Combo log
"Daz" - 2007-05-21 23:20:49 Service Pack 1
ComboFix 07-05.21.6.V - Running from: "C:\Documents and Settings\Daz\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\embaemb.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\install.log
C:\WINDOWS\system32\drivers\kalbpeac.sys
C:\WINDOWS\system32\embaemb.dll" . . . . failed to delete
C:\WINDOWS\system32\embaemb.dll.bak" . . . . failed to delete
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_QVYAMELA
-------\LEGACY_TBXNTMQC
-------\qvyamela
-------\tbxntmqc
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-21 ))))))))))))))))))))))))))))))))))
2007-05-12 22:40 8,704 --a------ C:\WINDOWS\system32\CNMVS7F.DLL
2007-05-12 22:40 140,288 --a------ C:\WINDOWS\system32\CNMLM7F.DLL
2007-05-12 22:40 <DIR> d--h----- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
2007-05-09 16:58 <DIR> d-------- C:\Hijackthis
2007-05-09 16:49 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2007-04-22 23:08 <DIR> d-------- C:\Program Files\iTunes
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-15 17:09:10 126,464 ----a-w C:\WINDOWS\system32\sbsrqgof.dll
2007-05-15 17:09:08 79,872 ------w C:\WINDOWS\system32\embaemb.dll
2007-05-04 17:57:35 99,840 ----a-w C:\WINDOWS\system32\hwksvbir.dll
2007-05-04 17:57:31 43,520 ----a-w C:\WINDOWS\system32\tpoextfi.dll
2007-04-22 22:08:32 -------- d-----w C:\Program Files\iPod
2007-04-22 22:06:52 -------- d-----w C:\Program Files\QuickTime
2007-04-22 22:02:21 -------- d-----w C:\Program Files\Apple Software Update
2007-04-17 07:42:08 -------- d-----w C:\Program Files\Windows Live Safety Center
2007-04-16 23:07:12 -------- d-----w C:\DOCUME~1\Daz\APPLIC~1\SpywareBot
2007-04-15 21:00:08 -------- d-----w C:\Program Files\TomTom HOME
2007-04-15 21:00:08 -------- d-----w C:\DOCUME~1\Daz\APPLIC~1\InstallShield
2007-04-11 17:38:31 43,008 ----a-w C:\WINDOWS\system32\tpoextfi(2).dll
2007-04-11 17:38:29 127,488 ----a-w C:\WINDOWS\system32\sbsrqgof(2).dll
2007-04-06 20:04:02 79,872 ----a-w C:\WINDOWS\system32\embaemb(2).dll
2007-03-28 21:05:44 -------- d-----w C:\DOCUME~1\Daz\APPLIC~1\uTorrent
2007-03-09 21:32:10 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-03-09 21:32:10 -------- d-----w C:\Program Files\TRACKER AVL Solutions
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 13:22]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar4.dll [2007-01-20 00:55]
{AE7CD045-E861-484f-8273-0445EE161910}=C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 01:03]
{E1D720DC-3612-8AA5-41B1-FF359B4FAC04}=C:\WINDOWS\system32\msrctlg.dll [2007-01-04 22:15]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-03-05 12:00]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-03-05 12:00]
"SiS Windows KeyHook"="C:\WINDOWS\System32\keyhook.exe" [2004-02-27 04:06]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 19:15]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 19:29]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 13:05]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-03-24 16:56]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32]
"EPSON Stylus C64 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0C2.exe" [2003-09-12 03:00]
"BTUSRBDG"="BtUsrBdg.exe" [2003-04-18 18:15 C:\WINDOWS\system32\BtUsrBdg.exe]
"BTSETBOOTKEY"="BTSetBootKey.exe" [2003-04-15 09:48 C:\WINDOWS\system32\BTSetBootKey.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-01 12:53]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03]
"@"="" []
"PinnacleDriverCheck"="C:\WINDOWS\System32\PSDrvCheck.exe" [2004-03-11 02:26]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 11:48]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe" []
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-02-10 18:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-07 08:50]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 15:13]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"{079F0F93-8BAF-47AD-A4D5-908340B49D16}"="C:\WINDOWS\system32\IEFilter.dll" []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages :\WINDOW
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk
backup=C:\WINDOWS\pss\Bluetooth Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=C:\WINDOWS\pss\Utility Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTSETBOOTKEY]
BTSetBootKey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BTUSRBDG]
BtUsrBdg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"C:\Program Files\D-Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 9.0]
C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowSet]
Wscript.exe //e:VBS C:\Drivers\Setpow.nec
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkypeMate]
C:\Program Files\SkypeMate\SkypeMate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareBot]
C:\Program Files\SpywareBot\SpywareBot.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
"C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"SLService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070521-231828-877
O20 - Winlogon Notify: tpavioim - C:\WINDOWS\SYSTEM32\embaemb.dll
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpavioim]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DLLName"="embaemb.dll"
"Logoff"="WLEventStop"
"Logon"="WLEventStart"
backup-20070521-231828-429
O4 - HKCU\..\Run: [AntiVirusScanv.1.] C:\WINDOWS\AntiVirusScanv.1.3.pif
Contents of the 'Scheduled Tasks' folder
2007-04-22 22:02:24 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2005-02-03 09:43:03 C:\WINDOWS\tasks\Registration reminder 3.job
2007-05-10 02:00:00 C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-21 23:28:59
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001101-0000-1000-8000-00805f9b34fb}]
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]
Completion time: 2007-05-21 23:34:21 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-21 23:34
--- E O F ---
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\embaemb.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\install.log
C:\WINDOWS\system32\drivers\kalbpeac.sys
C:\WINDOWS\system32\embaemb.dll" . . . . failed to delete
C:\WINDOWS\system32\embaemb.dll.bak" . . . . failed to delete
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_QVYAMELA
-------\LEGACY_TBXNTMQC
-------\qvyamela
-------\tbxntmqc
((((((((((((((((((((((((((((((( Files Created from 21/0-01-07 to 21/05/2007 ))))))))))))))))))))))))))))))))))