Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 01-01-2008, 10:25 PM   #1 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


trojan downloader

Ok. I went through the five step process and here are my results. I am unable to update my operating system, it again tells me to contact my system administrator (which I have none because this is a personal computer) and gives me an error # 0x8DDD0003. The security software that I have on my computer is Trend Micro PC-cilin Internet Security 12?? My computer keeps trying to copy files and I cannot get to my add/remove program link or "My Computer" properties and my clock is messed up and I can't change any of that stuff because it tells me to contact my system administrator. I have attached my extra.txt file and had to attach the main.txt results of the deckard scan (Deckard.doc) because the text in this log was too many characters. Below are the results of my active scan log and my main.txt. Hopefully this info can help. Thanks.

active scan

Incident Status Location

Adware:adware/portalscan Not disinfected c:\program files\STC
Adware:adware/seekmo Not disinfected Windows Registry
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.go.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.go.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.go.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.overture.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Golden Palace Online Casino Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.www.goldenpalace.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.phg.hitbox.com/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.targetnet.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.stat.onestat.com/]
Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.metriweb.be/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.ehg.hitbox.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.ehg-eline.hitbox.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.com.com/]
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.counter.hitslink.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.bfast.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.centrport.net/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Scott M. Bantel\Application Data\Mozilla\Firefox\Profiles\71ue8opw.default\cookies.txt[.c.enhance.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@adopt.hbmediapro[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@atdmt[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@belnk[1].txt
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@bfast[2].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@c.enhance[1].txt
Spyware:Cookie/Barelylegal Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@c.fsx[2].txt
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@centrport[1].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@clickbank[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@com[1].txt
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@counter.hitslink[2].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@ehg-eline.hitbox[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[10].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[11].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[12].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[13].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[14].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[15].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[16].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[17].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[18].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[19].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[20].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[21].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[22].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[23].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[24].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[25].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[26].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[27].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[28].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[29].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[30].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[31].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[32].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[33].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[34].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[35].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[36].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[37].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[38].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[39].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[3].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[40].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[4].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[5].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[6].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[7].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[8].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@go[9].txt
Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@metriweb[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@perf.overture[1].txt
Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@spylog[1].txt
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@targetnet[2].txt
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@tradedoubler[2].txt
Spyware:Cookie/Golden Palace Online Casino Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m. bantel@www.goldenpalace[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott m[60].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@112.2o7[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@247realmedia[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@adrevolver[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@ads.addynamix[1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@ads.pointroll[1].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@adserver.easyad[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@adtech[2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@adultfriendfinder[2].txt
Spyware:Cookie/AdvancedCleaner Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@advancedcleaner[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@advertising[2].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@apmebf[2].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@as-eu.falkag[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@atwola[1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@azjmp[1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@bravenet[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@bs.serving-sys[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@burstnet[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@casalemedia[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@ccbill[1].txt
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@citi.bridgetrack[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter1.sextracker[2].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter10.sextracker[2].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter13.sextracker[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter14.sextracker[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter15.sextracker[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter2.sextracker[2].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter3.sextracker[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter4.sextracker[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter5.sextracker[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter6.sextracker[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter8.sextracker[1].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@counter9.sextracker[1].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@cs.sexcounter[2].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@did-it[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@dist.belnk[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@doubleclick[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@drivecleaner[2].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@ehg-dig.hitbox[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@ehg.hitbox[1].txt
Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@entrepreneur[1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@errorsafe[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@fastclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@findwhat[1].txt
Spyware:Cookie/Comclick Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@fl01.ct2.comclick[2].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@fortunecity[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@gostats[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[10].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[11].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[3].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[4].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[5].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[6].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[7].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[8].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@go[9].txt
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@hc2.humanclick[2].txt
Spyware:Cookie/Kmpads Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@kmpads[2].txt
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@landing.domainsponsor[2].txt
Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@linksynergy[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@maxserving[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@media.adrevolver[3].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@mediaplex[2].txt
Spyware:Cookie/Outster Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@outster[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@overture[1].txt
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@paycounter[2].txt
Spyware:Cookie/Peel Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@peel[2].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@phg.hitbox[2].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@questionmarket[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@realmedia[2].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@revenue[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@searchportal.information[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@server.iad.liveperson[4].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@serving-sys[2].txt
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@sexlist[2].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@sextracker[1].txt
Spyware:Cookie/Smartadserver Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@smartadserver[1].txt
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@stat.onestat[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@statcounter[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@stats.drivecleaner[2].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@statse.webtrendslive[4].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@target[1].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@tickle[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@toplist[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@tribalfusion[2].txt
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@valueclick[1].txt
Spyware:Cookie/AntiVirGear Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@www.antivirgear[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@www.burstbeacon[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@www.drivecleaner[1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@www.errorsafe[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@www3.addfreestats[2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@www5.addfreestats[2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@yadro[2].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@z1.adserver[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Scott M. Bantel\Cookies\scott_m._bantel@zedo[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Scott M. Bantel\Desktop\SmitfraudFix\Process.exe
Virus:Trj/Rebooter.J Disinfected C:\Documents and Settings\Scott M. Bantel\Desktop\SmitfraudFix\Reboot.exe
Potentially unwanted tool:Application/SuperFast Not disinfected C:\Documents and Settings\Scott M. Bantel\Desktop\SmitfraudFix\restart.exe
Virus:Trj/Rebooter.J Disinfected C:\Documents and Settings\Scott M. Bantel\Desktop\SmitfraudFix.exe
Possible Virus. Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\9bd9b4hpd9b4a.exe
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@ads.pointroll[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@dist.belnk[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@doubleclick[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@ehg-dig.hitbox[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@go[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@mediaplex[2].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@questionmarket[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temp\Cookies\scott m. bantel@tribalfusion[1].txt
Possible Virus. Not disinfected C:\Documents and Settings\Scott M. Bantel\Local Settings\Temporary Internet Files\Content.IE5\QRZCSY4R\install[1].exe
Virus:Trj/Rebooter.J Disinfected C:\Documents and Settings\Scott M. Bantel\My Documents\SmitfraudFix.exe
Adware:Adware/Seekmo Not disinfected C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll
Adware:Adware/Seekmo Not disinfected C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTBUninstaller.exe
Virus:Eicar.Mod Not disinfected C:\Program Files\Trend Micro\Internet Security 12\tmhelp.chm[/PCC12/Test_virus.htm]
Adware:Adware/Zango Not disinfected C:\WINDOWS\Downloaded Program Files\ClientAX.dll
Possible Virus. Not disinfected C:\WINDOWS\system32\dllcache\beep.sys
Possible Virus. Not disinfected C:\WINDOWS\system32\drivers\beep.sys
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Adware:Adware/VirusAlarma Not disinfected C:\WINDOWS\system32\user32.dat
Attached Files
File Type: txt extra.txt (22.9 KB, 0 views)
File Type: doc Deckard.doc (58.5 KB, 3 views)
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 01-02-2008, 01:11 PM   #2 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

For easier viewing:

Deckard's System Scanner v20071014.68
Run by Scott M. Bantel on 2008-01-01 05:38:46
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
81: 2008-01-01 10:39:00 UTC - RP647 - Deckard's System Scanner Restore Point
80: 2008-01-01 07:54:20 UTC - RP646 - System Checkpoint
79: 2007-12-31 05:55:24 UTC - RP645 - System Checkpoint
78: 2007-12-30 03:54:18 UTC - RP644 - System Checkpoint
77: 2007-12-29 01:55:23 UTC - RP643 - System Checkpoint


-- First Restore Point --
1: 2007-10-13 13:54:48 UTC - RP567 - Installed InitTool


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Scott M. Bantel.exe) -------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:41:34 AM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Scott M. Bantel\Local Settings\Temporary Internet Files\Content.IE5\U3V7O9LM\dss[1].exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\TRENDM~1\HIJACK~1\Scott M. Bantel.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bengals.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [DIGServices] "C:\Program Files\ESPNRunTime\DIGServices.exe" /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [REGSHAVE] "C:\Program Files\REGSHAVE\REGSHAVE.EXE" /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Medichi] medichi.exe
O4 - HKLM\..\Run: [Medichi2] medichi2.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O20 - AppInit_DLLs: murka.dat
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 11312 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R1 omci (OMCI WDM Device Driver) - c:\windows\system32\drivers\omci.sys <Not Verified; Dell Inc; OMCI Driver>
R1 tmtdi (Trend Micro TDI Driver) - c:\windows\system32\drivers\tmtdi.sys <Not Verified; Trend Micro Inc.; Trend Micro Network Security Component 1.0>
R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.2.0.3) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.2.0.3>
R2 HPFECP13 - c:\windows\system32\drivers\hpfecp13.sys
R2 MASPINT - c:\windows\system32\drivers\maspint.sys <Not Verified; MicroStaff Co.,Ltd.; Aspi32 Driver for WinNT>
R2 tm_cfw (Common Firewall Driver) - c:\windows\system32\drivers\tm_cfw.sys <Not Verified; Trend Micro Inc.; Trend Network Security Component 1.0>

S3 DSproct - c:\program files\dellsupport\gtaction\triggers\dsproct.sys <Not Verified; Gteko Ltd.; processt>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 NICCONFIGSVC - c:\program files\dell\nicconfigsvc\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>
R2 Tmntsrv (Trend Micro Real-time Service) - c:\progra~1\trendm~1\intern~1\tmntsrv.exe <Not Verified; Trend Micro Incorporated.; Trend Micro Internet Security>
R2 TmPfw (Trend Micro Personal Firewall) - c:\progra~1\trendm~1\intern~1\tmpfw.exe <Not Verified; Trend Micro Inc.; Trend Network Security Component 1.0>
R2 tmproxy (Trend Micro Proxy Service) - c:\progra~1\trendm~1\intern~1\tmproxy.exe <Not Verified; Trend Micro Inc.; Trend Micro Network Security Components 1.0>
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>

S2 PcCtlCom (Trend Micro Central Control Component) - c:\progra~1\trendm~1\intern~1\pcctlcom.exe


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Parallel Device
Device ID: ROOT\LEGACY_HPFECP13\0000
Manufacturer:
Name: Parallel Device
PNP Device ID: ROOT\LEGACY_HPFECP13\0000
Service: HPFECP13

Class GUID:
Description:
Device ID: ROOT\LEGACY_NPF\0000
Manufacturer:
Name:
PNP Device ID: ROOT\LEGACY_NPF\0000
Service:


-- Scheduled Tasks -------------------------------------------------------------

2007-12-28 14:52:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


-- Files created between 2007-12-01 and 2008-01-01 -----------------------------

2008-01-01 15:34:40 6144 --a------ C:\WINDOWS\system32\user32.dat
2008-01-01 15:34:12 6144 --a------ C:\WINDOWS\murka.dat
2008-01-01 15:34:12 8192 --a------ C:\WINDOWS\medichi2.exe
2008-01-01 15:34:12 5632 --a------ C:\WINDOWS\medichi.exe
2008-01-01 10:48:10 0 d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 10:48:08 0 d-------- C:\WINDOWS\LastGood
2008-01-01 0757 0 d-------- C:\ie-spyad_zo
2008-01-01 07:03:28 0 d-------- C:\Program Files\SpywareBlaster


-- Find3M Report ---------------------------------------------------------------

2008-01-01 16:27:01 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-01-01 16:25:24 0 d-------- C:\Program Files\iTunes
2008-01-01 16:24:35 0 d-------- C:\Program Files\GoogleAFE
2008-01-01 16:24:35 0 d-------- C:\Program Files\Google
2008-01-01 16:24:10 0 d-------- C:\Program Files\ESPNRunTime
2008-01-01 16:23:53 0 d-------- C:\Program Files\DIGStream
2008-01-01 16:23:53 0 d-------- C:\Program Files\Digital Line Detect
2008-01-01 16:18:54 0 d-------- C:\Program Files\Apoint
2008-01-01 16:18:37 0 d-------- C:\Program Files\AIM6
2008-01-01 05:41:15 0 d-------- C:\Program Files\Trend Micro
2007-11-23 16:53:47 0 d-------- C:\Program Files\iPod
2007-11-23 16:51:31 0 d-------- C:\Program Files\QuickTime
2007-10-10 22:09:20 4452 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-03 23:36:46 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [01/31/2005 05:35 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [03/14/2007 02:43 AM]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [04/05/2005 09:05 PM]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [02/23/2005 05:19 PM]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [12/06/2004 02:05 AM]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [06/10/2005 11:44 AM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [06/10/2005 11:44 AM]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [01/27/2005 02:02 AM]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [09/08/2005 08:20 PM]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [08/30/2005 05:30 PM]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [02/08/2006 02:09 AM]
"HostManager"="C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe" [05/09/2006 07:24 PM]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [10/31/2005 11:05 AM]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [10/31/2005 11:18 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [04/03/2006 09:28 AM]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [06/06/2005 10:46 PM]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [02/17/2006 11:59 AM]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [02/04/2002 09:32 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [11/14/2007 11:43 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [11/15/2007 01:11 PM]
"Medichi"="medichi.exe" [01/01/2008 12:52 PM C:\WINDOWS\medichi.exe]
"Medichi2"="medichi2.exe" [01/01/2008 12:52 PM C:\WINDOWS\medichi2.exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [04/11/2006 07:39 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 06:00 AM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [10/04/2007 10:20 AM]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [04/22/2003 04:43 AM]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 10:09 AM]

C:\Documents and Settings\Scott M. Bantel\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [10/13/2007 8:54:28 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2/8/2006 1:59:48 AM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2/8/2006 1:55:11 AM]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [8/11/2004 1:22:40 AM]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2/13/2004 1:12:08 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 12:01:04 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=1 (0x1)
"DisableTaskMgr"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=1 (0x1)
"DisableTaskMgr"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoControlPanel"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoControlPanel"=1 (0x1)
"NoWindowsUpdate"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=murka.dat

*Newly Created Service* - RKPAVPROC



-- End of Deckard's System Scanner: finished at 2008-01-01 05:42:33 ------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-02-2008, 01:21 PM   #3 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

---------------------------------------------------------------------------------------------
  1. Download combofix.exe to your desktop. We'll use this shortly.
  2. Download SDFix and save it to your Desktop.
  3. Disconnect from the internet....pull the plug!


    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)


    Please then reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.

    • Open the extracted SDFix folder and double click RunThis.cmd to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard ready for posting back on the forum).
    • Post that log, C:\SDFix\report.txt , in your next reply at the end of this fix.


    Once SDFix has finished it's routine, run ComboFix:
  4. Disable your real time protection of your Anti-Virus. Exit the program via the SystemTray icon.
  5. Double click on combofix.exe & follow the prompts. Type "1" and press Enter to begin the scan.
  6. When finished, it shall produce a log for you. Post that log in your next reply.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall


    ---------------------------------------------------------------------------------------------
  7. Re-enable your Anti-Virus if it is not active...a reboot should have re-activated it.
  8. Re-establish an internet connection.
  9. Open HijackThis (not DSS) and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

    ---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-02-2008, 09:33 PM   #4 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


Re: trojan downloader

Ok, I went through the process and have copied the report and log onto this entry. The only problem I had was that I went to www.hijackthis.com but couldn't find a 'Do a System Scan and save a Logfile' to click on (the last step)...Let me know if there is something I am doing wrong or something else I need to do. Everything appears to be working fine, but like I said, I couldn't figure out the last step. Thanks for the help and below are the report and the log.


SDFix: Version 1.122

Run by Scott M. Bantel on Thu 01/03/2008 at 04:57 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

No Trojan Files Found





Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 17:04:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
---------------


Files with Hidden Attributes:

Wed 1 Sep 2004 54,384 A..H. --- "C:\Program Files\America Online 9.0\aolphx.exe"
Wed 1 Sep 2004 156,784 A..H. --- "C:\Program Files\America Online 9.0\aoltray.exe"
Wed 1 Sep 2004 31,344 A..H. --- "C:\Program Files\America Online 9.0\RBM.exe"
Tue 21 Aug 2007 56 ..SHR --- "C:\WINDOWS\system32\3A178CC52C.sys"
Tue 21 Aug 2007 3,766 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sat 14 Oct 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 30 Nov 2004 25,600 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Civ Prac\~WRL1267.tmp"
Tue 30 Nov 2004 26,624 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Civ Prac\~WRL2065.tmp"
Tue 30 Nov 2004 24,576 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Civ Prac\~WRL2177.tmp"
Tue 30 Nov 2004 25,088 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Civ Prac\~WRL2582.tmp"
Tue 30 Nov 2004 25,600 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Civ Prac\~WRL3747.tmp"
Tue 10 Jul 2007 28,672 ...H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Family\~WRL1106.tmp"
Wed 14 Sep 2005 20,480 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Financials\~WRL0001.tmp"
Fri 3 Feb 2006 62,976 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Moot Court\~WRL0001.tmp"
Fri 3 Feb 2006 62,976 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Moot Court\~WRL0005.tmp"
Fri 3 Feb 2006 64,512 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Moot Court\~WRL1618.tmp"
Fri 3 Feb 2006 62,976 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Moot Court\~WRL1927.tmp"
Fri 3 Feb 2006 62,976 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Moot Court\~WRL2557.tmp"
Fri 3 Feb 2006 63,488 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Moot Court\~WRL2633.tmp"
Fri 3 Feb 2006 64,512 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Moot Court\~WRL3541.tmp"
Thu 3 Feb 2005 33,280 A..H. --- "C:\Documents and Settings\Scott M. Bantel\My Documents\Resume and Cover letters\~WRL0003.tmp"
Fri 12 Nov 2004 37,376 ...H. --- "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"
Mon 19 Nov 2007 1,356 A..H. --- "C:\Program Files\Common Files\AOL\IPHSend\IPH.BAK"
Tue 1 Jan 2008 0 A..H. --- "C:\Deckard\System Scanner\backup\DOCUME~1\SCOTTM~1.BAN\LOCALS~1\Temp\9bd9b4hpd9b40.exe"
Thu 11 May 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Scott M. Bantel\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Scott M. Bantel\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Scott M. Bantel\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Sat 21 Apr 2007 8 A..H. --- "C:\Documents and Settings\Scott M. Bantel\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

Finished!


ComboFix 08-01-03.4 - Scott M. Bantel 2008-01-03 17:12:03.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.209 [GMT -5:00]
Running from: C:\Documents and Settings\Scott M. Bantel\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-03 16:52 . 2008-01-03 16:52 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-01 16:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 10:48 . 2008-01-01 16:46 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 10:48 . 2008-01-01 04:10 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-01 10:48 . 2008-01-01 04:10 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-01 10:48 . 2008-01-01 04:10 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-01 07:06 . 2008-01-01 07:06 <DIR> d-------- C:\ie-spyad_zo
2008-01-01 07:03 . 2008-01-01 07:03 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-01 07:03 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-01 05:38 . 2008-01-01 05:38 <DIR> d-------- C:\Deckard
2007-12-19 08:11 . 2007-12-19 08:11 23,405,072 --a------ C:\Program Files\AdbeRdr811_en_US.exe
2007-12-19 08:10 . 2007-12-19 08:10 711,024 --a------ C:\Program Files\DE04.ZIP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-01 21:27 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-01 21:25 --------- d-----w C:\Program Files\iTunes
2008-01-01 21:24 --------- d-----w C:\Program Files\GoogleAFE
2008-01-01 21:24 --------- d-----w C:\Program Files\Google
2008-01-01 21:24 --------- d-----w C:\Program Files\ESPNRunTime
2008-01-01 21:23 --------- d-----w C:\Program Files\DIGStream
2008-01-01 21:23 --------- d-----w C:\Program Files\Digital Line Detect
2008-01-01 21:18 --------- d-----w C:\Program Files\Apoint
2008-01-01 21:18 --------- d-----w C:\Program Files\AIM6
2008-01-01 10:41 --------- d-----w C:\Program Files\Trend Micro
2007-11-23 21:53 --------- d-----w C:\Program Files\iPod
2007-11-23 21:51 --------- d-----w C:\Program Files\QuickTime
2007-11-14 12:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 03:09 4,452 ----a-w C:\WINDOWS\system32\tmp.reg
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-10-04 04:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
2006-02-16 23:03 405,568 ----a-w C:\Program Files\AOLDNLD.exe
2006-01-25 13:57 1,696 ----a-w C:\Program Files\main.ini
2006-01-25 13:57 1,001,064 ----a-w C:\Program Files\aolsetup.exe
2007-08-21 16:27 56 --sh--r C:\WINDOWS\system32\3A178CC52C.sys
2007-08-21 16:27 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-01-03_16.31.59.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-03 21:52:28 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:28 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-03 21:52:14 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:14 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 19:39 176201]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-22 04:43 413775]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 17:35 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 21:05 339968]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 02:02 86016]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 20:20 8192]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30 823362]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-08 02:09 168448]
"HostManager"="C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 11:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 11:18 101888]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-03 09:28 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]

C:\Documents and Settings\Scott M. Bantel\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-13 08:54:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-02-08 01:59:48]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-02-08 01:55:11]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 01:22:40]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

R2 HPFECP13;HPFECP13;C:\WINDOWS\system32\drivers\HPFECP13.SYS [1999-04-09 02:07]
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-01-29 00:39]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-28 19:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 17:13:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-03 17:13:54
ComboFix-quarantined-files.txt 2008-01-03 22:13:38
ComboFix2.txt 2008-01-03 21:32:18
.
2007-12-12 08:04:36 --- E O F ---
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-02-2008, 10:00 PM   #5 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

HijackThis should have been installed on your machine by DSS. That website you visited has nothing to do with HijackThis.

On your desktop, there should be a shortcut to HijackThis. It should look like this:



Or, go to Start > Run and type HijackThis.exe then press Enter

Or, go to C:\Program Files\Trend Micro\HijackThis and double click on the .exe file to run it.

It looks like you ran ComboFix twice.

Please go to Start > Run and copy/paste the following, then press Enter.

"C:\Qoobox\ComboFix2.txt"

A notepad file should open.

Post the contents of that log in your next reply, along with a new HijackThis log.

If you cannot find HIjackThis still, do this:

Please download HijackThis to your desktop

Alternate link

Double-click on the file you just downloaded.
Click on the "Unzip" button to install. It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis

Upon install, HijackThis should open for you.

Should it not open, navigate to C:\Program Files\Trend Micro\HijackThis and double click on HijackThis.exe

1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'.
2. If you don't get the intro screen, just hit Scan and then click on Save log.
3. Post the hijackthis.log file here. Do not fix anything in HijackThis since they may be harmless.

---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-03-2008, 07:05 PM   #6 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


Re: trojan downloader

Ok, here are the results from the combofix2 and the hijackthis log. Let me know if there is anything else I should/need to do. Thanks again for your help.

ComboFix 08-01-03.4 - Scott M. Bantel 2008-01-03 17:12:03.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.209 [GMT -5:00]
Running from: C:\Documents and Settings\Scott M. Bantel\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-03 16:52 . 2008-01-03 16:52 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-01 16:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 10:48 . 2008-01-01 16:46 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 10:48 . 2008-01-01 04:10 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-01 10:48 . 2008-01-01 04:10 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-01 10:48 . 2008-01-01 04:10 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-01 07:06 . 2008-01-01 07:06 <DIR> d-------- C:\ie-spyad_zo
2008-01-01 07:03 . 2008-01-01 07:03 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-01 07:03 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-01 05:38 . 2008-01-01 05:38 <DIR> d-------- C:\Deckard
2007-12-19 08:11 . 2007-12-19 08:11 23,405,072 --a------ C:\Program Files\AdbeRdr811_en_US.exe
2007-12-19 08:10 . 2007-12-19 08:10 711,024 --a------ C:\Program Files\DE04.ZIP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-01 21:27 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-01 21:25 --------- d-----w C:\Program Files\iTunes
2008-01-01 21:24 --------- d-----w C:\Program Files\GoogleAFE
2008-01-01 21:24 --------- d-----w C:\Program Files\Google
2008-01-01 21:24 --------- d-----w C:\Program Files\ESPNRunTime
2008-01-01 21:23 --------- d-----w C:\Program Files\DIGStream
2008-01-01 21:23 --------- d-----w C:\Program Files\Digital Line Detect
2008-01-01 21:18 --------- d-----w C:\Program Files\Apoint
2008-01-01 21:18 --------- d-----w C:\Program Files\AIM6
2008-01-01 10:41 --------- d-----w C:\Program Files\Trend Micro
2007-11-23 21:53 --------- d-----w C:\Program Files\iPod
2007-11-23 21:51 --------- d-----w C:\Program Files\QuickTime
2007-11-14 12:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 03:09 4,452 ----a-w C:\WINDOWS\system32\tmp.reg
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-10-04 04:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
2006-02-16 23:03 405,568 ----a-w C:\Program Files\AOLDNLD.exe
2006-01-25 13:57 1,696 ----a-w C:\Program Files\main.ini
2006-01-25 13:57 1,001,064 ----a-w C:\Program Files\aolsetup.exe
2007-08-21 16:27 56 --sh--r C:\WINDOWS\system32\3A178CC52C.sys
2007-08-21 16:27 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-01-03_16.31.59.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-03 21:52:28 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:28 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-03 21:52:14 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:14 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 19:39 176201]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-22 04:43 413775]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 17:35 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 21:05 339968]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 02:02 86016]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 20:20 8192]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30 823362]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-08 02:09 168448]
"HostManager"="C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 11:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 11:18 101888]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-03 09:28 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]

C:\Documents and Settings\Scott M. Bantel\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-13 08:54:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-02-08 01:59:48]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-02-08 01:55:11]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 01:22:40]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

R2 HPFECP13;HPFECP13;C:\WINDOWS\system32\drivers\HPFECP13.SYS [1999-04-09 02:07]
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-01-29 00:39]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-28 19:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 17:13:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-03 17:13:54
ComboFix-quarantined-files.txt 2008-01-03 22:13:38
ComboFix2.txt 2008-01-03 21:32:18
.
2007-12-12 08:04:36 --- E O F ---


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:33:15 PM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bengals.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [DIGServices] "C:\Program Files\ESPNRunTime\DIGServices.exe" /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [REGSHAVE] "C:\Program Files\REGSHAVE\REGSHAVE.EXE" /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 10554 bytes
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-03-2008, 07:27 PM   #7 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

Seems like the same ComboFix log. Note the time stamp of both:

ComboFix 08-01-03.4 - Scott M. Bantel 2008-01-03 17:12:03.2 - NTFSx86

Did you run the command I posted, or search for the file yourself?
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-03-2008, 09:04 PM   #8 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


Re: trojan downloader

It shouldn't be the same log. Apparently I ran the combo fix twice last night, so I followed the directions you gave me for that tonight, and then I was able to find the hijackthis through your instructions and ran the hijackthis log tonight as well.
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-03-2008, 09:12 PM   #9 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

You ran it again after I asked for ComboFix2?

Do this...

Run a Windows search for ComboFix*.txt

Open each one, and post them.

I'm trying to see what removed the infections.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-09-2008, 10:00 PM   #10 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


Re: trojan downloader

I apologize it took me so long to get back, I had to go out of town. I ran the search for combofix.txt and below I have posted what came up. I think they are both the same. Let me know if I should do anything else. Thanks.

ComboFix 08-01-03.4 - Scott M. Bantel 2008-01-03 17:16:16.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.188 [GMT -5:00]
Running from: C:\Documents and Settings\Scott M. Bantel\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-03 16:52 . 2008-01-03 16:52 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-01 16:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 10:48 . 2008-01-01 16:46 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 10:48 . 2008-01-01 04:10 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-01 10:48 . 2008-01-01 04:10 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-01 10:48 . 2008-01-01 04:10 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-01 07:06 . 2008-01-01 07:06 <DIR> d-------- C:\ie-spyad_zo
2008-01-01 07:03 . 2008-01-01 07:03 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-01 07:03 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-01 05:38 . 2008-01-01 05:38 <DIR> d-------- C:\Deckard
2007-12-19 08:11 . 2007-12-19 08:11 23,405,072 --a------ C:\Program Files\AdbeRdr811_en_US.exe
2007-12-19 08:10 . 2007-12-19 08:10 711,024 --a------ C:\Program Files\DE04.ZIP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-01 21:27 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-01 21:25 --------- d-----w C:\Program Files\iTunes
2008-01-01 21:24 --------- d-----w C:\Program Files\GoogleAFE
2008-01-01 21:24 --------- d-----w C:\Program Files\Google
2008-01-01 21:24 --------- d-----w C:\Program Files\ESPNRunTime
2008-01-01 21:23 --------- d-----w C:\Program Files\DIGStream
2008-01-01 21:23 --------- d-----w C:\Program Files\Digital Line Detect
2008-01-01 21:18 --------- d-----w C:\Program Files\Apoint
2008-01-01 21:18 --------- d-----w C:\Program Files\AIM6
2008-01-01 10:41 --------- d-----w C:\Program Files\Trend Micro
2007-11-23 21:53 --------- d-----w C:\Program Files\iPod
2007-11-23 21:51 --------- d-----w C:\Program Files\QuickTime
2007-11-14 12:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 03:09 4,452 ----a-w C:\WINDOWS\system32\tmp.reg
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-10-04 04:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
2006-02-16 23:03 405,568 ----a-w C:\Program Files\AOLDNLD.exe
2006-01-25 13:57 1,696 ----a-w C:\Program Files\main.ini
2006-01-25 13:57 1,001,064 ----a-w C:\Program Files\aolsetup.exe
2007-08-21 16:27 56 --sh--r C:\WINDOWS\system32\3A178CC52C.sys
2007-08-21 16:27 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-01-03_16.31.59.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-03 21:52:28 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:28 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-03 21:52:14 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:14 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 19:39 176201]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-22 04:43 413775]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 17:35 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 21:05 339968]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 02:02 86016]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 20:20 8192]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30 823362]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-08 02:09 168448]
"HostManager"="C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 11:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 11:18 101888]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-03 09:28 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]

C:\Documents and Settings\Scott M. Bantel\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-13 08:54:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-02-08 01:59:48]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-02-08 01:55:11]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 01:22:40]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

R2 HPFECP13;HPFECP13;C:\WINDOWS\system32\drivers\HPFECP13.SYS [1999-04-09 02:07]
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-01-29 00:39]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-28 19:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 17:16:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-03 17:17:34
ComboFix-quarantined-files.txt 2008-01-03 22:17:18
ComboFix2.txt 2008-01-03 22:13:55
ComboFix3.txt 2008-01-03 21:32:18
.
2007-12-12 08:04:36 --- E O F ---

ComboFix 08-01-03.4 - Scott M. Bantel 2008-01-03 17:16:16.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.188 [GMT -5:00]
Running from: C:\Documents and Settings\Scott M. Bantel\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-03 16:52 . 2008-01-03 16:52 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-01 16:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 10:48 . 2008-01-01 16:46 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 10:48 . 2008-01-01 04:10 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-01 10:48 . 2008-01-01 04:10 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-01 10:48 . 2008-01-01 04:10 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-01 07:06 . 2008-01-01 07:06 <DIR> d-------- C:\ie-spyad_zo
2008-01-01 07:03 . 2008-01-01 07:03 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-01 07:03 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-01 05:38 . 2008-01-01 05:38 <DIR> d-------- C:\Deckard
2007-12-19 08:11 . 2007-12-19 08:11 23,405,072 --a------ C:\Program Files\AdbeRdr811_en_US.exe
2007-12-19 08:10 . 2007-12-19 08:10 711,024 --a------ C:\Program Files\DE04.ZIP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-01 21:27 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-01 21:25 --------- d-----w C:\Program Files\iTunes
2008-01-01 21:24 --------- d-----w C:\Program Files\GoogleAFE
2008-01-01 21:24 --------- d-----w C:\Program Files\Google
2008-01-01 21:24 --------- d-----w C:\Program Files\ESPNRunTime
2008-01-01 21:23 --------- d-----w C:\Program Files\DIGStream
2008-01-01 21:23 --------- d-----w C:\Program Files\Digital Line Detect
2008-01-01 21:18 --------- d-----w C:\Program Files\Apoint
2008-01-01 21:18 --------- d-----w C:\Program Files\AIM6
2008-01-01 10:41 --------- d-----w C:\Program Files\Trend Micro
2007-11-23 21:53 --------- d-----w C:\Program Files\iPod
2007-11-23 21:51 --------- d-----w C:\Program Files\QuickTime
2007-11-14 12:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 03:09 4,452 ----a-w C:\WINDOWS\system32\tmp.reg
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-10-04 04:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
2006-02-16 23:03 405,568 ----a-w C:\Program Files\AOLDNLD.exe
2006-01-25 13:57 1,696 ----a-w C:\Program Files\main.ini
2006-01-25 13:57 1,001,064 ----a-w C:\Program Files\aolsetup.exe
2007-08-21 16:27 56 --sh--r C:\WINDOWS\system32\3A178CC52C.sys
2007-08-21 16:27 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-01-03_16.31.59.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-03 21:52:28 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:28 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-03 21:52:14 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:14 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 19:39 176201]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-22 04:43 413775]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 17:35 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 21:05 339968]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 02:02 86016]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 20:20 8192]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30 823362]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-08 02:09 168448]
"HostManager"="C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 11:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 11:18 101888]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-03 09:28 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]

C:\Documents and Settings\Scott M. Bantel\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-13 08:54:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-02-08 01:59:48]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-02-08 01:55:11]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 01:22:40]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

R2 HPFECP13;HPFECP13;C:\WINDOWS\system32\drivers\HPFECP13.SYS [1999-04-09 02:07]
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-01-29 00:39]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-28 19:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 17:16:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-03 17:17:34
ComboFix-quarantined-files.txt 2008-01-03 22:17:18
ComboFix2.txt 2008-01-03 22:13:55
ComboFix3.txt 2008-01-03 21:32:18
.
2007-12-12 08:04:36 --- E O F ---
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-09-2008, 10:11 PM   #11 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

Well, I asked for all the logs to be posted, but we're not getting very far that way.

Post a new HijackThis log.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-14-2008, 07:24 PM   #12 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


Re: trojan downloader

Well, I apologize for frustrating you. I thought I had done exactly what you asked me to do. Below is your last post to me:

You ran it again after I asked for ComboFix2?
Do this...
Run a Windows search for ComboFix*.txt
Open each one, and post them.
I'm trying to see what removed the infections.

I ran a windows search for ComboFix*.txt and below is everything that came up.

ComboFix 08-01-03.4 - Scott M. Bantel 2008-01-03 17:12:03.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.209 [GMT -5:00]
Running from: C:\Documents and Settings\Scott M. Bantel\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-03 16:52 . 2008-01-03 16:52 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-01 16:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 10:48 . 2008-01-01 16:46 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 10:48 . 2008-01-01 04:10 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-01 10:48 . 2008-01-01 04:10 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-01 10:48 . 2008-01-01 04:10 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-01 07:06 . 2008-01-01 07:06 <DIR> d-------- C:\ie-spyad_zo
2008-01-01 07:03 . 2008-01-01 07:03 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-01 07:03 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-01 05:38 . 2008-01-01 05:38 <DIR> d-------- C:\Deckard
2007-12-19 08:11 . 2007-12-19 08:11 23,405,072 --a------ C:\Program Files\AdbeRdr811_en_US.exe
2007-12-19 08:10 . 2007-12-19 08:10 711,024 --a------ C:\Program Files\DE04.ZIP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-01 21:27 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-01 21:25 --------- d-----w C:\Program Files\iTunes
2008-01-01 21:24 --------- d-----w C:\Program Files\GoogleAFE
2008-01-01 21:24 --------- d-----w C:\Program Files\Google
2008-01-01 21:24 --------- d-----w C:\Program Files\ESPNRunTime
2008-01-01 21:23 --------- d-----w C:\Program Files\DIGStream
2008-01-01 21:23 --------- d-----w C:\Program Files\Digital Line Detect
2008-01-01 21:18 --------- d-----w C:\Program Files\Apoint
2008-01-01 21:18 --------- d-----w C:\Program Files\AIM6
2008-01-01 10:41 --------- d-----w C:\Program Files\Trend Micro
2007-11-23 21:53 --------- d-----w C:\Program Files\iPod
2007-11-23 21:51 --------- d-----w C:\Program Files\QuickTime
2007-11-14 12:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 03:09 4,452 ----a-w C:\WINDOWS\system32\tmp.reg
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-10-04 04:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
2006-02-16 23:03 405,568 ----a-w C:\Program Files\AOLDNLD.exe
2006-01-25 13:57 1,696 ----a-w C:\Program Files\main.ini
2006-01-25 13:57 1,001,064 ----a-w C:\Program Files\aolsetup.exe
2007-08-21 16:27 56 --sh--r C:\WINDOWS\system32\3A178CC52C.sys
2007-08-21 16:27 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-01-03_16.31.59.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-03 21:52:28 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:28 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-03 21:52:14 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:14 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 19:39 176201]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-22 04:43 413775]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 17:35 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 21:05 339968]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 02:02 86016]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 20:20 8192]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30 823362]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-08 02:09 168448]
"HostManager"="C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 11:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 11:18 101888]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-03 09:28 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]

C:\Documents and Settings\Scott M. Bantel\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-13 08:54:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-02-08 01:59:48]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-02-08 01:55:11]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 01:22:40]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

R2 HPFECP13;HPFECP13;C:\WINDOWS\system32\drivers\HPFECP13.SYS [1999-04-09 02:07]
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-01-29 00:39]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-28 19:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 17:13:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-03 17:13:54
ComboFix-quarantined-files.txt 2008-01-03 22:13:38
ComboFix2.txt 2008-01-03 21:32:18
.
2007-12-12 08:04:36 --- E O F ---

2003-11-18 04:06 99352 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mabryobj.dll.vir
2006-10-14 17:28 118784 --a------ C:\Qoobox\Quarantine\C\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll.vir
2006-10-14 17:28 23040 --a------ C:\Qoobox\Quarantine\C\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTBUninstaller.exe.vir
2008-01-01 12:52 5632 --a------ C:\Qoobox\Quarantine\C\WINDOWS\medichi.exe.vir
2008-01-01 12:52 6144 --a------ C:\Qoobox\Quarantine\C\WINDOWS\murka.dat.vir
2008-01-01 12:52 6144 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dat.vir
2008-01-01 12:52 8192 --a------ C:\Qoobox\Quarantine\C\WINDOWS\medichi2.exe.vir
2008-01-01 15:31 37888 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\beep.sys.vir
2008-01-01 15:31 37888 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\beep.sys.vir
2008-01-03 16:24 2749 --a------ C:\Qoobox\Quarantine\C\ComboFix\errdbg.dat.vir
2008-01-03 16:24 652 --a------ C:\Qoobox\Quarantine\Registry_backups\hklm_windowsNT_windows.reg.dat
2008-01-03 16:24 818 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_NPF.reg.dat

ComboFix 08-01-03.4 - Scott M. Bantel 2008-01-03 17:12:03.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.209 [GMT -5:00]
Running from: C:\Documents and Settings\Scott M. Bantel\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-03 16:52 . 2008-01-03 16:52 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-01 16:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 10:48 . 2008-01-01 16:46 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 10:48 . 2008-01-01 04:10 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-01 10:48 . 2008-01-01 04:10 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-01 10:48 . 2008-01-01 04:10 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-01 07:06 . 2008-01-01 07:06 <DIR> d-------- C:\ie-spyad_zo
2008-01-01 07:03 . 2008-01-01 07:03 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-01 07:03 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-01 05:38 . 2008-01-01 05:38 <DIR> d-------- C:\Deckard
2007-12-19 08:11 . 2007-12-19 08:11 23,405,072 --a------ C:\Program Files\AdbeRdr811_en_US.exe
2007-12-19 08:10 . 2007-12-19 08:10 711,024 --a------ C:\Program Files\DE04.ZIP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-01 21:27 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-01 21:25 --------- d-----w C:\Program Files\iTunes
2008-01-01 21:24 --------- d-----w C:\Program Files\GoogleAFE
2008-01-01 21:24 --------- d-----w C:\Program Files\Google
2008-01-01 21:24 --------- d-----w C:\Program Files\ESPNRunTime
2008-01-01 21:23 --------- d-----w C:\Program Files\DIGStream
2008-01-01 21:23 --------- d-----w C:\Program Files\Digital Line Detect
2008-01-01 21:18 --------- d-----w C:\Program Files\Apoint
2008-01-01 21:18 --------- d-----w C:\Program Files\AIM6
2008-01-01 10:41 --------- d-----w C:\Program Files\Trend Micro
2007-11-23 21:53 --------- d-----w C:\Program Files\iPod
2007-11-23 21:51 --------- d-----w C:\Program Files\QuickTime
2007-11-14 12:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 03:09 4,452 ----a-w C:\WINDOWS\system32\tmp.reg
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-10-04 04:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
2006-02-16 23:03 405,568 ----a-w C:\Program Files\AOLDNLD.exe
2006-01-25 13:57 1,696 ----a-w C:\Program Files\main.ini
2006-01-25 13:57 1,001,064 ----a-w C:\Program Files\aolsetup.exe
2007-08-21 16:27 56 --sh--r C:\WINDOWS\system32\3A178CC52C.sys
2007-08-21 16:27 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2008-01-03_16.31.59.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-03 21:52:28 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:28 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-01-02 08:44:46 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-03 21:52:14 4,206,592 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-01-03 21:52:14 172,032 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 19:39 176201]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-22 04:43 413775]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 17:35 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 21:05 339968]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 02:02 86016]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 20:20 8192]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30 823362]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-08 02:09 168448]
"HostManager"="C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 11:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 11:18 101888]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-03 09:28 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]

C:\Documents and Settings\Scott M. Bantel\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-13 08:54:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-02-08 01:59:48]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-02-08 01:55:11]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 01:22:40]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

R2 HPFECP13;HPFECP13;C:\WINDOWS\system32\drivers\HPFECP13.SYS [1999-04-09 02:07]
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-01-29 00:39]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-28 19:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 17:13:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-03 17:13:54
ComboFix-quarantined-files.txt 2008-01-03 22:13:38
ComboFix2.txt 2008-01-03 21:32:18
.
2007-12-12 08:04:36 --- E O F ---
ComboFix 08-01-03.4 - Scott M. Bantel 2008-01-01 16:18:37.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.101 [GMT -5:00]
Running from: C:\Documents and Settings\Scott M. Bantel\Local Settings\Temporary Internet Files\Content.IE5\8YI4ZZ4F\ComboFix[1].exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\dllcache\beep.sys
C:\WINDOWS\system32\drivers\beep.sys
C:\Program Files\Seekmo Programs
C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll
C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTBUninstaller.exe
C:\WINDOWS\medichi.exe
C:\WINDOWS\medichi2.exe
C:\WINDOWS\murka.dat
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32\user32.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_NPF


((((((((((((((((((((((((( Files Created from 2007-12-03 to 2008-01-03 )))))))))))))))))))))))))))))))
.

2008-01-01 16:17 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 10:48 . 2008-01-01 16:46 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 10:48 . 2008-01-01 10:48 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2008-01-01 10:48 . 2008-01-01 04:10 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-01 10:48 . 2008-01-01 04:10 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-01 10:48 . 2008-01-01 04:10 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-01 07:06 . 2008-01-01 07:06 <DIR> d-------- C:\ie-spyad_zo
2008-01-01 07:03 . 2008-01-01 07:03 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-01 07:03 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-01 05:38 . 2008-01-01 05:38 <DIR> d-------- C:\Deckard
2007-12-19 08:11 . 2007-12-19 08:11 23,405,072 --a------ C:\Program Files\AdbeRdr811_en_US.exe
2007-12-19 08:10 . 2007-12-19 08:10 711,024 --a------ C:\Program Files\DE04.ZIP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-01 21:27 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-01-01 21:25 --------- d-----w C:\Program Files\iTunes
2008-01-01 21:24 --------- d-----w C:\Program Files\GoogleAFE
2008-01-01 21:24 --------- d-----w C:\Program Files\Google
2008-01-01 21:24 --------- d-----w C:\Program Files\ESPNRunTime
2008-01-01 21:23 --------- d-----w C:\Program Files\DIGStream
2008-01-01 21:23 --------- d-----w C:\Program Files\Digital Line Detect
2008-01-01 21:18 --------- d-----w C:\Program Files\Apoint
2008-01-01 21:18 --------- d-----w C:\Program Files\AIM6
2008-01-01 17:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-01 10:41 --------- d-----w C:\Program Files\Trend Micro
2007-11-23 21:53 --------- d-----w C:\Program Files\iPod
2007-11-23 21:51 --------- d-----w C:\Program Files\QuickTime
2007-11-14 12:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2006-02-16 23:03 405,568 ----a-w C:\Program Files\AOLDNLD.exe
2006-01-25 13:57 1,696 ----a-w C:\Program Files\main.ini
2006-01-25 13:57 1,001,064 ----a-w C:\Program Files\aolsetup.exe
2007-08-21 16:27 56 --sh--r C:\WINDOWS\system32\3A178CC52C.sys
2007-08-21 16:27 3,766 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE_OEM"="C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe" [2006-04-11 19:39 176201]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 10:20 50528]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-22 04:43 413775]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-01-31 17:35 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-05 21:05 339968]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [ ]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 02:05 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 02:02 86016]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 20:20 8192]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe" [2005-08-30 17:30 823362]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-02-08 02:09 168448]
"HostManager"="C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 11:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 11:18 101888]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-03 09:28 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]

C:\Documents and Settings\Scott M. Bantel\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-13 08:54:28]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2006-02-08 01:59:48]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-02-08 01:55:11]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 01:22:40]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

R2 HPFECP13;HPFECP13;C:\WINDOWS\system32\drivers\HPFECP13.SYS [1999-04-09 02:07]
S3 O2SCBUS;O2Micro SmartCardBus Reader;C:\WINDOWS\system32\DRIVERS\ozscr.sys [2005-01-29 00:39]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-28 19:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 16:27:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-03 16:32:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-03 21:32:14
.
2007-12-12 08:04:36 --- E O F ---
2003-11-18 04:06 99352 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mabryobj.dll.vir
2006-10-14 17:28 118784 --a------ C:\Qoobox\Quarantine\C\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll.vir
2006-10-14 17:28 23040 --a------ C:\Qoobox\Quarantine\C\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTBUninstaller.exe.vir
2008-01-01 12:52 5632 --a------ C:\Qoobox\Quarantine\C\WINDOWS\medichi.exe.vir
2008-01-01 12:52 6144 --a------ C:\Qoobox\Quarantine\C\WINDOWS\murka.dat.vir
2008-01-01 12:52 6144 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dat.vir
2008-01-01 12:52 8192 --a------ C:\Qoobox\Quarantine\C\WINDOWS\medichi2.exe.vir
2008-01-01 15:31 37888 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\beep.sys.vir
2008-01-01 15:31 37888 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\beep.sys.vir
2008-01-03 16:24 2749 --a------ C:\Qoobox\Quarantine\C\ComboFix\errdbg.dat.vir
2008-01-03 16:24 652 --a------ C:\Qoobox\Quarantine\Registry_backups\hklm_windowsNT_windows.reg.dat
2008-01-03 16:24 818 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_NPF.reg.dat

2003-11-18 04:06 99352 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mabryobj.dll.vir
2006-10-14 17:28 118784 --a------ C:\Qoobox\Quarantine\C\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll.vir
2006-10-14 17:28 23040 --a------ C:\Qoobox\Quarantine\C\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTBUninstaller.exe.vir
2008-01-01 12:52 5632 --a------ C:\Qoobox\Quarantine\C\WINDOWS\medichi.exe.vir
2008-01-01 12:52 6144 --a------ C:\Qoobox\Quarantine\C\WINDOWS\murka.dat.vir
2008-01-01 12:52 6144 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\user32.dat.vir
2008-01-01 12:52 8192 --a------ C:\Qoobox\Quarantine\C\WINDOWS\medichi2.exe.vir
2008-01-01 15:31 37888 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\beep.sys.vir
2008-01-01 15:31 37888 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\beep.sys.vir
2008-01-03 16:24 2749 --a------ C:\Qoobox\Quarantine\C\ComboFix\errdbg.dat.vir
2008-01-03 16:24 652 --a------ C:\Qoobox\Quarantine\Registry_backups\hklm_windowsNT_windows.reg.dat
2008-01-03 16:24 818 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_NPF.reg.dat
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-14-2008, 07:41 PM   #13 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

As I stated at the outset, if you have any questions, ask before proceeding. Using the wildcard * in a search gives more results, and the info I needed.

Please do this:

Open notepad and copy/paste the text in the quotebox below into it:

Quote:
vfind -ltf "%systemdrive%\beep.sys" >log.txt
notepad log.txt
Save this as peek.bat Choose to "Save type as - All Files"
It should look like this:
Double click on peek.bat & allow it to run. A notepad file will open. Copy that information into your next reply, please.

Also post a new HijackThis log as requested in my last post.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-17-2008, 08:31 PM   #14 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


Re: trojan downloader

Below I have pasted the copy of what you asked for. Sorry, I tried to post a new blog but I can not figure out how to do so. If you tell me how to post a new blog and what you want in that blog, I will be happy to do so. Thanks.

----a-w 4,224 2004-08-04 11:00:00 C:\i386\beep.sys
----a-w 4,080 2008-01-02 08:44:48 C:\SDFix\apps\Replace\w2k\beep.sys
----a-w 4,224 2008-01-02 08:44:48 C:\SDFix\apps\Replace\xp\beep.sys
----a-w 4,224 2004-08-04 11:00:00 C:\WINDOWS\system32\dllcache\beep.sys
----a-w 4,224 2004-08-04 11:00:00 C:\WINDOWS\system32\drivers\beep.sys

Entries: 5 (5)
Directories: 0 Files: 5
Bytes: 20,976 Blocks: 44
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-17-2008, 08:35 PM   #15 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

Quote:
I tried to post a new blog but I can not figure out how to do so. If you tell me how to post a new blog and what you want in that blog, I will be happy to do so.


What I'd like is a new HijackThis log. You've posted a couple already in this thread.

Go to Start>Run and copy/paste the following command, then press Enter.

"%programfiles%\Trend Micro\HijackThis\HijackThis.exe" /autolog

HijackThis will be running in the background. When it's done, a logfile will open. Please post that log in your next reply.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-20-2008, 10:26 AM   #16 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


Re: trojan downloader

Ok. Here is the logfile that was produced. Thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:23:01 PM, on 1/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\Apple Software Update\SoftwareUpdate.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bengals.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1140131099\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [DIGStream] "C:\Program Files\DIGStream\digstream.exe"
O4 - HKLM\..\Run: [DIGServices] "C:\Program Files\ESPNRunTime\DIGServices.exe" /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [REGSHAVE] "C:\Program Files\REGSHAVE\REGSHAVE.EXE" /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 10867 bytes
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-20-2008, 11:23 AM   #17 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

---------------------------------------------------------------------------------------------



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u4.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the drop-down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windowsi586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      • Applications and Applets
        Trace and Log Files
    • Click OK on Delete Temporary Files Window
      Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
    • Click OK to leave the Temporary Files Window
    • Click OK to leave the Java Control Panel.

---------------------------------------------------------------------------------------------


Please run this online scan to help look for remnants.

Establish an internet connection & perform an online scan using Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

---------------------------------------------------------------------------------------------


Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-21-2008, 09:16 PM   #18 (permalink)
Registered User
 
Join Date: Oct 2007
Posts: 30
OS: xp


Re: trojan downloader

Ok, I got to the step of installing jre-6u4-windowsi586-p.exe and went into the control panel to double click the java icon but do not see one. I want to make sure I do this right, so let me know what I should do. Thanks.
skattyb is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-21-2008, 09:25 PM   #19 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

Are you using Classic View, or Category View?
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 01-21-2008, 09:34 PM   #20 (permalink)
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: trojan downloader

Using Classic View, there should be a Java icon in the Control Panel if it's been successfully installed. Restart your machine if it is not.

You can also access the Java Control Panel by:

Go to Start > Run and copy/paste the following, then press Enter

javacpl.cpl
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 05:33 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85