Happy Sunday. Latest progress
Installed and ran Wscfix. all seemed to go well.
Ran a HJT and removed the 4 entries listed.
Trashed and loaded Combofix again, rebooted into safe mode and ran it. Log is below. It seemed to reboot to normal mode and I re-ran HJT. the first of the 4 entries above was there again. I checked it to remove, hit fix but it was still there. I re-ran HJT again and the log is below.
thanks again, have a good weekend.
BTW I can't seem to get rid of those Symantec processes running...
Eddie
ComboFix 08-08-17.01 - Administrator 2008-08-17 12:24:07.7 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.359 [GMT -7:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\microsoft
C:\Documents and Settings\All Users\microsoft\SL\DL\ed6c43df-e0eb-4fbc-8231-1999c3ce2432\808d3af3-5ec3-4fe7-bb7d-0b7147cbeb10
C:\Documents and Settings\HP_Owner\Application Data\DOBE~1
C:\Documents and Settings\HP_Owner\Application Data\macromedia\Flash Player\#SharedObjects\GB9X9ZJC\interclick.com
C:\Documents and Settings\HP_Owner\Application Data\macromedia\Flash Player\#SharedObjects\GB9X9ZJC\interclick.com\ud.sol
C:\Documents and Settings\HP_Owner\Application Data\macromedia\Flash Player\#SharedObjects\GB9X9ZJC\
www.broadcaster.com
C:\Documents and Settings\HP_Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\HP_Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\HP_Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com
C:\Documents and Settings\HP_Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com\settings.sol
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@antispywaremaster[2].txt
C:\Documents and Settings\HP_Owner\UserData
C:\Documents and Settings\HP_Owner\UserData\GD27S96R\oWindowsUpdate[1].xml
C:\Documents and Settings\HP_Owner\UserData\index.dat
C:\WINDOWS\system32\abyeriij.ini
C:\WINDOWS\system32\afoxatnq.ini
C:\WINDOWS\system32\ahxxtjtx.ini
C:\WINDOWS\system32\ajvpjdms.dll
C:\WINDOWS\system32\atrxnxqk.ini
C:\WINDOWS\system32\ayvvmbfb.ini
C:\WINDOWS\system32\bblnpvaw.dll
C:\WINDOWS\system32\beeyvweq.ini
C:\WINDOWS\system32\bgucgsbp.ini
C:\WINDOWS\system32\bhilisoj.ini
C:\WINDOWS\system32\bhtmkvyr.ini
C:\WINDOWS\system32\blinicuq.dll
C:\WINDOWS\system32\bmvevhmu.ini
C:\WINDOWS\system32\bnvoscao.ini
C:\WINDOWS\system32\bopcxwsa.dll
C:\WINDOWS\system32\brtkdwfs.ini
C:\WINDOWS\system32\byodqeam.ini
C:\WINDOWS\system32\cgxqpiyp.dll
C:\WINDOWS\system32\cladcrqq.ini
C:\WINDOWS\system32\clovukgh.ini
C:\WINDOWS\system32\cmnrdmav.dll
C:\WINDOWS\system32\cputkfsv.dll
C:\WINDOWS\system32\cskiqp.dll
C:\WINDOWS\system32\cslmgdbv.ini
C:\WINDOWS\system32\csyabiqs.ini
C:\WINDOWS\system32\cuhxxyrc.ini
C:\WINDOWS\system32\cyqxddor.ini
C:\WINDOWS\system32\dgtagi.dll
C:\WINDOWS\system32\dguhtbhr.dll
C:\WINDOWS\system32\dhjrsupn.dll
C:\WINDOWS\system32\djoustgc.dll
C:\WINDOWS\system32\dnlbkind.ini
C:\WINDOWS\system32\dssbocux.ini
C:\WINDOWS\system32\dvholrnx.dll
C:\WINDOWS\system32\dwpmsskp.ini
C:\WINDOWS\system32\dxkhmwuo.dll
C:\WINDOWS\system32\eaictino.dll
C:\WINDOWS\system32\ecneeuxk.ini
C:\WINDOWS\system32\ecngapqf.ini
C:\WINDOWS\system32\ehhucjkt.dll
C:\WINDOWS\system32\ejosbnbg.dll
C:\WINDOWS\system32\eswkanrw.ini
C:\WINDOWS\system32\evsemvfj.dll
C:\WINDOWS\system32\ewfvitfx.dll
C:\WINDOWS\system32\exjpgavr.dll
C:\WINDOWS\system32\favagfwo.dll
C:\WINDOWS\system32\fcvtiucr.ini
C:\WINDOWS\system32\fdxegnyo.ini
C:\WINDOWS\system32\felldavx.ini
C:\WINDOWS\system32\ffcfsdvw.ini
C:\WINDOWS\system32\firogo.dll
C:\WINDOWS\system32\fjjndroq.ini
C:\WINDOWS\system32\fsegxchi.ini
C:\WINDOWS\system32\fuipna.dll
C:\WINDOWS\system32\furdjeii.dll
C:\WINDOWS\system32\gaymhusp.ini
C:\WINDOWS\system32\gbhveswf.ini
C:\WINDOWS\system32\gcwyrggr.dll
C:\WINDOWS\system32\gekcthua.ini
C:\WINDOWS\system32\ggtpjyud.ini
C:\WINDOWS\system32\ghanfsyr.ini
C:\WINDOWS\system32\glfbqhle.dll
C:\WINDOWS\system32\glglpkik.dll
C:\WINDOWS\system32\glipdylh.dll
C:\WINDOWS\system32\gnjmgvxy.dll
C:\WINDOWS\system32\grfyxaxt.ini
C:\WINDOWS\system32\gvebpsoo.dll
C:\WINDOWS\system32\hcjlmovi.dll
C:\WINDOWS\system32\hgxydt.dll
C:\WINDOWS\system32\hnckbeqg.ini
C:\WINDOWS\system32\htsgpefi.ini
C:\WINDOWS\system32\hugtkepu.dll
C:\WINDOWS\system32\hxyakuln.ini
C:\WINDOWS\system32\imaevyth.ini
C:\WINDOWS\system32\imcbsexi.ini
C:\WINDOWS\system32\imypxqpx.dll
C:\WINDOWS\system32\inllgwsi.ini
C:\WINDOWS\system32\iowhwwdl.ini
C:\WINDOWS\system32\isvwwofr.dll
C:\WINDOWS\system32\itbibwbf.ini
C:\WINDOWS\system32\ivbclfak.dll
C:\WINDOWS\system32\iwtkscdi.ini
C:\WINDOWS\system32\iyigvdpw.ini
C:\WINDOWS\system32\jbmgjukw.ini
C:\WINDOWS\system32\jfnpqemr.dll
C:\WINDOWS\system32\jgukwjna.dll
C:\WINDOWS\system32\jhxreudk.ini
C:\WINDOWS\system32\jifmmjjy.ini
C:\WINDOWS\system32\jmpbakbv.ini
C:\WINDOWS\system32\jogvjxph.ini
C:\WINDOWS\system32\jrqbjjno.ini
C:\WINDOWS\system32\jsgsymam.ini
C:\WINDOWS\system32\jthrxicd.dll
C:\WINDOWS\system32\karlipbu.ini
C:\WINDOWS\system32\kbtdgyeg.ini
C:\WINDOWS\system32\kekaqahg.ini
C:\WINDOWS\system32\keqdvead.ini
C:\WINDOWS\system32\kfjkhxsc.dll
C:\WINDOWS\system32\kleeeqpa.ini
C:\WINDOWS\system32\kmifjlgi.dll
C:\WINDOWS\system32\kqgjxvwl.dll
C:\WINDOWS\system32\kqshbmoq.dll
C:\WINDOWS\system32\ktgchtre.ini
C:\WINDOWS\system32\kykutb.dll
C:\WINDOWS\system32\lbpwcmvr.ini
C:\WINDOWS\system32\ljovwkyg.ini
C:\WINDOWS\system32\lnwwtaor.dll
C:\WINDOWS\system32\lprsmxif.ini
C:\WINDOWS\system32\lqmjvjex.ini
C:\WINDOWS\system32\lthfbphy.dll
C:\WINDOWS\system32\lwiutbcb.dll
C:\WINDOWS\system32\majmuhvb.dll
C:\WINDOWS\system32\mcommmwv.ini
C:\WINDOWS\system32\mcrvwvii.ini
C:\WINDOWS\system32\mdplinxg.dll
C:\WINDOWS\system32\mivypeog.ini
C:\WINDOWS\system32\mowjbwpv.ini
C:\WINDOWS\system32\mpgiwjyl.ini
C:\WINDOWS\system32\mxkvpacs.dll
C:\WINDOWS\system32\myrbinic.ini
C:\WINDOWS\system32\mztiqz.dll
C:\WINDOWS\system32\ndvfqkmw.ini
C:\WINDOWS\system32\ngwernnh.ini
C:\WINDOWS\system32\nlbvlmkt.ini
C:\WINDOWS\system32\npdvdmvs.dll
C:\WINDOWS\system32\ntcrhwcg.ini
C:\WINDOWS\system32\ntkrplqr.ini
C:\WINDOWS\system32\nvslqstr.dll
C:\WINDOWS\system32\odpidgkv.dll
C:\WINDOWS\system32\olrtmqfx.ini
C:\WINDOWS\system32\ovijpctl.ini
C:\WINDOWS\system32\oxnywsrt.ini
C:\WINDOWS\system32\pagwhhva.ini
C:\WINDOWS\system32\pdnghfta.ini
C:\WINDOWS\system32\pgattnfc.ini
C:\WINDOWS\system32\pmnflpfm.ini
C:\WINDOWS\system32\ppokmnly.dll
C:\WINDOWS\system32\pssdklma.ini
C:\WINDOWS\system32\pvdkjxtq.dll
C:\WINDOWS\system32\pvgywvag.dll
C:\WINDOWS\system32\qacomgeg.ini
C:\WINDOWS\system32\qejikfoa.ini
C:\WINDOWS\system32\qmstwydg.ini
C:\WINDOWS\system32\qnsqeuld.ini
C:\WINDOWS\system32\qqandcnc.dll
C:\WINDOWS\system32\qsywijuy.ini
C:\WINDOWS\system32\ralhwtnc.ini
C:\WINDOWS\system32\rctubdjy.dll
C:\WINDOWS\system32\rfdhfelv.dll
C:\WINDOWS\system32\rhgqhevd.dll
C:\WINDOWS\system32\rhlkapkb.dll
C:\WINDOWS\system32\rhmgossx.ini
C:\WINDOWS\system32\ribijemw.dll
C:\WINDOWS\system32\riqyrtvq.dll
C:\WINDOWS\system32\rmardxxp.dll
C:\WINDOWS\system32\rnvkaotg.ini
C:\WINDOWS\system32\romnhclt.dll
C:\WINDOWS\system32\rqmmnkkc.ini
C:\WINDOWS\system32\rrvrvdnr.ini
C:\WINDOWS\system32\rxdcexva.ini
C:\WINDOWS\system32\rxjfsqev.dll
C:\WINDOWS\system32\rxmdyqhs.ini
C:\WINDOWS\system32\sakvwuhl.ini
C:\WINDOWS\system32\scqxefvs.dll
C:\WINDOWS\system32\soopfxca.dll
C:\WINDOWS\system32\soouixoa.ini
C:\WINDOWS\system32\soxxwaug.ini
C:\WINDOWS\system32\spijkfap.ini
C:\WINDOWS\system32\spxccwjd.dll
C:\WINDOWS\system32\ssjsnvia.ini
C:\WINDOWS\system32\tbfcofiq.dll
C:\WINDOWS\system32\tclaoecr.ini
C:\WINDOWS\system32\temukjpj.dll
C:\WINDOWS\system32\tepcevno.ini
C:\WINDOWS\system32\tnobycdt.ini
C:\WINDOWS\system32\toflwvqk.ini
C:\WINDOWS\system32\tsdyjvlu.dll
C:\WINDOWS\system32\ttcmmlwi.ini
C:\WINDOWS\system32\tttss.ini
C:\WINDOWS\system32\tttss.ini2
C:\WINDOWS\system32\tubdittr.dll
C:\WINDOWS\system32\txrclrwq.ini
C:\WINDOWS\system32\udxtvfsd.dll
C:\WINDOWS\system32\ueclbmcv.dll
C:\WINDOWS\system32\umxwydda.ini
C:\WINDOWS\system32\umyefork.ini
C:\WINDOWS\system32\upvyywid.dll
C:\WINDOWS\system32\uukjannf.dll
C:\WINDOWS\system32\uxuycsju.ini
C:\WINDOWS\system32\vblqrfha.dll
C:\WINDOWS\system32\vehmhbag.ini
C:\WINDOWS\system32\vfuqywqw.ini
C:\WINDOWS\system32\vkgpjxyp.ini
C:\WINDOWS\system32\vltdhrei.ini
C:\WINDOWS\system32\vnktod.dll
C:\WINDOWS\system32\vpfgeegj.ini
C:\WINDOWS\system32\vvpyatnc.dll
C:\WINDOWS\system32\worulsyg.dll
C:\WINDOWS\system32\wxxtgmia.ini
C:\WINDOWS\system32\xavjwupe.ini
C:\WINDOWS\system32\xhrrwrdg.dll
C:\WINDOWS\system32\xjgbbgiv.ini
C:\WINDOWS\system32\xlraokup.ini
C:\WINDOWS\system32\xnypjlen.dll
C:\WINDOWS\system32\xvlhqfjp.ini
C:\WINDOWS\system32\xxkhixjo.dll
C:\WINDOWS\system32\yacnmtpc.dll
C:\WINDOWS\system32\yasojbjv.dll
C:\WINDOWS\system32\yckkekla.ini
C:\WINDOWS\system32\ydpkmwun.ini
C:\WINDOWS\system32\yicofcjd.dll
C:\WINDOWS\system32\yipilvub.ini
C:\WINDOWS\system32\yiuimvge.ini
C:\WINDOWS\system32\yjsisnkt.ini
C:\WINDOWS\system32\yqxyvcqb.ini
C:\WINDOWS\system32\yrriumxp.ini
C:\WINDOWS\system32\ysowseah.dll
C:\WINDOWS\system32\yuhvadru.dll
C:\WINDOWS\system32\yxlnmhnh.ini
C:\WINDOWS\system32\yyngywvd.ini
C:\WINDOWS\system32\atioglx.dll . . . . failed to delete
.
---- Previous Run -------
.
C:\WINDOWS\system32\stera.log
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DOMAINSERVICE
-------\Legacy_VSPF
-------\Legacy_VSPF_HK
((((((((((((((((((((((((( Files Created from 2008-07-17 to 2008-08-17 )))))))))))))))))))))))))))))))
.
2008-08-17 12:20 . 2004-10-21 18:59 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-08-17 12:20 . 2004-10-22 14:12 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-08-17 12:20 . 2004-10-21 19:52 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-08-17 12:20 . 2004-10-21 19:52 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-08-17 12:20 . 2004-10-21 18:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-08-17 12:20 . 2008-08-17 12:21 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-15 13:42 . 2008-08-15 13:42 809,192 ---hs---- C:\WINDOWS\system32\ajsjsmbj.tmp
2008-08-15 13:39 . 2008-08-15 13:39 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-15 13:39 . 2008-08-15 13:39 <DIR> d-------- C:\Documents and Settings\HP_Owner\Application Data\Malwarebytes
2008-08-15 13:39 . 2008-08-15 13:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-15 13:39 . 2008-07-30 20:15 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-15 13:39 . 2008-07-30 20:15 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-15 13:18 . 2008-08-15 13:18 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-08 21:29 . 2008-08-08 21:29 <DIR> d-------- C:\Program Files\Gameforge4D
2008-08-08 21:29 . 2004-05-10 13:14 118,272 --a------ C:\WINDOWS\system32\SX5363S.DLL
2008-08-08 21:29 . 2004-05-10 13:14 102,400 --a------ C:\WINDOWS\system32\RV32RTP.dll
2008-08-08 21:29 . 2004-05-10 13:15 40 --a------ C:\WINDOWS\system32\Sx5363.ini
2008-07-26 14:30 . 2008-07-26 14:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-488B9785
2008-07-19 19:48 . 2008-08-15 22:36 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-19 19:48 . 2008-08-13 10:37 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-13 19:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-13 18:30 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-13 17:35 --------- d-----w C:\Program Files\appleitunes
2008-08-12 05:24 --------- d-----w C:\Program Files\TrojanHunter 4.2
2008-08-12 05:22 --------- d-----w C:\Program Files\Java
2008-08-12 05:07 --------- d-----w C:\Program Files\QuickTime
2008-08-08 20:09 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Azureus
2008-08-08 18:41 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\OpenOffice.org2
2008-06-29 22:07 --------- d-----w C:\Program Files\Comprehensive Review 3e
2008-06-29 21:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-01-22 00:32 0 ----a-w C:\Documents and Settings\HP_Owner\loaded.exe
.
Code:
<pre>
----a-w 197,888 2008-03-24 16:47:20 C:\Program Files\Fisher-Price\DACS\MiniApp\DACSMiniApp .exe
----a-w 3,739,648 2008-02-20 05:54:57 C:\Program Files\Google\Google Talk\googletalk .exe
----a-w 158,208 2008-03-24 16:47:21 C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D1F7897-22DA-4C6E-AA15-B4CAD3894438}]
2008-07-19 19:12 101632 --a------ C:\WINDOWS\system32\atioglx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bomgar Support Reconnect []"="C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-488D11CA\bomgar-scc.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 05:00 158208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=oxweul.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Audible Download Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Audible Download Manager.lnk
backup=C:\WINDOWS\pss\Audible Download Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Background Monitor.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=C:\WINDOWS\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkvMon.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkvMon.exe.lnk
backup=C:\WINDOWS\pss\NkvMon.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^VirtuaGirl2.lnk]
path=C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\VirtuaGirl2.lnk
backup=C:\WINDOWS\pss\VirtuaGirl2.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoTBar
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon06
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-07-07 21:19 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2chkdsk]
C:\WINDOWS\system32\ucosbolp.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2004-08-13 20:17 58488 c:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\clc]
C:\WINDOWS\system32\clc.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 05:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 C:\Program Files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DC6_Check]
C:\Program Files\Common Files\WinAntiSpyware 2007 Free\uwasdc.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DllRunning]
C:\WINDOWS\system32\vjxaoakx.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner Free]
C:\Program Files\DriveCleaner Free\UDC.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ErrorSafeFree]
C:\Program Files\ErrorSafe Free\uers.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ERS_Check]
C:\Program Files\Common Files\WinAntiSpyware 2007 Free\uwasers.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPLv3]
C:\WINDOWS\system32\trswynxo.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 1998-05-07 16:04 52736 c:\WINDOWS\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydraVisionDesktopManager]
--a------ 2003-09-15 21:00 270336 C:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2004-08-20 22:55 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InfoData]
C:\WINDOWS\system32\ududiqoc.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
--a------ 2003-11-04 18:36 124096 c:\Program Files\Common Files\Symantec Shared\CfgWiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-04-17 13:41 196608 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-06-28 09:14 270648 C:\Program Files\appleitunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j7241439]
C:\WINDOWS\system32\j7241439.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
--a------ 2003-02-11 20:02 61440 C:\hp\KBD\kbd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\ssttt.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
--a------ 2004-10-14 21:54 253952 c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lswxf]
C:\DOCUME~1\HP_Owner\APPLIC~1\DOBE~1\WACLT~1.EXE [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
c:\Program Files\Norton AntiVirus\CfgWiz.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAS_Check]
C:\Program Files\Common Files\DriveCleaner Free\udcpas.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
--a------ 2002-10-16 16:57 81920 C:\WINDOWS\system32\ps2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-01-31 05:20 180224 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2004-04-14 20:43 233472 C:\WINDOWS\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
--a------ 2003-12-18 00:31 118784 C:\WINDOWS\CREATOR\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDR6_Check]
C:\Program Files\Common Files\DriveCleaner Free\udcsdr.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
C:\WINDOWS\system32\keajmmdf.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seekmo]
c:\program files\seekmo\seekmo.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundService]
C:\WINDOWS\system32\vbcfgqge.dll [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyQuake2.com]
C:\Program Files\SpyQuake2.com\Spy-Quake2.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Srro]
C:\DOCUME~1\HP_Owner\APPLIC~1\CROSOF~1.NET\attrib.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
--a------ 2007-08-21 16:17 111840 C:\PROGRA~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
C:\Program Files\TrojanHunter 4.2\THGuard.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UDC6cw]
C:\Program Files\DriveCleaner Free\UDC6cw.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uwas7cw]
C:\Program Files\WinAntiSpyware 2007 Free\uwas7cw.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\was_check]
C:\Program Files\ErrorSafe Free\PASmon.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiSpyware 2007 Free]
C:\Program Files\WinAntiSpyware 2007 Free\was7.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiVirusPro2006]
C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2005-03-04 12:01 88209 C:\WINDOWS\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 14:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
--------- 2004-09-24 09:49 49152 C:\WINDOWS\system32\SiSPower.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe [N/A]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Program Files\\Opera\\Opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\Program Files\Gameforge4D\AirRivals\Launcher.atm"= C:\Program Files\Gameforge4D\AirRivals\Launcher.atm:Enabled:GameExe2
"C:\Program Files\Gameforge4D\AirRivals\Res-Voip\SCVoIP.exe"= C:\Program Files\Gameforge4D\AirRivals\Res-Voip\SCVoIP.exe:Enabled:GameVoIP
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R0 uillinxo;uillinxo;C:\WINDOWS\system32\drivers\inyzouup.dat []
R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2008-04-24 12:15]
R3 MovRVDrv32;MovRVDrv32;C:\WINDOWS\system32\DRIVERS\MovRVDrv32.sys [2008-04-17 11:57]
R3 SndTDriverV32;SndTDriverV32;C:\WINDOWS\system32\drivers\SndTDriverV32.sys [2008-04-17 11:57]
S2 DP1112;DP1112;C:\WINDOWS\system32\Drivers\DP.sys []
S2 Net message Service;Net message Service;C:\WINDOWS\system32\netmsg.exe []
S2 Windows sharing object;Windows sharing object;C:\WINDOWS\system32\winvercp.exe []
S3 ICDUSB2;Sony IC Recorder (ST);C:\WINDOWS\system32\Drivers\ICDUSB2.sys [2002-11-28 21:23]
S3 mam4410c;mam4410c;C:\WINDOWS\system32\Drivers\mam4410c.sys [2005-06-16 19:11]
S3 mam4410m;mam4410m;C:\WINDOWS\system32\Drivers\mam4410m.sys [2005-06-16 19:13]
S3 mam4410u;mam4410u;C:\WINDOWS\system32\Drivers\mam4410u.sys [2007-03-19 15:39]
S3 SoundMovieServer;SoundMovieServer;C:\WINDOWS\system32\snmvtsvc.exe [2008-04-17 13:30]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\M]
\Shell\AutoRun\command - M:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce9c2e21-ad5c-11db-99e7-0011d866f771}]
\Shell\AutoRun\command - M:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce9c2e22-ad5c-11db-99e7-0011d866f771}]
\Shell\AutoRun\command - browse.bat
.
Contents of the 'Scheduled Tasks' folder
2008-08-14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 13:42]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\jl4m7y77.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/ig?hl=en
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint_03050024.dll
FF -: plugin - C:\Program Files\QuickTime\Plugins\npqtplugin8.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-17 12:36:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uillinxo]
"ImagePath"="system32\drivers\inyzouup.dat"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-08-17 12:49:45 - machine was rebooted [HP_Owner]
ComboFix-quarantined-files.txt 2008-08-17 19:48:41
Pre-Run: 13,210,570,752 bytes free
Post-Run: 12,422,995,968 bytes free
513 --- E O F --- 2008-07-21 05:56:21
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:03:03 PM, on 8/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.igoogle.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {0D1F7897-22DA-4C6E-AA15-B4CAD3894438} - C:\WINDOWS\system32\atioglx.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Bomgar Support Reconnect []] "C:\Documents and Settings\All Users\Application Data\Bomgar-SCC-488D11CA\bomgar-scc.exe" -nomulti
O8 - Extra context menu item: Add to Evernote - res://C:\Program Files\Evernote\Evernote3\enbar.dll/2000
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - C:\Program Files\SoundTaxi\YouTubeRipper.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O20 - AppInit_DLLs: oxweul.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Net message Service - Unknown owner - C:\WINDOWS\system32\netmsg.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMovieServer - SoundMovieServer - C:\WINDOWS\system32\snmvtsvc.exe
O23 - Service: Windows sharing object - Unknown owner - C:\WINDOWS\system32\winvercp.exe (file missing)
--
End of file - 5275 bytes