PDA

View Full Version : recurring detections - PWS.LDPinchIE and Win32.TDSS.rtk



sfrazee
2009-05-04, 20:29
Ran SB S&D last night and found multiple infections. I have ran it mulitple times since and the two infections listed in the thread title seem to reappear after reboot or using internet explorer. please help

here is HJT log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:09 AM, on 5/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MoRUN.net\Sticker Lite\sticker.exe
C:\DOCUME~1\frazeesw\LOCALS~1\Temp\2741756310.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\frazeesw\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mtech.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.65.122 spyware-protector-2009.com
O1 - Hosts: 91.212.65.122 www.spyware-protector-2009.com (http://www.spyware-protector-2009.com)
O1 - Hosts: 91.212.65.122 secure.spyware-protector-2009.com
O1 - Hosts: 91.212.65.122 knocker
O1 - Hosts: 91.212.65.222 swp2009.com
O1 - Hosts: 91.212.65.222 spyprotect2009.com
O1 - Hosts: 91.212.65.222 sp-protect2009.com
O1 - Hosts: 91.212.65.222 sys-protection.com
O1 - Hosts: 91.212.65.222 sysguard2009.com
O1 - Hosts: 91.212.65.222 os-protection.com
O1 - Hosts: 91.212.65.222 spy-protect-2009.com
O1 - Hosts: 91.212.65.222 spywprotect.com
O1 - Hosts: 91.212.65.222 adwareguard.net
O1 - Hosts: 91.212.65.222 antivirus-win.com
O1 - Hosts: 91.212.65.222 spwprotect2009.com
O1 - Hosts: 91.212.65.222 spy-protec.com
O1 - Hosts: 91.212.65.222 spyware-protector-2009.com
O2 - BHO: C:\WINDOWS\system32\afnoinkdsfe.dll - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\afnoinkdsfe.dll
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [FRYMXINS] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [StickerLite] C:\Program Files\MoRUN.net\Sticker Lite\sticker.exe
O4 - HKCU\..\Run: [prnet] "C:\WINDOWS\system32\prnet.tmp"
O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\frazeesw\LOCALS~1\Temp\2741756310.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1220621775968
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rose-hulman.edu
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = rose-hulman.edu,dhcp.rose-hulman.edu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\lawariko.dll c:\windows\system32\zuyajera.dll c:\windows\system32\vozanije.dll,C:\WINDOWS\system32\,C:\WINDOWS\system32\sugemeha.dll
O20 - Winlogon Notify: AfsLogon - C:\WINDOWS\SYSTEM32\afslogon.dll
O20 - Winlogon Notify: MIT_KFW - C:\WINDOWS\SYSTEM32\kfwlogon.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\vozanije.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\vozanije.dll (file missing)
O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\afnoinkdsfe.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OpenAFS Client Service (TransarcAFSDaemon) - OpenAFS Project - C:\Program Files\OpenAFS\Client\Program\afsd_service.exe

--
End of file - 10239 bytes


thanks in advance

O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.65.122 spyware-protector-2009.com
O1 - Hosts: 91.212.65.122 www.spyware-protector-2009.com (http://www.spyware-protector-2009.com)
O1 - Hosts: 91.212.65.122 secure.spyware-protector-2009.com
O1 - Hosts: 91.212.65.122 knocker
O1 - Hosts: 91.212.65.222 swp2009.com
O1 - Hosts: 91.212.65.222 spyprotect2009.com
O1 - Hosts: 91.212.65.222 sp-protect2009.com
O1 - Hosts: 91.212.65.222 sys-protection.com
O1 - Hosts: 91.212.65.222 sysguard2009.com
O1 - Hosts: 91.212.65.222 os-protection.com
O1 - Hosts: 91.212.65.222 spy-protect-2009.com
O1 - Hosts: 91.212.65.222 spywprotect.com
O1 - Hosts: 91.212.65.222 adwareguard.net
O1 - Hosts: 91.212.65.222 antivirus-win.com
O1 - Hosts: 91.212.65.222 spwprotect2009.com
O1 - Hosts: 91.212.65.222 spy-protec.com
O1 - Hosts: 91.212.65.222 spyware-protector-2009.com


I forgot about this, but about a month ago when my computer became infected with some other form of spyware, i was trying to manually remove it until someone recommended SB S&D. In the process i made an attempt to block some sites associated with the spyware, hence the stuff posted above but i didnt know what IP address to use and i dont know where i got the one i used from but it must not be right. anyway just thought i would explain what that stuff was. and now i can't remember how to edit the host file

pskelley
2009-05-05, 14:35
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance) http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

You must have read and followed the "Before you Post" instructions, anything else will waste your time and mine.

Please read this information carefully.
http://forums.spybot.info/showpost.php?p=25712&postcount=5

Domain = rose-hulman.edu <<< appears to be an Institutional computer? (and a very infected one at that)
http://www.rose-hulman.edu/

Thanks

sfrazee
2009-05-05, 19:04
this is a personal computer but it was issued by a school i am no longer attending (rose-hulman). I am pretty illiterate when it comes to computers but as far as i know i am not violating any of the criteria for you guys to help me. thanks

pskelley
2009-05-05, 19:51
Take the time you need to safely follow the directions in the numbered order.

1) Please download HostsXpert
http://www.funkytoad.com/index.php?option=com_content&task=view&id=13

* Unzip HostsXpert to it's own folder a convenient place such as C:\HostsXpert
* Run HostsXpert.exe
* Click: Make Writable? in the upper left corner.
* Click: Restore MVPs Hosts
* Click: Replace
* Click: OK
* Click: Make ReadOnly
* Close HostsXpert.

Note: If a custom Hosts file was in place, you will have to run those programs again to reset detections.
If needed Tutorial
http://i28.photobucket.com/albums/c227/tetonbob/emoticons/HostsXpert4.jpg

2) Please DO NOT ENABLE Spybot S&D TeaTimer while we work together.

3) A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use

Download ComboFix from here:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


http://i24.photobucket.com/albums/c30/ken545/RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://i24.photobucket.com/albums/c30/ken545/whatnext.jpg

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Tutorial if needed
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

4) Post also an uninstall list: Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list..." Button.
Save it to your desktop. Copy and paste the contents into your reply.
Image: http://img.bleepingcomputer.com/tutorials/hijackthis/uninstall-man.jpg

Thanks...Phil

sfrazee
2009-05-05, 21:05
thank you so much for your help.

ran combofix and here are the logs

ComboFix 09-05-04.A3 - frazeesw 05/05/2009 11:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1575 [GMT -6:00]
Running from: c:\documents and settings\frazeesw\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Outdated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\frazeesw\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\version.txt
c:\program files\WinBudget
c:\windows\IE4 Error Log.txt
c:\windows\system32\afnoinkdsfe.dll
c:\windows\system32\ak1.exe
c:\windows\system32\drivers\ovfsthaquqjpnismhnapfsokocmmxpubaiuxxq.sys
c:\windows\system32\ovfsthbylymyyvdyidlbpxnhjukxkitxqbwemh.dll
c:\windows\system32\ovfsthqlgwkvmaebxcaegampdftpxpsdjeexkh.dll
c:\windows\system32\ovfsthrcqmrrkwdhlvismrvttjjbexigepsoxh.dll
c:\windows\system32\ovfsthxpbrxqoymhanupbaceacytbjejyvefip.dat
c:\windows\system32\ovfsthykmgjejsnmhqtbsttstcpfjixovumwkd.dat
c:\windows\system32\p2hhr.bat
c:\windows\system32\rulisofo.exe
c:\windows\Temp\1276240272.exe
c:\windows\Temp\1296865272.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ovfsthodpulkftitbvyuwpkbyrvkbgkvvrjgfo


((((((((((((((((((((((((( Files Created from 2009-04-05 to 2009-05-05 )))))))))))))))))))))))))))))))
.

2009-05-04 17:05 . 2009-05-04 17:05 -------- d-----w c:\program files\ERUNT
2009-05-04 17:02 . 2009-05-04 17:02 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-05-04 16:21 . 2009-05-04 16:21 -------- d-sh--w c:\documents and settings\frazeesw\IECompatCache
2009-05-04 16:21 . 2009-05-04 16:21 -------- d-sh--w c:\documents and settings\frazeesw\PrivacIE
2009-05-04 16:20 . 2009-05-04 16:20 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-04 16:19 . 2009-05-04 16:19 -------- d-sh--w c:\windows\system32\config\systemprofile\IETldCache
2009-05-04 16:18 . 2009-05-04 16:18 -------- d-sh--w c:\documents and settings\frazeesw\IETldCache
2009-05-04 16:15 . 2009-05-04 16:15 -------- d-----w c:\windows\ie8updates
2009-05-04 16:15 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-05-04 16:14 . 2009-05-04 16:15 -------- dc-h--w c:\windows\ie8
2009-05-04 15:30 . 2009-05-04 15:30 -------- d-----w C:\59e88acc174b21d10775
2009-05-04 04:45 . 2009-05-04 16:14 -------- d-----w c:\documents and settings\frazeesw\Application Data\pidle
2009-04-19 18:08 . 2009-04-19 18:08 -------- d-----w c:\program files\Common Files\DivX Shared
2009-04-15 02:54 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-15 02:54 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 02:54 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-15 02:54 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 02:54 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 02:54 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 02:54 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 02:54 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 02:54 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 02:52 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-15 02:52 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 17:21 . 2007-07-26 15:19 150816 ----a-w c:\documents and settings\frazeesw\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-04 15:38 . 2007-06-07 19:21 -------- d-----w c:\program files\Microsoft Works
2009-04-19 18:08 . 2007-09-04 23:01 -------- d-----w c:\program files\DivX
2009-04-04 03:53 . 2009-04-04 03:50 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-08 10:34 . 2006-10-06 15:09 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 10:34 . 2006-10-06 15:12 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 10:33 . 2006-10-06 15:11 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 10:33 . 2006-10-06 15:15 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 10:32 . 2006-10-06 15:10 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 10:32 . 2006-10-06 15:12 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 10:31 . 2006-10-06 15:12 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 10:31 . 2006-10-06 15:13 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 10:31 . 2006-10-06 15:13 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 10:22 . 2006-10-06 15:13 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2006-10-06 15:13 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-24 19:34 . 2009-02-24 19:34 90112 ----a-w c:\windows\system32\dpl100.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-02-24 19:34 . 2009-02-24 19:34 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-02-24 19:34 . 2009-02-24 19:34 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-02-24 19:34 . 2009-02-24 19:34 684032 ----a-w c:\windows\system32\DivX.dll
2009-02-09 12:10 . 2006-10-06 15:09 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2006-10-06 15:09 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2006-10-06 15:09 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2006-10-06 15:09 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 11:13 . 2006-10-06 15:09 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2006-10-06 15:09 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2006-10-06 15:13 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2006-10-06 15:14 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-09-17 14:03 . 2008-09-17 13:59 27379 ----a-r c:\program files\UNINST.ISU
1999-05-18 03:27 . 2008-09-17 13:59 30483 ------r c:\program files\CHEMENG.HLP
1999-05-14 11:08 . 2008-09-17 13:59 189447 ------r c:\program files\EZTUT.HLP
1999-04-26 18:40 . 2008-09-17 13:59 797464 ------r c:\program files\CHENG.SBK
1999-04-08 20:04 . 2008-09-17 13:59 7347 ------r c:\program files\README.TXT
1999-03-17 20:48 . 2008-09-17 13:59 174160 ------r c:\program files\SPLASH.BMP
1999-01-11 05:45 . 2008-09-17 13:59 525176 ------r c:\program files\CHENGSYS.TBK
1998-12-18 21:13 . 2008-09-17 13:59 1790400 ------r c:\program files\EZSOLVE.EXE
1998-11-20 21:37 . 2008-09-17 13:59 773559 ------r c:\program files\PLOT2D.DLL
1998-07-24 21:15 . 2008-09-17 13:59 78634 ------r c:\program files\EZSOLVE.HLP
1998-07-24 19:53 . 2008-09-17 13:59 181968 ------r c:\program files\NEWSOLV.DLL
1998-07-24 17:23 . 2008-09-17 13:59 321040 ------r c:\program files\ODEMGR.DLL
1998-07-22 16:18 . 2008-09-17 13:59 87612 ------r c:\program files\IPPROD2.SBK
1998-07-17 12:58 . 2008-09-17 13:59 495120 ------r c:\program files\ANIMDLL.DLL
1998-07-15 17:37 . 2008-09-17 13:59 1827344 ------r c:\program files\MODEDLL.DLL
1998-07-15 13:51 . 2008-09-17 13:59 254696 ------r c:\program files\CHEMENG.EXE
1998-06-23 21:12 . 2008-09-17 13:59 163920 ------r c:\program files\OPENAPP.DLL
1998-06-19 20:36 . 2008-09-17 13:59 426430 ------r c:\program files\PLOT2D2.TBK
1998-05-15 14:42 . 2008-09-17 13:59 766 ------r c:\program files\ECEE.ICO
1998-05-08 14:28 . 2008-09-17 13:59 766 ------r c:\program files\ILS2.ICO
1998-05-03 15:00 . 2008-09-17 13:59 38414 ------r c:\program files\ASODE.DLL
1998-04-07 16:37 . 2008-09-17 13:59 42350 ------r c:\program files\EIGVAL.DLL
1998-03-17 17:42 . 2008-09-17 13:59 766 ------r c:\program files\ILS.ICO
1998-03-12 17:31 . 2008-09-17 13:59 766 ------r c:\program files\PROPERTY.ICO
1998-03-12 17:31 . 2008-09-17 13:59 766 ------r c:\program files\MSPLUS.ICO
1998-03-12 17:31 . 2008-09-17 13:59 766 ------r c:\program files\CHEMENG.ICO
1998-03-12 17:31 . 2008-09-17 13:59 766 ------r c:\program files\CHEM.ICO
1998-03-11 20:40 . 2008-09-17 13:59 101174 ------r c:\program files\FORMULA.TBK
1998-01-07 19:29 . 2008-09-17 13:59 57568 ------r c:\program files\FORMED.DLL
1997-12-22 23:21 . 2008-09-17 13:59 58964 ------r c:\program files\DATADLL.DLL
1997-08-20 14:34 . 2008-09-17 13:59 112694 ------r c:\program files\MISCFUNC.DLL
1997-06-05 17:39 . 2008-09-17 13:59 54272 ------r c:\program files\FUNCEVAL.DLL
1997-05-30 17:27 . 2008-09-17 13:59 29244 ------r c:\program files\DLGMGR.DLL
1997-04-15 12:30 . 2008-09-17 13:59 90186 ------r c:\program files\DATATBL.TBK
1997-03-25 22:12 . 2008-09-17 13:59 128096 ------r c:\program files\TB50VBX.DLL
1997-03-21 18:14 . 2008-09-17 13:59 36784 ------r c:\program files\FEVAL.TBK
1997-03-21 18:14 . 2008-09-17 13:59 51422 ------r c:\program files\IPTOOLS.TBK
1996-11-14 09:01 . 2008-09-17 13:59 515713 ------r c:\program files\TB50R.SBK
1996-11-14 09:01 . 2008-09-17 13:59 105136 ------r c:\program files\TB50HYP.SBK
1996-10-30 13:50 . 2008-09-17 13:59 20160 ------r c:\program files\EQCOMPAR.DLL
1996-06-14 21:06 . 2008-09-17 13:59 225040 ------r c:\program files\PLOT3D.DLL
1996-03-26 16:12 . 2008-09-17 13:59 23040 ------r c:\program files\FPFIX.DLL
1996-01-06 16:50 . 2008-09-17 13:59 22272 ------r c:\program files\IPVARDB.DLL
1995-10-16 17:29 . 2008-09-17 13:59 20818 ------r c:\program files\ENVPATH.DLL
1995-02-02 20:15 . 2008-09-17 13:59 31934 ------r c:\program files\LMSOLVE.DLL
1995-01-31 16:09 . 2008-09-17 13:59 2304 ------r c:\program files\HASHEXT.DLL
1994-11-16 00:02 . 2008-09-17 13:59 4880 ------r c:\program files\WINMOVE.DLL
1994-08-02 12:10 . 2008-09-17 13:59 3344 ------r c:\program files\PALETMAN.DLL
1994-02-01 21:48 . 2008-09-17 13:59 10768 ------r c:\program files\TBPROPS.DLL
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-05 23:03 . 2007-10-11 00:51 39792 c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
2008-01-12 03:16 . 2008-01-12 03:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

2007-06-06 20:50 . 2005-05-20 13:11 925696 c:\program files\Analog Devices\Core\bak\smax4pnp.exe

2007-06-07 13:00 . 2005-05-06 18:06 716800 c:\program files\Analog Devices\SoundMAX\bak\Smax4.exe

2005-08-12 18:43 . 2005-08-12 18:43 45056 c:\program files\ATI Technologies\ATI.ACE\bak\cli.exe

2007-08-16 00:15 . 2007-08-16 00:15 271672 c:\program files\iTunes\bak\iTunesHelper.exe
2008-10-02 01:57 . 2008-10-02 01:57 289576 c:\program files\iTunes\iTunesHelper.exe

2007-06-07 19:55 . 2006-12-19 15:27 136768 c:\program files\McAfee\Common Framework\bak\UdaterUI.exe

2007-02-23 00:50 . 2007-02-23 00:50 112216 c:\program files\McAfee\VirusScan Enterprise\bak\SHSTAT.EXE

2007-05-17 21:45 . 2007-05-17 21:45 279912 c:\program files\Microsoft LifeCam\bak\LifeExp.exe

2006-10-27 04:47 . 2006-10-27 04:47 31016 c:\program files\Microsoft Office\Office12\bak\GrooveMonitor.exe
2008-10-25 17:44 . 2008-10-25 17:44 31072 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

2007-06-29 10:24 . 2007-06-29 10:24 286720 c:\program files\QuickTime\bak\qttask.exe
2008-09-06 19:09 . 2008-09-06 19:09 413696 c:\program files\QuickTime\QTTask.exe

2007-06-07 13:04 . 2007-01-12 18:36 827392 c:\program files\Synaptics\SynTP\bak\SynTPEnh.exe
2008-05-09 15:01 . 2007-09-15 09:27 1015808 c:\program files\Synaptics\SynTP\SynTPEnh.exe

2006-11-03 23:20 . 2006-11-03 23:20 866584 c:\program files\Windows Defender\bak\MSASCui.exe

2007-10-22 16:21 . 2007-04-10 21:46 709992 c:\windows\bak\vVX1000.exe

2006-10-06 15:16 . 2004-08-04 12:00 15360 c:\windows\system32\bak\ctfmon.exe
2006-10-06 15:16 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe

2007-06-07 20:03 . 2005-08-31 09:20 122940 c:\windows\system32\DLA\bak\DLACTRLW.EXE

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [N/A]
"StickerLite"="c:\program files\MoRUN.net\Sticker Lite\sticker.exe" [2008-01-16 255488]
"prnet"="c:\windows\system32\prnet.tmp" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FRYMXINS"="c:\program files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl" [X]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 131072]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1015808]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-30 185896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\frazeesw\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AfsLogon]
2007-05-17 18:36 87664 ----a-w c:\windows\system32\afslogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MIT_KFW]
2007-05-03 03:59 23040 ----a-w c:\windows\system32\kfwlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Nortel Networks\\Extranet.exe"=
"c:\\Program Files\\Maple 11\\jre\\bin\\maple.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Maple 11\\jre\\bin\\java.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\MoRUN.net\\Sticker Lite\\sticker.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7001:UDP"= 7001:UDP:AFS CacheManager Callback (UDP)

R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 5:19 PM 13592]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [6/14/2007 8:47 AM 9049]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [6/7/2007 7:11 AM 88192]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [6/6/2007 2:49 PM 36352]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [6/14/2007 8:47 AM 115008]
S3 mfefeatk01;McAfee Inc.;\Device\mfefeatk01.sys --> \Device\mfefeatk01.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20707be4-e018-11dd-b0dc-444553544200}]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ac4e364-7e95-11dd-b040-444553544200}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68882338-e874-11dc-af12-444553544200}]
\Shell\AutoRun\command - E:\Autorun.exe /run
\Shell\Shell00\Command - E:\Autorun.exe /run
\Shell\Shell01\Command - E:\Autorun.exe /action
\Shell\Shell02\Command - E:\Autorun.exe /uninstall

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9fa52591-ebac-11dc-af1f-444553544200}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 16:34]

2009-05-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-06 02:44]

2009-05-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
- - - - ORPHANS REMOVED - - - -

BHO-{C2BA40A1-74F3-42BD-F434-12345A2C8953} - c:\windows\system32\afnoinkdsfe.dll
SharedTaskScheduler-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\vozanije.dll
SharedTaskScheduler-{C2BA40A1-74F3-42BD-F434-12345A2C8953} - c:\windows\system32\afnoinkdsfe.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.mtech.edu/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: antimalwareguard.com
Trusted Zone: antimalwareguard.com
FF - ProfilePath - c:\documents and settings\frazeesw\Application Data\Mozilla\Firefox\Profiles\kjmy1sgj.default\
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
.
.
------- File Associations -------
.
regfile\shell\edit\command=%SystemRoot%\system32\NOTEPAD.EXE %1
vbefile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
vbsfile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
jsefile\shell\edit\command=%SystemRoot%\System32\Notepad.exe %1
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-05 11:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\TEMP\TMP00000001CD3ABE0FC480CE4C 524288 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1112)
c:\program files\mit\kerberos\bin\krb5_32.dll
c:\program files\mit\kerberos\bin\comerr32.dll
c:\program files\mit\kerberos\bin\k5sprt32.dll
c:\program files\mit\kerberos\bin\krb524.dll
c:\program files\mit\kerberos\bin\xpprof32.dll
c:\program files\mit\kerberos\bin\leashw32.dll
c:\program files\mit\kerberos\bin\krbcc32.dll
c:\program files\mit\kerberos\bin\krbv4w32.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\kfwlogon.dll

- - - - - - - > 'explorer.exe'(2648)
c:\program files\TortoiseSVN\bin\tortoisesvn.dll
c:\program files\TortoiseSVN\bin\intl3_svn.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\scardsvr.exe
c:\program files\MIT\Kerberos\bin\krbcc32s.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\CCM\CcmExec.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\ati2evxx.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-05 11:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-05 17:55

Pre-Run: 44,696,154,112 bytes free
Post-Run: 44,726,857,728 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

355 --- E O F --- 2009-05-04 15:08


and the new hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:00:35 PM, on 5/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MoRUN.net\Sticker Lite\sticker.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\frazeesw\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mtech.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [FRYMXINS] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [StickerLite] C:\Program Files\MoRUN.net\Sticker Lite\sticker.exe
O4 - HKCU\..\Run: [prnet] "C:\WINDOWS\system32\prnet.tmp"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1220621775968
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rose-hulman.edu
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = rose-hulman.edu,dhcp.rose-hulman.edu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: AfsLogon - C:\WINDOWS\SYSTEM32\afslogon.dll
O20 - Winlogon Notify: MIT_KFW - C:\WINDOWS\SYSTEM32\kfwlogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OpenAFS Client Service (TransarcAFSDaemon) - OpenAFS Project - C:\Program Files\OpenAFS\Client\Program\afsd_service.exe

--
End of file - 8054 bytes


and the uninstall list

AC3Filter (remove only)
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.2
Adobe Shockwave Player 11
Advertisement Service
Agere Systems HDA Modem
Apple Mobile Device Support
Apple Software Update
ArcGIS Desktop
ArcSoft PhotoImpression 6
ArcSoft Print Creations
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
Autodesk Express Viewer
Bonjour
Critical Update for Windows Media Player 11 (KB959772)
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Web Player
EPSON CX7400 User's Guide
EPSON Printer Software
EPSON Scan
EPSON Stylus CX7400 Series Scanner Driver Update
ERUNT 1.1j
FireGL driver for 3D Studio MAX/VIZ
Getting to Know ArcGIS Desktop Exercise Data
Google Earth
Google Updater
GPL MPEG-1/2 DirectShow Decoder Filter
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HP Quick Launch Buttons 6.00 D2
InterVideo DVD Check
InterVideo WinDVD
iTunes
Java Access Bridge
Java(TM) SE Development Kit 6 Update 1
Java(TM) SE Runtime Environment 6 Update 1
Kerberos for Windows
Logger Pro 3.5.0
Maple 11
MATLAB R2007a
McAfee VirusScan Enterprise
Mechanical Desktop 2004
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft LifeCam
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office SharePoint Designer 2007
Microsoft Office SharePoint Designer 2007
Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)
Microsoft Office SharePoint Designer MUI (English) 2007
Microsoft Office Visio 2007 Service Pack 2 (SP2)
Microsoft Office Visio 2007 Service Pack 2 (SP2)
Microsoft Office Visio MUI (English) 2007
Microsoft Office Visio Professional 2007
Microsoft Office Visio Professional 2007
Microsoft Office Word MUI (English) 2007
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MobileMe Control Panel
MoRUN.net Sticker
Mozilla Firefox (3.0.1)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
Nortel Networks Contivity VPN Client
OpenAFS for Windows
Pdf995
PdfEdit995
Python 2.4.1
Python 2.5.1
QuickTime
RealPlayer
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Signature995
Solid Edge V19
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic DLA
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
SoundMAX
Spybot - Search & Destroy
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
TortoiseSVN 1.4.3.8645 (32 bit)
Update for 2007 Microsoft Office System (KB967642)
Update for 2007 Microsoft Office System (KB967642)
Update for 2007 Microsoft Office System (KB967642)
Update for Outlook 2007 Junk Email Filter (kb968503)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VanDyke Software SecureCRT 5.5
VanDyke Software SecureFX 4.5
VC80CRTRedist - 8.0.50727.762
WD Diagnostics
Windows Defender
Windows Imaging Component
Windows Internet Explorer 8
Windows Live installer
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR archiver

pskelley
2009-05-05, 22:40
You have a nasty infection called AWF, here is a little information about it. Hopefully combofix will fix it for us.
http://en.wikipedia.org/wiki/Agent.AWF

It also looks like you are using a USB or Flash drive, are you sure it is not infected?

Proceed carefully in the numbered order.

1) Please download ATF Cleaner by Atribune
http://www.atribune.org/public-beta/ATF-Cleaner.exe
Save it to your Desktop. We will use this later.

2) Open notepad and copy/paste the text in the codebox below into it:


AWF:
c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
c:\program files\Analog Devices\Core\bak\smax4pnp.exe
c:\program files\Analog Devices\SoundMAX\bak\Smax4.exe
c:\program files\ATI Technologies\ATI.ACE\bak\cli.exe
c:\program files\iTunes\bak\iTunesHelper.exe
c:\program files\McAfee\Common Framework\bak\UdaterUI.exe
c:\program files\McAfee\VirusScan Enterprise\bak\SHSTAT.EXE
c:\program files\Microsoft LifeCam\bak\LifeExp.exe
c:\program files\Microsoft Office\Office12\bak\GrooveMonitor.exe
c:\program files\QuickTime\bak\qttask.exe
c:\program files\Synaptics\SynTP\bak\SynTPEnh.exe
c:\program files\Windows Defender\bak\MSASCui.exe
c:\windows\bak\vVX1000.exe
c:\windows\system32\bak\ctfmon.exe
c:\windows\system32\DLA\bak\DLACTRLW.EXE

File::
C:\WINDOWS\system32\prnet.tmp

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20707be4-e018-11dd-b0dc-444553544200}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ac4e364-7e95-11dd-b040-444553544200}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{68882338-e874-11dc-af12-444553544200}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9fa52591-ebac-11dc-af1f-444553544200}]

Folder::
c:\windows\TEMP\TMP00000001CD3ABE0FC480CE4C

Save this as CFScript

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Referring to the picture above, drag CFScript into ComboFix.exe.

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log. (wait until you finish to post the logs)

3) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

(may be gone)

O4 - HKCU\..\Run: [prnet] "C:\WINDOWS\system32\prnet.tmp"

Close all programs but HJT and all browser windows, then click on "Fix Checked"

4) Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

*Cleaning Prefetch may result in a few slow starts until the folder is repopulated:
http://www.windowsnetworking.com/articles_tutorials/Gaining-Speed-Empty-Prefetch-XP.html

5) Download Malwarebytes' Anti-Malware to your Desktop
http://www.malwarebytes.org/

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
* Please post the log from CFScript, the log from MBAM and a new HJT log.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Tutorial if needed:
http://www.techsupportteam.org/forum/tutorials/2282-malwarebytes-anti-malware-mbam.html

How is the computer running now?

Thanks

Uninstall list: I look for malware and security issues and will not know all of your programs, but you should.
Hackers are using out of date programs to infect folks more and more,
Here is a small free tool that lets you know when something needs an update if you are interested:
http://secunia.com/vulnerability_scanning/personal/ While PSI runs in the System Tray for realtime notifications, I personally prefer to turn it off in MSConfig and run it from All Programs when I want to do a check.

Adobe Flash Player 10 ActiveX
Adobe recommends all users of Adobe Flash Player 10.0.12.36 and earlier versions upgrade to the newest version 10.0.22.87
http://www.adobe.com/support/security/bulletins/apsb09-01.html

Adobe Reader 8.1.2 <<< out of date and unsafe, see this:
http://news.cnet.com/8301-1009_3-10081618-83.html?tag=nl.e433
http://blogs.adobe.com/psirt/2009/04/update_on_adobe_reader_issue.html
http://www.filehippo.com/download_adobe_reader/
(if you want a smaller program, look at this one)
Foxit Reader 2.3 for Windows (make sure to uncheck any toolbars)
http://www.foxitsoftware.com/pdf/rd_intro.php

Java(TM) SE Runtime Environment 6 Update 1 <<< out of date and unsafe, see this:
http://forums.spybot.info/showpost.php?p=12880&postcount=2
Be aware of this information so you can opt out of anything you do not want.
Microsoft Does MSN Toolbar Distribution Deal With Java:
http://searchengineland.com/microsoft-does-msn-toolbar-distribution-deal-with-java-15413.php

sfrazee
2009-05-06, 00:14
I did plug my usb flash drive into my laptop last night but the computer never recognized it (thats never happened before). It never showed up on "my computer" but i could "safely remove" it and that was it. Not sure what that means, i guess it could be infected :confused:

Computer seems to be running ok i guess. Im not really seeing any obvious symptoms from an infection. Previously i would get redirected when i clicked on google search links but that doesn't seem to be happening anymore. I was also getting a message that said something about being redirected to another website but i havent seen that since the most recent scans and fixes.

so should i go ahead and update those programs you listed from the uninstall list now? or should i wait until you think all the bad stuff is gone?

thanks again for all your help

Combofix log

ComboFix 09-05-04.A3 - frazeesw 05/05/2009 13:53.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1498 [GMT -6:00]
Running from: c:\documents and settings\frazeesw\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\frazeesw\Desktop\CFScript.txt
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Outdated)

FILE ::
c:\windows\system32\prnet.tmp
.

((((((((((((((((((((((((( Files Created from 2009-04-05 to 2009-05-05 )))))))))))))))))))))))))))))))
.

2009-05-04 17:05 . 2009-05-04 17:05 -------- d-----w c:\program files\ERUNT
2009-05-04 17:02 . 2009-05-04 17:02 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-05-04 16:21 . 2009-05-04 16:21 -------- d-sh--w c:\documents and settings\frazeesw\IECompatCache
2009-05-04 16:21 . 2009-05-04 16:21 -------- d-sh--w c:\documents and settings\frazeesw\PrivacIE
2009-05-04 16:20 . 2009-05-04 16:20 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-04 16:19 . 2009-05-04 16:19 -------- d-sh--w c:\windows\system32\config\systemprofile\IETldCache
2009-05-04 16:18 . 2009-05-04 16:18 -------- d-sh--w c:\documents and settings\frazeesw\IETldCache
2009-05-04 16:15 . 2009-05-04 16:15 -------- d-----w c:\windows\ie8updates
2009-05-04 16:15 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-05-04 16:14 . 2009-05-04 16:15 -------- dc-h--w c:\windows\ie8
2009-05-04 15:30 . 2009-05-04 15:30 -------- d-----w C:\59e88acc174b21d10775
2009-05-04 04:45 . 2009-05-04 16:14 -------- d-----w c:\documents and settings\frazeesw\Application Data\pidle
2009-04-19 18:08 . 2009-04-19 18:08 -------- d-----w c:\program files\Common Files\DivX Shared
2009-04-15 02:54 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-15 02:54 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 02:54 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-15 02:54 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 02:54 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 02:54 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 02:54 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 02:54 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 02:54 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 02:52 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-15 02:52 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 17:21 . 2007-07-26 15:19 150816 ----a-w c:\documents and settings\frazeesw\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-04 15:38 . 2007-06-07 19:21 -------- d-----w c:\program files\Microsoft Works
2009-04-19 18:08 . 2007-09-04 23:01 -------- d-----w c:\program files\DivX
2009-04-04 03:53 . 2009-04-04 03:50 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-08 10:34 . 2006-10-06 15:09 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 10:34 . 2006-10-06 15:12 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 10:33 . 2006-10-06 15:11 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 10:33 . 2006-10-06 15:15 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 10:32 . 2006-10-06 15:10 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 10:32 . 2006-10-06 15:12 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 10:31 . 2006-10-06 15:12 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 10:31 . 2006-10-06 15:13 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 10:31 . 2006-10-06 15:13 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 10:22 . 2006-10-06 15:13 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2006-10-06 15:13 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-24 19:34 . 2009-02-24 19:34 90112 ----a-w c:\windows\system32\dpl100.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-02-24 19:34 . 2009-02-24 19:34 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-02-24 19:34 . 2009-02-24 19:34 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-02-24 19:34 . 2009-02-24 19:34 684032 ----a-w c:\windows\system32\DivX.dll
2009-02-09 12:10 . 2006-10-06 15:09 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2006-10-06 15:09 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2006-10-06 15:09 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2006-10-06 15:09 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 11:13 . 2006-10-06 15:09 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2006-10-06 15:09 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2006-10-06 15:13 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2006-10-06 15:14 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-09-17 14:03 . 2008-09-17 13:59 27379 ----a-r c:\program files\UNINST.ISU
1999-05-18 03:27 . 2008-09-17 13:59 30483 ------r c:\program files\CHEMENG.HLP
1999-05-14 11:08 . 2008-09-17 13:59 189447 ------r c:\program files\EZTUT.HLP
1999-04-26 18:40 . 2008-09-17 13:59 797464 ------r c:\program files\CHENG.SBK
1999-04-08 20:04 . 2008-09-17 13:59 7347 ------r c:\program files\README.TXT
1999-03-17 20:48 . 2008-09-17 13:59 174160 ------r c:\program files\SPLASH.BMP
1999-01-11 05:45 . 2008-09-17 13:59 525176 ------r c:\program files\CHENGSYS.TBK
1998-12-18 21:13 . 2008-09-17 13:59 1790400 ------r c:\program files\EZSOLVE.EXE
1998-11-20 21:37 . 2008-09-17 13:59 773559 ------r c:\program files\PLOT2D.DLL
1998-07-24 21:15 . 2008-09-17 13:59 78634 ------r c:\program files\EZSOLVE.HLP
1998-07-24 19:53 . 2008-09-17 13:59 181968 ------r c:\program files\NEWSOLV.DLL
1998-07-24 17:23 . 2008-09-17 13:59 321040 ------r c:\program files\ODEMGR.DLL
1998-07-22 16:18 . 2008-09-17 13:59 87612 ------r c:\program files\IPPROD2.SBK
1998-07-17 12:58 . 2008-09-17 13:59 495120 ------r c:\program files\ANIMDLL.DLL
1998-07-15 17:37 . 2008-09-17 13:59 1827344 ------r c:\program files\MODEDLL.DLL
1998-07-15 13:51 . 2008-09-17 13:59 254696 ------r c:\program files\CHEMENG.EXE
1998-06-23 21:12 . 2008-09-17 13:59 163920 ------r c:\program files\OPENAPP.DLL
1998-06-19 20:36 . 2008-09-17 13:59 426430 ------r c:\program files\PLOT2D2.TBK
1998-05-15 14:42 . 2008-09-17 13:59 766 ------r c:\program files\ECEE.ICO
1998-05-08 14:28 . 2008-09-17 13:59 766 ------r c:\program files\ILS2.ICO
1998-05-03 15:00 . 2008-09-17 13:59 38414 ------r c:\program files\ASODE.DLL
1998-04-07 16:37 . 2008-09-17 13:59 42350 ------r c:\program files\EIGVAL.DLL
1998-03-17 17:42 . 2008-09-17 13:59 766 ------r c:\program files\ILS.ICO
1998-03-12 17:31 . 2008-09-17 13:59 766 ------r c:\program files\PROPERTY.ICO
1998-03-12 17:31 . 2008-09-17 13:59 766 ------r c:\program files\MSPLUS.ICO
1998-03-12 17:31 . 2008-09-17 13:59 766 ------r c:\program files\CHEMENG.ICO
1998-03-12 17:31 . 2008-09-17 13:59 766 ------r c:\program files\CHEM.ICO
1998-03-11 20:40 . 2008-09-17 13:59 101174 ------r c:\program files\FORMULA.TBK
1998-01-07 19:29 . 2008-09-17 13:59 57568 ------r c:\program files\FORMED.DLL
1997-12-22 23:21 . 2008-09-17 13:59 58964 ------r c:\program files\DATADLL.DLL
1997-08-20 14:34 . 2008-09-17 13:59 112694 ------r c:\program files\MISCFUNC.DLL
1997-06-05 17:39 . 2008-09-17 13:59 54272 ------r c:\program files\FUNCEVAL.DLL
1997-05-30 17:27 . 2008-09-17 13:59 29244 ------r c:\program files\DLGMGR.DLL
1997-04-15 12:30 . 2008-09-17 13:59 90186 ------r c:\program files\DATATBL.TBK
1997-03-25 22:12 . 2008-09-17 13:59 128096 ------r c:\program files\TB50VBX.DLL
1997-03-21 18:14 . 2008-09-17 13:59 36784 ------r c:\program files\FEVAL.TBK
1997-03-21 18:14 . 2008-09-17 13:59 51422 ------r c:\program files\IPTOOLS.TBK
1996-11-14 09:01 . 2008-09-17 13:59 515713 ------r c:\program files\TB50R.SBK
1996-11-14 09:01 . 2008-09-17 13:59 105136 ------r c:\program files\TB50HYP.SBK
1996-10-30 13:50 . 2008-09-17 13:59 20160 ------r c:\program files\EQCOMPAR.DLL
1996-06-14 21:06 . 2008-09-17 13:59 225040 ------r c:\program files\PLOT3D.DLL
1996-03-26 16:12 . 2008-09-17 13:59 23040 ------r c:\program files\FPFIX.DLL
1996-01-06 16:50 . 2008-09-17 13:59 22272 ------r c:\program files\IPVARDB.DLL
1995-10-16 17:29 . 2008-09-17 13:59 20818 ------r c:\program files\ENVPATH.DLL
1995-02-02 20:15 . 2008-09-17 13:59 31934 ------r c:\program files\LMSOLVE.DLL
1995-01-31 16:09 . 2008-09-17 13:59 2304 ------r c:\program files\HASHEXT.DLL
1994-11-16 00:02 . 2008-09-17 13:59 4880 ------r c:\program files\WINMOVE.DLL
1994-08-02 12:10 . 2008-09-17 13:59 3344 ------r c:\program files\PALETMAN.DLL
1994-02-01 21:48 . 2008-09-17 13:59 10768 ------r c:\program files\TBPROPS.DLL
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-05_17.50.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-10-06 15:10 . 2009-05-05 17:54 70650 c:\windows\system32\perfc009.dat
- 2006-10-06 15:10 . 2009-05-05 17:52 70650 c:\windows\system32\perfc009.dat
+ 2006-10-06 15:10 . 2009-05-05 17:54 440032 c:\windows\system32\perfh009.dat
- 2006-10-06 15:10 . 2009-05-05 17:52 440032 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-05 23:03 . 2007-10-11 00:51 39792 c:\program files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe
2008-01-12 03:16 . 2008-01-12 03:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

2007-06-06 20:50 . 2005-05-20 13:11 925696 c:\program files\Analog Devices\Core\bak\smax4pnp.exe

2007-06-07 13:00 . 2005-05-06 18:06 716800 c:\program files\Analog Devices\SoundMAX\bak\Smax4.exe

2005-08-12 18:43 . 2005-08-12 18:43 45056 c:\program files\ATI Technologies\ATI.ACE\bak\cli.exe

2007-08-16 00:15 . 2007-08-16 00:15 271672 c:\program files\iTunes\bak\iTunesHelper.exe
2008-10-02 01:57 . 2008-10-02 01:57 289576 c:\program files\iTunes\iTunesHelper.exe

2007-06-07 19:55 . 2006-12-19 15:27 136768 c:\program files\McAfee\Common Framework\bak\UdaterUI.exe

2007-02-23 00:50 . 2007-02-23 00:50 112216 c:\program files\McAfee\VirusScan Enterprise\bak\SHSTAT.EXE

2007-05-17 21:45 . 2007-05-17 21:45 279912 c:\program files\Microsoft LifeCam\bak\LifeExp.exe

2006-10-27 04:47 . 2006-10-27 04:47 31016 c:\program files\Microsoft Office\Office12\bak\GrooveMonitor.exe
2008-10-25 17:44 . 2008-10-25 17:44 31072 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

2007-06-29 10:24 . 2007-06-29 10:24 286720 c:\program files\QuickTime\bak\qttask.exe
2008-09-06 19:09 . 2008-09-06 19:09 413696 c:\program files\QuickTime\QTTask.exe

2007-06-07 13:04 . 2007-01-12 18:36 827392 c:\program files\Synaptics\SynTP\bak\SynTPEnh.exe
2008-05-09 15:01 . 2007-09-15 09:27 1015808 c:\program files\Synaptics\SynTP\SynTPEnh.exe

2006-11-03 23:20 . 2006-11-03 23:20 866584 c:\program files\Windows Defender\bak\MSASCui.exe

2007-10-22 16:21 . 2007-04-10 21:46 709992 c:\windows\bak\vVX1000.exe

2006-10-06 15:16 . 2004-08-04 12:00 15360 c:\windows\system32\bak\ctfmon.exe
2006-10-06 15:16 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe

2007-06-07 20:03 . 2005-08-31 09:20 122940 c:\windows\system32\DLA\bak\DLACTRLW.EXE

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-02-04 14:11 536576 ------r c:\program files\TortoiseSVN\bin\TortoiseSVN.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [N/A]
"StickerLite"="c:\program files\MoRUN.net\Sticker Lite\sticker.exe" [2008-01-16 255488]
"prnet"="c:\windows\system32\prnet.tmp" [N/A]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FRYMXINS"="c:\program files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl" [X]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-02 131072]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-09-15 1015808]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-30 185896]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

c:\documents and settings\frazeesw\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AfsLogon]
2007-05-17 18:36 87664 ----a-w c:\windows\system32\afslogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MIT_KFW]
2007-05-03 03:59 23040 ----a-w c:\windows\system32\kfwlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Nortel Networks\\Extranet.exe"=
"c:\\Program Files\\Maple 11\\jre\\bin\\maple.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Maple 11\\jre\\bin\\java.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\MoRUN.net\\Sticker Lite\\sticker.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7001:UDP"= 7001:UDP:AFS CacheManager Callback (UDP)

R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 5:19 PM 13592]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [6/14/2007 8:47 AM 9049]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [6/7/2007 7:11 AM 88192]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [6/6/2007 2:49 PM 36352]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [6/14/2007 8:47 AM 115008]
S3 mfefeatk01;McAfee Inc.;\Device\mfefeatk01.sys --> \Device\mfefeatk01.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 16:34]

2009-05-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-06 02:44]

2009-05-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.mtech.edu/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: antimalwareguard.com
Trusted Zone: antimalwareguard.com
FF - ProfilePath - c:\documents and settings\frazeesw\Application Data\Mozilla\Firefox\Profiles\kjmy1sgj.default\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-05 13:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\docume~1\frazeesw\LOCALS~1\Temp\catchme.dll 53248 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1112)
c:\program files\mit\kerberos\bin\krb5_32.dll
c:\program files\mit\kerberos\bin\comerr32.dll
c:\program files\mit\kerberos\bin\k5sprt32.dll
c:\program files\mit\kerberos\bin\krb524.dll
c:\program files\mit\kerberos\bin\xpprof32.dll
c:\program files\mit\kerberos\bin\leashw32.dll
c:\program files\mit\kerberos\bin\krbcc32.dll
c:\program files\mit\kerberos\bin\krbv4w32.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\kfwlogon.dll

- - - - - - - > 'explorer.exe'(2836)
c:\program files\TortoiseSVN\bin\tortoisesvn.dll
c:\program files\TortoiseSVN\bin\intl3_svn.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-05 13:55
ComboFix-quarantined-files.txt 2009-05-05 19:55
ComboFix2.txt 2009-05-05 17:55

Pre-Run: 44,672,647,168 bytes free
Post-Run: 44,658,200,576 bytes free

291 --- E O F --- 2009-05-04 15:08


MBAM log

Malwarebytes' Anti-Malware 1.36
Database version: 2079
Windows 5.1.2600 Service Pack 3

5/5/2009 2:54:34 PM
mbam-log-2009-05-05 (14-54-34).txt

Scan type: Full Scan (C:\|)
Objects scanned: 309506
Time elapsed: 45 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 33

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
KHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\prnet (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Documents and Settings\frazeesw\Application Data\pidle (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthqlgwkvmaebxcaegampdftpxpsdjeexkh.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthrcqmrrkwdhlvismrvttjjbexigepsoxh.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ovfsthaquqjpnismhnapfsokocmmxpubaiuxxq.sys.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{856EC8A3-AA77-4FB5-9A35-4F24F1799E61}\RP542\A0092882.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{856EC8A3-AA77-4FB5-9A35-4F24F1799E61}\RP542\A0092884.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{856EC8A3-AA77-4FB5-9A35-4F24F1799E61}\RP542\A0092885.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Program Files\ANIMDLL.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\ASODE.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\DATADLL.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\DLGMGR.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\EIGVAL.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\ENVPATH.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\EQCOMPAR.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\FORMED.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\FPFIX.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\FUNCEVAL.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\HASHEXT.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\IPVARDB.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\LMSOLVE.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\MISCFUNC.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\MODEDLL.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\NEWSOLV.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\OPENAPP.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\PALETMAN.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\PCDLIB.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\PCDXBMP.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\PHOTO.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\PLOT2D.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\PLOT3D.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\TB50RCA.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\TB50RCR.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\TBPROPS.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\WINMOVE.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.


HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:12:15 PM, on 5/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MoRUN.net\Sticker Lite\sticker.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\McAfee\Common Framework\McScript.exe
C:\Documents and Settings\frazeesw\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mtech.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [FRYMXINS] "C:\Program Files\ATI Technologies\Fire GL 3D Studio Max\atiimxgl"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [StickerLite] C:\Program Files\MoRUN.net\Sticker Lite\sticker.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1220621775968
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = rose-hulman.edu
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = rose-hulman.edu,dhcp.rose-hulman.edu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: AfsLogon - C:\WINDOWS\SYSTEM32\afslogon.dll
O20 - Winlogon Notify: MIT_KFW - C:\WINDOWS\SYSTEM32\kfwlogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: OpenAFS Client Service (TransarcAFSDaemon) - OpenAFS Project - C:\Program Files\OpenAFS\Client\Program\afsd_service.exe

--
End of file - 8049 bytes

pskelley
2009-05-06, 00:39
Let's proceed like this to be sure:

1) Go ahead and insert the Flash Drive

Download Flash_Disinfector.exe by sUBs from HERE (http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe) and save it to your desktop. Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Reboot your computer when done.Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.


2) I forget to remove this junk from the Trusted Zone:

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)

Close all programs but HJT and all browser windows, then click on "Fix Checked"
As long as they are gone when you check the next HJT log, I do not need to see it.

Remove combofix from the computer like this:

Click START then RUN
Now type or copy Combofix /u in the runbox and click OK.
Note the space between the X and the U, it needs to be there.

http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png

Clean the System Restore files like this:

Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Reboot

Turn ON System Restore,
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

Update MBAM and scan to be sure we missed none of the junk, there is no need to post a clean scan result.
(MBAM is yours to keep if you wish, keep it updated and run it once a month or so)

Update Windows Defender and scan the system to make sure it is working right and scanning clean.
http://www.microsoft.com/windows/products/winfamily/defender/support.mspx

Update McAfee and scan the system, to be sure it is running right and scanning clean. If you have problems with the program, contact tech support for instructions.
You must have an updated antivirus program running, if you need links to good freeware programs, let me know.

If all is well at this point, let me know and I will close the topic.

Some good information for you:
http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html
http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx

Here is some great information from experts in this field that will help you stay clean and safe online.
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

http://www.malwarecomplaints.info/

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

How hard are your passwords to crack?
http://www.microsoft.com/protect/yourself/password/checker.mspx

http://users.telenet.be/bluepatchy/miekiemoes/Links.html
http://www.microsoft.com/windows/ie/community/columns/protection.mspx
Improve the safety of your browsing and e-mail activities
http://www.microsoft.com/protect/computer/advanced/browsing.mspx

sfrazee
2009-05-06, 04:08
thank you very much for your help, you guys are great!!

sfrazee
2009-05-06, 05:25
could you post the links to some good freeware programs, please? thanks

pskelley
2009-05-06, 12:35
Already posted, look at the links:
http://users.telenet.be/bluepatchy/miekiemoes/Links.html

1) http://free.grisoft.com/ww.download-avg-anti-virus-free-edition
FAQ: http://www.avg.com/faq
AVG Free Forum: http://freeforum.avg.com/

2) http://www.avast.com/eng/avast_4_home.html
What's new in avast! version 4
http://www.avast.com/eng/whats_new_in_avast_v2.html

3) http://www.free-av.com/
http://www.free-av.com/en/support/index.html