014C0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
sprtsvc.exe Global 000010A0 WH_KEYBOARD C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
sprtsvc.exe Global 00001580 WH_CBT C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
sprtsvc.exe Global 000010D0 WH_MOUSE C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
rapimgr.exe Global 000014C0 WH_KEYBOARD C:\PROGRA~1\MICROS~3\rapimgr.exe
rapimgr.exe Global 000010A0 WH_KEYBOARD C:\PROGRA~1\MICROS~3\rapimgr.exe
rapimgr.exe Global 63001580 WH_CBT C:\WINDOWS\system32\SynTPFcs.dll
rapimgr.exe Global 000010D0 WH_MOUSE C:\PROGRA~1\MICROS~3\rapimgr.exe

my5sons
2008-04-29, 04:39
I am also having trouble with my wireless card now. I can't view any wireless networks, it just connects to whatever it wants. When I try to view wireless networks, it says "Windows can not configure this wireless connection"

It's like one of my svchost.exe is being stopped before it ever starts.

Also, I still have the files complained of. No matter how many times I delete them, they keep coming back. Spybot catches them, and Combo-Fix catches it on every scan, but when I reboot, they get dropped right back into my system32/drivers folder.

I also have the folders downld and disdn that keep coming back.

Rorschach112
2008-04-29, 14:04
There is a file dropper there that we need to find

Can you tell me the full file path of disdn


Can you run these online scans ?


Please do an online scan with Kaspersky WebScanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html)

Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading the latest definition files:
Once the files have been downloaded click on NEXT

Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)

Scan Options:
Scan Archives
Scan Mail Bases

Click OK
Now under select a target to scan:Select My Computer

This will program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.




Click here (http://support.f-secure.com/enu/home/ols.shtml) to use the F-Secure Online Scanner
Then click the Start Scanning button below.
You should get a notification (bar on top) to install the activeX. Click on it and select to install the ActiveX.
Once the ActiveX is installed, you should accept the License terms by clicking OK below to start the scan.
In case you are having problems with installing the ActiveX/starting the scan, please read here (http://support.f-secure.com/enu/home/ols-faq.shtml).
Click the Full System Scan button.
It will start to download scanner components and databases. This can take a while.
The main scan will start.
Once the scan finished scanning, click the Automatic cleaning (recommended) button
It could be possible that your firewall gives an alert - allow it, because that's a connection you establish to submit infected files to F-Secure.
The cleaning can take a while, so please be patient.
Then click the Show report button and copy and paste what's present under results in your next reply.

my5sons
2008-04-29, 23:21
Thanks, sorry it took so long, but here are the results of the 2 files
Kaspersky
------------------------
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2008-04-29 14:09
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/04/2008
Kaspersky Anti-Virus database records: 731075
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 69970
Number of viruses found: 4
Number of infected objects: 43
Number of suspicious objects: 0
Duration of the scan process: 02:37:04

Infected Object Name / Virus Name / Last Action
C:\AdventNet\WebNMS\apache\logs\access.log Object is locked skipped
C:\AdventNet\WebNMS\apache\logs\error.log Object is locked skipped
C:\AdventNet\WebNMS\apache\logs\mod_jk2.log Object is locked skipped
C:\bootdir\tftp32\tftpd32.exe Infected: not-a-virus:Server-FTP.Win32.SFH.g skipped
C:\bootdir\tftp32.zip/tftp32/tftpd32.exe Infected: not-a-virus:Server-FTP.Win32.SFH.g skipped
C:\bootdir\tftp32.zip ZIP: infected - 1 skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\Program Files\ISS\Proventia Desktop\av.log Object is locked skipped
C:\Program Files\ISS\Proventia Desktop\avm.log Object is locked skipped
C:\Program Files\ISS\Proventia Desktop\BOEP_Daemon.log Object is locked skipped
C:\Program Files\ISS\Proventia Desktop\BOEP_Driver.log Object is locked skipped
C:\Program Files\ISS\Proventia Desktop\desktop-rapapp.log Object is locked skipped
C:\Program Files\ISS\Proventia Desktop\IbeEngine.log Object is locked skipped
C:\Program Files\ISS\Proventia Desktop\QM.log Object is locked skipped
C:\Program Files\ISS\Proventia Desktop\rapapp.log Object is locked skipped
C:\Program Files\ISS\Proventia Desktop\Scheduler.log Object is locked skipped
C:\Program Files\Juniper Networks\Common Files\NCService.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0539NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\VPTray.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\downld\1989921.exe.vir Infected: Trojan-Downloader.Win32.Bagle.ij skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\downld\319578.exe.vir Infected: Trojan-Downloader.Win32.Bagle.ij skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\downld\788453.exe.vir Infected: Trojan-Downloader.Win32.Bagle.ij skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\hldrrr.exe.vir Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\mdelk.exe.vir Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\QooBox\Quarantine\Registry_backups\Service_srosa.reg.dat Infected: Trojan-Downloader.Win32.Bagle.hp skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10\A0010012.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10\A0010013.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10\A0010018.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10\A0010019.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10\A0010068.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP11\A0011099.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP11\A0011100.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP11\A0011151.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP12\A0012195.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP12\A0012196.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13\A0012336.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13\A0014359.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13\A0014363.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13\A0014464.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13\A0014470.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13\A0015465.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13\change.log Object is locked skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2\A0000004.exe Infected: Trojan-Downloader.Win32.Bagle.ij skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2\A0000010.exe Infected: Trojan-Downloader.Win32.Bagle.ij skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2\A0000013.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2\A0000063.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2\A0002057.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2\A0002062.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2\A0002235.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP3\A0003240.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP3\A0003241.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4\A0003353.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4\A0004457.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4\A0005454.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4\A0005456.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\CAS.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\CcmExec.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\CertificateMaintenance.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\ClientIDManagerStartup.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\execmgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\LocationServices.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\mtrmgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PatchInstall.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PatchUIMonitor.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyAgent.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyAgentProvider.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\PolicyEvaluator.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\Scheduler.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\SrcUpdateMgr.log Object is locked skipped
C:\WINDOWS\system32\CCM\Logs\StatusAgent.log Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\0000001K.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\0000001K.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\0000000K.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\0000000K.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\0000000F.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\0000000F.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\0000000B.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\0000000B.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000T.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000T.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\0000001P.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\0000001P.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000008.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000008.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000003.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000003.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\000000B3.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\000000B3.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\0000000M.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\0000000M.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\00000032.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\00000032.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\0000002K.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\0000002K.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_il02isms-01.comm.mot.com_mp_locationmanager\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_il02isms-01.comm.mot.com_mp_locationmanager\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_pa06edm01_uploadprotocol\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_pa06edm01_uploadprotocol\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_zch68edm01_mp_locationmanager\00000001.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_zch68edm01_mp_locationmanager\00000001.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000004.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000004.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000003.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000003.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_relayendpoint\00000002.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_relayendpoint\00000002.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\00000002.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\00000002.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\00000012.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\00000012.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000D.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000D.que Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\0000002U.msg Object is locked skipped
C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\0000002U.que Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\hldrrr.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\WINDOWS\system32\drivers\mdelk.exe Infected: Trojan-Downloader.Win32.Bagle.nz skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_84c.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
D:\Profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
D:\Profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
D:\Profiles\All Users\Application Data\SupportSoft\supportsoft_amer_motorola\SYSTEM\state\logs\sprtcmd.log Object is locked skipped
D:\Profiles\LocalService\Cookies\index.dat Object is locked skipped
D:\Profiles\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Profiles\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Profiles\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Profiles\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Profiles\LocalService\NTUSER.DAT Object is locked skipped
D:\Profiles\LocalService\NTUSER.DAT.LOG Object is locked skipped
D:\Profiles\MGI2890\Application Data\$_hpcst$.hpc Object is locked skipped
D:\Profiles\MGI2890\Application Data\MessageOne\EMS\m1extension.log Object is locked skipped
D:\Profiles\MGI2890\Application Data\Microsoft\Outlook\Personal.srs Object is locked skipped
D:\Profiles\MGI2890\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\cert8.db Object is locked skipped
D:\Profiles\MGI2890\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\formhistory.dat Object is locked skipped
D:\Profiles\MGI2890\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\history.dat Object is locked skipped
D:\Profiles\MGI2890\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\key3.db Object is locked skipped
D:\Profiles\MGI2890\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\parent.lock Object is locked skipped
D:\Profiles\MGI2890\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\search.sqlite Object is locked skipped
D:\Profiles\MGI2890\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\urlclassifier2.sqlite Object is locked skipped
D:\Profiles\MGI2890\Cookies\index.dat Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\Cache\_CACHE_001_ Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\Cache\_CACHE_002_ Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\Cache\_CACHE_003_ Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Application Data\Mozilla\Firefox\Profiles\ryta075t.default\Cache\_CACHE_MAP_ Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Application Data\SupportSoft\supportsoft_amer_motorola\MGI2890\state\logs\sprtcmd.log Object is locked skipped
D:\Profiles\MGI2890\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Profiles\MGI2890\Local Settings\History\History.IE5\MSHist012008042920080430\index.dat Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Temp\WCESLog.log Object is locked skipped
D:\Profiles\MGI2890\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Profiles\MGI2890\ntuser.dat Object is locked skipped
D:\Profiles\MGI2890\NTUSER.DAT.LOG Object is locked skipped
D:\Profiles\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Profiles\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Profiles\NetworkService\NTUSER.DAT Object is locked skipped
D:\Profiles\NetworkService\NTUSER.DAT.LOG Object is locked skipped
D:\Profiles\sdm.MGI2890-02\Cookies\index.dat Object is locked skipped
D:\Profiles\sdm.MGI2890-02\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Profiles\sdm.MGI2890-02\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Profiles\sdm.MGI2890-02\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Profiles\sdm.MGI2890-02\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Profiles\sdm.MGI2890-02\ntuser.dat Object is locked skipped
D:\Profiles\sdm.MGI2890-02\NTUSER.DAT.LOG Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13\change.log Object is locked skipped
D:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4\A0005725.exe Infected: not-a-virus:Server-FTP.Win32.SFH.g skipped

Scan process completed.





------------------------
F-Secure
------------------------
Scanning Report
Tuesday, April 29, 2008 14:13:46 - 17:19:13

Computer name: MGI2890-02
Scanning type: Scan system for malware, rootkits
Target: C:\ D:\
Result: 6 malware found
Tracking Cookie (spyware)

* System

Trojan-Downloader.Win32.Bagle (virus)

* System

Trojan-Downloader.Win32.Bagle.nz (virus)

* C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE
* C:\WINDOWS\SYSTEM32\DRIVERS\MDELK.EXE
* C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\VPTRAY.EXE
* C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE

Statistics
Scanned:

* Files: 42232
* System: 4333
* Not scanned: 8

Actions:

* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 6
* Submitted: 0

Files not scanned:

* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
* D:\PROFILES\MGI2890\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\OUTLOOK\OUTLOOK.PST
* D:\PROFILES\MGI2890\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\OUTLOOK\OUTLOOK.PST

Options
Scanning engines:

* F-Secure USS: 2.30.0
* F-Secure Hydra: 2.8.8110, 2008-04-29
* F-Secure AVP: 7.0.171, 2008-04-29
* F-Secure Pegasus: 1.20.0, 2008-02-28
* F-Secure Blacklight: 1.0.64

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use Advanced heuristics

Rorschach112
2008-04-30, 00:17
Excellent, we found the file dropper


I also have the folders downld and disdn that keep coming back.
Can you tell me the full file path of this disdn folder/file



1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:


KillAll::

File::
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\mdelk.exe

Folder::
C:\WINDOWS\system32\drivers\downld

Registry::

Driver::



Save this as CFScript.txt, in the same location as ComboFix.exe


http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Doubleclick the drweb-cureit.exe file and Allow to run the express scan
This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, mark the drives that you want to scan.
Select all drives. A red dot shows which drives have been chosen.
Click the green arrow at the right, and the scan will start.
Click 'Yes to all' if it asks if you want to cure/move the file.
When the scan has finished, in the menu, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.

my5sons
2008-04-30, 03:42
The disdn folder is empty, but it keeps coming back. downld folder is gone now!!!!

C:\Windows\system32\drivers\disdn

Here is the result of Combo-Fix

ComboFix 08-04-27.3 - mgi2890 2008-04-29 21:20:40.8 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.623 [GMT -4:00]
Running from: D:\Profiles\MGI2890\Desktop\Combo-Fix.exe
Command switches used :: D:\Profiles\MGI2890\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\mdelk.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\downld
D:\Profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
D:\Profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

----- BITS: Possible infected sites -----

hxxp://PA06EDM01
.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-30 )))))))))))))))))))))))))))))))
.

2008-04-29 14:10 . 2008-04-29 14:10 <DIR> d-------- C:\fsaua.data
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- D:\Profiles\All Users\Application Data\Kaspersky Lab
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 15:24 . 2008-04-28 15:37 <DIR> d-------- D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2008-04-28 15:24 . 2008-04-28 15:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-28 15:23 . 2008-04-28 15:23 9,722,720 --a------ C:\spybotsd152.exe
2008-04-28 14:09 . 2008-04-28 15:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-28 01:32 . 2008-04-28 01:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-28 01:32 . 2008-04-28 01:32 812,344 --a------ C:\HJTInstall.exe
2008-04-28 00:50 . 2008-04-28 00:50 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-28 00:45 . 2008-04-27 20:49 <DIR> d-------- C:\SDFix
2008-04-27 23:32 . 2008-04-27 23:32 650,296 --a------ C:\PREVXCSIFREE(2).EXE
2008-04-27 23:12 . 2008-04-27 23:17 2,205,157 --a------ C:\IceSword122en.zip
2008-04-27 23:01 . 2008-04-27 23:01 650,296 --a------ C:\PREVXCSIFREE.EXE
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-27 22:39 . 2008-04-27 22:40 20,597,104 --a------ C:\aaw2007.exe
2008-04-25 22:05 . 2008-04-25 22:05 93,775 --a------ C:\2333.zip
2008-04-19 11:27 . 2008-04-19 11:27 <DIR> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-04-19 11:27 . 2008-04-24 12:21 275 --a------ C:\lxcjfire.csv
2008-04-19 11:27 . 2008-04-24 12:12 275 --a------ C:\lxcjfire.008
2008-04-19 11:27 . 2008-04-24 12:11 275 --a------ C:\lxcjfire.007
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.006
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.005
2008-04-19 11:27 . 2008-04-19 11:43 275 --a------ C:\lxcjfire.004
2008-04-19 11:27 . 2008-04-19 11:41 275 --a------ C:\lxcjfire.003
2008-04-19 11:27 . 2008-04-19 11:38 275 --a------ C:\lxcjfire.002
2008-04-19 11:27 . 2008-04-19 11:28 275 --a------ C:\lxcjfire.001
2008-04-19 11:27 . 2008-04-19 11:27 275 --a------ C:\lxcjfire.000
2008-04-19 11:22 . 2008-04-24 12:25 <DIR> d-------- C:\Lexmark
2008-04-17 18:20 . 2008-04-17 18:28 31,232 --a------ C:\proposedamendment(2).doc
2008-04-17 18:18 . 2008-04-17 18:18 23,552 --a------ C:\Proxy.doc
2008-04-17 18:18 . 2008-04-17 18:19 6,709 --a------ C:\proposedamendment.doc.part
2008-04-17 18:18 . 2008-04-17 18:18 0 --a------ C:\proposedamendment.doc
2008-04-17 18:15 . 2008-04-17 18:15 6,184 --a------ C:\Pheasant
2008-04-17 15:42 . 2008-04-27 23:07 8,704 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-15 09:45 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-15 09:45 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-08 20:50 . 2008-04-08 20:50 <DIR> d-------- D:\Profiles\All Users\Application Data\Office Genuine Advantage
2008-03-30 00:10 . 2008-03-30 00:10 732 --a------ C:\about_inc.php
2008-03-29 23:02 . 2008-03-29 23:02 <DIR> d-------- D:\Profiles\All Users\Application Data\FLEXnet
2008-03-29 22:01 . 2008-03-29 22:01 <DIR> d-------- D:\Profiles\NetworkService\Application Data\Juniper Networks
2008-03-29 02:02 . 2008-04-15 20:22 <DIR> d-------- C:\desktop
2008-03-26 22:11 . 2008-03-26 22:11 <DIR> d-------- D:\Profiles\sdm.MGI2890-02\Application Data\Juniper Networks
2008-03-18 22:54 . 2008-03-18 22:54 <DIR> d-------- D:\Profiles\MGI2890\Application Data\dvdcss
2008-03-15 21:43 . 2008-03-15 21:43 <DIR> d-------- C:\Program Files\WS_FTP
2008-03-14 23:56 . 2008-03-14 23:56 <DIR> d-------- D:\Profiles\MGI2890\Application Data\ZoomBrowser EX
2008-03-10 13:41 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-03-10 13:41 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-10 13:41 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-03-10 13:41 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-03-10 13:38 . 2008-03-10 13:38 <DIR> d-------- C:\Program Files\Common Files\Canon
2008-03-04 15:10 . 2008-03-04 15:10 754 --a------ C:\WINDOWS\WORDPAD.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-30 01:31 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-29 00:53 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-28 19:18 --------- d-----w C:\Program Files\Elaborate Bytes
2008-04-28 18:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 18:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 18:09 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-28 18:07 --------- d-----w C:\Program Files\Azureus
2008-04-28 18:05 --------- d-----w D:\Profiles\MGI2890\Application Data\Amazon
2008-04-28 18:05 --------- d-----w C:\Program Files\Amazon
2008-04-28 02:41 --------- d-----w D:\Profiles\All Users\Application Data\Lavasoft
2008-04-23 19:11 --------- d-----w D:\Profiles\MGI2890\Application Data\AdobeUM
2008-04-08 21:31 --------- d-----w D:\Profiles\MGI2890\Application Data\Vso
2008-03-28 19:08 --------- d-----w C:\Program Files\SlySoft
2008-03-22 01:14 --------- d-----w C:\Program Files\MSECache
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 19:46 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-03-08 02:09 --------- d-----w D:\Profiles\MGI2890\Application Data\Apple Computer
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-04 22:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2008-02-01 07:21 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2008-01-06 04:07 47,360 ----a-w D:\Profiles\MGI2890\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2008-04-28_ 0.37.27.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-28 04:29:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-30 01:26:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-02-27 19:59:28 290,816 ----a-w C:\WINDOWS\Downloaded Program Files\auc_lib.dll
+ 2008-02-27 19:59:28 495,616 ----a-w C:\WINDOWS\Downloaded Program Files\daas_s.dll
+ 2008-02-27 20:00:12 262,144 ----a-w C:\WINDOWS\Downloaded Program Files\fscax.dll
+ 2008-02-27 19:59:16 588,392 ----a-w C:\WINDOWS\Downloaded Program Files\gatelauncher.exe
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-28 04:50:45 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:46 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-28 04:50:43 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:43 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-26 20:41:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-28 19:10:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-21 04:29:56 1,516,240 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-28 19:42:36 1,515,504 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-04-30 01:31:36 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_980.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{749F8452-7D28-4658-A903-9B047E5A2CE8}"= "C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll" [2006-06-08 04:20 2420736]

[HKEY_CLASSES_ROOT\clsid\{749f8452-7d28-4658-a903-9b047e5a2ce8}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{37686C62-D497-42E3-BAAB-78D89A74E151}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DBISQL9"="" []
"SybaseCentral43"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 14:39 1289000]
"URLy Warning"="C:\Program Files\URLy Warning\URLyWarning.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 02:56 52896]
"CSCAdvantage"="C:\Program Files\Help Desk\CSCAdv.exe" [2005-06-09 13:41 111403]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 10:11 1388544]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 13:41 860160]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 22:05 344064]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 14:24 290816]
"AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 15:12 88209 C:\WINDOWS\AGRSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"CSCLogonInfo"="C:\WINDOWS\UsrLogon.exe" [2006-12-12 17:28 127079]
"SupportSoft_Amer_Motorola"="C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" [2006-07-12 17:00 192512]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SDFix"="C:\SDFix\RunThis.bat /second" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-02-01 18:31 3900776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
"LogonType"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoAutoTrayNotify"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-1086857\Scripts\Logon\0\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\0\0]
"Script"=wireless-qualification.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\1\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Netmeeting\\conf.exe"= C:\\Program Files\\Netmeeting\\conf.exe
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"113:TCP"= 113:TCP:10.176.1.190/199:enabled:bDNA
"497:TCP"= 497:TCP:10.0.38.5/10:enabled:bDNA2
"6000:TCP"= 6000:TCP:exceed
"135:TCP"= 135:TCP:10.160.5.8:enabled:foundscan
"137:TCP"= 137:TCP:10.197.24.2:enabled:foundscan2
"138:TCP"= 138:TCP:10.0.125.17:enabled:foundscan3
"139:TCP"= 139:TCP:10.0.125.20:enabled:foundscan4
"1503:TCP"= 1503:TCP:10.0.125.21:enabled:foundscan5
"1720:TCP"= 1720:TCP:10.1.250.11:enabled:foundscan6
"1761:TCP"= 1761:TCP:10.64.2.96:enabled:foundscan7
"2701:TCP"= 2701:TCP:10.128.132.49:enabled:iss1
"2702:TCP"= 2702:TCP:10.128.132.49:enabled:iss2
"43189:TCP"= 43189:TCP:10.160.9.87:enabled:iss3
"4445:TCP"= 4445:TCP:10.0.125.19:enabled:iss4
"6401:TCP"= 6401:TCP:192.168.30.7:enabled:iss5
"1023:UDP"= 1023:UDP:144.190.1.100:enabled:iss6
"445:TCP"= 445:TCP:10.0.125.15:enabled:nmap
"123:UDP"= 123:UDP:129.188.57.239:enabled:scanner1
"137:UDP"= 137:UDP:129.188.147.55:enabled:scanner2
"138:UDP"= 138:UDP:192.168.3.1:enabled:scanner3
"2233:UDP"= 2233:UDP:129.188.33.18:enabled:scanner4
"371:UDP"= 371:UDP:10.0.125.13:enabled:scanner5
"407:UDP"= 407:UDP:10.0.125.28:enabled:scanner6
"497:UDP"= 497:UDP:10.193.21.54:enabled:scanner7
"500:UDP"= 500:UDP:10.0.125.11:enabled:scanner8
"600:UDP"= 600:UDP:10.79.40.64:enabled:scanner9
"601:UDP"= 601:UDP:10.79.40.64:enabled:scanner10
"602:UDP"= 602:UDP:10.79.40.64:enabled:scanner11
"603:UDP"= 603:UDP:10.79.40.64:enabled:scanner12
"604:UDP"= 604:UDP:10.79.40.64:enabled:scanner13
"605:UDP"= 605:UDP:10.79.40.64:enabled:scanner14
"606:UDP"= 606:UDP:10.79.40.64:enabled:scanner15
"607:UDP"= 607:UDP:10.79.40.64:enabled:scanner16
"608:UDP"= 608:UDP:10.79.40.64:enabled:scanner17
"609:UDP"= 609:UDP:10.79.40.64:enabled:scanner18
"610:UDP"= 610:UDP:10.79.40.64:enabled:scanner19
"62514:UDP"= 62514:UDP:10.79.40.72,10.82.51.100,10.228.96.22/24,10.228.96.26,10.16.225.208,10.17.193.181,10.17.193.182:enabled:scanner20
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 1 (0x1)

R0 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-07-29 14:34]
R1 WrqDft;WrqDft;C:\WINDOWS\system32\drivers\WrqDft.sys [2002-07-29 09:50]
R1 WrqSDL;WrqSDL;C:\WINDOWS\system32\drivers\WrqSDL.sys [2002-07-29 09:50]
R2 ApacheForSDM;ApacheForSDM;"C:\AdventNet\WebNMS\apache\bin\Apache.exe" -k runservice []
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2007-04-13 03:50]
R2 sprtsvc_supportsoft_amer_motorola;SupportSoft Sprocket Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe [2006-07-12 17:01]
R2 tgsrvc_supportsoft_amer_motorola;SupportSoft Repair Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe [2006-07-12 17:01]
R2 VPatch;ISS Buffer Overflow Exploit Prevention;"C:\Program Files\ISS\Proventia Desktop\vpatch.exe" [2007-10-29 13:44]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2007-10-03 13:48]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 12:46]
R3 MakoNT;MakoNT;C:\WINDOWS\system32\drivers\isskboep.sys [2007-06-15 19:56]
R3 rap;rap;C:\WINDOWS\system32\drivers\RapDrv.sys [2007-10-29 13:44]
R4 black;black;C:\WINDOWS\system32\drivers\BlackCat.sys [2007-06-15 19:56]
S3 ASANYs_WebNmsDB;Adaptive Server Anywhere - WebNmsDB;C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [2005-02-25 11:27]
S3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys []
S3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2007-04-13 03:50]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C10BF3A1-3FEC-4a94-AAAF-9D6A4B522F63}]
"C:\Program Files\WinZip\wzusr90.exe" /NOICON /NOTRAY
.
Contents of the 'Scheduled Tasks' folder
"2008-04-30 01:29:15 C:\WINDOWS\Tasks\CheckNetwork.job"
- C:\Program Files\Motorola\WirelessControl\NetStatus.vbs
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-29 21:32:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe
C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-04-29 21:36:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-30 01:36:40
ComboFix2.txt 2008-04-29 00:06:54
ComboFix3.txt 2008-04-28 23:48:12
ComboFix4.txt 2008-04-28 21:44:35
ComboFix5.txt 2008-04-28 05:56:25

Pre-Run: 7,822,442,496 bytes free
Post-Run: 7,797,030,912 bytes free

307

my5sons
2008-04-30, 06:36
Here is the Dr. Web report. 2 of the items which say "probably DLOADR.Trojan" and other that say "Probably SCRIPT.Virus" are used by my company to update software on my laptop.

sprtsync.dll;c:\program files\supportsoft_amer_motorola\bin;Probably DLOADER.Trojan;;
sprtupdate.dll;c:\program files\supportsoft_amer_motorola\bin;Probably DLOADER.Trojan;;
psloggedon.exe;C:\ntutils;Program.PsLogon.131;;
modem_common.js;C:\Program Files\SupportSoft_Amer_Motorola\agentcommon\inc;Probably SCRIPT.Virus;;
sma_common.js;C:\Program Files\SupportSoft_Amer_Motorola\agentui\snapins\preferences;Probably SCRIPT.Virus;;
sprtsync.dll;C:\Program Files\SupportSoft_Amer_Motorola\bin;Probably DLOADER.Trojan;;
sprtupdate.dll;C:\Program Files\SupportSoft_Amer_Motorola\bin;Probably DLOADER.Trojan;;
ssrc.exe;C:\Program Files\SupportSoft_Amer_Motorola\bin;Probably DLOADER.Trojan;;
hldrrr.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32\drivers;Win32.HLLM.Beagle.212;Deleted.;
mdelk.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32\drivers;Win32.HLLM.Beagle.212;Deleted.;
Process.exe;C:\SDFix\apps;Tool.Prockill;;
A0010012.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10;Win32.HLLM.Beagle.212;Deleted.;
A0010013.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10;Win32.HLLM.Beagle.212;Deleted.;
A0010018.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10;Win32.HLLM.Beagle.212;Deleted.;
A0010019.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10;Win32.HLLM.Beagle.212;Deleted.;
A0010068.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP10;Win32.HLLM.Beagle.212;Deleted.;
A0011099.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP11;Win32.HLLM.Beagle.212;Deleted.;
A0011100.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP11;Win32.HLLM.Beagle.212;Deleted.;
A0011106.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP11;Probably BATCH.Virus;;
A0011112.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP11;Probably SCRIPT.Virus;;
A0011151.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP11;Win32.HLLM.Beagle.212;Deleted.;
A0012195.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP12;Win32.HLLM.Beagle.212;Deleted.;
A0012196.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP12;Win32.HLLM.Beagle.212;Deleted.;
A0012202.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP12;Probably BATCH.Virus;;
A0012208.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP12;Probably SCRIPT.Virus;;
A0012294.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Probably BATCH.Virus;;
A0012300.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Probably SCRIPT.Virus;;
A0012336.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Win32.HLLM.Beagle.212;Deleted.;
A0014359.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Win32.HLLM.Beagle.212;Deleted.;
A0014363.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Win32.HLLM.Beagle.212;Deleted.;
A0014464.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Win32.HLLM.Beagle.212;Deleted.;
A0014470.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Win32.HLLM.Beagle.212;Deleted.;
A0015465.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Win32.HLLM.Beagle.212;Deleted.;
A0015495.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Win32.HLLM.Beagle.212;Deleted.;
A0015496.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Win32.HLLM.Beagle.212;Deleted.;
A0016821.EXE;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP16;Program.PsExec.170;;
A0016823.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP16;Probably BATCH.Virus;;
A0016830.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP16;Probably SCRIPT.Virus;;
A0000013.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Win32.HLLM.Beagle.212;Deleted.;
A0000063.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Win32.HLLM.Beagle.212;Deleted.;
A0002057.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Win32.HLLM.Beagle.212;Deleted.;
A0002062.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Win32.HLLM.Beagle.212;Deleted.;
A0002070.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Probably BATCH.Virus;;
A0002077.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Probably SCRIPT.Virus;;
A0002107.EXE;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Program.PsExec.170;;
A0002161.EXE;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Program.PsExec.170;;
A0002164.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Probably BATCH.Virus;;
A0002172.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Probably SCRIPT.Virus;;
A0002235.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP2;Win32.HLLM.Beagle.212;Deleted.;
A0003240.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP3;Win32.HLLM.Beagle.212;Deleted.;
A0003241.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP3;Win32.HLLM.Beagle.212;Deleted.;
A0003253.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP3;Probably BATCH.Virus;;
A0003259.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP3;Probably SCRIPT.Virus;;
A0003286.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4;Probably BATCH.Virus;;
A0003292.bat;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4;Probably SCRIPT.Virus;;
A0003353.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4;Win32.HLLM.Beagle.212;Deleted.;
A0004369.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4;Tool.Prockill;;
A0004457.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4;Win32.HLLM.Beagle.212;Deleted.;
A0005454.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4;Win32.HLLM.Beagle.212;Deleted.;
A0005456.exe;C:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP4;Win32.HLLM.Beagle.212;Deleted.;
psloggedon.exe;C:\WINDOWS\system32\CCM\Cache\00N000DC.1.System\Source;Program.PsLogon.131;;
motimpop.exe;C:\WINDOWS\system32\CCM\Cache\00N000FC.2.System\Source;Modification of BackDoor.Generic.889;Moved.;
INSTSRV.EXE;C:\WINDOWS\system32\CCM\Cache\00N0010B.4.System\custom;Tool.InstSrv;;
SRVANY.EXE;C:\WINDOWS\system32\CCM\Cache\00N0010B.4.System\custom;Program.SrvAny;;
INSTSRV.EXE;C:\WINDOWS\system32\CCM\Cache\00N00147.1.System\custom;Tool.InstSrv;;
SRVANY.EXE;C:\WINDOWS\system32\CCM\Cache\00N00147.1.System\custom;Program.SrvAny;;
RegUBP2b-mgi2890.reg;D:\Profiles\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.;
A0012267.reg;D:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP12;Trojan.StartPage.1505;Deleted.;
A0014398.reg;D:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP13;Trojan.StartPage.1505;Deleted.;
A0015713.reg;D:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP15;Trojan.StartPage.1505;Deleted.;
A0016858.reg;D:\System Volume Information\_restore{B744757C-6CC3-42AA-AA44-27DE274B6188}\RP16;Trojan.StartPage.1505;Deleted.;

my5sons
2008-04-30, 06:37
Sorry, forgot to say that I am still having trouble with my wireless, I have lost Wireless Zero Configuration. I can't change my wireless networks. I go into Services, and I can't start WZC either.

Rorschach112
2008-04-30, 14:35
Ok looking good

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:


DirLook::
C:\Windows\system32\drivers\disdn

Folder::

Registry::

Driver::



Save this as CFScript.txt, in the same location as ComboFix.exe


http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall




Please download Malwarebytes' Anti-Malware from Here (http://www.besttechie.net/tools/mbam-setup.exe) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Full Scan", then click Scan. Check all the boxes and click Start Scan
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Also post a new HijackThis log

my5sons
2008-05-01, 06:18
disdn folder is still there after running ComboFix, but it is empty??????.

ComboFix 08-04-27.3 - mgi2890 2008-04-30 10:20:43.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.385 [GMT -4:00]
Running from: D:\Profiles\MGI2890\Desktop\Combo-Fix.exe
Command switches used :: D:\Profiles\MGI2890\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-30 )))))))))))))))))))))))))))))))
.

2008-04-29 21:48 . 2008-04-30 00:14 <DIR> d-------- D:\Profiles\MGI2890\DoctorWeb
2008-04-29 21:41 . 2008-04-29 21:45 10,258,232 --a------ C:\drweb-cureit.exe
2008-04-29 14:10 . 2008-04-29 14:10 <DIR> d-------- C:\fsaua.data
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- D:\Profiles\All Users\Application Data\Kaspersky Lab
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 15:24 . 2008-04-28 15:37 <DIR> d-------- D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2008-04-28 15:24 . 2008-04-28 15:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-28 15:23 . 2008-04-28 15:23 9,722,720 --a------ C:\spybotsd152.exe
2008-04-28 14:09 . 2008-04-28 15:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-28 01:32 . 2008-04-28 01:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-28 01:32 . 2008-04-28 01:32 812,344 --a------ C:\HJTInstall.exe
2008-04-28 00:50 . 2008-04-28 00:50 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-28 00:45 . 2008-04-27 20:49 <DIR> d-------- C:\SDFix
2008-04-27 23:32 . 2008-04-27 23:32 650,296 --a------ C:\PREVXCSIFREE(2).EXE
2008-04-27 23:12 . 2008-04-27 23:17 2,205,157 --a------ C:\IceSword122en.zip
2008-04-27 23:01 . 2008-04-27 23:01 650,296 --a------ C:\PREVXCSIFREE.EXE
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-27 22:39 . 2008-04-27 22:40 20,597,104 --a------ C:\aaw2007.exe
2008-04-25 22:05 . 2008-04-25 22:05 93,775 --a------ C:\2333.zip
2008-04-19 11:27 . 2008-04-19 11:27 <DIR> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-04-19 11:27 . 2008-04-24 12:21 275 --a------ C:\lxcjfire.csv
2008-04-19 11:27 . 2008-04-24 12:12 275 --a------ C:\lxcjfire.008
2008-04-19 11:27 . 2008-04-24 12:11 275 --a------ C:\lxcjfire.007
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.006
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.005
2008-04-19 11:27 . 2008-04-19 11:43 275 --a------ C:\lxcjfire.004
2008-04-19 11:27 . 2008-04-19 11:41 275 --a------ C:\lxcjfire.003
2008-04-19 11:27 . 2008-04-19 11:38 275 --a------ C:\lxcjfire.002
2008-04-19 11:27 . 2008-04-19 11:28 275 --a------ C:\lxcjfire.001
2008-04-19 11:27 . 2008-04-19 11:27 275 --a------ C:\lxcjfire.000
2008-04-19 11:22 . 2008-04-24 12:25 <DIR> d-------- C:\Lexmark
2008-04-17 18:20 . 2008-04-17 18:28 31,232 --a------ C:\proposedamendment(2).doc
2008-04-17 18:18 . 2008-04-17 18:18 23,552 --a------ C:\Proxy.doc
2008-04-17 18:18 . 2008-04-17 18:19 6,709 --a------ C:\proposedamendment.doc.part
2008-04-17 18:18 . 2008-04-17 18:18 0 --a------ C:\proposedamendment.doc
2008-04-17 18:15 . 2008-04-17 18:15 6,184 --a------ C:\Pheasant
2008-04-17 15:42 . 2008-04-27 23:07 8,704 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-15 09:45 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-15 09:45 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-08 20:50 . 2008-04-08 20:50 <DIR> d-------- D:\Profiles\All Users\Application Data\Office Genuine Advantage
2008-03-30 00:10 . 2008-03-30 00:10 732 --a------ C:\about_inc.php
2008-03-29 23:02 . 2008-03-29 23:02 <DIR> d-------- D:\Profiles\All Users\Application Data\FLEXnet
2008-03-29 22:01 . 2008-03-29 22:01 <DIR> d-------- D:\Profiles\NetworkService\Application Data\Juniper Networks
2008-03-29 02:02 . 2008-04-15 20:22 <DIR> d-------- C:\desktop
2008-03-26 22:11 . 2008-03-26 22:11 <DIR> d-------- D:\Profiles\sdm.MGI2890-02\Application Data\Juniper Networks
2008-03-18 22:54 . 2008-03-18 22:54 <DIR> d-------- D:\Profiles\MGI2890\Application Data\dvdcss
2008-03-15 21:43 . 2008-03-15 21:43 <DIR> d-------- C:\Program Files\WS_FTP
2008-03-14 23:56 . 2008-03-14 23:56 <DIR> d-------- D:\Profiles\MGI2890\Application Data\ZoomBrowser EX
2008-03-10 13:41 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-03-10 13:41 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-03-10 13:41 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-03-10 13:41 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-03-10 13:38 . 2008-03-10 13:38 <DIR> d-------- C:\Program Files\Common Files\Canon
2008-03-04 15:10 . 2008-03-04 15:10 754 --a------ C:\WINDOWS\WORDPAD.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-30 01:31 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-29 00:53 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-28 19:18 --------- d-----w C:\Program Files\Elaborate Bytes
2008-04-28 18:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 18:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 18:09 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-28 18:07 --------- d-----w C:\Program Files\Azureus
2008-04-28 18:05 --------- d-----w D:\Profiles\MGI2890\Application Data\Amazon
2008-04-28 18:05 --------- d-----w C:\Program Files\Amazon
2008-04-28 02:41 --------- d-----w D:\Profiles\All Users\Application Data\Lavasoft
2008-04-23 19:11 --------- d-----w D:\Profiles\MGI2890\Application Data\AdobeUM
2008-04-08 21:31 --------- d-----w D:\Profiles\MGI2890\Application Data\Vso
2008-03-28 19:08 --------- d-----w C:\Program Files\SlySoft
2008-03-22 01:14 --------- d-----w C:\Program Files\MSECache
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-18 19:46 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-03-08 02:09 --------- d-----w D:\Profiles\MGI2890\Application Data\Apple Computer
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-04 22:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2008-02-01 07:21 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2008-01-06 04:07 47,360 ----a-w D:\Profiles\MGI2890\Application Data\pcouffin.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\Windows\system32\drivers\disdn ----



((((((((((((((((((((((((((((( snapshot@2008-04-28_ 0.37.27.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-28 04:29:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-30 01:26:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-02-27 19:59:28 290,816 ----a-w C:\WINDOWS\Downloaded Program Files\auc_lib.dll
+ 2008-02-27 19:59:28 495,616 ----a-w C:\WINDOWS\Downloaded Program Files\daas_s.dll
+ 2008-02-27 20:00:12 262,144 ----a-w C:\WINDOWS\Downloaded Program Files\fscax.dll
+ 2008-02-27 19:59:16 588,392 ----a-w C:\WINDOWS\Downloaded Program Files\gatelauncher.exe
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-28 04:50:45 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:46 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-28 04:50:43 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:43 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-28 19:10:12 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-26 20:41:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-28 19:10:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-21 04:29:56 1,516,240 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-28 19:42:36 1,515,504 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-04-30 01:31:36 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_980.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{749F8452-7D28-4658-A903-9B047E5A2CE8}"= "C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll" [2006-06-08 04:20 2420736]

[HKEY_CLASSES_ROOT\clsid\{749f8452-7d28-4658-a903-9b047e5a2ce8}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{37686C62-D497-42E3-BAAB-78D89A74E151}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DBISQL9"="" []
"SybaseCentral43"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 14:39 1289000]
"URLy Warning"="C:\Program Files\URLy Warning\URLyWarning.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 02:56 52896]
"CSCAdvantage"="C:\Program Files\Help Desk\CSCAdv.exe" [2005-06-09 13:41 111403]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 10:11 1388544]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 13:41 860160]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 22:05 344064]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 14:24 290816]
"AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 15:12 88209 C:\WINDOWS\AGRSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"CSCLogonInfo"="C:\WINDOWS\UsrLogon.exe" [2006-12-12 17:28 127079]
"SupportSoft_Amer_Motorola"="C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" [2006-07-12 17:00 192512]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SDFix"="C:\SDFix\RunThis.bat /second" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-02-01 18:31 3900776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
"LogonType"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoAutoTrayNotify"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-1086857\Scripts\Logon\0\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\0\0]
"Script"=wireless-qualification.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\1\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Netmeeting\\conf.exe"= C:\\Program Files\\Netmeeting\\conf.exe
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"113:TCP"= 113:TCP:10.176.1.190/199:enabled:bDNA
"497:TCP"= 497:TCP:10.0.38.5/10:enabled:bDNA2
"6000:TCP"= 6000:TCP:exceed
"135:TCP"= 135:TCP:10.160.5.8:enabled:foundscan
"137:TCP"= 137:TCP:10.197.24.2:enabled:foundscan2
"138:TCP"= 138:TCP:10.0.125.17:enabled:foundscan3
"139:TCP"= 139:TCP:10.0.125.20:enabled:foundscan4
"1503:TCP"= 1503:TCP:10.0.125.21:enabled:foundscan5
"1720:TCP"= 1720:TCP:10.1.250.11:enabled:foundscan6
"1761:TCP"= 1761:TCP:10.64.2.96:enabled:foundscan7
"2701:TCP"= 2701:TCP:10.128.132.49:enabled:iss1
"2702:TCP"= 2702:TCP:10.128.132.49:enabled:iss2
"43189:TCP"= 43189:TCP:10.160.9.87:enabled:iss3
"4445:TCP"= 4445:TCP:10.0.125.19:enabled:iss4
"6401:TCP"= 6401:TCP:192.168.30.7:enabled:iss5
"1023:UDP"= 1023:UDP:144.190.1.100:enabled:iss6
"445:TCP"= 445:TCP:10.0.125.15:enabled:nmap
"123:UDP"= 123:UDP:129.188.57.239:enabled:scanner1
"137:UDP"= 137:UDP:129.188.147.55:enabled:scanner2
"138:UDP"= 138:UDP:192.168.3.1:enabled:scanner3
"2233:UDP"= 2233:UDP:129.188.33.18:enabled:scanner4
"371:UDP"= 371:UDP:10.0.125.13:enabled:scanner5
"407:UDP"= 407:UDP:10.0.125.28:enabled:scanner6
"497:UDP"= 497:UDP:10.193.21.54:enabled:scanner7
"500:UDP"= 500:UDP:10.0.125.11:enabled:scanner8
"600:UDP"= 600:UDP:10.79.40.64:enabled:scanner9
"601:UDP"= 601:UDP:10.79.40.64:enabled:scanner10
"602:UDP"= 602:UDP:10.79.40.64:enabled:scanner11
"603:UDP"= 603:UDP:10.79.40.64:enabled:scanner12
"604:UDP"= 604:UDP:10.79.40.64:enabled:scanner13
"605:UDP"= 605:UDP:10.79.40.64:enabled:scanner14
"606:UDP"= 606:UDP:10.79.40.64:enabled:scanner15
"607:UDP"= 607:UDP:10.79.40.64:enabled:scanner16
"608:UDP"= 608:UDP:10.79.40.64:enabled:scanner17
"609:UDP"= 609:UDP:10.79.40.64:enabled:scanner18
"610:UDP"= 610:UDP:10.79.40.64:enabled:scanner19
"62514:UDP"= 62514:UDP:10.79.40.72,10.82.51.100,10.228.96.22/24,10.228.96.26,10.16.225.208,10.17.193.181,10.17.193.182:enabled:scanner20
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 1 (0x1)

R0 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-07-29 14:34]
R1 WrqDft;WrqDft;C:\WINDOWS\system32\drivers\WrqDft.sys [2002-07-29 09:50]
R1 WrqSDL;WrqSDL;C:\WINDOWS\system32\drivers\WrqSDL.sys [2002-07-29 09:50]
R2 ApacheForSDM;ApacheForSDM;"C:\AdventNet\WebNMS\apache\bin\Apache.exe" -k runservice []
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2007-04-13 03:50]
R2 sprtsvc_supportsoft_amer_motorola;SupportSoft Sprocket Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe [2006-07-12 17:01]
R2 tgsrvc_supportsoft_amer_motorola;SupportSoft Repair Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe [2006-07-12 17:01]
R2 VPatch;ISS Buffer Overflow Exploit Prevention;"C:\Program Files\ISS\Proventia Desktop\vpatch.exe" [2007-10-29 13:44]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2007-10-03 13:48]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 12:46]
R3 MakoNT;MakoNT;C:\WINDOWS\system32\drivers\isskboep.sys [2007-06-15 19:56]
R3 rap;rap;C:\WINDOWS\system32\drivers\RapDrv.sys [2007-10-29 13:44]
R4 black;black;C:\WINDOWS\system32\drivers\BlackCat.sys [2007-06-15 19:56]
S3 ASANYs_WebNmsDB;Adaptive Server Anywhere - WebNmsDB;C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [2005-02-25 11:27]
S3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys []
S3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2007-04-13 03:50]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C10BF3A1-3FEC-4a94-AAAF-9D6A4B522F63}]
"C:\Program Files\WinZip\wzusr90.exe" /NOICON /NOTRAY
.
Contents of the 'Scheduled Tasks' folder
"2008-04-30 01:29:15 C:\WINDOWS\Tasks\CheckNetwork.job"
- C:\Program Files\Motorola\WirelessControl\NetStatus.vbs
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-30 10:22:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-04-30 10:23:47
ComboFix-quarantined-files.txt 2008-04-30 14:23:39
ComboFix2.txt 2008-04-30 01:36:53
ComboFix3.txt 2008-04-29 00:06:54
ComboFix4.txt 2008-04-28 23:48:12
ComboFix5.txt 2008-04-28 21:44:35

Pre-Run: 7,788,036,096 bytes free
Post-Run: 7,773,122,560 bytes free

274


--------------------------------------

Malwarebytes' Anti-Malware 1.11
Database version: 704

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 110094
Time elapsed: 45 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

my5sons
2008-05-01, 06:24
I still can't enable the Wireless Zero Configuration...

"Could not enable Wireless Zero Configuration Service on Local Computer.

Error 1068: The dependency service or group failed to start."

Also, everytime I right-click anything on my Computer, Symantec Antivirus begins to run and tries installing something from my work server. When it doesn't find it, it asks me to install it using browse. I've never seen this before????? I'm thinking the Symantec\VPTray that you see in Dr. Web that was deleted was probably something I needed :( :(


Here is my Hijack This Log...


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:19, on 2008-05-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\AdventNet\WebNMS\apache\bin\Apache.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
C:\Program Files\ISS\Proventia Desktop\vpatch.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.mot.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.mot.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.mot.com:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.mot.com;*.gi.com;<local>
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll (file missing)
O3 - Toolbar: RSAToolbar - {749F8452-7D28-4658-A903-9B047E5A2CE8} - C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CSCAdvantage] "C:\Program Files\Help Desk\CSCAdv.exe" /s
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CSCLogonInfo] C:\WINDOWS\UsrLogon.exe
O4 - HKLM\..\Run: [SupportSoft_Amer_Motorola] "C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" /P SupportSoft_Amer_Motorola
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [URLy Warning] "C:\Program Files\URLy Warning\URLyWarning.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-863651691-3918403040-59684098-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'sdm')
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://access.motorola.com/dana-cached/setup/JuniperSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\Software\..\Telephony: DomainName = ds.mot.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = am.mot.com,e1.bcs.mot.com,gic.gi.com,w1.bcs.mot.com,gi.com,corp.mot.com,ds.mot.com,mot.com,sps.mot.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = am.mot.com,e1.bcs.mot.com,gic.gi.com,w1.bcs.mot.com,gi.com,corp.mot.com,ds.mot.com,mot.com,sps.mot.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = am.mot.com,e1.bcs.mot.com,gic.gi.com,w1.bcs.mot.com,gi.com,corp.mot.com,ds.mot.com,mot.com,sps.mot.com
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ApacheForSDM - Apache Software Foundation - C:\AdventNet\WebNMS\apache\bin\Apache.exe
O23 - Service: Adaptive Server Anywhere - WebNmsDB (ASANYs_WebNmsDB) - iAnywhere Solutions, Inc. - C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\blackd.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\RapApp.exe
O23 - Service: Reflection Line Printer Daemon - WRQ, Inc. - C:\Program Files\Reflection\lpdserv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Motorola SDM (SDM Service) - Unknown owner - C:\WINDOWS\JavaService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SupportSoft Sprocket Service (supportsoft_amer_motorola) (sprtsvc_supportsoft_amer_motorola) - SupportSoft, Inc. - C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SupportSoft Repair Service (supportsoft_amer_motorola) (tgsrvc_supportsoft_amer_motorola) - SupportSoft, Inc. - C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
O23 - Service: ISS Buffer Overflow Exploit Prevention (VPatch) - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\vpatch.exe

--
End of file - 11585 bytes

Rorschach112
2008-05-01, 13:54
You will need to reinstall Symantec. One of the files was infected with Bagle so it had to be killed

Can you reinstall your wireless ? That should fix it


1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:


KillAll::

File::
C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE

Folder::
C:\Windows\system32\drivers\disdn

Registry::

Driver::
gusvc


Save this as CFScript.txt, in the same location as ComboFix.exe


http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



Also post a new HijackThis log and tell me how your PC is running

my5sons
2008-05-02, 04:00
I was able to fix the Wireless Zero Configuration problem by doing this...

So, I went to
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio
and checked that the "Start" Value is set to 1, 2 or 3. I found out it was disabled (it was set to 4). (I set it to 1).

And this solved my problem, after a System Restart the Wireless Zero Config Service can be readily started.

Unfortunately disdn folder is still there. I don't know what is using it, but it won't allow me to delete it. Even running ComboFix like you had with CFScript.txt.

ComboFix 08-04-27.3 - mgi2890 2008-05-01 21:35:57.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.547 [GMT -4:00]
Running from: D:\Profiles\MGI2890\Desktop\Combo-Fix.exe
Command switches used :: D:\Profiles\MGI2890\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE
C:\PROGRAM FILES\SYMANTEC ANTIVIRUS\VPTRAY.EXE
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
D:\Profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Windows\system32\drivers\disdn . . . . failed to delete

----- BITS: Possible infected sites -----

hxxp://PA06EDM01
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gusvc


((((((((((((((((((((((((( Files Created from 2008-04-02 to 2008-05-02 )))))))))))))))))))))))))))))))
.

2008-04-30 23:24 . 2008-04-30 23:24 <DIR> d-------- D:\Profiles\MGI2890\Application Data\Malwarebytes
2008-04-30 23:24 . 2008-04-30 23:24 <DIR> d-------- D:\Profiles\All Users\Application Data\Malwarebytes
2008-04-30 23:24 . 2008-04-30 23:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-30 23:23 . 2008-04-30 23:23 128,368 --a------ C:\Download_mbam-setup.exe
2008-04-30 13:19 . 2008-04-30 13:19 1,596,094 --a------ C:\mbam-setup.exe
2008-04-29 21:48 . 2008-04-30 00:14 <DIR> d-------- D:\Profiles\MGI2890\DoctorWeb
2008-04-29 21:41 . 2008-04-29 21:45 10,258,232 --a------ C:\drweb-cureit.exe
2008-04-29 14:10 . 2008-04-29 14:10 <DIR> d-------- C:\fsaua.data
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- D:\Profiles\All Users\Application Data\Kaspersky Lab
2008-04-28 16:56 . 2008-04-28 16:56 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 15:24 . 2008-04-28 15:37 <DIR> d-------- D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2008-04-28 15:24 . 2008-04-28 15:24 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-28 15:23 . 2008-04-28 15:23 9,722,720 --a------ C:\spybotsd152.exe
2008-04-28 14:09 . 2008-04-28 15:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-28 01:32 . 2008-04-28 01:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-28 01:32 . 2008-04-28 01:32 812,344 --a------ C:\HJTInstall.exe
2008-04-28 00:50 . 2008-04-28 00:50 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-28 00:45 . 2008-04-27 20:49 <DIR> d-------- C:\SDFix
2008-04-27 23:32 . 2008-04-27 23:32 650,296 --a------ C:\PREVXCSIFREE(2).EXE
2008-04-27 23:12 . 2008-04-27 23:17 2,205,157 --a------ C:\IceSword122en.zip
2008-04-27 23:01 . 2008-04-27 23:01 650,296 --a------ C:\PREVXCSIFREE.EXE
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-27 22:41 . 2008-04-27 22:41 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-27 22:39 . 2008-04-27 22:40 20,597,104 --a------ C:\aaw2007.exe
2008-04-25 22:05 . 2008-04-25 22:05 93,775 --a------ C:\2333.zip
2008-04-19 11:27 . 2008-04-19 11:27 <DIR> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-04-19 11:27 . 2008-04-24 12:21 275 --a------ C:\lxcjfire.csv
2008-04-19 11:27 . 2008-04-24 12:12 275 --a------ C:\lxcjfire.008
2008-04-19 11:27 . 2008-04-24 12:11 275 --a------ C:\lxcjfire.007
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.006
2008-04-19 11:27 . 2008-04-24 12:07 275 --a------ C:\lxcjfire.005
2008-04-19 11:27 . 2008-04-19 11:43 275 --a------ C:\lxcjfire.004
2008-04-19 11:27 . 2008-04-19 11:41 275 --a------ C:\lxcjfire.003
2008-04-19 11:27 . 2008-04-19 11:38 275 --a------ C:\lxcjfire.002
2008-04-19 11:27 . 2008-04-19 11:28 275 --a------ C:\lxcjfire.001
2008-04-19 11:27 . 2008-04-19 11:27 275 --a------ C:\lxcjfire.000
2008-04-19 11:22 . 2008-04-24 12:25 <DIR> d-------- C:\Lexmark
2008-04-17 18:20 . 2008-04-17 18:28 31,232 --a------ C:\proposedamendment(2).doc
2008-04-17 18:18 . 2008-04-17 18:18 23,552 --a------ C:\Proxy.doc
2008-04-17 18:18 . 2008-04-17 18:19 6,709 --a------ C:\proposedamendment.doc.part
2008-04-17 18:18 . 2008-04-17 18:18 0 --a------ C:\proposedamendment.doc
2008-04-17 18:15 . 2008-04-17 18:15 6,184 --a------ C:\Pheasant
2008-04-17 15:42 . 2008-04-27 23:07 8,704 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-15 09:45 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-15 09:45 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-15 09:45 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-08 20:50 . 2008-04-08 20:50 <DIR> d-------- D:\Profiles\All Users\Application Data\Office Genuine Advantage

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-02 01:44 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-29 00:53 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-28 19:18 --------- d-----w C:\Program Files\Elaborate Bytes
2008-04-28 18:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 18:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 18:09 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-28 18:07 --------- d-----w C:\Program Files\Azureus
2008-04-28 18:05 --------- d-----w D:\Profiles\MGI2890\Application Data\Amazon
2008-04-28 18:05 --------- d-----w C:\Program Files\Amazon
2008-04-28 02:41 --------- d-----w D:\Profiles\All Users\Application Data\Lavasoft
2008-04-23 19:11 --------- d-----w D:\Profiles\MGI2890\Application Data\AdobeUM
2008-04-08 21:31 --------- d-----w D:\Profiles\MGI2890\Application Data\Vso
2008-03-30 03:02 --------- d-----w D:\Profiles\All Users\Application Data\FLEXnet
2008-03-30 02:01 --------- d-----w D:\Profiles\NetworkService\Application Data\Juniper Networks
2008-03-28 19:08 --------- d-----w C:\Program Files\SlySoft
2008-03-27 02:11 --------- d-----w D:\Profiles\sdm.MGI2890-02\Application Data\Juniper Networks
2008-03-22 01:14 --------- d-----w C:\Program Files\MSECache
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 02:54 --------- d-----w D:\Profiles\MGI2890\Application Data\dvdcss
2008-03-18 19:46 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-03-16 01:43 --------- d-----w C:\Program Files\WS_FTP
2008-03-15 03:56 --------- d-----w D:\Profiles\MGI2890\Application Data\ZoomBrowser EX
2008-03-10 17:38 --------- d-----w C:\Program Files\Common Files\Canon
2008-03-08 02:09 --------- d-----w D:\Profiles\MGI2890\Application Data\Apple Computer
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-04 22:23 693,792 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
2008-01-06 04:07 47,360 ----a-w D:\Profiles\MGI2890\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2008-04-28_ 0.37.27.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-28 04:29:32 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-02 01:41:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-02-27 19:59:28 290,816 ----a-w C:\WINDOWS\Downloaded Program Files\auc_lib.dll
+ 2008-02-27 19:59:28 495,616 ----a-w C:\WINDOWS\Downloaded Program Files\daas_s.dll
+ 2008-02-27 20:00:12 262,144 ----a-w C:\WINDOWS\Downloaded Program Files\fscax.dll
+ 2008-02-27 19:59:16 588,392 ----a-w C:\WINDOWS\Downloaded Program Files\gatelauncher.exe
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-28 04:50:45 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:46 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-04-28 00:47:55 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-28 04:50:43 5,140,480 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2008-04-28 04:50:43 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2004-12-08 15:10:00 10,963 ----a-w C:\WINDOWS\system32\CCM\Cache\00N0008C.2.System\LoadPkg.vbs
+ 2005-03-24 17:29:48 384,923 ----a-w C:\WINDOWS\system32\CCM\Cache\00N0008C.2.System\runpack.exe
+ 2006-02-13 18:15:12 323,584 ----a-w C:\WINDOWS\system32\CCM\Cache\00N0008C.2.System\Source\WSUSAudit.exe
+ 2006-02-13 21:57:19 123,058 ----a-w C:\WINDOWS\system32\CCM\Cache\00N0008C.2.System\WUSvcFix.EXE
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-30 19:09:33 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-26 20:41:47 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-30 19:09:33 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-26 20:41:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-30 19:09:33 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-21 04:29:56 1,516,240 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-04-28 19:42:36 1,515,504 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-05-02 01:46:53 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_9e4.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{749F8452-7D28-4658-A903-9B047E5A2CE8}"= "C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll" [2006-06-08 04:20 2420736]

[HKEY_CLASSES_ROOT\clsid\{749f8452-7d28-4658-a903-9b047e5a2ce8}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{37686C62-D497-42E3-BAAB-78D89A74E151}]
[HKEY_CLASSES_ROOT\RSAToolbar.RSAToolbarBand]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DBISQL9"="" []
"SybaseCentral43"="" []
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 14:39 1289000]
"URLy Warning"="C:\Program Files\URLy Warning\URLyWarning.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 02:56 52896]
"CSCAdvantage"="C:\Program Files\Help Desk\CSCAdv.exe" [2005-06-09 13:41 111403]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 10:11 1388544]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 13:41 860160]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 22:05 344064]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 14:24 290816]
"AGRSMMSG"="AGRSMMSG.exe" [2005-11-16 15:12 88209 C:\WINDOWS\AGRSMMSG.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38 688218]
"CSCLogonInfo"="C:\WINDOWS\UsrLogon.exe" [2006-12-12 17:28 127079]
"SupportSoft_Amer_Motorola"="C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" [2006-07-12 17:00 192512]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SDFix"="C:\SDFix\RunThis.bat /second" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-02-01 18:31 3900776]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
"LogonType"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
"GreyMSIAds"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoAutoTrayNotify"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-1086857\Scripts\Logon\0\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\0\0]
"Script"=wireless-qualification.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2052111302-287218729-725345543-980161\Scripts\Logon\1\0]
"Script"=w2kenroll.cmd

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Netmeeting\\conf.exe"= C:\\Program Files\\Netmeeting\\conf.exe
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"113:TCP"= 113:TCP:10.176.1.190/199:enabled:bDNA
"497:TCP"= 497:TCP:10.0.38.5/10:enabled:bDNA2
"6000:TCP"= 6000:TCP:exceed
"135:TCP"= 135:TCP:10.160.5.8:enabled:foundscan
"137:TCP"= 137:TCP:10.197.24.2:enabled:foundscan2
"138:TCP"= 138:TCP:10.0.125.17:enabled:foundscan3
"139:TCP"= 139:TCP:10.0.125.20:enabled:foundscan4
"1503:TCP"= 1503:TCP:10.0.125.21:enabled:foundscan5
"1720:TCP"= 1720:TCP:10.1.250.11:enabled:foundscan6
"1761:TCP"= 1761:TCP:10.64.2.96:enabled:foundscan7
"2701:TCP"= 2701:TCP:10.128.132.49:enabled:iss1
"2702:TCP"= 2702:TCP:10.128.132.49:enabled:iss2
"43189:TCP"= 43189:TCP:10.160.9.87:enabled:iss3
"4445:TCP"= 4445:TCP:10.0.125.19:enabled:iss4
"6401:TCP"= 6401:TCP:192.168.30.7:enabled:iss5
"1023:UDP"= 1023:UDP:144.190.1.100:enabled:iss6
"445:TCP"= 445:TCP:10.0.125.15:enabled:nmap
"123:UDP"= 123:UDP:129.188.57.239:enabled:scanner1
"137:UDP"= 137:UDP:129.188.147.55:enabled:scanner2
"138:UDP"= 138:UDP:192.168.3.1:enabled:scanner3
"2233:UDP"= 2233:UDP:129.188.33.18:enabled:scanner4
"371:UDP"= 371:UDP:10.0.125.13:enabled:scanner5
"407:UDP"= 407:UDP:10.0.125.28:enabled:scanner6
"497:UDP"= 497:UDP:10.193.21.54:enabled:scanner7
"500:UDP"= 500:UDP:10.0.125.11:enabled:scanner8
"600:UDP"= 600:UDP:10.79.40.64:enabled:scanner9
"601:UDP"= 601:UDP:10.79.40.64:enabled:scanner10
"602:UDP"= 602:UDP:10.79.40.64:enabled:scanner11
"603:UDP"= 603:UDP:10.79.40.64:enabled:scanner12
"604:UDP"= 604:UDP:10.79.40.64:enabled:scanner13
"605:UDP"= 605:UDP:10.79.40.64:enabled:scanner14
"606:UDP"= 606:UDP:10.79.40.64:enabled:scanner15
"607:UDP"= 607:UDP:10.79.40.64:enabled:scanner16
"608:UDP"= 608:UDP:10.79.40.64:enabled:scanner17
"609:UDP"= 609:UDP:10.79.40.64:enabled:scanner18
"610:UDP"= 610:UDP:10.79.40.64:enabled:scanner19
"62514:UDP"= 62514:UDP:10.79.40.72,10.82.51.100,10.228.96.22/24,10.228.96.26,10.16.225.208,10.17.193.181,10.17.193.182:enabled:scanner20
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 1 (0x1)

R0 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-07-29 14:34]
R1 WrqDft;WrqDft;C:\WINDOWS\system32\drivers\WrqDft.sys [2002-07-29 09:50]
R1 WrqSDL;WrqSDL;C:\WINDOWS\system32\drivers\WrqSDL.sys [2002-07-29 09:50]
R2 ApacheForSDM;ApacheForSDM;"C:\AdventNet\WebNMS\apache\bin\Apache.exe" -k runservice []
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2007-04-13 03:50]
R2 sprtsvc_supportsoft_amer_motorola;SupportSoft Sprocket Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe [2006-07-12 17:01]
R2 tgsrvc_supportsoft_amer_motorola;SupportSoft Repair Service (supportsoft_amer_motorola);C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe [2006-07-12 17:01]
R2 VPatch;ISS Buffer Overflow Exploit Prevention;"C:\Program Files\ISS\Proventia Desktop\vpatch.exe" [2007-10-29 13:44]
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2007-10-03 13:48]
R3 GTIPCI21;GTIPCI21;C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2005-05-31 12:46]
R3 MakoNT;MakoNT;C:\WINDOWS\system32\drivers\isskboep.sys [2007-06-15 19:56]
R3 rap;rap;C:\WINDOWS\system32\drivers\RapDrv.sys [2007-10-29 13:44]
R4 black;black;C:\WINDOWS\system32\drivers\BlackCat.sys [2007-06-15 19:56]
S3 ASANYs_WebNmsDB;Adaptive Server Anywhere - WebNmsDB;C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe [2005-02-25 11:27]
S3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys []
S3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2007-04-13 03:50]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C10BF3A1-3FEC-4a94-AAAF-9D6A4B522F63}]
"C:\Program Files\WinZip\wzusr90.exe" /NOICON /NOTRAY
.
Contents of the 'Scheduled Tasks' folder
"2008-05-02 01:44:22 C:\WINDOWS\Tasks\CheckNetwork.job"
- C:\Program Files\Motorola\WirelessControl\NetStatus.vbs
.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-01 21:45:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\scardsvr.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe
C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-05-01 21:50:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-02 01:49:33
ComboFix2.txt 2008-04-30 14:23:48
ComboFix3.txt 2008-04-30 01:36:53
ComboFix4.txt 2008-04-29 00:06:54
ComboFix5.txt 2008-04-28 23:48:12

Pre-Run: 7,780,278,272 bytes free
Post-Run: 7,765,667,840 bytes free

314

my5sons
2008-05-02, 04:02
I can't login to my computer in Safe Mode anymore. I think I'll have to contact my IT department for this one. My PC appears to be running much better. I think you helped me a great deal! Thanks so much...

One more question...

How do I uninstall SDFix? I keep getting a command window popup saying that SDFix can't find a certain .txt file. I just want to uninstall it.

Thanks.

Rorschach112
2008-05-02, 12:59
Lets see if I can fix Safe Mode

Download and run SafeBootKeyRepair-CF from:

http://download.bleepingcomputer.com/sUBs/SafeBootKeyRepair.exe
or
http://www.techsupportforum.com/sectools/sUBs/SafeBootKeyRepair-CF.exe

It will take only a moment for it to run.
A log will be produced at C:\SafeBoot_Repair.txt. Please post that in your next reply



I can remove SDFix, just need to see a new HijackThis log



As for this folder

C:\Windows\system32\drivers\disdn

That is legitimate


So can I see the Safe Boot Repair log and a new HijackThis log and tell me of any problems you are having

my5sons
2008-05-03, 03:33
Thanks again for helping me with this....

Here is my Safeboot....


Reg export of SafeBoot key after repair:
========================

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\AppMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Base]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Boot file system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\CryptSvc]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\DcomLaunch]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmadmin]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmboot.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmio.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmload.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\dmserver]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\EventLog]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\HelpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Netlogon]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PCI Configuration]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PlugPlay]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PNP Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\Primary disk]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\PSEXESVC]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SCSI Class]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sermouse.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\SRService]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\System Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\WinMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
@="Universal Serial Bus controllers"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
@="CD-ROM Drive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
@="Standard floppy disk controller"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
@="PCMCIA Adapters"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
@="SCSIAdapter"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
@="Floppy disk drive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
@="Human Interface Devices"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AFD]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\AppMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Base]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Boot file system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Browser]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\CryptSvc]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DcomLaunch]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Dhcp]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmadmin]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmboot.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmio.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmload.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\dmserver]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\DnsCache]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\EventLog]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\HelpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ip6fw.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\ipnat.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanServer]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LanmanWorkstation]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\LmHosts]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Messenger]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NDIS Wrapper]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Ndisuio]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOS]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBIOSGroup]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetBT]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetDDEGroup]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Netlogon]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetMan]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Network]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NetworkProvider]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\NtLmSsp]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PCI Configuration]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PlugPlay]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP Filter]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PNP_TDI]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Primary disk]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\PSEXESVC]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpcdd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpdd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdpwd.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\rdsessmgr]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SCSI Class]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sermouse.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SharedAccess]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\sr.sys]
@="FSFilter System Recovery"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\SRService]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Streams Drivers]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\System Bus Extender]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\Tcpip]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\TDI]
@="Driver Group"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdpipe.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\tdtcp.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\termservice]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vga.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\WinMgmt]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
@="Universal Serial Bus controllers"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
@="CD-ROM Drive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
@="Standard floppy disk controller"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
@="Net"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
@="NetClient"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
@="NetService"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
@="NetTrans"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
@="PCMCIA Adapters"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
@="SCSIAdapter"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
@="Floppy disk drive"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
@="Human Interface Devices"

========================

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\PSEXESVC


----------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:32, on 2008-05-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\ISS\Proventia Desktop\blackd.exe
C:\AdventNet\WebNMS\apache\bin\Apache.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\ISS\Proventia Desktop\RapApp.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
C:\Program Files\ISS\Proventia Desktop\vpatch.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ISS\Proventia Desktop\RapUISvc.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.mot.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.mot.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.mot.com:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.mot.com;*.gi.com;<local>
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll (file missing)
O3 - Toolbar: RSAToolbar - {749F8452-7D28-4658-A903-9B047E5A2CE8} - C:\Program Files\RSA Security\IE Toolbar\RSAToolbar.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CSCAdvantage] "C:\Program Files\Help Desk\CSCAdv.exe" /s
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CSCLogonInfo] C:\WINDOWS\UsrLogon.exe
O4 - HKLM\..\Run: [SupportSoft_Amer_Motorola] "C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtcmd.exe" /P SupportSoft_Amer_Motorola
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [URLy Warning] "C:\Program Files\URLy Warning\URLyWarning.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-863651691-3918403040-59684098-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'sdm')
O4 - HKUS\S-1-5-18\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://access.motorola.com/dana-cached/setup/JuniperSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\Software\..\Telephony: DomainName = ds.mot.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = am.mot.com,e1.bcs.mot.com,gic.gi.com,w1.bcs.mot.com,gi.com,corp.mot.com,ds.mot.com,mot.com,sps.mot.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = ds.mot.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = am.mot.com,e1.bcs.mot.com,gic.gi.com,w1.bcs.mot.com,gi.com,corp.mot.com,ds.mot.com,mot.com,sps.mot.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = am.mot.com,e1.bcs.mot.com,gic.gi.com,w1.bcs.mot.com,gi.com,corp.mot.com,ds.mot.com,mot.com,sps.mot.com
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ApacheForSDM - Apache Software Foundation - C:\AdventNet\WebNMS\apache\bin\Apache.exe
O23 - Service: Adaptive Server Anywhere - WebNmsDB (ASANYs_WebNmsDB) - iAnywhere Solutions, Inc. - C:\Sybase\SQL Anywhere 9\win32\dbsrv9.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\blackd.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\RapApp.exe
O23 - Service: Reflection Line Printer Daemon - WRQ, Inc. - C:\Program Files\Reflection\lpdserv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Motorola SDM (SDM Service) - Unknown owner - C:\WINDOWS\JavaService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SupportSoft Sprocket Service (supportsoft_amer_motorola) (sprtsvc_supportsoft_amer_motorola) - SupportSoft, Inc. - C:\Program Files\SupportSoft_Amer_Motorola\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SupportSoft Repair Service (supportsoft_amer_motorola) (tgsrvc_supportsoft_amer_motorola) - SupportSoft, Inc. - C:\Program Files\SupportSoft_Amer_Motorola\bin\tgsrvc.exe
O23 - Service: ISS Buffer Overflow Exploit Prevention (VPatch) - Internet Security Systems, Inc. - C:\Program Files\ISS\Proventia Desktop\vpatch.exe

--
End of file - 11535 bytes

Rorschach112
2008-05-03, 12:39
Fix this entry in HijackThis

O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second


Then delete the folder C:\SDFix if it is there


Then tell me how your PC is running

Rorschach112
2008-05-08, 03:03
Due to inactivity, this thread will now be closed.

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

tashi
2008-05-19, 19:54
I think I'll have to contact my IT department for this one. My PC appears to be running much better.

FYI:
Personal computers or..... (http://forums.spybot.info/showpost.php?p=25712&postcount=5)