Win PC Antivirus
Page 1 of 1
- bronbron81Intermediate
-
OS : Window Xp Media center edition 2005
Posts : 72
Rubies : 3606
Likes : 0
I understand this is a rogue antivirus system that has infected my computer and I need some help getting rid of the program as well as the associated files.
Here is a Hijackthis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:40:46 PM, on 5/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Melissa\Temporary Internet Files\Content.IE5\5E1ISUG0\HiJackThis[1].exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80203
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80203
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80203
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll
R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: (no name) - {01E45C5E-5308-455E-8B01-F6A584957E69} - C:\WINDOWS\system32\urxdbrol.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WinInet Class - {39fc2065-c9c7-49cd-8942-44cc2dedc844} - C:\WINDOWS\ieocx.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {A500099D-A113-414D-A380-6A1AD5AB7F0A} - c:\windows\system32\llexrtn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Inbox Toolbar - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AVScan] C:\Documents and Settings\Melissa\Application Data\winav.exe
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Elf Bowling 7 17 - The Last Insult\Images\stg_drm.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238892460062
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Elf Bowling 7 17 - The Last Insult\Images\armhelper.ocx
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: ortkmcwh - C:\WINDOWS\SYSTEM32\llexrtn.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\HP Game Console\GameConsoleService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 13587 bytes
Here is a Hijackthis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:40:46 PM, on 5/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Melissa\Temporary Internet Files\Content.IE5\5E1ISUG0\HiJackThis[1].exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80203
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80203
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80203
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll
R3 - URLSearchHook: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: (no name) - {01E45C5E-5308-455E-8B01-F6A584957E69} - C:\WINDOWS\system32\urxdbrol.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WinInet Class - {39fc2065-c9c7-49cd-8942-44cc2dedc844} - C:\WINDOWS\ieocx.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL Search\AOLSearch.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {A500099D-A113-414D-A380-6A1AD5AB7F0A} - c:\windows\system32\llexrtn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Inbox Toolbar - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AVScan] C:\Documents and Settings\Melissa\Application Data\winav.exe
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Elf Bowling 7 17 - The Last Insult\Images\stg_drm.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238892460062
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) - http://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Elf Bowling 7 17 - The Last Insult\Images\armhelper.ocx
O18 - Protocol: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\PROGRA~1\INBOXT~1\Inbox.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: ortkmcwh - C:\WINDOWS\SYSTEM32\llexrtn.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\HP Game Console\GameConsoleService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 13587 bytes
- OriginTech Colleague
-
OS : Windows Xp Sp3
Posts : 2684
Rubies : 7038
Likes : 0
WildTangent is a game software driver, some HP laptops come with it so users can play games, but in other cases, if no game are installed, uninstall the WildTangent Web Driver.
WildTangent uses pop-unders (not exactly pop-ups, but they both behave the same way).
The pop-unders themself may not be malicious, but this is considered adware, and plus clicking any pop-under leads the user to god knows where.
Please read here for more information about WildTangent. Your choice if you want to remove it or not.
If you choose to follow my advice, please follow these instructions.
Go to Start > Control Panel > Add/Remove Programs and remove the following programs.
* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".
2. During the download, rename Combofix to Combo-Fix as follows:


3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.
See HERE for how to disable your AV..
WildTangent uses pop-unders (not exactly pop-ups, but they both behave the same way).
The pop-unders themself may not be malicious, but this is considered adware, and plus clicking any pop-under leads the user to god knows where.
Please read here for more information about WildTangent. Your choice if you want to remove it or not.
If you choose to follow my advice, please follow these instructions.
Go to Start > Control Panel > Add/Remove Programs and remove the following programs.
- WildTangent Web Driver
- Open HijackThis
- Choose "Do a system scan only"
- Check the boxes in front of these lines:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80203
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80203
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80203
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
If you didnt set these host files fix them as well:
O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
O1 - Hosts: 217.20.175.74 reviews.techradar.com
O2 - BHO: (no name) - {01E45C5E-5308-455E-8B01-F6A584957E69} - C:\WINDOWS\system32\urxdbrol.dll
O2 - BHO: (no name) - {A500099D-A113-414D-A380-6A1AD5AB7F0A} - c:\windows\system32\llexrtn.dll
O20 - Winlogon Notify: ortkmcwh - C:\WINDOWS\SYSTEM32\llexrtn.dll
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\HP Game Console\GameConsoleService.exe - Press "Fix Checked"
- Close Hijack This.
- Download combofix from here
Link 1
Link 2
* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".
2. During the download, rename Combofix to Combo-Fix as follows:


3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.
See HERE for how to disable your AV..
- Double click on ComboFix.exe.
- Follow the prompts. NOTE:
- ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
***It's strongly recommended to have the Recovery Console installed before doing any malware removal.*** - Allow combofix to run
- Post C:\combofix.txt back here.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
While my help is always free, please consider donating to keep this site alive: Donate

- bronbron81Intermediate
-
OS : Window Xp Media center edition 2005
Posts : 72
Rubies : 3606
Likes : 0
ComboFix 09-05-30.06 - Melissa 05/31/2009 22:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1.#QNAN.262 [GMT -4:00]
Running from: c:\documents and settings\Melissa\Desktop\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Internet Explorer\msimg32.dll
c:\windows\IE4 Error Log.txt
c:\windows\ieocx.dll
c:\windows\system32\drivers\bnygwfzg.sys
c:\windows\system32\drivers\mbudccfv.sys
c:\windows\system32\drivers\UACkopargflxorwulk.sys
c:\windows\system32\llexrtn.dll
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\rakzkld.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\UACbgdiviysapwwopw.log
c:\windows\system32\UACdhsjdefmshjhvmr.dll
c:\windows\system32\UACfdkmghbbtokamyc.log
c:\windows\system32\UAChnadufitipjduca.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACixrjoehiogkvsty.dll
c:\windows\system32\UAClltijtwykobmmra.log
c:\windows\system32\UACmyuktliqotrrprr.dat
c:\windows\system32\UACufcmqbtfqdtpcni.dll
c:\windows\system32\UACwsrjxboewsbgknp.dll
c:\windows\system32\urxdbrol.dll
c:\windows\Tasks\At1.job
D:\Autorun.inf
D:\Desktop.ini
----- BITS: Possible infected sites -----
hxxp://downloadsoftwareserver.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_MBUDCCFV
-------\Legacy_PKXHZVHS
-------\Service_mbudccfv
-------\Service_pkxhzvhs
((((((((((((((((((((((((( Files Created from 2009-05-01 to 2009-06-01 )))))))))))))))))))))))))))))))
.
2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk
2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\documents and settings\Melissa\Application Data\aebwsgmk
2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\docume~1\Melissa\APPLIC~1\aebwsgmk
2009-05-16 00:47 . 2009-05-16 00:47 -------- d-----w- c:\program files\iPod
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\program files\iTunes
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-16 00:32 . 2009-05-16 00:32 -------- d-----w- c:\program files\Safari
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-27 01:51 . 2008-03-22 17:07 -------- d-----w- c:\program files\Norton Security Scan
2009-05-27 01:14 . 2006-09-19 22:13 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-27 00:27 . 2006-09-19 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-05-24 02:18 . 2009-05-24 02:18 186 ----a-w- c:\documents and settings\Melissa\Application Data\asd.bat
2009-05-24 02:18 . 2009-05-24 02:18 186 ----a-w- c:\docume~1\Melissa\APPLIC~1\asd.bat
2009-05-23 01:04 . 2009-05-23 01:04 1096704 ----a-w- c:\documents and settings\Melissa\Application Data\winav.exe
2009-05-23 01:04 . 2009-05-23 01:04 1096704 ----a-w- c:\docume~1\Melissa\APPLIC~1\winav.exe
2009-05-16 03:14 . 2009-01-02 05:58 -------- d-----w- c:\documents and settings\Melissa\Application Data\LimeWire
2009-05-16 03:14 . 2009-01-02 05:58 -------- d-----w- c:\docume~1\Melissa\APPLIC~1\LimeWire
2009-05-16 00:47 . 2007-10-07 04:56 -------- d-----w- c:\program files\Common Files\Apple
2009-04-30 02:19 . 2006-09-19 22:30 -------- d-----w- c:\program files\Microsoft Money 2006
2009-04-13 04:03 . 2006-09-19 22:05 66192 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-05 01:30 . 2006-09-19 22:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-04-05 01:20 . 2007-11-05 23:10 -------- d--h--r- c:\documents and settings\All Users\Application Data\yahoo!
2009-04-05 01:20 . 2006-09-19 22:46 -------- d-----w- c:\program files\Yahoo!
2009-04-05 00:31 . 2009-04-05 00:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-05 00:31 . 2006-09-19 20:58 -------- d-----w- c:\program files\Java
2009-03-28 19:35 . 2006-06-29 18:43 92819 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-26 20:49 . 2009-03-30 23:52 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 20:49 . 2009-03-30 23:52 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-08 08:34 . 2006-03-16 04:00 914944 ----a-w- c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2006-03-16 04:00 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2006-03-16 04:00 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2006-03-16 04:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2006-03-16 04:00 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2006-03-16 04:00 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2006-03-16 04:00 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2006-03-16 04:00 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2006-03-16 04:00 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2006-03-16 04:00 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2006-03-16 04:00 284160 ----a-w- c:\windows\system32\pdh.dll
2008-06-13 22:08 . 2008-06-13 22:08 0 ----a-w- c:\program files\temp01
2006-12-26 02:51 . 2006-12-26 02:51 774144 ----a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-10 1838592]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-25 714608]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-08-18 1617920]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/25/2007 1:07 AM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/5/2009 5:18 PM 101936]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [6/6/2006 4:39 PM 61952]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [5/29/2007 4:55 PM 23888]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*NewlyCreated* - MBUDCCFV
*Deregistered* - mbudccfv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-03-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-05-19 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Melissa.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]
2009-05-08 c:\windows\Tasks\Norton Security Scan for Melissa.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 08:18]
.
- - - - ORPHANS REMOVED - - - -
BHO-{01E45C5E-5308-455E-8B01-F6A584957E69} - c:\windows\system32\urxdbrol.dll
BHO-{39fc2065-c9c7-49cd-8942-44cc2dedc844} - c:\windows\ieocx.dll
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - c:\progra~1\INBOXT~1\Inbox.dll
DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - hxxp://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-31 22:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????@? ??? ]??????Y?@?????@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1236)
c:\windows\system32\NTMARTA.DLL
- - - - - - - > 'explorer.exe'(4032)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\InstallShield\UpdateService\agent.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-06-01 22:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-01 02:58
Pre-Run: 36,952,145,920 bytes free
Post-Run: 38,129,074,176 bytes free
244 --- E O F --- 2009-05-14 02:59
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1.#QNAN.262 [GMT -4:00]
Running from: c:\documents and settings\Melissa\Desktop\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\Internet Explorer\msimg32.dll
c:\windows\IE4 Error Log.txt
c:\windows\ieocx.dll
c:\windows\system32\drivers\bnygwfzg.sys
c:\windows\system32\drivers\mbudccfv.sys
c:\windows\system32\drivers\UACkopargflxorwulk.sys
c:\windows\system32\llexrtn.dll
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\rakzkld.dll
c:\windows\system32\sdra64.exe
c:\windows\system32\UACbgdiviysapwwopw.log
c:\windows\system32\UACdhsjdefmshjhvmr.dll
c:\windows\system32\UACfdkmghbbtokamyc.log
c:\windows\system32\UAChnadufitipjduca.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACixrjoehiogkvsty.dll
c:\windows\system32\UAClltijtwykobmmra.log
c:\windows\system32\UACmyuktliqotrrprr.dat
c:\windows\system32\UACufcmqbtfqdtpcni.dll
c:\windows\system32\UACwsrjxboewsbgknp.dll
c:\windows\system32\urxdbrol.dll
c:\windows\Tasks\At1.job
D:\Autorun.inf
D:\Desktop.ini
----- BITS: Possible infected sites -----
hxxp://downloadsoftwareserver.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_MBUDCCFV
-------\Legacy_PKXHZVHS
-------\Service_mbudccfv
-------\Service_pkxhzvhs
((((((((((((((((((((((((( Files Created from 2009-05-01 to 2009-06-01 )))))))))))))))))))))))))))))))
.
2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk
2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\documents and settings\Melissa\Application Data\aebwsgmk
2009-05-31 17:57 . 2009-05-31 17:57 -------- d-----w- c:\docume~1\Melissa\APPLIC~1\aebwsgmk
2009-05-16 00:47 . 2009-05-16 00:47 -------- d-----w- c:\program files\iPod
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\program files\iTunes
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-16 00:32 . 2009-05-16 00:32 -------- d-----w- c:\program files\Safari
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-27 01:51 . 2008-03-22 17:07 -------- d-----w- c:\program files\Norton Security Scan
2009-05-27 01:14 . 2006-09-19 22:13 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-27 00:27 . 2006-09-19 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-05-24 02:18 . 2009-05-24 02:18 186 ----a-w- c:\documents and settings\Melissa\Application Data\asd.bat
2009-05-24 02:18 . 2009-05-24 02:18 186 ----a-w- c:\docume~1\Melissa\APPLIC~1\asd.bat
2009-05-23 01:04 . 2009-05-23 01:04 1096704 ----a-w- c:\documents and settings\Melissa\Application Data\winav.exe
2009-05-23 01:04 . 2009-05-23 01:04 1096704 ----a-w- c:\docume~1\Melissa\APPLIC~1\winav.exe
2009-05-16 03:14 . 2009-01-02 05:58 -------- d-----w- c:\documents and settings\Melissa\Application Data\LimeWire
2009-05-16 03:14 . 2009-01-02 05:58 -------- d-----w- c:\docume~1\Melissa\APPLIC~1\LimeWire
2009-05-16 00:47 . 2007-10-07 04:56 -------- d-----w- c:\program files\Common Files\Apple
2009-04-30 02:19 . 2006-09-19 22:30 -------- d-----w- c:\program files\Microsoft Money 2006
2009-04-13 04:03 . 2006-09-19 22:05 66192 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-05 01:30 . 2006-09-19 22:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-04-05 01:20 . 2007-11-05 23:10 -------- d--h--r- c:\documents and settings\All Users\Application Data\yahoo!
2009-04-05 01:20 . 2006-09-19 22:46 -------- d-----w- c:\program files\Yahoo!
2009-04-05 00:31 . 2009-04-05 00:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-05 00:31 . 2006-09-19 20:58 -------- d-----w- c:\program files\Java
2009-03-28 19:35 . 2006-06-29 18:43 92819 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-26 20:49 . 2009-03-30 23:52 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 20:49 . 2009-03-30 23:52 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-08 08:34 . 2006-03-16 04:00 914944 ----a-w- c:\windows\system32\wininet.dll
2009-03-08 08:34 . 2006-03-16 04:00 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 08:33 . 2006-03-16 04:00 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 08:33 . 2006-03-16 04:00 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 08:32 . 2006-03-16 04:00 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 08:32 . 2006-03-16 04:00 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 08:31 . 2006-03-16 04:00 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 08:31 . 2006-03-16 04:00 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 08:31 . 2006-03-16 04:00 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 08:22 . 2006-03-16 04:00 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2006-03-16 04:00 284160 ----a-w- c:\windows\system32\pdh.dll
2008-06-13 22:08 . 2008-06-13 22:08 0 ----a-w- c:\program files\temp01
2006-12-26 02:51 . 2006-12-26 02:51 774144 ----a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-10 1838592]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-25 714608]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-08-18 1617920]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/25/2007 1:07 AM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/5/2009 5:18 PM 101936]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [6/6/2006 4:39 PM 61952]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [5/29/2007 4:55 PM 23888]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*NewlyCreated* - MBUDCCFV
*Deregistered* - mbudccfv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-03-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-05-19 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Melissa.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]
2009-05-08 c:\windows\Tasks\Norton Security Scan for Melissa.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 08:18]
.
- - - - ORPHANS REMOVED - - - -
BHO-{01E45C5E-5308-455E-8B01-F6A584957E69} - c:\windows\system32\urxdbrol.dll
BHO-{39fc2065-c9c7-49cd-8942-44cc2dedc844} - c:\windows\ieocx.dll
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - c:\progra~1\INBOXT~1\Inbox.dll
DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - hxxp://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-31 22:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????@? ??? ]??????Y?@?????@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1236)
c:\windows\system32\NTMARTA.DLL
- - - - - - - > 'explorer.exe'(4032)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\InstallShield\UpdateService\agent.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-06-01 22:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-01 02:58
Pre-Run: 36,952,145,920 bytes free
Post-Run: 38,129,074,176 bytes free
244 --- E O F --- 2009-05-14 02:59
- BelahzurSite Admin
-
OS : 7 Home Premium x64
Posts : 34948
Rubies : 218222
Likes : 18
Hello.
I see that you are running Limewire.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.
If Limewire is not removed, then I won't help you.
Go to Start > Control Panel > Add/Remove Programs and remove the following programs.
Now open a new notepad file.
Input this into the notepad file:
Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:

This will open combofix again, agree to it's terms and allow it to run.
It may want to reboot after it's done. (It will warn you if it wants to)
Post the resulting log back here.
I see that you are running Limewire.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.
If Limewire is not removed, then I won't help you.
Go to Start > Control Panel > Add/Remove Programs and remove the following programs.
- Limewire 4.18.8
Now open a new notepad file.
Input this into the notepad file:
KILLALL::
Driver::
mbudccfv
File::
c:\documents and settings\Melissa\Application Data\asd.bat
c:\docume~1\Melissa\APPLIC~1\asd.bat
c:\documents and settings\Melissa\Application Data\winav.exe
c:\docume~1\Melissa\APPLIC~1\winav.exe
Folder::
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk
c:\documents and settings\Melissa\Application Data\aebwsgmk
c:\docume~1\Melissa\APPLIC~1\aebwsgmk
c:\documents and settings\Melissa\Application Data\LimeWire
c:\docume~1\Melissa\APPLIC~1\LimeWire
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=-
"AntiVirusDisableNotify"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\LimeWire\\LimeWire.exe"=-
Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:

This will open combofix again, agree to it's terms and allow it to run.
It may want to reboot after it's done. (It will warn you if it wants to)
Post the resulting log back here.
Site Admin / Security Administrator
[Prework] - Please PM me if I fail to respond within 24hrs.


- bronbron81Intermediate
-
OS : Window Xp Media center edition 2005
Posts : 72
Rubies : 3606
Likes : 0
ComboFix 09-05-30.06 - Melissa 06/14/2009 19:21.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.173 [GMT -4:00]
Running from: c:\documents and settings\Melissa\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Melissa\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
FILE ::
"c:\docume~1\Melissa\APPLIC~1\asd.bat"
"c:\docume~1\Melissa\APPLIC~1\winav.exe"
"c:\documents and settings\Melissa\Application Data\asd.bat"
"c:\documents and settings\Melissa\Application Data\winav.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Melissa\APPLIC~1\aebwsgmk
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\profiles.ini
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\cert8.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\compatibility.ini
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\compreg.dat
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\cookies.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\formhistory.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\key3.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\localstore.rdf
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\permissions.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite-journal
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\pluginreg.dat
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\prefs.js
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\secmod.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\webappsstore.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\xpti.dat
c:\docume~1\Melissa\APPLIC~1\asd.bat
c:\docume~1\Melissa\APPLIC~1\LimeWire
c:\docume~1\Melissa\APPLIC~1\LimeWire\active.mojito
c:\docume~1\Melissa\APPLIC~1\LimeWire\certificate\limewire.keystore
c:\docume~1\Melissa\APPLIC~1\LimeWire\createtimes.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\downloads.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\fileurns.bak
c:\docume~1\Melissa\APPLIC~1\LimeWire\fileurns.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\filters.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\gnutella.net
c:\docume~1\Melissa\APPLIC~1\LimeWire\installation.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\library.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\limewire.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\mojito.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\passive.mojito
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.backup
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.data
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.lck
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.log
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.properties
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.script
c:\docume~1\Melissa\APPLIC~1\LimeWire\questions.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\responses.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\simpp.xml
c:\docume~1\Melissa\APPLIC~1\LimeWire\spam.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\tables.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme.lwtp
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\01_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\02_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\03_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\04_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\05_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\chat.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\forward_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\forward_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\kill.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\kill_on.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\pause_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\pause_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\play_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\play_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\question.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\rewind_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\rewind_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\stop_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\stop_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\theme.txt
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\version.txt
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\warning.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\ttrees.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\ttroot.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\version.xml
c:\docume~1\Melissa\APPLIC~1\LimeWire\versions.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\xml\data\audio.sxml2
c:\docume~1\Melissa\APPLIC~1\LimeWire\xml\data\video.sxml2
c:\docume~1\Melissa\APPLIC~1\winav.exe
c:\documents and settings\Melissa\Application Data\aebwsgmk\profiles.ini
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\cert8.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\compatibility.ini
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\compreg.dat
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\cookies.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\formhistory.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\key3.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\localstore.rdf
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\permissions.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite-journal
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\pluginreg.dat
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\prefs.js
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\secmod.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\webappsstore.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\xpti.dat
c:\documents and settings\Melissa\Application Data\asd.bat
c:\documents and settings\Melissa\Application Data\LimeWire\active.mojito
c:\documents and settings\Melissa\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Melissa\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Melissa\Application Data\LimeWire\downloads.dat
c:\documents and settings\Melissa\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Melissa\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Melissa\Application Data\LimeWire\filters.props
c:\documents and settings\Melissa\Application Data\LimeWire\gnutella.net
c:\documents and settings\Melissa\Application Data\LimeWire\installation.props
c:\documents and settings\Melissa\Application Data\LimeWire\library.dat
c:\documents and settings\Melissa\Application Data\LimeWire\limewire.props
c:\documents and settings\Melissa\Application Data\LimeWire\mojito.props
c:\documents and settings\Melissa\Application Data\LimeWire\passive.mojito
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.lck
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.log
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Melissa\Application Data\LimeWire\questions.props
c:\documents and settings\Melissa\Application Data\LimeWire\responses.cache
c:\documents and settings\Melissa\Application Data\LimeWire\simpp.xml
c:\documents and settings\Melissa\Application Data\LimeWire\spam.dat
c:\documents and settings\Melissa\Application Data\LimeWire\tables.props
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\01_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\02_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\03_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\04_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\05_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Melissa\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Melissa\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Melissa\Application Data\LimeWire\version.xml
c:\documents and settings\Melissa\Application Data\LimeWire\versions.props
c:\documents and settings\Melissa\Application Data\LimeWire\xml\data\audio.sxml2
c:\documents and settings\Melissa\Application Data\LimeWire\xml\data\video.sxml2
c:\documents and settings\Melissa\Application Data\winav.exe
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk\Profiles\9ji4sfue.default\urlclassifier3.sqlite
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk\Profiles\9ji4sfue.default\XPC.mfl
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.479.173 [GMT -4:00]
Running from: c:\documents and settings\Melissa\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Melissa\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
FILE ::
"c:\docume~1\Melissa\APPLIC~1\asd.bat"
"c:\docume~1\Melissa\APPLIC~1\winav.exe"
"c:\documents and settings\Melissa\Application Data\asd.bat"
"c:\documents and settings\Melissa\Application Data\winav.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Melissa\APPLIC~1\aebwsgmk
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\profiles.ini
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\cert8.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\compatibility.ini
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\compreg.dat
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\cookies.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\formhistory.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\key3.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\localstore.rdf
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\permissions.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite-journal
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\pluginreg.dat
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\prefs.js
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\secmod.db
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\webappsstore.sqlite
c:\docume~1\Melissa\APPLIC~1\aebwsgmk\Profiles\9ji4sfue.default\xpti.dat
c:\docume~1\Melissa\APPLIC~1\asd.bat
c:\docume~1\Melissa\APPLIC~1\LimeWire
c:\docume~1\Melissa\APPLIC~1\LimeWire\active.mojito
c:\docume~1\Melissa\APPLIC~1\LimeWire\certificate\limewire.keystore
c:\docume~1\Melissa\APPLIC~1\LimeWire\createtimes.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\downloads.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\fileurns.bak
c:\docume~1\Melissa\APPLIC~1\LimeWire\fileurns.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\filters.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\gnutella.net
c:\docume~1\Melissa\APPLIC~1\LimeWire\installation.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\library.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\limewire.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\mojito.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\passive.mojito
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.backup
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.data
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.lck
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.log
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.properties
c:\docume~1\Melissa\APPLIC~1\LimeWire\promotion\promodb.script
c:\docume~1\Melissa\APPLIC~1\LimeWire\questions.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\responses.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\simpp.xml
c:\docume~1\Melissa\APPLIC~1\LimeWire\spam.dat
c:\docume~1\Melissa\APPLIC~1\LimeWire\tables.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme.lwtp
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\01_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\02_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\03_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\04_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\05_star.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\chat.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\forward_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\forward_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\kill.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\kill_on.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\pause_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\pause_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\play_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\play_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\question.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\rewind_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\rewind_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\stop_dn.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\stop_up.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\theme.txt
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\version.txt
c:\docume~1\Melissa\APPLIC~1\LimeWire\themes\windows_theme\warning.gif
c:\docume~1\Melissa\APPLIC~1\LimeWire\ttrees.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\ttroot.cache
c:\docume~1\Melissa\APPLIC~1\LimeWire\version.xml
c:\docume~1\Melissa\APPLIC~1\LimeWire\versions.props
c:\docume~1\Melissa\APPLIC~1\LimeWire\xml\data\audio.sxml2
c:\docume~1\Melissa\APPLIC~1\LimeWire\xml\data\video.sxml2
c:\docume~1\Melissa\APPLIC~1\winav.exe
c:\documents and settings\Melissa\Application Data\aebwsgmk\profiles.ini
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\cert8.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\compatibility.ini
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\compreg.dat
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\cookies.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\formhistory.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\key3.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\localstore.rdf
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\permissions.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite-journal
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\places.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\pluginreg.dat
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\prefs.js
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\secmod.db
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\webappsstore.sqlite
c:\documents and settings\Melissa\Application Data\aebwsgmk\Profiles\9ji4sfue.default\xpti.dat
c:\documents and settings\Melissa\Application Data\asd.bat
c:\documents and settings\Melissa\Application Data\LimeWire\active.mojito
c:\documents and settings\Melissa\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Melissa\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Melissa\Application Data\LimeWire\downloads.dat
c:\documents and settings\Melissa\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Melissa\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Melissa\Application Data\LimeWire\filters.props
c:\documents and settings\Melissa\Application Data\LimeWire\gnutella.net
c:\documents and settings\Melissa\Application Data\LimeWire\installation.props
c:\documents and settings\Melissa\Application Data\LimeWire\library.dat
c:\documents and settings\Melissa\Application Data\LimeWire\limewire.props
c:\documents and settings\Melissa\Application Data\LimeWire\mojito.props
c:\documents and settings\Melissa\Application Data\LimeWire\passive.mojito
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.lck
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.log
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Melissa\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Melissa\Application Data\LimeWire\questions.props
c:\documents and settings\Melissa\Application Data\LimeWire\responses.cache
c:\documents and settings\Melissa\Application Data\LimeWire\simpp.xml
c:\documents and settings\Melissa\Application Data\LimeWire\spam.dat
c:\documents and settings\Melissa\Application Data\LimeWire\tables.props
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\01_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\02_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\03_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\04_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\05_star.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Melissa\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Melissa\Application Data\LimeWire\ttrees.cache
c:\documents and settings\Melissa\Application Data\LimeWire\ttroot.cache
c:\documents and settings\Melissa\Application Data\LimeWire\version.xml
c:\documents and settings\Melissa\Application Data\LimeWire\versions.props
c:\documents and settings\Melissa\Application Data\LimeWire\xml\data\audio.sxml2
c:\documents and settings\Melissa\Application Data\LimeWire\xml\data\video.sxml2
c:\documents and settings\Melissa\Application Data\winav.exe
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk\Profiles\9ji4sfue.default\urlclassifier3.sqlite
c:\documents and settings\Melissa\Local Settings\Application Data\aebwsgmk\Profiles\9ji4sfue.default\XPC.mfl
- bronbron81Intermediate
-
OS : Window Xp Media center edition 2005
Posts : 72
Rubies : 3606
Likes : 0
((((((((((((((((((((((((( Files Created from 2009-05-14 to 2009-06-14 )))))))))))))))))))))))))))))))
.
2009-05-16 00:47 . 2009-05-16 00:47 -------- d-----w- c:\program files\iPod
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\program files\iTunes
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-16 00:34 . 2009-05-16 00:34 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-16 00:32 . 2009-05-16 00:32 -------- d-----w- c:\program files\Safari
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2098-01-01 05:00 . 2007-12-25 15:18 9096 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\LUTPReg.dll
2098-01-01 05:00 . 2007-08-25 03:51 9584 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\WP20.dll
2098-01-01 05:00 . 2007-08-25 03:51 9584 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\IV20.dll
2098-01-01 05:00 . 2007-08-22 21:45 9048 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\FWLUReg.dll
2009-05-27 01:51 . 2008-03-22 17:07 -------- d-----w- c:\program files\Norton Security Scan
2009-05-27 01:14 . 2006-09-19 22:13 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-27 00:27 . 2006-09-19 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-05-16 00:47 . 2007-10-07 04:56 -------- d-----w- c:\program files\Common Files\Apple
2009-04-30 02:19 . 2006-09-19 22:30 -------- d-----w- c:\program files\Microsoft Money 2006
2009-04-13 04:03 . 2006-09-19 22:05 66192 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-05 00:31 . 2009-04-05 00:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-05 00:29 . 2009-04-05 00:29 152576 ----a-w- c:\documents and settings\Melissa\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-28 19:35 . 2006-06-29 18:43 92819 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-26 20:49 . 2009-03-30 23:52 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 20:49 . 2009-03-30 23:52 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-19 20:32 . 2009-03-19 20:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-06-13 22:08 . 2008-06-13 22:08 0 ----a-w- c:\program files\temp01
2006-12-26 02:51 . 2006-12-26 02:51 774144 ----a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-01_02.53.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-14 23:26 . 2009-06-14 23:26 16384 c:\windows\temp\Perflib_Perfdata_4b0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-10 1838592]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-25 714608]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-08-18 1617920]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/25/2007 1:07 AM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/5/2009 5:18 PM 101936]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [6/6/2006 4:39 PM 61952]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [5/29/2007 4:55 PM 23888]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
*Deregistered* - YahooAUService
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-03-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-05-19 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Melissa.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]
2009-05-08 c:\windows\Tasks\Norton Security Scan for Melissa.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 08:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - c:\progra~1\INBOXT~1\Inbox.dll
DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - hxxp://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-14 19:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????@? ??? ]??????Y?@?????@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4084)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-06-14 19:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-14 23:37
ComboFix2.txt 2009-06-01 02:59
Pre-Run: 37,993,279,488 bytes free
Post-Run: 37,949,100,032 bytes free
342 --- E O F --- 2009-05-14 02:59
.
2009-05-16 00:47 . 2009-05-16 00:47 -------- d-----w- c:\program files\iPod
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\program files\iTunes
2009-05-16 00:46 . 2009-05-16 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-16 00:34 . 2009-05-16 00:34 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-16 00:32 . 2009-05-16 00:32 -------- d-----w- c:\program files\Safari
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2098-01-01 05:00 . 2007-12-25 15:18 9096 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\LUTPReg.dll
2098-01-01 05:00 . 2007-08-25 03:51 9584 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\WP20.dll
2098-01-01 05:00 . 2007-08-25 03:51 9584 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\IV20.dll
2098-01-01 05:00 . 2007-08-22 21:45 9048 ----a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\FWLUReg.dll
2009-05-27 01:51 . 2008-03-22 17:07 -------- d-----w- c:\program files\Norton Security Scan
2009-05-27 01:14 . 2006-09-19 22:13 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-27 00:27 . 2006-09-19 22:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-05-16 00:47 . 2007-10-07 04:56 -------- d-----w- c:\program files\Common Files\Apple
2009-04-30 02:19 . 2006-09-19 22:30 -------- d-----w- c:\program files\Microsoft Money 2006
2009-04-13 04:03 . 2006-09-19 22:05 66192 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-05 00:31 . 2009-04-05 00:32 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-05 00:29 . 2009-04-05 00:29 152576 ----a-w- c:\documents and settings\Melissa\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-28 19:35 . 2006-06-29 18:43 92819 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-26 20:49 . 2009-03-30 23:52 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 20:49 . 2009-03-30 23:52 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-19 20:32 . 2009-03-19 20:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 20:32 . 2008-01-29 16:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2008-06-13 22:08 . 2008-06-13 22:08 0 ----a-w- c:\program files\temp01
2006-12-26 02:51 . 2006-12-26 02:51 774144 ----a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-01_02.53.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-14 23:26 . 2009-06-14 23:26 16384 c:\windows\temp\Perflib_Perfdata_4b0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="-" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-05 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-18 7585792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-18 86016]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 761946]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-10 1838592]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-25 714608]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-08-18 1617920]
"MsmqIntCert"="mqrt.dll" - c:\windows\system32\mqrt.dll [2008-04-14 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-06-02 61952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/25/2007 1:07 AM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [3/5/2009 5:18 PM 101936]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [6/6/2006 4:39 PM 61952]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [5/29/2007 4:55 PM 23888]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
*Deregistered* - YahooAUService
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-03-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-05-19 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Melissa.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-27 01:19]
2009-05-08 c:\windows\Tasks\Norton Security Scan for Melissa.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 08:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - c:\progra~1\INBOXT~1\Inbox.dll
DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} - hxxp://l.yimg.com/jh/games/web_games/sony/bewitched/main.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-14 19:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\Hewlett-Packard\Default Settings\cpqset.exe????????????@? ??? ]??????Y?@?????@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
"ImagePath"="-"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
"ImagePath"="-"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4084)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2009-06-14 19:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-14 23:37
ComboFix2.txt 2009-06-01 02:59
Pre-Run: 37,993,279,488 bytes free
Post-Run: 37,949,100,032 bytes free
342 --- E O F --- 2009-05-14 02:59
- BelahzurSite Admin
-
OS : 7 Home Premium x64
Posts : 34948
Rubies : 218222
Likes : 18
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:
ComboFix /u

This will also reset your restore points.
How is the machine running now?
ComboFix /u

This will also reset your restore points.
How is the machine running now?
Site Admin / Security Administrator
[Prework] - Please PM me if I fail to respond within 24hrs.


Similar topics
Create an account or log in to leave a reply
You need to be a member in order to leave a reply.
Page 1 of 1
Permissions in this forum:
You cannot reply to topics in this forum