PDA

View Full Version : Please kindly instruct on fixing the continous infection.



Anara
2008-05-14, 07:49
Spybot is unable to fix for a long time after updating.

--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
--------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 13, 2008 1:57:58 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 13/05/2008
Kaspersky Anti-Virus database records: 768228
--------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 128104
Number of viruses found: 6
Number of infected objects: 24
Number of suspicious objects: 0
Duration of the scan process: 02:21:34

Infected Object Name / Virus Name / Last Action
C:\78bf0341dfe7409fff\update\update.exe Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\otmjcpkf\ynqzahyh.exe.bak Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\Config\interchk.chk Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\logs\SAV.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip/utakaofm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qor skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip/badjhjjg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qor skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll12.zip/byXPIbxX.dll_old Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll12.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip/mlJcCspQ.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll5.zip/mlJcCspQ.dll_old Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll6.zip/ljJaywWM.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll9.zip/byXPIbxX.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\call256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\callmember256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chat1024.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chat2048.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chat256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chat4096.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chat512.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chat8192.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chatmember256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chatmsg1024.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chatmsg16384.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chatmsg2048.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chatmsg256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chatmsg4096.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chatmsg512.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\chatmsg8192.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\contactgroup1024.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\index2.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\profile4096.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\sms1024.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\sms256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\sms512.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\transfer1024.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\transfer256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\transfer512.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\user1024.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\user16384.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\user256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\user32768.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\user4096.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype\anarkotik_kz\voicemail256.dbb Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\History\History.IE5\MSHist012008051320080514\index.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\analog and other stuff~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Buck Hollywood - I had to have it!~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\CBC ~p Top Stories News~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\eBay Canada General Announcements~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Europe and Central Asia World Bank~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Facebook~dcom~\Anara Zh's Friends' Facebook Notes~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Facebook~dcom~\Anara Zh's Friends' Facebook Posts~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Facebook~dcom~\Anara Zh's Friends' Facebook Status Updates~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Facebook~dcom~\Facebook~d Anara Zh's Notifications~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Facebook~dcom~\Facebook~d What's New~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\FeedsStore.feedsdb-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\FreeExchange~dRU~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\FreeTorrent~dru~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\IMDb News~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\International Herald Tribune - World News, Analysis, and Global Opinions~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\KVN links~\Видео КВН~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\KVN links~\КВН для ВСЕХ~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\KVN links~\Новинки КВН~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Microsoft Office Online Canada~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\MIT OpenCourseWare~c New Courses in Economics~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Most Viewed~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\MyOttawa~dRU~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Off the Rack - StyleWatch - People~dcom~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Official Gmail Blog~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds\Olympus America Consumer Electronics~.feed-ms Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF100A.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF107D.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1094.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1107.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1115.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1188.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF119F.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1A3B.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1A49.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1AC5.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1AD3.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1B4F.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF1B66.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF324F.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF325D.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF330E.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF331C.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF33AD.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF33BB.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF3439.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF3502.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF3577.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF358E.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF3AFF.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF3B0E.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF8CB.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF910.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF9EE.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DF9FC.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFA81.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFA98.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFAC62.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFAD39.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFB14.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFB22.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFB95.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFBAC.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFC1F.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFC2D.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFCA0.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFCB7.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFD33.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFD4A.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFDBD.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFDCB.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFE47.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFE5A.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFECD.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFEE4.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFF60.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFF80.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Local Settings\Temp\~DFFFC.tmp Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Temporary Internet Files\Content.IE5\2BT3A698\68_180_219_135[1] Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Anara Zhiyenbekova\Temporary Internet Files\Content.IE5\K0E6XL2M\68_180_219_128[1] Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe/data0004 Infected: not-a-virus:AdWare.Win32.Agent.aeh skipped
C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vtUlKCsS.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\SDFix\backups\backups.zip/backups/dpevflbg.dll Infected: Trojan.Win32.Vapsup.ekr skipped
C:\SDFix\backups\backups.zip/backups/olgdqarf.exe Infected: Trojan.Win32.Vapsup.ekr skipped
C:\SDFix\backups\backups.zip/backups/vadokmxt.dll Infected: Trojan.Win32.Vapsup.ekr skipped
C:\SDFix\backups\backups.zip/backups/wdpoefan.dll Infected: Trojan.Win32.Vapsup.ekr skipped
C:\SDFix\backups\backups.zip/backups/wxvgsdbq.exe Infected: Trojan.Win32.Vapsup.ekr skipped
C:\SDFix\backups\backups.zip ZIP: infected - 5 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP58\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\pfirewall.log Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{65434333-06DC-4666-8ECC-AA0A02377264}.crmlog Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\Windows_OneCare_Evt.evt Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\W3SVC1\ex080513.log Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\msmq\storage\QMLog Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\Perflib_Perfdata_8d8.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP58\change.log Object is locked skipped

Scan process completed.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:51:52 PM, on 5/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MimarSinan Rubber Ducky\RubberDucky.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\PRMT8\PRMTED\EDLauncher.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\PRMT8\PRMTED\prmedsvr.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8FAA95CB-EC60-4996-BB6B-6D0E4545C9C8} - C:\WINDOWS\system32\mlJcCspQ.dll (file missing)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {C4999B47-3FD3-4EF1-8A7F-A46CE75D79AD} - C:\WINDOWS\system32\wvUlIXQI.dll (file missing)
O2 - BHO: (no name) - {C733BC2E-B26F-48DF-AEB7-6D5111C0A000} - C:\WINDOWS\system32\byXPIbxX.dll (file missing)
O2 - BHO: (no name) - {E439B6B9-46AA-4FD3-8705-237436B12F99} - C:\WINDOWS\system32\ljJaywWM.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [21766322] rundll32.exe "C:\WINDOWS\system32\badjhjjg.dll",b
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP-Diags] C:\DOCUME~1\ANARAZ~1\LOCALS~1\Temp\HPISPz\hpdom\hpdiags.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autoclose
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MimarSinan Rubber Ducky] "C:\Program Files\MimarSinan Rubber Ducky\RubberDucky.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [zbnewpvb] C:\WINDOWS\system32\kxofafcz.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EDLauncher] C:\Program Files\PRMT8\PRMTED\EDLauncher.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: utorrent.lnk = C:\Program Files\uTorrent\utorrent.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqnbk2/downloads/sysinfo.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F519B46-96EF-499F-BF24-C9E1548FA56B} (Sony SNC-DF70 Control) - http://ffcoservery1.webcam.carleton.ca/program/SonySncDf70View.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ANARAZ~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/ANARAZ~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 14628 bytes

pskelley
2008-05-14, 16:02
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

You are infected, I suggest you keep this computer offline except when troubleshooting, the junk may download more. If you have any tool I use, delete it and download it new from the link I provide. Read and follow the directions carefully, the tools will not work unless you do.
This can be a tough infection to remove so do not expect fast or easy.

If you still need help, I will see what I can do. I can see you have used several tool and the quarantines/backups are much of what KOS finds, the exception appears to be from PeoplePC. If you don't use them anymore, I would uninstall them in Add Remove programs, if you still use them, scan the files in red to make sure they are not infected, it may be a false positive from Kaspersky.

C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe <<< file
Online scanner to use: http://virusscan.jotti.org/

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ <<< delete the contents of the folder in redhttp://ict.cas.psu.edu/training/howto/util/removespybot.htm#1

C:\QooBox\Quarantine\ <<< delete the folder (combofix)

C:\SDFix\ <<< delete the folder

Empty the Recycle Bin on the Desktop and restart the computer.


1) Windows Defender: Click on "Tools"
Click on "General Settings"
Scroll down to "Real-time protection options"
Uncheck "Turn on Real-time protection (recommended)"
Click "Save"
Make sure to turn your protection back on when you finish.

2) We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:
* Run Spybot-S&D in Advanced Mode.
* If it is not already set to do this Go to the Mode menu select "Advanced Mode"
* On the left hand side, Click on Tools
* Then click on the Resident Icon in the List
* Uncheck "Resident TeaTimer" and OK any prompts.
* Restart your computer.
(leave TT disabled until we finish)

3) Remove any old copies of combofix before you proceed.

Thanks to sUBs and anyone else who helped with this fix.

It is important that it is saved directly to your Desktop

Download ComboFix from Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop

Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix's window while its running. That may cause it to stall

Post the combofix log and a new HJT log.

Tutorial if needed:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Thanks

Anara
2008-05-19, 16:11
Hello there!!!
Sincere thanks for reviewing my problem.
I have followed thoroughly all your instructions & below are the required logs. I will be waiting for your further commands on trackin out the malware :mad:

1. Combofix

ComboFix 08-05-15.3 - Anara Zhiyenbekova 2008-05-18 20:08:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.470 [GMT -4:00]
Running from: C:\Documents and Settings\Anara Zhiyenbekova\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\akttzn.exe
C:\WINDOWS\system32\anticipator.dll
C:\WINDOWS\system32\awtoolb.dll
C:\WINDOWS\system32\bdn.com
C:\WINDOWS\system32\dpcproxy.exe
C:\WINDOWS\system32\gjjhjdab.ini
C:\WINDOWS\system32\hoproxy.dll
C:\WINDOWS\system32\hxiwlgpm.dat
C:\WINDOWS\system32\hxiwlgpm.exe
C:\WINDOWS\system32\medup012.dll
C:\WINDOWS\system32\mfoakatu.ini
C:\WINDOWS\system32\msgp.exe
C:\WINDOWS\system32\msnbho.dll
C:\WINDOWS\system32\mssecu.exe
C:\WINDOWS\system32\mtr2.exe
C:\WINDOWS\system32\mwin32.exe
C:\WINDOWS\system32\netode.exe
C:\WINDOWS\system32\newsd32.exe
C:\WINDOWS\system32\ps1.exe
C:\WINDOWS\system32\psof1.exe
C:\WINDOWS\system32\psoft1.exe
C:\WINDOWS\system32\regc64.dll
C:\WINDOWS\system32\regm64.dll
C:\WINDOWS\system32\Rundl1.exe
C:\WINDOWS\system32\smp
C:\WINDOWS\system32\smp\msrc.exe
C:\WINDOWS\system32\sncntr.exe
C:\WINDOWS\system32\ssurf022.dll
C:\WINDOWS\system32\ssvchost.com
C:\WINDOWS\system32\ssvchost.exe
C:\WINDOWS\system32\sysreq.exe
C:\WINDOWS\system32\taack.dat
C:\WINDOWS\system32\taack.exe
C:\WINDOWS\system32\temp#01.exe
C:\WINDOWS\system32\thun.dll
C:\WINDOWS\system32\thun32.dll
C:\WINDOWS\system32\VBIEWER.OCX
C:\WINDOWS\system32\vbsys2.dll
C:\WINDOWS\system32\vcatchpi.dll
C:\WINDOWS\system32\winlogonpc.exe
C:\WINDOWS\system32\WINWGPX.EXE

.
((((((((((((((((((((((((( Files Created from 2008-04-19 to 2008-05-19 )))))))))))))))))))))))))))))))
.

2008-05-16 22:58 . 2008-05-16 22:58 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-16 22:58 . 2008-05-16 22:58 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-15 23:36 . 2008-05-15 23:36 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\CyberLink
2008-05-14 01:54 . 2008-05-14 01:55 <DIR> d-------- C:\Program Files\SureThing CD Labeler 5
2008-05-14 01:32 . 2008-05-14 01:32 <DIR> d-------- C:\Program Files\LightScribe Diagnostic Utility
2008-05-14 01:17 . 2008-05-14 01:17 <DIR> d-------- C:\Program Files\LightScribeTemplateLabeler
2008-05-13 22:59 . 2008-05-13 22:59 <DIR> d-------- C:\Program Files\NetWaiting
2008-05-13 20:51 . 2008-05-13 20:51 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-13 04:24 . 2008-05-13 04:24 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-13 04:24 . 2008-05-13 04:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-11 04:38 . 2008-05-11 15:16 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-05-11 04:36 . 2008-05-11 04:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LightScribe
2008-05-11 04:26 . 2008-05-11 04:26 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-05-11 04:26 . 2008-05-11 04:26 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2008-05-11 04:25 . 2007-06-08 13:46 1,560,576 --a------ C:\WINDOWS\system32\BttnCmns_64.dll
2008-05-11 04:25 . 2006-11-02 06:09 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-05-11 04:25 . 2007-06-18 16:12 16,768 --a------ C:\WINDOWS\system32\drivers\HpqKbFiltr.sys
2008-05-11 04:23 . 2008-05-11 04:23 <DIR> d-------- C:\Program Files\Broadcom
2008-05-11 00:43 . 2008-05-11 00:43 <DIR> d-------- C:\Program Files\DVD Shrink
2008-05-11 00:43 . 2008-05-11 00:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-05-06 05:13 . 2008-05-06 05:13 <DIR> d-------- C:\Program Files\NCH Software
2008-05-06 05:13 . 2008-05-12 19:35 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\NCH Swift Sound
2008-05-06 05:13 . 2008-05-12 19:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-05-06 05:12 . 2008-05-12 18:40 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-05-05 11:50 . 2008-05-05 11:50 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\PRMT
2008-05-05 11:15 . 2008-05-05 11:15 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\PROject MT
2008-05-05 09:34 . 2008-05-05 09:35 <DIR> d-------- C:\Program Files\PRMT8
2008-05-05 09:34 . 2008-05-05 09:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PRMT
2008-05-01 02:29 . 2008-05-01 02:29 38 --a------ C:\WINDOWS\AviSplitter.INI
2008-04-30 22:35 . 2008-04-30 22:36 8 --a------ C:\WINDOWS\system32\nvModes.dat
2008-04-29 16:26 . 2008-05-04 14:22 <DIR> d----c--- C:\videodvdmaker
2008-04-29 16:26 . 2008-04-29 16:26 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Video DVD Maker FREE
2008-04-29 16:24 . 2008-04-29 16:24 <DIR> d-------- C:\Program Files\Video DVD Maker
2008-04-28 09:03 . 2008-04-28 10:40 37 --a------ C:\WINDOWS\filelisting.bat
2008-04-28 07:49 . 2008-04-28 08:48 0 --a--c--- C:\documents
2008-04-28 01:12 . 2008-02-28 13:26 1,414,440 --a------ C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-04-28 01:12 . 2008-02-28 13:01 774,144 --a------ C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-04-27 16:52 . 2008-04-27 16:56 <DIR> d-------- C:\Program Files\HP DVB-T TV Tuner
2008-04-27 07:03 . 2008-04-27 07:03 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-04-27 07:02 . 2008-04-27 16:50 <DIR> d-------- C:\Program Files\Avi2Dvd
2008-04-27 06:31 . 2008-04-27 06:31 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\DonationCoder
2008-04-27 06:31 . 2008-04-27 06:31 46 --a------ C:\WINDOWS\system32\DonationCoder_urlsnooper_InstallInfo.dat
2008-04-27 03:44 . 2008-04-27 06:44 <DIR> d-------- C:\Program Files\URLSnooper2
2008-04-27 03:44 . 2008-04-27 03:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DonationCoder
2008-04-26 20:46 . 2008-04-27 04:03 <DIR> d-------- C:\Program Files\WinPcap
2008-04-26 20:45 . 2008-05-14 07:10 <DIR> d-------- C:\Program Files\WMR11
2008-04-26 19:13 . 2008-04-26 19:13 <DIR> d-------- C:\WINDOWS\Replay Media Catcher
2008-04-26 19:13 . 2008-04-26 19:13 <DIR> d-------- C:\Program Files\Replay Media Catcher
2008-04-24 09:29 . 2008-04-27 16:16 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-04-24 05:12 . 2008-05-16 04:41 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-24 03:30 . 2005-11-03 07:00 110,080 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-04-24 03:30 . 2005-11-15 05:00 109,056 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-04-23 11:53 . 2008-04-23 11:53 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\TmpRecentIcons
2008-04-23 06:34 . 2008-04-24 00:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\otmjcpkf
2008-04-19 01:10 . 2008-04-19 01:10 <DIR> d-------- C:\Program Files\Motorola Phone Tools

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-19 00:06 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype
2008-05-18 20:55 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\uTorrent
2008-05-18 07:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}
2008-05-16 13:06 --------- d-----w C:\Program Files\Hewlett-Packard
2008-05-16 13:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-16 03:25 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\CyberLink
2008-05-14 05:55 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-05-14 02:58 --------- d-----w C:\Program Files\CONEXANT
2008-05-11 08:23 822,272 ----a-w C:\WINDOWS\system32\drivers\BCMWL5.SYS
2008-05-05 02:58 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Apple Computer
2008-05-04 20:54 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Vso
2008-05-04 00:31 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\BSplayer Pro
2008-05-03 03:38 --------- d-----w C:\Program Files\Microsoft Works
2008-04-28 08:23 --------- d-----w C:\Program Files\Rhapsody
2008-04-26 23:07 --------- d-----w C:\Program Files\Free FLV Converter
2008-04-22 07:41 --------- d-----w C:\Program Files\ICQ6
2008-04-15 06:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-15 06:07 --------- d-----w C:\Program Files\SmartSound Software
2008-04-15 06:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-04-15 06:06 --------- d-----w C:\Program Files\Cyberlink
2008-04-15 06:01 --------- d-----w C:\Program Files\QuickTime
2008-04-15 05:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-15 05:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-04-15 05:06 8,413 ----a-w C:\WINDOWS\system32\drivers\mcstrm.sys
2008-04-15 05:06 --------- d-----w C:\Program Files\Common Files\Real
2008-04-15 05:05 --------- d-----w C:\Program Files\Real
2008-04-14 07:10 --------- d-----w C:\Program Files\VSO
2008-04-14 06:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-04-14 02:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-04-14 02:33 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2008-04-12 00:35 --------- d-----w C:\Program Files\uTorrent
2008-04-10 04:47 --------- d-----w C:\Program Files\Autorun
2008-04-10 04:06 --------- d-----w C:\Program Files\CommonAppData
2008-04-03 02:24 --------- d-----w C:\Program Files\muvee Technologies
2008-04-03 02:22 --------- d-----w C:\Program Files\Common Files\muvee Technologies
2008-04-02 04:27 --------- d-----w C:\Program Files\DivX
2008-04-02 04:23 3,340 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\wklnhst.dat
2008-03-29 02:38 --------- d-----w C:\Program Files\HP
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-22 12:25 --------- d-----w C:\Program Files\Microsoft Money 2006
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 22:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2007-07-04 20:31 47,360 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\pcouffin.sys
2007-03-24 14:06 331 -c--a-w C:\Program Files\Setup.ini
2007-03-24 14:06 3,584 -c--a-w C:\Program Files\1033.mst
2007-03-24 14:06 194,048 -c--a-w C:\Program Files\1049.mst
2007-03-24 14:06 187,392 ----a-w C:\Program Files\1058.mst
2007-03-20 02:38 374 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\internaldb6334.dat
2007-03-20 02:11 18,432 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\internaldb41.dat
2007-03-20 01:37 538 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\internaldb8467.dat
2007-02-05 08:06 251 -c--a-w C:\Program Files\wt3d.ini
2007-01-14 06:24 24,192 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\usbsermptxp.sys
2007-01-14 06:24 22,768 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\usbsermpt.sys
2007-01-14 05:52 92,064 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmmdm.sys
2007-01-14 05:52 9,232 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmmdfl.sys
2007-01-14 05:52 79,328 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmserd.sys
2007-01-14 05:52 66,656 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmbus.sys
2007-01-14 05:52 6,208 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmcmnt.sys
2007-01-14 05:52 5,936 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmwhnt.sys
2007-01-14 05:52 4,048 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmcr.sys
2006-08-10 14:26 99,840 -c--a-w C:\Program Files\1031.mst
2006-08-10 14:26 99,840 -c--a-w C:\Program Files\1029.mst
2006-08-10 14:26 97,792 -c--a-w C:\Program Files\1040.mst
2006-08-10 14:26 97,280 -c--a-w C:\Program Files\1051.mst
2006-08-10 14:26 96,256 -c--a-w C:\Program Files\1045.mst
2006-08-10 14:26 95,744 -c--a-w C:\Program Files\1036.mst
2006-08-10 14:26 94,720 -c--a-w C:\Program Files\1034.mst
2006-08-10 14:26 91,136 -c--a-w C:\Program Files\1043.mst
2006-08-10 14:26 102,400 -c--a-w C:\Program Files\1038.mst
2004-07-15 22:22 1,822,520 -c--a-w C:\Program Files\instmsiw.exe
2004-04-28 05:19 233,160 -c--a-w C:\Program Files\LISTOOL.EXE
2004-02-11 21:32 257,189 -c--a-w C:\Program Files\LISTOOL.CHM
2003-04-21 23:09 245,408 -c--a-w C:\Program Files\unicows.dll
2007-12-19 08:28 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8FAA95CB-EC60-4996-BB6B-6D0E4545C9C8}]
C:\WINDOWS\system32\mlJcCspQ.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C4999B47-3FD3-4EF1-8A7F-A46CE75D79AD}]
C:\WINDOWS\system32\wvUlIXQI.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C733BC2E-B26F-48DF-AEB7-6D5111C0A000}]
C:\WINDOWS\system32\byXPIbxX.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E439B6B9-46AA-4FD3-8705-237436B12F99}]
C:\WINDOWS\system32\ljJaywWM.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MimarSinan Rubber Ducky"="C:\Program Files\MimarSinan Rubber Ducky\RubberDucky.exe" [2006-09-22 02:45 974336]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 11:50 205480]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 17:45 22058792]
"zbnewpvb"="C:\WINDOWS\system32\kxofafcz.exe" [ ]
"EDLauncher"="C:\Program Files\PRMT8\PRMTED\EDLauncher.exe" [2007-08-17 11:38 122880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 03:29 102400]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 03:27 1015808]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2006-03-16 00:00 143360]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [2006-02-09 12:52 643072]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 13:23 1187840]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-10-18 18:12 102400]
"nwiz"="nwiz.exe" [2006-09-27 21:10 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-27 21:10 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-27 21:10 7585792]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"Mouse Suite 98 Daemon"="ICO.EXE" [2004-07-14 19:36 57344 C:\WINDOWS\system32\ICO.EXE]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 06:56 86960]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 11:50 205480]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 01:58 458752]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-07-26 23:44 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-06 00:56 64512]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2007-09-20 13:58 61440]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"1A:Stardock TrayMonitor"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-04-15 02:00 282624]
"21766322"="C:\WINDOWS\system32\badjhjjg.dll" [ ]
"QlbCtrl.exe"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-10-19 13:28 202032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"1A:Stardock TrayMonitor"="" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-16 00:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 19:29 39264]

C:\Documents and Settings\Anara Zhiyenbekova\Start Menu\Programs\Startup\
utorrent.lnk - C:\Program Files\uTorrent\utorrent.exe [2007-02-15 16:17:12 267568]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - C:\Program Files\Sophos\AutoUpdate\ALMon.exe [2007-08-06 21:24:48 245760]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\Program Files\\VSO\\ConvertXtoDVD\\ConvertXtoDvd.exe"=
"C:\\Program Files\\Far\\Far.exe"=
"C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe"=
"C:\\Program Files\\WinRAR\\WinRAR.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Webteh\\BSplayerPro\\bsplayer.exe"=
"C:\\Program Files\\Free FLV Converter\\FreeFLVConverter.exe"=
"C:\\Program Files\\MagicISO\\MagicISO.exe"=
"C:\\Program Files\\muvee Technologies\\muvee autoProducer 5.0 - SE\\muveeapp.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\HP Pavilion Webcam Demo\\Start.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqdirec.exe"=
"C:\\Program Files\\HP Rhapsody\\rhapsody.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Product Assistant\\bin\\hprbui.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\MimarSinan Rubber Ducky\\RubberDucky.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Movie Maker\\moviemk.exe"=
"C:\\Program Files\\Sophos\\Sophos Anti-Virus\\SavMain.exe"=
"C:\\Program Files\\DC++\\DCPlusPlus.exe"=
"C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\PPTVIEW.EXE"=
"C:\\Program Files\\Cyberlink\\PowerDirector\\PDR.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"80:TCP"= 80:TCP:HTTP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)

R1 SAVOnAccessControl;SAVOnAccessControl;C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys [2007-12-13 01:29]
R1 SAVOnAccessFilter;SAVOnAccessFilter;C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys [2007-12-13 01:28]
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};C:\Program Files\HP\QuickPlay\000.fcl [2007-10-18 18:12]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 03:49]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;C:\WINDOWS\system32\Drivers\5U870CAP.sys [2006-06-06 16:39]
S3 NetWlan5;802.11b Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\NetWlan5.sys [2001-11-06 09:07]
S3 NPF;WinPcap Packet Driver (NPF);C:\WINDOWS\system32\drivers\NPF.sys [2007-11-14 15:40]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2006-03-16 00:00]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2006-03-16 00:00]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2006-03-16 00:00]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2006-03-16 00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

*Newly Created Service* - CATCHME

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-05-18 13:28:00 C:\WINDOWS\Tasks\AutoUpdate Monitor.job"
- C:\PROGRA~1\Sophos\AUTOUP~1\ALMon.exe
"2008-05-18 07:00:03 C:\WINDOWS\Tasks\MimarSinan Rubber Ducky Updates.job"
- C:\WINDOWS\Installer\MimarSinan Rubber Ducky Updates for All Users.lnk
"2006-01-01 08:09:19 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job"
- C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe%Scan -RestrictPrivileges -ScanType 1
"2008-05-18 04:30:05 C:\WINDOWS\Tasks\Scheduled Scan.job"
- C:\Program Files\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe'{7012536F-D9D1-4C69-B1DB-FEA891410FF9}
"2008-05-18 20:56:01 C:\WINDOWS\Tasks\User_Feed_Synchronization-{ED3BCAB5-473A-4940-9B4A-44C4E1A39161}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-18 20:09:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????H??????????????|?M?|?????M?|??@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\C:\Program Files\HP\QuickPlay\000.fcl"
.
Completion time: 2008-05-18 20:12:03
ComboFix-quarantined-files.txt 2008-05-19 00:11:06

Pre-Run: 11,580,411,904 bytes free
Post-Run: 11,793,158,144 bytes free

364 --- E O F --- 2008-05-15 19:47:08

2. HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:39:40 PM, on 5/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\MimarSinan Rubber Ducky\RubberDucky.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\PRMT8\PRMTED\EDLauncher.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\PRMT8\PRMTED\prmedsvr.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcrobatInfo.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8FAA95CB-EC60-4996-BB6B-6D0E4545C9C8} - C:\WINDOWS\system32\mlJcCspQ.dll (file missing)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {C4999B47-3FD3-4EF1-8A7F-A46CE75D79AD} - C:\WINDOWS\system32\wvUlIXQI.dll (file missing)
O2 - BHO: (no name) - {C733BC2E-B26F-48DF-AEB7-6D5111C0A000} - C:\WINDOWS\system32\byXPIbxX.dll (file missing)
O2 - BHO: (no name) - {E439B6B9-46AA-4FD3-8705-237436B12F99} - C:\WINDOWS\system32\ljJaywWM.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [21766322] rundll32.exe "C:\WINDOWS\system32\badjhjjg.dll",b
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKCU\..\Run: [MimarSinan Rubber Ducky] "C:\Program Files\MimarSinan Rubber Ducky\RubberDucky.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [zbnewpvb] C:\WINDOWS\system32\kxofafcz.exe
O4 - HKCU\..\Run: [EDLauncher] C:\Program Files\PRMT8\PRMTED\EDLauncher.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: utorrent.lnk = C:\Program Files\uTorrent\utorrent.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqnbk2/downloads/sysinfo.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F519B46-96EF-499F-BF24-C9E1548FA56B} (Sony SNC-DF70 Control) - http://ffcoservery1.webcam.carleton.ca/program/SonySncDf70View.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ANARAZ~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/ANARAZ~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 14190 bytes

pskelley
2008-05-19, 16:41
Thanks for returning your information and your comments.

It looks like Sophos is your antivirus of choice, wondering why you have this Symantec stuff running in services?
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
If it is a leftover from the uninstall (something Symantec does not do well) have a look at this tool:
http://basconotw.mvps.org/SymRem.htm

1) How to make files and folders visible:
Click Start > Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm. Click OK.
You may reverse this for safety when we are finished.

2) Please download ATF Cleaner by Atribune
http://www.atribune.org/public-beta/ATF-Cleaner.exe
Save it to your Desktop. We will use this later.

3) Open notepad and copy/paste the text in the codebox below into it:


File::
C:\WINDOWS\system32\badjhjjg.dll
C:\WINDOWS\system32\kxofafcz.exe

Folder::
C:\Documents and Settings\All Users\Application Data\otmjcpkf

Save this as CFScript

http://i24.photobucket.com/albums/c30/ken545/CFScript.gif

Referring to the picture above, drag CFScript into ComboFix.exe.

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

4) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

(leave the first item if you set it like that on purpose)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

O2 - BHO: (no name) - {8FAA95CB-EC60-4996-BB6B-6D0E4545C9C8} - C:\WINDOWS\system32\mlJcCspQ.dll (file missing)
O2 - BHO: (no name) - {C4999B47-3FD3-4EF1-8A7F-A46CE75D79AD} - C:\WINDOWS\system32\wvUlIXQI.dll (file missing)
O2 - BHO: (no name) - {C733BC2E-B26F-48DF-AEB7-6D5111C0A000} - C:\WINDOWS\system32\byXPIbxX.dll (file missing)
O2 - BHO: (no name) - {E439B6B9-46AA-4FD3-8705-237436B12F99} - C:\WINDOWS\system32\ljJaywWM.dll (file missing)
O4 - HKLM\..\Run: [21766322] rundll32.exe "C:\WINDOWS\system32\badjhjjg.dll",b
O4 - HKCU\..\Run: [zbnewpvb] C:\WINDOWS\system32\kxofafcz.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ANARAZ~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/ANARAZ~1/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

Close all programs but HJT and all browser windows, then click on "Fix Checked"

5) Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Restart and post the combofix log, a new HJT log and tell me how the computer is running.

Thanks

Anara
2008-05-19, 22:32
here I am :crowned:
i hope we are clean now :red:

ComboFix 08-05-15.3 - Anara Zhiyenbekova 2008-05-19 15:25:29.3 - NTFSx86
Running from: C:\Documents and Settings\Anara Zhiyenbekova\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-04-19 to 2008-05-19 )))))))))))))))))))))))))))))))
.

2008-05-16 22:58 . 2008-05-16 22:58 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-16 22:58 . 2008-05-16 22:58 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-15 23:36 . 2008-05-15 23:36 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\CyberLink
2008-05-14 01:54 . 2008-05-14 01:55 <DIR> d-------- C:\Program Files\SureThing CD Labeler 5
2008-05-14 01:32 . 2008-05-14 01:32 <DIR> d-------- C:\Program Files\LightScribe Diagnostic Utility
2008-05-14 01:17 . 2008-05-14 01:17 <DIR> d-------- C:\Program Files\LightScribeTemplateLabeler
2008-05-13 22:59 . 2008-05-13 22:59 <DIR> d-------- C:\Program Files\NetWaiting
2008-05-13 20:51 . 2008-05-13 20:51 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-13 04:24 . 2008-05-13 04:24 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-13 04:24 . 2008-05-13 04:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-11 04:38 . 2008-05-11 15:16 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-05-11 04:36 . 2008-05-11 04:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LightScribe
2008-05-11 04:26 . 2008-05-11 04:26 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-05-11 04:26 . 2008-05-11 04:26 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2008-05-11 04:25 . 2007-06-08 13:46 1,560,576 --a------ C:\WINDOWS\system32\BttnCmns_64.dll
2008-05-11 04:25 . 2006-11-02 06:09 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-05-11 04:25 . 2007-06-18 16:12 16,768 --a------ C:\WINDOWS\system32\drivers\HpqKbFiltr.sys
2008-05-11 04:23 . 2008-05-11 04:23 <DIR> d-------- C:\Program Files\Broadcom
2008-05-11 00:43 . 2008-05-11 00:43 <DIR> d-------- C:\Program Files\DVD Shrink
2008-05-11 00:43 . 2008-05-11 00:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-05-06 05:13 . 2008-05-06 05:13 <DIR> d-------- C:\Program Files\NCH Software
2008-05-06 05:13 . 2008-05-12 19:35 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\NCH Swift Sound
2008-05-06 05:13 . 2008-05-12 19:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-05-06 05:12 . 2008-05-12 18:40 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-05-05 11:50 . 2008-05-05 11:50 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\PRMT
2008-05-05 11:15 . 2008-05-05 11:15 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\PROject MT
2008-05-05 09:34 . 2008-05-05 09:35 <DIR> d-------- C:\Program Files\PRMT8
2008-05-05 09:34 . 2008-05-05 09:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PRMT
2008-05-01 02:29 . 2008-05-01 02:29 38 --a------ C:\WINDOWS\AviSplitter.INI
2008-04-30 22:35 . 2008-04-30 22:36 8 --a------ C:\WINDOWS\system32\nvModes.dat
2008-04-29 16:26 . 2008-05-04 14:22 <DIR> d----c--- C:\videodvdmaker
2008-04-29 16:26 . 2008-04-29 16:26 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Video DVD Maker FREE
2008-04-29 16:24 . 2008-04-29 16:24 <DIR> d-------- C:\Program Files\Video DVD Maker
2008-04-28 09:03 . 2008-04-28 10:40 37 --a------ C:\WINDOWS\filelisting.bat
2008-04-28 07:49 . 2008-04-28 08:48 0 --a--c--- C:\documents
2008-04-28 01:12 . 2008-02-28 13:26 1,414,440 --a------ C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-04-28 01:12 . 2008-02-28 13:01 774,144 --a------ C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-04-27 16:52 . 2008-04-27 16:56 <DIR> d-------- C:\Program Files\HP DVB-T TV Tuner
2008-04-27 07:03 . 2008-04-27 07:03 <DIR> d-------- C:\Program Files\AviSynth 2.5
2008-04-27 07:02 . 2008-04-27 16:50 <DIR> d-------- C:\Program Files\Avi2Dvd
2008-04-27 06:31 . 2008-04-27 06:31 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\DonationCoder
2008-04-27 06:31 . 2008-04-27 06:31 46 --a------ C:\WINDOWS\system32\DonationCoder_urlsnooper_InstallInfo.dat
2008-04-27 03:44 . 2008-04-27 06:44 <DIR> d-------- C:\Program Files\URLSnooper2
2008-04-27 03:44 . 2008-04-27 03:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DonationCoder
2008-04-26 20:46 . 2008-04-27 04:03 <DIR> d-------- C:\Program Files\WinPcap
2008-04-26 20:45 . 2008-05-14 07:10 <DIR> d-------- C:\Program Files\WMR11
2008-04-26 19:13 . 2008-04-26 19:13 <DIR> d-------- C:\WINDOWS\Replay Media Catcher
2008-04-26 19:13 . 2008-04-26 19:13 <DIR> d-------- C:\Program Files\Replay Media Catcher
2008-04-24 09:29 . 2008-04-27 16:16 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-04-24 05:12 . 2008-05-16 04:41 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-24 03:30 . 2005-11-03 07:00 110,080 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-04-24 03:30 . 2005-11-15 05:00 109,056 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-04-23 11:53 . 2008-04-23 11:53 <DIR> d-------- C:\Documents and Settings\Anara Zhiyenbekova\Application Data\TmpRecentIcons
2008-04-23 06:34 . 2008-04-24 00:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\otmjcpkf
2008-04-19 01:10 . 2008-04-19 01:10 <DIR> d-------- C:\Program Files\Motorola Phone Tools

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-19 19:24 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\uTorrent
2008-05-19 19:24 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Skype
2008-05-18 07:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\{C357FF4B-BB69-4DC2-9869-55F052974DA8}
2008-05-16 13:06 --------- d-----w C:\Program Files\Hewlett-Packard
2008-05-16 13:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-05-16 03:25 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\CyberLink
2008-05-14 05:55 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-05-14 02:58 --------- d-----w C:\Program Files\CONEXANT
2008-05-11 08:23 822,272 ----a-w C:\WINDOWS\system32\drivers\BCMWL5.SYS
2008-05-05 02:58 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Apple Computer
2008-05-04 20:54 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\Vso
2008-05-04 00:31 --------- d-----w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\BSplayer Pro
2008-05-03 03:38 --------- d-----w C:\Program Files\Microsoft Works
2008-04-28 08:23 --------- d-----w C:\Program Files\Rhapsody
2008-04-26 23:07 --------- d-----w C:\Program Files\Free FLV Converter
2008-04-22 07:41 --------- d-----w C:\Program Files\ICQ6
2008-04-15 06:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-15 06:07 --------- d-----w C:\Program Files\SmartSound Software
2008-04-15 06:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-04-15 06:06 --------- d-----w C:\Program Files\Cyberlink
2008-04-15 06:01 --------- d-----w C:\Program Files\QuickTime
2008-04-15 05:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-15 05:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-04-15 05:06 8,413 ----a-w C:\WINDOWS\system32\drivers\mcstrm.sys
2008-04-15 05:06 --------- d-----w C:\Program Files\Common Files\Real
2008-04-15 05:05 --------- d-----w C:\Program Files\Real
2008-04-14 07:10 --------- d-----w C:\Program Files\VSO
2008-04-14 06:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-04-14 02:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-04-14 02:33 --------- d-----w C:\Program Files\Common Files\Motorola Shared
2008-04-12 00:35 --------- d-----w C:\Program Files\uTorrent
2008-04-10 04:47 --------- d-----w C:\Program Files\Autorun
2008-04-10 04:06 --------- d-----w C:\Program Files\CommonAppData
2008-04-03 02:24 --------- d-----w C:\Program Files\muvee Technologies
2008-04-03 02:22 --------- d-----w C:\Program Files\Common Files\muvee Technologies
2008-04-02 04:27 --------- d-----w C:\Program Files\DivX
2008-04-02 04:23 3,340 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\wklnhst.dat
2008-03-29 02:38 --------- d-----w C:\Program Files\HP
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-22 12:25 --------- d-----w C:\Program Files\Microsoft Money 2006
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 22:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2007-07-04 20:31 47,360 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\pcouffin.sys
2007-03-24 14:06 331 -c--a-w C:\Program Files\Setup.ini
2007-03-24 14:06 3,584 -c--a-w C:\Program Files\1033.mst
2007-03-24 14:06 194,048 -c--a-w C:\Program Files\1049.mst
2007-03-24 14:06 187,392 ----a-w C:\Program Files\1058.mst
2007-03-20 02:38 374 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\internaldb6334.dat
2007-03-20 02:11 18,432 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\internaldb41.dat
2007-03-20 01:37 538 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\Application Data\internaldb8467.dat
2007-02-05 08:06 251 -c--a-w C:\Program Files\wt3d.ini
2007-01-14 06:24 24,192 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\usbsermptxp.sys
2007-01-14 06:24 22,768 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\usbsermpt.sys
2007-01-14 05:52 92,064 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmmdm.sys
2007-01-14 05:52 9,232 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmmdfl.sys
2007-01-14 05:52 79,328 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmserd.sys
2007-01-14 05:52 66,656 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmbus.sys
2007-01-14 05:52 6,208 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmcmnt.sys
2007-01-14 05:52 5,936 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmwhnt.sys
2007-01-14 05:52 4,048 -c--a-w C:\Documents and Settings\Anara Zhiyenbekova\mqdmcr.sys
2006-08-10 14:26 99,840 -c--a-w C:\Program Files\1031.mst
2006-08-10 14:26 99,840 -c--a-w C:\Program Files\1029.mst
2006-08-10 14:26 97,792 -c--a-w C:\Program Files\1040.mst
2006-08-10 14:26 97,280 -c--a-w C:\Program Files\1051.mst
2006-08-10 14:26 96,256 -c--a-w C:\Program Files\1045.mst
2006-08-10 14:26 95,744 -c--a-w C:\Program Files\1036.mst
2006-08-10 14:26 94,720 -c--a-w C:\Program Files\1034.mst
2006-08-10 14:26 91,136 -c--a-w C:\Program Files\1043.mst
2006-08-10 14:26 102,400 -c--a-w C:\Program Files\1038.mst
2004-07-15 22:22 1,822,520 -c--a-w C:\Program Files\instmsiw.exe
2004-04-28 05:19 233,160 -c--a-w C:\Program Files\LISTOOL.EXE
2004-02-11 21:32 257,189 -c--a-w C:\Program Files\LISTOOL.CHM
2003-04-21 23:09 245,408 -c--a-w C:\Program Files\unicows.dll
2007-12-19 08:28 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-05-18_20.10.51.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-17 00:55:13 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-19 19:14:47 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-17 00:55:49 214,398 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
+ 2008-05-19 19:16:00 214,405 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
+ 2008-05-19 19:15:38 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_920.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MimarSinan Rubber Ducky"="C:\Program Files\MimarSinan Rubber Ducky\RubberDucky.exe" [2006-09-22 02:45 974336]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 11:50 205480]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 17:45 22058792]
"EDLauncher"="C:\Program Files\PRMT8\PRMTED\EDLauncher.exe" [2007-08-17 11:38 122880]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-16 00:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 03:29 102400]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 03:27 1015808]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2006-03-16 00:00 143360]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [2006-02-09 12:52 643072]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 13:23 1187840]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-10-18 18:12 102400]
"nwiz"="nwiz.exe" [2006-09-27 21:10 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-09-27 21:10 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-09-27 21:10 7585792]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"Mouse Suite 98 Daemon"="ICO.EXE" [2004-07-14 19:36 57344 C:\WINDOWS\system32\ICO.EXE]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 06:56 86960]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 11:50 205480]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 01:58 458752]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-07-26 23:44 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-06 00:56 64512]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2007-09-20 13:58 61440]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"1A:Stardock TrayMonitor"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-04-15 02:00 282624]
"QlbCtrl.exe"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-10-19 13:28 202032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"1A:Stardock TrayMonitor"="" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-16 00:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 19:29 39264]

C:\Documents and Settings\Anara Zhiyenbekova\Start Menu\Programs\Startup\
utorrent.lnk - C:\Program Files\uTorrent\utorrent.exe [2007-02-15 16:17:12 267568]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - C:\Program Files\Sophos\AutoUpdate\ALMon.exe [2007-08-06 21:24:48 245760]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\Program Files\\VSO\\ConvertXtoDVD\\ConvertXtoDvd.exe"=
"C:\\Program Files\\Far\\Far.exe"=
"C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe"=
"C:\\Program Files\\WinRAR\\WinRAR.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Webteh\\BSplayerPro\\bsplayer.exe"=
"C:\\Program Files\\Free FLV Converter\\FreeFLVConverter.exe"=
"C:\\Program Files\\MagicISO\\MagicISO.exe"=
"C:\\Program Files\\muvee Technologies\\muvee autoProducer 5.0 - SE\\muveeapp.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\HP Pavilion Webcam Demo\\Start.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqdirec.exe"=
"C:\\Program Files\\HP Rhapsody\\rhapsody.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Product Assistant\\bin\\hprbui.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\MimarSinan Rubber Ducky\\RubberDucky.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Movie Maker\\moviemk.exe"=
"C:\\Program Files\\Sophos\\Sophos Anti-Virus\\SavMain.exe"=
"C:\\Program Files\\DC++\\DCPlusPlus.exe"=
"C:\\Program Files\\Microsoft Office\\PowerPoint Viewer\\PPTVIEW.EXE"=
"C:\\Program Files\\Cyberlink\\PowerDirector\\PDR.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"80:TCP"= 80:TCP:HTTP

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)

R1 SAVOnAccessControl;SAVOnAccessControl;C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys [2007-12-13 01:29]
R1 SAVOnAccessFilter;SAVOnAccessFilter;C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys [2007-12-13 01:28]
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};C:\Program Files\HP\QuickPlay\000.fcl [2007-10-18 18:12]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 03:49]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;C:\WINDOWS\system32\Drivers\5U870CAP.sys [2006-06-06 16:39]
S3 NetWlan5;802.11b Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\NetWlan5.sys [2001-11-06 09:07]
S3 NPF;WinPcap Packet Driver (NPF);C:\WINDOWS\system32\drivers\NPF.sys [2007-11-14 15:40]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2006-03-16 00:00]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2006-03-16 00:00]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2006-03-16 00:00]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2006-03-16 00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-05-19 13:28:00 C:\WINDOWS\Tasks\AutoUpdate Monitor.job"
- C:\PROGRA~1\Sophos\AUTOUP~1\ALMon.exe
"2008-05-18 07:00:03 C:\WINDOWS\Tasks\MimarSinan Rubber Ducky Updates.job"
- C:\WINDOWS\Installer\MimarSinan Rubber Ducky Updates for All Users.lnk
"2006-01-01 08:09:19 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job"
- C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe%Scan -RestrictPrivileges -ScanType 1
"2008-05-19 04:30:02 C:\WINDOWS\Tasks\Scheduled Scan.job"
- C:\Program Files\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe'{7012536F-D9D1-4C69-B1DB-FEA891410FF9}
"2008-05-19 17:52:08 C:\WINDOWS\Tasks\User_Feed_Synchronization-{ED3BCAB5-473A-4940-9B4A-44C4E1A39161}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-19 15:29:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????H??????????????|?M?|?????M?|??@

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\C:\Program Files\HP\QuickPlay\000.fcl"
.
Completion time: 2008-05-19 15:31:18
ComboFix-quarantined-files.txt 2008-05-19 19:30:31
ComboFix2.txt 2008-05-19 17:10:55
ComboFix3.txt 2008-05-19 00:12:03

Pre-Run: 10,856,931,328 bytes free
Post-Run: 10,847,526,912 bytes free

317 --- E O F --- 2008-05-15 19:47:08

+

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:17:15 PM, on 5/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\MimarSinan Rubber Ducky\RubberDucky.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\PRMT8\PRMTED\EDLauncher.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\PRMT8\PRMTED\prmedsvr.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKCU\..\Run: [MimarSinan Rubber Ducky] "C:\Program Files\MimarSinan Rubber Ducky\RubberDucky.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [EDLauncher] C:\Program Files\PRMT8\PRMTED\EDLauncher.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: utorrent.lnk = C:\Program Files\uTorrent\utorrent.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra 'Tools' menuitem: About Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - C:\Program Files\Iconix\IEAddOn\IconixBHO_26.dll (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqnbk2/downloads/sysinfo.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F519B46-96EF-499F-BF24-C9E1548FA56B} (Sony SNC-DF70 Control) - http://ffcoservery1.webcam.carleton.ca/program/SonySncDf70View.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

--
End of file - 13174 bytes

pskelley
2008-05-19, 23:06
:sad:You have not follow the directions, unless you do, I can not help you. You ran combofix again instend of following the directions to run the CFScript. Please review My last instructions again, especially #3 and run the CFScript again. It is very, very important that you read and follow these directions.

pskelley
2008-05-26, 15:29
No response since 2008-05-19, 17:06

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.