PDA

View Full Version : smitfraud c cache service



karmamoon
2008-08-11, 18:50
hi i just scanned computer and it keeps coming up smitfraud. i can not delete this and have tried several different things. i can not find combo fix log to post but do have hijack log. i also have kaspersky log and am doing malwarebyte scan now. here are logs.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31, on 2008-08-11
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [combofix] C:\Windows\system32\CF15383.exe /c C:\ComboFix\Combobatch.bat
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} -
O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} -
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} -
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} -
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} -
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcz_device - Unknown owner - C:\Windows\system32\lxczcoms.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7162 bytes


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, August 11, 2008
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, August 11, 2008 08:22:56
Records in database: 1081589
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan statistics:
Files scanned: 177795
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 02:04:11


File name / Threat name / Threats count
D:\Program Files\Internet Explorer\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cg 1
D:\Windows\System32\f3PSSavr.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch.bg 1

The selected area was scanned.

I went into system and deleted these threats, but do not know what to do with hijack this info. thanks!

pskelley
2008-08-15, 18:14
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

If you still require help, follow these directions.
1) Review the directions

2) Describe any symptoms of malware

3) From the looks of your HJT log, you should know this:

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use
and this:
The Waiting Room
http://forums.spybot.info/forumdisplay.php?f=37
4) If you want me to look at this, post a fresh HJT log along with any information I requested and any comments you think will help.

Thanks...Phil

karmamoon
2008-08-15, 21:19
yes i have read all instructions and did at my own risk. I still get pop ups for internet explorer, and when i do spybot scan it still has smitfraud on it. computer runs slow at some times or doesnt respond and the constant pop ups drive me crazy. here is a new log and thank you.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:17:03 PM, on 8/15/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} -
O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} -
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} -
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} -
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} -
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7089 bytes

pskelley
2008-08-15, 21:45
Thanks for returning your information and the feedback. Understand, not a lot is showing in the log so the junk is likely hidden and it may take some work to get rid of it. We will start like this.

(remember to run all tools as administrator in Vista)

1) We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:
* Run Spybot-S&D in Advanced Mode.
* If it is not already set to do this Go to the Mode menu select "Advanced Mode"
* On the left hand side, Click on Tools
* Then click on the Resident Icon in the List
* Uncheck "Resident TeaTimer" and OK any prompts.
* Restart your computer.
(leave TT disabled until we finish)

2) Download ResetTeaTimer.bat to the Desktop
http://downloads.subratam.org/ResetTeaTimer.bat
Double click ResetTeaTimer.bat
to remove all entries set by TeaTimer (and preventing TeaTimer to restore them upon reactivation).

3) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O13 - Gopher Prefix:

(if you use any of these, just install them again the next time you visit the site, you will be prompted)

O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} -
O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} -
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} -
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} -
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} -
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
O16 - DPF: {CF969D51-F764-4FBF-9E90-475248601C8A} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

Close all programs but HJT and all browser windows, then click on "Fix Checked"

4) Run Disk Cleanup:
DISK CLEANUP: ALL PROGRAMS > ACCESSORIES > SYSTEM TOOLS > DISK CLEANUP
http://www.lockergnome.com/windows/2006/10/26/disk-cleanup-in-vista/

5) Download Malwarebytes' Anti-Malware to your Desktop
http://www.besttechie.net/tools/mbam-setup.exe

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
* Please post contents of that file & a new HJT log in your next reply.

Let me know how the computer is running now.

Thanks...Phil

karmamoon
2008-08-17, 03:26
hi, ok i did what you said but the tea timer comes up as this unsupported version press any key to exit press any key to continue. i have been having trouble with the malwarebyte program. it keeps freezing up in full scan mode when i get to almost the end of d disk drive scan. i did do quick scan because the items to be removed are on disk c and i did try to delete them. here is the log for that and below is hjt log. thanks
Malwarebytes' Anti-Malware 1.24
Database version: 1040
Windows 6.0.6001 Service Pack 1

8:58:16 PM 8/16/2008
mbam-log-8-16-2008 (20-58-12).txt

Scan type: Quick Scan
Objects scanned: 38534
Time elapsed: 2 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\drivers\parportt.sys (Rootkit.Agent) -> No action taken.
C:\Windows\System32\drivers\core.cache.dsk (Rootkit.Agent) -> No action taken.


it did say that it will try to delete after reboot. nothing came up after reboot though. here is hjt scan log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:18:14 PM, on 8/16/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Windows\ehome\ehmsas.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 6008 bytes

thanks again 4 the help. i can do most things but this is a little tricky.:):p:

pskelley
2008-08-17, 13:37
Good morning, first the good news, I see no malware in this HJT log you just posted, how is the computer performing?

i did what you said but the tea timer comes up as this unsupported, etc.
If you have issues disabling TT, just uninstall Spybot S&D in Add Remove programs. You can reinstall it later, make sure you view this information:
Spybot-S&D 1.6 has arrived! 8. July 2008
http://www.safer-networking.org/en/
http://www.safer-networking.org/en/news/2008-07-08.html

MBAM found two very bad pieces of malware, but it appears you did not delete them?
Files Infected:
C:\Windows\System32\drivers\parportt.sys (Rootkit.Agent) -> No action taken.
C:\Windows\System32\drivers\core.cache.dsk (Rootkit.Agent) -> No action taken.

* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
Run MBAM again, make sure to remove what it finds, post the MBAM log only and some feedback about the computers performance.

C:\Program Files\Alwil Software\Avast4\ <<< I do not see this in running processes? If it is not running you will have no realtime protection. Let me know about this, I can provide another free AV if you can not get Avast4 to run.

Thanks...Phil

karmamoon
2008-08-18, 00:31
hi, thanks again! I tried to remove using malware but it is no use. it will not delete.
Malwarebytes' Anti-Malware 1.24
Database version: 1059
Windows 6.0.6001 Service Pack 1

9:01:03 AM 8/17/2008
mbam-log-8-17-2008 (09-01-03).txt

Scan type: Full Scan (C:\|)
Objects scanned: 116340
Time elapsed: 31 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\drivers\parportt.sys (Rootkit.Agent) -> Delete on reboot.
C:\Windows\System32\drivers\core.cache.dsk (Rootkit.Agent) -> Delete on reboot.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:07:41 AM, on 8/17/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 5971 bytes
i see something new in this log oobefldr.dll that was not in other logs. i have my welcome center disabled so it does not show every day. i also have the sidebar disabled because i dont like it. yeah i dont know how avast4 stopped working it was after i donloaded one of the programs to clean up files.

pskelley
2008-08-18, 00:39
MBAM is asking for you to reboot so it can remove that rookit infection:
Files Infected:
C:\Windows\System32\drivers\parportt.sys (Rootkit.Agent) -> Delete on reboot.
C:\Windows\System32\drivers\core.cache.dsk (Rootkit.Agent) -> Delete on reboot.
restart your computer and scan again to see if they are deleted. Post the MBAM log.


i see something new in this log oobefldr.dll that was not in other logs.
where do you see this?

karmamoon
2008-08-18, 19:30
oh boy, i try and try and it does not remove.

Malwarebytes' Anti-Malware 1.24
Database version: 1059
Windows 6.0.6001 Service Pack 1

11:26:24 PM 8/17/2008
mbam-log-8-17-2008 (23-26-24).txt

Scan type: Full Scan (C:\|)
Objects scanned: 113782
Time elapsed: 33 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\drivers\parportt.sys (Rootkit.Agent) -> Delete on reboot.
C:\Windows\System32\drivers\core.cache.dsk (Rootkit.Agent) -> Delete on reboot.

i have done this so many times and still keeps coming up:sad:
here is a new hjt log as well. and i did re install avast and did boot scan. it supposedly deleted C:\Windows\System32\drivers\parportt.sys (Rootkit.Agent) -> but the malweare scan still showed it above. i made mistake about oobefldr.dll. :oops: these show up in hjt do you want me to delete?

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file) thanks. the glithches seem to be improving, but still running slow.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:23 PM, on 8/17/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\mobsync.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = karmamoon
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 5593 bytes

pskelley
2008-08-18, 20:14
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.

Remove any old copies of combofix before you proceed.

Thanks to sUBs and anyone else who helped with this fix.

It is important that it is saved directly to your Desktop.

Download ComboFix from Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop

Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix's window while its running. That may cause it to stall

Post the combofix log and a new HJT log.

Tutorial
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Thanks

karmamoon
2008-08-20, 04:51
hi again. i still have no luck. here are the logs.
ComboFix 08-08-18.05 - karmamoonbeam 2008-08-19 22:29:56.8 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.301 [GMT -4:00]
Running from: C:\Users\karmamoonbeam\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\tn3
C:\Users\karmamoonbeam\AppData\Roaming\Microsoft\Windows\Cookies\karmamoonbeam@pubmatic[3].txt
C:\Windows\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.

2008-08-19 22:35 . 2008-08-19 22:35 <DIR> d----c--- C:\TEMP\tn3
2008-08-18 13:06 . 2008-08-18 13:06 <DIR> d----c--- C:\Program Files\Spybot - Search & Destroy
2008-08-18 11:51 . 2008-08-18 11:51 <DIR> d----c--- C:\Users\pixierain45\AppData\Roaming\Games
2008-08-17 20:54 . 2008-07-19 10:36 51,280 --a--c--- C:\Windows\System32\drivers\aswMonFlt.sys
2008-08-16 17:27 . 2008-08-16 17:27 <DIR> d----c--- C:\Users\pixierain45\AppData\Roaming\Flood Light Games
2008-08-16 17:27 . 2008-08-16 17:27 <DIR> d----c--- C:\Users\All Users\Flood Light Games
2008-08-16 17:27 . 2008-08-16 17:27 <DIR> d----c--- C:\ProgramData\Flood Light Games
2008-08-15 11:03 . 2008-07-15 21:32 2,048 --a--c--- C:\Windows\System32\tzres.dll
2008-08-15 08:18 . 2008-06-26 21:55 1,383,424 --a--c--- C:\Windows\System32\mshtml.tlb
2008-08-15 08:18 . 2008-06-27 00:15 827,392 --a--c--- C:\Windows\System32\wininet.dll
2008-08-15 08:18 . 2008-06-18 23:31 361,984 --a--c--- C:\Windows\System32\IPSECSVC.DLL
2008-08-15 08:18 . 2008-04-18 01:48 269,312 --a--c--- C:\Windows\System32\es.dll
2008-08-15 08:17 . 2008-04-10 01:12 738,304 --a--c--- C:\Windows\System32\inetcomm.dll
2008-08-11 12:20 . 2008-08-11 12:20 <DIR> d----c--- C:\Users\karmamoonbeam\AppData\Roaming\Malwarebytes
2008-08-11 12:20 . 2008-08-11 12:20 <DIR> d----c--- C:\Users\All Users\Malwarebytes
2008-08-11 12:20 . 2008-08-11 12:20 <DIR> d----c--- C:\ProgramData\Malwarebytes
2008-08-11 02:56 . 2008-08-11 02:56 <DIR> d----c--- C:\Program Files\Trend Micro
2008-08-07 08:06 . 2008-08-16 16:56 <DIR> d----c--- C:\Users\pixierain45\AppData\Roaming\PlayFirst

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-20 02:23 --------- dc----w C:\ProgramData\Spybot - Search & Destroy
2008-08-20 00:58 --------- dc--a-w C:\ProgramData\TEMP
2008-08-19 14:13 --------- dc----w C:\Program Files\Microsoft Silverlight
2008-08-16 21:16 --------- dc----w C:\ProgramData\Dekovir
2008-08-15 15:01 --------- dc----w C:\Program Files\Windows Mail
2008-08-11 14:50 --------- dc----w C:\Program Files\7 Artifacts
2008-08-11 14:41 --------- dc----w C:\Program Files\Speeditup Free
2008-08-11 14:39 --------- dc----w C:\Program Files\Boonty
2008-08-05 12:47 --------- dc----w C:\Users\karmamoonbeam\AppData\Roaming\AOL
2008-08-03 19:52 --------- dc----w C:\Users\pixierain45\AppData\Roaming\LimeWire
2008-07-15 21:50 --------- dc----w C:\Users\karmamoonbeam\AppData\Roaming\LimeWire
2008-07-14 18:11 --------- dc----w C:\Program Files\Java
2008-07-11 19:59 --------- dc----w C:\Program Files\Voyage
2008-07-02 22:55 --------- dc----w C:\Users\karmamoonbeam\AppData\Roaming\PlayFirst
2008-07-02 22:55 --------- dc----w C:\ProgramData\PlayFirst
2008-06-30 23:20 --------- dc----w C:\Program Files\The Secret of Margrave Manor
2008-06-27 03:21 --------- dc----w C:\Program Files\Free Registry Cleaner for Vista
2008-06-25 18:49 --------- dc----w C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
2008-06-12 05:28 541,696 -c--a-w C:\Windows\AppPatch\AcLayers.dll
2008-06-07 18:25 708,426 -c--a-w C:\Windows\unins000.exe
2008-04-12 16:57 174 --sha-w C:\Program Files\desktop.ini
2007-08-22 19:46 262,144 ----a-w C:\ProgramData\ntuser.dat
2008-04-13 16:38 16,384 -csha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-13 16:38 32,768 -csha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-13 16:38 16,384 -csha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((( snapshot_2008-08-18_16.25.29.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-18 20:23:11 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-20 02:35:04 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-08-18 20:23:11 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-20 02:35:04 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-20 02:35:04 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-08-18 20:23:07 16,384 -csha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-08-20 02:35:00 16,384 -csha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-08-18 20:23:07 32,768 -csha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-08-20 02:35:00 32,768 -csha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-08-18 20:23:07 32,768 -csha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-08-20 02:35:00 32,768 -csha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-08-18 20:15:39 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-08-20 02:29:51 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
- 2008-08-18 20:13:06 9,688 -c--a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4218041708-3946741569-2960005307-1000_UserData.bin
+ 2008-08-19 14:13:50 9,846 -c--a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4218041708-3946741569-2960005307-1000_UserData.bin
- 2008-08-18 20:13:05 57,982 -c--a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-19 14:13:49 57,990 -c--a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-08-18 20:13:05 49,650 -c--a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-08-19 14:13:46 49,800 -c--a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 03:33 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 03:33 202240]
"AOL Fast Start"="C:\Program Files\AOL 9.1\AOL.EXE" [2007-10-27 13:44 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe" [2007-05-25 13:16 42032]
"WPCUMI"="C:\Windows\system32\WpcUmi.exe" [2006-11-02 08:35 176128]
"lxczbmgr.exe"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2007-04-19 15:44 74672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]

C:\Users\pixierain45\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk.disabled [2008-03-13 20:22:54 1662]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3E794EBA-1089-4BBA-B608-3D4B75CAA2E0}"= UDP:C:\Program Files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{A83D96A3-7C46-4FE7-8CA9-A1E345326D5F}"= TCP:C:\Program Files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{4ABB90C8-B0A3-412D-970A-74C7A63415F2}"= UDP:C:\Program Files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{8E4B5C05-71D0-42DC-8CED-D3331B76B5D1}"= TCP:C:\Program Files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{007F6096-B650-4A8B-A2A8-5AE3FFFD55D4}"= UDP:C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe:AOL Shared Components
"{60DAA38D-9F43-48C3-897E-78475E1AC166}"= TCP:C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe:AOL Shared Components
"{7F259B94-7CDF-4880-BB34-146515F97ACF}"= UDP:C:\Program Files\AOL 9.0\waol.exe:AOL
"{6FD6BD91-AEF1-4C96-B515-6920E92F4039}"= TCP:C:\Program Files\AOL 9.0\waol.exe:AOL
"{3195AE45-7768-44ED-8CB6-D3D868D7DEDC}"= UDP:C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{3B2989FE-E20E-411A-B11A-CEE013BAA796}"= TCP:C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{78AABB67-5933-44E6-B86B-84E897E5883C}"= UDP:C:\Program Files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{668C0E5C-D723-4F02-9066-F3F063A2DA7A}"= TCP:C:\Program Files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{498CC920-CE19-4C6D-87FE-A5E1AAFF65F0}"= UDP:C:\Program Files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{4D9D2ED8-96EF-4D00-BF2A-8AE74AFE4DA1}"= TCP:C:\Program Files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{0A2C0688-3C5C-49AE-BCD0-B6B43E458C65}"= UDP:C:\Program Files\AOL 9.0a\waol.exe:AOL
"{0AE26686-8848-4D24-BA1F-E5956C08B3B3}"= TCP:C:\Program Files\AOL 9.0a\waol.exe:AOL
"{DE1A72BD-C620-4152-B5AA-CDCBD241FDDB}"= UDP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{F06C59AE-3295-4890-A0B0-08AD4346E91F}"= TCP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{FB93E2B0-ADD0-4A87-A110-EFA9F3A79F48}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{818801E9-9255-4AFA-92AA-B62C6E224EE4}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{7872E73F-18D9-4666-8B3D-2DF5D61AB454}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{ADE3DED5-0E89-4DD2-877D-D7F3618F0F32}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FE9BDBBF-4212-45FD-9C6E-36F777215232}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{0826A52C-CCC8-4028-84E1-0FBFC818266E}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{BE598FDA-A849-4EC0-B9D0-09CFE657651D}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{AAAB7FF3-19B0-4668-921E-5E34EA05B068}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{23218EE9-E08E-4496-BFD8-E76477822ECA}"= UDP:C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:FineScanManager
"{4B60EBA1-C1CC-4820-A276-0E09F80808BD}"= TCP:C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:FineScanManager
"{37A418EF-BC48-477F-8F4E-CED63853A9FD}"= UDP:C:\Windows\System32\lxczcoms.exe:Lexmark Communications System
"{0AECFA2F-F1C9-47D1-9853-29688AE89993}"= TCP:C:\Windows\System32\lxczcoms.exe:Lexmark Communications System
"{2377155E-5BB8-4557-9390-B605F37FDE23}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{9B3F8C28-EC5C-4FC8-97A5-4650C0F2D1D2}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{870BE08F-6501-4C9C-BD6F-B6E953D19B60}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{4469A0C7-D3C8-47CB-B8EA-6728D93F66D3}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{65FBCC79-D25F-4EB5-82DD-8DA6F73AC89C}C:\\program files\\rhapsody\\rhapsody.exe"= UDP:C:\program files\rhapsody\rhapsody.exe:RealNetworks Rhapsody
"UDP Query User{AA0ABC00-1B61-425E-A3AB-49772E9D626A}C:\\program files\\rhapsody\\rhapsody.exe"= TCP:C:\program files\rhapsody\rhapsody.exe:RealNetworks Rhapsody
"{3F7B8C13-C090-4F0F-AA06-7F7D5D36D815}"= UDP:C:\Program Files\AOL 9.1\waol.exe:AOL
"{CF38FE05-C836-446D-9F02-6EDDE7D35653}"= TCP:C:\Program Files\AOL 9.1\waol.exe:AOL
"TCP Query User{68EB0B30-476A-4875-A67F-9019D9AEFF3F}C:\\program files\\windows sidebar\\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar
"UDP Query User{6C13DE1B-E46B-48C3-8BB9-3BF8AE3EC5A7}C:\\program files\\windows sidebar\\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar
"TCP Query User{EDEAFE95-F807-4C6A-B458-247DE4D19BF7}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{72B724EF-09F1-4B36-9341-748BDA444E05}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{15239215-3248-45E9-9C0C-19777066CF36}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{B152D3C4-01C3-4A6C-9102-165C57FA4DB4}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{211F8848-2653-4C43-8B35-C01B837CA948}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{30DED489-D23E-4E1E-BB56-F6819FEA6B5C}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{FD7B863D-78EB-40FD-BF5D-8E601A37B49B}"= UDP:7594:BitCometBeta 7594 TCP
"{81EC7980-30D6-456D-B87B-244A2D686F58}"= TCP:7594:BitCometBeta 7594 UDP
"{2330AC28-9286-4D5D-A7E9-F6A61CA04778}"= UDP:9130:BitCometBeta 9130 TCP
"{95935BEA-BAAF-47F9-B099-AF919344571B}"= TCP:9130:BitCometBeta 9130 UDP
"{A441EAA4-AE8F-4A73-990C-09ED54D3CBC8}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{B39D0769-596E-46B6-845F-57812DA8D5DE}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{81969492-6333-41C2-969A-848AD41E7089}"= UDP:C:\Program Files\Alwil Software\Avast4\ashAvast.exe:avast! Antivirus
"{22B39377-6C6A-465D-9C4F-B337A0A5CBFE}"= TCP:C:\Program Files\Alwil Software\Avast4\ashAvast.exe:avast! Antivirus

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"= C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox

R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 10:35]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 10:37]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 10:36]
S4 lxcz_device;lxcz_device;C:\Windows\system32\lxczcoms.exe []
.
Contents of the 'Scheduled Tasks' folder

2008-08-20 C:\Windows\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe []

2008-08-14 C:\Windows\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe []

2008-08-20 C:\Windows\Tasks\User_Feed_Synchronization-{41DA37C9-46F9-4C59-9784-6969FACC4046}.job
- C:\Windows\system32\msfeedssync.exe [2008-01-19 03:33]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\karmamoonbeam\AppData\Roaming\Mozilla\Firefox\Profiles\2x9sjega.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.torrentpond.com/?bookmark
FF -: plugin - C:\Downloads\plugins\npnul32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - C:\Users\karmamoonbeam\AppData\Roaming\Mozilla\Firefox\Profiles\2x9sjega.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07074039.dll
.
.
------- File Associations (Beta) -------
.
VBEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
VBSFile="%SystemRoot%\System32\WScript.exe" "%1" %*
vbefile\shell\open\command="%SystemRoot%\System32\WScript.exe" "%1" %*
vbsfile\shell\open\command="%SystemRoot%\System32\WScript.exe" "%1" %*
jsefile\shell\open\command=%SystemRoot%\System32\WScript.exe "%1" %*
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-19 22:35:09
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\aol\acs\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmon.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AOL 9.1\shellmon.exe
.
**************************************************************************
.
Completion time: 2008-08-19 22:38:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-20 02:38:32
ComboFix2.txt 2008-08-18 20:26:32
ComboFix3.txt 2008-08-13 20:24:05

Pre-Run: 261,279,608,832 bytes free
Post-Run: 261,721,788,416 bytes free

241 --- E O F --- 2008-08-19 14:13:32

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:56 PM, on 8/19/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Windows\Explorer.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 5901 bytes

what next?

pskelley
2008-08-20, 14:23
Thanks for keeping me informed, a few thoughts for you.

1) If you were told Vista would not get infected, they lied to you. In fact I see as many infected Vista computers as XP.

2) Many tools that work on XP do not work on Vista limiting our ability to clean them. Even the ones that do work different.

3) C:\Windows\system32\drivers\core.cache.dsk <<< this driver I have not seen on an infected Vista machine before myself, but it always comes with another hidden rootkit driver that must be located and removed before that item can be deleted. In XP MBAM and combofix both remove both the hidden item and core.cache.dsk, and as you have seen, this is not the case in Vista.

4) If you will be patient, I believe we can clean the computer, one option if you do not wish to wait is to reformat.

5) I would also like you to review this information:
http://forums.spybot.info/showthread.php?t=282

If your helper detects the presence of such programs on your computer he/she will ask you to remove them. Help will be withdrawn should you not agree to their removal.

Let's give this a try:

Open notepad and copy/paste the text in the codebox below into it:


Driver::
parportt

File::
C:\Windows\System32\drivers\parportt.sys
C:\Windows\System32\drivers\core.cache.dsk

Save this as CFScript

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Referring to the picture above, drag CFScript into ComboFix.exe.

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Thanks

karmamoon
2008-08-22, 01:43
hi i did what you said and after this post will remove the p2p since i scanned before removal.:oops:
ComboFix 08-08-21.01 - karmamoonbeam 2008-08-21 19:14:00.9 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.240 [GMT -4:00]
Running from: C:\Users\karmamoonbeam\Desktop\ComboFix.exe
Command switches used :: C:\Users\karmamoonbeam\Desktop\cfscript.txt
* Created a new restore point

FILE ::
C:\Windows\System32\drivers\core.cache.dsk
C:\Windows\System32\drivers\parportt.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\tn3
C:\Users\karmamoonbeam\AppData\Roaming\Microsoft\Windows\Cookies\karmamoonbeam@c.dsite[2].txt
C:\Windows\system32\drivers\core.cache.dsk
C:\Windows\System32\drivers\parportt.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_PARPORTT
-------\Service_parportt


((((((((((((((((((((((((( Files Created from 2008-07-21 to 2008-08-21 )))))))))))))))))))))))))))))))
.

2008-08-20 08:19 . 2008-08-20 08:19 <DIR> d----c--- C:\Program Files\Google
2008-08-18 13:06 . 2008-08-18 13:06 <DIR> d----c--- C:\Program Files\Spybot - Search & Destroy
2008-08-18 11:51 . 2008-08-18 11:51 <DIR> d----c--- C:\Users\pixierain45\AppData\Roaming\Games
2008-08-17 20:54 . 2008-07-19 10:36 51,280 --a--c--- C:\Windows\System32\drivers\aswMonFlt.sys
2008-08-16 17:27 . 2008-08-16 17:27 <DIR> d----c--- C:\Users\pixierain45\AppData\Roaming\Flood Light Games
2008-08-16 17:27 . 2008-08-16 17:27 <DIR> d----c--- C:\Users\All Users\Flood Light Games
2008-08-16 17:27 . 2008-08-16 17:27 <DIR> d----c--- C:\ProgramData\Flood Light Games
2008-08-15 11:03 . 2008-07-15 21:32 2,048 --a--c--- C:\Windows\System32\tzres.dll
2008-08-15 08:18 . 2008-06-26 21:55 1,383,424 --a--c--- C:\Windows\System32\mshtml.tlb
2008-08-15 08:18 . 2008-06-27 00:15 827,392 --a--c--- C:\Windows\System32\wininet.dll
2008-08-15 08:18 . 2008-06-18 23:31 361,984 --a--c--- C:\Windows\System32\IPSECSVC.DLL
2008-08-15 08:18 . 2008-04-18 01:48 269,312 --a--c--- C:\Windows\System32\es.dll
2008-08-15 08:17 . 2008-04-10 01:12 738,304 --a--c--- C:\Windows\System32\inetcomm.dll
2008-08-11 12:20 . 2008-08-11 12:20 <DIR> d----c--- C:\Users\karmamoonbeam\AppData\Roaming\Malwarebytes
2008-08-11 12:20 . 2008-08-11 12:20 <DIR> d----c--- C:\Users\All Users\Malwarebytes
2008-08-11 12:20 . 2008-08-11 12:20 <DIR> d----c--- C:\ProgramData\Malwarebytes
2008-08-11 02:56 . 2008-08-11 02:56 <DIR> d----c--- C:\Program Files\Trend Micro
2008-08-07 08:06 . 2008-08-16 16:56 <DIR> d----c--- C:\Users\pixierain45\AppData\Roaming\PlayFirst

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-21 22:59 --------- dc----w C:\ProgramData\Spybot - Search & Destroy
2008-08-20 22:38 --------- dc--a-w C:\ProgramData\TEMP
2008-08-20 12:18 --------- dc----w C:\Program Files\Java
2008-08-19 14:13 --------- dc----w C:\Program Files\Microsoft Silverlight
2008-08-16 21:16 --------- dc----w C:\ProgramData\Dekovir
2008-08-15 15:01 --------- dc----w C:\Program Files\Windows Mail
2008-08-11 14:50 --------- dc----w C:\Program Files\7 Artifacts
2008-08-11 14:41 --------- dc----w C:\Program Files\Speeditup Free
2008-08-11 14:39 --------- dc----w C:\Program Files\Boonty
2008-08-05 12:47 --------- dc----w C:\Users\karmamoonbeam\AppData\Roaming\AOL
2008-08-03 19:52 --------- dc----w C:\Users\pixierain45\AppData\Roaming\LimeWire
2008-07-15 21:50 --------- dc----w C:\Users\karmamoonbeam\AppData\Roaming\LimeWire
2008-07-11 19:59 --------- dc----w C:\Program Files\Voyage
2008-07-02 22:55 --------- dc----w C:\Users\karmamoonbeam\AppData\Roaming\PlayFirst
2008-07-02 22:55 --------- dc----w C:\ProgramData\PlayFirst
2008-06-30 23:20 --------- dc----w C:\Program Files\The Secret of Margrave Manor
2008-06-27 03:21 --------- dc----w C:\Program Files\Free Registry Cleaner for Vista
2008-06-26 03:29 801,280 -c--a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 -c--a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 -c--a-w C:\Windows\System32\NlsLexicons0007.dll
2008-06-25 18:49 --------- dc----w C:\Program Files\Hide and Secret 2 - Cliffhanger Castle
2008-06-12 05:28 541,696 -c--a-w C:\Windows\AppPatch\AcLayers.dll
2008-06-07 18:37 107,888 -c--a-w C:\Windows\System32\CmdLineExt.dll
2008-06-07 18:25 708,426 -c--a-w C:\Windows\unins000.exe
2008-05-30 23:22 823,296 -c--a-w C:\Windows\System32\divx_xx0c.dll
2008-05-30 23:22 823,296 -c--a-w C:\Windows\System32\divx_xx07.dll
2008-05-30 23:22 815,104 -c--a-w C:\Windows\System32\divx_xx0a.dll
2008-05-30 23:22 802,816 -c--a-w C:\Windows\System32\divx_xx11.dll
2008-05-30 23:22 683,520 -c--a-w C:\Windows\System32\DivX.dll
2008-05-30 23:22 593,920 -c--a-w C:\Windows\System32\dpuGUI11.dll
2008-05-30 23:22 57,344 -c--a-w C:\Windows\System32\dpv11.dll
2008-05-30 23:22 53,248 -c--a-w C:\Windows\System32\dpuGUI10.dll
2008-05-30 23:22 344,064 -c--a-w C:\Windows\System32\dpus11.dll
2008-05-30 23:22 294,912 -c--a-w C:\Windows\System32\dpu11.dll
2008-05-30 23:22 294,912 -c--a-w C:\Windows\System32\dpu10.dll
2008-05-27 05:21 1,582,592 -c--a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 -c--a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 -c--a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 -c--a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 -c--a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 -c--a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 -c--a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 34,816 -c--a-w C:\Windows\System32\msscb.dll
2008-05-27 05:17 32,768 -c--a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 -c--a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 -c--a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 -c--a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 -c--a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 11,776 -c--a-w C:\Windows\System32\msshooks.dll
2008-05-27 05:17 1,671,680 -c--a-w C:\Windows\System32\chsbrkr.dll
2008-05-27 04:59 18,904 -c--a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-05-27 04:59 106,605 -c--a-w C:\Windows\System32\StructuredQuerySchema.bin
2008-05-22 22:22 524,288 -c--a-w C:\Windows\System32\DivXsm.exe
2008-05-22 22:22 3,596,288 -c--a-w C:\Windows\System32\qt-dx331.dll
2008-05-22 22:20 200,704 -c--a-w C:\Windows\System32\ssldivx.dll
2008-05-22 22:20 1,044,480 -c--a-w C:\Windows\System32\libdivx.dll
2008-05-22 22:19 81,920 -c--a-w C:\Windows\System32\dpl100.dll
2008-05-22 22:19 196,608 -c--a-w C:\Windows\System32\dtu100.dll
2008-05-22 22:19 161,096 -c--a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 -c--a-w C:\Windows\System32\DivXWMPExtType.dll
2008-04-12 16:57 174 --sha-w C:\Program Files\desktop.ini
2007-08-22 19:46 262,144 ----a-w C:\ProgramData\ntuser.dat
2008-04-13 16:38 16,384 -csha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-04-13 16:38 32,768 -csha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-04-13 16:38 16,384 -csha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((( snapshot_2008-08-18_16.25.29.92 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 00:02:28 163,328 -c--a-w C:\Windows\erdnt\subs\ERDNT.EXE
+ 2008-08-21 23:23:18 2,048 -csha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-08-21 23:23:18 2,048 -csha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-08-18 20:23:11 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-21 23:24:28 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-08-18 20:23:11 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-21 23:24:42 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-21 23:24:42 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-08-18 20:23:07 16,384 -csha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-08-21 23:23:39 16,384 -csha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-08-18 20:23:07 32,768 -csha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-08-21 23:23:39 32,768 -csha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-08-18 20:23:07 32,768 -csha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-08-21 23:23:39 32,768 -csha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-08-18 20:15:39 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-08-21 23:13:51 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
- 2008-08-16 23:51:40 101,144 -c--a-w C:\Windows\System32\perfc009.dat
+ 2008-08-21 21:06:08 101,144 -c--a-w C:\Windows\System32\perfc009.dat
- 2008-08-16 23:51:40 595,446 -c--a-w C:\Windows\System32\perfh009.dat
+ 2008-08-21 21:06:08 595,446 -c--a-w C:\Windows\System32\perfh009.dat
- 2008-08-18 20:13:06 9,688 -c--a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4218041708-3946741569-2960005307-1000_UserData.bin
+ 2008-08-20 11:01:13 9,886 -c--a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4218041708-3946741569-2960005307-1000_UserData.bin
- 2008-08-18 20:13:05 57,982 -c--a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-20 11:01:13 58,066 -c--a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-08-18 20:13:05 49,650 -c--a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-08-20 11:01:12 49,864 -c--a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 03:33 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 03:33 202240]
"AOL Fast Start"="C:\Program Files\AOL 9.1\AOL.EXE" [2007-10-27 13:44 50528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe" [2007-05-25 13:16 42032]
"WPCUMI"="C:\Windows\system32\WpcUmi.exe" [2006-11-02 08:35 176128]
"lxczbmgr.exe"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2007-04-19 15:44 74672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

C:\Users\pixierain45\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk.disabled [2008-03-13 20:22:54 1662]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3E794EBA-1089-4BBA-B608-3D4B75CAA2E0}"= UDP:C:\Program Files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{A83D96A3-7C46-4FE7-8CA9-A1E345326D5F}"= TCP:C:\Program Files\Common Files\aol\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{4ABB90C8-B0A3-412D-970A-74C7A63415F2}"= UDP:C:\Program Files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{8E4B5C05-71D0-42DC-8CED-D3331B76B5D1}"= TCP:C:\Program Files\Common Files\aol\acs\AOLacsd.exe:AOL Connectivity Service
"{007F6096-B650-4A8B-A2A8-5AE3FFFD55D4}"= UDP:C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe:AOL Shared Components
"{60DAA38D-9F43-48C3-897E-78475E1AC166}"= TCP:C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe:AOL Shared Components
"{7F259B94-7CDF-4880-BB34-146515F97ACF}"= UDP:C:\Program Files\AOL 9.0\waol.exe:AOL
"{6FD6BD91-AEF1-4C96-B515-6920E92F4039}"= TCP:C:\Program Files\AOL 9.0\waol.exe:AOL
"{3195AE45-7768-44ED-8CB6-D3D868D7DEDC}"= UDP:C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{3B2989FE-E20E-411A-B11A-CEE013BAA796}"= TCP:C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{78AABB67-5933-44E6-B86B-84E897E5883C}"= UDP:C:\Program Files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{668C0E5C-D723-4F02-9066-F3F063A2DA7A}"= TCP:C:\Program Files\Common Files\aol\Loader\aolload.exe:AOL Loader
"{498CC920-CE19-4C6D-87FE-A5E1AAFF65F0}"= UDP:C:\Program Files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{4D9D2ED8-96EF-4D00-BF2A-8AE74AFE4DA1}"= TCP:C:\Program Files\Common Files\aol\System Information\sinf.exe:AOL System Information
"{0A2C0688-3C5C-49AE-BCD0-B6B43E458C65}"= UDP:C:\Program Files\AOL 9.0a\waol.exe:AOL
"{0AE26686-8848-4D24-BA1F-E5956C08B3B3}"= TCP:C:\Program Files\AOL 9.0a\waol.exe:AOL
"{DE1A72BD-C620-4152-B5AA-CDCBD241FDDB}"= UDP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{F06C59AE-3295-4890-A0B0-08AD4346E91F}"= TCP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{FB93E2B0-ADD0-4A87-A110-EFA9F3A79F48}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{818801E9-9255-4AFA-92AA-B62C6E224EE4}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{7872E73F-18D9-4666-8B3D-2DF5D61AB454}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{ADE3DED5-0E89-4DD2-877D-D7F3618F0F32}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{FE9BDBBF-4212-45FD-9C6E-36F777215232}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{0826A52C-CCC8-4028-84E1-0FBFC818266E}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{BE598FDA-A849-4EC0-B9D0-09CFE657651D}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{AAAB7FF3-19B0-4668-921E-5E34EA05B068}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{23218EE9-E08E-4496-BFD8-E76477822ECA}"= UDP:C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:FineScanManager
"{4B60EBA1-C1CC-4820-A276-0E09F80808BD}"= TCP:C:\Program Files\Abbyy FineReader 6.0 Sprint\Scan\ScanMan6.exe:FineScanManager
"{37A418EF-BC48-477F-8F4E-CED63853A9FD}"= UDP:C:\Windows\System32\lxczcoms.exe:Lexmark Communications System
"{0AECFA2F-F1C9-47D1-9853-29688AE89993}"= TCP:C:\Windows\System32\lxczcoms.exe:Lexmark Communications System
"{2377155E-5BB8-4557-9390-B605F37FDE23}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{9B3F8C28-EC5C-4FC8-97A5-4650C0F2D1D2}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{870BE08F-6501-4C9C-BD6F-B6E953D19B60}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{4469A0C7-D3C8-47CB-B8EA-6728D93F66D3}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{65FBCC79-D25F-4EB5-82DD-8DA6F73AC89C}C:\\program files\\rhapsody\\rhapsody.exe"= UDP:C:\program files\rhapsody\rhapsody.exe:RealNetworks Rhapsody
"UDP Query User{AA0ABC00-1B61-425E-A3AB-49772E9D626A}C:\\program files\\rhapsody\\rhapsody.exe"= TCP:C:\program files\rhapsody\rhapsody.exe:RealNetworks Rhapsody
"{3F7B8C13-C090-4F0F-AA06-7F7D5D36D815}"= UDP:C:\Program Files\AOL 9.1\waol.exe:AOL
"{CF38FE05-C836-446D-9F02-6EDDE7D35653}"= TCP:C:\Program Files\AOL 9.1\waol.exe:AOL
"TCP Query User{68EB0B30-476A-4875-A67F-9019D9AEFF3F}C:\\program files\\windows sidebar\\sidebar.exe"= UDP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar
"UDP Query User{6C13DE1B-E46B-48C3-8BB9-3BF8AE3EC5A7}C:\\program files\\windows sidebar\\sidebar.exe"= TCP:C:\program files\windows sidebar\sidebar.exe:Windows Sidebar
"TCP Query User{EDEAFE95-F807-4C6A-B458-247DE4D19BF7}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{72B724EF-09F1-4B36-9341-748BDA444E05}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{15239215-3248-45E9-9C0C-19777066CF36}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{B152D3C4-01C3-4A6C-9102-165C57FA4DB4}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"TCP Query User{211F8848-2653-4C43-8B35-C01B837CA948}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{30DED489-D23E-4E1E-BB56-F6819FEA6B5C}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{FD7B863D-78EB-40FD-BF5D-8E601A37B49B}"= UDP:7594:BitCometBeta 7594 TCP
"{81EC7980-30D6-456D-B87B-244A2D686F58}"= TCP:7594:BitCometBeta 7594 UDP
"{2330AC28-9286-4D5D-A7E9-F6A61CA04778}"= UDP:9130:BitCometBeta 9130 TCP
"{95935BEA-BAAF-47F9-B099-AF919344571B}"= TCP:9130:BitCometBeta 9130 UDP
"{A441EAA4-AE8F-4A73-990C-09ED54D3CBC8}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{B39D0769-596E-46B6-845F-57812DA8D5DE}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{81969492-6333-41C2-969A-848AD41E7089}"= UDP:C:\Program Files\Alwil Software\Avast4\ashAvast.exe:avast! Antivirus
"{22B39377-6C6A-465D-9C4F-B337A0A5CBFE}"= TCP:C:\Program Files\Alwil Software\Avast4\ashAvast.exe:avast! Antivirus

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"= C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox

R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 10:35]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 10:37]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 10:36]
S4 lxcz_device;lxcz_device;C:\Windows\system32\lxczcoms.exe []
.
Contents of the 'Scheduled Tasks' folder

2008-08-21 C:\Windows\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe []

2008-08-21 C:\Windows\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe []

2008-08-21 C:\Windows\Tasks\User_Feed_Synchronization-{41DA37C9-46F9-4C59-9784-6969FACC4046}.job
- C:\Windows\system32\msfeedssync.exe [2008-01-19 03:33]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-21 19:25:02
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\Users\karmamoonbeam\AppData\Local\Microsoft\Portable Devices\wpdlog05.sqm 472 bytes
C:\Users\karmamoonbeam\AppData\Local\Microsoft\Portable Devices\wpdlog06.sqm 472 bytes
C:\Users\karmamoonbeam\AppData\Local\Microsoft\Portable Devices\wpdlog07.sqm 472 bytes
C:\Users\karmamoonbeam\AppData\Local\Microsoft\Portable Devices\wpdlog08.sqm 472 bytes

scan completed successfully
hidden files: 4

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\aol\acs\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmon.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\aol\Loader\aolload.exe
C:\Program Files\AOL 9.1\shellmon.exe
.
**************************************************************************
.
Completion time: 2008-08-21 19:29:34 - machine was rebooted [karmamoonbeam]
ComboFix-quarantined-files.txt 2008-08-21 23:29:29
ComboFix2.txt 2008-08-18 20:26:32
ComboFix3.txt 2008-08-13 20:24:05

Pre-Run: 246,151,200,768 bytes free
Post-Run: 246,368,526,336 bytes free

281 --- E O F --- 2008-08-20 19:17:40

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:48 PM, on 8/21/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\aol\1185407646\ee\aolsoftware.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\AOL 9.1\waol.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AOL 9.1\shellmon.exe
C:\Windows\Explorer.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1185407646\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u5-windows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 6455 bytes

did it work? in combofix while doing the scan, it said could not remove, but it doesn't say that in log.

pskelley
2008-08-22, 02:20
Thanks for returning your information and the feedback, you asked:

did it work? in combofix while doing the scan, it said could not remove, but it doesn't say that in log.
Both items must be removed at the same time, sometimes the rootkit driver is not even visable. In this case MBAM showed both drivers and the rootkit and tried to remove them (sometimes it does) but at least it showed it to us. If MBAB had removed them, I would not have used combofix.

You can use HJT to remove these dead items:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (file missing)

If all is running well, remove combofix from your computer like this:
Click START then RUN
Now type or copy Combofix /u in the runbox and click OK.
Note the space between the X and the U, it needs to be there.

http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png

You need to get your antivirus program up and running.
Here is some information, all of it may not apply to Vista.

Get maximum performance from Windows Vista
http://windowshelp.microsoft.com/windows/en-us/Help/596FB57F-CC9D-4AC5-A813-5C0830E9156A1033.mspx

Some good information for you:
http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx

Here is some great information from experts in this field that will help you stay clean and safe online.
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

http://www.malwarecomplaints.info/

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

http://users.telenet.be/bluepatchy/miekiemoes/Links.html

karmamoon
2008-08-24, 05:54
Thanks so much!!!! Everything seems to be working ok now. the last scan I did before I posted the log, i ran combofix to delete the rootkit and core cache, then ran avast and moved the rootkit to the chest. i ran spybot and it told me i was clean, so hopefully its gone!!! I also ran hjt and removed what you told me to do and uninstalled combofix.:):):):) i always disk clean and have a scheduled defrag weekly, along with ccleaner.
some other things i have used are Free registry cleaner for windows vista, and Speed it up free. I do not use the disk defrag on speed it up free though because it freezes in the middle of the run, but they seem to work pretty well along with avast.
i have never had a problem with the bitcomet giving me a virus, it always came from limewire, so i NEVER use it. i have thanked my friends for the infection, and told them no more free music. i belong to plenty of other music sites that i can listen to music on like rhapsody. Thanks again!!!!
karmamoon

pskelley
2008-08-24, 14:35
Thanks for the feedback:

Free registry cleaner for windows vista
Those can be very dangerous and turn your combuter into a plant stand.
NEVER do anything in your registry that you do make a backup first in the event of an emergency.

If you have not yet read our policy in the "Before you Post" information, I suggest you do so.
If you want music, listen to it online, if you must possess it, purchase it for about a $1.00 each, that way the artist can eat to.
http://arstechnica.com/news.ars/post/20080316-kazaa-downloads-cost-one-man-750-per-song-in-riaa-suit.html

Safe surfing...Phil