Page 1 of 2 12 LastLast
Results 1 to 10 of 20

Thread: I think I have virtumonde - in need of lots of help

  1. #1
    Junior Member
    Join Date
    Aug 2008
    Posts
    13

    Default I think I have virtumonde - in need of lots of help

    I have tried adware, and S&D and symantec but it just doesnt want to go away. The computer was a complete mess when I started but I think I have it down to virtumonde only...at least I think. Here is the log if someone could be of help. I hope I posted it correctly after reading the before posting posts. Thank you.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:05:05 PM, on 8/22/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myembarq.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: {1832210c-e267-dc49-6914-f7f9675b10b4} - {4b01b576-9f7f-4196-94cd-762ec0122381} - C:\WINDOWS\system32\zfhzdm.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {549925D9-6F7D-49A7-93CC-D79CB1F42F90} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {81DFEAE8-AE0D-4A27-8980-64C5FA410268} - (no file)
    O4 - HKLM\..\Run: [70f73acd] rundll32.exe "C:\WINDOWS\system32\ukwdvbxj.dll",b
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [BM73c40951] Rundll32.exe "C:\WINDOWS\system32\niowwpaa.dll",s
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Startup: PowerReg Scheduler.exe
    O8 - Extra context menu item: &Search - ?p=ZCman000
    O8 - Extra context menu item: Display All Images with Full Quality - "res://C:\Program Files\Juno\qsacc\appres.dll/228"
    O8 - Extra context menu item: Display Image with Full Quality - "res://C:\Program Files\Juno\qsacc\appres.dll/227"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v48/pool/pool.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab
    O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/...nlineGames.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v45.../bejeweled.cab
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/soft...ch/alaunch.cab
    O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v64/swapit/swapit.cab
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.18.37/ttinst.cab
    O16 - DPF: {C738EA53-97C2-441B-AC52-DFBC597BCBE5} (Chess Control) - http://www.worldwinner.com/games/v48/chess/chess.cab
    O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51...ol/h2hpool.cab
    O18 - Filter hijack: text/html - (no CLSID) - (no file)
    O20 - AppInit_DLLs: zfhzdm.dll
    O20 - Winlogon Notify: iifdbXPG - iifdbXPG.dll (file missing)
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

    --
    End of file - 7879 bytes

  2. #2
    Junior Member
    Join Date
    Aug 2008
    Posts
    13

    Default

    Unfortunately I did not instruct a housemate to leave the computer alone and they tried to fix it as I did. It is currently disconnected from the internet and some programs were uninstalled and malwarebytes? is currently scanning the drive. I think that is it. Should I abort the scan and wait for my above log to be reviewed or start over? Sorry again.

  3. #3
    Junior Member
    Join Date
    Aug 2008
    Posts
    13

    Default

    I feel as though I have shot myself in the foot after replying to my post and removing the 0 count since I see more recent posts being replied too. Not sure what to do at this point. I went ahead and cleaned with malwarebytes what it found which was quite a bit and I think it may be clean now just needs some housekeeping. I did not want to start a new post so I hope this is seen and replied too. Thanks again for providing this help platform. I have learned a lot from reading this site the last few days.

  4. #4
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    Please post a fresh hjt log and earlier MBAM report (The report can be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt)
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #5
    Junior Member
    Join Date
    Aug 2008
    Posts
    13

    Default

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:01:52 AM, on 8/26/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myembarq.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {549925D9-6F7D-49A7-93CC-D79CB1F42F90} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {81DFEAE8-AE0D-4A27-8980-64C5FA410268} - (no file)
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Startup: PowerReg Scheduler.exe
    O8 - Extra context menu item: &Search - ?p=ZCman000
    O8 - Extra context menu item: Display All Images with Full Quality - "res://C:\Program Files\Juno\qsacc\appres.dll/228"
    O8 - Extra context menu item: Display Image with Full Quality - "res://C:\Program Files\Juno\qsacc\appres.dll/227"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v48/pool/pool.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab
    O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/...nlineGames.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v45.../bejeweled.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1219592234859
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/soft...ch/alaunch.cab
    O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v64/swapit/swapit.cab
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.18.37/ttinst.cab
    O16 - DPF: {C738EA53-97C2-441B-AC52-DFBC597BCBE5} (Chess Control) - http://www.worldwinner.com/games/v48/chess/chess.cab
    O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51...ol/h2hpool.cab
    O18 - Filter hijack: text/html - (no CLSID) - (no file)
    O20 - AppInit_DLLs: zfhzdm.dll
    O20 - Winlogon Notify: iifdbXPG - iifdbXPG.dll (file missing)
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

    --
    End of file - 7745 bytes



    Malwarebytes' Anti-Malware 1.25
    Database version: 1078
    Windows 5.1.2600 Service Pack 3

    6:14:47 PM 8/23/2008
    mbam-log-08-23-2008 (18-14-47).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 179842
    Time elapsed: 4 hour(s), 9 minute(s), 0 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 2
    Registry Keys Infected: 27
    Registry Values Infected: 2
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 15

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\WINDOWS\SYSTEM32\ukwdvbxj.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\SYSTEM32\zfhzdm.dll (Trojan.Vundo.H) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4b01b576-9f7f-4196-94cd-762ec0122381} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{4b01b576-9f7f-4196-94cd-762ec0122381} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\sai.instantiator (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\sai.instantiator.1 (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\70f73acd (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm73c40951 (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\SYSTEM32\zfhzdm.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\SYSTEM32\qkiqiwnr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\rnwiqikq.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\ukwdvbxj.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\WINDOWS\SYSTEM32\jxbvdwku.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\ejadcpkt.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\ijefyqyk.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\nbyifgks.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\pnvkkdks.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\SYSTEM32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\BM73c40951.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\WINDOWS\BM73c40951.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

  6. #6
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi


    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:

    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.


    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New HijackThis log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Junior Member
    Join Date
    Aug 2008
    Posts
    13

    Default

    Hi, and thanks for your help so far. Posting from another pc in the house now. I started running combofix a few minutes after your post and its currently sitting on the Preparing Log message box and has been for the last 10 minutes. Should I be concerned or just let it continue? Thanks again.

  8. #8
    Junior Member
    Join Date
    Aug 2008
    Posts
    13

    Default

    I spoke too soon, it just finished. I noticed several games etc listed on her computer that do not show up in the add/remove programs list. She also complained that they tried to remove several games and the unistalls failed. not sure if that all ties in to the pc issues or not. Here are the logs. Thanks again.

    ComboFix 08-08-25.01 - Christina 2008-08-26 11:04:13.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.110 [GMT -4:00]
    Running from: C:\Documents and Settings\Christina\Desktop\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Christina\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Christina\Application Data\macromedia\Flash Player\#SharedObjects\QRYFE6KL\bin.clearspring.com
    C:\Documents and Settings\Christina\Application Data\macromedia\Flash Player\#SharedObjects\QRYFE6KL\bin.clearspring.com\clearspring.sol
    C:\Documents and Settings\Christina\Application Data\macromedia\Flash Player\#SharedObjects\QRYFE6KL\interclick.com
    C:\Documents and Settings\Christina\Application Data\macromedia\Flash Player\#SharedObjects\QRYFE6KL\interclick.com\ud.sol
    C:\Documents and Settings\Christina\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
    C:\Documents and Settings\Christina\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
    C:\Documents and Settings\Christina\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
    C:\Documents and Settings\Christina\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
    C:\WINDOWS\smdat32m.sys
    C:\WINDOWS\system32\acdgsaog.dll
    C:\WINDOWS\system32\ckccnvdl.ini
    C:\WINDOWS\system32\drivers\fad.sys
    C:\WINDOWS\system32\fmwqfu.dll
    C:\WINDOWS\system32\ghkhvgws.ini
    C:\WINDOWS\SYSTEM32\JjkTuBeg.ini
    C:\WINDOWS\SYSTEM32\JjkTuBeg.ini2
    C:\WINDOWS\system32\jlodwvfd.dll
    C:\WINDOWS\system32\xjtmtbip.dll
    C:\WINDOWS\system32\xxiemghj.dll
    C:\WINDOWS\system32\zbrcau.dll

    .
    ((((((((((((((((((((((((( Files Created from 2008-07-26 to 2008-08-26 )))))))))))))))))))))))))))))))
    .

    2008-08-26 01:06 . <DIR> C:\WINDOWS\LastGood.Tmp
    2008-08-25 17:46 . 2008-08-25 17:46 <DIR> d-------- C:\WINDOWS\Sun
    2008-08-25 07:49 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
    2008-08-25 07:47 . 2008-08-25 07:49 <DIR> d-------- C:\Program Files\Java
    2008-08-25 00:00 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll
    2008-08-25 00:00 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll.mui
    2008-08-24 11:39 . 2008-08-24 11:39 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-08-22 23:48 . 2008-08-22 23:48 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-08-22 23:48 . 2008-08-22 23:48 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\Malwarebytes
    2008-08-22 23:48 . 2008-08-22 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-08-22 23:48 . 2008-08-17 17:01 38,472 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
    2008-08-22 23:48 . 2008-08-17 17:01 17,144 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
    2008-08-22 23:40 . 2008-08-22 23:40 <DIR> d-------- C:\Program Files\Windows Media Connect 2
    2008-08-22 23:35 . 2008-08-22 23:35 <DIR> d-------- C:\WINDOWS\SYSTEM32\LogFiles
    2008-08-22 23:35 . 2008-08-22 23:37 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\UMDF
    2008-08-22 17:04 . 2008-08-22 17:04 <DIR> d-------- C:\Program Files\Trend Micro
    2008-08-22 15:50 . 2008-08-22 15:50 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Windows Search
    2008-08-22 15:41 . 2003-06-25 18:05 266,360 --a------ C:\WINDOWS\SYSTEM32\TweakUI.exe
    2008-08-22 15:41 . 2002-06-21 17:09 160,217 --a------ C:\WINDOWS\SYSTEM32\PowerToysLicense.rtf
    2008-08-22 15:07 . 2008-08-22 15:07 <DIR> d--h----- C:\WINDOWS\PIF
    2008-08-22 14:55 . 2005-10-19 10:59 163,840 --a------ C:\WINDOWS\SYSTEM32\igfxres.dll
    2008-08-22 14:43 . 2008-08-22 14:43 <DIR> d-------- C:\WINDOWS\SYSTEM32\GroupPolicy
    2008-08-22 14:41 . 2008-03-07 13:02 192,000 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\offfilt.dll
    2008-08-22 14:41 . 2008-03-07 13:02 98,304 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\nlhtml.dll
    2008-08-22 14:41 . 2008-03-07 13:02 29,696 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\mimefilt.dll
    2008-08-22 14:40 . 2008-08-22 14:40 <DIR> d-------- C:\Program Files\Managed DirectX (0901)
    2008-08-22 14:39 . 2008-07-22 10:45 1,214,526 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\sysmain.sdb
    2008-08-22 14:39 . 2008-07-22 10:45 790,846 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\apph_sp.sdb
    2008-08-22 14:39 . 2008-07-22 10:45 9,696 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\drvmain.sdb
    2008-08-22 13:48 . 2008-08-22 13:48 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
    2008-08-22 13:47 . 2008-08-22 13:47 <DIR> d-------- C:\WINDOWS\SYSTEM32\en
    2008-08-22 13:47 . 2008-08-22 13:47 <DIR> d-------- C:\WINDOWS\l2schemas
    2008-08-22 04:05 . 2008-04-13 20:12 712,704 --------- C:\WINDOWS\SYSTEM32\windowscodecs.dll
    2008-08-22 04:04 . 2008-04-13 20:12 246,814 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\strmdll.dll
    2008-08-22 04:04 . 2008-04-13 20:12 152,064 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\shmedia.dll
    2008-08-22 04:04 . 2008-04-13 20:10 86,016 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\sl_anet.acm
    2008-08-22 04:04 . 2002-08-29 07:00 1,148 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\snd.htm
    2008-08-22 04:04 . 2004-08-04 01:51 908 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\skins.inf
    2008-08-22 04:02 . 2008-04-13 20:12 412,160 --------- C:\WINDOWS\SYSTEM32\photometadatahandler.dll
    2008-08-22 04:01 . 2008-04-13 20:12 1,306,624 --------- C:\WINDOWS\SYSTEM32\msxml6.dll
    2008-08-22 04:00 . 2006-12-04 18:21 414,720 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msscp.dll
    2008-08-22 04:00 . 2006-10-18 23:47 179,712 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msnetobj.dll
    2008-08-22 04:00 . 2006-10-18 23:47 175,616 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\mspmsp.dll
    2008-08-22 04:00 . 2008-04-13 20:12 155,136 --------- C:\WINDOWS\SYSTEM32\mssha.dll
    2008-08-22 04:00 . 2008-04-13 14:14 76,800 --------- C:\WINDOWS\SYSTEM32\msshavmsg.dll
    2008-08-22 04:00 . 2008-04-13 20:12 69,632 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\msscds32.ax
    2008-08-22 04:00 . 2006-10-18 23:47 27,136 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\mspmsnsv.dll
    2008-08-22 03:58 . 2008-04-13 20:12 786,432 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\migrate.exe
    2008-08-22 03:58 . 2002-08-29 07:00 457,607 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\mdlib.wmv
    2008-08-22 03:58 . 2008-04-13 20:11 397,312 --------- C:\WINDOWS\SYSTEM32\mmcex.dll
    2008-08-22 03:58 . 2008-04-13 20:11 184,320 --------- C:\WINDOWS\SYSTEM32\microsoft.managementconsole.dll
    2008-08-22 03:58 . 2008-04-13 20:11 106,496 --------- C:\WINDOWS\SYSTEM32\mmcfxcommon.dll
    2008-08-22 03:58 . 2006-10-18 22:03 100,864 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\logagent.exe
    2008-08-22 03:58 . 2008-04-13 20:12 33,792 --------- C:\WINDOWS\SYSTEM32\mmcperf.exe
    2008-08-22 03:58 . 2006-10-18 23:47 11,264 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\LAPRXY.dll
    2008-08-22 03:57 . 2008-04-13 20:09 290,816 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\l3codeca.acm
    2008-08-22 03:57 . 2008-04-13 20:11 61,440 --------- C:\WINDOWS\SYSTEM32\kmsvc.dll
    2008-08-22 03:57 . 2008-04-13 20:11 37,376 --------- C:\WINDOWS\SYSTEM32\l2gpstore.dll
    2008-08-22 03:57 . 2008-04-13 20:09 6,144 --------- C:\WINDOWS\SYSTEM32\kbdpash.dll
    2008-08-22 03:57 . 2008-04-13 20:09 6,144 --------- C:\WINDOWS\SYSTEM32\kbdnepr.dll
    2008-08-22 03:57 . 2008-04-13 20:09 6,144 --------- C:\WINDOWS\SYSTEM32\kbdiultn.dll
    2008-08-22 03:57 . 2008-04-13 20:09 6,144 --------- C:\WINDOWS\SYSTEM32\kbdbhc.dll
    2008-08-22 03:55 . 2006-10-18 23:47 991,744 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\drmv2clt.dll
    2008-08-22 03:54 . 2006-10-18 23:47 542,720 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\blackbox.dll
    2008-08-22 03:54 . 2008-04-13 20:11 233,472 --------- C:\WINDOWS\SYSTEM32\azroles.dll
    2008-08-22 03:54 . 2006-10-18 23:47 229,376 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\cewmdm.dll
    2008-08-22 03:54 . 2008-04-13 20:11 136,192 --------- C:\WINDOWS\SYSTEM32\aaclient.dll
    2008-08-22 03:54 . 2006-10-18 23:47 7,168 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\asferror.dll
    2008-08-22 03:54 . 2008-04-13 20:11 7,168 --------- C:\WINDOWS\SYSTEM32\bitsprx4.dll
    2008-08-22 03:54 . 2002-08-29 07:00 999 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\bktrh.gif
    2008-08-21 20:59 . 2008-08-21 21:12 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-08-21 20:59 . 2008-08-22 02:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-08-21 16:53 . 2008-08-22 02:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-08-21 16:12 . 2008-08-21 16:16 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\Business Logic
    2008-08-21 16:05 . 2008-08-26 11:27 5,164,576 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
    2008-08-21 16:05 . 2008-08-26 11:27 70,220 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
    2008-08-21 15:56 . 2008-08-21 15:56 <DIR> d-------- C:\Program Files\Business Logic Corporation
    2008-08-21 15:53 . 2008-08-21 15:55 4,212 ---h----- C:\WINDOWS\SYSTEM32\zllictbl.dat
    2008-08-21 15:52 . 2008-07-09 11:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
    2008-08-21 15:52 . 2004-04-27 06:40 11,264 --a------ C:\WINDOWS\SYSTEM32\SpOrder.dll
    2008-08-21 15:51 . 2008-08-21 15:51 <DIR> d-------- C:\Program Files\Zone Labs
    2008-08-21 12:47 . 2003-12-30 11:08 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
    2008-08-21 12:47 . 2003-12-30 11:12 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
    2008-08-21 12:47 . 2008-08-22 15:48 <DIR> d-------- C:\Documents and Settings\Administrator
    2008-08-21 01:05 . 2005-05-13 21:50 123,488 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
    2008-08-21 01:05 . 2005-05-13 21:50 91,856 --a------ C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
    2008-08-21 00:38 . 2008-08-21 00:38 0 --a------ C:\WINDOWS\vpc32.INI
    2008-08-20 23:17 . 2008-08-26 11:15 <DIR> d-------- C:\Program Files\Symantec AntiVirus
    2008-08-20 23:11 . 2008-08-20 23:11 <DIR> d-------- C:\Documents and Settings\Christina\Application Data\U3
    2008-08-13 19:55 . 2008-04-11 15:04 691,712 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\inetcomm.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-26 15:33 --------- d-----w C:\Program Files\Steam
    2008-08-26 15:27 1,497,600 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
    2008-08-24 15:23 1,464,832 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
    2008-08-23 02:57 204,800 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
    2008-08-22 06:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Napster
    2008-08-22 06:17 --------- d-----w C:\Documents and Settings\Christina\Application Data\Hamachi
    2008-08-22 06:17 --------- d-----w C:\Documents and Settings\Christina\Application Data\F-Secure
    2008-08-22 06:17 --------- d-----w C:\Documents and Settings\Christina\Application Data\COREL
    2008-08-22 06:15 --------- d-----w C:\Program Files\Modem Helper
    2008-08-22 06:15 --------- d-----w C:\Program Files\FinePixViewer
    2008-08-22 06:15 --------- d-----w C:\Program Files\Common Files\Real
    2008-08-21 05:16 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-08-21 05:07 --------- d-----w C:\Program Files\Symantec
    2008-08-21 05:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-08-18 06:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-07-29 04:19 --------- d-----w C:\Program Files\Sonic
    2008-07-09 17:29 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
    2008-07-06 16:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
    2008-07-06 14:50 --------- d-----w C:\Documents and Settings\Christina\Application Data\skypePM
    2006-02-26 03:37 774,144 ----a-w C:\Program Files\RngInterstitial.dll
    2003-08-27 20:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Steam"="c:\program files\steam\steam.exe" [2008-03-27 20:01 1271032]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 11:21 48752]
    "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 21:27 85696]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 11:05 919016]
    "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 10:59 155648]
    "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 10:59 126976]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

    C:\Documents and Settings\Christina\Start Menu\Programs\Startup\
    PowerReg Scheduler V3.exe [2007-02-10 21:13:28 225280]
    PowerReg Scheduler.exe [2006-02-09 18:44:42 256000]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=zfhzdm.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
    backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Christina^Start Menu^Programs^Startup^RollerCoaster Tycoon 3 Registration.lnk]
    path=C:\Documents and Settings\Christina\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk
    backup=C:\WINDOWS\pss\RollerCoaster Tycoon 3 Registration.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
    --a------ 2005-06-02 11:21 48752 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a------ 2008-04-13 20:12 15360 C:\WINDOWS\SYSTEM32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A940]
    --a------ 2003-02-17 19:00 86102 C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
    --a------ 2003-08-06 03:04 114741 C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    --a------ 2005-10-19 10:59 126976 C:\WINDOWS\SYSTEM32\hkcmd.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    --a------ 2005-10-19 10:59 155648 C:\WINDOWS\SYSTEM32\igfxtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --a------ 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2003-12-30 11:07 77824 C:\Program Files\QuickTime\qttask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
    --------- 2002-02-05 00:32 53248 C:\Program Files\REGSHAVE\REGSHAVE.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SM1BG]
    -ra------ 2003-08-27 16:20 94208 C:\WINDOWS\SM1bg.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
    --a------ 2003-02-13 03:01 155648 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
    --a------ 2003-08-29 06:59 122880 C:\WINDOWS\BCMSMMSG.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\killer1031\\dedicated server\\hlds.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\killer1031\\condition zero\\hl.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\killer1031\\counter-strike\\hl.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\killer1031\\counter-strike source\\hl2.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\killer1031\\day of defeat source\\hl2.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\killer1031\\half-life 2 deathmatch\\hl2.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\freakshow1032\\counter-strike\\hl.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\freakshow1032\\condition zero\\hl.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\freakshow1032\\counter-strike source\\hl2.exe"=
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\freakshow1032\\garrysmod\\hl2.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\skullkid9\\counter-strike\\hl.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\skullkid9\\condition zero\\hl.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\skullkid9\\half-life 2 deathmatch\\hl2.exe"=
    "C:\\Program Files\\Steam\\Steam.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\skullkid9\\counter-strike source\\hl2.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\skullkid9\\garrysmod\\hl2.exe"=
    "C:\\Program Files\\Steam\\SteamApps\\skullkid9\\half-life deathmatch source\\hl2.exe"=

    S3 idrmkl;idrmkl;C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\idrmkl.sys []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    \Shell\AutoRun\command - F:\LaunchU3.exe -a
    .
    Contents of the 'Scheduled Tasks' folder

    2008-08-26 C:\WINDOWS\Tasks\Symantec NetDetect.job
    - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2005-03-31 19:32]
    .
    - - - - ORPHANS REMOVED - - - -

    Notify-iifdbXPG - iifdbXPG.dll
    MSConfigStartUp-70f73acd - C:\WINDOWS\system32\qkiqiwnr.dll
    MSConfigStartUp-AltnetPointsManager - C:\Program Files\Altnet\Points Manager\Points Manager.exe
    MSConfigStartUp-BM73c40951 - C:\WINDOWS\system32\acdgsaog.dll
    MSConfigStartUp-CMESys - C:\Program Files\Common Files\CMEII\CMESys.exe
    MSConfigStartUp-F-Secure Manager - C:\Program Files\EMBARQ Online Security\Common\FSM32.EXE
    MSConfigStartUp-F-Secure Startup Wizard - C:\Program Files\EMBARQ Online Security\FSGUI\FSSW.EXE
    MSConfigStartUp-F-Secure TNB - C:\Program Files\EMBARQ Online Security\TNB\TNBUtil.exe
    MSConfigStartUp-Juno_uoltray - C:\Program Files\Juno6\exec.exe
    MSConfigStartUp-KAZAA - C:\Program Files\Kazaa\kazaa.exe
    MSConfigStartUp-mmtask - c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    MSConfigStartUp-MMTray - C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    MSConfigStartUp-MoneyAgent - C:\Program Files\Microsoft Money\System\mnyexpr.exe
    MSConfigStartUp-NapsterShell - C:\Program Files\Napster\napster.exe
    MSConfigStartUp-P2P Networking - C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
    MSConfigStartUp-PCMService - C:\Program Files\Dell\Media Experience\PCMService.exe
    MSConfigStartUp-Registry Cleaner - C:\Program Files\Registry Cleaner\RegClean.exe
    MSConfigStartUp-SearchUpgrader - C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe
    MSConfigStartUp-spc_w - C:\Program Files\JUSearch\juspc.exe
    MSConfigStartUp-SSC_UserPrompt - C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    MSConfigStartUp-SunJavaUpdateSched - C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    MSConfigStartUp-TkBellExe - C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    MSConfigStartUp-Logitech Utility - Logi_MwX.Exe


    .
    ------- Supplementary Scan -------
    .
    R0 -: HKCU-Main,Start Page = hxxp://www.myembarq.com/
    R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
    R1 -: HKCU-SearchURL,(Default) = hxxp://my.juno.com/s/search?r=minisearch
    O8 -: &Search - ?p=ZCman000
    O8 -: Display All Images with Full Quality - "C:\Program Files\Juno\qsacc\appres.dll/228"
    O8 -: Display Image with Full Quality - "C:\Program Files\Juno\qsacc\appres.dll/227"

    O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
    C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-26 11:28:52
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\SYSTEM32\LEXBCES.EXE
    C:\WINDOWS\SYSTEM32\LEXPPS.EXE
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\SYSTEM32\imapi.exe
    .
    **************************************************************************
    .
    Completion time: 2008-08-26 11:41:50 - machine was rebooted [Christina]
    ComboFix-quarantined-files.txt 2008-08-26 15:41:36

    Pre-Run: 1,359,548,416 bytes free
    Post-Run: 1,341,911,040 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

    306 --- E O F --- 2008-08-16 12:21:49


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:46:04 AM, on 8/26/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myembarq.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Startup: PowerReg Scheduler.exe
    O8 - Extra context menu item: &Search - ?p=ZCman000
    O8 - Extra context menu item: Display All Images with Full Quality - "res://C:\Program Files\Juno\qsacc\appres.dll/228"
    O8 - Extra context menu item: Display Image with Full Quality - "res://C:\Program Files\Juno\qsacc\appres.dll/227"
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v48/pool/pool.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab
    O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/...nlineGames.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v45.../bejeweled.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1219592234859
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/soft...ch/alaunch.cab
    O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v64/swapit/swapit.cab
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.18.37/ttinst.cab
    O16 - DPF: {C738EA53-97C2-441B-AC52-DFBC597BCBE5} (Chess Control) - http://www.worldwinner.com/games/v48/chess/chess.cab
    O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51...ol/h2hpool.cab
    O20 - AppInit_DLLs: zfhzdm.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

    --
    End of file - 6859 bytes

  9. #9
    Junior Member
    Join Date
    Aug 2008
    Posts
    13

    Default

    Just wanted to note that it appears Symantec Norton AntiVirus is no longer working after combofix. The error I get is:
    An error occurred while loading savrt32.dll

  10. #10
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    You need to reinstall Symantec Norton AntiVirus after cleaning process is ready.

    IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.


    Kazaa
    Napster


    I'd like you to read the this thread.

    Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

    Delete these folders afterwards (if found):

    C:\Documents and Settings\All Users\Application Data\Napster
    C:\Program Files\Altnet
    C:\Program Files\Kazaa
    C:\Program Files\Napster
    C:\WINDOWS\System32\P2P Networking

    Empty Recycle Bin.

    After that:

    Re-run ComboFix and post back its report.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •