rutherfordbrave
New member
I have been trying to remove it with several programs. I Just recently ran ComboFix. Here is the log.
Thank You for all your help!!!
ComboFix 08-04-20.5 - David 2008-04-21 16:17:19.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.228 [GMT -6:00]
Running from: C:\Documents and Settings\David\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\David\My Documents\DOBE~1
C:\Documents and Settings\David\My Documents\DOBE~1\?dobe\
C:\Documents and Settings\David\My Documents\DOBE~1\winlogon.exe
C:\Documents and Settings\David\My Documents\SSTEM~1
C:\Documents and Settings\David\My Documents\SSTEM~1\notepad.exe.vir
C:\Documents and Settings\David\My Documents\SSTEM~1\s?stem\
C:\WINDOWS\mcroso~1.net
C:\WINDOWS\mcroso~1.net\?serinit.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aabbdccf.ini
C:\WINDOWS\system32\aabbdccf.ini2
C:\WINDOWS\system32\jbyebiw.dll
C:\WINDOWS\system32\rtvwyxyb.ini
C:\WINDOWS\system32\rtvwyxyb.ini2
C:\WINDOWS\system32\uxyacfii.ini
C:\WINDOWS\system32\uxyacfii.ini2
C:\WINDOWS\system32\xwyxxbay.ini
C:\WINDOWS\system32\xwyxxbay.ini2
C:\WINDOWS\system32\yyxwaccf.ini2
.
((((((((((((((((((((((((( Files Created from 2008-03-21 to 2008-04-21 )))))))))))))))))))))))))))))))
.
2008-04-21 11:39 . 2008-04-21 11:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Webroot
2008-04-19 13:44 . 2008-04-20 11:39 534 ---hs---- C:\WINDOWS\system32\qdihxbdh.ini
2008-04-19 13:32 . 2008-04-19 13:32 34,099 --a------ C:\WINDOWS\system32\cbxxyaxw.dll.vir
2008-04-19 13:01 . 2008-04-19 12:37 275,456 --a------ C:\WINDOWS\system32\pmnnmkll.dll.vir
2008-04-19 13:00 . 2008-04-19 13:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software
2008-04-19 12:58 . 2005-12-13 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-04-19 12:58 . 2005-12-13 20:48 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Gtek
2008-04-19 12:58 . 2008-04-19 12:58 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-19 12:58 . 2008-04-21 16:17 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-19 12:39 . 2008-04-19 12:39 294 ---hs---- C:\WINDOWS\system32\hwooqyyc.ini
2008-04-19 12:38 . 2008-04-21 11:16 109,752 --a------ C:\WINDOWS\BMa7acc3a2.xml
2008-04-19 12:32 . 2008-04-19 12:32 34,099 --a------ C:\WINDOWS\system32\khfdaayx.dll.vir
2008-04-19 11:14 . 2008-04-19 11:14 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache.dsk.vir
2008-04-19 11:12 . 2008-04-19 11:12 86,144 --a------ C:\WINDOWS\system32\drivers\rootmdmm.sys.vir
2008-04-19 11:06 . 2008-04-19 11:08 <DIR> d-------- C:\Program Files\Trojan Remover
2008-04-19 11:06 . 2008-04-19 11:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-04-19 11:06 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-04-19 11:06 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-04-19 11:06 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-04-19 11:06 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-04-19 11:06 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-04-19 11:05 . 2008-04-19 11:05 <DIR> d-------- C:\Documents and Settings\David\Application Data\Simply Super Software
2008-04-19 00:56 . 2008-04-21 16:13 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-19 00:56 . 2008-04-19 00:56 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-19 00:10 . 2008-04-19 00:10 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-19 00:10 . 2008-04-19 00:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-18 23:57 . 2008-04-18 23:57 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-04-18 23:23 . 2008-04-19 00:56 354 ---hs---- C:\WINDOWS\system32\hthcnlwj.ini
2008-04-17 23:20 . 2008-04-17 23:20 294 ---hs---- C:\WINDOWS\system32\xhyhjdno.ini
2008-04-17 22:45 . 2008-04-17 22:45 <DIR> d-------- C:\VundoFix Backups
2008-04-17 19:59 . 2008-04-17 19:59 294 --ahs---- C:\WINDOWS\system32\rhhnxomx.ini
2008-04-17 16:54 . 2008-04-17 16:54 294 --ahs---- C:\WINDOWS\system32\elcsynlg.ini
2008-04-17 14:27 . 2008-04-17 14:27 1,529,129 --ahs---- C:\WINDOWS\system32\ofrnynjw.ini
2008-04-17 13:35 . 2008-04-19 11:09 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-17 13:35 . 2008-04-17 14:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-17 12:12 . 2008-04-17 12:12 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-04-17 12:12 . 2008-01-04 20:34 163,696 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-04-17 12:12 . 2008-01-04 20:34 23,920 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-04-17 12:12 . 2008-01-04 20:34 21,872 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-04-17 12:12 . 2008-01-04 20:34 20,336 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-04-17 12:11 . 2008-04-17 12:11 <DIR> d-------- C:\Program Files\Webroot
2008-04-17 12:11 . 2008-04-17 12:11 <DIR> d-------- C:\Documents and Settings\David\Application Data\Webroot
2008-04-17 12:11 . 2008-04-17 12:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-04-17 12:11 . 2008-01-04 20:56 1,526,640 --a------ C:\WINDOWS\WRSetup.dll
2008-04-17 11:33 . 2008-04-17 11:41 1,529,249 --ahs---- C:\WINDOWS\system32\wpakdgks.ini
2008-04-17 10:45 . 2008-04-17 16:17 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-04-17 10:45 . 2008-04-17 10:45 <DIR> d-------- C:\Documents and Settings\David\Application Data\PC Tools
2008-04-17 10:45 . 2008-04-21 15:58 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-17 10:45 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-17 10:45 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-17 10:45 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-17 10:45 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-16 23:51 . 2008-04-19 12:32 <DIR> d-------- C:\WINDOWS\system32\xcsDd01
2008-04-16 23:51 . 2008-04-17 16:39 <DIR> d-------- C:\WINDOWS\system32\trcTMP
2008-04-16 23:51 . 2008-04-16 23:51 <DIR> d-------- C:\WINDOWS\system32\slNew
2008-04-16 23:51 . 2008-04-16 23:51 <DIR> d-------- C:\WINDOWS\system32\NFi
2008-04-16 23:51 . 2008-04-17 11:24 <DIR> d-------- C:\WINDOWS\system32\iTmp
2008-04-16 23:51 . 2008-04-17 11:24 <DIR> d--hs---- C:\WINDOWS\RGF2aWQ
2008-04-16 23:51 . 2008-04-16 23:51 63,839 --a------ C:\WINDOWS\system32\{4b2e2cb6-f5e2-cf5f-2135-347d0474f070}.dll-uninst.exe
2008-04-16 23:51 . 2008-04-16 23:51 34,099 --a------ C:\WINDOWS\system32\nnnollih.dll.vir
2008-04-04 06:41 . 2008-04-04 06:41 329,216 --a------ C:\WINDOWS\system32\{4b2e2cb6-f5e2-cf5f-2135-347d0474f070}.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 21:33 --------- d-----w C:\Documents and Settings\David\Application Data\AdobeUM
2008-04-16 19:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-15 04:14 --------- d-----w C:\Program Files\Real
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 09:07 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-09-25 21:38 56 --sh--r C:\WINDOWS\system32\1562D2E02C.sys
2007-09-25 21:38 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{406b5831-f44c-ba2c-bb26-a0085176ad72}]
2008-04-04 06:41 329216 --a------ C:\WINDOWS\system32\{4b2e2cb6-f5e2-cf5f-2135-347d0474f070}.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59 385024]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 10:44 249856]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-04-19 11:08 873552]
"AntiSpywareMaster"="C:\Program Files\AntiSpywareMaster\asm.exe" [ ]
"a49ff03e"="rundll32.exe" [2004-08-04 05:00 33280 C:\WINDOWS\system32\rundll32.exe]
"BMa7acc3a2"="Rundll32.exe" [2004-08-04 05:00 33280 C:\WINDOWS\system32\rundll32.exe]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 20:56 5367664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 19:34 5419008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a--c--- 2004-09-13 16:33 155648 C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a--c--- 2005-08-05 21:05 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a--c--- 2005-12-02 07:28 98352 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
--a--c--- 2005-12-13 20:18 61440 c:\dell\bldbubg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
--a--c--- 2005-08-31 11:06 106496 C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a--c--- 2005-09-01 17:24 684032 C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a--c--- 2005-05-15 02:04 332800 C:\Program Files\Dell Support\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
-----c--- 2005-02-23 16:19 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-06-10 10:44 249856 c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a--c--- 2005-06-10 10:44 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a--c--- 2005-09-08 19:20 8192 C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
--a--c--- 2005-09-08 19:20 110592 C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a--c--- 2005-07-12 19:05 1117184 C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2004-04-11 20:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
--a--c--- 2004-11-11 10:26 26112 C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 11:56 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2003-11-19 17:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-02 22:50:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-12-20 15:05:40 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-21 16:20:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-21 16:21:53
ComboFix-quarantined-files.txt 2008-04-21 22:21:14
Pre-Run: 1,110,175,744 bytes free
Post-Run: 1,633,366,016 bytes free
211 --- E O F --- 2008-04-19 17:42:02
Thank You for all your help!!!
ComboFix 08-04-20.5 - David 2008-04-21 16:17:19.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.228 [GMT -6:00]
Running from: C:\Documents and Settings\David\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\David\My Documents\DOBE~1
C:\Documents and Settings\David\My Documents\DOBE~1\?dobe\
C:\Documents and Settings\David\My Documents\DOBE~1\winlogon.exe
C:\Documents and Settings\David\My Documents\SSTEM~1
C:\Documents and Settings\David\My Documents\SSTEM~1\notepad.exe.vir
C:\Documents and Settings\David\My Documents\SSTEM~1\s?stem\
C:\WINDOWS\mcroso~1.net
C:\WINDOWS\mcroso~1.net\?serinit.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aabbdccf.ini
C:\WINDOWS\system32\aabbdccf.ini2
C:\WINDOWS\system32\jbyebiw.dll
C:\WINDOWS\system32\rtvwyxyb.ini
C:\WINDOWS\system32\rtvwyxyb.ini2
C:\WINDOWS\system32\uxyacfii.ini
C:\WINDOWS\system32\uxyacfii.ini2
C:\WINDOWS\system32\xwyxxbay.ini
C:\WINDOWS\system32\xwyxxbay.ini2
C:\WINDOWS\system32\yyxwaccf.ini2
.
((((((((((((((((((((((((( Files Created from 2008-03-21 to 2008-04-21 )))))))))))))))))))))))))))))))
.
2008-04-21 11:39 . 2008-04-21 11:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Webroot
2008-04-19 13:44 . 2008-04-20 11:39 534 ---hs---- C:\WINDOWS\system32\qdihxbdh.ini
2008-04-19 13:32 . 2008-04-19 13:32 34,099 --a------ C:\WINDOWS\system32\cbxxyaxw.dll.vir
2008-04-19 13:01 . 2008-04-19 12:37 275,456 --a------ C:\WINDOWS\system32\pmnnmkll.dll.vir
2008-04-19 13:00 . 2008-04-19 13:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Simply Super Software
2008-04-19 12:58 . 2005-12-13 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-04-19 12:58 . 2005-12-13 20:48 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Gtek
2008-04-19 12:58 . 2008-04-19 12:58 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-19 12:58 . 2008-04-21 16:17 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-19 12:39 . 2008-04-19 12:39 294 ---hs---- C:\WINDOWS\system32\hwooqyyc.ini
2008-04-19 12:38 . 2008-04-21 11:16 109,752 --a------ C:\WINDOWS\BMa7acc3a2.xml
2008-04-19 12:32 . 2008-04-19 12:32 34,099 --a------ C:\WINDOWS\system32\khfdaayx.dll.vir
2008-04-19 11:14 . 2008-04-19 11:14 167,545 --a------ C:\WINDOWS\system32\drivers\core.cache.dsk.vir
2008-04-19 11:12 . 2008-04-19 11:12 86,144 --a------ C:\WINDOWS\system32\drivers\rootmdmm.sys.vir
2008-04-19 11:06 . 2008-04-19 11:08 <DIR> d-------- C:\Program Files\Trojan Remover
2008-04-19 11:06 . 2008-04-19 11:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-04-19 11:06 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-04-19 11:06 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-04-19 11:06 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-04-19 11:06 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-04-19 11:06 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-04-19 11:05 . 2008-04-19 11:05 <DIR> d-------- C:\Documents and Settings\David\Application Data\Simply Super Software
2008-04-19 00:56 . 2008-04-21 16:13 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-19 00:56 . 2008-04-19 00:56 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-19 00:10 . 2008-04-19 00:10 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-19 00:10 . 2008-04-19 00:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-18 23:57 . 2008-04-18 23:57 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-04-18 23:23 . 2008-04-19 00:56 354 ---hs---- C:\WINDOWS\system32\hthcnlwj.ini
2008-04-17 23:20 . 2008-04-17 23:20 294 ---hs---- C:\WINDOWS\system32\xhyhjdno.ini
2008-04-17 22:45 . 2008-04-17 22:45 <DIR> d-------- C:\VundoFix Backups
2008-04-17 19:59 . 2008-04-17 19:59 294 --ahs---- C:\WINDOWS\system32\rhhnxomx.ini
2008-04-17 16:54 . 2008-04-17 16:54 294 --ahs---- C:\WINDOWS\system32\elcsynlg.ini
2008-04-17 14:27 . 2008-04-17 14:27 1,529,129 --ahs---- C:\WINDOWS\system32\ofrnynjw.ini
2008-04-17 13:35 . 2008-04-19 11:09 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-17 13:35 . 2008-04-17 14:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-17 12:12 . 2008-04-17 12:12 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-04-17 12:12 . 2008-01-04 20:34 163,696 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-04-17 12:12 . 2008-01-04 20:34 23,920 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-04-17 12:12 . 2008-01-04 20:34 21,872 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-04-17 12:12 . 2008-01-04 20:34 20,336 --a------ C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-04-17 12:11 . 2008-04-17 12:11 <DIR> d-------- C:\Program Files\Webroot
2008-04-17 12:11 . 2008-04-17 12:11 <DIR> d-------- C:\Documents and Settings\David\Application Data\Webroot
2008-04-17 12:11 . 2008-04-17 12:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-04-17 12:11 . 2008-01-04 20:56 1,526,640 --a------ C:\WINDOWS\WRSetup.dll
2008-04-17 11:33 . 2008-04-17 11:41 1,529,249 --ahs---- C:\WINDOWS\system32\wpakdgks.ini
2008-04-17 10:45 . 2008-04-17 16:17 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-04-17 10:45 . 2008-04-17 10:45 <DIR> d-------- C:\Documents and Settings\David\Application Data\PC Tools
2008-04-17 10:45 . 2008-04-21 15:58 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-17 10:45 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-17 10:45 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-17 10:45 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-17 10:45 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-16 23:51 . 2008-04-19 12:32 <DIR> d-------- C:\WINDOWS\system32\xcsDd01
2008-04-16 23:51 . 2008-04-17 16:39 <DIR> d-------- C:\WINDOWS\system32\trcTMP
2008-04-16 23:51 . 2008-04-16 23:51 <DIR> d-------- C:\WINDOWS\system32\slNew
2008-04-16 23:51 . 2008-04-16 23:51 <DIR> d-------- C:\WINDOWS\system32\NFi
2008-04-16 23:51 . 2008-04-17 11:24 <DIR> d-------- C:\WINDOWS\system32\iTmp
2008-04-16 23:51 . 2008-04-17 11:24 <DIR> d--hs---- C:\WINDOWS\RGF2aWQ
2008-04-16 23:51 . 2008-04-16 23:51 63,839 --a------ C:\WINDOWS\system32\{4b2e2cb6-f5e2-cf5f-2135-347d0474f070}.dll-uninst.exe
2008-04-16 23:51 . 2008-04-16 23:51 34,099 --a------ C:\WINDOWS\system32\nnnollih.dll.vir
2008-04-04 06:41 . 2008-04-04 06:41 329,216 --a------ C:\WINDOWS\system32\{4b2e2cb6-f5e2-cf5f-2135-347d0474f070}.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 21:33 --------- d-----w C:\Documents and Settings\David\Application Data\AdobeUM
2008-04-16 19:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-15 04:14 --------- d-----w C:\Program Files\Real
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 09:07 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-09-25 21:38 56 --sh--r C:\WINDOWS\system32\1562D2E02C.sys
2007-09-25 21:38 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{406b5831-f44c-ba2c-bb26-a0085176ad72}]
2008-04-04 06:41 329216 --a------ C:\WINDOWS\system32\{4b2e2cb6-f5e2-cf5f-2135-347d0474f070}.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59 385024]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 10:44 249856]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-04-19 11:08 873552]
"AntiSpywareMaster"="C:\Program Files\AntiSpywareMaster\asm.exe" [ ]
"a49ff03e"="rundll32.exe" [2004-08-04 05:00 33280 C:\WINDOWS\system32\rundll32.exe]
"BMa7acc3a2"="Rundll32.exe" [2004-08-04 05:00 33280 C:\WINDOWS\system32\rundll32.exe]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 20:56 5367664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 19:34 5419008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a--c--- 2004-09-13 16:33 155648 C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a--c--- 2005-08-05 21:05 344064 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a--c--- 2005-12-02 07:28 98352 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
--a--c--- 2005-12-13 20:18 61440 c:\dell\bldbubg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
--a--c--- 2005-08-31 11:06 106496 C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a--c--- 2005-09-01 17:24 684032 C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a--c--- 2005-05-15 02:04 332800 C:\Program Files\Dell Support\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
-----c--- 2005-02-23 16:19 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-06-10 10:44 249856 c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a--c--- 2005-06-10 10:44 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-12-11 13:10 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
--a--c--- 2005-09-08 19:20 8192 C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
--a--c--- 2005-09-08 19:20 110592 C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a--c--- 2005-07-12 19:05 1117184 C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
-----c--- 2004-04-11 20:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
--a--c--- 2004-11-11 10:26 26112 C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 11:56 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2003-11-19 17:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-02 22:50:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-12-20 15:05:40 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-21 16:20:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-21 16:21:53
ComboFix-quarantined-files.txt 2008-04-21 22:21:14
Pre-Run: 1,110,175,744 bytes free
Post-Run: 1,633,366,016 bytes free
211 --- E O F --- 2008-04-19 17:42:02