ComboFix Log Workaround - Part one
I think I found a workaround for ComboFix. I switched users on the computer and it ran fine. Then I switched back and was able to run it on the user where the problems have been. I'm posting both logs as they are different.
User Log that has NOT been the user the other logs are for:
ComboFix 07-12-31.4 - Randy 2007-12-30 22:55:51.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.230 [GMT -6:00]
Running from: C:\Documents and Settings\Randy\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\1.exe
C:\check_LSA7.txt
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
C:\Documents and Settings\Randy\Start Menu\Programs\Startup\ta_start.lnk
C:\Documents and Settings\Sherry\Application Data\ICROSO~1.NET
C:\Documents and Settings\Sherry\Application Data\ICROSO~1.NET\m?hta.exe
C:\Documents and Settings\Sherry\Application Data\WNSXS~1
C:\Documents and Settings\Sherry\err.log
C:\Documents and Settings\Sherry\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Sherry\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Sherry\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\asembl~1
C:\Program Files\asembl~1\a?sembly\
C:\Program Files\ISM2
C:\Program Files\ISM2\adhydraupd.exe
C:\Program Files\ISM2\dictionary.gz
C:\Program Files\ISM2\targets.gz
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\QdrPack10.exe
C:\Program Files\QdrPack\QdrPack11.exe
C:\Program Files\QdrPack\trffyupd.exe
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\QdrPack\zhydupd.exe
C:\Program Files\Temporary
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\crap.1187053590.old
C:\Program Files\WinBudget\bin\matrix.dll
C:\svhost.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fCOe
C:\Temp\fCOe\tOasF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\tskmgr.exe
C:\WINDOWS\1.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\PerfInfo
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\ctfmona.exe
C:\WINDOWS\system32\dkmynmof.ini
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rnituabg.exe
C:\WINDOWS\system32\syslodr.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_DRIVER
-------\LEGACY_GENERAL_SOCKET_SERVICE
-------\DomainService
-------\General Socket Service
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-31 )))))))))))))))))))))))))))))))
.
2007-12-30 22:54 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-30 17:01 . 2007-12-30 21:35 <DIR> d-------- C:\VundoFix Backups
2007-12-30 16:47 . 2007-12-30 16:47 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-30 15:49 . 2007-12-30 16:27 16,384 --a------ C:\Program Files\NTDLL.dll
2007-12-30 15:15 . 2007-12-30 15:15 <DIR> d-------- C:\Program Files\RcvSystem
2007-12-29 18:46 . 2007-12-29 18:46 <DIR> d-------- C:\Documents and Settings\Randy\Application Data\Grisoft
2007-12-28 16:53 . 2007-12-28 16:53 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-28 16:51 . 2007-12-28 16:51 <DIR> d-------- C:\Documents and Settings\Sherry\Application Data\Grisoft
2007-12-28 16:51 . 2007-12-28 16:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-28 16:51 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-28 13:23 . 2007-12-28 13:23 4,096 --ahs---- C:\WINDOWS\system32\5558.dat
2007-12-28 12:35 . 2007-12-28 12:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-27 13:10 . 2007-12-27 13:10 <DIR> d--h----- C:\WINDOWS\PIF
2007-12-26 15:12 . 2007-12-26 15:12 <DIR> d-------- C:\Documents and Settings\Randy\Application Data\Lavasoft
2007-12-26 14:27 . 2005-09-30 14:27 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-26 14:27 . 2005-09-30 14:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Gtek
2007-12-01 12:51 . 2007-12-29 10:53 20,480 --a------ C:\WINDOWS\quit.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-30 22:53 --------- d-----w C:\Program Files\Java
2007-12-30 22:12 0 ----a-w C:\Documents and Settings\Sherry\NTDLL.dll
2007-10-21 01:25 82,432 ----a-w C:\WINDOWS\zolgdeho.dll
2007-10-21 01:25 82,432 ----a-w C:\Documents and Settings\All Users\Application Data\mbgvotcb.dll
2007-09-10 20:10 2,011,099 --sha-w C:\WINDOWS\system32\ccbeg.bak1
2007-09-22 16:00 1,978,569 --sha-w C:\WINDOWS\system32\ccbeg.bak2
.
C:\WINDOWS\system32\mswsock.dll ... is infected !!
C:\WINDOWS\system32\drivers\tcpip.sys ... is infected !! (additional data below)
360,576 2006-04-20 12:18:35 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
359,808 2006-04-20 11:51:50 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
359,040 2006-02-28 12:00:00 C:\WINDOWS\system32\dllcache\tcpip.sys
359,040 2006-02-28 12:00:00 C:\WINDOWS\system32\drivers\tcpip.sys
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 57,344 2005-06-07 04:46:24 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
----a-w 1,404,928 2004-10-15 00:42:54 C:\Program Files\Analog Devices\Core\bak\smax4pnp.exe
----a-w 1,404,928 2004-10-15 00:42:54 C:\Program Files\Analog Devices\Core\smax4pnp.exe
----a-w 81,920 2004-07-27 21:50:18 C:\Program Files\Common Files\InstallShield\UpdateService\bak\issch.exe
----a-w 221,184 2004-07-27 21:50:42 C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe
----a-w 86,016 2005-01-27 06:02:00 C:\Program Files\Dell\Media Experience\bak\DMXLauncher.exe
----a-w 332,800 2005-05-15 07:04:12 C:\Program Files\Dell Support\bak\DSAgnt.exe
----a-w 49,152 2004-09-13 21:49:00 C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 49,152 2004-09-13 20:49:00 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
----a-w 221,184 2003-09-04 01:12:44 C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe
----a-w 278,528 2006-06-14 21:24:14 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 32,881 2003-11-19 22:48:14 C:\Program Files\Java\j2re1.4.2_03\bin\bak\jusched.exe
----a-w 53,248 2004-09-14 13:50:48 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mmtask.exe
----a-w 131,072 2004-09-14 13:50:48 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe
----a-w 282,624 2006-08-19 20:38:04 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 26,112 2005-09-30 20:31:48 C:\Program Files\Real\RealPlayer\bak\RealPlay.exe
----a-w 1,921,024 2004-01-30 14:44:32 C:\Program Files\Support.com\bin\bak\tgcmd.exe
----a-w 15,360 2004-08-04 10:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2006-02-28 12:00:00 C:\WINDOWS\system32\ctfmon.exe
----a-w 126,976 2005-01-23 21:31:34 C:\WINDOWS\system32\bak\hkcmd.exe
----a-w 126,976 2005-01-23 21:31:34 C:\WINDOWS\system32\hkcmd.exe
----a-w 155,648 2005-01-23 21:36:10 C:\WINDOWS\system32\bak\igfxtray.exe
----a-w 155,648 2005-01-23 21:36:10 C:\WINDOWS\system32\igfxtray.exe
----a-w 127,035 2004-12-06 06:05:00 C:\WINDOWS\system32\dla\bak\tfswctrl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1a46cb08-135c-44e5-b84f-37aff70bf4c3}]
C:\WINDOWS\system32\xkcwaudc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{440EC62D-5187-4340-8ECF-C5AB50ACC040}]
C:\WINDOWS\system32\ddccy.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 06:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 10:59:36]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NkbMonitor.exe.lnk
backup=C:\WINDOWS\pss\NkbMonitor.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sherry^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Sherry\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sherry^Start Menu^Programs^Startup^Think-Adz.lnk]
path=C:\Documents and Settings\Sherry\Start Menu\Programs\Startup\Think-Adz.lnk
backup=C:\WINDOWS\pss\Think-Adz.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 10:09 63712 --a------ C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dnse]
C:\Program Files\Common Files\Update\dnse.exe -c -product=was
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Esid]
C:\Documents and Settings\Sherry\Application Data\?icrosoft.NET\m?hta.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\twinrldt.exe CHD003
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-01-23 15:36 155648 --a------ C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISMModule4]
C:\Program Files\ISM\ISMModule4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\niwo]
C:\Program Files\MSN Gaming Zone\niwo22011.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
rundll32.exe C:\WINDOWS\system32\lpssxtcq.dll,sitypnow
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sen]
C:\PROGRA~1\ASEMBL~1\javaw.exe -vt ndrv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-27 11:49 68856 --a------ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe C:\WINDOWS\system32\fomnymkd.dll,forkonce
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uwas7cw]
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe -c
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiSpyware 2007 Free]
C:\Program Files\WinAntiSpyware 2007\was7.exe /min
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{30-08-8B-B9-ZN}]
C:\windows\system32\kqdsrngs.exe CHD003
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-30 23:04:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\dmdlgs.cpl 649 bytes
C:\WINDOWS\system32\rshx348.dll 106496 bytes executable
scan completed successfully
hidden files: 2
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\csrss.exe
-> C:\WINDOWS\system32\basemcdpf32.dll
.
Completion time: 2007-12-30 23:08:13 - machine was rebooted
C:\qoobox\ComboFix-quarantined-files.txt 2007-12-31 05:08:05
.
2007-12-31 03:50:08 --- E O F ---