Update on item you asked for Thank You
Hi again from Wisconsin, Thanks for you help
Here is the update:
Cfscript to Combo fix (got log)
Uninstall old Vava installed new jre-6u7-windows-i586-p-s V7
uninstall old Adobe Installed new V9
Install ATF (ran per your instructions)
Ran Kaspersky (posted log)
HJT (posted new log)
ComboFix resultant (posted log) program asked if i wanted to download an update I said yes
Posted ComboFix before posting
Thanks for you continued patience B
++++++++++
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, September 15, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, September 15, 2008 16:14:17
Records in database: 1236420
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan statistics:
Files scanned: 72626
Threat name: 6
Infected objects: 6
Suspicious objects: 0
Duration of the scan: 02:37:41
File name / Threat name / Threats count
C:\Program Files\Online Services\AOL90US\comps\toolbar\toolbr.EXE Infected: not-a-virus:AdWare.Win32.SearchIt.t 1
C:\QooBox\Quarantine\C\Program Files\rhc1roj0e32n\rhc1roj0e32n.exe.vir Infected: not-a-virus:FraudTool.Win32.AntivirusXP2008.az 1
C:\QooBox\Quarantine\C\Program Files\rhc1roj0e32n\Uninstall.exe.vir Infected: Trojan-Downloader.Win32.FraudLoad.vcbp 1
C:\QooBox\Quarantine\C\WINDOWS\buritos.exe.vir Infected: Trojan.Win32.Crypt.lh 1
C:\QooBox\Quarantine\C\WINDOWS\karina.dat.vir Infected: Backdoor.Win32.Small.eug 1
D:\I386\APPS\APP17170\src\HPSummer2005.exe Infected: not-a-virus:AdWare.Win32.MyWay.j 1
The selected area was scanned.
++++++++++++++++++++
HJT Updated LOg
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:01:34 PM, on 9/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0a\aoltray.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\VTTimer.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 8297 bytes
++++++++++++++++
ComboFix Log after draging CFScipt into ComboFix
ComboFix 08-09-14.06 - Compaq_Owner 2008-09-15 9:12:19.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.71 [GMT -5:00]Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Compaq_Owner\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\tijefuvo.sys
C:\Documents and Settings\All Users\Application Data\very.bat
C:\Documents and Settings\Compaq_Owner\Application Data\morojys.dll
C:\Pleasebaby.exe
C:\Program Files\Common Files\aguxe.com
C:\Program Files\Common Files\jicodafov._sy
C:\Program Files\Common Files\pupu._sy
C:\Program Files\Common Files\qahi.dll
C:\Program Files\Common Files\tixusibudy.dl
C:\Program Files\rhc1roj0e32n
C:\Program Files\rhc1roj0e32n\database.dat
C:\Program Files\rhc1roj0e32n\license.txt
C:\Program Files\rhc1roj0e32n\MFC71.dll
C:\Program Files\rhc1roj0e32n\MFC71ENU.DLL
C:\Program Files\rhc1roj0e32n\msvcp71.dll
C:\Program Files\rhc1roj0e32n\msvcr71.dll
C:\Program Files\rhc1roj0e32n\rhc1roj0e32n.exe
C:\Program Files\rhc1roj0e32n\rhc1roj0e32n.exe.local
C:\Program Files\rhc1roj0e32n\Uninstall.exe
C:\WINDOWS\bawepe.bat
C:\WINDOWS\dycy.bin
.
((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.
2008-09-14 18:37 . 2004-08-03 23:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-09-14 18:37 . 2008-09-14 18:37 1,846 -rahs---- C:\WINDOWS\system32\drivers\103C_HP_CPC_PX786AA-ABA SR1500NX NA530_YC_0Pres_QCNH528_E53NAheRED3_47_IKelut_SASUSTek Computer INC._V2.02_B3.14_T050309_WXH2_L409_M256_J80_7AMD_8Sempron_92_#051022_N11063065_Z10573052_G10DE0185.MRK
2008-09-14 18:36 . 2005-10-22 01:28 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\WINDOWS
2008-09-14 18:36 . 2005-10-22 01:54 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
2008-09-14 18:36 . 2005-10-22 01:44 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SampleView
2008-09-14 18:36 . 2005-10-22 01:50 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\InterMute
2008-09-14 18:36 . 2008-09-14 18:38 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
2008-09-14 18:36 . 2008-09-14 19:07 <DIR> d-------- C:\Documents and Settings\Compaq_Owner
2008-09-14 18:35 . 2005-10-22 01:28 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-09-14 18:35 . 2005-10-22 01:54 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2008-09-14 18:35 . 2005-10-22 01:44 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-09-14 18:35 . 2005-10-22 01:50 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\InterMute
2008-09-14 18:35 . 2005-10-22 01:27 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Apple Computer
2008-09-14 18:30 . 2004-08-04 02:56 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-09-14 18:30 . 2004-08-04 00:29 1,897,408 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-09-14 18:05 . 2008-09-14 18:15 <DIR> dr-hs---- C:\WINDOWS\system32\dllcache
2008-09-14 17:18 . 2008-09-14 17:18 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-11 14:25 . 2008-09-14 15:37 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-11 11:42 . 2008-09-11 11:42 <DIR> d-------- C:\backups
2008-09-08 12:00 . 2008-09-10 14:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\WINDOWS
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\Application Data\Symantec
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\Application Data\SampleView
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\Application Data\InterMute
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\Application Data\Apple Computer
2008-09-08 11:39 . 2008-09-08 11:39 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY
2008-09-07 19:17 . 2008-09-07 19:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-07 19:12 . 2008-09-11 13:22 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-07 17:43 . 2008-09-07 17:43 <DIR> d-------- C:\Program Files\CCleaner
2008-08-27 22:27 . 2008-08-27 22:27 <DIR> d-------- C:\Program Files\Bonjour
2008-08-27 20:58 . 2008-08-27 21:01 <DIR> d-------- C:\Program Files\Safari
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterMute
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-08-26 12:38 . 2008-08-26 12:38 <DIR> d-------- C:\Documents and Settings\Administrator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 00:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-14 23:40 --------- d-----w C:\Program Files\Easy Internet signup
2008-09-13 00:54 4,412 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2008-09-08 17:27 --------- d-----w C:\Program Files\THQ
2008-09-08 00:17 --------- d-----w C:\Program Files\Lavasoft
2008-08-28 03:53 --------- d-----w C:\Program Files\Apple Software Update
.
((((((((((((((((((((((((((((( snapshot@2008-09-14_19.20.16.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-25 00:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\CONFLICT.1\FP_AX_CAB_INSTALLER.exe
- 2004-08-04 11:00:00 12,288 ----a-w C:\WINDOWS\I386\winntupg\APMUPGRD.DLL
+ 2004-08-04 18:00:00 12,288 ----a-w C:\WINDOWS\I386\winntupg\APMUPGRD.DLL
- 2004-08-04 11:00:00 6,656 ----a-w C:\WINDOWS\I386\winntupg\BOSCOMP.DLL
+ 2004-08-04 18:00:00 6,656 ----a-w C:\WINDOWS\I386\winntupg\BOSCOMP.DLL
- 2004-08-04 11:00:00 58,128 ----a-w C:\WINDOWS\I386\winntupg\CFGMGR32.DLL
+ 2004-08-04 18:00:00 58,128 ----a-w C:\WINDOWS\I386\winntupg\CFGMGR32.DLL
- 2004-08-04 11:00:00 40,960 ----a-w C:\WINDOWS\I386\winntupg\CLUSCOMP.DLL
+ 2004-08-04 18:00:00 40,960 ----a-w C:\WINDOWS\I386\winntupg\CLUSCOMP.DLL
- 2004-08-04 11:00:00 5,120 ----a-w C:\WINDOWS\I386\winntupg\FSFILTER.DLL
+ 2004-08-04 18:00:00 5,120 ----a-w C:\WINDOWS\I386\winntupg\FSFILTER.DLL
- 2004-08-04 11:00:00 6,656 ----a-w C:\WINDOWS\I386\winntupg\FTCOMP.DLL
+ 2004-08-04 18:00:00 6,656 ----a-w C:\WINDOWS\I386\winntupg\FTCOMP.DLL
- 2004-08-04 11:00:00 5,632 ----a-w C:\WINDOWS\I386\winntupg\INPUPGRD.DLL
+ 2004-08-04 18:00:00 5,632 ----a-w C:\WINDOWS\I386\winntupg\INPUPGRD.DLL
- 2004-08-04 11:00:00 5,632 ----a-w C:\WINDOWS\I386\winntupg\MS\MODEMSHR\MDMSHRUP.DLL
+ 2004-08-04 18:00:00 5,632 ----a-w C:\WINDOWS\I386\winntupg\MS\MODEMSHR\MDMSHRUP.DLL
- 2004-08-04 11:00:00 30,748 ----a-w C:\WINDOWS\I386\winntupg\MS\SNA\IBMMGUG.DLL
+ 2004-08-04 18:00:00 30,748 ----a-w C:\WINDOWS\I386\winntupg\MS\SNA\IBMMGUG.DLL
- 2004-08-04 11:00:00 38,941 ----a-w C:\WINDOWS\I386\winntupg\MS\SNA\NTSNAUPG.DLL
+ 2004-08-04 18:00:00 38,941 ----a-w C:\WINDOWS\I386\winntupg\MS\SNA\NTSNAUPG.DLL
- 2004-08-04 11:00:00 28,701 ----a-w C:\WINDOWS\I386\winntupg\MS\SNA\SNADLCUG.DLL
+ 2004-08-04 18:00:00 28,701 ----a-w C:\WINDOWS\I386\winntupg\MS\SNA\SNADLCUG.DLL
- 2004-08-04 11:00:00 5,632 ----a-w C:\WINDOWS\I386\winntupg\MSMQCOMP.DLL
+ 2004-08-04 18:00:00 5,632 ----a-w C:\WINDOWS\I386\winntupg\MSMQCOMP.DLL
- 2004-08-04 11:00:00 121,344 ----a-w C:\WINDOWS\I386\winntupg\NETUPGRD.DLL
+ 2004-08-04 18:00:00 121,344 ----a-w C:\WINDOWS\I386\winntupg\NETUPGRD.DLL
- 2004-08-04 11:00:00 11,264 ----a-w C:\WINDOWS\I386\winntupg\NTDSUPG.DLL
+ 2004-08-04 18:00:00 11,264 ----a-w C:\WINDOWS\I386\winntupg\NTDSUPG.DLL
- 2004-08-04 11:00:00 6,144 ----a-w C:\WINDOWS\I386\winntupg\NV4PREP.DLL
+ 2004-08-04 18:00:00 6,144 ----a-w C:\WINDOWS\I386\winntupg\NV4PREP.DLL
- 2004-08-04 11:00:00 9,756 ----a-w C:\WINDOWS\I386\winntupg\OEM\DIGI\ASYNC\DGUPGRD.DLL
+ 2004-08-04 18:00:00 9,756 ----a-w C:\WINDOWS\I386\winntupg\OEM\DIGI\ASYNC\DGUPGRD.DLL
- 2004-08-04 11:00:00 72,732 ----a-w C:\WINDOWS\I386\winntupg\OEM\DIGI\ISDN\BRI\DIGIUPG.DLL
+ 2004-08-04 18:00:00 72,732 ----a-w C:\WINDOWS\I386\winntupg\OEM\DIGI\ISDN\BRI\DIGIUPG.DLL
- 2004-08-04 11:00:00 28,701 ----a-w C:\WINDOWS\I386\winntupg\OEM\DIGI\ISDN\PRI\DIGPRIUP.DLL
+ 2004-08-04 18:00:00 28,701 ----a-w C:\WINDOWS\I386\winntupg\OEM\DIGI\ISDN\PRI\DIGPRIUP.DLL
- 2004-08-04 11:00:00 11,292 ----a-w C:\WINDOWS\I386\winntupg\OEM\DIGI\REALPORT\DGRPUPG.DLL
+ 2004-08-04 18:00:00 11,292 ----a-w C:\WINDOWS\I386\winntupg\OEM\DIGI\REALPORT\DGRPUPG.DLL
- 2004-08-04 11:00:00 114,717 ----a-w C:\WINDOWS\I386\winntupg\OEM\EQN\EQNUPGRD.DLL
+ 2004-08-04 18:00:00 114,717 ----a-w C:\WINDOWS\I386\winntupg\OEM\EQN\EQNUPGRD.DLL
- 2004-08-04 11:00:00 31,744 ----a-w C:\WINDOWS\I386\winntupg\OEM\SPX\MPS\SPXUPGRD.DLL
+ 2004-08-04 18:00:00 31,744 ----a-w C:\WINDOWS\I386\winntupg\OEM\SPX\MPS\SPXUPGRD.DLL
- 2004-08-04 11:00:00 33,792 ----a-w C:\WINDOWS\I386\winntupg\OEM\TIGERJET\TJUPG.DLL
+ 2004-08-04 18:00:00 33,792 ----a-w C:\WINDOWS\I386\winntupg\OEM\TIGERJET\TJUPG.DLL
- 2004-08-04 11:00:00 323,344 ----a-w C:\WINDOWS\I386\winntupg\SETUPAPI.DLL
+ 2004-08-04 18:00:00 323,344 ----a-w C:\WINDOWS\I386\winntupg\SETUPAPI.DLL
- 2004-08-04 11:00:00 4,608 ----a-w C:\WINDOWS\I386\winntupg\TSCOMP.DLL
+ 2004-08-04 18:00:00 4,608 ----a-w C:\WINDOWS\I386\winntupg\TSCOMP.DLL
- 2004-08-04 11:00:00 11,776 ----a-w C:\WINDOWS\I386\winntupg\VIDUPGRD.DLL
+ 2004-08-04 18:00:00 11,776 ----a-w C:\WINDOWS\I386\winntupg\VIDUPGRD.DLL
+ 2001-07-14 22:32:24 69,632 ----a-w C:\WINDOWS\setupupd\temp\wsdueng.dll
- 2005-10-22 06:44:15 154,768 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-09-15 00:26:18 154,768 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-03-25 02:32:44 218,496 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
+ 2008-09-15 01:47:02 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSC_UserPrompt"="c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-03 218240]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-08-28 58488]
"IS CfgWiz"="c:\Program Files\Norton Internet Security\cfgwiz.exe" [2004-08-18 132248]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2004-08-31 33936]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-22 180269]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 C:\WINDOWS\sm56hlpr.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0a\aoltray.exe [2006-11-08 156784]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\sslaunch.exe [2005-10-22 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9b408d0-bc63-11d9-842c-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 09:14:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-15 9:17:58
ComboFix-quarantined-files.txt 2008-09-15 14:17:55
ComboFix2.txt 2008-09-15 00:20:38
Pre-Run: 50,582,503,424 bytes free
Post-Run: 50,581,692,416 bytes free
189
++++++++++++++++++++++++++++++++
++++++++++++++++++++++++++++++++
ComboFix Log just before I posted
ComboFix 08-09-15.01 - Compaq_Owner 2008-09-15 14:32:55.5 - NTFSx86
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-15 to 2008-09-15 )))))))))))))))))))))))))))))))
.
2008-09-15 10:45 . 2008-09-15 10:45 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-09-15 10:38 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-14 18:37 . 2004-08-03 23:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-09-14 18:37 . 2008-09-14 18:37 1,846 -rahs---- C:\WINDOWS\system32\drivers\103C_HP_CPC_PX786AA-ABA SR1500NX NA530_YC_0Pres_QCNH528_E53NAheRED3_47_IKelut_SASUSTek Computer INC._V2.02_B3.14_T050309_WXH2_L409_M256_J80_7AMD_8Sempron_92_#051022_N11063065_Z10573052_G10DE0185.MRK
2008-09-14 18:36 . 2005-10-22 01:28 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\WINDOWS
2008-09-14 18:36 . 2005-10-22 01:54 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
2008-09-14 18:36 . 2005-10-22 01:44 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\SampleView
2008-09-14 18:36 . 2005-10-22 01:50 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\InterMute
2008-09-14 18:36 . 2008-09-14 18:38 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer
2008-09-14 18:36 . 2008-09-14 19:07 <DIR> d-------- C:\Documents and Settings\Compaq_Owner
2008-09-14 18:35 . 2005-10-22 01:28 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-09-14 18:35 . 2005-10-22 01:54 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2008-09-14 18:35 . 2005-10-22 01:44 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\SampleView
2008-09-14 18:35 . 2005-10-22 01:50 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\InterMute
2008-09-14 18:35 . 2005-10-22 01:27 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Apple Computer
2008-09-14 18:30 . 2004-08-04 02:56 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-09-14 18:30 . 2004-08-04 00:29 1,897,408 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-09-14 18:05 . 2008-09-14 18:15 <DIR> dr-hs---- C:\WINDOWS\system32\dllcache
2008-09-14 17:18 . 2008-09-14 17:18 <DIR> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-11 14:25 . 2008-09-14 15:37 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-11 11:42 . 2008-09-11 11:42 <DIR> d-------- C:\backups
2008-09-08 12:00 . 2008-09-10 14:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\WINDOWS
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\Application Data\Symantec
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\Application Data\SampleView
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\Application Data\InterMute
2008-09-08 11:39 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY\Application Data\Apple Computer
2008-09-08 11:39 . 2008-09-08 11:39 <DIR> d-------- C:\Documents and Settings\Administrator.FAMILY
2008-09-07 19:17 . 2008-09-07 19:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-07 19:12 . 2008-09-11 13:22 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-07 17:43 . 2008-09-07 17:43 <DIR> d-------- C:\Program Files\CCleaner
2008-08-27 22:27 . 2008-08-27 22:27 <DIR> d-------- C:\Program Files\Bonjour
2008-08-27 20:58 . 2008-08-27 21:01 <DIR> d-------- C:\Program Files\Safari
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterMute
2008-08-26 12:38 . 2005-10-21 19:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-08-26 12:38 . 2008-08-26 12:38 <DIR> d-------- C:\Documents and Settings\Administrator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 15:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-15 15:38 --------- d-----w C:\Program Files\Java
2008-09-15 00:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-14 23:40 --------- d-----w C:\Program Files\Easy Internet signup
2008-09-13 00:54 4,412 ----a-w C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2008-09-08 17:27 --------- d-----w C:\Program Files\THQ
2008-09-08 00:17 --------- d-----w C:\Program Files\Lavasoft
2008-08-28 03:53 --------- d-----w C:\Program Files\Apple Software Update
.
((((((((((((((((((((((((((((( snapshot_2008-09-15_ 9.17.40.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-12 20:06:42 295,606 ----a-r C:\WINDOWS\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
- 2005-10-22 06:00:31 49,245 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-06-10 06:21:01 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2005-10-22 06:00:31 49,247 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-06-10 06:21:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2005-10-22 06:00:31 127,075 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2008-06-10 07:32:34 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2006-12-02 03:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-02 03:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-02 03:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SSC_UserPrompt"="c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-03 218240]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-08-28 58488]
"IS CfgWiz"="c:\Program Files\Norton Internet Security\cfgwiz.exe" [2004-08-18 132248]
"URLLSTCK.exe"="c:\Program Files\Norton Internet Security\UrlLstCk.exe" [2004-08-31 33936]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-22 180269]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 C:\WINDOWS\sm56hlpr.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0a\aoltray.exe [2006-11-08 156784]
SpySubtract.lnk - C:\Program Files\InterMute\SpySubtract\sslaunch.exe [2005-10-22 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9b408d0-bc63-11d9-842c-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R0 -: HKLM-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/keyword/%s
O8 -: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 -: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 -: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 -: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 -: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 14:37:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-15 14:42:07
ComboFix-quarantined-files.txt 2008-09-15 19:41:58
ComboFix2.txt 2008-09-15 19:14:17
ComboFix3.txt 2008-09-15 14:17:59
ComboFix4.txt 2008-09-15 00:20:38
Pre-Run: 50,218,606,592 bytes free
Post-Run: 50,207,830,016 bytes free
139
End of post thank you Blade