Hi Blade81, Sorry for taking so long. Took awhile to download Kaspersky. After I done that Combo Fix I was able to write that missing file. It's fdsv-cb.
Also on that Registry search tool it didn't find either file. Hope this is all right.
ComboFix 08-05-11.1 - amy 2008-05-11 13:25:23.4 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.100 [GMT -6:00]
Running from: C:\Documents and Settings\amy\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\amy\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
.
2008-05-10 13:07 . 2008-05-10 13:07 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-05-10 10:23 . 2002-08-29 04:41 110,080 --------- C:\WINDOWS\system32\sbeio.dll
2008-05-10 10:22 . 2002-08-29 04:41 218,112 --------- C:\WINDOWS\system32\sbe.dll
2008-05-10 10:22 . 2002-08-29 04:41 200,192 -ra------ C:\WINDOWS\system32\termsrv.dll
2008-05-10 10:22 . 2002-08-29 04:41 71,168 --a------ C:\WINDOWS\system32\telnet.exe
2008-05-10 10:21 . 2002-08-29 04:41 233,984 --a------ C:\WINDOWS\system32\tapisrv.dll
2008-05-10 10:21 . 2002-08-29 04:41 165,376 --a------ C:\WINDOWS\system32\tapi32.dll
2008-05-10 10:21 . 2002-08-29 04:41 128,512 --a------ C:\WINDOWS\system32\taskmgr.exe
2008-05-10 10:20 . 2002-08-29 04:41 172,032 --------- C:\WINDOWS\system32\mssap.dll
2008-05-10 10:20 . 2002-08-29 02:28 11,904 --------- C:\WINDOWS\system32\drivers\mutohpen.sys
2008-05-10 10:19 . 2002-08-29 04:39 205,312 --a------ C:\WINDOWS\system32\sysmon.ocx
2008-05-10 10:19 . 2002-08-29 02:11 162,304 --------- C:\WINDOWS\system32\msctfime.ime
2008-05-10 10:18 . 2002-08-29 04:41 674,816 --a------ C:\WINDOWS\system32\sxs.dll
2008-05-10 10:18 . 2002-08-29 04:41 638,976 --a------ C:\WINDOWS\system32\sstext3d.scr
2008-05-10 10:18 . 2002-08-29 04:41 251,904 --a------ C:\WINDOWS\system32\strmdll.dll
2008-05-10 10:18 . 2002-08-29 04:40 155,648 --------- C:\WINDOWS\system32\encdec.dll
2008-05-10 10:18 . 2002-08-29 04:41 130,560 --a------ C:\WINDOWS\system32\sti_ci.dll
2008-05-10 10:18 . 2002-08-29 04:41 117,760 --a------ C:\WINDOWS\system32\stobject.dll
2008-05-10 10:18 . 2002-08-29 04:41 71,168 --a------ C:\WINDOWS\system32\storprop.dll
2008-05-10 10:18 . 2002-08-29 04:41 61,952 --a------ C:\WINDOWS\system32\sti.dll
2008-05-10 10:18 . 2002-08-29 04:41 18,944 --------- C:\WINDOWS\system32\faxpatch.exe
2008-05-10 10:18 . 2002-08-29 02:32 6,912 --------- C:\WINDOWS\system32\drivers\hidir.sys
2008-05-10 10:17 . 2002-04-19 19:20 66,082 --------- C:\WINDOWS\system32\c_28603.nls
2008-05-10 10:17 . 2002-08-29 00:16 63,663 --------- C:\WINDOWS\system32\drivers\atinrvxx.sys
2008-05-10 10:17 . 2002-08-29 00:16 36,463 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2008-05-10 10:17 . 2002-08-29 00:16 34,735 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2008-05-10 10:17 . 2002-08-29 04:41 31,263 --------- C:\WINDOWS\system32\ativmvxx.ax
2008-05-10 10:17 . 2002-08-29 00:16 29,455 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys
2008-05-10 10:17 . 2002-08-29 00:16 26,367 --------- C:\WINDOWS\system32\drivers\atinsnxx.sys
2008-05-10 10:17 . 2002-08-29 00:16 21,343 --------- C:\WINDOWS\system32\drivers\atinttxx.sys
2008-05-10 10:17 . 2002-08-29 04:41 12,831 --------- C:\WINDOWS\system32\ativdaxx.ax
2008-05-10 10:17 . 2002-08-29 02:14 3,584 --------- C:\WINDOWS\system32\dsprpres.dll
2008-05-10 10:16 . 2002-08-29 04:40 921,475 --------- C:\WINDOWS\system32\ati3d2ag.dll
2008-05-10 10:16 . 2002-08-29 04:41 569,344 --a------ C:\WINDOWS\system32\sspipes.scr
2008-05-10 10:16 . 2002-08-29 00:16 56,591 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2008-05-10 10:16 . 2002-08-29 00:16 30,671 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2008-05-10 10:16 . 2002-08-29 04:41 13,312 --a------ C:\WINDOWS\system32\ssstars.scr
2008-05-10 10:16 . 2002-08-29 00:16 12,047 --------- C:\WINDOWS\system32\drivers\atinpdxx.sys
2008-05-10 10:16 . 2002-08-29 00:16 11,615 --------- C:\WINDOWS\system32\drivers\atinmdxx.sys
2008-05-10 10:15 . 2002-08-29 04:41 364,544 --a------ C:\WINDOWS\system32\ssflwbox.scr
2008-05-10 10:15 . 2002-08-29 04:41 19,456 --a------ C:\WINDOWS\system32\ssmarque.scr
2008-05-10 10:15 . 2002-08-29 04:41 17,408 --a------ C:\WINDOWS\system32\ssmyst.scr
2008-05-10 10:14 . 2002-08-29 04:40 844,675 --------- C:\WINDOWS\system32\ati3d1ag.dll
2008-05-10 10:14 . 2002-08-29 04:41 667,648 --a------ C:\WINDOWS\system32\ss3dfo.scr
2008-05-10 10:14 . 2002-08-29 04:41 43,008 --a------ C:\WINDOWS\system32\ssdpsrv.dll
2008-05-10 10:14 . 2002-08-29 04:41 27,136 --a------ C:\WINDOWS\system32\ssdpapi.dll
2008-05-10 10:14 . 2002-08-29 04:41 18,944 --a------ C:\WINDOWS\system32\ssbezier.scr
2008-05-10 10:12 . 2002-08-29 00:16 450,176 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-05-10 10:12 . 2002-08-29 04:41 158,720 --a------ C:\WINDOWS\system32\srsvc.dll
2008-05-10 10:11 . 2002-08-29 00:16 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-05-10 10:11 . 2002-08-29 04:41 226,304 --a------ C:\WINDOWS\system32\srrstr.dll
2008-05-10 10:11 . 2002-08-29 04:41 63,488 --a------ C:\WINDOWS\system32\srclient.dll
2008-05-10 10:09 . 2002-08-29 04:41 420,864 --a------ C:\WINDOWS\system32\shimgvw.dll
2008-05-10 10:09 . 2002-08-29 04:41 62,976 --a------ C:\WINDOWS\system32\shgina.dll
2008-05-10 10:09 . 2002-08-29 04:41 60,416 --a------ C:\WINDOWS\system32\shimeng.dll
2008-05-10 10:09 . 2002-08-29 04:41 22,528 --a------ C:\WINDOWS\system32\shfolder.dll
2008-05-10 10:08 . 2002-04-15 22:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-05-10 10:07 . 2002-08-29 04:41 1,622,528 --a------ C:\WINDOWS\system32\netshell.dll
2008-05-10 10:07 . 2002-08-29 04:48 326,656 --a------ C:\WINDOWS\system32\netsetup.exe
2008-05-10 10:06 . 2002-08-29 04:41 857,600 --a------ C:\WINDOWS\system32\netplwiz.dll
2008-05-10 10:06 . 2002-08-29 04:41 584,192 --a------ C:\WINDOWS\system32\netcfgx.dll
2008-05-10 10:06 . 2002-08-29 04:41 399,360 --a------ C:\WINDOWS\system32\netlogon.dll
2008-05-10 10:06 . 2002-08-29 04:41 154,112 --a------ C:\WINDOWS\system32\netman.dll
2008-05-10 10:06 . 2002-08-29 04:41 105,984 --a------ C:\WINDOWS\system32\netdde.exe
2008-05-10 10:05 . 2002-08-29 04:41 1,122,304 --a------ C:\WINDOWS\system32\msxml3.dll
2008-05-10 10:05 . 2002-08-29 04:41 115,200 --a------ C:\WINDOWS\system32\net1.exe
2008-05-10 10:05 . 2002-08-29 04:41 42,496 --a------ C:\WINDOWS\system32\ncobjapi.dll
2008-05-10 10:05 . 2002-08-29 04:41 39,424 --a------ C:\WINDOWS\system32\net.exe
2008-05-10 10:05 . 2002-08-29 04:41 16,384 --a------ C:\WINDOWS\system32\nddenb32.dll
2008-05-10 10:04 . 2002-08-29 04:41 699,392 --a------ C:\WINDOWS\system32\msxml2.dll
2008-05-10 10:03 . 2002-08-29 04:41 344,095 --a------ C:\WINDOWS\system32\msxbde40.dll
2008-05-10 10:00 . 2002-08-29 02:40 598,016 --a------ C:\WINDOWS\system32\mstscax.dll
2008-05-10 10:00 . 2002-08-29 04:41 401,462 --a------ C:\WINDOWS\system32\msvcp60.dll
2008-05-10 10:00 . 2002-08-29 02:40 388,608 --a------ C:\WINDOWS\system32\mstsc.exe
2008-05-10 10:00 . 2002-08-29 04:41 323,072 --a------ C:\WINDOWS\system32\msvcrt.dll
2008-05-10 10:00 . 2002-08-29 04:41 241,725 --a------ C:\WINDOWS\system32\msuni11.dll
2008-05-10 10:00 . 2002-08-29 04:41 182,784 --a------ C:\WINDOWS\system32\msutb.dll
2008-05-10 10:00 . 2002-08-29 04:41 113,664 --a------ C:\WINDOWS\system32\msvfw32.dll
2008-05-10 10:00 . 2002-08-29 04:41 9,728 --a------ C:\WINDOWS\system32\mstinit.exe
2008-05-10 09:59 . 2002-08-29 04:41 552,991 --a------ C:\WINDOWS\system32\msrepl40.dll
2008-05-10 09:59 . 2002-08-29 04:41 253,983 --a------ C:\WINDOWS\system32\mstext40.dll
2008-05-10 09:59 . 2002-08-29 04:41 250,368 --a------ C:\WINDOWS\system32\mstask.dll
2008-05-10 09:59 . 2002-08-29 04:41 245,760 --a------ C:\WINDOWS\system32\msscp.dll
2008-05-10 09:59 . 2002-08-29 04:39 106,547 --a------ C:\WINDOWS\system32\msscript.ocx
2008-05-10 09:59 . 2002-08-29 04:41 69,632 --a------ C:\WINDOWS\system32\msscds32.ax
2008-05-10 09:59 . 2002-08-29 04:41 10,240 --a------ C:\WINDOWS\system32\msrle32.dll
2008-05-10 09:54 . 2002-08-29 04:41 159,232 --a------ C:\WINDOWS\system32\schedsvc.dll
2008-05-10 09:54 . 2002-08-29 04:41 71,168 --a------ C:\WINDOWS\system32\sdbinst.exe
2008-05-10 09:54 . 2002-08-29 04:41 52,224 --a------ C:\WINDOWS\system32\secur32.dll
2008-05-10 09:54 . 2002-08-29 04:41 36,352 --a------ C:\WINDOWS\system32\sens.dll
2008-05-10 09:54 . 2002-08-29 04:41 20,992 --a------ C:\WINDOWS\system32\setup.exe
2008-05-10 09:54 . 2002-08-29 04:41 8,192 --a------ C:\WINDOWS\system32\scrnsave.scr
2008-05-10 09:54 . 2002-08-29 04:41 6,144 --a------ C:\WINDOWS\system32\sensapi.dll
2008-05-10 09:53 . 2002-08-29 04:41 548,864 --a------ C:\WINDOWS\system32\rtcdll.dll
2008-05-10 09:53 . 2002-08-29 04:41 530,432 --a------ C:\WINDOWS\system32\rpcrt4.dll
2008-05-10 09:53 . 2002-08-29 04:41 297,984 --a------ C:\WINDOWS\system32\scesrv.dll
2008-05-10 09:53 . 2002-08-29 04:41 260,608 --a------ C:\WINDOWS\system32\rpcss.dll
2008-05-10 09:53 . 2002-08-29 04:41 174,592 --a------ C:\WINDOWS\system32\scecli.dll
2008-05-10 09:53 . 2002-08-29 04:41 171,008 --a------ C:\WINDOWS\system32\sccsccp.dll
2008-05-10 09:53 . 2002-08-28 23:27 169,984 --a------ C:\WINDOWS\system32\sccbase.dll
2008-05-10 09:53 . 2002-08-28 23:27 133,632 --a------ C:\WINDOWS\system32\rsaenh.dll
2008-05-10 09:53 . 2002-08-29 04:41 74,240 --a------ C:\WINDOWS\system32\rtcshare.exe
2008-05-10 09:53 . 2002-08-29 04:41 12,800 --a------ C:\WINDOWS\system32\runonce.exe
2008-05-10 09:51 . 2002-08-29 04:41 1,349,120 --a------ C:\WINDOWS\system32\query.dll
2008-05-10 09:51 . 2002-08-29 04:41 264,704 --a------ C:\WINDOWS\system32\wzcsvc.dll
2008-05-10 09:51 . 2002-07-16 19:55 172,664 --a------ C:\WINDOWS\system32\xenroll.dll
2008-05-10 09:51 . 2002-08-29 04:41 86,016 --a------ C:\WINDOWS\system32\xactsrv.dll
2008-05-10 09:51 . 2002-08-29 04:41 56,832 --a------ C:\WINDOWS\system32\wzcdlg.dll
2008-05-10 09:51 . 2002-08-29 04:41 23,552 --a------ C:\WINDOWS\system32\wzcsapi.dll
2008-05-10 09:51 . 2002-08-29 04:41 9,216 --a------ C:\WINDOWS\system32\wuauserv.dll
2008-05-10 09:50 . 2002-08-29 04:41 446,464 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2008-05-10 09:50 . 2002-08-29 04:41 258,048 --a------ C:\WINDOWS\system32\wmvds32.ax
2008-05-10 09:50 . 2002-08-29 04:41 247,808 --a------ C:\WINDOWS\system32\wow32.dll
2008-05-10 09:50 . 2002-08-29 04:41 38,912 --a------ C:\WINDOWS\system32\wsnmp32.dll
2008-05-10 09:50 . 2002-08-29 04:41 17,408 --a------ C:\WINDOWS\system32\wtsapi32.dll
2008-05-10 09:50 . 2002-08-29 04:41 13,312 --a------ C:\WINDOWS\system32\wship6.dll
2008-05-10 09:47 . 2002-08-29 04:39 1,998,848 --a------ C:\WINDOWS\system32\wmploc.dll
2008-05-10 09:47 . 2002-08-29 04:41 1,404,928 --a------ C:\WINDOWS\system32\wmpui.dll
2008-05-10 09:47 . 2002-08-29 04:41 1,298,432 --a------ C:\WINDOWS\system32\wmpcore.dll
2008-05-10 09:47 . 2002-08-29 04:41 311,327 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-05-10 09:47 . 2002-08-29 04:41 296,448 --a------ C:\WINDOWS\system32\wmstream.dll
2008-05-10 09:47 . 2002-08-29 04:41 278,559 --a------ C:\WINDOWS\system32\wmv8ds32.ax
2008-05-10 09:47 . 2002-08-29 04:41 118,784 --a------ C:\WINDOWS\system32\wmsdmoe.dll
2008-05-10 09:47 . 2002-08-29 04:41 77,824 --a------ C:\WINDOWS\system32\wmpstub.exe
2008-05-10 09:47 . 2002-08-29 04:41 77,824 --a------ C:\WINDOWS\system32\wmpshell.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-01 23:47 756,387 ----a-w C:\Program Files\INSTALL.LOG
2008-04-27 10:25 89,088 --sh--r C:\WINDOWS\AppPatch\wuaclt.exe
2008-02-27 10:05 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-29 04:41 1511453]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2008-04-20 05:18 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-24 20:17 98304]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-02-10 11:55 155648]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 11:18 49152]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-10 11:51 118784]
"DXM6Patch_981116"="C:\WINDOWS\p_981116.exe" [1998-11-30 18:04 497376]
"HelpCenter4.1"="C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 19:02 198184]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
iZone Monitor.lnk - C:\Program Files\ArcSoft\Polaroid iZone PhotoBase\iZone Monitor.exe [2007-11-01 17:01:14 184320]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.NSVI"= NSVIDEO.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FastAccess Help]
--a------ 2007-10-03 08:19 108421 C:\Program Files\BellSouth Application Management\content\..\Start.exe
R2 McciCMService;McciCMService;"C:\Program Files\Common Files\Motive\McciCMService.exe" [2008-01-28 14:56]
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-08-17 22:36]
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\System32\DRIVERS\ptserlp.sys [2001-08-17 13:28]
S2 Ca536av;FashionCam Video Camera Device;C:\WINDOWS\System32\Drivers\Ca536av.sys [2004-06-29 21:21]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;C:\WINDOWS\System32\DRIVERS\mr97310v.sys [2004-03-30 11:29]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-01-19 11:53]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-01-19 11:53]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 USBCamera;FashionCam Digital Still Camera Device;C:\WINDOWS\System32\Drivers\Bulk536.sys [2003-05-14 23:28]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-01 23:46:40 C:\WINDOWS\Tasks\System Restore.job"
- C:\WINDOWS\system32\Restore\rstrui.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-11 13:26:31
Windows 5.1.2600 Service Pack 1 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-11 13:26:56
ComboFix-quarantined-files.txt 2008-05-11 19:26:56
ComboFix4.txt 2008-05-09 18:21:18
ComboFix3.txt 2008-05-10 07:12:28
ComboFix2.txt 2008-05-11 19:17:52
Pre-Run: 19,790,200,832 bytes free
Post-Run: 19,793,215,488 bytes free
204
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 13, 2008 1:18:14 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 12/05/2008
Kaspersky Anti-Virus database records: 765113
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 39835
Number of viruses found: 18
Number of infected objects: 31
Number of suspicious objects: 10
Duration of the scan process: 00:45:02
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\AppPatch\wuaclt.exe Infected: Trojan-Downloader.Win32.Agent.kwg skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\ModemLog_HSP56 Micromodem.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader3.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader4.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader9.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader9.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader11.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader11.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader13.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader13.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\amy\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\amy\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\amy\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\amy\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\amy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\amy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\amy\Local Settings\Application Data\SupportSoft\HelpCenter4.1\amy\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\amy\Local Settings\temp\abm3.tmp Object is locked skipped
C:\Documents and Settings\amy\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\amy\Application Data\AT&T\Internet Security Wizard\client_gateway.log Object is locked skipped
C:\Documents and Settings\amy\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.98866 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0024020.old Infected: Trojan-Downloader.Win32.Agent.nua skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029120.exe Infected: not-a-virus:FraudTool.Win32.XPAntivirus.da skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029125.exe Infected: Trojan-Downloader.Win32.PurityScan.gb skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029126.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029126.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029129.DLL Infected: Trojan.Win32.Monder.cy skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029130.DLL Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029131.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0030207.dll Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0030237.dll Infected: Trojan.Win32.Monder.dc skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0030239.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qvb skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0030240.dll Infected: Trojan.Win32.Monder.dd skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0031424.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0031426.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0031427.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0031428.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0040867.exe Infected: Trojan.Win32.Agent.lke skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP92\A0041108.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP92\A0041108.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP92\A0041108.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP94\A0044227.sys Infected: Rootkit.Win32.Agent.aii skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP97\change.log Object is locked skipped
C:\PeoplePC98XP\Utilities\ppal3ppc.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.ac skipped
C:\PeoplePC98XP\Utilities\ppal3ppc.exe NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\WNSXS~1\сѕrss.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.hl skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\clbdriver.sys.vir Infected: Rootkit.Win32.Agent.aii skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\default.htm.vir Infected: not-virus:Hoax.HTML.Secureinvites.b skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\g37.exe.vir/stream/data0002 Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\g37.exe.vir/stream Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\g37.exe.vir NSIS: infected - 2 skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:29:57 AM, on 5/13/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ArcSoft\Polaroid iZone PhotoBase\iZone Monitor.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.spybot.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: iZone Monitor.lnk = C:\Program Files\ArcSoft\Polaroid iZone PhotoBase\iZone Monitor.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.forums.spybot.info
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C3B48A7-1C39-43AD-9D30-353181A238A5}: NameServer = 207.69.188.187 207.69.188.186
O17 - HKLM\System\CS1\Services\Tcpip\..\{3C3B48A7-1C39-43AD-9D30-353181A238A5}: NameServer = 207.69.188.187 207.69.188.186
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 4091 bytes
Also on that Registry search tool it didn't find either file. Hope this is all right.
ComboFix 08-05-11.1 - amy 2008-05-11 13:25:23.4 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.100 [GMT -6:00]
Running from: C:\Documents and Settings\amy\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\amy\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
.
2008-05-10 13:07 . 2008-05-10 13:07 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-05-10 10:23 . 2002-08-29 04:41 110,080 --------- C:\WINDOWS\system32\sbeio.dll
2008-05-10 10:22 . 2002-08-29 04:41 218,112 --------- C:\WINDOWS\system32\sbe.dll
2008-05-10 10:22 . 2002-08-29 04:41 200,192 -ra------ C:\WINDOWS\system32\termsrv.dll
2008-05-10 10:22 . 2002-08-29 04:41 71,168 --a------ C:\WINDOWS\system32\telnet.exe
2008-05-10 10:21 . 2002-08-29 04:41 233,984 --a------ C:\WINDOWS\system32\tapisrv.dll
2008-05-10 10:21 . 2002-08-29 04:41 165,376 --a------ C:\WINDOWS\system32\tapi32.dll
2008-05-10 10:21 . 2002-08-29 04:41 128,512 --a------ C:\WINDOWS\system32\taskmgr.exe
2008-05-10 10:20 . 2002-08-29 04:41 172,032 --------- C:\WINDOWS\system32\mssap.dll
2008-05-10 10:20 . 2002-08-29 02:28 11,904 --------- C:\WINDOWS\system32\drivers\mutohpen.sys
2008-05-10 10:19 . 2002-08-29 04:39 205,312 --a------ C:\WINDOWS\system32\sysmon.ocx
2008-05-10 10:19 . 2002-08-29 02:11 162,304 --------- C:\WINDOWS\system32\msctfime.ime
2008-05-10 10:18 . 2002-08-29 04:41 674,816 --a------ C:\WINDOWS\system32\sxs.dll
2008-05-10 10:18 . 2002-08-29 04:41 638,976 --a------ C:\WINDOWS\system32\sstext3d.scr
2008-05-10 10:18 . 2002-08-29 04:41 251,904 --a------ C:\WINDOWS\system32\strmdll.dll
2008-05-10 10:18 . 2002-08-29 04:40 155,648 --------- C:\WINDOWS\system32\encdec.dll
2008-05-10 10:18 . 2002-08-29 04:41 130,560 --a------ C:\WINDOWS\system32\sti_ci.dll
2008-05-10 10:18 . 2002-08-29 04:41 117,760 --a------ C:\WINDOWS\system32\stobject.dll
2008-05-10 10:18 . 2002-08-29 04:41 71,168 --a------ C:\WINDOWS\system32\storprop.dll
2008-05-10 10:18 . 2002-08-29 04:41 61,952 --a------ C:\WINDOWS\system32\sti.dll
2008-05-10 10:18 . 2002-08-29 04:41 18,944 --------- C:\WINDOWS\system32\faxpatch.exe
2008-05-10 10:18 . 2002-08-29 02:32 6,912 --------- C:\WINDOWS\system32\drivers\hidir.sys
2008-05-10 10:17 . 2002-04-19 19:20 66,082 --------- C:\WINDOWS\system32\c_28603.nls
2008-05-10 10:17 . 2002-08-29 00:16 63,663 --------- C:\WINDOWS\system32\drivers\atinrvxx.sys
2008-05-10 10:17 . 2002-08-29 00:16 36,463 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2008-05-10 10:17 . 2002-08-29 00:16 34,735 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2008-05-10 10:17 . 2002-08-29 04:41 31,263 --------- C:\WINDOWS\system32\ativmvxx.ax
2008-05-10 10:17 . 2002-08-29 00:16 29,455 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys
2008-05-10 10:17 . 2002-08-29 00:16 26,367 --------- C:\WINDOWS\system32\drivers\atinsnxx.sys
2008-05-10 10:17 . 2002-08-29 00:16 21,343 --------- C:\WINDOWS\system32\drivers\atinttxx.sys
2008-05-10 10:17 . 2002-08-29 04:41 12,831 --------- C:\WINDOWS\system32\ativdaxx.ax
2008-05-10 10:17 . 2002-08-29 02:14 3,584 --------- C:\WINDOWS\system32\dsprpres.dll
2008-05-10 10:16 . 2002-08-29 04:40 921,475 --------- C:\WINDOWS\system32\ati3d2ag.dll
2008-05-10 10:16 . 2002-08-29 04:41 569,344 --a------ C:\WINDOWS\system32\sspipes.scr
2008-05-10 10:16 . 2002-08-29 00:16 56,591 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2008-05-10 10:16 . 2002-08-29 00:16 30,671 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2008-05-10 10:16 . 2002-08-29 04:41 13,312 --a------ C:\WINDOWS\system32\ssstars.scr
2008-05-10 10:16 . 2002-08-29 00:16 12,047 --------- C:\WINDOWS\system32\drivers\atinpdxx.sys
2008-05-10 10:16 . 2002-08-29 00:16 11,615 --------- C:\WINDOWS\system32\drivers\atinmdxx.sys
2008-05-10 10:15 . 2002-08-29 04:41 364,544 --a------ C:\WINDOWS\system32\ssflwbox.scr
2008-05-10 10:15 . 2002-08-29 04:41 19,456 --a------ C:\WINDOWS\system32\ssmarque.scr
2008-05-10 10:15 . 2002-08-29 04:41 17,408 --a------ C:\WINDOWS\system32\ssmyst.scr
2008-05-10 10:14 . 2002-08-29 04:40 844,675 --------- C:\WINDOWS\system32\ati3d1ag.dll
2008-05-10 10:14 . 2002-08-29 04:41 667,648 --a------ C:\WINDOWS\system32\ss3dfo.scr
2008-05-10 10:14 . 2002-08-29 04:41 43,008 --a------ C:\WINDOWS\system32\ssdpsrv.dll
2008-05-10 10:14 . 2002-08-29 04:41 27,136 --a------ C:\WINDOWS\system32\ssdpapi.dll
2008-05-10 10:14 . 2002-08-29 04:41 18,944 --a------ C:\WINDOWS\system32\ssbezier.scr
2008-05-10 10:12 . 2002-08-29 00:16 450,176 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-05-10 10:12 . 2002-08-29 04:41 158,720 --a------ C:\WINDOWS\system32\srsvc.dll
2008-05-10 10:11 . 2002-08-29 00:16 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-05-10 10:11 . 2002-08-29 04:41 226,304 --a------ C:\WINDOWS\system32\srrstr.dll
2008-05-10 10:11 . 2002-08-29 04:41 63,488 --a------ C:\WINDOWS\system32\srclient.dll
2008-05-10 10:09 . 2002-08-29 04:41 420,864 --a------ C:\WINDOWS\system32\shimgvw.dll
2008-05-10 10:09 . 2002-08-29 04:41 62,976 --a------ C:\WINDOWS\system32\shgina.dll
2008-05-10 10:09 . 2002-08-29 04:41 60,416 --a------ C:\WINDOWS\system32\shimeng.dll
2008-05-10 10:09 . 2002-08-29 04:41 22,528 --a------ C:\WINDOWS\system32\shfolder.dll
2008-05-10 10:08 . 2002-04-15 22:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-05-10 10:07 . 2002-08-29 04:41 1,622,528 --a------ C:\WINDOWS\system32\netshell.dll
2008-05-10 10:07 . 2002-08-29 04:48 326,656 --a------ C:\WINDOWS\system32\netsetup.exe
2008-05-10 10:06 . 2002-08-29 04:41 857,600 --a------ C:\WINDOWS\system32\netplwiz.dll
2008-05-10 10:06 . 2002-08-29 04:41 584,192 --a------ C:\WINDOWS\system32\netcfgx.dll
2008-05-10 10:06 . 2002-08-29 04:41 399,360 --a------ C:\WINDOWS\system32\netlogon.dll
2008-05-10 10:06 . 2002-08-29 04:41 154,112 --a------ C:\WINDOWS\system32\netman.dll
2008-05-10 10:06 . 2002-08-29 04:41 105,984 --a------ C:\WINDOWS\system32\netdde.exe
2008-05-10 10:05 . 2002-08-29 04:41 1,122,304 --a------ C:\WINDOWS\system32\msxml3.dll
2008-05-10 10:05 . 2002-08-29 04:41 115,200 --a------ C:\WINDOWS\system32\net1.exe
2008-05-10 10:05 . 2002-08-29 04:41 42,496 --a------ C:\WINDOWS\system32\ncobjapi.dll
2008-05-10 10:05 . 2002-08-29 04:41 39,424 --a------ C:\WINDOWS\system32\net.exe
2008-05-10 10:05 . 2002-08-29 04:41 16,384 --a------ C:\WINDOWS\system32\nddenb32.dll
2008-05-10 10:04 . 2002-08-29 04:41 699,392 --a------ C:\WINDOWS\system32\msxml2.dll
2008-05-10 10:03 . 2002-08-29 04:41 344,095 --a------ C:\WINDOWS\system32\msxbde40.dll
2008-05-10 10:00 . 2002-08-29 02:40 598,016 --a------ C:\WINDOWS\system32\mstscax.dll
2008-05-10 10:00 . 2002-08-29 04:41 401,462 --a------ C:\WINDOWS\system32\msvcp60.dll
2008-05-10 10:00 . 2002-08-29 02:40 388,608 --a------ C:\WINDOWS\system32\mstsc.exe
2008-05-10 10:00 . 2002-08-29 04:41 323,072 --a------ C:\WINDOWS\system32\msvcrt.dll
2008-05-10 10:00 . 2002-08-29 04:41 241,725 --a------ C:\WINDOWS\system32\msuni11.dll
2008-05-10 10:00 . 2002-08-29 04:41 182,784 --a------ C:\WINDOWS\system32\msutb.dll
2008-05-10 10:00 . 2002-08-29 04:41 113,664 --a------ C:\WINDOWS\system32\msvfw32.dll
2008-05-10 10:00 . 2002-08-29 04:41 9,728 --a------ C:\WINDOWS\system32\mstinit.exe
2008-05-10 09:59 . 2002-08-29 04:41 552,991 --a------ C:\WINDOWS\system32\msrepl40.dll
2008-05-10 09:59 . 2002-08-29 04:41 253,983 --a------ C:\WINDOWS\system32\mstext40.dll
2008-05-10 09:59 . 2002-08-29 04:41 250,368 --a------ C:\WINDOWS\system32\mstask.dll
2008-05-10 09:59 . 2002-08-29 04:41 245,760 --a------ C:\WINDOWS\system32\msscp.dll
2008-05-10 09:59 . 2002-08-29 04:39 106,547 --a------ C:\WINDOWS\system32\msscript.ocx
2008-05-10 09:59 . 2002-08-29 04:41 69,632 --a------ C:\WINDOWS\system32\msscds32.ax
2008-05-10 09:59 . 2002-08-29 04:41 10,240 --a------ C:\WINDOWS\system32\msrle32.dll
2008-05-10 09:54 . 2002-08-29 04:41 159,232 --a------ C:\WINDOWS\system32\schedsvc.dll
2008-05-10 09:54 . 2002-08-29 04:41 71,168 --a------ C:\WINDOWS\system32\sdbinst.exe
2008-05-10 09:54 . 2002-08-29 04:41 52,224 --a------ C:\WINDOWS\system32\secur32.dll
2008-05-10 09:54 . 2002-08-29 04:41 36,352 --a------ C:\WINDOWS\system32\sens.dll
2008-05-10 09:54 . 2002-08-29 04:41 20,992 --a------ C:\WINDOWS\system32\setup.exe
2008-05-10 09:54 . 2002-08-29 04:41 8,192 --a------ C:\WINDOWS\system32\scrnsave.scr
2008-05-10 09:54 . 2002-08-29 04:41 6,144 --a------ C:\WINDOWS\system32\sensapi.dll
2008-05-10 09:53 . 2002-08-29 04:41 548,864 --a------ C:\WINDOWS\system32\rtcdll.dll
2008-05-10 09:53 . 2002-08-29 04:41 530,432 --a------ C:\WINDOWS\system32\rpcrt4.dll
2008-05-10 09:53 . 2002-08-29 04:41 297,984 --a------ C:\WINDOWS\system32\scesrv.dll
2008-05-10 09:53 . 2002-08-29 04:41 260,608 --a------ C:\WINDOWS\system32\rpcss.dll
2008-05-10 09:53 . 2002-08-29 04:41 174,592 --a------ C:\WINDOWS\system32\scecli.dll
2008-05-10 09:53 . 2002-08-29 04:41 171,008 --a------ C:\WINDOWS\system32\sccsccp.dll
2008-05-10 09:53 . 2002-08-28 23:27 169,984 --a------ C:\WINDOWS\system32\sccbase.dll
2008-05-10 09:53 . 2002-08-28 23:27 133,632 --a------ C:\WINDOWS\system32\rsaenh.dll
2008-05-10 09:53 . 2002-08-29 04:41 74,240 --a------ C:\WINDOWS\system32\rtcshare.exe
2008-05-10 09:53 . 2002-08-29 04:41 12,800 --a------ C:\WINDOWS\system32\runonce.exe
2008-05-10 09:51 . 2002-08-29 04:41 1,349,120 --a------ C:\WINDOWS\system32\query.dll
2008-05-10 09:51 . 2002-08-29 04:41 264,704 --a------ C:\WINDOWS\system32\wzcsvc.dll
2008-05-10 09:51 . 2002-07-16 19:55 172,664 --a------ C:\WINDOWS\system32\xenroll.dll
2008-05-10 09:51 . 2002-08-29 04:41 86,016 --a------ C:\WINDOWS\system32\xactsrv.dll
2008-05-10 09:51 . 2002-08-29 04:41 56,832 --a------ C:\WINDOWS\system32\wzcdlg.dll
2008-05-10 09:51 . 2002-08-29 04:41 23,552 --a------ C:\WINDOWS\system32\wzcsapi.dll
2008-05-10 09:51 . 2002-08-29 04:41 9,216 --a------ C:\WINDOWS\system32\wuauserv.dll
2008-05-10 09:50 . 2002-08-29 04:41 446,464 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2008-05-10 09:50 . 2002-08-29 04:41 258,048 --a------ C:\WINDOWS\system32\wmvds32.ax
2008-05-10 09:50 . 2002-08-29 04:41 247,808 --a------ C:\WINDOWS\system32\wow32.dll
2008-05-10 09:50 . 2002-08-29 04:41 38,912 --a------ C:\WINDOWS\system32\wsnmp32.dll
2008-05-10 09:50 . 2002-08-29 04:41 17,408 --a------ C:\WINDOWS\system32\wtsapi32.dll
2008-05-10 09:50 . 2002-08-29 04:41 13,312 --a------ C:\WINDOWS\system32\wship6.dll
2008-05-10 09:47 . 2002-08-29 04:39 1,998,848 --a------ C:\WINDOWS\system32\wmploc.dll
2008-05-10 09:47 . 2002-08-29 04:41 1,404,928 --a------ C:\WINDOWS\system32\wmpui.dll
2008-05-10 09:47 . 2002-08-29 04:41 1,298,432 --a------ C:\WINDOWS\system32\wmpcore.dll
2008-05-10 09:47 . 2002-08-29 04:41 311,327 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-05-10 09:47 . 2002-08-29 04:41 296,448 --a------ C:\WINDOWS\system32\wmstream.dll
2008-05-10 09:47 . 2002-08-29 04:41 278,559 --a------ C:\WINDOWS\system32\wmv8ds32.ax
2008-05-10 09:47 . 2002-08-29 04:41 118,784 --a------ C:\WINDOWS\system32\wmsdmoe.dll
2008-05-10 09:47 . 2002-08-29 04:41 77,824 --a------ C:\WINDOWS\system32\wmpstub.exe
2008-05-10 09:47 . 2002-08-29 04:41 77,824 --a------ C:\WINDOWS\system32\wmpshell.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-01 23:47 756,387 ----a-w C:\Program Files\INSTALL.LOG
2008-04-27 10:25 89,088 --sh--r C:\WINDOWS\AppPatch\wuaclt.exe
2008-02-27 10:05 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-29 04:41 1511453]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2008-04-20 05:18 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-24 20:17 98304]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 13:12 2061816]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-02-10 11:55 155648]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 11:18 49152]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-10 11:51 118784]
"DXM6Patch_981116"="C:\WINDOWS\p_981116.exe" [1998-11-30 18:04 497376]
"HelpCenter4.1"="C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 19:02 198184]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
iZone Monitor.lnk - C:\Program Files\ArcSoft\Polaroid iZone PhotoBase\iZone Monitor.exe [2007-11-01 17:01:14 184320]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.NSVI"= NSVIDEO.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FastAccess Help]
--a------ 2007-10-03 08:19 108421 C:\Program Files\BellSouth Application Management\content\..\Start.exe
R2 McciCMService;McciCMService;"C:\Program Files\Common Files\Motive\McciCMService.exe" [2008-01-28 14:56]
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-08-17 22:36]
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\System32\DRIVERS\ptserlp.sys [2001-08-17 13:28]
S2 Ca536av;FashionCam Video Camera Device;C:\WINDOWS\System32\Drivers\Ca536av.sys [2004-06-29 21:21]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;C:\WINDOWS\System32\DRIVERS\mr97310v.sys [2004-03-30 11:29]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-01-19 11:53]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-01-19 11:53]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 USBCamera;FashionCam Digital Still Camera Device;C:\WINDOWS\System32\Drivers\Bulk536.sys [2003-05-14 23:28]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-01 23:46:40 C:\WINDOWS\Tasks\System Restore.job"
- C:\WINDOWS\system32\Restore\rstrui.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-11 13:26:31
Windows 5.1.2600 Service Pack 1 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-11 13:26:56
ComboFix-quarantined-files.txt 2008-05-11 19:26:56
ComboFix4.txt 2008-05-09 18:21:18
ComboFix3.txt 2008-05-10 07:12:28
ComboFix2.txt 2008-05-11 19:17:52
Pre-Run: 19,790,200,832 bytes free
Post-Run: 19,793,215,488 bytes free
204
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 13, 2008 1:18:14 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 12/05/2008
Kaspersky Anti-Virus database records: 765113
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 39835
Number of viruses found: 18
Number of infected objects: 31
Number of suspicious objects: 10
Duration of the scan process: 00:45:02
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\AppPatch\wuaclt.exe Infected: Trojan-Downloader.Win32.Agent.kwg skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\ModemLog_HSP56 Micromodem.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader3.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader4.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader9.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader9.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader11.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader11.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader13.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader13.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\amy\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\amy\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\amy\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\amy\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\amy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\amy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\amy\Local Settings\Application Data\SupportSoft\HelpCenter4.1\amy\state\logs\sprtcmd.log Object is locked skipped
C:\Documents and Settings\amy\Local Settings\temp\abm3.tmp Object is locked skipped
C:\Documents and Settings\amy\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\amy\Application Data\AT&T\Internet Security Wizard\client_gateway.log Object is locked skipped
C:\Documents and Settings\amy\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.98866 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0024020.old Infected: Trojan-Downloader.Win32.Agent.nua skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029120.exe Infected: not-a-virus:FraudTool.Win32.XPAntivirus.da skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029125.exe Infected: Trojan-Downloader.Win32.PurityScan.gb skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029126.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029126.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029129.DLL Infected: Trojan.Win32.Monder.cy skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029130.DLL Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0029131.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0030207.dll Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0030237.dll Infected: Trojan.Win32.Monder.dc skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0030239.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qvb skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0030240.dll Infected: Trojan.Win32.Monder.dd skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0031424.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0031426.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0031427.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0031428.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP91\A0040867.exe Infected: Trojan.Win32.Agent.lke skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP92\A0041108.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP92\A0041108.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP92\A0041108.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP94\A0044227.sys Infected: Rootkit.Win32.Agent.aii skipped
C:\System Volume Information\_restore{6D78691B-31FB-4FEA-964E-A64B541795DA}\RP97\change.log Object is locked skipped
C:\PeoplePC98XP\Utilities\ppal3ppc.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.ac skipped
C:\PeoplePC98XP\Utilities\ppal3ppc.exe NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\WNSXS~1\сѕrss.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.hl skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\clbdriver.sys.vir Infected: Rootkit.Win32.Agent.aii skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\default.htm.vir Infected: not-virus:Hoax.HTML.Secureinvites.b skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\g37.exe.vir/stream/data0002 Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\g37.exe.vir/stream Infected: not-a-virus:AdWare.Win32.Agent.bob skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\g37.exe.vir NSIS: infected - 2 skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:29:57 AM, on 5/13/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ArcSoft\Polaroid iZone PhotoBase\iZone Monitor.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.spybot.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe /P HelpCenter4.1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: iZone Monitor.lnk = C:\Program Files\ArcSoft\Polaroid iZone PhotoBase\iZone Monitor.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.forums.spybot.info
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C3B48A7-1C39-43AD-9D30-353181A238A5}: NameServer = 207.69.188.187 207.69.188.186
O17 - HKLM\System\CS1\Services\Tcpip\..\{3C3B48A7-1C39-43AD-9D30-353181A238A5}: NameServer = 207.69.188.187 207.69.188.186
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 4091 bytes