ana Posted August 20, 2007 Report Share Posted August 20, 2007 I've been having the same problem with WinAntiSpyWare2007FreeInstall.exe.I downloaded Combofix, ran it and rebooted.Here is my log. Please advise.ThanksComboFix 07-08-17.2 - "Ana Pittell" 2007-08-19 19:53:05.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.145 [GMT -7:00] * Created a new restore point((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))C:\DOCUME~1\ANAPIT~1.\us0004.exeC:\DOCUME~1\ANAPIT~1.\wn0004.exeC:\DOCUME~1\ANAPIT~1\APPLIC~1.\macromedia\Flash Player\#SharedObjects\U5JS85G7\www.broadcaster.comC:\DOCUME~1\ANAPIT~1\APPLIC~1.\macromedia\Flash Player\#SharedObjects\U5JS85G7\www.broadcaster.com\played_list.solC:\DOCUME~1\ANAPIT~1\APPLIC~1.\macromedia\Flash Player\#SharedObjects\U5JS85G7\www.broadcaster.com\video_queue.solC:\DOCUME~1\ANAPIT~1\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.comC:\DOCUME~1\ANAPIT~1\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.solC:\DOCUME~1\ANAPIT~1\APPLIC~1.\searchtoolbarcorpC:\DOCUME~1\ANAPIT~1\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txtC:\DOCUME~1\ANAPIT~1\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txtC:\DOCUME~1\ANAPIT~1\APPLIC~1\install.datC:\DOCUME~1\ANAPIT~1\STARTM~1\Programs\Startup.\TA_Start.lnkC:\DOCUME~1\Kevin\APPLIC~1\install.datC:\Program Files\Common Files\Yazzle1281OinAdmin.exeC:\Program Files\Common Files\Yazzle1281OinUninstaller.exeC:\Program Files\Common Files\Yazzle1549OinAdmin.exeC:\Program Files\Common Files\Yazzle1549OinUninstaller.exeC:\Program Files\Common Files\ystem3~1C:\Program Files\Common Files\ystem3~1\?ystem32\C:\Program Files\Common Files\ystem3~1\tracert.exeC:\Program Files\poolsvC:\Program Files\poolsv\k11u72.exeC:\Program Files\poolsv\svhost.exeC:\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exeC:\Program Files\poolsv\wr-1-0000077.exeC:\Program Files\poolsv\YazzleBundle-1549.exeC:\Program Files\svhostC:\Program Files\svhost\wr-1-0000077.exeC:\tempb9C:\tempb9\tmpTF.logC:\WINDOWS\DOWNLO~1\USYP_0002_N91M1708NetInstaller.exeC:\WINDOWS\DOWNLO~1\UWA6P_0001_N91M1807NetInstaller.exeC:\WINDOWS\poolsv.exeC:\WINDOWS\retadpu77.exeC:\WINDOWS\svhost.exeC:\WINDOWS\system32\acenphwv.iniC:\WINDOWS\system32\akuktmwu.dllC:\WINDOWS\system32\aucgrnjf.iniC:\WINDOWS\system32\awfnrpcf.exeC:\WINDOWS\system32\aydpdwwe.exeC:\WINDOWS\system32\ayessumv.dllC:\WINDOWS\system32\bbdbxhwi.dllC:\WINDOWS\system32\behxqmru.dllC:\WINDOWS\system32\bejjrihh.exeC:\WINDOWS\system32\bfeelmgv.dllC:\WINDOWS\system32\bggffrkn.dllC:\WINDOWS\system32\biwbihkv.dllC:\WINDOWS\system32\bllbyivf.dllC:\WINDOWS\system32\bmevnvys.dllC:\WINDOWS\system32\bmslgsts.dllC:\WINDOWS\system32\boyykiut.dllC:\WINDOWS\system32\buucwtii.exeC:\WINDOWS\system32\cehasutl.exeC:\WINDOWS\system32\cgpcqvdm.dllC:\WINDOWS\system32\cgpdcxfc.dllC:\WINDOWS\system32\cjmbllei.dllC:\WINDOWS\system32\cksheboe.dllC:\WINDOWS\system32\cuctyytq.dllC:\WINDOWS\system32\cvjwkbcn.exeC:\WINDOWS\system32\cvqxsghj.dllC:\WINDOWS\system32\cvsenfsr.dllC:\WINDOWS\system32\cxriwrxp.dllC:\WINDOWS\system32\cxyjylgi.dllC:\WINDOWS\system32\dkleayud.iniC:\WINDOWS\system32\dkwjbbun.dllC:\WINDOWS\system32\drivers\dp.sysC:\WINDOWS\system32\dtnhkvxg.exeC:\WINDOWS\system32\duyaelkd.dllC:\WINDOWS\system32\dwdsregt.exeC:\WINDOWS\system32\dwospvbb.dllC:\WINDOWS\system32\dxdvgfys.dllC:\WINDOWS\system32\efcyyvs.dllC:\WINDOWS\system32\ejlwkiqh.dllC:\WINDOWS\system32\elehegdr.dllC:\WINDOWS\system32\emmonkps.dllC:\WINDOWS\system32\essjrhuf.dllC:\WINDOWS\system32\etvvkttk.exeC:\WINDOWS\system32\eudeyeaj.dllC:\WINDOWS\system32\evhqaiii.dllC:\WINDOWS\system32\fdnscppd.dllC:\WINDOWS\system32\fgcvhxfg.dllC:\WINDOWS\system32\fgunaywb.exeC:\WINDOWS\system32\fhtqkpsr.dllC:\WINDOWS\system32\fjnrgcua.dllC:\WINDOWS\system32\gcvncxcw.dllC:\WINDOWS\system32\gerraqtb.exeC:\WINDOWS\system32\getufjov.exeC:\WINDOWS\system32\gfiriutu.dllC:\WINDOWS\system32\ggxqdosp.exeC:\WINDOWS\system32\gjmklais.exeC:\WINDOWS\system32\gkarwgbn.dllC:\WINDOWS\system32\glcrabig.exeC:\WINDOWS\system32\gmfrlqro.dllC:\WINDOWS\system32\gosdvwio.dllC:\WINDOWS\system32\gpqmvvyb.dllC:\WINDOWS\system32\grfxssuf.exeC:\WINDOWS\system32\griaviex.exeC:\WINDOWS\system32\gtqdxkns.dllC:\WINDOWS\system32\gutougwd.exeC:\WINDOWS\system32\gvmcfphx.dllC:\WINDOWS\system32\gwephdhy.dllC:\WINDOWS\system32\hacnwcyu.dllC:\WINDOWS\system32\hbtvsjgj.exeC:\WINDOWS\system32\hcnucfqt.dllC:\WINDOWS\system32\hfsuplrj.dllC:\WINDOWS\system32\hhahekwn.dllC:\WINDOWS\system32\hlgdtukb.dllC:\WINDOWS\system32\hlolgucs.exeC:\WINDOWS\system32\homuaiga.dllC:\WINDOWS\system32\hpburdcm.exeC:\WINDOWS\system32\hqikwlje.iniC:\WINDOWS\system32\hriayfsx.dllC:\WINDOWS\system32\hthomsdq.dllC:\WINDOWS\system32\huuvlqsf.exeC:\WINDOWS\system32\huwfvexj.dllC:\WINDOWS\system32\hvtsyykr.dllC:\WINDOWS\system32\hxxhyfjs.dllC:\WINDOWS\system32\iacaolna.exeC:\WINDOWS\system32\idccqbcb.dllC:\WINDOWS\system32\idlchgbm.dllC:\WINDOWS\system32\iemflenu.exeC:\WINDOWS\system32\ifiqraqq.iniC:\WINDOWS\system32\iklsmmmu.dllC:\WINDOWS\system32\ipbgaurh.dllC:\WINDOWS\system32\iryhmgcd.exeC:\WINDOWS\system32\iveqccgt.exeC:\WINDOWS\system32\ivsshwwk.exeC:\WINDOWS\system32\ixbxsllp.exeC:\WINDOWS\system32\iykdvvco.dllC:\WINDOWS\system32\jdxoqnif.exeC:\WINDOWS\system32\jgaejgfn.iniC:\WINDOWS\system32\jkpbnhlr.exeC:\WINDOWS\system32\jkvvsxno.dllC:\WINDOWS\system32\jmkitawl.exeC:\WINDOWS\system32\jpckyqcp.dllC:\WINDOWS\system32\jqqxaeag.dllC:\WINDOWS\system32\jtgwnmup.exeC:\WINDOWS\system32\kahscxgm.exeC:\WINDOWS\system32\kcefjihq.iniC:\WINDOWS\system32\kemskxsy.dllC:\WINDOWS\system32\kenriboi.exeC:\WINDOWS\system32\kfbpneah.exeC:\WINDOWS\system32\kgjqquyp.exeC:\WINDOWS\system32\kucyphse.exeC:\WINDOWS\system32\kyivogro.exeC:\WINDOWS\system32\lgrcfadw.exeC:\WINDOWS\system32\lhjrqpjl.iniC:\WINDOWS\system32\ljpqrjhl.dllC:\WINDOWS\system32\lktomsbw.iniC:\WINDOWS\system32\lnuumhqb.dllC:\WINDOWS\system32\lnvctyvj.dllC:\WINDOWS\system32\lowmlpwo.exeC:\WINDOWS\system32\lvbmpsus.dllC:\WINDOWS\system32\lycwtgab.exeC:\WINDOWS\system32\mcxgrtmx.dllC:\WINDOWS\system32\mdjdjili.exeC:\WINDOWS\system32\mdvqcpgc.iniC:\WINDOWS\system32\meysamep.dllC:\WINDOWS\system32\mglkcvjv.dllC:\WINDOWS\system32\mjwfxpxq.dllC:\WINDOWS\system32\mlwofdnd.dllC:\WINDOWS\system32\msgqweat.dllC:\WINDOWS\system32\msnav32.axC:\WINDOWS\system32\mwbwgpjn.dllC:\WINDOWS\system32\mwfbnena.dllC:\WINDOWS\system32\myjofuoq.dllC:\WINDOWS\system32\nadfkbag.dllC:\WINDOWS\system32\nddilyev.dllC:\WINDOWS\system32\ndrgdnvl.exeC:\WINDOWS\system32\nesjrsxx.dllC:\WINDOWS\system32\nevscrxn.dllC:\WINDOWS\system32\nfgjeagj.dllC:\WINDOWS\system32\nibytoql.exeC:\WINDOWS\system32\njamouys.dllC:\WINDOWS\system32\nkekfxqw.dllC:\WINDOWS\system32\nndsregr.exeC:\WINDOWS\system32\nqdsregl.exeC:\WINDOWS\system32\nrktqgic.dllC:\WINDOWS\system32\nsxbfjmw.dllC:\WINDOWS\system32\ntoskrnl.dllC:\WINDOWS\system32\ntsystem.exeC:\WINDOWS\system32\nvisjnoq.exeC:\WINDOWS\system32\nyhidhyq.iniC:\WINDOWS\system32\oaytyetn.exeC:\WINDOWS\system32\odaatpea.dllC:\WINDOWS\system32\oeouhurh.dllC:\WINDOWS\system32\oglxorsd.dllC:\WINDOWS\system32\oiqniptm.dllC:\WINDOWS\system32\oiwvdsog.iniC:\WINDOWS\system32\ojkqctag.dllC:\WINDOWS\system32\okejbrrf.dllC:\WINDOWS\system32\onwhyfmt.dllC:\WINDOWS\system32\oqnamfcu.dllC:\WINDOWS\system32\orqlrfmg.iniC:\WINDOWS\system32\otugbaqh.exeC:\WINDOWS\system32\paeojecy.dllC:\WINDOWS\system32\pdtofpbs.dllC:\WINDOWS\system32\pkjtyjjy.exeC:\WINDOWS\system32\pkvwfxgd.dllC:\WINDOWS\system32\ppoyohrt.dllC:\WINDOWS\system32\pprnbwjk.exeC:\WINDOWS\system32\pvhgvhgs.dllC:\WINDOWS\system32\qciykuhn.dllC:\WINDOWS\system32\qdoffpdv.exeC:\WINDOWS\system32\qhijfeck.dllC:\WINDOWS\system32\qlicpcrr.dllC:\WINDOWS\system32\qomkkli.dllC:\WINDOWS\system32\qotpagef.exeC:\WINDOWS\system32\qpqteinu.exeC:\WINDOWS\system32\qqarqifi.dllC:\WINDOWS\system32\qtbbwetl.dllC:\WINDOWS\system32\qwfbecsq.exeC:\WINDOWS\system32\qwjyfxuu.dllC:\WINDOWS\system32\qyhdihyn.dllC:\WINDOWS\system32\qysspigl.dllC:\WINDOWS\system32\rallpfnp.exeC:\WINDOWS\system32\raxbrxbl.dllC:\WINDOWS\system32\rjjrbnov.dllC:\WINDOWS\system32\rqrpopp.dllC:\WINDOWS\system32\rqtwovxc.exeC:\WINDOWS\system32\rqumniwq.dllC:\WINDOWS\system32\rrcpcilq.iniC:\WINDOWS\system32\rttlieuk.exeC:\WINDOWS\system32\rxaptshh.exeC:\WINDOWS\system32\rxwytmwg.dllC:\WINDOWS\system32\rycnoyhp.exeC:\WINDOWS\system32\rydfhiix.dllC:\WINDOWS\system32\ryoqhuub.exeC:\WINDOWS\system32\samlechj.dllC:\WINDOWS\system32\scpqgari.dllC:\WINDOWS\system32\sduhkrwu.dllC:\WINDOWS\system32\shpjarbo.dllC:\WINDOWS\system32\sibefjyd.exeC:\WINDOWS\system32\speqljlh.exeC:\WINDOWS\system32\srllumfg.dllC:\WINDOWS\system32\sttxpqff.dllC:\WINDOWS\system32\svqidone.exeC:\WINDOWS\system32\sxgltakf.dllC:\WINDOWS\system32\T3C:\WINDOWS\system32\T3\am67.exeC:\WINDOWS\system32\T4C:\WINDOWS\system32\T4\amst5.exeC:\WINDOWS\system32\T6C:\WINDOWS\system32\T6\amwr.exeC:\WINDOWS\system32\T7C:\WINDOWS\system32\T7\icm.exeC:\WINDOWS\system32\tbutypwo.dllC:\WINDOWS\system32\tchtmuvk.dllC:\WINDOWS\system32\tcojoopq.dllC:\WINDOWS\system32\tdfcmlij.dllC:\WINDOWS\system32\tnpaqkjw.dllC:\WINDOWS\system32\tnyppfct.dllC:\WINDOWS\system32\tpmqpwft.dllC:\WINDOWS\system32\tqfcunch.iniC:\WINDOWS\system32\trhoyopp.iniC:\WINDOWS\system32\tsfgwmnl.dllC:\WINDOWS\system32\tuikyyob.iniC:\WINDOWS\system32\ufbgrvjb.dllC:\WINDOWS\system32\uuckaydq.dllC:\WINDOWS\system32\uvahntua.dllC:\WINDOWS\system32\vbrsxbte.dllC:\WINDOWS\system32\vdxholpx.exeC:\WINDOWS\system32\vewjjiax.dllC:\WINDOWS\system32\vfoxousf.dllC:\WINDOWS\system32\vfvtugxx.dllC:\WINDOWS\system32\vgfhislg.dllC:\WINDOWS\system32\vgggwxop.dllC:\WINDOWS\system32\vhtyymyl.dllC:\WINDOWS\system32\visglvuq.dllC:\WINDOWS\system32\vjvcklgm.iniC:\WINDOWS\system32\vmjejkqv.dllC:\WINDOWS\system32\vmsmtlsk.dllC:\WINDOWS\system32\vqebpndy.exeC:\WINDOWS\system32\vqoxtpiv.dllC:\WINDOWS\system32\vsdrexnc.dllC:\WINDOWS\system32\vtljycbi.dllC:\WINDOWS\system32\vwhpneca.dllC:\WINDOWS\system32\vxkrlppb.dllC:\WINDOWS\system32\vxspctwd.dllC:\WINDOWS\system32\vyjvwivj.exeC:\WINDOWS\system32\vytwnhsd.dllC:\WINDOWS\system32\wayrhogm.exeC:\WINDOWS\system32\wbsmotkl.dllC:\WINDOWS\system32\wepmqwxk.dllC:\WINDOWS\system32\wgvysnar.exeC:\WINDOWS\system32\winpfz32.sysC:\WINDOWS\system32\wjgoeila.dllC:\WINDOWS\system32\wjrnjybv.dllC:\WINDOWS\system32\wkiokmhh.dllC:\WINDOWS\system32\wqonxfng.dllC:\WINDOWS\system32\wtbefdfe.dllC:\WINDOWS\system32\wtukhadd.exeC:\WINDOWS\system32\wupmbhvc.exeC:\WINDOWS\system32\xhhurgve.exeC:\WINDOWS\system32\xiiujhcl.dllC:\WINDOWS\system32\xoydhnfp.exeC:\WINDOWS\system32\xpjvqujx.dllC:\WINDOWS\system32\xqkvejyw.exeC:\WINDOWS\system32\xqrdxqau.exeC:\WINDOWS\system32\xxbjstoh.exeC:\WINDOWS\system32\xywipetm.dllC:\WINDOWS\system32\ybdquoib.dllC:\WINDOWS\system32\ygowfdnl.dllC:\WINDOWS\system32\yhdhpewg.iniC:\WINDOWS\system32\yhfxevrx.exeC:\WINDOWS\system32\yhvpubck.exeC:\WINDOWS\system32\yignryrw.dllC:\WINDOWS\system32\zxdnt3d.cfgC:\WINDOWS\wr.txtC:\winstall.exe((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))-------\LEGACY_DOMAINSERVICE-------\DomainService((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))2007-08-19 20:53 <DIR> d-------- C:\Program Files\VSAdd-in2007-08-19 19:28 51,200 --a------ C:\WINDOWS\nircmd.exe2007-08-18 20:43 <DIR> d-------- C:\WINDOWS\pss2007-08-17 15:38 92,880 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\errprotec.exe2007-08-16 15:29 6,144 --a------ C:\WINDOWS\system32\spoolvs.exe2007-08-16 15:29 6,144 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\findfast.exe2007-08-16 15:29 50,847 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\spoolsv.dll2007-08-11 20:31 <DIR> d-------- C:\Program Files\Airhogs2007-08-03 01:07 95,696 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\sysdoctor.exe2007-07-31 12:19 322,968 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\protector.exe(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))2007-08-19 20:54 --------- d-------- C:\DOCUME~1\ANAPIT~1\APPLIC~1\SearchToolbarCorp2007-08-19 20:53 88340 --a------ C:\WINDOWS\system32\yjaseyfj.exe2007-08-16 19:25 --------- d-------- C:\Program Files\Movie Maker2007-08-04 12:31 122648 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\drvcleaner.exe2007-07-25 12:29 --------- d-------- C:\Program Files\PestTrap2007-07-24 12:53 --------- d-------- C:\DOCUME~1\ANAPIT~1\APPLIC~1\tiny2007-07-18 23:59 3583488 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll2007-07-18 10:27 --------- d-------- C:\DOCUME~1\ANAPIT~1\APPLIC~1\ultra2007-07-16 14:56 --------- d--h----- C:\Program Files\InstallShield Installation Information2007-07-14 13:26 --------- d-------- C:\Program Files\Ulead Systems2007-07-14 13:00 192622 --a------ C:\WINDOWS\system32\swinoodt.exe2007-07-12 16:31 765952 --a------ C:\WINDOWS\system32\dllcache\vgx.dll2007-07-10 12:17 87248 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\antivir.exe2007-07-08 19:36 --------- d-------- C:\Program Files\Crazy Browser2007-06-29 11:48 2 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\xxx.exe2007-06-27 07:34 823808 --a------ C:\WINDOWS\system32\dllcache\wininet.dll2007-06-27 07:34 671232 --a------ C:\WINDOWS\system32\dllcache\mstime.dll2007-06-27 07:34 6058496 --a------ C:\WINDOWS\system32\dllcache\ieframe.dll2007-06-27 07:34 52224 --a------ C:\WINDOWS\system32\dllcache\msfeedsbs.dll2007-06-27 07:34 477696 --a------ C:\WINDOWS\system32\dllcache\mshtmled.dll2007-06-27 07:34 459264 --a------ C:\WINDOWS\system32\dllcache\msfeeds.dll2007-06-27 07:34 44544 --a------ C:\WINDOWS\system32\dllcache\iernonce.dll2007-06-27 07:34 384512 --a------ C:\WINDOWS\system32\dllcache\iedkcs32.dll2007-06-27 07:34 383488 --a------ C:\WINDOWS\system32\dllcache\ieapfltr.dll2007-06-27 07:34 27648 --a------ C:\WINDOWS\system32\dllcache\jsproxy.dll2007-06-27 07:34 267776 --a------ C:\WINDOWS\system32\dllcache\iertutil.dll2007-06-27 07:34 232960 --a------ C:\WINDOWS\system32\dllcache\webcheck.dll2007-06-27 07:34 230400 --a------ C:\WINDOWS\system32\dllcache\ieaksie.dll2007-06-27 07:34 193024 --a------ C:\WINDOWS\system32\dllcache\msrating.dll2007-06-27 07:34 153088 --a------ C:\WINDOWS\system32\dllcache\ieakeng.dll2007-06-27 07:34 132608 --a------ C:\WINDOWS\system32\dllcache\extmgr.dll2007-06-27 07:34 124928 --a------ C:\WINDOWS\system32\dllcache\advpack.dll2007-06-27 07:34 1152000 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll2007-06-27 07:34 105984 --a------ C:\WINDOWS\system32\dllcache\url.dll2007-06-27 07:34 102400 --a------ C:\WINDOWS\system32\dllcache\occache.dll2007-06-27 01:27 63488 --a------ C:\WINDOWS\system32\dllcache\ie4uinit.exe2007-06-27 01:27 625152 --a------ C:\WINDOWS\system32\dllcache\iexplore.exe2007-06-27 01:27 13824 --a------ C:\WINDOWS\system32\dllcache\ieudinit.exe2007-06-27 00:00 161792 --a------ C:\WINDOWS\system32\dllcache\ieakui.dll2007-06-25 23:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll2007-06-25 23:08 1104896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll2007-06-22 17:09 124948 --a------ C:\WINDOWS\system32\gtceqejl.dll2007-06-19 06:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll2007-06-19 06:31 282112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll2007-06-13 03:23 1033216 --a------ C:\WINDOWS\system32\dllcache\explorer.exe2007-06-13 03:23 1033216 --a------ C:\WINDOWS\explorer.exe2007-06-01 04:00 192622 --a------ C:\WINDOWS\system32\owinrodt.exe2004-06-07 01:59 18432 --a------ C:\DOCUME~1\ANAPIT~1\APPLIC~1\xlibgfl254.dll2005-11-23 01:30:03 27,661 --sha-w C:\WINDOWS\system32\ddcay.dll2006-11-10 00:20:27 712,724 --sha-w C:\WINDOWS\system32\1025\bdva.dll((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}]2007-08-19 20:53 68864 --a------ C:\Program Files\VSAdd-in\VSAdd-in.dll[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACFBFE1C-226C-4B6D-B097-779C319DF912}]2006-11-09 17:20 712724 --ahs---- C:\WINDOWS\system32\1025\bdva.dll[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1}]2007-08-19 20:55 69140 --a------ C:\WINDOWS\system32\lxglxebd.dll[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]"{74DD705D-6834-439C-A735-A6DBE2677452}"= C:\Program Files\VSAdd-in\VSAdd-in.dll [2007-08-19 20:53 68864][HKEY_CLASSES_ROOT\CLSID\{74DD705D-6834-439C-A735-A6DBE2677452}][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-10-30 01:46]"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-10-30 01:33]"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-05-03 22:22]"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-26 10:15]"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-26 10:15]"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-04-21 11:28]"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-05-03 23:47]"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-04-30 10:32]"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-07-30 08:33]"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2004-10-24 12:15]"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-08-13 13:17]"Advanced Tools Check"="C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE" [2004-08-18 08:44]"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2004-12-24 03:56]"s75Q33W"="terfos.exe" []"CamCheck"="C:\Program Files\NuCam\CamCheck\CamCheck.exe" [2002-11-06 17:52]"Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-02-27 18:48]"svhost"="C:\WINDOWS\svhost.exe" []"findfast"="C:\Documents and Settings\Ana Pittell\Application Data\findfast.exe" [2007-08-16 15:29]"LaserJet"="C:\WINDOWS\system32\spoolvs.exe" [2007-08-16 15:29]"svchost"="C:\Documents and Settings\Ana Pittell\Start Menu\Programs\Startup\svchost.exe" [2007-08-16 15:29]"SystemOptimizer"="C:\WINDOWS\system32\jlhwrtlt.dll" [2007-08-19 20:55][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"RecordNow!"="" []"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:00]"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2004-08-06 16:33]"dwu4RTaFj"="sorogmsg.exe" []"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2004-02-25 11:48]"MoneyAgent"="c:\Program Files\Microsoft Money\System\mnyexpr.exe" []"SysProtect Free"="C:\Program Files\SysProtect Free\USYP.exe" []"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []"Tbsa"="C:\PROGRA~1\COMMON~1\YSTEM3~1\tracert.exe" []"findfast"="C:\Documents and Settings\Ana Pittell\Application Data\findfast.exe" [2007-08-16 15:29]"LaserJet"="C:\WINDOWS\system32\spoolvs.exe" [2007-08-16 15:29]"svchost"="C:\Documents and Settings\Ana Pittell\Start Menu\Programs\Startup\svchost.exe" [2007-08-16 15:29][HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]Source= C:\Documents and Settings\Ana Pittell\My Documents\My Pictures\home01.jpgFriendlyName= [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bdva] C:\WINDOWS\system32\1025\bdva.dll 2006-11-09 17:20 712724 C:\WINDOWS\system32\1025\bdva.dll[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll, xlibgfl254.dll, append.dll[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ana Pittell^Start Menu^Programs^Startup^Think-Adz.lnk]path=C:\Documents and Settings\Ana Pittell\Start Menu\Programs\Startup\Think-Adz.lnkbackup=C:\WINDOWS\pss\Think-Adz.lnkStartup[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3DBoxShot]C:\PROGRA~1\3DBOXS~1\3DBoxShot.exeR2 Blink2PnP;Blink2PnP;C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exeR2 CdaD10BA;CdaD10BA;\??\C:\WINDOWS\system32\drivers\CdaD10BA.SYSR2 DP1112;DP1112;\??\C:\WINDOWS\system32\Drivers\DP.sysR3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYSS3 DCamUSBBVI;SiPix StyleCam BlinkII Dual Mode Camera;C:\WINDOWS\system32\Drivers\biomini.sysContents of the 'Scheduled Tasks' folder2007-08-18 03:00:51 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Ana Pittell.job **************************************************************************catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-08-19 20:51:49Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ...scanning hidden autostart entries ...HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????8?1?1?2??????? ???B???????????????B? ?????? scanning hidden files ...C:\WINDOWS\system32\lxglxebd.dllC:\WINDOWS\system32\yjaseyfj.exeC:\WINDOWS\system32\yvsactgp.exescan completed successfullyhidden files: 3**************************************************************************Completion time: 2007-08-19 21:07:41 - machine was rebootedC:\ComboFix-quarantined-files.txt ... 2007-08-19 21:07 --- E O F --- Link to post Share on other sites
jwbirdsong Posted August 22, 2007 Report Share Posted August 22, 2007 Open Notepad and copy/paste the text in the quotebox below into it:File::C:\Documents and Settings\Ana Pittell\Start Menu\Programs\Startup\svchost.exeC:\WINDOWS\system32\yjaseyfj.exeC:\WINDOWS\system32\swinoodt.exeC:\DOCUME~1\ANAPIT~1\APPLIC~1\xxx.exeC:\DOCUME~1\ANAPIT~1\APPLIC~1\findfast.exeC:\DOCUME~1\ANAPIT~1\APPLIC~1\spoolsv.dllC:\DOCUME~1\ANAPIT~1\APPLIC~1\errprotec.exeFileLook::C:\DOCUME~1\ANAPIT~1\APPLIC~1\sysdoctor.exeC:\DOCUME~1\ANAPIT~1\APPLIC~1\protector.exeSubmit::C:\WINDOWS\system32\lxglxebd.dllC:\WINDOWS\system32\yjaseyfj.exeC:\WINDOWS\system32\yvsactgp.exeRegistry::[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}][-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACFBFE1C-226C-4B6D-B097-779C319DF912}][-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACFBFE1C-226C-4B6D-B097-779C319DF912}][-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CF46BFB3-2ACC-441b-B82B-36B9562C7FF1}][-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"s75Q33W"=-"svhost"=-"findfast"=-"LaserJet"=-"svchost"=-"SystemOptimizer"="-[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Tbsa"=-"findfast"="-"LaserJet"=-"svchost"="-[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bdva]Save this as CFScript.txt Then drag/drop the CFScript.txt onto ComboFix.exe as you see in the screenshot below.This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.Additonally, ComboFix will generate a zipped file on your desktop called Submit [Date Time].zipPlease submit this file to:http://www.bleepingcomputer.com/submit-malware.php?channel=4Please include a link to this topic in the message. Link to post Share on other sites
Recommended Posts