Page 1 of 4 1234 LastLast
Results 1 to 10 of 31

Thread: Virtumonde infection

  1. #1
    Member
    Join Date
    Dec 2008
    Posts
    41

    Exclamation Virtumonde infection

    You can add me to the list of those hit with this nasty virus.
    Any and all assistance is greatly appreciated.

    Thank you very much in advance.

    Here is my most recent HijackThis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:22:38 PM, on 12/6/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\Program Files\Maxtor\Sync\SyncServices.exe
    C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\McAfee\MBK\MBackMonitor.exe
    C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\McAfee\VirusScan\McShield.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 205.150.73.3:65208
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupport-] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-20\..\Run: [puvujufaha] Rundll32.exe "C:\WINDOWS\system32\bujiwofi.dll",s (User 'NETWORK SERVICE')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download All by FlashGet - C:\Documents and Settings\owner\My Documents\AD\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download using FlashGet - C:\Documents and Settings\owner\My Documents\AD\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: ComcastHSI - {28AF5171-19DD-41CA-B714-FA611DC5FD08} - http://www.comcast.net (file missing) (HKCU)
    O9 - Extra button: Help - {FCF05CCD-CBFB-4EA2-B68D-7FDB8DA5BC43} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
    O9 - Extra button: Support - {FE75A239-4EB9-47C5-AF22-A25EC64BF505} - http://www.comcastsupport.com (file missing) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196447399734
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://chill.comcast.net/gameshell/online/en/chainz2/mjolauncher.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://playgames.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab
    O20 - AppInit_DLLs: karna.dat c:\windows\system32\kapidugo.dll C:\WINDOWS\system32\zahenese.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 13346 bytes

  2. #2
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Hello Dave090

    Welcome to Safer Networking.

    Please read Before You Post
    That said, All advice given by anyone volunteering here, is taken at own risk.
    While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your personal data before starting any clean up procedure.



    Do this first...Important

    Disable the TeaTimer, leave it disabled until we're done or it will prevent fixes from taking

    • Run Spybot-S&D in Advanced Mode.
    • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
    • On the left hand side, Click on Tools
    • Then click on the Resident Icon in the List
    • Uncheck "Resident TeaTimer" and OK any prompts.
    • Restart your computer.<--You need to do this for it to take effect




    Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

    O4 - HKUS\S-1-5-20\..\Run: [puvujufaha] Rundll32.exe "C:\WINDOWS\system32\bujiwofi.dll",s (User 'NETWORK SERVICE')

    O20 - AppInit_DLLs: karna.dat c:\windows\system32\kapidugo.dll C:\WINDOWS\system32\zahenese.dll





    Please download Malwarebytes' Anti-Malware from Here or Here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.<-- Don't forget this
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply along with a New Hijackthis log.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  3. #3
    Member
    Join Date
    Dec 2008
    Posts
    41

    Default

    Hi Ken-

    First of all, thank you for being a part of this forum and for helping so many with their problems, me specifically.
    We are collectively in your debt as you (collectively), try to balance the playing field.

    OK, I performed the tasks as instructed and here are the log files, as requested.

    Malwarebytes' Anti-Malware 1.31
    Database version: 1477
    Windows 5.1.2600 Service Pack 3

    12/9/2008 6:18:30 PM
    mbam-log-2008-12-09 (18-18-30).txt

    Scan type: Quick Scan
    Objects scanned: 61999
    Time elapsed: 14 minute(s), 45 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\GetModule (Adware.Agent) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:19:49 PM, on 12/9/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Maxtor\Sync\SyncServices.exe
    C:\Program Files\McAfee\MBK\MBackMonitor.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\McAfee\VirusScan\McShield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 205.150.73.3:65208
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupport-] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download All by FlashGet - C:\Documents and Settings\owner\My Documents\AD\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download using FlashGet - C:\Documents and Settings\owner\My Documents\AD\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: ComcastHSI - {28AF5171-19DD-41CA-B714-FA611DC5FD08} - http://www.comcast.net (file missing) (HKCU)
    O9 - Extra button: Help - {FCF05CCD-CBFB-4EA2-B68D-7FDB8DA5BC43} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
    O9 - Extra button: Support - {FE75A239-4EB9-47C5-AF22-A25EC64BF505} - http://www.comcastsupport.com (file missing) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...0/mcinsctl.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1196447399734
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://chill.comcast.net/gameshell/o...jolauncher.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...23/mcgdmgr.cab
    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://playgames.comcast.net/Gameshe...onGameHost.cab
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 13237 bytes

  4. #4
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Looking good but there may be more hidding


    Please download ATF Cleaner by Atribune to your desktop.
    • This program is for XP and Windows 2000 only
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
    Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.






    Download ComboFix from one of these locations:

    Link 1
    Link 2
    Link 3

    * IMPORTANT !!! Save ComboFix.exe to your Desktop


    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    • See this Link for programs that need to be disabled and instruction on how to disable them.
    • Remember to re-enable them when we're done.

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

    *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  5. #5
    Member
    Join Date
    Dec 2008
    Posts
    41

    Default

    It's really scary having my AV down, but I know it's a necessary evil.

    Here are the latest results:



    ComboFix 08-12-07.04 - owner 2008-12-09 19:05:54.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.520 [GMT -5:00]
    Running from: c:\documents and settings\owner\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\owner\Local Settings\Temporary Internet Files\awamamofa.inf
    c:\documents and settings\owner\Local Settings\Temporary Internet Files\egosa.reg
    c:\documents and settings\owner\Local Settings\Temporary Internet Files\ejiwiz.ban
    c:\documents and settings\owner\Local Settings\Temporary Internet Files\eloqyky.db
    c:\documents and settings\owner\Local Settings\Temporary Internet Files\fbk.sts
    c:\documents and settings\owner\Local Settings\Temporary Internet Files\ipyfafuma.sys
    c:\documents and settings\owner\Local Settings\Temporary Internet Files\ityt.dll
    c:\documents and settings\owner\Local Settings\Temporary Internet Files\rywedaq.ban
    c:\documents and settings\owner\Local Settings\Temporary Internet Files\weqexely.dll
    c:\windows\IE4 Error Log.txt
    c:\windows\system32\bszip.dll
    c:\windows\system32\system
    c:\windows\system32\system\AVICAP.DLL
    c:\windows\system32\system\AVIFILE.DLL
    c:\windows\system32\system\COMMDLG.DLL
    c:\windows\system32\system\KEYBOARD.DRV
    c:\windows\system32\system\LZEXPAND.DLL
    c:\windows\system32\system\MCIAVI.DRV
    c:\windows\system32\system\MCISEQ.DRV
    c:\windows\system32\system\MCIWAVE.DRV
    c:\windows\system32\system\MMSYSTEM.DLL
    c:\windows\system32\system\MMTASK.TSK
    c:\windows\system32\system\MOUSE.DRV
    c:\windows\system32\system\MSVIDEO.DLL
    c:\windows\system32\system\OLECLI.DLL
    c:\windows\system32\system\OLESVR.DLL
    c:\windows\system32\system\setup.inf
    c:\windows\system32\system\SHELL.DLL
    c:\windows\system32\system\SOUND.DRV
    c:\windows\system32\system\stdole.tlb
    c:\windows\system32\system\SYSTEM.DRV
    c:\windows\system32\system\TAPI.DLL
    c:\windows\system32\system\TIMER.DRV
    c:\windows\system32\system\VER.DLL
    c:\windows\system32\system\VGA.DRV
    c:\windows\system32\system\WFWNET.DRV
    c:\windows\system32\system\WINSPOOL.DRV
    c:\windows\system32\TDSSmtpe.dat
    c:\windows\wiaservb.log
    c:\windows\wiaserviv.log
    c:\windows\wiaservv.log
    E:\Autorun.inf
    F:\Autorun.inf

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_TDSSSERV.SYS
    -------\Service_TDSSserv.sys


    ((((((((((((((((((((((((( Files Created from 2008-11-10 to 2008-12-10 )))))))))))))))))))))))))))))))
    .

    2008-12-06 13:21 . 2008-12-06 13:21 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2008-12-06 12:51 . 2008-12-06 12:51 <DIR> d-------- c:\program files\iTunes
    2008-12-06 12:51 . 2008-12-06 12:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2008-12-06 12:49 . 2008-12-06 12:49 <DIR> d-------- c:\program files\Bonjour
    2008-12-06 12:47 . 2008-12-06 12:48 <DIR> d-------- c:\program files\QuickTime
    2008-12-06 12:44 . 2008-12-06 12:44 <DIR> d-------- c:\program files\Common Files\Apple
    2008-12-06 00:51 . 2008-12-06 00:51 <DIR> d-------- C:\VundoFix Backups
    2008-12-06 00:43 . 2008-12-06 00:42 410,984 --a------ c:\windows\system32\deploytk.dll
    2008-11-12 17:53 . 2008-10-24 06:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
    2008-11-12 17:52 . 2008-09-04 12:15 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-09 23:02 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
    2008-12-06 17:51 --------- d-----w c:\program files\iPod
    2008-12-06 17:47 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
    2008-12-06 17:35 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-12-06 05:49 --------- d-----w c:\program files\Java
    2008-12-06 00:56 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-12-06 00:49 --------- d-----w c:\program files\Enigma Software Group
    2008-12-05 23:31 --------- d-----w c:\program files\Spybot - Search & Destroy
    2008-12-04 00:59 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
    2008-12-04 00:59 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
    2008-11-24 23:13 --------- d--h--w c:\documents and settings\owner\Application Data\Move Networks
    2008-11-12 23:05 --------- d-----w c:\program files\MSN Messenger
    2008-10-25 03:46 --------- d-----w c:\documents and settings\All Users\Application Data\xudqjcxk
    2008-10-24 23:56 --------- d-----w c:\program files\Microsoft Silverlight
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-18 17:49 --------- d-----w c:\program files\Apple Software Update
    2008-10-18 17:49 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
    2008-10-11 07:31 --------- d-----w c:\documents and settings\LocalService\Application Data\McAfee
    2008-10-11 07:17 --------- d-----w c:\documents and settings\owner\Application Data\Malwarebytes
    2008-10-11 07:17 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-10-11 06:54 15,377 ----a-w c:\documents and settings\All Users\Application Data\pyjelobuxe.bat
    2008-10-11 06:54 14,808 ----a-w c:\documents and settings\All Users\Application Data\rijerisixu.bin
    2008-10-11 06:54 12,543 ----a-w c:\documents and settings\owner\Application Data\alehodeqy.sys
    2008-10-11 06:54 12,381 ----a-w c:\documents and settings\owner\Application Data\piqoqaxeqe.com
    2008-10-11 06:54 11,919 ----a-w c:\program files\Common Files\yguwavag.ban
    2008-10-11 06:54 10,389 ----a-w c:\windows\nyhij.vbs
    2008-10-11 06:52 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2008-10-11 06:26 --------- d-----w c:\program files\Trend Micro
    2008-10-11 03:40 19,686 ----a-w c:\windows\wuxamy.scr
    2008-10-11 03:40 18,941 ----a-w c:\program files\Common Files\unewyx.bat
    2008-10-11 03:40 15,973 ----a-w c:\documents and settings\owner\Application Data\hype.sys
    2008-10-11 03:40 15,473 ----a-w c:\program files\Common Files\telewywec.dll
    2008-10-11 03:40 15,332 ----a-w c:\documents and settings\All Users\Application Data\ykukypo.reg
    2008-10-11 03:40 12,961 ----a-w c:\program files\Common Files\ehydulybif._sy
    2008-10-11 03:40 11,966 ----a-w c:\windows\haka.com
    2008-10-11 03:40 11,044 ----a-w c:\program files\Common Files\zekoxuqa.dll
    2008-10-11 03:30 18,906 ----a-w c:\documents and settings\owner\Application Data\wyka.bin
    2008-10-11 03:30 18,240 ----a-w c:\windows\jugitezo.dll
    2008-10-11 03:30 16,264 ----a-w c:\program files\Common Files\evenodew.lib
    2008-10-11 03:30 12,739 ----a-w c:\documents and settings\All Users\Application Data\bunegodihy.com
    2008-10-11 03:30 10,215 ----a-w c:\documents and settings\All Users\Application Data\ufokuwyba.exe
    2008-10-11 03:30 10,159 ----a-w c:\program files\Common Files\wowyzopig.dl
    2008-10-11 03:30 10,015 ----a-w c:\documents and settings\All Users\Application Data\rytovef.sys
    2006-01-28 04:39 251 ----a-w c:\program files\wt3d.ini
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\ypager.exe" [2005-08-05 3092480]
    "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
    "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
    "DellSupport-"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
    "Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 344064]
    "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-06-29 1032192]
    "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
    "BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2001-12-17 483394]
    "ComcastSUPPORT"="c:\program files\Support.com\bin\tgkill.exe" [2001-11-21 57344]
    "dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
    "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 16384]
    "mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 169264]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 4838952]
    "MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-06 136600]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
    Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-08-11 24576]
    QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "ForceClassicControlPanel"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
    2004-09-07 16:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "vidc.xvid"= xvid.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "AOL ACS"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Support.com\\bin\\tgcmd.exe"=
    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "c:\\Program Files\\Azureus\\Azureus.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\MSN Messenger\\livecall.exe"=
    "c:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
    "c:\\Program Files\\Intel\\Wireless\\Bin\\iFrmewrk.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R2 Maxtor Sync Service;Maxtor Service;"c:\program files\Maxtor\Sync\SyncServices.exe" [2007-07-13 156976]
    S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-06-28 42512]
    .
    Contents of the 'Scheduled Tasks' folder

    2008-11-10 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2008-11-15 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

    2008-12-01 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.google.com
    uInternet Settings,ProxyServer = 205.150.73.3:65208
    uInternet Settings,ProxyOverride = *.local
    IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
    IE: Download All by FlashGet - c:\documents and settings\owner\My Documents\AD\FlashGet\jc_all.htm
    IE: Download using FlashGet - c:\documents and settings\owner\My Documents\AD\FlashGet\jc_link.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
    IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
    IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
    FireFox -: Profile - c:\documents and settings\owner\Application Data\Mozilla\Firefox\Profiles\wktw0cxn.default\
    FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-09 19:12:16
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    McAfee Backup = c:\program files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1100)
    c:\windows\system32\Ati2evxx.dll
    c:\windows\System32\BCMLogon.dll
    c:\program files\Intel\Wireless\Bin\LgNotify.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\ati2evxx.exe
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
    c:\windows\system32\WLTRYSVC.EXE
    c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
    c:\windows\system32\BCMWLTRY.EXE
    c:\windows\system32\ati2evxx.exe
    c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\ehome\ehRecvr.exe
    c:\windows\ehome\ehSched.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\progra~1\McAfee\MSC\mcmscsvc.exe
    c:\program files\Apoint\ApntEx.exe
    c:\program files\Support.com\bin\tgcmd.exe
    c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
    c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
    c:\program files\McAfee\VirusScan\Mcshield.exe
    c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\program files\McAfee\MPF\MpfSrv.exe
    c:\program files\Dell\QuickSet\NicConfigSvc.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\Dell Support Center\bin\sprtsvc.exe
    c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
    c:\windows\system32\dllhost.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\ehome\ehmsas.exe
    c:\progra~1\McAfee\MSC\mcuimgr.exe
    .
    **************************************************************************
    .
    Completion time: 2008-12-09 19:19:54 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-12-10 00:19:13

    Pre-Run: 12,933,869,568 bytes free
    Post-Run: 12,901,318,656 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptIn

    281 --- E O F --- 2008-11-12 23:14:23



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:24:04 PM, on 12/9/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Maxtor\Sync\SyncServices.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    C:\Program Files\McAfee\VirusScan\McShield.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\eHome\ehmsas.exe
    c:\PROGRA~1\mcafee\msc\mcuimgr.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 205.150.73.3:65208
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
    O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupport-] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download All by FlashGet - C:\Documents and Settings\owner\My Documents\AD\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download using FlashGet - C:\Documents and Settings\owner\My Documents\AD\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: ComcastHSI - {28AF5171-19DD-41CA-B714-FA611DC5FD08} - http://www.comcast.net (file missing) (HKCU)
    O9 - Extra button: Help - {FCF05CCD-CBFB-4EA2-B68D-7FDB8DA5BC43} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
    O9 - Extra button: Support - {FE75A239-4EB9-47C5-AF22-A25EC64BF505} - http://www.comcastsupport.com (file missing) (HKCU)
    O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...0/mcinsctl.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1196447399734
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://chill.comcast.net/gameshell/o...jolauncher.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...23/mcgdmgr.cab
    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://playgames.comcast.net/Gameshe...onGameHost.cab
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 12871 bytes

  6. #6
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    You have a bunch of files that may be bad, lets check a few before we delete them

    You need to enable windows to show all files and folders, instructions Here

    Go to VirusTotal and submit these files for analysis, just use the BROWSE feature and then Send File , you will get a report back, post the report into this thread for me to see.

    c:\documents and settings\All Users\Application Data\ufokuwyba.exe
    c:\documents and settings\owner\Application Data\alehodeqy.sys
    c:\windows\jugitezo.dll
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  7. #7
    Member
    Join Date
    Dec 2008
    Posts
    41

    Default

    OK, here are the results. I did a Copy & Paste of the files from your reply, but I did enable Windows to show all files & folders; hope that doesn't mess things up.

    Can I re-enable my AV yet?

    Thanks again, I cannot begin to tell you how much I appreciate this help.


    File ufokuwyba.exe received on 12.10.2008 02:03:04 (CET)
    Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


    Result: 0/38 (0%)
    Loading server information...
    Your file is queued in position: 1.
    Estimated start time is between 38 and 55 seconds.
    Do not close the window until scan is complete.
    The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
    If you are waiting for more than five minutes you have to resend your file.
    Your file is being scanned by VirusTotal in this moment,
    results will be shown as they're generated.
    Compact Print results
    Your file has expired or does not exists.
    Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

    You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
    Email:


    Antivirus Version Last Update Result
    AhnLab-V3 2008.12.10.0 2008.12.10 -
    AntiVir 7.9.0.43 2008.12.09 -
    Authentium 5.1.0.4 2008.12.10 -
    Avast 4.8.1281.0 2008.12.10 -
    AVG 8.0.0.199 2008.12.09 -
    BitDefender 7.2 2008.12.10 -
    CAT-QuickHeal 10.00 2008.12.09 -
    ClamAV 0.94.1 2008.12.10 -
    Comodo 713 2008.12.09 -
    DrWeb 4.44.0.09170 2008.12.09 -
    eSafe 7.0.17.0 2008.12.09 -
    eTrust-Vet 31.6.6253 2008.12.10 -
    Ewido 4.0 2008.12.09 -
    F-Prot 4.4.4.56 2008.12.09 -
    F-Secure 8.0.14332.0 2008.12.10 -
    Fortinet 3.117.0.0 2008.12.09 -
    GData 19 2008.12.10 -
    Ikarus T3.1.1.45.0 2008.12.08 -
    K7AntiVirus 7.10.549 2008.12.09 -
    Kaspersky 7.0.0.125 2008.12.10 -
    McAfee 5459 2008.12.09 -
    McAfee+Artemis 5459 2008.12.09 -
    Microsoft 1.4205 2008.12.09 -
    NOD32 3679 2008.12.09 -
    Norman 5.80.02 2008.12.09 -
    Panda 9.0.0.4 2008.12.09 -
    PCTools 4.4.2.0 2008.12.09 -
    Prevx1 V2 2008.12.10 -
    Rising 21.07.12.00 2008.12.09 -
    SecureWeb-Gateway 6.7.6 2008.12.09 -
    Sophos 4.36.0 2008.12.09 -
    Sunbelt 3.1.1832.2 2008.12.01 -
    Symantec 10 2008.12.10 -
    TheHacker 6.3.1.2.180 2008.12.09 -
    TrendMicro 8.700.0.1004 2008.12.09 -
    VBA32 3.12.8.10 2008.12.09 -
    ViRobot 2008.12.9.1509 2008.12.09 -
    VirusBuster 4.5.11.0 2008.12.09 -
    Additional information
    File size: 10215 bytes
    MD5...: ee0c1c9353268d54c84b6dbfd6e4f158
    SHA1..: 96b4f836834a0bb69b392cf29b4cff833526dc87
    SHA256: 98965dabbe4f5493b17fb239569795d85859d0cdd2c6642be70595e1fbd8f2eb
    SHA512: 1aeabd1a94ce5bdb60879fff3f943be905957e9b87037b993046abfab229f53c
    b1e658515ce0fc0547857d22f258e6e2c9ef6e0f8ed7c7b4a384e22bda452a9d

    ssdeep: 192:UPJvOGwrNtzOnU3krATax/+GbycYvBpPqXE/t08b8Y2Vit/9:Uxvct6neSma
    x/+wyvPqX4ijg9

    PEiD..: -
    TrID..: File type identification
    Unknown!
    PEInfo: -



    File alehodeqy.sys received on 12.10.2008 02:05:25 (CET)
    Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


    Result: 0/38 (0%)
    Loading server information...
    Your file is queued in position: ___.
    Estimated start time is between ___ and ___ .
    Do not close the window until scan is complete.
    The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
    If you are waiting for more than five minutes you have to resend your file.
    Your file is being scanned by VirusTotal in this moment,
    results will be shown as they're generated.
    Compact Print results
    Your file has expired or does not exists.
    Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

    You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
    Email:


    Antivirus Version Last Update Result
    AhnLab-V3 2008.12.10.0 2008.12.10 -
    AntiVir 7.9.0.43 2008.12.09 -
    Authentium 5.1.0.4 2008.12.10 -
    Avast 4.8.1281.0 2008.12.10 -
    AVG 8.0.0.199 2008.12.09 -
    BitDefender 7.2 2008.12.10 -
    CAT-QuickHeal 10.00 2008.12.09 -
    ClamAV 0.94.1 2008.12.10 -
    Comodo 713 2008.12.09 -
    DrWeb 4.44.0.09170 2008.12.09 -
    eSafe 7.0.17.0 2008.12.09 -
    eTrust-Vet 31.6.6253 2008.12.10 -
    Ewido 4.0 2008.12.09 -
    F-Prot 4.4.4.56 2008.12.09 -
    F-Secure 8.0.14332.0 2008.12.10 -
    Fortinet 3.117.0.0 2008.12.09 -
    GData 19 2008.12.10 -
    Ikarus T3.1.1.45.0 2008.12.08 -
    K7AntiVirus 7.10.549 2008.12.09 -
    Kaspersky 7.0.0.125 2008.12.10 -
    McAfee 5459 2008.12.09 -
    McAfee+Artemis 5459 2008.12.09 -
    Microsoft 1.4205 2008.12.09 -
    NOD32 3679 2008.12.09 -
    Norman 5.80.02 2008.12.09 -
    Panda 9.0.0.4 2008.12.09 -
    PCTools 4.4.2.0 2008.12.09 -
    Prevx1 V2 2008.12.10 -
    Rising 21.07.12.00 2008.12.09 -
    SecureWeb-Gateway 6.7.6 2008.12.09 -
    Sophos 4.36.0 2008.12.09 -
    Sunbelt 3.1.1832.2 2008.12.01 -
    Symantec 10 2008.12.10 -
    TheHacker 6.3.1.2.180 2008.12.09 -
    TrendMicro 8.700.0.1004 2008.12.09 -
    VBA32 3.12.8.10 2008.12.09 -
    ViRobot 2008.12.9.1509 2008.12.09 -
    VirusBuster 4.5.11.0 2008.12.09 -
    Additional information
    File size: 12543 bytes
    MD5...: 75bada9559c00443d89b376e78067b84
    SHA1..: c606eb8f23a4103504cf6777d65f730ba405f2d6
    SHA256: d9dcb0c600d74b4641c934f4922170c75b500e002d654ca1d1edce1959656ff2
    SHA512: 6419f74a5fd3c3823ce41fe66895abe4d276de391757de75242921ed888cc9c6
    8d438ab396055c0d6679dd7350edabd01f00a94dc8bd07b20086d4abcb9972f8

    ssdeep: 192:3AE8v2HEOyYmXC6dvD9EhSstlfq0B21R1h9BUrgyWxyBMKFXhMJ0ER:wEwYm
    FdvxEs4lfq0B21esyWxyBFNSJT

    PEiD..: -
    TrID..: File type identification
    Unknown!
    PEInfo: -



    File jugitezo.dll received on 12.10.2008 02:07:00 (CET)
    Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


    Result: 0/38 (0%)
    Loading server information...
    Your file is queued in position: 1.
    Estimated start time is between 38 and 55 seconds.
    Do not close the window until scan is complete.
    The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
    If you are waiting for more than five minutes you have to resend your file.
    Your file is being scanned by VirusTotal in this moment,
    results will be shown as they're generated.
    Compact Print results
    Your file has expired or does not exists.
    Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

    You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
    Email:


    Antivirus Version Last Update Result
    AhnLab-V3 2008.12.10.0 2008.12.10 -
    AntiVir 7.9.0.43 2008.12.09 -
    Authentium 5.1.0.4 2008.12.10 -
    Avast 4.8.1281.0 2008.12.10 -
    AVG 8.0.0.199 2008.12.09 -
    BitDefender 7.2 2008.12.10 -
    CAT-QuickHeal 10.00 2008.12.09 -
    ClamAV 0.94.1 2008.12.10 -
    Comodo 713 2008.12.09 -
    DrWeb 4.44.0.09170 2008.12.09 -
    eSafe 7.0.17.0 2008.12.09 -
    eTrust-Vet 31.6.6253 2008.12.10 -
    Ewido 4.0 2008.12.09 -
    F-Prot 4.4.4.56 2008.12.09 -
    F-Secure 8.0.14332.0 2008.12.10 -
    Fortinet 3.117.0.0 2008.12.09 -
    GData 19 2008.12.10 -
    Ikarus T3.1.1.45.0 2008.12.08 -
    K7AntiVirus 7.10.549 2008.12.09 -
    Kaspersky 7.0.0.125 2008.12.10 -
    McAfee 5459 2008.12.09 -
    McAfee+Artemis 5459 2008.12.09 -
    Microsoft 1.4205 2008.12.09 -
    NOD32 3679 2008.12.09 -
    Norman 5.80.02 2008.12.09 -
    Panda 9.0.0.4 2008.12.09 -
    PCTools 4.4.2.0 2008.12.09 -
    Prevx1 V2 2008.12.10 -
    Rising 21.07.12.00 2008.12.09 -
    SecureWeb-Gateway 6.7.6 2008.12.09 -
    Sophos 4.36.0 2008.12.09 -
    Sunbelt 3.1.1832.2 2008.12.01 -
    Symantec 10 2008.12.10 -
    TheHacker 6.3.1.2.180 2008.12.09 -
    TrendMicro 8.700.0.1004 2008.12.09 -
    VBA32 3.12.8.10 2008.12.09 -
    ViRobot 2008.12.9.1509 2008.12.09 -
    VirusBuster 4.5.11.0 2008.12.09 -
    Additional information
    File size: 18240 bytes
    MD5...: 83ad303e7a04abc2f2be65eda2c18b63
    SHA1..: afbbc46f6297a021b46e32f3a5d9a398b96e0ebd
    SHA256: 3c9c477b116517bc6c506bbbe9edfb3b9a75c856f64110dd69fa33644b574159
    SHA512: e7953cca8e35e12f192b398e246154e23453b0e9175af823d9dec177a9a3501f
    8f90ac708ba241e262216e7f4977004b787f92bc90d6af82ff9e00b89705bc33

    ssdeep: 384:KqXqeu4v/V2sU7ffX/vKDX20ePpr7qufDbhqCZN4wkBmNuFang:KqXJu4v/V
    2sI8G0eP97Hf5qCDk70ng

    PEiD..: -
    TrID..: File type identification
    Unknown!
    PEInfo: -

  8. #8
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    You need to upload them, they will inspect the actual file
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  9. #9
    Member
    Join Date
    Dec 2008
    Posts
    41

    Default

    Oops, sorry about that...

    Here are the first two; I'm experiencing a long lag time getting the third to load to be reanalyzed.
    I will post the results as soon as they become available.

    File ufokuwyba.exe received on 12.10.2008 02:43:40 (CET)Antivirus Version Last Update Result
    AhnLab-V3 2008.12.10.0 2008.12.10 -
    AntiVir 7.9.0.43 2008.12.09 -
    Authentium 5.1.0.4 2008.12.10 -
    Avast 4.8.1281.0 2008.12.10 -
    AVG 8.0.0.199 2008.12.09 -
    BitDefender 7.2 2008.12.10 -
    CAT-QuickHeal 10.00 2008.12.09 -
    ClamAV 0.94.1 2008.12.10 -
    Comodo 713 2008.12.09 -
    DrWeb 4.44.0.09170 2008.12.09 -
    eSafe 7.0.17.0 2008.12.09 -
    eTrust-Vet 31.6.6253 2008.12.10 -
    Ewido 4.0 2008.12.09 -
    F-Prot 4.4.4.56 2008.12.09 -
    F-Secure 8.0.14332.0 2008.12.10 -
    Fortinet 3.117.0.0 2008.12.09 -
    GData 19 2008.12.10 -
    Ikarus T3.1.1.45.0 2008.12.08 -
    K7AntiVirus 7.10.549 2008.12.09 -
    Kaspersky 7.0.0.125 2008.12.10 -
    McAfee 5459 2008.12.09 -
    McAfee+Artemis 5459 2008.12.09 -
    Microsoft 1.4205 2008.12.09 -
    NOD32 3679 2008.12.09 -
    Norman 5.80.02 2008.12.09 -
    Panda 9.0.0.4 2008.12.09 -
    PCTools 4.4.2.0 2008.12.09 -
    Prevx1 V2 2008.12.10 -
    Rising 21.07.12.00 2008.12.09 -
    SecureWeb-Gateway 6.7.6 2008.12.09 -
    Sophos 4.36.0 2008.12.09 -
    Sunbelt 3.1.1832.2 2008.12.01 -
    Symantec 10 2008.12.10 -
    TheHacker 6.3.1.2.182 2008.12.10 -
    TrendMicro 8.700.0.1004 2008.12.09 -
    VBA32 3.12.8.10 2008.12.09 -
    ViRobot 2008.12.9.1509 2008.12.09 -
    VirusBuster 4.5.11.0 2008.12.09 -

    Additional information
    File size: 10215 bytes
    MD5...: ee0c1c9353268d54c84b6dbfd6e4f158
    SHA1..: 96b4f836834a0bb69b392cf29b4cff833526dc87
    SHA256: 98965dabbe4f5493b17fb239569795d85859d0cdd2c6642be70595e1fbd8f2eb
    SHA512: 1aeabd1a94ce5bdb60879fff3f943be905957e9b87037b993046abfab229f53c<BR>b1e658515ce0fc0547857d22f258e6e2c9ef6e0f8ed7c7b4a384e22bda452a9d<BR>
    ssdeep: 192:UPJvOGwrNtzOnU3krATax/+GbycYvBpPqXE/t08b8Y2Vit/9:Uxvct6neSma<BR>x/+wyvPqX4ijg9<BR>
    PEiD..: -
    TrID..: File type identification<BR>Unknown!
    PEInfo: -



    File alehodeqy.sys received on 12.10.2008 02:47:22 (CET)Antivirus Version Last Update Result
    AhnLab-V3 2008.12.10.0 2008.12.10 -
    AntiVir 7.9.0.43 2008.12.09 -
    Authentium 5.1.0.4 2008.12.10 -
    Avast 4.8.1281.0 2008.12.10 -
    AVG 8.0.0.199 2008.12.09 -
    BitDefender 7.2 2008.12.10 -
    CAT-QuickHeal 10.00 2008.12.09 -
    ClamAV 0.94.1 2008.12.10 -
    Comodo 713 2008.12.09 -
    DrWeb 4.44.0.09170 2008.12.09 -
    eSafe 7.0.17.0 2008.12.09 -
    eTrust-Vet 31.6.6253 2008.12.10 -
    Ewido 4.0 2008.12.09 -
    F-Prot 4.4.4.56 2008.12.09 -
    F-Secure 8.0.14332.0 2008.12.10 -
    Fortinet 3.117.0.0 2008.12.09 -
    GData 19 2008.12.10 -
    Ikarus T3.1.1.45.0 2008.12.08 -
    K7AntiVirus 7.10.549 2008.12.09 -
    Kaspersky 7.0.0.125 2008.12.10 -
    McAfee 5459 2008.12.09 -
    McAfee+Artemis 5459 2008.12.09 -
    Microsoft 1.4205 2008.12.09 -
    NOD32 3679 2008.12.09 -
    Norman 5.80.02 2008.12.09 -
    Panda 9.0.0.4 2008.12.09 -
    PCTools 4.4.2.0 2008.12.09 -
    Prevx1 V2 2008.12.10 -
    Rising 21.07.12.00 2008.12.09 -
    SecureWeb-Gateway 6.7.6 2008.12.09 -
    Sophos 4.36.0 2008.12.09 -
    Sunbelt 3.1.1832.2 2008.12.01 -
    Symantec 10 2008.12.10 -
    TheHacker 6.3.1.2.182 2008.12.10 -
    TrendMicro 8.700.0.1004 2008.12.09 -
    VBA32 3.12.8.10 2008.12.09 -
    ViRobot 2008.12.9.1509 2008.12.09 -
    VirusBuster 4.5.11.0 2008.12.09 -

    Additional information
    File size: 12543 bytes
    MD5...: 75bada9559c00443d89b376e78067b84
    SHA1..: c606eb8f23a4103504cf6777d65f730ba405f2d6
    SHA256: d9dcb0c600d74b4641c934f4922170c75b500e002d654ca1d1edce1959656ff2
    SHA512: 6419f74a5fd3c3823ce41fe66895abe4d276de391757de75242921ed888cc9c6<BR>8d438ab396055c0d6679dd7350edabd01f00a94dc8bd07b20086d4abcb9972f8<BR>
    ssdeep: 192:3AE8v2HEOyYmXC6dvD9EhSstlfq0B21R1h9BUrgyWxyBMKFXhMJ0ER:wEwYm<BR>FdvxEs4lfq0B21esyWxyBFNSJT<BR>
    PEiD..: -
    TrID..: File type identification<BR>Unknown!
    PEInfo: -

  10. #10
    Member
    Join Date
    Dec 2008
    Posts
    41

    Default

    And the third...


    File jugitezo.dll received on 12.10.2008 03:00:30 (CET)Antivirus Version Last Update Result
    AhnLab-V3 2008.12.10.0 2008.12.10 -
    AntiVir 7.9.0.43 2008.12.09 -
    Authentium 5.1.0.4 2008.12.10 -
    Avast 4.8.1281.0 2008.12.10 -
    AVG 8.0.0.199 2008.12.09 -
    BitDefender 7.2 2008.12.10 -
    CAT-QuickHeal 10.00 2008.12.09 -
    ClamAV 0.94.1 2008.12.10 -
    Comodo 713 2008.12.09 -
    DrWeb 4.44.0.09170 2008.12.09 -
    eSafe 7.0.17.0 2008.12.09 -
    eTrust-Vet 31.6.6253 2008.12.10 -
    Ewido 4.0 2008.12.09 -
    F-Prot 4.4.4.56 2008.12.09 -
    F-Secure 8.0.14332.0 2008.12.10 -
    Fortinet 3.117.0.0 2008.12.09 -
    GData 19 2008.12.10 -
    Ikarus T3.1.1.45.0 2008.12.08 -
    K7AntiVirus 7.10.549 2008.12.09 -
    Kaspersky 7.0.0.125 2008.12.10 -
    McAfee 5459 2008.12.09 -
    McAfee+Artemis 5459 2008.12.09 -
    Microsoft 1.4205 2008.12.09 -
    NOD32 3679 2008.12.09 -
    Norman 5.80.02 2008.12.09 -
    Panda 9.0.0.4 2008.12.09 -
    PCTools 4.4.2.0 2008.12.09 -
    Prevx1 V2 2008.12.10 -
    Rising 21.07.12.00 2008.12.09 -
    SecureWeb-Gateway 6.7.6 2008.12.09 -
    Sophos 4.36.0 2008.12.09 -
    Sunbelt 3.1.1832.2 2008.12.01 -
    Symantec 10 2008.12.10 -
    TheHacker 6.3.1.2.182 2008.12.10 -
    TrendMicro 8.700.0.1004 2008.12.09 -
    VBA32 3.12.8.10 2008.12.09 -
    ViRobot 2008.12.9.1509 2008.12.09 -
    VirusBuster 4.5.11.0 2008.12.09 -

    Additional information
    File size: 18240 bytes
    MD5...: 83ad303e7a04abc2f2be65eda2c18b63
    SHA1..: afbbc46f6297a021b46e32f3a5d9a398b96e0ebd
    SHA256: 3c9c477b116517bc6c506bbbe9edfb3b9a75c856f64110dd69fa33644b574159
    SHA512: e7953cca8e35e12f192b398e246154e23453b0e9175af823d9dec177a9a3501f<BR>8f90ac708ba241e262216e7f4977004b787f92bc90d6af82ff9e00b89705bc33<BR>
    ssdeep: 384:KqXqeu4v/V2sU7ffX/vKDX20ePpr7qufDbhqCZN4wkBmNuFang:KqXJu4v/V<BR>2sI8G0eP97Hf5qCDk70ng<BR>
    PEiD..: -
    TrID..: File type identification<BR>Unknown!
    PEInfo: -

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •