View Full Version : Virtumonde notice - please help
I am cleaning a friends computer. The thought was there was a physical hard drive problem. After observing the blue screen on a reboot, I looked up information and it seemed to be Backdoor:Rustock.B. I removed according to Symantec instructions, including disabling and removing pe386. Another scan cleaned more junk. I updated and ran spybot to discover virtumonde. I noticed in the detailed description this is difficult to remove and to seek help in the Spybot forums.
I followed the preparation instructions. I have scanned with Kapersky and will apply that information below. I will also include the HJT scan info. I ran Spybot in safe mode as instructed and could not remove the last entry of virtumonde. After a restart to prepare joining this forum, Spybot ran on boot up and found no problems. I just want to be sure everything is removed and if not find out how to remove what is left.
Thank you,
ajweg
Kapersky scan:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 21, 2008 9:03:06 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 20/05/2008
Kaspersky Anti-Virus database records: 788663
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 241283
Number of viruses found: 5
Number of infected objects: 8
Number of suspicious objects: 0
Duration of the scan process: 01:26:42
Infected Object Name / Virus Name / Last Action
C:\22caee060e80142803040f\$shtdwn$.req Object is locked skipped
C:\22caee060e80142803040f\admparse.dll Object is locked skipped
C:\22caee060e80142803040f\admparse.dll.mui Object is locked skipped
C:\22caee060e80142803040f\advpack.dll Object is locked skipped
C:\22caee060e80142803040f\advpack.dll.mui Object is locked skipped
C:\22caee060e80142803040f\browseui.dll Object is locked skipped
C:\22caee060e80142803040f\corpol.dll Object is locked skipped
C:\22caee060e80142803040f\custsat.dll Object is locked skipped
C:\22caee060e80142803040f\dxtmsft.dll Object is locked skipped
C:\22caee060e80142803040f\dxtrans.dll Object is locked skipped
C:\22caee060e80142803040f\extmgr.dll Object is locked skipped
C:\22caee060e80142803040f\extmgr.dll.mui Object is locked skipped
C:\22caee060e80142803040f\feeddisc.wav Object is locked skipped
C:\22caee060e80142803040f\hmmapi.dll Object is locked skipped
C:\22caee060e80142803040f\hmmapi.dll.mui Object is locked skipped
C:\22caee060e80142803040f\html.iec Object is locked skipped
C:\22caee060e80142803040f\html.iec.mui Object is locked skipped
C:\22caee060e80142803040f\icardie.dll Object is locked skipped
C:\22caee060e80142803040f\icardie.dll.mui Object is locked skipped
C:\22caee060e80142803040f\icrav03.rat Object is locked skipped
C:\22caee060e80142803040f\ie4uinit.exe Object is locked skipped
C:\22caee060e80142803040f\ie4uinit.exe.mui Object is locked skipped
C:\22caee060e80142803040f\ieakeng.dll Object is locked skipped
C:\22caee060e80142803040f\ieakeng.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieakmmc.chm Object is locked skipped
C:\22caee060e80142803040f\ieaksie.dll Object is locked skipped
C:\22caee060e80142803040f\ieaksie.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieakui.dll Object is locked skipped
C:\22caee060e80142803040f\ieakui.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieapfltr.dat Object is locked skipped
C:\22caee060e80142803040f\ieapfltr.dll Object is locked skipped
C:\22caee060e80142803040f\iedkcs32.dll Object is locked skipped
C:\22caee060e80142803040f\iedkcs32.dll.mui Object is locked skipped
C:\22caee060e80142803040f\iedw.exe Object is locked skipped
C:\22caee060e80142803040f\iedw.exe.mui Object is locked skipped
C:\22caee060e80142803040f\ieencode.dll Object is locked skipped
C:\22caee060e80142803040f\ieeula.chm Object is locked skipped
C:\22caee060e80142803040f\ieframe.dll Object is locked skipped
C:\22caee060e80142803040f\ieframe.dll.mui Object is locked skipped
C:\22caee060e80142803040f\iepeers.dll Object is locked skipped
C:\22caee060e80142803040f\iepeers.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieproxy.dll Object is locked skipped
C:\22caee060e80142803040f\iernonce.dll Object is locked skipped
C:\22caee060e80142803040f\iernonce.dll.mui Object is locked skipped
C:\22caee060e80142803040f\iertutil.dll Object is locked skipped
C:\22caee060e80142803040f\iesetup.dll Object is locked skipped
C:\22caee060e80142803040f\iesetup.dll.mui Object is locked skipped
C:\22caee060e80142803040f\iesupp.chm Object is locked skipped
C:\22caee060e80142803040f\ieudinit.exe Object is locked skipped
C:\22caee060e80142803040f\ieui.dll Object is locked skipped
C:\22caee060e80142803040f\ieui.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieuinit.inf Object is locked skipped
C:\22caee060e80142803040f\ieunatt.exe.mui Object is locked skipped
C:\22caee060e80142803040f\iexplore.chm Object is locked skipped
C:\22caee060e80142803040f\iexplore.exe Object is locked skipped
C:\22caee060e80142803040f\iexplore.exe.mui Object is locked skipped
C:\22caee060e80142803040f\imgutil.dll Object is locked skipped
C:\22caee060e80142803040f\inetcorp.iem Object is locked skipped
C:\22caee060e80142803040f\inetcpl.cpl Object is locked skipped
C:\22caee060e80142803040f\inetcpl.cpl.mui Object is locked skipped
C:\22caee060e80142803040f\inetres.adm Object is locked skipped
C:\22caee060e80142803040f\inetset.iem Object is locked skipped
C:\22caee060e80142803040f\infobar.wav Object is locked skipped
C:\22caee060e80142803040f\inseng.dll Object is locked skipped
C:\22caee060e80142803040f\inseng.dll.mui Object is locked skipped
C:\22caee060e80142803040f\install.ins Object is locked skipped
C:\22caee060e80142803040f\jscript.dll Object is locked skipped
C:\22caee060e80142803040f\jsproxy.dll Object is locked skipped
C:\22caee060e80142803040f\licmgr10.dll Object is locked skipped
C:\22caee060e80142803040f\licmgr10.dll.mui Object is locked skipped
C:\22caee060e80142803040f\msfeeds.dll Object is locked skipped
C:\22caee060e80142803040f\msfeeds.mof Object is locked skipped
C:\22caee060e80142803040f\msfeedsbs.dll Object is locked skipped
C:\22caee060e80142803040f\msfeedsbs.dll.mui Object is locked skipped
C:\22caee060e80142803040f\msfeedsbs.mof Object is locked skipped
C:\22caee060e80142803040f\msfeedssync.exe Object is locked skipped
C:\22caee060e80142803040f\mshta.exe Object is locked skipped
C:\22caee060e80142803040f\mshta.exe.mui Object is locked skipped
C:\22caee060e80142803040f\mshtml.dll Object is locked skipped
C:\22caee060e80142803040f\mshtml.dll.mui Object is locked skipped
C:\22caee060e80142803040f\mshtml.tlb Object is locked skipped
C:\22caee060e80142803040f\mshtmled.dll Object is locked skipped
C:\22caee060e80142803040f\mshtmled.dll.mui Object is locked skipped
C:\22caee060e80142803040f\mshtmler.dll Object is locked skipped
C:\22caee060e80142803040f\mshtmler.dll.mui Object is locked skipped
C:\22caee060e80142803040f\msls31.dll Object is locked skipped
C:\22caee060e80142803040f\msrating.dll Object is locked skipped
C:\22caee060e80142803040f\msrating.dll.mui Object is locked skipped
C:\22caee060e80142803040f\mstime.dll Object is locked skipped
C:\22caee060e80142803040f\navstart.wav Object is locked skipped
C:\22caee060e80142803040f\occache.dll Object is locked skipped
C:\22caee060e80142803040f\occache.dll.mui Object is locked skipped
C:\22caee060e80142803040f\occache.ini Object is locked skipped
C:\22caee060e80142803040f\pngfilt.dll Object is locked skipped
C:\22caee060e80142803040f\popupblk.wav Object is locked skipped
C:\22caee060e80142803040f\shdocvw.dll Object is locked skipped
C:\22caee060e80142803040f\shlwapi.dll Object is locked skipped
C:\22caee060e80142803040f\spmsg.dll Object is locked skipped
C:\22caee060e80142803040f\spuninst.exe Object is locked skipped
C:\22caee060e80142803040f\spupdsvc.exe Object is locked skipped
C:\22caee060e80142803040f\tdc.ocx Object is locked skipped
C:\22caee060e80142803040f\ticrf.rat Object is locked skipped
C:\22caee060e80142803040f\update\eula.rtf Object is locked skipped
C:\22caee060e80142803040f\update\idndl.exe Object is locked skipped
C:\22caee060e80142803040f\update\ie7.cat Object is locked skipped
C:\22caee060e80142803040f\update\iecustom.dll Object is locked skipped
C:\22caee060e80142803040f\update\iereseticons.exe Object is locked skipped
C:\22caee060e80142803040f\update\iesetup.exe Object is locked skipped
C:\22caee060e80142803040f\update\legitlibm.dll Object is locked skipped
C:\22caee060e80142803040f\update\nlsdl.exe Object is locked skipped
C:\22caee060e80142803040f\update\update.exe Object is locked skipped
C:\22caee060e80142803040f\update\update.exe.manifest Object is locked skipped
C:\22caee060e80142803040f\update\update.inf Object is locked skipped
C:\22caee060e80142803040f\update\update.ver Object is locked skipped
C:\22caee060e80142803040f\update\updspapi.dll Object is locked skipped
C:\22caee060e80142803040f\update\xmllitesetup.exe Object is locked skipped
C:\22caee060e80142803040f\url.dll Object is locked skipped
C:\22caee060e80142803040f\urlmon.dll Object is locked skipped
C:\22caee060e80142803040f\urlmon.dll.mui Object is locked skipped
C:\22caee060e80142803040f\vbscript.dll Object is locked skipped
C:\22caee060e80142803040f\vgx.dll Object is locked skipped
C:\22caee060e80142803040f\webcheck.dll Object is locked skipped
C:\22caee060e80142803040f\webcheck.dll.mui Object is locked skipped
C:\22caee060e80142803040f\webcheck.ini Object is locked skipped
C:\22caee060e80142803040f\winfxdocobj.exe Object is locked skipped
C:\22caee060e80142803040f\winfxdocobj.exe.mui Object is locked skipped
C:\22caee060e80142803040f\wininet.dll Object is locked skipped
C:\22caee060e80142803040f\wininet.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\$shtdwn$.req Object is locked skipped
C:\aa68eaea23d0e7dedbde61\admparse.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\admparse.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\advpack.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\advpack.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\browseui.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\corpol.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\custsat.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\dxtmsft.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\dxtrans.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\extmgr.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\extmgr.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\feeddisc.wav Object is locked skipped
C:\aa68eaea23d0e7dedbde61\hmmapi.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\hmmapi.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\html.iec Object is locked skipped
C:\aa68eaea23d0e7dedbde61\html.iec.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\icardie.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\icardie.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\icrav03.rat Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ie4uinit.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ie4uinit.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakeng.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakeng.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakmmc.chm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieaksie.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieaksie.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakui.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakui.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieapfltr.dat Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieapfltr.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iedkcs32.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iedkcs32.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iedw.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iedw.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieencode.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieeula.chm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieframe.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieframe.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iepeers.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iepeers.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieproxy.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iernonce.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iernonce.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iertutil.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iesetup.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iesetup.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iesupp.chm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieudinit.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieui.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieui.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieuinit.inf Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieunatt.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iexplore.chm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iexplore.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iexplore.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\imgutil.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetcorp.iem Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetcpl.cpl Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetcpl.cpl.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetres.adm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetset.iem Object is locked skipped
C:\aa68eaea23d0e7dedbde61\infobar.wav Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inseng.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inseng.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\install.ins Object is locked skipped
C:\aa68eaea23d0e7dedbde61\jscript.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\jsproxy.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\licmgr10.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\licmgr10.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeeds.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeeds.mof Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeedsbs.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeedsbs.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeedsbs.mof Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeedssync.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshta.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshta.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtml.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtml.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtml.tlb Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtmled.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtmled.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtmler.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtmler.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msls31.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msrating.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msrating.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mstime.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\navstart.wav Object is locked skipped
C:\aa68eaea23d0e7dedbde61\occache.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\occache.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\occache.ini Object is locked skipped
C:\aa68eaea23d0e7dedbde61\pngfilt.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\popupblk.wav Object is locked skipped
C:\aa68eaea23d0e7dedbde61\shdocvw.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\shlwapi.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\spmsg.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\spuninst.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\spupdsvc.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\tdc.ocx Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ticrf.rat Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\eula.rtf Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\idndl.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\ie7.cat Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\iecustom.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\iereseticons.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\iesetup.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\legitlibm.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\nlsdl.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\update.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\update.exe.manifest Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\update.inf Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\update.ver Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\updspapi.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\xmllitesetup.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\url.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\urlmon.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\urlmon.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\vbscript.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\vgx.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\webcheck.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\webcheck.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\webcheck.ini Object is locked skipped
C:\aa68eaea23d0e7dedbde61\winfxdocobj.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\winfxdocobj.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\wininet.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\wininet.dll.mui Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{EA5B41AC-0691-432B-AF7D-941C2539D806}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR1E.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\All Users\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\Brian McCullough\ntuser.dat Object is locked skipped
C:\Documents and Settings\Brian McCullough\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Darius McCullough\ntuser.dat Object is locked skipped
C:\Documents and Settings\Darius McCullough\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Demetrius McCullough\ntuser.dat Object is locked skipped
C:\Documents and Settings\Demetrius McCullough\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Derrick McCullough J\ntuser.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough J\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\SiteAdvisor\SiteAdv.csh Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\eRT.jar-1bc9dae6-3d2e7438.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\eRT.jar-1bc9dae6-3d2e7438.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-2098ac78-6e654d3d.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-2098ac78-6e654d3d.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Derrick McCullough S\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Temporary Internet Files\Content.IE5\7ASFVX8D\in[1].htm Infected: Exploit.VBS.Phel.do skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Temporary Internet Files\Content.IE5\WD87WRCF\lc00[2].htm Infected: Trojan-Downloader.JS.Agent.rn skipped
C:\Documents and Settings\Derrick McCullough S\ntuser.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\wn0004.exe Infected: not-virus:Hoax.Win32.Renos.gk skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{AD376830-05F4-41C2-97A7-214EDC7828F8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hmkvqbjb.dll Infected: not-a-virus:AdWare.Win32.BHO.pq skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcmsc_HUjK84iuiZ4qA9R Object is locked skipped
C:\WINDOWS\Temp\mcmsc_MBxvaJ8a48wPuGB Object is locked skipped
C:\WINDOWS\Temp\mcmsc_oTfd622ci111e5z Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
HJT scan:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:04:12 PM, on 5/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\lxamsp32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {E865B01A-6012-450B-B857-45F06026BC0B} - C:\WINDOWS\addins\iwndobc.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\SiteAdv.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LaserJet] C:\WINDOWS\system32\spoolvs.exe
O4 - HKCU\..\Run: [findfast] C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe
O4 - Startup: findfast.lnk = C:\Documents and Settings\Derrick McCullough S\Local Settings\Temp\us0001.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} -
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum135.txt
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 8566 bytes
I forgot to mention. After cleaning the Backdoor.Rustock.B, there were no more blue screens and a hardware diagnostic could not find any errors on the hard drive.
Rorschach112
2008-05-22, 02:00
Hello
Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.
Download SDFix (http://downloads.andymanchesta.com/RemovalTools/SDFix.exe) and save it to your Desktop.
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.
Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.
It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum.
Please download the OTMoveIt2 by OldTimer (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe).
Save it to your desktop.
Please double-click OTMoveIt2.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
[kill explorer]
C:\Documents and Settings\Derrick McCullough S\wn0004.exe
C:\WINDOWS\system32\hmkvqbjb.dll
purity
[start explorer]
Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
Click the red Moveit! button.
A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
Please download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune.
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
Please visit this web page for instructions for downloading and running ComboFix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
This includes installing the Windows XP Recovery Console in case you have not installed it yet.
For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.
Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.
Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
Thank you for your help. Below are the log files requested.
SDFIX
SDFix: Version 1.184
Run by Administrator on Wed 05/21/2008 at 11:29 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting SecurityProviders Value
Rebooting
Checking Files :
Trojan Files Found:
C:\Documents and Settings\Derrick McCullough S\Application Data\Install.dat - Deleted
Removing Temp Files
ADS Check :
C:\WINDOWS\system32
:lzx32.sys 66600
Total size: 66600 bytes.
system32: deleted 66600 bytes in 1 streams.
Checking for remaining Streams
C:\WINDOWS\system32
No streams found.
Final Check :
catchme 0.3.1359.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-21 23:52:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0a\\waol.exe"="C:\\Program Files\\America Online 9.0a\\waol.exe:*:Enabled:America Online 9.0a"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Common Files\\AOL\\1153457330\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1153457330\\ee\\aolsoftware.exe:*:Enabled:AOL Shared Components"
"C:\\WINDOWS\\system32\\fgvgcvhe.exe"="C:\\WINDOWS\\system32\\fgv"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\ocvyprne.exe"="C:\\WINDOWS\\system32\\ocv"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0a\\waol.exe"="C:\\Program Files\\America Online 9.0a\\waol.exe:*:Enabled:America Online 9.0a"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Wed 1 Sep 2004 54,384 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe"
Wed 1 Sep 2004 156,784 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe"
Wed 1 Sep 2004 31,344 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe"
Wed 1 Sep 2004 54,384 A..H. --- "C:\Program Files\America Online 9.0a\aolphx.exe"
Wed 1 Sep 2004 156,784 A..H. --- "C:\Program Files\America Online 9.0a\aoltray.exe"
Wed 1 Sep 2004 31,344 A..H. --- "C:\Program Files\America Online 9.0a\RBM.exe"
Thu 13 May 2004 2,710,348 A..H. --- "C:\Program Files\iLuminaStarter\iLuminaInstaller.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Fri 8 Jun 2007 1,386,292 A.SH. --- "C:\WINDOWS\addins\cbodnwi.tmp"
Mon 1 Oct 2007 2,109,734 ..SH. --- "C:\WINDOWS\addins\cbodnwi.bak1"
Mon 1 Oct 2007 2,109,071 ..SH. --- "C:\WINDOWS\addins\cbodnwi.bak2"
Thu 29 Sep 2005 952 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Tue 11 Apr 2006 370,715 ..SH. --- "C:\WINDOWS\system32\oqtss.tmp"
Thu 28 Jun 2007 27,648 ...H. --- "C:\Documents and Settings\Derrick McCullough S\My Documents\~WRL0757.tmp"
Tue 22 Aug 2006 30,208 ...H. --- "C:\Documents and Settings\Derrick McCullough S\My Documents\~WRL1135.tmp"
Sun 27 Jan 2008 271 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti68.tmp"
Tue 15 Apr 2008 20,487 A.SHR --- "C:\Program Files\McAfee\MQC\MRU.bak"
Tue 15 Apr 2008 265 A.SHR --- "C:\Program Files\McAfee\MQC\qcconf.bak"
Mon 12 Feb 2007 3,096,576 A..H. --- "C:\Documents and Settings\Administrator\Application Data\U3\temp\Launchpad Removal.exe"
Mon 24 Oct 2005 27,648 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Templates\~WRL3065.tmp"
Sun 8 Apr 2007 29,184 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0001.tmp"
Wed 14 Dec 2005 20,480 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0003.tmp"
Sun 1 Jan 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0004.tmp"
Thu 15 Dec 2005 20,992 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0005.tmp"
Thu 26 Jan 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0006.tmp"
Tue 14 Feb 2006 24,064 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0007.tmp"
Wed 29 Nov 2006 20,992 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0008.tmp"
Sat 9 Dec 2006 19,968 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0009.tmp"
Sat 7 Apr 2007 28,672 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0010.tmp"
Sun 1 Jan 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0096.tmp"
Sun 1 Jan 2006 20,480 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0141.tmp"
Thu 26 Jan 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0143.tmp"
Fri 30 Jun 2006 20,480 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0397.tmp"
Sat 21 Jan 2006 21,504 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0420.tmp"
Tue 14 Feb 2006 22,528 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0598.tmp"
Sat 9 Dec 2006 23,552 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0680.tmp"
Sat 21 Jan 2006 25,088 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0692.tmp"
Sun 19 Feb 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL0898.tmp"
Fri 30 Jun 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL1122.tmp"
Thu 15 Dec 2005 21,504 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL1244.tmp"
Mon 27 Feb 2006 26,112 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL1294.tmp"
Sat 21 Jan 2006 21,504 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL1405.tmp"
Fri 30 Jun 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL1842.tmp"
Sat 21 Jan 2006 24,064 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2118.tmp"
Sat 9 Dec 2006 20,992 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2221.tmp"
Thu 26 Jan 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2224.tmp"
Mon 20 Feb 2006 19,968 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2227.tmp"
Thu 21 Dec 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2309.tmp"
Thu 26 Jan 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2329.tmp"
Sun 19 Feb 2006 19,968 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2347.tmp"
Wed 29 Nov 2006 31,744 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2401.tmp"
Thu 15 Dec 2005 21,504 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2566.tmp"
Sat 9 Dec 2006 21,504 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2630.tmp"
Sun 19 Feb 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2652.tmp"
Wed 1 Mar 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL2743.tmp"
Sat 21 Jan 2006 24,064 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL3064.tmp"
Sun 19 Feb 2006 18,432 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL3068.tmp"
Sun 19 Feb 2006 19,968 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL3531.tmp"
Sat 9 Dec 2006 20,480 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL3612.tmp"
Sun 19 Feb 2006 19,456 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL3716.tmp"
Thu 15 Dec 2005 21,504 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL3733.tmp"
Sat 9 Dec 2006 23,552 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL3736.tmp"
Mon 27 Feb 2006 26,624 ...H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Microsoft\Word\~WRL3940.tmp"
Sat 9 Feb 2008 8 A..H. --- "C:\Documents and Settings\Brian McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sat 9 Feb 2008 8 A..H. --- "C:\Documents and Settings\Brian McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sat 9 Feb 2008 8 A..H. --- "C:\Documents and Settings\Brian McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sat 9 Feb 2008 8 A..H. --- "C:\Documents and Settings\Brian McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Fri 29 Feb 2008 8 A..H. --- "C:\Documents and Settings\Darius McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Fri 9 May 2008 8 A..H. --- "C:\Documents and Settings\Darius McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Fri 9 May 2008 8 A..H. --- "C:\Documents and Settings\Darius McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Fri 9 May 2008 8 A..H. --- "C:\Documents and Settings\Darius McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Mon 21 Jan 2008 8 A..H. --- "C:\Documents and Settings\Demetrius McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Mon 21 Jan 2008 8 A..H. --- "C:\Documents and Settings\Demetrius McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Mon 21 Jan 2008 8 A..H. --- "C:\Documents and Settings\Demetrius McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Mon 21 Jan 2008 8 A..H. --- "C:\Documents and Settings\Demetrius McCullough\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Fri 13 Apr 2007 8 A..H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Fri 13 Apr 2007 8 A..H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Fri 13 Apr 2007 8 A..H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Fri 13 Apr 2007 8 A..H. --- "C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Finished!
OTMoveIt2
Explorer killed successfully
C:\Documents and Settings\Derrick McCullough S\wn0004.exe moved successfully.
File/Folder C:\WINDOWS\system32\hmkvqbjb.dll not found.
< purity >
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05222008_001841
ComboFix
ComboFix 08-05-21.2 - Derrick McCullough S 2008-05-22 0:58:24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.177 [GMT -5:00]
Running from: C:\Downloads\Anti-Malware\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\btpwaijq.ini
C:\WINDOWS\system32\buknqpnj.ini
C:\WINDOWS\system32\ccrsdfpa.ini
C:\WINDOWS\system32\dmainogv.ini
C:\WINDOWS\system32\fhnpgkbq.ini
C:\WINDOWS\system32\hnubddkw.ini
C:\WINDOWS\system32\jrgeljjv.ini
C:\WINDOWS\system32\laeffmfa.ini
C:\WINDOWS\system32\ldigjwhh.ini
C:\WINDOWS\system32\letcjdor.ini
C:\WINDOWS\system32\lheflivs.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mmsvbuuq.ini
C:\WINDOWS\system32\mvnshpje.ini
C:\WINDOWS\system32\oeqksins.ini
C:\WINDOWS\system32\yqqyiqnx.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2008-04-22 to 2008-05-22 )))))))))))))))))))))))))))))))
.
2100-02-23 18:55 . 2001-05-17 16:06 1,096 --a------ C:\WINDOWS\Lexmark_ICM.ini
2008-05-22 00:52 . 2008-05-22 00:52 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-05-22 00:52 . 2008-05-22 00:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-22 00:18 . 2008-05-22 00:18 <DIR> d----c--- C:\_OTMoveIt
2008-05-21 23:23 . 2008-05-21 23:24 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-21 23:14 . 2008-05-21 23:56 <DIR> d----c--- C:\SDFix
2008-05-21 13:36 . 2008-05-21 13:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-21 00:43 . 2008-05-21 00:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-21 00:43 . 2008-05-21 00:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-20 22:37 . 2008-05-20 22:37 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-20 22:37 . 2008-05-20 22:37 2,561 --a------ C:\WINDOWS\unins000.dat
2008-05-18 22:16 . 2008-05-18 22:16 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-18 22:14 . 2008-05-18 22:14 <DIR> d----c--- C:\Downloads
2008-05-18 22:00 . 2008-05-18 22:04 <DIR> d----c--- C:\McAfee CommandLine Scanner
2008-05-16 01:28 . 2008-05-16 07:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-05-15 19:49 . 2008-05-15 19:52 <DIR> d----c--- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 06:06 --------- d-----w C:\Program Files\SiteAdvisor
2008-05-21 19:21 --------- d-----w C:\Documents and Settings\Derrick McCullough S\Application Data\SiteAdvisor
2008-05-21 03:44 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-19 05:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-19 03:51 --------- d-----w C:\Program Files\Google
2008-04-25 20:59 --------- d-----w C:\Documents and Settings\Brian McCullough\Application Data\SiteAdvisor
2008-04-17 04:12 --------- d-----w C:\Program Files\McAfee
2008-04-15 21:45 90,112 ----a-w C:\WINDOWS\DUMP445c.tmp
2007-06-22 17:02 2 ----a-w C:\Documents and Settings\Derrick McCullough S\Application Data\xxx.exe
2007-10-01 06:48 2,109,734 --sh--w C:\WINDOWS\addins\cbodnwi.bak1
2007-10-01 06:47 2,109,071 --sh--w C:\WINDOWS\addins\cbodnwi.bak2
2007-10-09 07:17 13,682 --sh--w C:\WINDOWS\addins\cbodnwi.ini2
2005-09-29 17:24 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E865B01A-6012-450B-B857-45F06026BC0B}]
C:\WINDOWS\addins\iwndobc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"LaserJet"="C:\WINDOWS\system32\spoolvs.exe" [ ]
"findfast"="C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01 110592]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-03-12 07:25 110592]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-03-25 20:08 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"lxamsp32.exe"="lxamsp32.exe" [2001-10-21 19:12 45056 C:\WINDOWS\system32\LXAMSP32.EXE]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-21 16:54 36864]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 15:09 57344]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2006-07-24 15:28 35992]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AcBtnMgr_X63.exe.lnk - C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe [2001-06-06 15:03:10 53248]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ACMonitor_X63.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ACMonitor_X63.exe.lnk
backup=C:\WINDOWS\pss\ACMonitor_X63.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0057821187508148mcinstcleanup]
C:\DOCUME~1\DERRIC~1\LOCALS~1\Temp\005782~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2004-09-13 17:33 155648 C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-12-03 22:00 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 2004-11-10 12:54 598016 C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2004-10-12 17:54 57344 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\findfast]
C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1153457330\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2004-10-30 15:59 385024 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a------ 2005-03-12 07:25 11776 C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--------- 2004-04-11 21:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
C:\WINDOWS\system32\sniskqeo.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2003-11-19 18:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\America Online 9.0a\\waol.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\1153457330\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-01-22 01:22:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-09 23:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (D43P3271-Derrick McCullough S).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2007-12-15 07:00:00 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2007-12-01 07:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe.4158 0
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-22 01:05:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6261\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-05-22 1:10:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-22 06:10:08
Pre-Run: 13,533,442,048 bytes free
Post-Run: 13,549,617,152 bytes free
215 --- E O F --- 2008-05-16 11:45:09
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:20:21 AM, on 5/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\lxamsp32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {E865B01A-6012-450B-B857-45F06026BC0B} - C:\WINDOWS\addins\iwndobc.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LaserJet] C:\WINDOWS\system32\spoolvs.exe
O4 - HKCU\..\Run: [findfast] C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe
O4 - Startup: findfast.lnk = C:\Documents and Settings\Derrick McCullough S\Local Settings\Temp\us0001.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 9131 bytes
Thank you,
ajweg
Rorschach112
2008-05-22, 16:25
Hello
1. Close any open browsers.
2. Open notepad and copy/paste the text in the quotebox below into it:
File::
C:\WINDOWS\addins\cbodnwi.tmp
C:\WINDOWS\addins\cbodnwi.bak1
C:\WINDOWS\addins\cbodnwi.bak2
C:\WINDOWS\system32\oqtss.tmp
C:\WINDOWS\addins\cbodnwi.ini2
Folder::
Registry::
Driver::
Save this as CFScript.txt, in the same location as ComboFix.exe
http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Also post a new HijackThis log
Hello,
Here are the 2 logs.
ComboFix
ComboFix 08-05-21.2 - Derrick McCullough S 2008-05-22 9:25:42.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.174 [GMT -5:00]
Running from: C:\Downloads\Anti-Malware\ComboFix.exe
Command switches used :: C:\Downloads\Anti-Malware\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\addins\cbodnwi.bak1
C:\WINDOWS\addins\cbodnwi.bak2
C:\WINDOWS\addins\cbodnwi.ini2
C:\WINDOWS\addins\cbodnwi.tmp
C:\WINDOWS\system32\oqtss.tmp
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\addins\cbodnwi.bak1
C:\WINDOWS\addins\cbodnwi.bak2
C:\WINDOWS\addins\cbodnwi.ini2
C:\WINDOWS\addins\cbodnwi.tmp
C:\WINDOWS\system32\oqtss.tmp
.
((((((((((((((((((((((((( Files Created from 2008-04-22 to 2008-05-22 )))))))))))))))))))))))))))))))
.
2100-02-23 18:55 . 2001-05-17 16:06 1,096 --a------ C:\WINDOWS\Lexmark_ICM.ini
2008-05-22 00:52 . 2008-05-22 00:52 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-05-22 00:52 . 2008-05-22 00:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-22 00:18 . 2008-05-22 00:18 <DIR> d----c--- C:\_OTMoveIt
2008-05-21 23:23 . 2008-05-21 23:24 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-21 23:14 . 2008-05-21 23:56 <DIR> d----c--- C:\SDFix
2008-05-21 13:36 . 2008-05-21 13:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-21 00:43 . 2008-05-21 00:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-21 00:43 . 2008-05-21 00:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-20 22:37 . 2008-05-20 22:37 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-20 22:37 . 2008-05-20 22:37 2,561 --a------ C:\WINDOWS\unins000.dat
2008-05-18 22:16 . 2008-05-18 22:16 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-18 22:14 . 2008-05-18 22:14 <DIR> d----c--- C:\Downloads
2008-05-18 22:00 . 2008-05-18 22:04 <DIR> d----c--- C:\McAfee CommandLine Scanner
2008-05-16 01:28 . 2008-05-16 07:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-05-15 19:49 . 2008-05-15 19:52 <DIR> d----c--- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 06:07 --------- d-----w C:\Program Files\SiteAdvisor
2008-05-21 19:21 --------- d-----w C:\Documents and Settings\Derrick McCullough S\Application Data\SiteAdvisor
2008-05-21 03:44 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-19 05:49 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-19 05:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-19 03:51 --------- d-----w C:\Program Files\Google
2008-04-25 20:59 --------- d-----w C:\Documents and Settings\Brian McCullough\Application Data\SiteAdvisor
2008-04-17 04:12 --------- d-----w C:\Program Files\McAfee
2008-04-15 21:45 90,112 ----a-w C:\WINDOWS\DUMP445c.tmp
2008-04-02 21:45 2,750 ----a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2005-09-29 17:24 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-05-22_ 1.09.43.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-22 06:03:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-22 14:16:44 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-22 04:17:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-05-22 12:19:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-05-22 04:17:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-05-22 12:19:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-05-22 04:17:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-22 12:19:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E865B01A-6012-450B-B857-45F06026BC0B}]
C:\WINDOWS\addins\iwndobc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"LaserJet"="C:\WINDOWS\system32\spoolvs.exe" [ ]
"findfast"="C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01 110592]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-03-12 07:25 110592]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-03-25 20:08 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"lxamsp32.exe"="lxamsp32.exe" [2001-10-21 19:12 45056 C:\WINDOWS\system32\LXAMSP32.EXE]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-21 16:54 36864]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 15:09 57344]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2006-07-24 15:28 35992]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AcBtnMgr_X63.exe.lnk - C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe [2001-06-06 15:03:10 53248]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ACMonitor_X63.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ACMonitor_X63.exe.lnk
backup=C:\WINDOWS\pss\ACMonitor_X63.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0057821187508148mcinstcleanup]
C:\DOCUME~1\DERRIC~1\LOCALS~1\Temp\005782~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2004-09-13 17:33 155648 C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-12-03 22:00 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 2004-11-10 12:54 598016 C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2004-10-12 17:54 57344 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\findfast]
C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1153457330\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2004-10-30 15:59 385024 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a------ 2005-03-12 07:25 11776 C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--------- 2004-04-11 21:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
C:\WINDOWS\system32\sniskqeo.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2003-11-19 18:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\America Online 9.0a\\waol.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\1153457330\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-01-22 01:22:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-09 23:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (D43P3271-Derrick McCullough S).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2007-12-15 07:00:00 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2007-12-01 07:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe.4158 0
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-22 09:28:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-22 9:29:52
ComboFix-quarantined-files.txt 2008-05-22 14:29:43
ComboFix2.txt 2008-05-22 06:10:23
Pre-Run: 13,538,553,856 bytes free
Post-Run: 13,533,163,520 bytes free
185 --- E O F --- 2008-05-16 11:45:09
HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:33:12 AM, on 5/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\system32\lxamsp32.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {E865B01A-6012-450B-B857-45F06026BC0B} - C:\WINDOWS\addins\iwndobc.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LaserJet] C:\WINDOWS\system32\spoolvs.exe
O4 - HKCU\..\Run: [findfast] C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe
O4 - Startup: findfast.lnk = C:\Documents and Settings\Derrick McCullough S\Local Settings\Temp\us0001.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 9042 bytes
Rorschach112
2008-05-22, 17:52
Hello
1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):
O2 - BHO: (no name) - {E865B01A-6012-450B-B857-45F06026BC0B} - C:\WINDOWS\addins\iwndobc.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.
1. Close any open browsers.
2. Open notepad and copy/paste the text in the quotebox below into it:
File::
C:\WINDOWS\system32\sniskqeo.dll
Folder::
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
Driver::
Save this as CFScript.txt, in the same location as ComboFix.exe
http://i266.photobucket.com/albums/ii277/sUBs_/Combo-Do.gif
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Please do an online scan with Kaspersky WebScanner (http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html)
Click on Kaspersky Online Scanner and click Accept
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading the latest definition files:
Once the files have been downloaded click on NEXT
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan:Select My Computer
This will program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.
Also post a new HijackThis log
Hello,
I ran the HJT scan only and fixed the 2 entries you listed. Below are the log files you requested. Thanks for all your help with this.
ComboFix
ComboFix 08-05-21.2 - Derrick McCullough S 2008-05-22 10:17:03.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.169 [GMT -5:00]
Running from: C:\Downloads\Anti-Malware\ComboFix.exe
Command switches used :: C:\Downloads\Anti-Malware\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\sniskqeo.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-22 to 2008-05-22 )))))))))))))))))))))))))))))))
.
2100-02-23 18:55 . 2001-05-17 16:06 1,096 --a------ C:\WINDOWS\Lexmark_ICM.ini
2008-05-22 00:52 . 2008-05-22 00:52 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-05-22 00:52 . 2008-05-22 00:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-22 00:18 . 2008-05-22 00:18 <DIR> d----c--- C:\_OTMoveIt
2008-05-21 23:23 . 2008-05-21 23:24 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-21 23:14 . 2008-05-21 23:56 <DIR> d----c--- C:\SDFix
2008-05-21 13:36 . 2008-05-21 13:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-21 00:43 . 2008-05-21 00:43 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-21 00:43 . 2008-05-21 00:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-20 22:37 . 2008-05-20 22:37 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-20 22:37 . 2008-05-20 22:37 2,561 --a------ C:\WINDOWS\unins000.dat
2008-05-18 22:16 . 2008-05-18 22:16 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-18 22:14 . 2008-05-18 22:14 <DIR> d----c--- C:\Downloads
2008-05-18 22:00 . 2008-05-18 22:04 <DIR> d----c--- C:\McAfee CommandLine Scanner
2008-05-16 01:28 . 2008-05-16 07:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-05-15 19:49 . 2008-05-15 19:52 <DIR> d----c--- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 06:07 --------- d-----w C:\Program Files\SiteAdvisor
2008-05-21 19:21 --------- d-----w C:\Documents and Settings\Derrick McCullough S\Application Data\SiteAdvisor
2008-05-21 03:44 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-19 05:49 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-19 05:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-19 03:51 --------- d-----w C:\Program Files\Google
2008-04-25 20:59 --------- d-----w C:\Documents and Settings\Brian McCullough\Application Data\SiteAdvisor
2008-04-17 04:12 --------- d-----w C:\Program Files\McAfee
2008-04-15 21:45 90,112 ----a-w C:\WINDOWS\DUMP445c.tmp
2008-04-02 21:45 2,750 ----a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2005-09-29 17:24 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-05-22_ 1.09.43.18 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-22 06:03:24 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-22 14:16:44 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-22 04:17:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-05-22 12:19:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-05-22 04:17:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-05-22 12:19:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-05-22 04:17:20 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-22 12:19:47 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09 460784]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"LaserJet"="C:\WINDOWS\system32\spoolvs.exe" [ ]
"findfast"="C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01 110592]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-03-12 07:25 110592]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-03-25 20:08 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"lxamsp32.exe"="lxamsp32.exe" [2001-10-21 19:12 45056 C:\WINDOWS\system32\LXAMSP32.EXE]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-21 16:54 36864]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 15:09 57344]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2006-07-24 15:28 35992]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AcBtnMgr_X63.exe.lnk - C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe [2001-06-06 15:03:10 53248]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 17:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ACMonitor_X63.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ACMonitor_X63.exe.lnk
backup=C:\WINDOWS\pss\ACMonitor_X63.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0057821187508148mcinstcleanup]
C:\DOCUME~1\DERRIC~1\LOCALS~1\Temp\005782~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
-ra------ 2006-10-23 07:50 71216 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2004-09-13 17:33 155648 C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-12-03 22:00 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 2004-11-10 12:54 598016 C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 11:09 460784 C:\Program Files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2004-10-12 17:54 57344 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\findfast]
C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2006-09-25 19:52 50736 C:\Program Files\Common Files\AOL\1153457330\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2004-10-30 15:59 385024 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a------ 2005-03-12 07:25 11776 C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--------- 2004-04-11 21:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2003-11-19 18:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\America Online 9.0a\\waol.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Common Files\\AOL\\1153457330\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-01-22 01:22:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-09 23:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (D43P3271-Derrick McCullough S).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
"2007-12-15 07:00:00 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2007-12-01 07:00:01 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe.4158 0
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-22 10:19:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6261\saHook.dll
.
Completion time: 2008-05-22 10:20:46
ComboFix-quarantined-files.txt 2008-05-22 15:20:29
ComboFix2.txt 2008-05-22 14:29:53
ComboFix3.txt 2008-05-22 06:10:23
Pre-Run: 13,513,596,928 bytes free
Post-Run: 13,509,308,416 bytes free
174 --- E O F --- 2008-05-16 11:45:09
Kapersky
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, May 22, 2008 11:28:22 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/05/2008
Kaspersky Anti-Virus database records: 795111
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 62918
Number of viruses found: 2
Number of infected objects: 4
Number of suspicious objects: 0
Duration of the scan process: 00:59:18
Infected Object Name / Virus Name / Last Action
C:\22caee060e80142803040f\$shtdwn$.req Object is locked skipped
C:\22caee060e80142803040f\admparse.dll Object is locked skipped
C:\22caee060e80142803040f\admparse.dll.mui Object is locked skipped
C:\22caee060e80142803040f\advpack.dll Object is locked skipped
C:\22caee060e80142803040f\advpack.dll.mui Object is locked skipped
C:\22caee060e80142803040f\browseui.dll Object is locked skipped
C:\22caee060e80142803040f\corpol.dll Object is locked skipped
C:\22caee060e80142803040f\custsat.dll Object is locked skipped
C:\22caee060e80142803040f\dxtmsft.dll Object is locked skipped
C:\22caee060e80142803040f\dxtrans.dll Object is locked skipped
C:\22caee060e80142803040f\extmgr.dll Object is locked skipped
C:\22caee060e80142803040f\extmgr.dll.mui Object is locked skipped
C:\22caee060e80142803040f\feeddisc.wav Object is locked skipped
C:\22caee060e80142803040f\hmmapi.dll Object is locked skipped
C:\22caee060e80142803040f\hmmapi.dll.mui Object is locked skipped
C:\22caee060e80142803040f\html.iec Object is locked skipped
C:\22caee060e80142803040f\html.iec.mui Object is locked skipped
C:\22caee060e80142803040f\icardie.dll Object is locked skipped
C:\22caee060e80142803040f\icardie.dll.mui Object is locked skipped
C:\22caee060e80142803040f\icrav03.rat Object is locked skipped
C:\22caee060e80142803040f\ie4uinit.exe Object is locked skipped
C:\22caee060e80142803040f\ie4uinit.exe.mui Object is locked skipped
C:\22caee060e80142803040f\ieakeng.dll Object is locked skipped
C:\22caee060e80142803040f\ieakeng.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieakmmc.chm Object is locked skipped
C:\22caee060e80142803040f\ieaksie.dll Object is locked skipped
C:\22caee060e80142803040f\ieaksie.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieakui.dll Object is locked skipped
C:\22caee060e80142803040f\ieakui.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieapfltr.dat Object is locked skipped
C:\22caee060e80142803040f\ieapfltr.dll Object is locked skipped
C:\22caee060e80142803040f\iedkcs32.dll Object is locked skipped
C:\22caee060e80142803040f\iedkcs32.dll.mui Object is locked skipped
C:\22caee060e80142803040f\iedw.exe Object is locked skipped
C:\22caee060e80142803040f\iedw.exe.mui Object is locked skipped
C:\22caee060e80142803040f\ieencode.dll Object is locked skipped
C:\22caee060e80142803040f\ieeula.chm Object is locked skipped
C:\22caee060e80142803040f\ieframe.dll Object is locked skipped
C:\22caee060e80142803040f\ieframe.dll.mui Object is locked skipped
C:\22caee060e80142803040f\iepeers.dll Object is locked skipped
C:\22caee060e80142803040f\iepeers.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieproxy.dll Object is locked skipped
C:\22caee060e80142803040f\iernonce.dll Object is locked skipped
C:\22caee060e80142803040f\iernonce.dll.mui Object is locked skipped
C:\22caee060e80142803040f\iertutil.dll Object is locked skipped
C:\22caee060e80142803040f\iesetup.dll Object is locked skipped
C:\22caee060e80142803040f\iesetup.dll.mui Object is locked skipped
C:\22caee060e80142803040f\iesupp.chm Object is locked skipped
C:\22caee060e80142803040f\ieudinit.exe Object is locked skipped
C:\22caee060e80142803040f\ieui.dll Object is locked skipped
C:\22caee060e80142803040f\ieui.dll.mui Object is locked skipped
C:\22caee060e80142803040f\ieuinit.inf Object is locked skipped
C:\22caee060e80142803040f\ieunatt.exe.mui Object is locked skipped
C:\22caee060e80142803040f\iexplore.chm Object is locked skipped
C:\22caee060e80142803040f\iexplore.exe Object is locked skipped
C:\22caee060e80142803040f\iexplore.exe.mui Object is locked skipped
C:\22caee060e80142803040f\imgutil.dll Object is locked skipped
C:\22caee060e80142803040f\inetcorp.iem Object is locked skipped
C:\22caee060e80142803040f\inetcpl.cpl Object is locked skipped
C:\22caee060e80142803040f\inetcpl.cpl.mui Object is locked skipped
C:\22caee060e80142803040f\inetres.adm Object is locked skipped
C:\22caee060e80142803040f\inetset.iem Object is locked skipped
C:\22caee060e80142803040f\infobar.wav Object is locked skipped
C:\22caee060e80142803040f\inseng.dll Object is locked skipped
C:\22caee060e80142803040f\inseng.dll.mui Object is locked skipped
C:\22caee060e80142803040f\install.ins Object is locked skipped
C:\22caee060e80142803040f\jscript.dll Object is locked skipped
C:\22caee060e80142803040f\jsproxy.dll Object is locked skipped
C:\22caee060e80142803040f\licmgr10.dll Object is locked skipped
C:\22caee060e80142803040f\licmgr10.dll.mui Object is locked skipped
C:\22caee060e80142803040f\msfeeds.dll Object is locked skipped
C:\22caee060e80142803040f\msfeeds.mof Object is locked skipped
C:\22caee060e80142803040f\msfeedsbs.dll Object is locked skipped
C:\22caee060e80142803040f\msfeedsbs.dll.mui Object is locked skipped
C:\22caee060e80142803040f\msfeedsbs.mof Object is locked skipped
C:\22caee060e80142803040f\msfeedssync.exe Object is locked skipped
C:\22caee060e80142803040f\mshta.exe Object is locked skipped
C:\22caee060e80142803040f\mshta.exe.mui Object is locked skipped
C:\22caee060e80142803040f\mshtml.dll Object is locked skipped
C:\22caee060e80142803040f\mshtml.dll.mui Object is locked skipped
C:\22caee060e80142803040f\mshtml.tlb Object is locked skipped
C:\22caee060e80142803040f\mshtmled.dll Object is locked skipped
C:\22caee060e80142803040f\mshtmled.dll.mui Object is locked skipped
C:\22caee060e80142803040f\mshtmler.dll Object is locked skipped
C:\22caee060e80142803040f\mshtmler.dll.mui Object is locked skipped
C:\22caee060e80142803040f\msls31.dll Object is locked skipped
C:\22caee060e80142803040f\msrating.dll Object is locked skipped
C:\22caee060e80142803040f\msrating.dll.mui Object is locked skipped
C:\22caee060e80142803040f\mstime.dll Object is locked skipped
C:\22caee060e80142803040f\navstart.wav Object is locked skipped
C:\22caee060e80142803040f\occache.dll Object is locked skipped
C:\22caee060e80142803040f\occache.dll.mui Object is locked skipped
C:\22caee060e80142803040f\occache.ini Object is locked skipped
C:\22caee060e80142803040f\pngfilt.dll Object is locked skipped
C:\22caee060e80142803040f\popupblk.wav Object is locked skipped
C:\22caee060e80142803040f\shdocvw.dll Object is locked skipped
C:\22caee060e80142803040f\shlwapi.dll Object is locked skipped
C:\22caee060e80142803040f\spmsg.dll Object is locked skipped
C:\22caee060e80142803040f\spuninst.exe Object is locked skipped
C:\22caee060e80142803040f\spupdsvc.exe Object is locked skipped
C:\22caee060e80142803040f\tdc.ocx Object is locked skipped
C:\22caee060e80142803040f\ticrf.rat Object is locked skipped
C:\22caee060e80142803040f\update\eula.rtf Object is locked skipped
C:\22caee060e80142803040f\update\idndl.exe Object is locked skipped
C:\22caee060e80142803040f\update\ie7.cat Object is locked skipped
C:\22caee060e80142803040f\update\iecustom.dll Object is locked skipped
C:\22caee060e80142803040f\update\iereseticons.exe Object is locked skipped
C:\22caee060e80142803040f\update\iesetup.exe Object is locked skipped
C:\22caee060e80142803040f\update\legitlibm.dll Object is locked skipped
C:\22caee060e80142803040f\update\nlsdl.exe Object is locked skipped
C:\22caee060e80142803040f\update\update.exe Object is locked skipped
C:\22caee060e80142803040f\update\update.exe.manifest Object is locked skipped
C:\22caee060e80142803040f\update\update.inf Object is locked skipped
C:\22caee060e80142803040f\update\update.ver Object is locked skipped
C:\22caee060e80142803040f\update\updspapi.dll Object is locked skipped
C:\22caee060e80142803040f\update\xmllitesetup.exe Object is locked skipped
C:\22caee060e80142803040f\url.dll Object is locked skipped
C:\22caee060e80142803040f\urlmon.dll Object is locked skipped
C:\22caee060e80142803040f\urlmon.dll.mui Object is locked skipped
C:\22caee060e80142803040f\vbscript.dll Object is locked skipped
C:\22caee060e80142803040f\vgx.dll Object is locked skipped
C:\22caee060e80142803040f\webcheck.dll Object is locked skipped
C:\22caee060e80142803040f\webcheck.dll.mui Object is locked skipped
C:\22caee060e80142803040f\webcheck.ini Object is locked skipped
C:\22caee060e80142803040f\winfxdocobj.exe Object is locked skipped
C:\22caee060e80142803040f\winfxdocobj.exe.mui Object is locked skipped
C:\22caee060e80142803040f\wininet.dll Object is locked skipped
C:\22caee060e80142803040f\wininet.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\$shtdwn$.req Object is locked skipped
C:\aa68eaea23d0e7dedbde61\admparse.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\admparse.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\advpack.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\advpack.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\browseui.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\corpol.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\custsat.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\dxtmsft.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\dxtrans.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\extmgr.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\extmgr.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\feeddisc.wav Object is locked skipped
C:\aa68eaea23d0e7dedbde61\hmmapi.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\hmmapi.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\html.iec Object is locked skipped
C:\aa68eaea23d0e7dedbde61\html.iec.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\icardie.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\icardie.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\icrav03.rat Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ie4uinit.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ie4uinit.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakeng.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakeng.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakmmc.chm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieaksie.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieaksie.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakui.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieakui.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieapfltr.dat Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieapfltr.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iedkcs32.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iedkcs32.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iedw.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iedw.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieencode.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieeula.chm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieframe.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieframe.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iepeers.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iepeers.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieproxy.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iernonce.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iernonce.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iertutil.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iesetup.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iesetup.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iesupp.chm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieudinit.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieui.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieui.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieuinit.inf Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ieunatt.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iexplore.chm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iexplore.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\iexplore.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\imgutil.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetcorp.iem Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetcpl.cpl Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetcpl.cpl.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetres.adm Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inetset.iem Object is locked skipped
C:\aa68eaea23d0e7dedbde61\infobar.wav Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inseng.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\inseng.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\install.ins Object is locked skipped
C:\aa68eaea23d0e7dedbde61\jscript.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\jsproxy.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\licmgr10.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\licmgr10.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeeds.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeeds.mof Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeedsbs.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeedsbs.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeedsbs.mof Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msfeedssync.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshta.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshta.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtml.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtml.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtml.tlb Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtmled.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtmled.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtmler.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mshtmler.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msls31.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msrating.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\msrating.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\mstime.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\navstart.wav Object is locked skipped
C:\aa68eaea23d0e7dedbde61\occache.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\occache.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\occache.ini Object is locked skipped
C:\aa68eaea23d0e7dedbde61\pngfilt.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\popupblk.wav Object is locked skipped
C:\aa68eaea23d0e7dedbde61\shdocvw.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\shlwapi.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\spmsg.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\spuninst.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\spupdsvc.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\tdc.ocx Object is locked skipped
C:\aa68eaea23d0e7dedbde61\ticrf.rat Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\eula.rtf Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\idndl.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\ie7.cat Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\iecustom.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\iereseticons.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\iesetup.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\legitlibm.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\nlsdl.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\update.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\update.exe.manifest Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\update.inf Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\update.ver Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\updspapi.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\update\xmllitesetup.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\url.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\urlmon.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\urlmon.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\vbscript.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\vgx.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\webcheck.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\webcheck.dll.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\webcheck.ini Object is locked skipped
C:\aa68eaea23d0e7dedbde61\winfxdocobj.exe Object is locked skipped
C:\aa68eaea23d0e7dedbde61\winfxdocobj.exe.mui Object is locked skipped
C:\aa68eaea23d0e7dedbde61\wininet.dll Object is locked skipped
C:\aa68eaea23d0e7dedbde61\wininet.dll.mui Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{75F53070-80FD-4E1A-B439-0617FB07FAE5}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\History\History.IE5\MSHist012008052220080523\index.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Temp\~DFFD8F.tmp Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\ntuser.dat Object is locked skipped
C:\Documents and Settings\Derrick McCullough S\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\catchme2008-05-22_ 10509.60.zip/Documents and Settings/Administrator/Desktop/catchme.zip/lzx32.sys Infected: Trojan-Clicker.Win32.Costrat.e skipped
C:\QooBox\Quarantine\catchme2008-05-22_ 10509.60.zip/Documents and Settings/Administrator/Desktop/catchme.zip Infected: Trojan-Clicker.Win32.Costrat.e skipped
C:\QooBox\Quarantine\catchme2008-05-22_ 10509.60.zip ZIP: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP4\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcmsc_91gEmVoXoqEQViF Object is locked skipped
C:\WINDOWS\Temp\mcmsc_c6dYWORXfdjpHCb Object is locked skipped
C:\WINDOWS\Temp\mcmsc_zwU7k2BQmgQyPeP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\_OTMoveIt\MovedFiles\05222008_001841\Documents and Settings\Derrick McCullough S\wn0004.exe Infected: not-virus:Hoax.Win32.Renos.gk skipped
Scan process completed.
HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:33:02 AM, on 5/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\system32\lxamsp32.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LaserJet] C:\WINDOWS\system32\spoolvs.exe
O4 - HKCU\..\Run: [findfast] C:\Documents and Settings\Derrick McCullough S\Application Data\findfast.exe
O4 - Startup: findfast.lnk = C:\Documents and Settings\Derrick McCullough S\Local Settings\Temp\us0001.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} -
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 8823 bytes
Rorschach112
2008-05-23, 00:26
Your logs are clean
Follow these steps to uninstall Combofix and tools used in the removal of malware
Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png
You now need to update your Java and remove your older versions.
Please follow these steps to remove older version Java components.
* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.
Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here (http://java.sun.com/javase/downloads/index.jsp)
Make sure you have an Internet Connection.
Double-click OTMoveIt2.exe to run it.
Click on the CleanUp! button
A list of tool components used in the Cleanup of malware will be downloaded.
If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
Click Yes to beging the Cleanup process and remove these components, including this application.
You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com/products/acrobat/readstep2.html
Below I have included a number of recommendations for how to protect your computer against malware infections.
* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.
* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster (http://www.javacoolsoftware.com/sbdownload.html) protects against bad ActiveX
IE-SPYAD (http://www.spywarewarrior.com/uiuc/res/ie-spyad.exe) puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here (http://www.bleepingcomputer.com/tutorials/tutorial53.html)
* SpywareGuard (http://www.javacoolsoftware.com/sgdownload.html) offers realtime protection from spyware installation attempts.
Make Internet Explorer more secure
Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.
* MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here (http://www.mozilla.org/products/firefox/)
* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here (http://forums.spywareinfo.com/index.php?showtopic=60955)
Thank you very much for your help. I am following the instructions for cleaning up the tools used and will also apply the updates and other software suggested. I will also provide the information for my friend of how to surf safer.
I also learned a lot and did not even know where to start. I have worked tech support for a medical clinic for 7 years but have not had anything this difficult to remove. Each step of the solution was time consuming yet went faster over all than I thought it might. Thank you again for your expertise.
Rorschach112
2008-05-23, 14:55
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.
Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.
If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.