Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 36

Thread: Hello Its been Awhile

  1. #11
    Senior Member
    Join Date
    May 2006
    Posts
    170

    Default

    Here they are

  2. #12
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Make sure you update ComboFix during the following process.

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    File::
    C:\Documents and Settings\All Users\Application Data\avg9\Temp\avg-308c8625-834d-4b56-b35c-02016299a464.tmp
    C:\Documents and Settings\All Users\Application Data\avg9\Temp\avg-4c44eb3a-f625-491f-8bf4-a52e7b23045a.tmp
    C:\Documents and Settings\Bob\Application Data\Sun\Java\Deployment\cache\6.0\27\77aee51b-2ccc86d7
    C:\Documents and Settings\Bob\Application Data\Sun\Java\Deployment\cache\6.0\27\77aee51b-66ae5cd8
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\Yahoo!\Companion\Installs\cpn2\ytbb.exe
    C:\WINDOWS\Downloaded Program Files\QaBar.dll

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe (let the tool to update itself if prompted).
    Then post the resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #13
    Senior Member
    Join Date
    May 2006
    Posts
    170

    Default

    Things have been going well until this last run.

    System won't let me open IE now. I see that the 280384237:390508522 process is now running in the system again. I was able to get around that when I did the system restore when this first happened. But it looks ilk fit is now back?

    Log attached

  4. #14
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Format of that log is impossible to read. Was that log ComboFix created in c:\ or did you manually change its output format (by enabling word wrap)? If it was the first mentioned run ComboFix again with that same cfscript. Post back the log + fresh dds & ESET logs.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  5. #15
    Senior Member
    Join Date
    May 2006
    Posts
    170

    Default

    I had to send the log via email to my MAC. Here is the log. This was at C:.

    I will rerun the script again because now I can't open IE.

    But here is the last log for your review.



    ComboFix 11-11-10.01 - Bob 11/10/2011 1:16.8.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.228 [GMT -6:00]
    Running from: c:\documents and settings\Bob\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Bob\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .
    FILE ::
    "c:\documents and settings\All Users\Application Data\avg9\Temp\avg-308c8625-834d-4b56-b35c-02016299a464.tmp"
    "c:\documents and settings\All Users\Application Data\avg9\Temp\avg-4c44eb3a-f625-491f-8bf4-a52e7b23045a.tmp"
    "c:\documents and settings\Bob\Application Data\Sun\Java\Deployment\cache\6.0\27\77aee51b-2ccc86d7"
    "c:\documents and settings\Bob\Application Data\Sun\Java\Deployment\cache\6.0\27\77aee51b-66ae5cd8"
    "c:\program files\AVG\AVG9\avgchsvx.exe"
    "c:\program files\AVG\AVG9\avgnsx.exe"
    "c:\program files\Yahoo!\Companion\Installs\cpn2\ytbb.exe"
    "c:\windows\Downloaded Program Files\QaBar.dll"
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-10-10 to 2011-11-10 )))))))))))))))))))))))))))))))
    .
    .
    2011-11-09 15:00 . 2011-11-09 15:00 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\Sun
    2011-11-09 11:43 . 2011-11-09 11:43 -------- d-----w- c:\windows\LastGood
    2011-11-09 05:31 . 2011-11-09 05:31 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2011-11-09 02:09 . 2011-11-09 02:09 -------- d-----w- c:\program files\ESET
    2011-11-09 02:02 . 2011-11-09 02:02 -------- d-----w- c:\program files\Common Files\Java
    2011-11-09 02:01 . 2011-11-09 01:59 128000 ----a-w- c:\windows\system32\javacpl.cpl
    2011-11-09 01:25 . 2011-11-09 01:25 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-05 22:59 . 2011-11-05 22:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
    2011-11-05 22:58 . 2011-11-05 22:58 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
    2011-11-05 06:12 . 2011-11-05 06:12 -------- d-----w- C:\rsit
    2011-11-05 05:45 . 2011-11-05 05:46 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-11-05 05:42 . 2011-08-31 22:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-11-05 05:42 . 2011-11-05 05:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-11-05 04:25 . 2011-11-05 04:25 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-11-05 04:13 . 2011-11-05 04:13 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
    2011-10-21 00:38 . 2011-10-21 00:38 664 ----a-w- c:\documents and settings\Bob\Local Settings\Application Data\d3d9caps.tmp
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-11-09 01:59 . 2010-10-13 18:31 544656 ----a-w- c:\windows\system32\deployJava1.dll
    2011-09-26 16:41 . 2008-07-30 01:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
    2011-09-26 16:41 . 2002-08-29 10:00 220160 ----a-w- c:\windows\system32\oleacc.dll
    2011-09-26 16:41 . 2002-08-29 10:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-09-13 13:08 . 2007-03-01 16:09 29712 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2011-09-09 09:12 . 2004-11-22 19:14 599040 ----a-w- c:\windows\system32\crypt32.dll
    2011-09-06 13:20 . 2004-11-22 19:12 1858944 ----a-w- c:\windows\system32\win32k.sys
    2011-08-22 23:48 . 2004-11-22 19:13 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-08-22 23:48 . 2004-11-22 19:14 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-08-22 23:48 . 2004-11-22 19:14 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-08-22 11:56 . 2004-08-04 05:59 385024 ----a-w- c:\windows\system32\html.iec
    2011-08-17 13:49 . 2004-11-22 19:12 138496 ----a-w- c:\windows\system32\drivers\afd.sys
    2004-02-19 02:22 . 2004-02-27 06:11 1009152 ----a-w- c:\program files\K-Tuner.msi
    1998-02-10 22:34 . 2003-05-10 05:31 128000 ----a-w- c:\program files\UNWISE.EXE
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-11-08_09.18.45 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2011-11-09 05:31 . 2011-11-09 05:31 28160 c:\windows\Installer\c93d3b.msi
    + 2011-06-06 18:55 . 2011-06-06 18:55 17304 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\ViewerPS.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 35736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\reader_sl.exe
    + 2011-06-06 18:55 . 2011-06-06 18:55 88992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlr.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 94608 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\eula.exe
    + 2011-06-06 18:55 . 2011-06-06 18:55 49064 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrotextextractor.exe
    + 2011-06-06 18:55 . 2011-06-06 18:55 17824 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32Info.exe
    + 2011-06-06 18:55 . 2011-06-06 18:55 63912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acroiehelpershim.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 64928 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroIEHelper.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 63384 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\Acrofx32.dll
    + 2011-11-09 01:25 . 2011-11-09 01:25 247968 c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11c_ActiveX.exe
    + 2011-11-09 01:25 . 2011-11-09 01:25 335520 c:\windows\SYSTEM32\Macromed\Flash\FlashUtil11c_ActiveX.dll
    + 2011-11-09 02:01 . 2011-11-09 01:59 214408 c:\windows\SYSTEM32\javaws.exe
    + 2011-11-09 02:01 . 2011-11-09 01:59 173960 c:\windows\SYSTEM32\javaw.exe
    + 2011-11-09 02:01 . 2011-11-09 01:59 173960 c:\windows\SYSTEM32\java.exe
    + 2002-12-17 17:27 . 2003-05-06 18:50 206464 c:\windows\SYSTEM32\DRIVERS\udfreadr_xp.sys
    - 2002-12-17 17:27 . 2004-09-16 00:24 206464 c:\windows\SYSTEM32\DRIVERS\udfreadr_xp.sys
    + 2011-11-09 02:02 . 2011-11-09 02:02 176640 c:\windows\Installer\637f4.msi
    + 2011-11-09 01:59 . 2011-11-09 01:59 938496 c:\windows\Installer\637ee.msi
    + 2011-06-06 18:55 . 2011-06-06 18:55 249232 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\sqlite.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 394136 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\pdfshell.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 103848 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlrShim.exe
    + 2011-06-06 18:55 . 2011-06-06 18:55 183696 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\nppdf32.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 104344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AiodLite.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 102808 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRdIF.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 755088 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroPDF.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 296344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrobroker.exe
    + 2011-06-06 18:55 . 2011-06-06 18:55 205720 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\a3dutils.dll
    + 2011-11-09 14:56 . 2011-11-09 14:56 294912 c:\windows\ERDNT\AutoBackup\11-9-2011\Users\00000002\UsrClass.dat
    + 2011-11-09 14:56 . 2005-10-20 18:02 163328 c:\windows\ERDNT\AutoBackup\11-9-2011\ERDNT.EXE
    + 2011-11-09 05:44 . 2011-11-09 05:44 2295808 c:\windows\Installer\c93dff.msi
    + 2011-06-06 18:55 . 2011-06-06 18:55 2215312 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\rt3d.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 6543768 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\authplay.dll
    + 2011-06-06 18:55 . 2011-06-06 18:55 1240992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AdobeCollabSync.exe
    + 2011-06-06 18:55 . 2011-06-06 18:55 1480600 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.exe
    + 2011-11-09 14:56 . 2011-11-09 14:56 8654848 c:\windows\ERDNT\AutoBackup\11-9-2011\Users\00000001\ntuser.dat
    + 2011-09-05 21:51 . 2011-09-05 21:51 13135872 c:\windows\Installer\c93e00.msp
    + 2011-06-06 18:55 . 2011-06-06 18:55 24731544 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    2008-10-15 17:59 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-15 333192]
    .
    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-15 333192]
    .
    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SkinClock"="c:\program files\Free Desktop Clock\DesktopClock.exe" [2006-10-01 334848]
    "Eraser"="c:\program files\Eraser\Eraser.exe" [2009-06-10 334224]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-28 68856]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
    "DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2003-10-07 294912]
    "AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2004-09-16 684032]
    "StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 155648]
    "eFax 4.2"="c:\program files\eFax Messenger 4.2\J2GDllCmd.exe" [2006-06-20 107008]
    "nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-05-21 451896]
    "nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-05-06 151597]
    "Linksys Wireless Manager"="c:\program files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2009-02-16 1358384]
    "RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-28 68856]
    .
    c:\documents and settings\Bob\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
    Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-11-16 111376]
    Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1996-11-16 51984]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
    SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2004-10-30 217088]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2010-07-15 14:57 12536 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online Tray Icon.lnk
    backup=c:\windows\pss\America Online Tray Icon.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
    backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Bob^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
    path=c:\documents and settings\Bob\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
    backup=c:\windows\pss\PowerReg Scheduler V3.exeStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    c:\windows\system32\dumprep 0 -k [X]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
    2004-09-16 00:24 684032 ----a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2005-10-19 13:59 126976 ----a-w- c:\windows\SYSTEM32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2005-10-19 13:59 155648 ----a-w- c:\windows\SYSTEM32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 23:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2003-05-06 18:50 151597 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\AIM\\aim.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"=
    "c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
    "c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
    "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
    "c:\\Program Files\\Outlook Express\\msimn.exe"=
    "c:\\WINDOWS\\SYSTEM32\\msfeedssync.exe"=
    "c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "67:UDP"= 67:UDP:DHCP Discovery Service
    .
    R0 sonyhcb;Sony Digital Imaging Base;c:\windows\SYSTEM32\DRIVERS\sonyhcb.sys [7/7/2003 8:39 PM 6097]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [6/19/2008 7:21 AM 216400]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [6/19/2008 7:21 AM 243152]
    R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/8/2011 3:07 AM 308136]
    R3 L6DP;L6DP;c:\windows\SYSTEM32\DRIVERS\l6dp.sys [7/15/2002 9:39 PM 26496]
    R3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\SYSTEM32\DRIVERS\WUSB54GCv3.sys [6/22/2009 10:31 AM 627072]
    S3 L6PODLV;PODxt Live Service;c:\windows\SYSTEM32\DRIVERS\L6PODLV.sys [10/5/2004 7:58 PM 114048]
    S3 RDID1003;EDIROL UM-2;c:\windows\SYSTEM32\DRIVERS\Rdwm1003.sys [11/5/2007 1:30 AM 80481]
    S3 RDID1005;EDIROL UA-5;c:\windows\SYSTEM32\DRIVERS\Rdwm1005.sys [5/22/2003 10:35 PM 144561]
    S3 RDWM1005;EDIROL UA-5 (WDM);c:\windows\SYSTEM32\DRIVERS\Rdwm1005.sys [5/22/2003 10:35 PM 144561]
    S3 sonyhcs;Sony Digital Imaging Video;c:\windows\SYSTEM32\DRIVERS\sonyhcs.sys [7/7/2003 8:39 PM 299923]
    S3 WLUX96;3Com 3CRSHEW696 Wireless LAN USB Adapter;c:\windows\SYSTEM32\DRIVERS\wlux96f.sys [5/22/2003 11:06 PM 80896]
    S4 sptd;sptd;c:\windows\SYSTEM32\DRIVERS\sptd.sys [11/27/2006 10:18 PM 639224]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
    .
    2011-11-09 c:\windows\Tasks\User_Feed_Synchronization-{622DC8BF-5DC0-43FC-829B-F944D2B2EB67}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-14 09:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://google.com/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.yahoo.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
    TCP: DhcpNameServer = 68.94.156.1 68.94.157.1 192.168.1.1
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-11-10 01:36
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    DwlClient = c:\program files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e???????X:??h???x???@???X???????????@???P???? ?w? ?w)??p????????(???y????U?w????????????0??????w, ?w?M?wW??w???w)??p????????x'@?????????X????????"@?e?????
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'explorer.exe'(3776)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2011-11-10 01:42:45
    ComboFix-quarantined-files.txt 2011-11-10 07:42
    ComboFix2.txt 2011-11-09 20:47
    ComboFix3.txt 2011-11-09 06:30
    ComboFix4.txt 2011-11-09 01:06
    ComboFix5.txt 2011-11-10 07:13
    .
    Pre-Run: 3,087,073,280 bytes free
    Post-Run: 3,063,267,328 bytes free
    .
    - - End Of File - - CB029E39001C8A0EA1EFD627C3591B45

  6. #16
    Senior Member
    Join Date
    May 2006
    Posts
    170

    Default

    I seem to be having real trouble now. IE will not open in any way. I tried to run in safe mode....still won't open.

    Here is the last combo fix log. I didn't want to attach it because I had to email it to my MAC in order to be able to post it.

    Odd. Everything was going smoothly up until last nights combo fix?

    I'm nervous now!





    ComboFix 11-11-10.02 - Bob 11/10/2011 9:47.9.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.108 [GMT -6:00]
    Running from: c:\documents and settings\Bob\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Bob\Desktop\CFScript.txt
    AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .
    FILE ::
    "c:\documents and settings\All Users\Application Data\avg9\Temp\avg-308c8625-834d-4b56-b35c-02016299a464.tmp"
    "c:\documents and settings\All Users\Application Data\avg9\Temp\avg-4c44eb3a-f625-491f-8bf4-a52e7b23045a.tmp"
    "c:\documents and settings\Bob\Application Data\Sun\Java\Deployment\cache\6.0\27\77aee51b-2ccc86d7"
    "c:\documents and settings\Bob\Application Data\Sun\Java\Deployment\cache\6.0\27\77aee51b-66ae5cd8"
    "c:\program files\AVG\AVG9\avgchsvx.exe"
    "c:\program files\AVG\AVG9\avgnsx.exe"
    "c:\program files\Yahoo!\Companion\Installs\cpn2\ytbb.exe"
    "c:\windows\Downloaded Program Files\QaBar.dll"
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\$NtUninstallKB63333$\389881767\@
    c:\windows\$NtUninstallKB63333$\389881767\L\asobptkf
    c:\windows\$NtUninstallKB63333$\389881767\loader.tlb
    c:\windows\$NtUninstallKB63333$\389881767\U\@00000001
    c:\windows\$NtUninstallKB63333$\389881767\U\@000000c0
    c:\windows\$NtUninstallKB63333$\389881767\U\@000000cb
    c:\windows\$NtUninstallKB63333$\389881767\U\@000000cf
    c:\windows\$NtUninstallKB63333$\389881767\U\@80000000
    c:\windows\$NtUninstallKB63333$\389881767\U\@800000c0
    c:\windows\$NtUninstallKB63333$\389881767\U\@800000cb
    c:\windows\$NtUninstallKB63333$\389881767\U\@800000cf
    c:\windows\$NtUninstallKB63333$\986928604
    c:\windows\system32\
    c:\windows\system32\c_75354.nl_
    c:\windows\$NtUninstallKB63333$ . . . . Failed to delete
    .
    c:\windows\system32\drivers\cdudf_xp.sys . . . is infected!! . . . Failed to find a valid replacement.
    Infected copy of c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe was found and disinfected
    Restored copy from - c:\system volume information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP397\A0043816.exe
    .
    Infected copy of c:\program files\AVG\AVG9\avgwdsvc.exe was found and disinfected
    Restored copy from - c:\system volume information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP397\A0043817.exe
    .
    Infected copy of c:\program files\Bonjour\mDNSResponder.exe was found and disinfected
    Restored copy from - c:\system volume information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP397\A0043818.exe
    .
    Infected copy of c:\program files\iPod\bin\iPodService.exe was found and disinfected
    Restored copy from - c:\system volume information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP397\A0043828.exe
    .
    Infected copy of c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe was found and disinfected
    Restored copy from - c:\system volume information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP397\A0043820.exe
    .
    Infected copy of c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe was found and disinfected
    Restored copy from - c:\system volume information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP397\A0043819.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Service_173d1fa7
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-10-10 to 2011-11-10 )))))))))))))))))))))))))))))))
    .
    .
    2011-11-09 15:00 . 2011-11-09 15:00 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\Sun
    2011-11-09 05:31 . 2011-11-09 05:31 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2011-11-09 02:09 . 2011-11-09 02:09 -------- d-----w- c:\program files\ESET
    2011-11-09 02:02 . 2011-11-09 02:02 -------- d-----w- c:\program files\Common Files\Java
    2011-11-09 01:25 . 2011-11-09 01:25 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-05 22:59 . 2011-11-05 22:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
    2011-11-05 22:58 . 2011-11-05 22:58 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
    2011-11-05 06:12 . 2011-11-05 06:12 -------- d-----w- C:\rsit
    2011-11-05 05:45 . 2011-11-05 05:46 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-11-05 05:42 . 2011-08-31 22:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-11-05 05:42 . 2011-11-05 05:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-11-05 04:25 . 2011-11-05 04:25 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-11-05 04:13 . 2011-11-05 04:13 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
    2011-10-21 00:38 . 2011-10-21 00:38 664 ----a-w- c:\documents and settings\Bob\Local Settings\Application Data\d3d9caps.tmp
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-11-09 01:59 . 2011-11-09 02:01 128000 ----a-w- c:\windows\system32\javacpl.cpl
    2011-11-09 01:59 . 2010-10-13 18:31 544656 ----a-w- c:\windows\system32\deployJava1.dll
    2011-10-10 14:22 . 2004-11-22 19:14 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-09-26 16:41 . 2008-07-30 01:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
    2011-09-26 16:41 . 2002-08-29 10:00 220160 ----a-w- c:\windows\system32\oleacc.dll
    2011-09-26 16:41 . 2002-08-29 10:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-09-13 13:08 . 2007-03-01 16:09 29712 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2011-09-09 09:12 . 2004-11-22 19:14 599040 ----a-w- c:\windows\system32\crypt32.dll
    2011-09-06 13:20 . 2004-11-22 19:12 1858944 ----a-w- c:\windows\system32\win32k.sys
    2011-08-22 23:48 . 2004-11-22 19:13 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-08-22 23:48 . 2004-11-22 19:14 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-08-22 23:48 . 2004-11-22 19:14 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-08-22 11:56 . 2004-08-04 05:59 385024 ----a-w- c:\windows\system32\html.iec
    2011-08-17 13:49 . 2004-11-22 19:12 138496 ----a-w- c:\windows\system32\drivers\afd.sys
    2004-02-19 02:22 . 2004-02-27 06:11 1009152 ----a-w- c:\program files\K-Tuner.msi
    1998-02-10 22:34 . 2003-05-10 05:31 128000 ----a-w- c:\program files\UNWISE.EXE
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    2008-10-15 17:59 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-15 333192]
    .
    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-15 333192]
    .
    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SkinClock"="c:\program files\Free Desktop Clock\DesktopClock.exe" [2006-10-01 334848]
    "Eraser"="c:\program files\Eraser\Eraser.exe" [2009-06-10 334224]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-28 68856]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
    "DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2003-10-07 294912]
    "AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2004-09-16 684032]
    "StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 155648]
    "eFax 4.2"="c:\program files\eFax Messenger 4.2\J2GDllCmd.exe" [2006-06-20 107008]
    "nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-05-21 451896]
    "nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-05-06 151597]
    "Linksys Wireless Manager"="c:\program files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2009-02-16 1358384]
    "RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-28 68856]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
    SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2004-10-30 217088]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2010-07-15 14:57 12536 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online Tray Icon.lnk
    backup=c:\windows\pss\America Online Tray Icon.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
    backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Bob^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
    path=c:\documents and settings\Bob\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
    backup=c:\windows\pss\PowerReg Scheduler V3.exeStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    c:\windows\system32\dumprep 0 -k [X]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
    2004-09-16 00:24 684032 ----a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2005-10-19 13:59 126976 ----a-w- c:\windows\SYSTEM32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2005-10-19 13:59 155648 ----a-w- c:\windows\SYSTEM32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 23:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2003-05-06 18:50 151597 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\AIM\\aim.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"=
    "c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
    "c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
    "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
    "c:\\Program Files\\Outlook Express\\msimn.exe"=
    "c:\\WINDOWS\\SYSTEM32\\msfeedssync.exe"=
    "c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "67:UDP"= 67:UDP:DHCP Discovery Service
    .
    R0 sonyhcb;Sony Digital Imaging Base;c:\windows\SYSTEM32\DRIVERS\sonyhcb.sys [7/7/2003 8:39 PM 6097]
    R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [6/19/2008 7:21 AM 216400]
    R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [6/19/2008 7:21 AM 243152]
    R3 L6DP;L6DP;c:\windows\SYSTEM32\DRIVERS\l6dp.sys [7/15/2002 9:39 PM 26496]
    R3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\SYSTEM32\DRIVERS\WUSB54GCv3.sys [6/22/2009 10:31 AM 627072]
    S3 L6PODLV;PODxt Live Service;c:\windows\SYSTEM32\DRIVERS\L6PODLV.sys [10/5/2004 7:58 PM 114048]
    S3 RDID1003;EDIROL UM-2;c:\windows\SYSTEM32\DRIVERS\Rdwm1003.sys [11/5/2007 1:30 AM 80481]
    S3 RDID1005;EDIROL UA-5;c:\windows\SYSTEM32\DRIVERS\Rdwm1005.sys [5/22/2003 10:35 PM 144561]
    S3 RDWM1005;EDIROL UA-5 (WDM);c:\windows\SYSTEM32\DRIVERS\Rdwm1005.sys [5/22/2003 10:35 PM 144561]
    S3 sonyhcs;Sony Digital Imaging Video;c:\windows\SYSTEM32\DRIVERS\sonyhcs.sys [7/7/2003 8:39 PM 299923]
    S3 WLUX96;3Com 3CRSHEW696 Wireless LAN USB Adapter;c:\windows\SYSTEM32\DRIVERS\wlux96f.sys [5/22/2003 11:06 PM 80896]
    S4 sptd;sptd;c:\windows\SYSTEM32\DRIVERS\sptd.sys [11/27/2006 10:18 PM 639224]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
    .
    2011-11-10 c:\windows\Tasks\User_Feed_Synchronization-{622DC8BF-5DC0-43FC-829B-F944D2B2EB67}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-14 09:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://google.com/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.yahoo.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
    TCP: DhcpNameServer = 68.94.156.1 68.94.157.1 192.168.1.1
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-11-10 10:22
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    DwlClient = c:\program files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e???????X:??h???x???@???X???????????@???P???? ?w? ?w)??p????????(???y????U?w????????????0??????w, ?w?M?wW??w???w)??p????????x'@?????????X????????"@?e?????
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'explorer.exe'(3832)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\AVG\AVG9\avgchsvx.exe
    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\AVG\AVG9\avgwdsvc.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
    c:\program files\AVG\AVG9\avgnsx.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\Microsoft Office\Office\OSA.EXE
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2011-11-10 10:47:01 - machine was rebooted
    ComboFix-quarantined-files.txt 2011-11-10 16:46
    ComboFix2.txt 2011-11-10 07:42
    ComboFix3.txt 2011-11-09 20:47
    ComboFix4.txt 2011-11-09 06:30
    ComboFix5.txt 2011-11-10 14:59
    .
    Pre-Run: 2,878,734,336 bytes free
    Post-Run: 2,856,169,472 bytes free
    .
    - - End Of File - - 0C0908A93AC14372B04823AAC081BCBA

  7. #17
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Do you get any error message or how does IE fail?

    Uninstall AVG.

    Then manually delete following files one by one (if found):
    C:\Documents and Settings\All Users\Application Data\avg9\Temp\avg-308c8625-834d-4b56-b35c-02016299a464.tmp
    C:\Documents and Settings\All Users\Application Data\avg9\Temp\avg-4c44eb3a-f625-491f-8bf4-a52e7b23045a.tmp
    C:\Documents and Settings\Bob\Application Data\Sun\Java\Deployment\cache\6.0\27\77aee51b-2ccc86d7
    C:\Documents and Settings\Bob\Application Data\Sun\Java\Deployment\cache\6.0\27\77aee51b-66ae5cd8
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\Yahoo!\Companion\Installs\cpn2\ytbb.exe
    C:\WINDOWS\Downloaded Program Files\QaBar.dll


    Re-run ComboFix.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  8. #18
    Senior Member
    Join Date
    May 2006
    Posts
    170

    Default

    I click on it (IE) and nothing happens. When i click on a bookmark file that is linked to IE it says "windows cannot access the specified device, file, or path. You may not have appropriate permissions to access item.

    I will work on the other things now.

  9. #19
    Senior Member
    Join Date
    May 2006
    Posts
    170

    Default

    Ok. I was able to find a few of the files and delete them. The rest were not found.

    I am still not able to open IE so I have to post the log here rather than attach it.

    Thanks


    ComboFix 11-11-10.02 - Bob 11/10/2011 12:47:30.10.1 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.184 [GMT -6:00]
    Running from: c:\documents and settings\Bob\Desktop\ComboFix.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\system32\drivers\cdudf_xp.sys . . . is infected!!
    .
    .
    ((((((((((((((((((((((((( Files Created from 2011-10-10 to 2011-11-10 )))))))))))))))))))))))))))))))
    .
    .
    2011-11-09 15:00 . 2011-11-09 15:00 -------- d-----w- c:\documents and settings\Bob\Local Settings\Application Data\Sun
    2011-11-09 05:31 . 2011-11-09 05:31 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2011-11-09 02:09 . 2011-11-09 02:09 -------- d-----w- c:\program files\ESET
    2011-11-09 02:02 . 2011-11-09 02:02 -------- d-----w- c:\program files\Common Files\Java
    2011-11-09 02:01 . 2011-11-09 01:59 128000 ----a-w- c:\windows\system32\javacpl.cpl
    2011-11-09 01:25 . 2011-11-09 01:25 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-11-05 22:59 . 2011-11-05 22:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
    2011-11-05 22:58 . 2011-11-05 22:58 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
    2011-11-05 06:12 . 2011-11-05 06:12 -------- d-----w- C:\rsit
    2011-11-05 05:45 . 2011-11-05 05:46 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-11-05 05:42 . 2011-08-31 22:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-11-05 05:42 . 2011-11-05 05:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-11-05 04:25 . 2011-11-05 04:25 -------- d-----w- c:\windows\system32\wbem\Repository
    2011-11-05 04:13 . 2011-11-05 04:13 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
    2011-10-21 00:38 . 2011-10-21 00:38 664 ----a-w- c:\documents and settings\Bob\Local Settings\Application Data\d3d9caps.tmp
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-11-09 01:59 . 2010-10-13 18:31 544656 ----a-w- c:\windows\system32\deployJava1.dll
    2011-10-10 14:22 . 2004-11-22 19:14 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-09-26 16:41 . 2008-07-30 01:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
    2011-09-26 16:41 . 2002-08-29 10:00 220160 ----a-w- c:\windows\system32\oleacc.dll
    2011-09-26 16:41 . 2002-08-29 10:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
    2011-09-09 09:12 . 2004-11-22 19:14 599040 ----a-w- c:\windows\system32\crypt32.dll
    2011-09-06 13:20 . 2004-11-22 19:12 1858944 ----a-w- c:\windows\system32\win32k.sys
    2011-08-22 23:48 . 2004-11-22 19:13 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-08-22 23:48 . 2004-11-22 19:14 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-08-22 23:48 . 2004-11-22 19:14 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2011-08-22 11:56 . 2004-08-04 05:59 385024 ----a-w- c:\windows\system32\html.iec
    2011-08-17 13:49 . 2004-11-22 19:12 138496 ----a-w- c:\windows\system32\drivers\afd.sys
    2004-02-19 02:22 . 2004-02-27 06:11 1009152 ----a-w- c:\program files\K-Tuner.msi
    1998-02-10 22:34 . 2003-05-10 05:31 128000 ----a-w- c:\program files\UNWISE.EXE
    .
    .
    ------- Sigcheck -------
    Note: Unsigned files aren't necessarily malware.
    .
    [7] 2009-04-25 . 092A7F2B49A19ECCE5369D3CB2276148 . 636088 . . [7.00.6000.16850] . . c:\windows\ie8\iexplore.exe
    [7] 2009-04-25 . C0503FD8D163652735C1EE900672A75C . 636088 . . [7.00.6000.21045] . . c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
    [7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\ERDNT\cache\iexplore.exe
    [7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
    [7] 2009-02-28 . BCD8E48709BE4A79606F0B6E8E9A6162 . 636088 . . [7.00.6000.21020] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
    [7] 2009-02-28 . A251068640DDB69FD7805B57D89D7FF7 . 636072 . . [7.00.6000.16827] . . c:\windows\ie7updates\KB969897-IE7\iexplore.exe
    [7] 2008-12-19 . 15E8A89499741D5CF59A9CF6463A4339 . 634024 . . [7.00.6000.20978] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
    [7] 2008-12-19 . 030D78FE84A086ED376EFCBD2D72C522 . 634024 . . [7.00.6000.16791] . . c:\windows\ie7updates\KB963027-IE7\iexplore.exe
    [7] 2008-10-15 . 9D3DB9ADFABD2F0BC778EC03250A3ABB . 633632 . . [7.00.6000.16762] . . c:\windows\ie7updates\KB961260-IE7\iexplore.exe
    [7] 2008-10-15 . 056C927CF7207857E8B34F7A8FFD9B9E . 633632 . . [7.00.6000.20935] . . c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
    [7] 2008-08-23 . E8305C30D35E85D6657ED3E9934CB302 . 635848 . . [7.00.6000.20900] . . c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
    [7] 2008-08-23 . 1F03216084447F990AE797317D0A6E70 . 635848 . . [7.00.6000.16735] . . c:\windows\ie7updates\KB958215-IE7\iexplore.exe
    [7] 2008-06-23 . 64E376A47763DAEABCDA14BD5B6EA286 . 625664 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB956390-IE7\iexplore.exe
    [7] 2008-06-23 . C52A9EF571E91535EB78DB4B8B95EA07 . 625664 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
    [7] 2008-04-22 . 197B7E4030CFBD8D2979D375E1787AA2 . 625664 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
    [7] 2008-04-22 . 232B22817B90AE0AFF2D189E3E3735AC . 625664 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\iexplore.exe
    [7] 2008-04-14 . 55794B97A7FAABD2910873C85274F409 . 93184 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\iexplore.exe
    [7] 2008-02-29 . 2D0E5592AB5A46C27DAF7CCAFF4F5B59 . 625664 . . [7.00.6000.16640] . . c:\windows\ie7updates\KB950759-IE7\iexplore.exe
    [7] 2008-02-22 . 6E0888626E0CAC79F57149814E22DB4D . 625664 . . [7.00.6000.20772] . . c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
    [7] 2007-12-06 . 2703D940A62B731AA220529DD7331A78 . 625664 . . [7.00.6000.16608] . . c:\windows\ie7updates\KB947864-IE7\iexplore.exe
    [7] 2007-12-06 . 809D17D8FA0FDAEE07778CD821CAFFDE . 625664 . . [7.00.6000.20733] . . c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
    [7] 2007-10-10 . E854D02E4231F704D9BE782A424E6D8B . 625152 . . [7.00.6000.16574] . . c:\windows\ie7updates\KB944533-IE7\iexplore.exe
    [7] 2007-10-10 . E854D02E4231F704D9BE782A424E6D8B . 625152 . . [7.00.6000.16574] . . c:\windows\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2GDR\iexplore.exe
    [7] 2007-10-10 . 632BDE0179847234433CA50945442ACB . 625664 . . [7.00.6000.20696] . . c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
    2008-10-15 17:59 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-15 333192]
    .
    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    .
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-15 333192]
    .
    [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
    [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SkinClock"="c:\program files\Free Desktop Clock\DesktopClock.exe" [2006-10-01 334848]
    "Eraser"="c:\program files\Eraser\Eraser.exe" [2009-06-10 334224]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-28 68856]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
    "DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2003-10-07 294912]
    "AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2004-09-16 684032]
    "StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 155648]
    "eFax 4.2"="c:\program files\eFax Messenger 4.2\J2GDllCmd.exe" [2006-06-20 107008]
    "nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-05-21 451896]
    "nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-05-06 151597]
    "Linksys Wireless Manager"="c:\program files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2009-02-16 1358384]
    "RIMBBLaunchAgent.exe"="c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYAMgBRAEcAUgAtAFMAWAAwAEsARwAtAEcAMABOAFYAQQAtAEIAQQBCADYAOAAtAEQARgBUAFQAUAA&inst=NwA3AC0AMwA4ADcAMAAyADgAMAA5ADIALQBGAFAAOQArADYALQBCAEEAUgA5AEcAKwAxAC0AVABCADkAKwAyAC0ARgBMACsAOQAtAFgATwAzADYAKwAxAC0ARgA5AE0ANwBDACsANQAtAEYAOQBNADEAMABCACsAMQAtAFgATwA5ACsAMQAtAEYAOQBNADIAKwAxAC0ARABEAFQAKwA1ADQANAA1ADEALQBEAEQAOQAwAEYAKwAxAC0AUwBUADkAMABGAEEAUABQACsAMQAtAEYAOQAwAE0AMQAyAEEAVAArADIALQBGADkAMABNADEAMgBBACsAMQAtAEYAOQAwAE0AMQAyAEEAQgArADEALQBVADkANQArADEALQBGADkAMABNADEAMgBBAFQAQgBOACsAMQA&prod=90&ver=9.0.894" [?]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-28 68856]
    .
    c:\documents and settings\Bob\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
    Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-11-16 111376]
    Office Startup.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1996-11-16 51984]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
    SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2004-10-30 217088]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
    backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online Tray Icon.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online Tray Icon.lnk
    backup=c:\windows\pss\America Online Tray Icon.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
    backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^Bob^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
    path=c:\documents and settings\Bob\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
    backup=c:\windows\pss\PowerReg Scheduler V3.exeStartup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
    c:\windows\system32\dumprep 0 -k [X]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
    2004-09-16 00:24 684032 ----a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2005-10-19 13:59 126976 ----a-w- c:\windows\SYSTEM32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2005-10-19 13:59 155648 ----a-w- c:\windows\SYSTEM32\igfxtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 23:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2003-05-06 18:50 151597 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\AIM\\aim.exe"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"=
    "c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
    "c:\\Program Files\\AIM6\\aim6.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\WINDOWS\\SYSTEM32\\dpvsetup.exe"=
    "c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
    "c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
    "c:\\Program Files\\Outlook Express\\msimn.exe"=
    "c:\\WINDOWS\\SYSTEM32\\msfeedssync.exe"=
    "c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "67:UDP"= 67:UDP:DHCP Discovery Service
    .
    R0 sonyhcb;Sony Digital Imaging Base;c:\windows\SYSTEM32\DRIVERS\sonyhcb.sys [7/7/2003 8:39 PM 6097]
    R3 L6DP;L6DP;c:\windows\SYSTEM32\DRIVERS\l6dp.sys [7/15/2002 9:39 PM 26496]
    R3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\SYSTEM32\DRIVERS\WUSB54GCv3.sys [6/22/2009 10:31 AM 627072]
    S3 L6PODLV;PODxt Live Service;c:\windows\SYSTEM32\DRIVERS\L6PODLV.sys [10/5/2004 7:58 PM 114048]
    S3 RDID1003;EDIROL UM-2;c:\windows\SYSTEM32\DRIVERS\Rdwm1003.sys [11/5/2007 1:30 AM 80481]
    S3 RDID1005;EDIROL UA-5;c:\windows\SYSTEM32\DRIVERS\Rdwm1005.sys [5/22/2003 10:35 PM 144561]
    S3 RDWM1005;EDIROL UA-5 (WDM);c:\windows\SYSTEM32\DRIVERS\Rdwm1005.sys [5/22/2003 10:35 PM 144561]
    S3 sonyhcs;Sony Digital Imaging Video;c:\windows\SYSTEM32\DRIVERS\sonyhcs.sys [7/7/2003 8:39 PM 299923]
    S3 WLUX96;3Com 3CRSHEW696 Wireless LAN USB Adapter;c:\windows\SYSTEM32\DRIVERS\wlux96f.sys [5/22/2003 11:06 PM 80896]
    S4 sptd;sptd;c:\windows\SYSTEM32\DRIVERS\sptd.sys [11/27/2006 10:18 PM 639224]
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2011-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
    .
    2011-11-10 c:\windows\Tasks\User_Feed_Synchronization-{622DC8BF-5DC0-43FC-829B-F944D2B2EB67}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-14 09:31]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://google.com/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mStart Page = hxxp://www.yahoo.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.dellnet.com/
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
    TCP: DhcpNameServer = 68.94.156.1 68.94.157.1 192.168.1.1
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-11-10 13:12
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    DwlClient = c:\program files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x?e???????X:??h???x???@???X???????????@???P???? ?w? ?w)??p????????(???y????U?w????????????0??????w, ?w?M?wW??w???w)??p????????x'@?????????X????????"@?e?????
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------
    .
    - - - - - - - > 'explorer.exe'(2440)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2011-11-10 13:20:43
    ComboFix-quarantined-files.txt 2011-11-10 19:20
    ComboFix2.txt 2011-11-10 16:47
    ComboFix3.txt 2011-11-10 07:42
    ComboFix4.txt 2011-11-09 20:47
    ComboFix5.txt 2011-11-10 18:41
    .
    Pre-Run: 4,023,971,840 bytes free
    Post-Run: 4,014,997,504 bytes free
    .
    - - End Of File - - EB270257D639D8B6AAD1CDB89AF4D41D

  10. #20
    Senior Member
    Join Date
    May 2006
    Posts
    170

    Default

    Ive attached a DES log. Hopefully you can read it.

    I had to email it to my MAC.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •